← Browse

@aws-samples/setup

B

Set up the OKF MCP plugin — outputs a guide for the user to create their ~/.okf/credentials file with their OAuth2 client id/secret. Use when first enabling the plugin, when headersHelper fails with "Missing credentials", or when the user says "setup okf".

skillclaude

Install

agr install @aws-samples/setup --target claude

Writes 1 file into .claude/skills/, pinned to git-e84d4bc2.

  • .claude/skills/setup/SKILL.md

Document


name: setup description: Set up the OKF MCP plugin — outputs a guide for the user to create their ~/.okf/credentials file with their OAuth2 client id/secret. Use when first enabling the plugin, when headersHelper fails with "Missing credentials", or when the user says "setup okf".

OKF MCP Setup

Outputs a guide for the user to configure the plugin's credentials. The client id and secret are long-lived machine credentials that must NEVER be pasted into the conversation.

When to use

  • First time enabling the okf-mcp plugin
  • When the user says "setup okf", "configure okf credentials", or similar
  • When the headersHelper fails with "Missing credentials"

Steps

  1. Check if ~/.okf/credentials already exists:

    test -f ~/.okf/credentials && echo "exists ($(wc -l < ~/.okf/credentials) lines)" || echo "not found"
    
  2. If it already exists and the user didn't ask to reconfigure, inform them the file is present and suggest running the refresh-okf-mcp-token skill to test it.

  3. Output the following guide as markdown to the user (do NOT ask them to paste secrets into the chat):


OKF MCP Credentials Setup

Create ~/.okf/credentials with your OAuth2 client ID and secret. Run these commands in your terminal (outside of Claude Code) or prefix with ! to run inline:

mkdir -p ~/.okf && chmod 700 ~/.okf
cat > ~/.okf/credentials << 'EOF'
OKF_MCP_CLIENT_ID=<paste your client id here>
OKF_MCP_CLIENT_SECRET=<paste your client secret here>
EOF
chmod 600 ~/.okf/credentials

Replace the <paste ...> placeholders with the real values from when you created the credential in the OKF console.

Where to find your credentials: They were shown once when you created the machine credential in the OKF console. If you've lost them, create a new credential pair in the console.

Verify it works:

python3 "<plugin_root>/scripts/okf-mcp-token.py" headers

This should print a JSON object with an Authorization header. After that, restart Claude Code (or reconnect the MCP via /mcp) for the plugin to pick up the credentials automatically.


  1. After outputting the guide, mention that <plugin_root> should be replaced with the actual CLAUDE_PLUGIN_ROOT path if running manually, or they can just restart the session and the headersHelper will take care of it.

Important

  • NEVER ask the user to paste their client ID or secret into the conversation
  • NEVER write secrets directly — only output the shell commands they can run
  • The credentials file lives at ~/.okf/credentials (outside the repo)
  • The token cache lives at ~/.okf/token-cache.json (auto-managed)

Trustgrade B

  • passBody integrity

    Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.

  • passType matchnot applicable to this artifact type

    Whether the artifact is really the kind of thing its metadata claims it is.

  • passFreshness

    How long since the source repository was last pushed to.

  • passPrompt injection

    Scans the artifact's own text for instructions aimed at your agent rather than at you.

  • warnLicensecopyleft/unknown — index-and-link only

    Whether the source repository declares an SPDX license permissive enough to redistribute.

How the grade is calculated

Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:

  • Aevery check passed
  • Bone warning
  • Ctwo warnings
  • Dprompt injection or body integrity failed, or three warnings
  • Fone of those failed, and something else is wrong

These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.

Versions

  • git-e84d4bc219aa2026-07-31