clawauth
Installation
SKILL.md
Clawauth OAuth Skill
This skill gives agents a production-safe OAuth handover flow that is async by default and works across chat/session interruptions.
Use this when the agent needs provider credentials from a human user, but must avoid blocking execution and must avoid long-lived token storage on a third-party auth SaaS.
Why this exists
Most "OAuth gateway" patterns keep user refresh tokens in a central hosted database. clawauth avoids that model:
- Hosted edge service mints short-lived auth sessions.
- User authorizes directly with the provider.
- Token response is encrypted end-to-end to the requesting CLI session.
- CLI claims once and stores token locally in system keychain.
- Server-side session is ephemeral and deleted on claim/expiry.
Result: async UX for agents, minimal operator overhead, and no permanent central token vault by design.