Skip to content
CAI
Software that uses CAICheck a score

kivra/oauth2

50.5

Adequate · 2 October 2026

1.1k

lines of production code

Erlang

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Erlang library implementing the server-side components of the OAuth 2.0 specification (RFC 6749). It provides a pluggable architecture for handling authentication, token management, and scope verification across various grant types. The codebase includes core modules for token generation and response handling, supported by a comprehensive test suite and mock backends for validation.

Features

Initial release of the Erlang OAuth 2.0 server library

This change introduces the core components of the oauth2\_erlang library, providing a pluggable backend architecture for implementing the server side of OAuth 2.0 (RFC 6749). It adds the \oauth2\_backend\ behavior, which defines callbacks for authenticating users and clients, storing and resolving tokens (access, code, refresh), and verifying scopes and redirection URIs. The release includes a default configuration module (\oauth2\_config\) for managing token expiry and backend selection, a \priv\_set\ module for efficient scope management, and response handling utilities in \oauth2\_response\. Token generation is abstracted via the \oauth2\_token\_generation\ behavior with a default implementation in \oauth2\_token\ using strong random bytes. The main \oauth2\ module exposes API functions for password, client credentials, and authorization code grants, along with token issuance and verification. The package metadata is updated to reflect the new name \oauth2\_erlang\ and version \git\.

src · high confidence

Behavioural changes

Removal of OAuth2 record definition and type declarations

The \include/oauth2.hrl\ header file has been removed, eliminating the \oauth2\ record and \uri()\ type definition from the public API. This change removes the \access\_type\ field from the OAuth2 record structure, aligning the implementation with the standard specification by discarding non-standard API parameters previously used by providers like Google and Facebook.

include · high confidence

Repository modernization and build system migration

The project has been modernized by migrating the build tooling from rebar to rebar3, updating the Makefile to use rebar3 commands for testing and analysis, and adding a .git-blame-ignore-revs file to ignore formatting commits. The rebar.config has been significantly expanded to include Erlang/OTP version-specific platform defines (pre17, pre18), stricter compiler warnings, and a test profile that pins the meck dependency to v1.2.0 and proper to v1.5.0. Additionally, a LICENSE file (MIT) and a comprehensive README.md documenting the library's concepts, configuration, and backend customization have been added.

(repo-wide) · high confidence

Test coverage

Added test suite and mock backend for OAuth 2.0 implementation

Added a comprehensive test suite covering the OAuth 2.0 response handling, token generation, and private set operations, along with a new \oauth2\_mock\_backend\ module to facilitate testing of authentication, client verification, and scope validation flows.

test · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 50 → 50 (+0.0)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 34 → 34 (+0.0)
  • Readiness 57 → 57 (+0.0)
  • Security 70 → 70 (+0.0)

Resolved (3)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)

New (1)

  • Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)

Changes since last survey

  • 2 commits — 2 feature/other, 0 fixes

By area

  • .github/renovate.json5 — 1 commit
  • .github/workflows — 1 commit

Notable commits

  • change: no-release: [PE-7420] allow for merge queues (#118)
  • change: no-release: [PE-7494] increase consistency with renovate/beam (internal) custom manager (#119)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kivra/oauth2 was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b21622ee732995e917b73a1221f4b04c066f010d — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.