A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys

MITAuto-check passedBackend & APIs

Install Auth Setup

skills CLI
$ npx skills add butterbase-ai/butterbase-skills --skill auth-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install butterbase-ai/butterbase-skills auth-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/butterbase-ai/butterbase-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auth-setup .claude/skills/auth-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auth-setup
GitHub stars
534
Token cost
~2.2k tokens
SKILL.md length
678 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys

  • Works in 7 steps: The role model → Configure an OAuth provider → Tune JWT lifetimes → …
  • Configuring OAuth providers (Google/GitHub/Apple/X/etc.)
  • SKILL.md covers 1. The role model, 2. Configure an OAuth provider, 3. Tune JWT lifetimes and 4. Auth hooks (run code after…, plus 3 more sections
  • Reaches api.butterbase.ai; needs RESEND_API_KEY

What it does

Auth Setup is an agent skill from butterbase-ai/butterbase-skills. Use when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. It works with GitHub. The repository describes itself as: Plugin for Butterbase.ai. The licence is MIT.

When your agent uses it

  • Configuring OAuth providers (Google/GitHub/Apple/X/etc.)
  • Setting up post-login auth hooks
  • Tuning JWT lifetimes
  • Generating service API keys

Example prompts

  • “/auth-setup”

Requirements

  • A credential in RESEND_API_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. The role model
  2. Configure an OAuth provider
  3. Tune JWT lifetimes
  4. Auth hooks (run code after every login)
  5. Service keys (bb_sk_*)
  6. Anti-patterns
  7. Quick reference

What it can do on your machine

Read from SKILL.md and the folder at commit aa8ae69. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript, typescript and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.butterbase.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • RESEND_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auth Setup loads about 2.2k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 678 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from butterbase-ai/butterbase-skills at commit aa8ae69, republished under its MIT licence (© butterbase-ai). 678 words, ~2,155 tokens.

Download SKILL.mdSave it as .claude/skills/auth-setup/SKILL.md (or your agent's skills folder).
name
auth-setup
description
Use when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys

Butterbase Auth Setup

Two umbrella tools cover end-user authentication:

  • manage_oauth — provider configuration (Google, GitHub, Apple, X, custom)
  • manage_auth_config — auth hooks, JWT lifetimes, service key generation

For broad app build-out, see also butterbase-skills:build-app. This skill is the deep dive.


1. The role model

Every request runs under one of three database roles:

Auth headerRolecurrent_user_id()RLS
nonebutterbase_anonNULLenforced; default deny
End-user JWT (issued by manage_oauth or email login)butterbase_useruser UUIDenforced
Service key (bb_sk_*)butterbase_serviceNULLbypassed

Auth is what transforms a request into the right role. RLS is what filters the data. Both must be configured.


2. Configure an OAuth provider

js
manage_oauth({
  app_id: "app_abc123",
  action: "configure",
  provider: "google",
  client_id: "123456789.apps.googleusercontent.com",
  client_secret: "GOCSPX-...",
  redirect_uris: ["https://api.butterbase.ai/auth/app_abc123/oauth/google/callback"]
  // scopes / authorization_url / token_url / userinfo_url / provider_metadata are auto-filled for built-in providers
})

Built-in providers (URLs and scopes pre-filled): google, github, discord, facebook, linkedin, microsoft, apple, x.

Custom providers: pass authorization_url, token_url, userinfo_url, and scopes explicitly.

Redirect URI format
https://api.butterbase.ai/auth/{app_id}/oauth/{provider}/callback

Register this exact URI in the provider's developer console. Mismatch is the most common reason OAuth flows fail.

