What problem does it solve?
Professional guidance for designing and validating secure authentication and authorization across web, mobile, and API systems. It covers identity flows, credential and token lifecycle, session/JWT/OAuth/OIDC/API-key patterns, and policy enforcement models (RBAC/ABAC/ReBAC).
Core Features & Use Cases
- Guides architecture decisions for authentication and authorization across web, mobile, and API surfaces.
- Covers token lifecycles, protocol choices (OAuth/OIDC, JWT, SAML, API keys, mTLS), and policy models (RBAC/ABAC/ReBAC).
- Supports threat modeling and integration with related skills like security-pro, nestjs-pro, nextjs-pro, postgresql-pro, and testing-pro.
Quick Start
Ask me to design a secure authentication and authorization architecture for a multi-platform system, including token workflows and policy enforcement.