a2a-market-google-oauth

Handle Google OAuth login, account linking, and session bootstrap for A2A market users and operators. Use when implementing identity login endpoints, callback verification, and secure token/session lifecycle.

Safety Notice

This listing is from the official public ClawHub registry. Review SKILL.md and referenced scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "a2a-market-google-oauth" with this command: npx skills add luoqianchenguni-max/a2a-market-google-oauth

a2a-Market Google OAuth

Create a stable OAuth integration shell for buyer and merchant sign-in.

Current status: publish-ready scaffold. Keep flows explicit and deterministic before full SSO hardening.

Scope

  • Implement Google OAuth authorization code flow.
  • Link external identity to internal Agent/Operator profile.
  • Bootstrap session token and refresh workflow after callback.

Suggested Project Layout

  • app/integrations/oauth/google_client.py
  • app/interfaces/api/auth_routes.py
  • app/application/services/session_service.py
  • app/protocol/identity/user_identity_mapper.py

Minimum Contracts (MVP P0)

  1. GET /auth/google/start builds state + redirect URL.
  2. GET /auth/google/callback validates state and exchanges code.
  3. upsert_identity(provider, provider_user_id, email) returns internal principal id.
  4. create_session(principal_id) returns short-lived access token and refresh token.

Security Baseline

  • Validate state and nonce against server-side cache.
  • Reject callback if issuer/audience do not match configuration.
  • Store only hashed refresh tokens and rotate on use.

Events

  • Emit login event to audit log stream.
  • Emit session-created event for WebSocket presence bootstrap.

Implementation Backlog

  • Add account merge flow for duplicate emails across providers.
  • Add step-up verification for risky sessions.

Runtime Implementation

  • Status: implemented in local runtime package.
  • Primary code paths:
  • runtime/src/integrations/oauth/google-oauth-service.js
  • Validation: covered by runtime/tests and npm test in runtime/.

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

General

Huo15 Openclaw Enhance

火一五·克劳德·龙虾增强插件 v5.7.8 — 全面适配 openclaw 2026.4.24:peerDep ^4.24 + build/compat 同步到 4.24 + 14 处 api.on 全部去掉 as any 改成 typed hook(hookName 联合类型 + handler 自动推断 Pl...

Registry SourceRecently Updated
General

Content Trend Analyzer

Aggregates and analyzes content trends across platforms to identify hot topics, user intent, content gaps, and generates data-driven article outlines.

Registry SourceRecently Updated
General

Prompt Debugger

Debug prompts that produce unexpected AI outputs — diagnose failure modes, identify ambiguity and conflicting instructions, test variations, compare model re...

Registry SourceRecently Updated
General

Indie Maker News

独行者 Daily - 变现雷达。读对一条新闻,少走一年弯路。每天5分钟,给创业者装上商业雷达。聚焦一人公司、副业、创业变现资讯,智能分类,行动导向。用户下载即能用,无需本地部署!

Registry SourceRecently Updated