Agent skill

Team Cert Verification

by awebai in awebai/aweb

A skill your agent uses when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party…

MITAuto-check passedDevelopment

Install Team Cert Verification

skills CLI
$ npx skills add awebai/aweb --skill team-cert-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awebai/aweb team-cert-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .claude/skills && cp -r skills-src/naapp/folio/skills/team-cert-verification .claude/skills/team-cert-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
team-cert-verification
GitHub stars
115
Token cost
~1.8k tokens
SKILL.md length
832 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party…

  • Works in 10 steps: Parse DIDKey auth and timestamp — 401 on… → Decode the team certificate and required… → Read and hash exact request bytes —… → …
  • Reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope
  • SKILL.md covers Envelope contract, Ten verification steps, Subtleties that bite and AWID facts and caching, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Team Cert Verification is an agent skill from awebai/aweb. Use when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party, wiring aw id request --team-auth, or debugging X-AWEB-Signed-Payload and team certificate failures in a new service.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: Communication for AI agents: stable identity, durable mail and chat, and wake-up events across sessions, runtimes, machines, and organizations. MIT, self-hostable. The licence is MIT.

When your agent uses it

  • Reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope
  • Porting folio auth.py
  • Building a BYOT relying party
  • Wiring aw id request --team-auth

Example prompts

  • “/team-cert-verification”

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Parse DIDKey auth and timestamp — 401 on bad Authorization,
  2. Decode the team certificate and required fields — 401 on missing or
  3. Read and hash exact request bytes — store the body bytes and SHA-256.
  4. Require and decode X-AWEB-Signed-Payload — 401 on missing, malformed,
  5. Require v == 2 — 401 on absent or other versions. Why: v1/compact
  6. Bind timestamp, body hash, method, raw path, team id, and audience — 401
  7. Verify the DIDKey signature over decoded signed-payload bytes — 401 on
  8. Resolve AWID team facts — 401 for an invalid/unknown team id; 503 for
  9. Check revocation and verify the certificate signature — 401 if the
  10. Build the principal from the verified certificate — no request-body team

What it can do on your machine

Read from SKILL.md and the folder at commit a6ca92a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are http and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Team Cert Verification loads about 1.8k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 832 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from awebai/aweb at commit a6ca92a, republished under its MIT licence (© awebai). 832 words, ~1,831 tokens.

Download SKILL.mdSave it as .claude/skills/team-cert-verification/SKILL.md (or your agent's skills folder).
name
team-cert-verification
description
Use when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party, wiring aw id request --team-auth, or debugging X-AWEB-Signed-Payload and team certificate failures in a new service.

Team certificate verification

Use this when your service is a BYOT relying party: agents present a DIDKey signature plus an AWID team certificate on every team-scoped request. The code ground truth is src/folio/auth.py; the test ground truth is tests/test_auth_v2_envelope.py. Port both and keep the tests green.

Envelope contract

Every team-scoped request carries four headers:

http
Authorization: DIDKey <did:key:z6Mk...> <base64url-no-padding-ed25519-signature>
X-AWEB-Timestamp: <RFC3339 UTC timestamp>
X-AWID-Team-Certificate: <base64-standard-json-team-certificate>
X-AWEB-Signed-Payload: <base64url-no-padding canonical-JSON of the signed payload>

X-AWEB-Signed-Payload decodes to canonical JSON with these fields:

json
{"aud":"https://<service-origin>","body_sha256":"<sha256 hex of request body>","method":"<UPPER>","path":"<raw path?query>","team_id":"<team>:<namespace>","timestamp":"<RFC3339 UTC timestamp>","v":2}

Rules:

  • The signed-payload header is base64url with no padding (= is rejected in folio; see src/folio/auth.py:137-146).
  • Parsed JSON must round-trip to the same canonical bytes: canonical_json(parsed) == decoded bytes (src/folio/auth.py:188-193).
  • The Ed25519 signature verifies over those decoded presented bytes, not over a payload the server reconstructs (src/folio/auth.py:217-220).

Ten verification steps

Follow this implementation order when porting src/folio/auth.py. The cert is parsed early to obtain team_id for request binding and to compare member_did_key; it is still untrusted data until the AWID-resolved team key verifies its signature and revocation passes.

