Agent skill

Authentication Patterns

by athola in athola/claude-night-market

Provides auth patterns for API keys, OAuth, and token management.

MITAuto-check passedBackend & APIs

Install Authentication Patterns

skills CLI
$ npx skills add athola/claude-night-market --skill authentication-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market authentication-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/leyline/skills/authentication-patterns .claude/skills/authentication-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authentication-patterns
GitHub stars
342
Token cost
~1.2k tokens
SKILL.md length
244 words
Files
7
Skills in repo
160
Repo updated
First seen
Licence
MIT

At a glance

Provides auth patterns for API keys, OAuth, and token management.

  • Works in 3 steps: Check Environment → Verify with Service → Handle Failures
  • Reviewing service authentication and credential handling
  • SKILL.md covers Overview, When To Use, When NOT To Use and Authentication Methods, plus 6 more sections
  • Runs Shell scripts from its folder; calls gh, glab and aws; needs API_KEY and GEMINI_API_KEY

What it does

Authentication Patterns is an agent skill from athola/claude-night-market. Provides auth patterns for API keys, OAuth, and token management. Use when implementing or reviewing service authentication and credential handling.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files (for example `README.md`, `examples/workflow-integration.md` and `modules/auth-methods.md`).

It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Reviewing service authentication and credential handling
  • Tasks that involve Authentication
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “Use the authentication-patterns skill to provide auth patterns for API keys, OAuth, and token management”
  • “/authentication-patterns”

Requirements

  • Python 3
  • A Bash shell
  • A credential in API_KEY
  • A credential in GEMINI_API_KEY

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Check Environment
  2. Verify with Service
  3. Handle Failures

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • gh
    • glab
    • aws
    • pytest

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, glab and aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • GEMINI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authentication Patterns loads about 1.2k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 244 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 244 words, ~1,180 tokens.

Download SKILL.mdSave it as .claude/skills/authentication-patterns/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
authentication-patterns
description
Provides auth patterns for API keys, OAuth, and token management. Use when implementing or reviewing service authentication and credential handling.
alwaysApply
false
category
infrastructure
tags
authentication, api-keys, oauth, tokens, security
dependencies
error-patterns
provides.infrastructure
authentication, credential-management, auth-verification
provides.patterns
api-key-auth, oauth-flow, token-refresh
usage_patterns
service-authentication, credential-verification, token-management
complexity
beginner
model_hint
fast
estimated_tokens
400

Authentication Patterns

Overview

Common authentication patterns for integrating with external services. Provides consistent approaches to credential management, verification, and error handling.

When To Use

  • Integrating with external APIs
  • Need credential verification
  • Managing multiple auth methods
  • Handling auth failures gracefully

When NOT To Use

  • Project doesn't use the leyline infrastructure patterns
  • Simple scripts without service architecture needs

Authentication Methods

MethodBest ForEnvironment Variable
API KeySimple integrations{SERVICE}_API_KEY
OAuthUser-authenticatedBrowser-based flow
TokenSession-based{SERVICE}_TOKEN
NonePublic APIsN/A

Quick Start

Verify Authentication
python
from leyline.auth import verify_auth, AuthMethod

# API Key verification
status = verify_auth(
    service="gemini", method=AuthMethod.API_KEY, env_var="GEMINI_API_KEY"
)

if not status.authenticated:
    print(f"Auth failed: {status.message}")
    print(f"Action: {status.suggested_action}")

Verification: Run the command with --help flag to verify availability.

Smoke Test
python
def verify_with_smoke_test(service: str) -> bool:
    """Verify auth with simple request."""
    result = execute_simple_request(service, "ping")
    return result.success

Verification: Run pytest -v to verify tests pass.

Standard Flow

Step 1: Check Environment
python
def check_credentials(service: str, env_var: str) -> bool:
    value = os.getenv(env_var)
    if not value:
        print(f"Missing {env_var}")
        return False
    return True

Verification: Run the command with --help flag to verify availability.

Step 2: Verify with Service
python
def verify_with_service(service: str) -> AuthStatus:
    result = subprocess.run([service, "auth", "status"], capture_output=True)
    return AuthStatus(
        authenticated=(result.returncode == 0), message=result.stdout.decode()
    )

Verification: Run the command with --help flag to verify availability.

