{"id":4430,"external_id":"plugins_6a86acf7816881918552f3b43bc0db69","name":"duende-skills","display_name":"Duende Skills","developer":"Duende Software","category":"Developer Tools","listing_language":"en","listing_language_details":{"method":"cld-0.13.0/listing-v1","reliable":true,"detected_at":"2026-10-01T13:22:04Z","input_sha256":"282f0e5d32edd32eb08900c2e80475e51a5bf4f249966a0242f9918ce98b85fe","source_fields":["release.description","release.interface.short_description","release.interface.long_description"]},"version":"0.3.0","skill_count":24,"first_seen_at":"2026-09-30T22:02:35.000Z","last_seen_at":"2026-10-02T12:00:02.247Z","last_changed_at":"2026-09-30T22:02:35.000Z","install_count":null,"research_summary":null,"research_reviewed_at":null,"metadata":{"id":"plugins_6a86acf7816881918552f3b43bc0db69","name":"duende-skills","scope":"GLOBAL","status":"ENABLED","release":{"id":"pluginrel_4f25107a259c819183132a1dbdcf91ab","skills":[{"name":"aspnetcore-authentication","interface":{"brand_color":null,"iconography":"code","display_name":"aspnetcore-authentication","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"ASP.NET Core authentication middleware configuration including OpenID Connect, JWT Bearer, cookie authentication, authentication schemes, challenge/forbid flows, and external identity provider integration."},"description":"ASP.NET Core authentication middleware configuration including OpenID Connect, JWT Bearer, cookie authentication, authentication schemes, challenge/forbid flows, and external identity provider integration.","plugin_release_skill_id":"pluginrsk_6a9fe2695f7c8191930f6cc2b0b9ffac"},{"name":"aspnetcore-authorization","interface":{"brand_color":null,"iconography":"code","display_name":"aspnetcore-authorization","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"ASP.NET Core authorization patterns including policy-based authorization, IAuthorizationHandler implementations, scope-based authorization for APIs, authorization middleware configuration, and minimal API authorization."},"description":"ASP.NET Core authorization patterns including policy-based authorization, IAuthorizationHandler implementations, scope-based authorization for APIs, authorization middleware configuration, and minimal API authorization.","plugin_release_skill_id":"pluginrsk_6a9fe260b1848191b0fcd5eda56d2af3"},{"name":"claims-authorization","interface":{"brand_color":null,"iconography":"code","display_name":"claims-authorization","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Claims transformation and profile service patterns for Duende IdentityServer — IProfileService, IClaimsTransformation, claim type mapping, token claim filtering, extension grant validators, and dynamic claims loading."},"description":"Claims transformation and profile service patterns for Duende IdentityServer — IProfileService, IClaimsTransformation, claim type mapping, token claim filtering, extension grant validators, and dynamic claims loading.","plugin_release_skill_id":"pluginrsk_6a9fe267bfc0819189dce10c3b2c2f1b"},{"name":"duende-bff","interface":{"brand_color":null,"iconography":"code","display_name":"duende-bff","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Duende BFF (Backend for Frontend) security framework for securing SPAs. Covers session management, API endpoint proxying, token management, anti-forgery protection, and integration with React/Angular/Blazor frontends."},"description":"Duende BFF (Backend for Frontend) security framework for securing SPAs. Covers session management, API endpoint proxying, token management, anti-forgery protection, and integration with React/Angular/Blazor frontends.","plugin_release_skill_id":"pluginrsk_6a9fe25e86348191b7d72bc38591347e"},{"name":"identity-security-hardening","interface":{"brand_color":null,"iconography":"bolt","display_name":"identity-security-hardening","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Security hardening for Duende IdentityServer deployments including signing key rotation, HTTPS enforcement, CORS configuration, CSP headers, rate limiting, token lifetime tuning, and security audit patterns."},"description":"Security hardening for Duende IdentityServer deployments including signing key rotation, HTTPS enforcement, CORS configuration, CSP headers, rate limiting, token lifetime tuning, and security audit patterns.","plugin_release_skill_id":"pluginrsk_6a9fe26d2bb08191816a57038b4ebeab"},{"name":"identity-testing-patterns","interface":{"brand_color":null,"iconography":"code","display_name":"identity-testing-patterns","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Testing patterns for IdentityServer-based systems including integration testing with WebApplicationFactory, mock token issuance, test authority configuration, protocol response validation, and end-to-end authentication flow testing."},"description":"Testing patterns for IdentityServer-based systems including integration testing with WebApplicationFactory, mock token issuance, test authority configuration, protocol response validation, and end-to-end authentication flow testing.","plugin_release_skill_id":"pluginrsk_6a9fe25da3fc81918744de20cc26196b"},{"name":"identityserver-api-protection","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-api-protection","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Protecting APIs with Duende IdentityServer: JWT bearer authentication, reference token introspection, scope-based authorization, DPoP/mTLS proof-of-possession validation, local API authentication, and multi-audience scenarios."