Agent skill

Insforge Integrations

by aiskillstore in aiskillstore/marketplace

A skill your agent uses when wiring an external auth provider (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) into InsForge for JWT-based RLS, or when adding the OKX x402 payment facilitator for…

Apache-2.0Auto-check passedBackend & APIs

Install Insforge Integrations

skills CLI
$ npx skills add aiskillstore/marketplace --skill insforge-integrations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace insforge-integrations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/insforge/insforge-integrations .claude/skills/insforge-integrations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
insforge-integrations
GitHub stars
430
Token cost
~1.5k tokens
SKILL.md length
696 words
Files
10 (incl. references)
Skills in repo
1,108
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when wiring an external auth provider (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) into InsForge for JWT-based RLS, or when adding the OKX x402 payment facilitator for…

  • Works in 4 steps: Provider signs or issues a JWT… → JWT is passed to InsForge via… → InsForge exposes claims through… → …
  • Wiring an external auth provider (Clerk
  • SKILL.md covers Auth Providers, Payment Facilitators, Common Patterns and Choosing a Provider, plus 4 more sections
  • Calls npx; needs JWT_SECRET

What it does

Insforge Integrations is an agent skill from aiskillstore/marketplace. Use when wiring an external auth provider (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) into InsForge for JWT-based RLS, or when adding the OKX x402 payment facilitator for onchain pay-per-use billing.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files (for example `agents/openai.yaml`, `references/auth0.md` and `references/better-auth.md`).

It sits in Backend & APIs, covering Authentication. It works with x402, Auth0, WorkOS and Better Auth. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. The licence is Apache-2.0.

When your agent uses it

  • Wiring an external auth provider (Clerk
  • Better Auth) into InsForge for JWT-based RLS
  • Adding the OKX x402 payment facilitator for onchain pay-per-use billing

Example prompts

  • “/insforge-integrations”

Requirements

  • Node.js
  • A credential in JWT_SECRET

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Provider signs or issues a JWT containing the user's ID
  2. JWT is passed to InsForge via accessToken in createClient() (deprecated alias: edgeFunctionToken)
  3. InsForge exposes claims through auth.jwt() in SQL
  4. RLS policies use a requesting_user_id() function to enforce row-level security

What it can do on your machine

Read from SKILL.md and the folder at commit ad8daf7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Insforge Integrations loads about 1.5k tokens when it runs, and up to ~28k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 696 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~28k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aiskillstore/marketplace at commit ad8daf7, republished under its Apache-2.0 licence (© aiskillstore). 696 words, ~1,480 tokens.

Download SKILL.mdSave it as .claude/skills/insforge-integrations/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
insforge-integrations
description
Use when wiring an external auth provider (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) into InsForge for JWT-based RLS, or when adding the OKX x402 payment facilitator for onchain pay-per-use billing.
license
Apache-2.0

InsForge Integrations

This skill covers integrating third-party providers with InsForge. Currently two categories are supported: auth providers (RLS via JWT claims) and payment facilitators (x402 HTTP payment protocol). Each provider has its own guide under this directory.

Auth Providers

ProviderGuideWhen to use
ClerkClerk JWT Templates + InsForge RLSClerk signs tokens directly via JWT Template — no server-side signing needed
Auth0Auth0 Actions + InsForge RLSAuth0 uses a post-login Action to embed claims into the access token
WorkOSWorkOS AuthKit + InsForge RLSWorkOS AuthKit middleware + server-side JWT signing with jsonwebtoken
KindeKinde + InsForge RLSKinde token customization for InsForge integration
StytchStytch + InsForge RLSStytch session tokens for InsForge integration
Better AuthBetter Auth + InsForge RLSSelf-hosted auth running in your InsForge Postgres — no third-party SaaS, no per-MAU cost

Payment Facilitators

ProviderGuideWhen to use
OKX x402OKX as x402 facilitator (USDG on X Layer)Pay-per-use HTTP endpoints settled onchain with zero gas for the payer

