dpop-adoption
Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform. Use when configuring non-extractable asymmetric key pairs (P-256), generating DPoP Proof JWTs for authorization code exchange and
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 1145e7777388cdde… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
DPoP Adoption & Identity Security Architecture
Demonstrating Proof-of-Possession (DPoP, RFC 9449) secures OAuth 2.0 refresh
tokens against interception and replay attacks by cryptographically binding them
to a private key held exclusively by the client. In Google's OAuth 2.0 platform,
DPoP binds the refresh token at the token endpoint, while access tokens issued
for Google APIs are standard Bearer tokens (token_type: "Bearer").
1. Core Cryptographic & Architectural Invariants
When implementing DPoP helpers or upgrading HTTP clients, you MUST adhere to the following strict security invariants:
A. Universal WebCrypto & Runtime Compatibility
- In modern ES6 JavaScript (
"type": "module"for Node 18+ and browsers), ALWAYS accessglobalThis.cryptodirectly after verifying the environment context. - NEVER import legacy CommonJS modules via
require('node:crypto')or reference browser-scopedwindow.crypto, as these cause module initialization crashes across hybrid runtimes.
B. Hardware-Backed Non-Extractable Key Persistence
- Generate an Elliptic Curve key pair on the SECP256R1 (
P-256) curve:{ name: 'ECDSA', namedCurve: 'P-256' }. - CRITICAL SECURITY GUARDRAIL: The private key MUST be configured as
non-extractable (
extractable: false). This guarantees the private key can never leave the hardware cryptographic boundary (Secure Enclave, Android KeyStore, or JS sandbox memory), thwarting XSS and dependency token theft attacks. - The public key MUST remain exportable (
extractable: true) to allow emitting JSON Web Keys (JWKs).
C. Public JWK Formatting Standards
- When exporting public keys to attach to DPoP Proof JWT headers, construct a
clean JWK dictionary containing strictly:
"kty": "EC""crv": "P-256""x": Base64URL-encoded x-coordinate without trailing equal sign padding (=)."y": Base64URL-encoded y-coordinate without trailing equal sign padding (=).
- NEVER expose private key parameters (
"d") or superfluous metadata.
D. IEEE P1363 vs. ASN.1 DER Signature Disambiguation
- DPoP Proof JWTs require raw concatenated coordinate signatures ($R \parallel S$, exactly 64 bytes for P-256) per IEEE P1363 and RFC 7518.
- WebCrypto Native Rule: In standard WebCrypto (
crypto.subtle.sign), ECDSA signatures are ALREADY emitted natively in raw IEEE P1363 format (concatenated 32-byterandsbuffers, 64 bytes total). DO NOT attempt DER-to-Raw conversion oncrypto.subtle.signoutputs, as parsing a 64-byte raw buffer as ASN.1 DER causes an immediate runtime exception (Invalid DER sequence). Directly base64url-encode the raw ArrayBuffer. - Legacy API Fallback: If and only if implementing in legacy Java/Android
(
java.security.Signature) or Node CommonJS (crypto.createSign), convert ASN.1 DER output to raw 64-byte IEEE P1363 format before base64url encoding.
E. SPA & Backend-for-Frontend (BFF) Architecture
- Secretless SPAs Limitation: Pure client-side single-page applications
(SPAs) without a backend cannot use DPoP directly with Google APIs due to
client_secretrequirements on server endpoints and browser CORS limitations on theDPoP-Nonceresponse header. - BFF Pattern: To secure SPAs with DPoP, route authorization and token
refresh requests through a Backend-for-Frontend (BFF) server-side client.
The BFF sets
access_type=offline, binds refresh tokens server-side using DPoP, and maintains secure session cookies with the frontend.
2. Implementation Rules & Mandatory Public API
When creating new modules, your module MUST explicitly export all functions below to integrate cleanly with CI/CD verification harnesses and automated probers. When inspecting or refactoring existing codebases, ensure equivalent cryptographic and RFC 9449 logic is present. Obey strict claim derivation logic in all cases:
A. DPoP Proof JWT Claim Derivation Rules (createDPoPProof)
When generating the DPoP Proof JWT in createDPoPProof:
1. JOSE Header (typ, alg, jwk):
// Header
{
"typ": "dpop+jwt",
"alg": "ES256",
"jwk": await exportPublicJWK(publicKey)
}
2. Payload Claims:
"htm": Uppercase HTTP Method ("POST"for token requests)."htu": Target URI stripped of query parameters and hash fragments usingsanitizeHTU(htu). For token requests, this ishttps://oauth2.googleapis.com/token."iat": Current integer epoch timestamp in seconds (Math.floor(Date.now() / 1000))."jti"(Critical Invariant):- If an explicit
jtiargument is provided tocreateDPoPProof, use that exact string over all others. - Otherwise, if an
authCodeargument is provided (during initial code exchange), setjti = await calculateAuthCodeJti(authCode)wherecalculateAuthCodeJticomputesbase64url(sha256(authCode))to ensure the DPoP proof is cryptographically bound to the authorization code. - Only if neither
jtinorauthCodeis provided, generate a fresh cryptographic random string viagenerateRandomString()(such ascrypto.getRandomValues(new Uint8Array(24))base64url encoded).