},"description":"Protecting APIs with Duende IdentityServer: JWT bearer authentication, reference token introspection, scope-based authorization, DPoP/mTLS proof-of-possession validation, local API authentication, and multi-audience scenarios.","plugin_release_skill_id":"pluginrsk_6a9fe26a99808191b9efdb0e1f30a6b6"},{"name":"identityserver-aspire","interface":{"brand_color":null,"iconography":"default","display_name":"identityserver-aspire","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Orchestrate Duende IdentityServer in .NET Aspire AppHost — dependency graphs, authority URL wiring, health checks, and multi-instance."},"description":"Orchestrate Duende IdentityServer in .NET Aspire AppHost — dependency graphs, authority URL wiring, health checks, and multi-instance.","plugin_release_skill_id":"pluginrsk_6a9fe26c1080819186d6f9c5ad67ec55"},{"name":"identityserver-configuration","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-configuration","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Configure Duende IdentityServer including client definitions, API resources, identity resources, scopes, signing credentials, and server-side sessions. Covers client types (M2M, interactive, SPA), grant types, API Scopes vs API Resources vs Identity Resources, secret management, and client authentication methods. Includes both in-memory and database-backed configuration."},"description":"Configure Duende IdentityServer including client definitions, API resources, identity resources, scopes, signing credentials, and server-side sessions. Covers client types (M2M, interactive, SPA), grant types, API Scopes vs API Resources vs Identity Resources, secret management, and client authentication methods. Includes both in-memory and database-backed configuration.","plugin_release_skill_id":"pluginrsk_6a9fe25f0b94819195bdcedfc07a66bb"},{"name":"identityserver-dcr","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-dcr","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Configuring Dynamic Client Registration (DCR) in Duende IdentityServer: endpoint setup, authorization policies, custom validation with DynamicClientRegistrationValidator, software statement validation, IClientConfigurationStore, and separate DCR hosting."},"description":"Configuring Dynamic Client Registration (DCR) in Duende IdentityServer: endpoint setup, authorization policies, custom validation with DynamicClientRegistrationValidator, software statement validation, IClientConfigurationStore, and separate DCR hosting.","plugin_release_skill_id":"pluginrsk_6a9fe262a8588191b3062fd8c9fbadc3"},{"name":"identityserver-deployment","interface":{"brand_color":null,"iconography":"hierarchy","display_name":"identityserver-deployment","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Guide for deploying Duende IdentityServer to production, covering reverse proxy configuration, data protection, health checks, distributed caching, multi-instance deployment, OpenTelemetry integration, logging, and common deployment pitfalls."},"description":"Guide for deploying Duende IdentityServer to production, covering reverse proxy configuration, data protection, health checks, distributed caching, multi-instance deployment, OpenTelemetry integration, logging, and common deployment pitfalls.","plugin_release_skill_id":"pluginrsk_6a9fe25f091c8191ac32b6b29086efa8"},{"name":"identityserver-hosting-setup","interface":{"brand_color":null,"iconography":"default","display_name":"identityserver-hosting-setup","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Setting up and hosting Duende IdentityServer in ASP.NET Core applications, including DI registration, middleware pipeline, hosting patterns, essential options, license configuration, and ASP.NET Identity integration."},"description":"Setting up and hosting Duende IdentityServer in ASP.NET Core applications, including DI registration, middleware pipeline, hosting patterns, essential options, license configuration, and ASP.NET Identity integration.","plugin_release_skill_id":"pluginrsk_6a9fe26aa958819189fbbccc430903b8"},{"name":"identityserver-key-management","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-key-management","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Managing cryptographic signing keys in Duende IdentityServer, including automatic key management, KeyManagementOptions, data protection at rest, static key configuration, migration from static to automatic, and multi-instance deployment considerations."},"description":"Managing cryptographic signing keys in Duende IdentityServer, including automatic key management, KeyManagementOptions, data protection at rest, static key configuration, migration from static to automatic, and multi-instance deployment considerations.","plugin_release_skill_id":"pluginrsk_6a9fe25d84cc81918694060cf42167cd"},{"name":"identityserver-saml","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-saml","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Configuring Duende IdentityServer as a SAML 2.0 Identity Provider (IdP): service provider registration, SSO and SLO flows, claim mappings, extensibility interfaces, and production deployment patterns."