Step 3: Handle Failures
python
def handle_auth_failure(service: str, method: AuthMethod) -> str:
    actions = {
        AuthMethod.API_KEY: f"Set {service.upper()}_API_KEY environment variable",
        AuthMethod.OAUTH: f"Run '{service} auth login' for browser auth",
        AuthMethod.TOKEN: f"Refresh token with '{service} token refresh'",
    }
    return actions[method]

Verification: Run the command with --help flag to verify availability.

Integration Pattern

yaml
# In your skill's frontmatter
dependencies: [leyline:authentication-patterns]

Verification: Run the command with --help flag to verify availability.

Interactive Authentication (Shell)

For workflows requiring interactive authentication with token caching and session management:

bash
# Source the interactive auth script
source plugins/leyline/scripts/interactive_auth.sh

# Ensure authentication before proceeding
ensure_auth github || exit 1
ensure_auth gitlab || exit 1
ensure_auth aws || exit 1

# Continue with authenticated operations
gh pr view 123
glab issue list
aws s3 ls

Features:

  • ✅ Interactive OAuth flows for GitHub, GitLab, AWS, and more
  • ✅ Token caching (5-minute TTL)
  • ✅ Session persistence (24-hour TTL)
  • ✅ CI/CD compatible (auto-detects non-interactive environments)
  • ✅ Multi-service support

See modules/interactive-auth.md for complete documentation.

Detailed Resources

  • Auth Methods: See modules/auth-methods.md for method details
  • Verification: See modules/verification-patterns.md for testing patterns
  • Interactive: See modules/interactive-auth.md for shell-based auth flows

Exit Criteria

  • Credentials verified or clear failure message
  • Suggested action for auth failures
  • Smoke test confirms working auth

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in plugins/leyline/skills/authentication-patterns of athola/claude-night-market.

  • SKILL.md
  • README.md
  • examples/workflow-integration.md
  • modules/auth-methods.md
  • modules/interactive-auth.md
  • modules/verification-patterns.md
  • tests/test-interactive-auth.sh

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Authentication Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authentication Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authentication Patterns this skillathola/claude-night-market342—~1.2kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
OAuth Account Setupspinabot/brigade11k—~878Automated safety check: PassMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • OAuth Account Setup

    spinabot/brigade

    Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.

    11k GitHub stars~878 tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 9 repos~4.4k tokens
    Backend & APIsAuto-check passed

More from athola/claude-night-market

All 160 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    342 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    342 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    342 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    342 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    342 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    342 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Authentication Patterns

What does Authentication Patterns do?

Provides auth patterns for API keys, OAuth, and token management. Authentication Patterns is an agent skill from athola/claude-night-market. Provides auth patterns for API keys, OAuth, and token management.

When should I use Authentication Patterns?

Authentication Patterns fits situations like: reviewing service authentication and credential handling; tasks that involve Authentication; tasks that involve OAuth and OpenID Connect.

How do I install Authentication Patterns in Claude Code?

Run `npx skills add athola/claude-night-market --skill authentication-patterns -a claude-code`. Or copy the skill folder (plugins/leyline/skills/authentication-patterns in athola/claude-night-market) into .claude/skills/authentication-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Authentication Patterns in Codex?

Run `npx skills add athola/claude-night-market --skill authentication-patterns -a codex`. Or copy the skill folder (plugins/leyline/skills/authentication-patterns in athola/claude-night-market) into .agents/skills/authentication-patterns in your project. Codex loads it when a task matches its description.

Can I use Authentication Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill authentication-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authentication-patterns, .gemini/skills/authentication-patterns, .github/skills/authentication-patterns and .opencode/skills/authentication-patterns in your project.

What does Authentication Patterns need to run?

Going by SKILL.md and its folder, Authentication Patterns needs a shell for the scripts in its folder, the command-line tools its instructions call (gh, glab, aws and pytest) and credentials named API_KEY and GEMINI_API_KEY. Our summary lists: Python 3; A Bash shell; A credential in API_KEY; A credential in GEMINI_API_KEY.

Does Authentication Patterns access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Authentication Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authentication Patterns use?

Authentication Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authentication Patterns use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authentication Patterns?

Skills that share tags, products or a category with Authentication Patterns: Fortify Development (coollabsio/coolify, 63k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Security Review (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authentication Patterns?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 342 GitHub stars. The repository holds 160 skills in this directory. The repository was last updated on October 6, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.