Loading...
Loading...
Found 5 Skills
Use when the user asks about IdP integration, SCIM provisioning, security policies, device trust, groups, users, or access control in Twingate. Activate for: SAML, SCIM, Okta, Entra ID, Google Workspace, JumpCloud, OneLogin, Keycloak, device trust, device posture, MFA enforcement, groups, JIT access, ephemeral access, auto-lock, offboarding, deprovisioning, multi-IdP deployments, or security policy configuration. Also activate for identity automation tooling: automating device trust from an MDM or EDR inventory (Jamf, Kandji, Intune, CrowdStrike, SentinelOne, FleetDM, Automox, JumpCloud, Mosyle, Datto RMM), migrating group access between IdPs, self-service or Slack-based group access requests, and location-based group switching.
Use when the user needs to deploy, configure, upgrade, or troubleshoot Twingate Connectors on any platform. Activate for: Docker connector, Linux connector, systemd connector, ECS connector, Azure Container Instances, GCE, Helm chart connector, connector tokens, connector HA, connector health, connector metrics, connector logging, connector upgrades, DEAD_NO_RELAYS, DEAD_NO_HEARTBEAT, or connector placement questions. Also activate for connector deployment tooling and unofficial platform support: Raspberry Pi, Ubiquiti/UniFi (UDM Pro, UDM SE, UXG) gateways, Unraid, Home Assistant, Steam Deck / Decky Loader, Hyper-V, Chocolatey packaging, custom or hardened connector containers, GitHub Codespaces, Coder workspaces, render.com, Spacelift CI runners, connector log shipping to S3, connector fleet autoscaling, Grafana connector dashboards, PagerDuty connector alerting, or Docker container auto-updating for connector hosts.
Use when the user asks how Twingate works, wants to design or evaluate a Twingate deployment, needs to understand components (Controller, Client, Connector, Relay), or is planning a ZTNA rollout. Activate for: zero trust, ZTNA, remote access architecture, network design with Twingate, VPN replacement, microsegmentation, split DNS, NAT traversal, P2P vs Relay, Remote Network topology, Resource definition strategy, or deployment sequencing. Also activate for community/reference deployment patterns: exposing a self-hosted AI chat assistant (OpenClaw, WhatsApp/Telegram bots) with no public inbound ports, private Railway/PaaS app deployment with zero-ingress, or "what does the twingate-assistant plugin itself do" meta-questions.
Use when the user reports connectivity issues, access failures, DNS resolution problems, or any error with Twingate. Activate for: "can't connect", "not working", "resource not found", "access denied", DEAD connector, DNS not resolving, device trust blocking access, security policy issues, P2P failure, or any Twingate troubleshooting or diagnostic request. Also activate for symptom-shaped and error-string queries: exact client error text ("unknown network name", "too many open files", "setup wizard ended prematurely", "unable to join network"), OS-specific client bugs on Windows, macOS, Linux (Fedora, Ubuntu, NixOS), ChromeOS, or Android Auto; client crashes, freezes, or unresponsiveness; version-specific regressions (e.g. a specific client build number misbehaving); TAP adapter or virtual network adapter issues; device posture / screen lock / disk encryption check failures; third-party AV, EDR, VPN, or DNS-filtering software conflicts (CrowdStrike, Zscaler, Elastic AV, Avast, consumer VPNs); packet capture, system report, or client/connector log collection; and engaging or escalating to Twingate technical support.
Use for the Twingate Identity Firewall (IDFW) and the Twingate Gateway — protocol-level identity enforcement for SSH, the Kubernetes API, AND self-hosted/internal web apps, not just network-level access. LOAD whenever the user wants to grant, secure, SSO into, or audit access to a self-hosted or internal web application — including forwarding or injecting the logged-in user's identity into HTTP requests, or a per-user/request-level audit trail of who accessed an app. This is the Gateway acting as a Layer 7 reverse proxy that injects signed ES256 JWTs (Gateway Access Tokens) or trusted headers into web apps: JWKS verification, request-header injection, framework middleware (Express, Django, Next.js, Auth.js), and no-code SSO integrations (Grafana, Jenkins). Also use when the user deploys the Gateway; configures SSH privileged access with short-lived certificates; manages privileged / vendor / contractor access; configures Certificate Authorities (X.509 or SSH CA, local or HashiCorp Vault); routes kubectl through the Gateway; automates IDFW with Terraform or Ansible; or implements/reviews session recording (asciicast/.cast playback and archival, scanning recorded SSH or kubectl sessions for dangerous commands or leaked secrets, self-hosting a recording browse UI). If a question is about identity-aware access to an app or host — "can Twingate pass the user's identity to my app?", "audit who used this app", "SSO for my internal tool" — assume this skill is relevant and load it.