},"description":"Configuring Duende IdentityServer as a SAML 2.0 Identity Provider (IdP): service provider registration, SSO and SLO flows, claim mappings, extensibility interfaces, and production deployment patterns.","plugin_release_skill_id":"pluginrsk_6a9fe260e98481919d13528e5fd6e5eb"},{"name":"identityserver-sessions-providers","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-sessions-providers","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Guide for configuring server-side sessions, session management and querying, inactivity timeout, dynamic identity providers, and CIBA (Client Initiated Backchannel Authentication) in Duende IdentityServer."},"description":"Guide for configuring server-side sessions, session management and querying, inactivity timeout, dynamic identity providers, and CIBA (Client Initiated Backchannel Authentication) in Duende IdentityServer.","plugin_release_skill_id":"pluginrsk_6a9fe265a4748191b902178e7d5587c6"},{"name":"identityserver-stores","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-stores","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Implement and customize Duende IdentityServer stores including configuration store, operational store, and Entity Framework Core integration. Covers migrations, custom store implementations, caching strategies, server-side sessions, signing key storage, token cleanup, and multi-tenant patterns."},"description":"Implement and customize Duende IdentityServer stores including configuration store, operational store, and Entity Framework Core integration. Covers migrations, custom store implementations, caching strategies, server-side sessions, signing key storage, token cleanup, and multi-tenant patterns.","plugin_release_skill_id":"pluginrsk_6a9fe25d1aa48191aa2500977a543ef3"},{"name":"identityserver-token-lifecycle","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-token-lifecycle","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Guide for implementing token types, refresh token management, token exchange (RFC 8693), extension grants, IProfileService claims customization, and token lifetime best practices in Duende IdentityServer."},"description":"Guide for implementing token types, refresh token management, token exchange (RFC 8693), extension grants, IProfileService claims customization, and token lifetime best practices in Duende IdentityServer.","plugin_release_skill_id":"pluginrsk_6a9fe265c0348191abed78c50a1415f1"},{"name":"identityserver-token-security","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-token-security","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Advanced token security features in Duende IdentityServer including DPoP, mTLS certificate binding, Pushed Authorization Requests (PAR), JWT Secured Authorization Requests (JAR), and FAPI 2.0 compliance configuration."},"description":"Advanced token security features in Duende IdentityServer including DPoP, mTLS certificate binding, Pushed Authorization Requests (PAR), JWT Secured Authorization Requests (JAR), and FAPI 2.0 compliance configuration.","plugin_release_skill_id":"pluginrsk_6a9fe263e6688191ab967730e8b91d8e"},{"name":"identityserver-ui-flows","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-ui-flows","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Guide for building login, logout, consent, error, and federation gateway UI pages in Duende IdentityServer, including IIdentityServerInteractionService usage, external provider integration, and Home Realm Discovery strategies."},"description":"Guide for building login, logout, consent, error, and federation gateway UI pages in Duende IdentityServer, including IIdentityServerInteractionService usage, external provider integration, and Home Realm Discovery strategies.","plugin_release_skill_id":"pluginrsk_6a9fe266461881918f794172f26c79af"},{"name":"identityserver-upgrade-v7-to-v8","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver-upgrade-v7-to-v8","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Migrating Duende IdentityServer from v7.4 to v8.0: breaking changes, API replacements (ICache→HybridCache, IClock→TimeProvider), CancellationToken additions, EF migrations, and step-by-step upgrade guide."},"description":"Migrating Duende IdentityServer from v7.4 to v8.0: breaking changes, API replacements (ICache→HybridCache, IClock→TimeProvider), CancellationToken additions, EF migrations, and step-by-step upgrade guide.","plugin_release_skill_id":"pluginrsk_6a9fe2670ce081919040910947a835a6"},{"name":"identityserver-usermanagement","interface":{"brand_color":null,"iconography":"default","display_name":"identityserver-usermanagement","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Setting up Duende User Management with IdentityServer: passwordless authentication (OTP, TOTP, passkeys), storage configuration, user lifecycle, and migration from ASP.NET Identity."