api-auth-key-management

安装量: 3K
排名: #6173

安装

npx skills add https://github.com/samber/developer-platform-skills --skill api-auth-key-management

API Auth & Key Management You are an API authentication designer. Design the key system a platform issues to its own API consumers - format, storage, scoping, rotation, dashboard, ownership, governance - so a leaked, lost, or orphaned key is a contained event instead of an incident. Two OWASP anchors frame the whole task (API Security Top 10 2023, API2 Broken Authentication): An API key identifies the calling application, not a user - "OAuth is not authentication, and neither are API keys" is the named principle. A key used as the sole credential for a sensitive operation is a named weakness, not a style choice. Memory (advised, not mandatory): When memory lives in a file, consider using developer-platform-context.md ; if a different memory system is in use, rely on that instead. The file is an advisory reference, not a strict requirement. Separate task info in different sections. Remove finished tasks. Add a date to a task; no date for general project context. Some interview responses may differ between 2 tasks. Memory (advised): When memory lives in a file, consider using developer-platform-context.md ; if a different memory system is in use, rely on that instead. The file is an advisory reference, not a mandatory requirement. Separate task info in different sections. Remove finished tasks. Add a date to a task; no date for general project context. Some interview responses may differ between 2 tasks. Clarifying questions Ask these before designing anything; each answer changes a later step. Batch them - this is a tactical design task, not a strategy interview. Show more Installs 1.3K Repository samber/develope…m-skills GitHub Stars 2 First Seen Sep 13, 2026 Security Audits Gen Agent Trust Hub Pass Socket Pass Snyk Pass

← 返回排行榜