Provider quirks
ProviderQuirk
appleRequires provider_metadata: { teamId, keyId, privateKey }. Apple only returns the user's name on first auth and uses POST callback (handled automatically).
xDoes not return email. Butterbase synthesises {username}@users.noreply.x.local for the user record.
facebookDefault scopes email, public_profile.
googleStandard.
githubStandard.
List, update, delete
js
manage_oauth({ app_id, action: "get" })                          // list all providers (secrets redacted)
manage_oauth({ app_id, action: "get", provider: "google" })      // single provider
manage_oauth({ app_id, action: "update", provider: "google", client_secret: "new-secret" })
manage_oauth({ app_id, action: "delete", provider: "google" })   // disables future logins; existing sessions valid until expiry
Frontend flow
GET https://api.butterbase.ai/auth/{app_id}/oauth/{provider}?redirect_to=https://yourapp.com/auth/callback

User signs in at the provider, gets bounced back to redirect_to with access_token and refresh_token as query params. The Butterbase SDK wraps this:

ts
await client.auth.signInWithOAuth({ provider: "google" });
const { user, accessToken } = await client.auth.getSession();

3. Tune JWT lifetimes

js
manage_auth_config({
  app_id: "app_abc123",
  action: "update_jwt",
  accessTokenTtl: "15m",       // formats: "15m", "1h", "2h", "1d"
  refreshTokenTtlDays: 30      // integer days
})

Defaults: 15-minute access tokens, 7-day refresh tokens.

Use caseaccessTokenTtlrefreshTokenTtlDays
High-security (banking, admin)5m–15m1–7
Standard SaaS15m (default)30
Low-friction consumer apps1h90

Important: changes apply only to new tokens. Active tokens keep their original expiration — there is no global revoke. Treat TTL changes as forward-looking only.


4. Auth hooks (run code after every login)

A post-auth function is a deployed Butterbase function invoked fire-and-forget after every successful auth event (OAuth login, email login, email signup).

Wire it up
js
// 1. Deploy the function first (see butterbase-skills:function-dev)
deploy_function({
  app_id: "app_abc123",
  name: "after-auth",
  code: postAuthHandlerCode,
  trigger: { type: "http", config: { auth: "none" } }
})

// 2. Register it as the auth hook
manage_auth_config({
  app_id: "app_abc123",
  action: "configure_auth_hook",
  post_auth_function: "after-auth"
})

// To remove the hook later: pass post_auth_function: null

The function must already exist when you configure the hook.

Payload shape

The function receives a POST with this body:

json
{
  "event": "oauth_login | login | signup",
  "user": {
    "id": "uuid",
    "email": "...",
    "provider": "google | github | email | ...",
    "display_name": "...",
    "avatar_url": "..."
  },
  "isNewUser": true,
  "provider": "google"
}

The function runs as butterbase_service (RLS bypassed, ctx.user is null). Use body.user.id to know who just logged in.

Common uses
ts
// after-auth/index.ts
export async function handler(req, ctx) {
  const { user, isNewUser, event } = await req.json();

  if (isNewUser) {
    // 1. Create profile row
    await ctx.db.query(
      "INSERT INTO profiles (user_id, display_name) VALUES ($1, $2) ON CONFLICT DO NOTHING",
      [user.id, user.display_name]
    );

    // 2. Send welcome email (via env-stored API key)
    ctx.waitUntil(sendWelcomeEmail(ctx.env.RESEND_API_KEY, user.email));
  }

  // 3. Audit log on every login
  await ctx.db.query(
    "INSERT INTO login_log (user_id, event, provider) VALUES ($1, $2, $3)",
    [user.id, event, ctx.user ?? null]
  );

  return new Response("ok", { status: 200 });
}

Auth hooks are fire-and-forget. Don't return data the user needs — they won't see it. Use them for side effects only.


5. Service keys (bb_sk_*)

Service keys grant full access to all your apps and bypass RLS. Treat them like passwords.

Generate
js
manage_auth_config({
  action: "generate_service_key",
  name: "CI/CD pipeline"
})
// → { key: "bb_sk_a1b2c3...", key_id, prefix, name, created_at }

The full key is returned once. Store it immediately in your secret manager — you cannot retrieve it again. If you lose it, generate a new one and revoke the old.

Show full SKILL.md (258 more words)Show less
List & revoke
js
manage_api_keys({ action: "list" })
manage_api_keys({ action: "revoke", key_id: "uuid-..." })

list returns metadata only (prefix, name, last_used_at), never the secret. revoke is immediate and irreversible.

Rotation workflow
  1. manage_auth_config (generate_service_key) — create the new key.
  2. Update CI/CD, MCP config, scripts to use the new key.
  3. Verify with a smoke test (e.g. manage_app list).
  4. manage_api_keys (revoke) — kill the old key.

