oauth-disguiseConfigure Anthropic OAuth tokens (sk-ant-oat01-*) to work as API keys in OpenClaw via environment variable injection, enabling Claude Pro/Team API access.
Install via ClawdBot CLI:
clawdbot install jiafar/oauth-disguiseGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
${ANTHROPICCalls external URL not in known-safe list
https://your-proxy.com/Uses known external API (expected, informational)
api.anthropic.comAI Analysis
This skill provides legitimate configuration guidance for using Anthropic OAuth tokens with the official API and does not contain hidden malicious instructions. The only external URLs referenced are the official Anthropic API (expected) and a user-configured proxy (clearly documented as optional fallback), with no evidence of credential harvesting or data exfiltration.
Generated Jul 11, 2026
An enterprise using Anthropic's official API can inject OAuth tokens via environment variables to replace proxy-based connections, ensuring direct access to latest models like Claude Sonnet 4 and Opus 4.6. This avoids authentication errors from using OAuth tokens directly. Ideal for companies migrating from third-party proxies to Anthropic's official endpoints.
A developer sets up dual providers (proxy and official) to seamlessly switch between a custom proxy and Anthropic's official API. This allows testing new models while keeping a fallback for reliability. Useful for gradual rollout of official API adoption.
Claude Pro/Team subscribers who possess OAuth tokens can use this skill to convert those tokens into working API keys via OpenClaw. This enables API access without needing standard API keys. Ideal for users with active subscriptions but no API key.
A user configures different agents to use either proxy or official Anthropic models by adjusting per-agent settings. For example, a coding agent uses Opus via official API while a generic chat agent stays on proxy. This optimizes cost and performance per task.
Organizations can inject sensitive OAuth tokens via environment variables rather than inline in config files, keeping tokens redacted in outputs. This prevents accidental exposure in version control. Suitable for teams with strict security policies.
Offer basic features via proxy while premium users get direct Anthropic API access by injecting their OAuth tokens. This encourages subscription conversion while maintaining service for free tier. Revenue from premium subscriptions.
Resell Anthropic API access to enterprises by handling OAuth token injection and configuration. Provide managed OpenClaw instances with pre-configured official providers. Revenue from markup on API usage or flat monthly fees.
Consulting service that helps businesses set up dual provider configurations to balance cost and performance. Analyze usage patterns to automatically switch between proxy and official API. Revenue from setup fees and maintenance contracts.
💬 Integration Tip
Always restart the OpenClaw gateway after modifying env.vars, and avoid rapid token switching to prevent authentication cooldown.
Scored Jul 11, 2026
Audited Apr 17, 2026 · audit v1.0
Self-hosted auth for TypeScript/Cloudflare Workers with social auth, 2FA, passkeys, organizations, RBAC, and 15+ plugins. Requires Drizzle ORM or Kysely for D1 (no direct adapter). Self-hosted alternative to Clerk/Auth.js. Use when: self-hosting auth on D1, building OAuth provider, multi-tenant SaaS, or troubleshooting D1 adapter errors, session caching, rate limits, Expo crashes, additionalFields bugs.
Clerk integration. Manage Users, Organizations. Use when the user wants to interact with Clerk data.
Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP outages), and component reference. Prevents 15 documented errors. Use when: API keys for users/orgs, Next.js 16 middleware filename, troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors, webhook verification, user type inconsistencies, or testing with 424242 OTP.
Access ETH wallet address and securely send ETH or USDC on Ethereum or Base chains with 2FA authentication code verification.
Manages consent with strict safety limits, prohibits profiling or coercion, limits crisis inference, and ensures autonomy without persistent tracking or pres...
Agent verification via ClawX OAuth system. Use when checking agent verification status, embedding verification widgets, or working with agent identity/trust tiers.