Self-hosted Zitadel v4 OIDC field guide — 43 documented quirks + working docker-compose, idempotent TypeScript bootstrap, and reset script. High-friction traps: FirstInstance env placement, JWT/JWKS over self-signed HTTPS, TLS-terminating reverse proxy (--tlsMode external) and the admin-console Failed to fetch mixed-content trap, Login UI v1/v2, v2.66→v4 upgrade, API v1→v2 mapping, silent-renew, 401-storm defenses, smoke-e2e CI. Triggers — zitadel, oidc self-hosted, silent-renew, JWKS, masterkey, v2.66→v4, api v1→v2, login-ui-v2, tlsMode external, console Failed to fetch, mixed content, smoke-e2e CI, Playwright self-signed Zitadel.
$npx -y skills add j0ruge/skills_commands_manager --skill zitadel-idpInstalls into the current project.
Run `npx skills use "https://github.com/j0ruge/skills_commands_manager" --skill "j0ruge/skills_commands_manager/zitadel-idp"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/j0ruge/skills_commands_manager" that are relevant to the current task. Run `npx skills add "https://github.com/j0ruge/skills_commands_manager"` and select the relevant skills, then follow their instructions.