Install
openclaw skills install oauthImplement OAuth 2.0 and OpenID Connect flows securely.
openclaw skills install oauthcode_verifier: 43-128 char random string, stored client-sidecode_challenge: SHA256 hash of verifier, sent with auth requestcode_verifier—server verifies against stored challengestate in authorization request—prevents CSRF attacksstate matches stored value before processing callback/callback ≠ /callback/openid profile email (OIDC), repo:read (GitHub-style)openid scope required for OIDC—triggers ID token issuancesub, iss, aud, exp + profile claimsnonce parameter prevents replay attacks—include in auth request, verify in ID tokeniss and aud in tokens—prevents token confusion across services/authorize: user-facing, returns code via redirect/token: backend-to-backend, exchanges code for tokens; requires client auth for confidential clients/userinfo (OIDC): returns user profile claims; requires access token/revoke: invalidates tokens; accepts access or refresh token