Security
OwlAuth is security-sensitive pre-release software. Do not use the current scaffold as a production authorization server. The target server invariants are defined in the OAuth/security specification, and SDK handling rules are defined in the SDK security specification; these are design requirements, not claims of current implementation.
Report suspected vulnerabilities through GitHub private vulnerability reporting, not a public issue.
Registry and Cloudflare credentials belong only in GitHub Actions secrets or trusted-publishing identities. Never commit tokens, include them in release metadata, or paste them into issues and pull requests.