Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
5 results
label:oidc

Zitadel

@dataverket/zitadel · v2026.10.05.1

Zitadel for swamp, over its API: seven model types, one per resource, with the whole life cycle of each.

upd Oct 521 pullsA100/100

Gcp/iam

@hivemq/gcp/iam · v2026.09.11.1789122862

Bootstrap and maintain the GCP identities CI authenticates as: Workload Identity Federation pools and providers, the service accounts behind them, and the IAM bindings tying the two together. CI cannot create the identity it federates into, so an operator provisions it out of band with this model. Project IAM grants and revocations are condition-aware — including delegated role grants, which bound `roles/resourcemanager.projectIamAdmin` to a fixed set of roles — and policies are read and written at version 3 so conditional bindings survive a read-modify-write.

upd Sep 1154 pullsB85/100

Pocket Id

@jamesakeech/pocket-id · v2026.08.08.1

Observability for a Pocket ID instance — the passkey-based OIDC provider. `health` is a cheap, admin-free probe that separates an unreachable host from a wrong API key from a key whose owner is not an admin, and reports version drift; it writes its result as data rather than throwing, so a failed run still leaves a truthful record. `sync` fans out one resource per user, OIDC client, group and API key, joins each user against their passkeys and their sign-ins and each client against its authorizations, then scores the whole instance into `instance.findings`: accounts with no passkey that therefore cannot sign in, public clients with PKCE disabled, clients nobody has authorized, empty groups, and the API key whose expiry will silently stop the sync. `syncActivity` reads a bounded window of the audit log on its own — Pocket ID has no date filter, so the window is applied by walking newest-first and stopping early, which makes a short window genuinely cheap. Read-only throughout.

upd Aug 814 pullsA100/100

Zitadel

@thomas/zitadel · v2026.06.24.1

Careful, non-destructive administration of a Zitadel instance over its Management API (v1 REST), authenticated with a JWT private-key service account. Read/audit of orgs, projects, applications, users and managers; idempotent provisioning of OIDC/API applications and machine (service) users; project-role and user-grant authorization (roles, grants, and the role-assertion flag that surfaces roles in tokens); rotation of client secrets, PATs, machine keys and secrets; and reversible deactivate/reactivate. Machine identities only. The only hard delete is a single, verify-first project-role removal (roles have no deactivate state); secrets are emitted once and marked sensitive.

upd Jun 2419 pullsA100/100

Trust Network

@mccormick/trust-network · v2026.06.13.1

Inventory and report on OIDC trust policies and workload-identity federation across GitHub, Google Cloud, and Cloudflare One.

upd Jun 1333 pullsA100/100