← Cursor Skills · ENGINEERING
OAuth 2.0 & Third-Party API Integrations
.cursor/skills/oauth-integrations
PKCE flow, refresh token rotation, scope management, and webhook listeners.
Where it installs
# .cursor/skills/oauth-integrations/SKILL.md
---
name: oauth-integrations
description: ...
---# .claude/skills/oauth-integrations/SKILL.md
---
name: oauth-integrations
description: ...
---
# identical content, skills are the same file in both editorsWhat it does
OAuth 2.0 & Third-Party API Integrations is a Cursor skill: a SKILL.md playbook that AgenticKit installs at .cursor/skills/oauth-integrations. Cursor's agent loads it when the task matches the skill description, instead of stuffing the same rules into every chat.
Guidelines for integrating external OAuth providers (Google, GitHub, Slack) securely, managing token lifecycles, and handling API webhooks.
PKCE flow, refresh token rotation, scope management, and webhook listeners. The file is domain knowledge, not a slash macro. You do not type it. The agent reads it when the job is oauth integrations.
Why it exists
Default Cursor has no memory of how your team ships code, schema, and tests. Founders paste the same conventions into chat, then watch the model drift on the next turn. This skill exists so those conventions live on disk and load only when relevant.
It ships in the Engineering Kit. It is wired to the Third-Party Integration Lead (integration-engineer) and API Integration Specialist (api-engineer) agents. It is wired to the /auth-system: Authentication & Role-Based Access System and /build-api: API Endpoint & Route Generator commands. That graph is the point: the skill is the standard, the agent is the role, the command is the trigger.
When to use it
- Use OAuth 2.0 & Third-Party API Integrations when the work is specifically about pkce flow, refresh token rotation, scope management, and webhook listeners.
- Load it before a long session that will touch this surface more than once. A one-line edit does not need the full playbook.
- Use it on production SaaS work (multi-tenant apps, paid features, anything that will be reviewed) rather than a throwaway prototype.
When not to use it
- Do not treat the skill as a replacement for a slash command. Skills teach. Commands run a pipeline.
- Do not paste the whole SKILL.md into chat. If Cursor is not loading it, fix the description or invoke the matching command.
- Do not use it as a generic 'write better code' rule. Scope is this domain only.
Example workflow
- Install the Engineering Kit so .cursor/skills/oauth-integrations lands in the repo.
- Open a new Cursor agent chat pointed at the files this skill governs.
- Ask the Third-Party Integration Lead (integration-engineer) to read the skill, or run /auth-system: Authentication & Role-Based Access System.
- Review the first artifact against the practices below. If it violates one, stop and correct the file. Do not prompt 'just finish it'.
- Commit the skill-guided files with the rest of the slice so the next session inherits the same standard.
Example usage
Example prompt: "Read .cursor/skills/oauth-integrations and apply it to this change. Do not invent extra conventions."
Or trigger the pipeline: /auth-system: Authentication & Role-Based Access System. That command is written to load this skill.
Check the output against: Implement OAuth 2.0 with Proof Key for Code Exchange (PKCE) for authorization
Example output
- The skill itself does not write a single output file. It changes what the agent is allowed to produce in code, schema, and tests.
- When you run /auth-system: Authentication & Role-Based Access System, expect repo files plus notes under docs/, not a chat-only answer.
Best practices
- Implement OAuth 2.0 with Proof Key for Code Exchange (PKCE) for authorization
- Encrypt OAuth access tokens and refresh tokens before storing in database
- Implement automatic token refresh mechanisms when access tokens expire
- Verify webhook signatures and replay protection timestamps
Common mistakes
- Ignoring "Implement OAuth 2.0 with Proof Key for Code Exchange (PKCE) for authorization" and hoping a later prompt will clean it up.
- Copying the skill into .cursor/rules as always-on. That burns context and fights Cursor's load-on-match design.
- Running two overlapping skills that contradict each other in the same turn.
- Letting the agent skip tests or types because 'the skill is about architecture'.
Frequently asked questions
What is the OAuth 2.0 & Third-Party API Integrations Cursor skill?
Guidelines for integrating external OAuth providers (Google, GitHub, Slack) securely, managing token lifecycles, and handling API webhooks. It lives at .cursor/skills/oauth-integrations after you install the Engineering Kit.When should I use oauth-integrations instead of a Cursor rule?
Use a rule for always-on or glob-scoped constraints. Use this skill for the full playbook that should load only when the task matches.Which agents read oauth-integrations?
Third-Party Integration Lead (integration-engineer); API Integration Specialist (api-engineer). Those roles are told to open this file before they edit.Which commands use oauth-integrations?
/auth-system: Authentication & Role-Based Access System; /build-api: API Endpoint & Route Generator.Does this skill work outside AgenticKit?
Yes. A SKILL.md in .cursor/skills/oauth-integrations is a normal Cursor skill. AgenticKit is the packaged version plus the agent and command graph.
Add oauth-integrations and the other 48 Cursor skills
AgenticKit installs 61 skills, 46 agents, and 47 slash commands into .cursor/. One license, lifetime updates.