007
無料Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Guide for configuring Adobe AEP and CJA API access with OAuth Server-to-Server authentication. Use when setting up API credentials or troubleshooting OAuth errors (401/403).
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
This skill provides guidance on configuring Adobe Experience Platform (AEP) and Customer Journey Analytics (CJA) API access for projects using OAuth Server-to-Server authentication.
Invoke this skill when:
Before using Adobe CJA/AEP APIs, ensure:
CJA Integration, AEP Data Pipeline)Critical: The Adobe Experience Platform API must be added to your project even if you're only using CJA. This associates your service account with an Experience Platform product profile, which is required for CJA API authentication.
Your project should now show two APIs configured:
Both APIs share the same OAuth credentials (Client ID and Secret).
Collect these four values from Adobe Developer Console:
| Credential | Location | Format Example |
|---|---|---|
| Organization ID | Top-right of console, or Project Overview | ABC123DEF456@AdobeOrg |
| Client ID | OAuth Server-to-Server > Credentials | cm1234567890abcdef... |
| Client Secret | Click "Retrieve client secret" | p8e-XXXXXXXXXXXX... |
| Scopes | OAuth Server-to-Server > Scopes | Space-separated scope URIs |
Security: Never commit credentials to version control. Use environment variables, secrets managers, or gitignored configuration files.
{
"org_id": "ABC123DEF456@AdobeOrg",
"client_id": "1234567890abcdef1234567890abcdef",
"secret": "p8e-XXX...",
"scopes": "your_scopes_from_developer_console"
}
Best for: Local development, single organization
Important: Add config.json to .gitignore
export ORG_ID="ABC123DEF456@AdobeOrg"
export CLIENT_ID="1234567890abcdef1234567890abcdef"
export SECRET="p8e-XXX..."
export SCOPES="your_scopes_from_developer_console"
Best for: CI/CD pipelines, Docker containers, cloud deployments
# .env file (requires python-dotenv)
ORG_ID=ABC123DEF456@AdobeOrg
CLIENT_ID=1234567890abcdef1234567890abcdef
SECRET=p8e-XXX...
SCOPES=your_scopes_from_developer_console
Best for: Local development with environment variable pattern
OAuth scopes define what permissions the API client has. Copy the exact scopes string from Adobe Developer Console.
| API | Typical Scopes |
|---|---|
| CJA Read | openid, AdobeID, read_organizations, additional_info.projectedProductContext |
| CJA + AEP | Above plus AEP-specific scopes from your project |
Important: Copy scopes exactly as shown in Developer Console. Incorrect or missing scopes cause
invalid_scopeorinsufficient_scopeerrors.
Users and service accounts need appropriate CJA product profiles:
| Profile Type | Permissions |
|---|---|
| Data View Access | Read access to specific Data Views |
| Component Access | Access to metrics, dimensions, segments, calculated metrics |
| Admin | Full access including configuration |
Even for CJA-only projects, an AEP product profile association is required:
OAuth response: {"error": "invalid_client", "error_description": "..."}
Causes:
Solutions:
OAuth response: {"error": "invalid_scope", "error_description": "..."}
Causes:
Solutions:
OAuth response: {"error": "unauthorized_client", "error_description": "..."}
Causes:
Solutions:
ERROR - 403 Forbidden
ERROR - Failed to fetch data: 403
Causes:
Solutions:
ERROR - 401 Unauthorized
ERROR - Authentication failed
Causes:
Solutions:
config.json, .env, and credential files to .gitignore# Adobe API credentials
config.json
.env
# Credential directories
.cja/
credentials/
{
"org_id": "YOUR_ORG_ID@AdobeOrg",
"client_id": "YOUR_CLIENT_ID",
"secret": "YOUR_CLIENT_SECRET",
"scopes": "your_scopes_from_developer_console"
}
| Resource | URL |
|---|---|
| Adobe Developer Console | https://developer.adobe.com/console/ |
| Adobe Admin Console | https://adminconsole.adobe.com/ |
| CJA API Documentation | https://developer.adobe.com/cja-apis/docs/ |
| AEP API Documentation | https://developer.adobe.com/experience-platform-apis/ |
When authentication fails, verify:
@AdobeOrgまだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).
日本語の概要は準備中です。原文の説明を表示しています。
You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.
日本語の概要は準備中です。原文の説明を表示しています。
Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。