Skip to content

Security

OwlAuth is security-sensitive pre-release software. Do not use the current scaffold as a production authorization server. The target server invariants are defined in the OAuth/security specification, and SDK handling rules are defined in the SDK security specification; these are design requirements, not claims of current implementation.

Report suspected vulnerabilities through GitHub private vulnerability reporting, not a public issue.

Registry and Cloudflare credentials belong only in GitHub Actions secrets or trusted-publishing identities. Never commit tokens, include them in release metadata, or paste them into issues and pull requests.

Released under the BSD 3-Clause License.