Common Patterns

Auth providers
  1. Provider signs or issues a JWT containing the user's ID
  2. JWT is passed to InsForge via accessToken in createClient() (deprecated alias: edgeFunctionToken)
  3. InsForge exposes claims through auth.jwt() in SQL
  4. RLS policies use a requesting_user_id() function to enforce row-level security
Payment facilitators (x402)
  1. Server returns 402 Payment Required with a JSON challenge base64-encoded in PAYMENT-REQUIRED header
  2. Client signs an EIP-3009 authorization using the stablecoin's EIP-712 domain
  3. Server forwards the signed payload to the facilitator's /verify + /settle endpoints
  4. Server records the settled payment in an InsForge table with a realtime trigger for live dashboards

Choosing a Provider

Auth

  • Clerk — Simplest setup; JWT Template handles signing, no server code needed
  • Auth0 — Flexible; uses post-login Actions for claim injection
  • WorkOS — Enterprise-focused; AuthKit middleware + server-side JWT signing
  • Kinde — Developer-friendly; built-in token customization
  • Stytch — API-first; session-based token flow
  • Better Auth — Self-hosted in your Postgres; no SaaS vendor; you own the user table. Pairs cleanly with InsForge's Postgres via a connection string + a small bridge route. Requires a one-time REVOKE after migrate to seal PostgREST exposure.

Payment facilitators

  • OKX x402 — Onchain pay-per-use via USDG on X Layer; zero gas for the payer

Setup

  1. Identify which provider the project uses
  2. Read the corresponding reference guide from the tables above
  3. Follow the provider-specific setup steps

Usage Examples

Each provider guide includes full code examples for:

  • Provider dashboard configuration (API keys, application settings, etc.)
  • Server and client code (JWT utilities for auth; facilitator client + signing utilities for payments)
  • Database setup (RLS for auth; payment table + realtime trigger for payments)
  • Environment variable setup

Refer to the specific references/<provider>.md file for complete examples.

Show full SKILL.md (262 more words)Show less

Best Practices

Auth

  • All auth provider user IDs are strings (not UUIDs) — always use TEXT columns for user_id
  • Use requesting_user_id() instead of auth.uid() for RLS policies
  • Pass the JWT via accessToken — a static string, not a function; for short-lived tokens (Clerk) sync refreshes with client.setAccessToken(token, AuthChangeEvent.TOKEN_REFRESHED) after the initial same-user sign-in
  • Always get the JWT secret via npx -y @insforge/cli secrets get JWT_SECRET

Payment facilitators (x402)

  • Always check the result of the database insert(...) after settlement — settlement takes money onchain before the insert runs; a silent DB failure loses the record
  • Add UNIQUE to the tx_hash column to prevent duplicate records from retries
  • Verify EIP-712 domain (name, version) against the token contract's on-chain DOMAIN_SEPARATOR — wrong values produce Invalid Authority errors
  • Use a MOCK_OKX_FACILITATOR env flag for local dev so the full flow can be exercised without real funds

Common Mistakes

Auth

MistakeSolution
Using auth.uid() for RLSUse requesting_user_id() — third-party IDs are strings, not UUIDs
Using UUID columns for user_idUse TEXT — all supported providers use string-format IDs
Hardcoding the JWT secretAlways retrieve via npx -y @insforge/cli secrets get JWT_SECRET
Missing requesting_user_id() functionMust be created before RLS policies will work

Payments (x402)

MistakeSolution
Using an OKX exchange trading API keyCreate a separate Web3 API key at web3.okx.com/onchainos/dev-portal
Wrong EIP-712 domain valuesRead the token contract's DOMAIN_SEPARATOR — for USDG on X Layer use name: "Global Dollar", version: "1"
Ignoring DB insert error after settlementAlways destructure { error } and log/handle it — money has already moved
MOCK_OKX_FACILITATOR=true in productionMock mode is demo-only; it returns fake tx hashes and bypasses verification

© aiskillstore, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (references) in skills/insforge/insforge-integrations of aiskillstore/marketplace.