- If an explicit
"ath"(Optional): If anaccessTokenargument is provided for RFC 9449 resource requests, computebase64url(sha256(accessToken))viacalculateATH(accessToken)and inject it (RFC 9449 Section 6.1)."nonce"(Optional): If anonceargument is provided, inject it directly into the payload.
B. Explicit Export Signatures
// 1. Key generation & JWK export
export async function generateDPoPKeyPair() // -> { publicKey, privateKey } (private key extractable=false)
export async function exportPublicJWK(publicKey) // -> { kty: 'EC', crv: 'P-256', x, y }
// 2. Proof generation & validation
export async function createDPoPProof({ privateKey, publicKey, htm, htu, nonce, accessToken, authCode, jti }) // -> signed JWT string
export async function verifyDPoPProof(dpopProofJwt) // -> { isValid: boolean, header, payload, error }
export function sanitizeHTU(htu) // -> URL stripped of query and hash: const u = new URL(htu); return `${u.origin}${u.pathname}`;
// 3. Cryptographic & encoding utilities
export function base64UrlEncode(buffer) // -> Uint8Array/ArrayBuffer to base64url string without '=' padding
export function base64UrlDecode(str) // -> base64url string to Uint8Array/Buffer
export function stringToBase64Url(str) // -> UTF-8 string to base64url
export function base64UrlToString(str) // -> base64url to UTF-8 string
export function generateRandomString(byteLength = 32) // -> cryptographic random base64url string
export async function calculateATH(accessToken) // -> base64url(sha256(accessToken)) per RFC 9449 Sec 6.1
export async function calculateAuthCodeJti(code) // -> base64url(sha256(code))
export async function generatePKCE() // -> { codeVerifier (>=43 chars), codeChallenge, codeChallengeMethod: 'S256' }
3. Token Endpoint & Resource Request Workflow
When integrating with Google's OAuth 2.0 platform:
- Token Endpoint Requests (
oauth2.googleapis.com/token):- Attach the DPoP Proof JWT in the
DPoPHTTP header:`DPoP: ${proofJwt}`when makingPOSTrequests for code exchange (grant_type=authorization_code) and token refresh (grant_type=refresh_token).
- Attach the DPoP Proof JWT in the
- Resource API Requests:
- Google's token endpoint returns
"token_type": "Bearer". Downstream requests to Google APIs (e.g. Calendar, Drive, Gmail) use standard`Authorization: Bearer ${accessToken}`headers without DPoP headers.
- Google's token endpoint returns
- Single-Retry Nonce Challenge Loop & Workflow Isolation:
- If Google's token endpoint returns HTTP
400 Bad Requestwitherror: "use_dpop_nonce"and a"DPoP-Nonce"response header:- Workflow Isolation: Google's authorization server enforces
workflow isolation between authorization code exchange and token
refresh, returning an HTTP
400 use_dpop_noncechallenge to establish a fresh nonce namespace. This is standard RFC-compliant protocol behavior, not a server failure. - Cache the fresh nonce in client state (
this.dpopNonce). - Immediately synthesize a new DPoP Proof JWT incorporating the
updated
nonceclaim and a freshjti. - Replay the failed token request exactly once. If the retried request fails, terminate immediately with an error to prevent infinite recursion.
- Workflow Isolation: Google's authorization server enforces
workflow isolation between authorization code exchange and token
refresh, returning an HTTP
- If Google's token endpoint returns HTTP
4. Concise Agent Egress Protocol
When prompted to synthesize or output code deliverables under this skill, prioritize returning clean, directly importable code blocks without redundant conversational preambles or repetitive filler. For conceptual or architectural inquiries, provide standard direct answers.
5. References & Supporting Documentation
Developer Documentation (Google for Developers)
- DPoP Adoption Guide — Official Google Identity guide for implementing DPoP across authorization code exchange and token refresh.
- Using OAuth 2.0 for Web Server Applications — Offline access, refresh tokens, and server-side authorization flows.
- OAuth 2.0 Best Practices: Sender-Constrain Tokens — Recommendations for token storage, rotation, and sender-constraining.
Developer Knowledge MCP Server
- Agents equipped with Model Context Protocol (
MCP) can query real-time Google Developer documentation using the Google Developer Knowledge MCP Server (npx -y @google/mcp-developer-knowledge-server) viadeveloper_knowledge:search_documentsanddeveloper_knowledge:get_documents.
Standards & RFC Specifications
Files
1- SKILL.md
c6fc02759411.0 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from google/skills8
Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st
Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model
Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run
Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be
Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c
Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry
Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.
Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.
Related frontend skillsscan passed
PostHog error tracking for React
Routes live context checks to the native Codex or Claude Code meter without scanning files, and performs a bounded static component audit only when explicitly requested. Use for context-budget requests about remaining capacity or installed context overhead.
Build UIs with @nuxt/ui v4 — 125+ accessible Vue components with Tailwind CSS theming. Use when creating interfaces, customizing themes to match a brand, building forms, or composing layouts like dashboards, docs sites, and chat interfaces.
Launch GStack Browser — AI-controlled Chromium with the sidebar extension baked in.
Generate an explorable HTML report of Claude Code session usage (tokens, cache, subagents, skills, expensive prompts) from ~/.claude/projects transcripts.
Reviews and fixes keyboard and focus behavior, ARIA, accessible names, forms, screen-reader announcements, motion and zoom in your project against WCAG 2.2.