  1. Parse DIDKey auth and timestamp — 401 on bad Authorization, missing/invalid timestamp, or timestamp outside skew. Why: this selects the request signing key and bounds stale requests.
  2. Decode the team certificate and required fields — 401 on missing or malformed certificate, missing team_id/certificate_id/member_did_key/ alias, or certificate.member_did_key != request did:key. Why: the signed payload's team_id must bind to the presented cert's team, and the cert must name the same member key as the request signer.
  3. Read and hash exact request bytes — store the body bytes and SHA-256. Later return 401 if signed body_sha256 differs. Why: bodyless and bodyful methods use the same rule; tampered bodies fail.
  4. Require and decode X-AWEB-Signed-Payload — 401 on missing, malformed, padded, non-canonical, or non-object payload. Why: the presented canonical bytes are the signed object; accepting alternatives creates ambiguity.
  5. Require v == 2 — 401 on absent or other versions. Why: v1/compact payloads do not bind method/path/audience.
  6. Bind timestamp, body hash, method, raw path, team id, and audience — 401 on mismatch or invalid/disallowed audience. Why: this is what makes a captured signature useless against another endpoint, method, team, body, or host.
  7. Verify the DIDKey signature over decoded signed-payload bytes — 401 on bad signature. Why: the agent must have signed exactly the payload bytes it presented.
  8. Resolve AWID team facts — 401 for an invalid/unknown team id; 503 for unavailable or malformed AWID team-key/revocation facts with no unexpired cache entry. Why: AWID, not the cert, is authority for the team key.
  9. Check revocation and verify the certificate signature — 401 if the certificate_id is revoked or the cert signature fails; 503 if the AWID-resolved team public key is invalid. Why: membership can be removed outside your app, and cert signatures must verify against AWID-resolved authority.
  10. Build the principal from the verified certificate — no request-body team id. Why: all app queries must scope by the certificate's team_id.
Show full SKILL.md (374 more words)Show less

Subtleties that bite

  • Path is raw target, not router path. Use ASGI raw_path plus raw query_string, preserving percent-encoding and query order; include root_path for mounted apps. See src/folio/auth.py:149-173 and tests/test_auth_v2_envelope.py:258-272.
  • Audience canonicalization must match aweb. Use the same origin rules as aweb.team_auth_envelope / awid.log.canonical_server_origin: scheme and host lowercased, default ports removed, no path/query/fragment. See src/folio/auth.py:209-215 and the interop check in tests/test_auth_v2_envelope.py:312-343.
  • Signature verification uses presented bytes. Decode X-AWEB-Signed-Payload, verify those bytes, then compare parsed claims to the actual request. Do not sign or verify a server-reconstructed dictionary.

AWID facts and caching

  • Cache only public AWID facts: team public key and revoked certificate ids (src/folio/auth.py:43-100).
  • If the cache entry is unexpired, use it; if expired, refresh. On refresh failure, fail closed with 503 instead of trusting the presented cert (src/folio/auth.py:58-87).
  • Unknown team is 401; AWID unavailable or missing/invalid team-key facts are 503 (src/folio/auth.py:67-87).
  • Revoked certificate id is 401 (src/folio/auth.py:287-288).
  • Misconfigured public_origin should make every v2 request fail closed. That is a feature: it prevents accepting signatures for the wrong host and exposes deploy misconfiguration immediately.

Anti-patterns

Anti-patternFailure it creates
Verify the cert against its own team_did_key field.Lets a forged cert bring its own authority. Resolve the team key from AWID.
Accept absent version, v1, or compact payloads.Drops method/path/audience binding and enables cross-endpoint replay.
Skip body_sha256 for GET or empty bodies.Creates a second contract and lets body mutation bugs hide. Hash exact bytes always.
Trust the presented cert when AWID is down.Converts an availability incident into an auth bypass. Use unexpired cache or fail closed.
Set clock skew very wide.Expands replay window. Keep the default small (folio default: 300 seconds).
Add API keys, trusted headers, sessions, or OAuth “just for testing.”Creates a second auth path reviewers and users must reason about. Test the real verifier.
Use router-normalized paths.Breaks percent-encoding/query-order binding and disagrees with aw id request --team-auth.
Verify a reconstructed payload.Lets the verifier sign what it wishes it saw, not what the agent actually signed.

References

  • src/folio/auth.py — copyable FastAPI verifier implementation.
  • tests/test_auth_v2_envelope.py — spec by example; port it with the code and keep it green.
  • docs/sot.md Authentication envelope section — product/source-of-truth contract (docs/sot.md:61-126 on main when this skill was written).
  • aweb/docs/vectors/team-auth-envelope-v2.json and aweb/test-vectors/ — byte-for-byte interop fixtures used by the tests.

© awebai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in naapp/folio/skills/team-cert-verification of awebai/aweb.

