Agent skill

Authentication

by BuilderIO in BuilderIO/agent-native

How auth works in agent-native apps. An agent skill from BuilderIO/agent-native.

No licenceAuto-check: notesBackend & APIs

Install Authentication

skills CLI
$ npx skills add BuilderIO/agent-native --skill authentication -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BuilderIO/agent-native authentication --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BuilderIO/agent-native.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/authentication .claude/skills/authentication && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authentication
GitHub stars
7.1k
Token cost
~6.8k tokens
SKILL.md length
3,427 words
Files
1
Skills in repo
102
Repo updated
First seen
Licence
None found

At a glance

How auth works in agent-native apps. An agent skill from BuilderIO/agent-native.

  • Wiring login/signup
  • SKILL.md covers Rule, Auth Modes, Hosted Sign-In Pages and the… and Remote MCP OAuth, plus 10 more sections
  • Calls pnpm and npx; reaches dispatch.agent-native.com; needs A2A_SECRET and ACCESS_TOKEN
  • Configuring auth modes

What it does

Authentication is an agent skill from BuilderIO/agent-native. How auth works in agent-native apps. Use when wiring login/signup, configuring auth modes, setting up organizations, protecting routes, or debugging session issues.

Its SKILL.md is about 6.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with Better Auth. The repository describes itself as: A framework for building agentic apps.

When your agent uses it

  • Wiring login/signup
  • Configuring auth modes
  • Setting up organizations
  • Protecting routes

Example prompts

  • “/authentication”

Requirements

  • Node.js
  • A credential in ACCESS_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit e16da0c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • dispatch.agent-native.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • A2A_SECRET
    • ACCESS_TOKEN
    • AGENT_NATIVE_IDENTITY_FEDERATION_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authentication loads about 6.8k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 3,427 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:303
    d persist shared browser credentials in `.env`. Agents then use the built-in `get-browser-connection` tool to provision

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 3,427 words (~6,813 tokens).

“Auth is powered by Better Auth with account-first design. Every new user creates an account on first visit. Use getSession(event) to authenticate custom routes; actions are auto-protected. Normal app HTML and React Router page-data responses are one impersonal, public-cacheable shell…”

— opening of SKILL.md by BuilderIO
name
authentication
scope
dev
metadata.internal
true

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/authentication of BuilderIO/agent-native.

Open the folder on GitHubat commit e16da0c

Compare with similar skills

Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authentication compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authentication this skillBuilderIO/agent-native7.1k—~6.8kAutomated safety check: NotesNone
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Neon Authneondatabase/agent-skills100—~3.1kAutomated safety check: PassApache-2.0
Email And Password Best Practicesever-works/ever-works1583 repos~1.5kAutomated safety check: PassAGPL-3.0
Two Factor Authentication Best Practicesever-works/ever-works1582 repos~1.8kAutomated safety check: PassAGPL-3.0
Workosusenotra/notra256—~6.2kAutomated safety check: PassAGPL-3.0

Similar skills

  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Neon Auth

    neondatabase/agent-skills

    Official

    Add authentication to a new app. An agent skill from neondatabase/agent-skills.

    100 GitHub stars~3.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Configure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication.

    158 GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.

    158 GitHub starsUsed in 2 repos~1.8k tokens
    Backend & APIsAuto-check passed
  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    256 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Lunora Setup Auth

    anolilab/lunora

    Adds authentication to a Lunora app with the auth registry item (better-auth via @lunora/auth, users and sessions in D1).

    283 GitHub stars~2.8k tokensUpdated today
    Backend & APIsAuto-check passed

More from BuilderIO/agent-native

All 102 skills in this repo
  • Actions

    BuilderIO/agent-native

    How to create and run agent actions. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Client Methods

    BuilderIO/agent-native

    Client method surface rules. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Adding A Feature

    BuilderIO/agent-native

    The four-area checklist every new feature must complete. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Address Feedback

    BuilderIO/agent-native

    Triage feedback from docs, issues, Slack threads, or pasted notes into verified bugs, UX proposals, unclear questions, and skipped noise.

    7.1k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Audit Log

    BuilderIO/agent-native

    Durable, access-scoped, append-only record of who changed what app data, when, and whether it was the agent or a human.

    7.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Automations

    BuilderIO/agent-native

    Event-triggered and schedule-triggered automations with natural-language conditions.

    7.1k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Works with

Questions about Authentication

What does Authentication do?

How auth works in agent-native apps. An agent skill from BuilderIO/agent-native. Authentication is an agent skill from BuilderIO/agent-native. How auth works in agent-native apps.

When should I use Authentication?

Authentication fits situations like: wiring login/signup; configuring auth modes; setting up organizations; protecting routes.

How do I install Authentication in Claude Code?

Run `npx skills add BuilderIO/agent-native --skill authentication -a claude-code`. Or copy the skill folder (.agents/skills/authentication in BuilderIO/agent-native) into .claude/skills/authentication in your project. Claude Code loads it when a task matches its description.

How do I install Authentication in Codex?

Run `npx skills add BuilderIO/agent-native --skill authentication -a codex`. Or copy the skill folder (.agents/skills/authentication in BuilderIO/agent-native) into .agents/skills/authentication in your project. Codex loads it when a task matches its description.

Can I use Authentication in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BuilderIO/agent-native --skill authentication -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authentication, .gemini/skills/authentication, .github/skills/authentication and .opencode/skills/authentication in your project.

What does Authentication need to run?

Going by SKILL.md and its folder, Authentication needs the command-line tools its instructions call (pnpm and npx) and credentials named A2A_SECRET, ACCESS_TOKEN and AGENT_NATIVE_IDENTITY_FEDERATION_SECRET. Our summary lists: Node.js; A credential in ACCESS_TOKEN.

Does Authentication access the network?

SKILL.md names 1 domain. In commands or code: dispatch.agent-native.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Authentication safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Authentication use?

No licence was found for Authentication or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Authentication use?

About 6.8k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authentication?

Skills that share tags, products or a category with Authentication: Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Neon Auth (neondatabase/agent-skills, 100 stars), Email And Password Best Practices (ever-works/ever-works, 158 stars) and Two Factor Authentication Best Practices (ever-works/ever-works, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authentication?

BuilderIO (a GitHub organization) maintains it in BuilderIO/agent-native, which has 7,087 GitHub stars. The repository holds 102 skills in this directory. The repository was last updated on October 8, 2026.

Source: BuilderIO/agent-native on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.