  • SKILL.md
  • agents/openai.yaml
  • references/auth0.md
  • references/better-auth.md
  • references/clerk.md
  • references/kinde.md
  • references/okx-x402.md
  • references/stytch.md
  • references/workos.md
  • skill-report.json

Open the folder on GitHubat commit ad8daf7

Compare with similar skills

Insforge Integrations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Insforge Integrations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Insforge Integrations this skillaiskillstore/marketplace430—~1.5kAutomated safety check: PassApache-2.0
Workosusenotra/notra256—~6.2kAutomated safety check: PassAGPL-3.0
Convex Setup Authwaynesutton/markdown-site628—~1.4kAutomated safety check: PassMIT
Lunora Setup Authanolilab/lunora283—~2.8kAutomated safety check: PassCustom licence
Convex Setup Authvvedantb/eva101—~1.5kAutomated safety check: PassMIT
Authvercel/vercel-plugin301—~6.4kAutomated safety check: NotesCustom licence

Similar skills

  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    256 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    waynesutton/markdown-site

    Set up Convex authentication with proper user management, identity mapping, and access control patterns.

    628 GitHub stars~1.4k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Lunora Setup Auth

    anolilab/lunora

    Adds authentication to a Lunora app with the auth registry item (better-auth via @lunora/auth, users and sessions in D1).

    283 GitHub stars~2.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    vvedantb/eva

    Set up Convex authentication with proper user management, identity mapping, and access control patterns.

    101 GitHub stars~1.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Auth

    vercel/vercel-plugin

    Official

    Authentication integration guidance — Clerk (native Vercel Marketplace), Better Auth, Descope, and Auth0 setup for Next.js applications, plus Sign in with Vercel, Vercel Passport, and Vercel KMS.

    301 GitHub stars~6.4k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Convex Auth

    IgorWarzocha/Opencode-Workflows

    Implement Convex authentication and authorization patterns with OIDC providers or Convex Auth.

    122 GitHub stars~744 tokensUpdated 8 mo ago
    Backend & APIsAuto-check passed

More from aiskillstore/marketplace

All 1,108 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 2 repos~697 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 2 repos~598 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Investigating Codebases

    aiskillstore/marketplace

    Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…

    430 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes

Categories

Questions about Insforge Integrations

What does Insforge Integrations do?

A skill your agent uses when wiring an external auth provider (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) into InsForge for JWT-based RLS, or when adding the OKX x402 payment facilitator for…. Insforge Integrations is an agent skill from aiskillstore/marketplace. Use when wiring an external auth provider (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) into InsForge for JWT-based RLS, or when adding the OKX x402 payment facilitator for onchain pay-per-use billing.

When should I use Insforge Integrations?

Insforge Integrations fits situations like: wiring an external auth provider (Clerk; better Auth) into InsForge for JWT-based RLS; adding the OKX x402 payment facilitator for onchain pay-per-use billing.

How do I install Insforge Integrations in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill insforge-integrations -a claude-code`. Or copy the skill folder (skills/insforge/insforge-integrations in aiskillstore/marketplace) into .claude/skills/insforge-integrations in your project. Claude Code loads it when a task matches its description.

How do I install Insforge Integrations in Codex?

Run `npx skills add aiskillstore/marketplace --skill insforge-integrations -a codex`. Or copy the skill folder (skills/insforge/insforge-integrations in aiskillstore/marketplace) into .agents/skills/insforge-integrations in your project. Codex loads it when a task matches its description.

Can I use Insforge Integrations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill insforge-integrations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/insforge-integrations, .gemini/skills/insforge-integrations, .github/skills/insforge-integrations and .opencode/skills/insforge-integrations in your project.

What does Insforge Integrations need to run?

Going by SKILL.md and its folder, Insforge Integrations needs the command-line tools its instructions call (npx) and credentials named JWT_SECRET. Our summary lists: Node.js; A credential in JWT_SECRET.

Does Insforge Integrations access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Insforge Integrations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Insforge Integrations use?

Insforge Integrations is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Insforge Integrations use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 27k tokens, read only when the agent opens those files.

What are the alternatives to Insforge Integrations?

Skills that share tags, products or a category with Insforge Integrations: Workos (usenotra/notra, 256 stars), Convex Setup Auth (waynesutton/markdown-site, 628 stars), Lunora Setup Auth (anolilab/lunora, 283 stars) and Convex Setup Auth (vvedantb/eva, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Insforge Integrations?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,108 skills in this directory. The repository was last updated on October 7, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.