Skip to content
CAI
Software that uses CAICheck a score

kivra/oauth2_client

50.4

Adequate · 2 October 2026

661

lines of production code

Erlang

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Erlang OAuth 2.0 client library designed to simplify interactions with OAuth-enabled REST services. It supports multiple authentication flows, including Client Credentials and Google service account JWTs, while managing token caching and automatic re-authentication. The library decouples HTTP transport from core logic and integrates with OpenTelemetry for distributed tracing.

Features

Initial release of OAuth2 Client library

This entry introduces the oauth2\_client library, an Erlang tool designed to simplify consuming OAuth2-enabled REST services by wrapping the restc HTTP client and handling automatic re-authentication for expired access tokens. The release supports Client Credentials Grant, Resource Owner Password Credentials Grant, and a specific flow for Microsoft Azure AD. It includes comprehensive documentation with usage examples for standard OAuth2 and Twitter, along with build tooling via rebar3, elvis code style checks, and dependency locking.

(repo-wide) · high confidence

Initial release of the Erlang OAuth 2.0 client library

This change introduces the oauth2c library, providing an Erlang-based OAuth 2.0 client. It supports multiple grant types, including service account JWT tokens (Google) and client credentials (Microsoft Azure), and allows callers to supply custom HTTP transports. The library includes a built-in token cache with configurable TTL to handle token reuse and race conditions, and integrates with OpenTelemetry for distributed tracing.

src · high confidence

New OAuth2 client library header definitions and transport abstraction

The \include/oauth2c.hrl\ file introduces the core data structures and type definitions for the OAuth2 client library. It defines the \\#service\_account\ record for Google service account JWT tokens and the \\#client\ record to manage OAuth2 state, including support for client credentials in the request body. Additionally, it establishes a \request\_fun\ type, allowing callers to supply a custom HTTP transport function for making requests, thereby decoupling the library from a specific HTTP client implementation.

include · high confidence

Test coverage

Added test coverage for OAuth2 client and token cache

Added new Common Test suites (\oauth2c\_SUITE\ and \oauth2c\_token\_cache\_SUITE\) to verify the OAuth2 client's token retrieval, caching, and refresh behaviors. The tests cover client credentials passing (in body vs. header), token caching with expiration, concurrent request handling (burst), and automatic token refresh on 401 responses.

test · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 50 → 50 (+0.8)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 33 → 33 (+0.0)
  • Readiness 59 → 55 (-3.4)
  • Security 61 → 76 (+15.1)

Resolved (4)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1

New (2)

  • Medium CVE: [GHSA redacted] (rebar.lock)
  • Off-boarding risk: anonymized user #1

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kivra/oauth2_client was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d9bd3829b2ab2b2e1e0391b2cc16a7586763557f — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.