{"name":"j0ruge-zitadel-idp-plugins-zitadel-idp","owner":{"name":"ClaudePluginHub"},"plugins":[{"name":"j0ruge-zitadel-idp-plugins-zitadel-idp","source":{"source":"git-subdir","url":"https://github.com/j0ruge/skills_commands_manager","path":"plugins/zitadel-idp"},"description":"Self-hosted Zitadel v4 OIDC field guide — 43 documented quirks + working docker-compose, idempotent TypeScript bootstrap, and reset script. High-friction traps: FirstInstance env placement, JWT/JWKS over self-signed HTTPS, TLS-terminating reverse proxy (`--tlsMode external`) and the admin-console `Failed to fetch` mixed-content trap, Login UI v1/v2, v2.66→v4 upgrade, API v1→v2 mapping, silent-renew, 401-storm defenses, smoke-e2e CI. Triggers — zitadel, oidc self-hosted, silent-renew, JWKS, masterkey, v2.66→v4, api v1→v2, login-ui-v2, tlsMode external, console Failed to fetch, mixed content, smoke-e2e CI, Playwright self-signed Zitadel.","version":"0.10.0","strict":true,"keywords":["zitadel","idp","oidc","auth","pkce","jwt","self-hosted","bootstrap","login-ui","branding","silent-renew","react-oidc-context","management-api","troubleshooting","firstinstance","jwks","private-labeling","masterkey","zitadel-v2","zitadel-v4","v2.66-to-v4","api-v1-to-v2","connect-protocol","login-ui-v2","schema-migration","v4.15","proto-aligned","createapplication","oidcConfiguration","extra-hosts","hairpin-nat","jwks-reload","jose-error-after-ttl","refresh-token-dedupe","rt-rotation","rt-reuse-detection","session-revoke","tanstack-query-retry-401","apiclient-unauthorized-event","smoke-e2e","gha-bind-mount-eacces","admin-pat","unique-constraints-pkey-cascade","password-policy-4-class","comma-voarj","login-ui-v2-healthcheck-slow","compose-up-wait-scope","tls-mode-external","console-failed-to-fetch","mixed-content","docker-start-stale-config"],"category":"deployment"}]}