Open the folder on GitHubat commit a6ca92a

Compare with similar skills

Team Cert Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Team Cert Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Team Cert Verification this skillawebai/aweb115—~1.8kAutomated safety check: PassMIT
Backend Code Reviewlanggenius/dify158k—~676Automated safety check: PassCustom licence
Native Data FetchingCherryHQ/cherry-studio-app4k6 repos~2.9kAutomated safety check: NotesMIT
Twenty App Entity Developmenttwentyhq/twenty58k—~1.8kAutomated safety check: PassCustom licence
Go Pedantrychromedp/chromedp13k—~3.7kAutomated safety check: PassMIT
Gumroad Prod Consoleantiwork/gumroad9.8k—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed
  • Native Data Fetching

    CherryHQ/cherry-studio-app

    A skill your agent uses when implementing or debugging ANY network request, API call, or data fetching.

    4k GitHub starsUsed in 6 repos~2.9k tokens
    DevelopmentAuto-check: notes
  • Guides changes to an existing Twenty app: adding or editing objects, layouts, logic functions and front components, with a plan stated before multi-entity edits.

    58k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Go Pedantry

    chromedp/chromedp

    This skill should be used when the user is writing Go code and needs guidance on Go-specific pedantry: error wrapping with fmt.Errorf and %w, interface design (accept interfaces return structs)…

    13k GitHub stars~3.7k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Gumroad Prod Console

    antiwork/gumroad

    Execute read-only Ruby/Rails commands against Gumroad's production database for debugging and investigation.

    9.8k GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • LangBot Plugin Development

    langbot-app/LangBot

    Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.

    18k GitHub stars~3.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from awebai/aweb

All 17 skills in this repo
  • Recognizes old aweb bootstrap-era `agents/` directories and migrates them to current team and identity primitives, since the old command family is retired.

    115 GitHub stars~701 tokensUpdated today
    Auto-check passed
  • Guides decisions for agents working in an aweb team: when to check shared state, claim tasks, take locks, read team roles and instructions, and open separate worktrees.

    115 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • aweb Messaging

    awebai/aweb

    Guides how an agent reads and responds to aweb mail and chat events, choosing between asynchronous mail and synchronous chat and respecting sender verification and encryption boundaries.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • This skill should be used when joining or being added to an aweb team, picking the correct invite/add-member path for the team's authority model (hosted vs BYOT), accepting invites, fetching team…

    115 GitHub stars~5.4k tokensUpdated today
    Auto-check passed
  • Creates or appends a folio document from the built-in pitch, memo or metrics templates by sending schema-checked slots that folio renders to Markdown.

    115 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Present To Human

    awebai/aweb

    A skill your agent uses when an agent needs to show a human an folio document: mint a document-bound capability link with POST /v1/present, open the returned URL for the human, print it as fallback…

    115 GitHub stars~590 tokensUpdated today
    Auto-check passed

Questions about Team Cert Verification

What does Team Cert Verification do?

A skill your agent uses when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party…. Team Cert Verification is an agent skill from awebai/aweb.py, building a BYOT relying party, wiring aw id request --team-auth, or debugging X-AWEB-Signed-Payload and team certificate failures in a new service.

When should I use Team Cert Verification?

Team Cert Verification fits situations like: reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope; porting folio auth.py; building a BYOT relying party; wiring aw id request --team-auth.

How do I install Team Cert Verification in Claude Code?

Run `npx skills add awebai/aweb --skill team-cert-verification -a claude-code`. Or copy the skill folder (naapp/folio/skills/team-cert-verification in awebai/aweb) into .claude/skills/team-cert-verification in your project. Claude Code loads it when a task matches its description.

How do I install Team Cert Verification in Codex?

Run `npx skills add awebai/aweb --skill team-cert-verification -a codex`. Or copy the skill folder (naapp/folio/skills/team-cert-verification in awebai/aweb) into .agents/skills/team-cert-verification in your project. Codex loads it when a task matches its description.

Can I use Team Cert Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awebai/aweb --skill team-cert-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/team-cert-verification, .gemini/skills/team-cert-verification, .github/skills/team-cert-verification and .opencode/skills/team-cert-verification in your project.

What does Team Cert Verification need to run?

SKILL.md names no scripts, command-line tools or credentials: Team Cert Verification is instructions for the agent only.

Does Team Cert Verification access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Team Cert Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Team Cert Verification use?

Team Cert Verification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Team Cert Verification use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Team Cert Verification?

Skills that share tags, products or a category with Team Cert Verification: Backend Code Review (langgenius/dify, 158k stars), Native Data Fetching (CherryHQ/cherry-studio-app, 4k stars), Twenty App Entity Development (twentyhq/twenty, 58k stars) and Go Pedantry (chromedp/chromedp, 13k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Team Cert Verification?

awebai (a GitHub organization) maintains it in awebai/aweb, which has 115 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.

Source: awebai/aweb on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.