Signet SDK for Go — OAuth 2.0 device/PKCE flows, JWKS-based JWT verification, and secure credential storage with OS keyring integration
-
Updated
Sep 5, 2026 - Go
Signet SDK for Go — OAuth 2.0 device/PKCE flows, JWKS-based JWT verification, and secure credential storage with OS keyring integration
A Linux PAM module that authenticates SSH logins with GitHub's OAuth2 device flow — users approve on their phone, so there are no passwords and no SSH keys to distribute. Plain-C PAM module plus a Go broker enforcing org/team rules and username mapping.
Access governance for git repos you already host: RFC 8628 device-flow auth, scoped revocable tokens, branch protection as a pre-receive hook.
Detect and block OAuth 2.0 device code phishing (RFC 8628) across Entra ID, Keycloak, and Auth0 — with SIEM detection and incident response scripts
Federated data access testbed: one credential per user, valid at every member service, with the federation's centre never in the data path. Keycloak + Apache APISIX, control plane and data plane on separate hosts.
Python SDK for Signet — OAuth 2.0 authentication and token management
To associate your repository with the rfc8628 topic, visit your repo's landing page and select "manage topics."