Skip to content
CAI
Software that uses CAICheck a score

ueberauth/oauth2

52.0

Adequate · 3 October 2026

1.3k

lines of production code

Elixir

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Elixir library that implements the OAuth 2.0 protocol to manage authentication flows. It provides a modular architecture with dedicated strategies for Auth Code, Client Credentials, Refresh, and Password grants, allowing users to handle token acquisition and management. The library leverages Tesla for HTTP requests and supports custom serializers and middleware for flexible integration with various OAuth providers.

Features

Add OAuth2 strategies for Auth Code, Client Credentials, Refresh, and Password grants

The library now includes four new OAuth2 strategy implementations: Auth Code, Client Credentials, Refresh, and Password. The Auth Code strategy handles the standard authorization flow, including the required response\_type parameter and redirect URI. The Client Credentials strategy supports both header and request body authentication schemes. The Refresh strategy allows exchanging refresh tokens for new access tokens, and the Password strategy enables direct username/password authentication. Each strategy implements the necessary authorize\_url and get\_token functions according to the OAuth 2.0 specification.

lib/oauth2/strategy · high confidence

Initial project scaffolding and configuration

The repository has been initialized with essential configuration files for the Elixir project, including \.credo.exs\ for code linting, \.formatter.exs\ for code formatting, and \.tool-versions\ specifying Elixir 1.19.5 and Erlang 28.5. A comprehensive \CHANGELOG.md\ documents the library's history up to v2.1.0, noting the migration from Hackney to Tesla as the default HTTP client. The \README.md\ has been updated to reflect current usage, including installation instructions, serializer configuration, and examples for OAuth2 strategies.

(repo-wide) · high confidence

Behavioural changes

Added placeholder for PLT files

A new .gitkeep file has been added to the priv/plts directory. This ensures the directory is tracked by version control, likely to support the storage or generation of Persistent Library Tables (PLTs) used by tools like Dialyzer, although no actual PLT files or configuration changes are present in this change.

priv · low confidence

Configuration modernized and OAuth2 credentials added

The application configuration has been migrated from the legacy format to the modern \import Config\ syntax, enabling environment-specific settings. Additionally, default OAuth2 client credentials (client ID and secret) and a redirect URI are now explicitly defined in the main config file, and the test environment is configured to use the Hackney adapter for HTTP requests.

config · high confidence

OAuth2 library refactored to use Tesla HTTP client and modular strategy architecture

The OAuth2 library has been significantly restructured to replace the underlying HTTP client (previously hackney/HTTPoison) with Tesla, allowing users to configure custom adapters and middleware via application environment. The architecture is now modular, introducing dedicated modules for \AccessToken\, \Request\, \Response\, \Error\, \Serializer\, and \Strategy\, which standardizes how tokens are parsed, requests are built, and responses are decoded. Users can now define custom serializers for encoding/decoding bodies and implement custom OAuth2 strategies by implementing the \OAuth2.Strategy\ behavior, providing greater flexibility in handling different OAuth2 provider quirks and content types.

lib/oauth2 · high confidence

OAuth2 library restructured from OTP application to module-based library

The OAuth2 library has been refactored from an OTP application with a supervisor into a pure module-based library. The \lib/oauth2.ex\ file no longer implements the \Application\ behavior or defines a supervisor tree, removing the automatic startup process. Instead, it now serves as the main documentation entry point, providing usage examples for the \OAuth2.Client\ and \OAuth2.Strategy\ modules. This change simplifies the library's footprint, requiring users to interact directly with client and strategy modules rather than relying on application-level supervision.

lib · high confidence

Test coverage

Added test coverage for OAuth2 strategies; Added test helper module for OAuth2 client testing; Added unit tests for OAuth2 core components; Expanded OAuth2 client configuration tests and test environment setup.

Dependencies

OAuth2 library upgraded to v2.1.1 with modern Elixir and dependency stack

The OAuth2 client library has been updated to version 2.1.1, requiring Elixir 1.2 or later. The HTTP client backend has shifted from the legacy \hackney\/\httpoison\ stack to \tesla\ (v1.18), which brings support for modern HTTP features and improved security via updated underlying dependencies like \hackney\ (v4.1) and \certifi\. Development tooling has also been modernized, adding \credo\ for static analysis, \dialyxir\ for type checking, and \excoveralls\ for test coverage reporting, while the project structure has been cleaned up to remove the application callback and use standard Hex package metadata.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 50 → 52 (+1.8)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 46 → 46 (+0.0)
  • Readiness 38 → 41 (+3.2)
  • Security 77 → 80 (+3.1)

Resolved (3)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)

New (1)

  • High CVE: [GHSA redacted] (mix.lock)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ueberauth/oauth2 was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fefc41585c1882282041c77138862b910a405520 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-8fe32cd45d00.