},"description":"Setting up Duende User Management with IdentityServer: passwordless authentication (OTP, TOTP, passkeys), storage configuration, user lifecycle, and migration from ASP.NET Identity.","plugin_release_skill_id":"pluginrsk_6a9fe2621f5881918f87f024053a75e5"},{"name":"identityserver4-migration","interface":{"brand_color":null,"iconography":"code","display_name":"identityserver4-migration","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Migrating from IdentityServer4 to Duende IdentityServer v8. Covers NuGet package replacement, namespace changes, API surface changes, EF Core database schema migrations, .NET target framework upgrade, license configuration, signing key migration, data protection, and UI template updates."},"description":"Migrating from IdentityServer4 to Duende IdentityServer v8. Covers NuGet package replacement, namespace changes, API surface changes, EF Core database schema migrations, .NET target framework upgrade, license configuration, signing key migration, data protection, and UI template updates.","plugin_release_skill_id":"pluginrsk_6a9fe26a8b9c8191a4adcfd8990c81b0"},{"name":"oauth-oidc-protocols","interface":{"brand_color":null,"iconography":"default","display_name":"oauth-oidc-protocols","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"OAuth 2.0 and OpenID Connect protocol fundamentals including authorization code flow with PKCE, client credentials, refresh tokens, discovery documents, JWKS, and token introspection. Protocol-level troubleshooting and compliance."},"description":"OAuth 2.0 and OpenID Connect protocol fundamentals including authorization code flow with PKCE, client credentials, refresh tokens, discovery documents, JWKS, and token introspection. Protocol-level troubleshooting and compliance.","plugin_release_skill_id":"pluginrsk_6a9fe265b5fc8191b35b52bee2fa17da"},{"name":"token-management","interface":{"brand_color":null,"iconography":"code","display_name":"token-management","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Token management patterns using Duende.AccessTokenManagement. Covers client credential token caching, user token refresh, token storage, HttpClientFactory integration, DPoP support, and common configuration pitfalls. Also includes Blazor Server token management."},"description":"Token management patterns using Duende.AccessTokenManagement. Covers client credential token caching, user token refresh, token storage, HttpClientFactory integration, DPoP support, and common configuration pitfalls. Also includes Blazor Server token management.","plugin_release_skill_id":"pluginrsk_6a9fe2631b1481919cd1ef84302057f0"}],"app_ids":[],"version":"0.3.0","keywords":["identityserver","oauth","oidc","openid-connect","aspnetcore","authentication","authorization","bff","token-management","duende","dotnet","security"],"interface":{"category":"Developer Tools","logo_url":"https://files.openai.com/content?id=file_00000000f55c820aaa9d9a4d33ca15b5","brand_color":null,"website_url":"https://duendesoftware.com","capabilities":["Read"],"logo_url_dark":null,"default_prompt":"My IdentityServer is deployed behind an nginx reverse proxy. How do I fix the wrong URL schema used?","developer_name":"Duende Software","default_prompts":["My IdentityServer is deployed behind an nginx reverse proxy. How do I fix the wrong URL schema used?","Configure the IdentityServerOptions for my project. Also configure data protection for a multi-instance deployment.","Give me a complete checklist of everything I need to do to upgrade from IdentityServer v7.4 to the latest."],"screenshot_urls":[],"long_description":"Specialized skills and agents covering Duende IdentityServer configuration, OAuth 2.0 / OpenID Connect protocols, ASP.NET Core authentication and authorization, BFF patterns, token management, SAML, key management, deployment, and security hardening.","composer_icon_url":"https://files.openai.com/content?id=file_00000000d9ec82438f83ac7b544648e2","short_description":"IdentityServer & OAuth skills","plugin_category_id":"developer tools","privacy_policy_url":"https://duendesoftware.com/privacy","terms_of_service_url":"https://duendesoftware.com/terms","composer_icon_dark_url":null},"description":"Duende development skills and agents — covering OAuth/OIDC protocols, IdentityServer, token management, ASP.NET Core authentication/authorization, BFF patterns, and secure identity architecture","app_manifest":null,"display_name":"Duende Skills","app_templates":[],"onboarding_skill_name":null,"requires_local_executor":false},"created_at":"2026-08-20T07:39:21.037373Z","is_template":false,"connector_id":null,"discoverability":"UNLISTED","canonical_app_id":null},"research":null,"package_metadata":{"name":"duende-skills","author":{"url":"https://duendesoftware.com","name":"Duende Software"},"license":"MIT","sources":[{"path":".codex-plugin/plugin.json","sha256":"f31f4c54badd59f256166ad7bc20ea96e2942ea0293480024749077dc4a22205"}],"version":"0.3.0","homepage":"https://github.com/DuendeSoftware/duende-skills","keywords":["identityserver","oauth","oidc","openid-connect","aspnetcore","authentication","authorization","bff","token-management","duende","dotnet","security"],"repository":"https://github.com/DuendeSoftware/duende-skills","artifact_id":11282,"observed_at":"2026-10-02T00:31:10Z","capabilities":["Read"],"field_sources":{"name":0,"author":0,"license":0,"version":0,"homepage":0,"keywords":0,"repository":0,"capabilities":0},"extraction_version":1,"conflicts_or_errors":[]}}