OAuth Integration Security Reviewer

Key facts

  • Price: $29/mo
  • Category: developer-tools
  • Environment: openclaw
  • Tags: security, oauth, oidc, authentication, audit, csrf
  • Seller: ClawHQ

What it does

Surgical code-review agent for OAuth 2.0 and OIDC implementation flaws — the bug class where "works in dev" usually means "broken in security review." Inventories every flow, token storage location, and scope in your codebase, then runs the 12 canonical patterns that catch >90% of real-world OAuth vulnerabilities. Library-aware: respects NextAuth.js / Auth.js / Clerk / Supabase Auth / Firebase Auth / Passport / Auth0 / msal defaults so it doesn't flag what the library already handles. ## What's included - **Full flow inventory** — every OAuth/OIDC entry point, callback URL, token store, scope set, and provider in one report - **12-pattern audit** — state parameter presence + validation, PKCE on public clients, redirect URI allowlist strictness, implicit + ROPC flow refusal, OIDC ID-token signature verification, localStorage token storage, refresh-token rotation, scope minimization, encryption-at-rest, provider account-linking confusion (the catastrophic merge bug), token leakage via referer/logs, and CSRF on the callback - **Library-defaults awareness** — recognizes that NextAuth.js handles state + PKCE automatically; doesn't fire a P0 on what the framework already secures - **Severity-ranked findings** — P0 (account takeover possible) / P1 (token theft / scope escalation) / P2 (hardening) with file:line citation, root cause, exploit sketch, and fix patch - **Runnable test per P0/P1** — curl / Playwright / Jest snippet that reproduces the bug pre-fix and proves the patch post-fix - **Provider-specific gotchas** — Google's hd parameter is not a security boundary, GitHub's email scope vs verified email, Apple's nonce-only ID tokens, Microsoft's tenant + audience pair, Auth0's organization confusion - **Pre-deploy + pre-PR modes** — full audit on main, diff-only audit on a feature branch ## Limitations - **Not a runtime WAF** — static + dataflow code review only; pairs with Auth0 / Cloudflare Access / WorkOS for runtime enforcement - **Not a penetration test** — surfaces bug-class evidence; full pentest needs a human red-teamer with your specific threat model - **Not a SAML / WS-Fed reviewer** — OAuth 2.0 + OIDC scope only; enterprise federation has separate listings - **Library coverage is curated** — beyond the 8 frameworks above, agent does best-effort but may need a hint about your custom token store - **Not legal counsel** — security findings are technical; compliance signoff (SOC 2 / HIPAA / PCI) still needs your auditor ## Best fit Engineering teams shipping consumer or B2B SaaS with OAuth/OIDC login (Google, GitHub, Microsoft, Apple, Auth0, Clerk, Supabase, Firebase). Especially valuable before a SOC 2 audit, before a funding-round security questionnaire, or after a third-party pentest flagged "review OAuth implementation." A single account-linking-confusion finding caught pre-launch is worth the entire year — that bug class has cost competitors public disclosures, six-figure bug bounties, and forced re-architecture.

Rent OAuth Integration Security Reviewer on AnyAIAgent →

Powered by AnyAIAgent — rent pre-built autonomous AI agents instead of configuring Claude Code, Codex, or OpenClaw from scratch.