Do steps 1–3 before step 4 to avoid downtime.


6. Anti-patterns

Don'tDo
Hardcode bb_sk_* keys in client code or commit them to gitStore in env vars / secret manager
Reuse one OAuth app between dev, staging, prodSeparate OAuth apps per environment, with their own redirect URIs
Use a service key from frontend code "for convenience"Frontends use end-user JWTs; service keys are server-only
Increase accessTokenTtl to "fix" frequent re-authUse the refresh token; SDK handles this automatically
Forget that manage_oauth delete only stops new loginsExisting sessions remain valid until they expire — rotate JWT keys via support if you need a hard kill
Put critical logic in the auth hookHooks are fire-and-forget. Errors don't surface to the user. Keep them to side effects.
Log the full service key in audit / debug outputLog only the prefix (bb_sk_a1b2c3) — secrets must never appear in logs

7. Quick reference

TaskTool
Add Google OAuthmanage_oauth (configure)
List OAuth providersmanage_oauth (get)
Set post-login hookmanage_auth_config (configure_auth_hook)
Change JWT lifetimesmanage_auth_config (update_jwt)
Create service keymanage_auth_config (generate_service_key)
List service keysmanage_api_keys (list)
Revoke service keymanage_api_keys (revoke)

If a docs/butterbase/00-state.md exists in the working directory, prefer invoking via /butterbase-skills:journey-auth so the journey orchestrator stays in sync.

© butterbase-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/auth-setup of butterbase-ai/butterbase-skills.

Open the folder on GitHubat commit aa8ae69

Compare with similar skills

Auth Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auth Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auth Setup this skillbutterbase-ai/butterbase-skills534—~2.2kAutomated safety check: PassMIT
GitHub OAuth Nango IntegrationAgentWorkforce/relay8661 repos~3.4kAutomated safety check: PassApache-2.0
Atmos Authcloudposse/atmos1.4k—~4.2kAutomated safety check: PassApache-2.0
Nuxt Studiosecondsky/claude-skills227—~2.8kAutomated safety check: PassMIT
OAuthhashgraph-online/awesome-codex-plugins1.2k—~1.1kAutomated safety check: PassApache-2.0
Authaiskillstore/marketplace430—~1.6kAutomated safety check: PassNone

Similar skills

  • GitHub OAuth Nango Integration

    AgentWorkforce/relay

    A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling

    866 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed
  • Atmos Auth

    cloudposse/atmos

    Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

    1.4k GitHub stars~4.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Nuxt Studio

    secondsky/claude-skills

    This skill should be used when the user asks to "set up Nuxt Studio", "configure Studio OAuth", "deploy Studio to Cloudflare", "add visual editor to Nuxt", "configure studio.domain.com subdomain"…

    227 GitHub stars~2.8k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • OAuth

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when a val needs to require login with a Val Town account — gating routes behind authentication, identifying the current user, building user-specific dashboards.

    1.2k GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Auth

    aiskillstore/marketplace

    Authentication and access control skill for Next.js 15 + Supabase applications.

    430 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Admin

    grafana/skills

    Official

    Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

    279 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from butterbase-ai/butterbase-skills

All 39 skills in this repo
  • AI

    butterbase-ai/butterbase-skills

    A skill your agent uses when calling the app's AI gateway from agent tools — chat completions, embeddings, listing models, configuring defaults or BYOK, reading token/cost usage

    534 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Build App

    butterbase-ai/butterbase-skills

    A skill your agent uses when building a new Butterbase app from scratch, creating a full-stack application, or when the user asks to set up a complete backend with database, auth, and deployment

    534 GitHub stars~4.9k tokensUpdated 2 days ago
    Auto-check passed
  • Contributing

    butterbase-ai/butterbase-skills

    A skill your agent uses when contributing to the Butterbase codebase, adding new MCP tools, creating API routes, writing migrations, or understanding the monorepo architecture

    534 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Debug Rls

    butterbase-ai/butterbase-skills

    A skill your agent uses when users report access denied errors, see wrong data, RLS policies are not working, or when troubleshooting Row-Level Security issues in Butterbase

    534 GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed
  • Deploy Frontend

    butterbase-ai/butterbase-skills

    A skill your agent uses when deploying a frontend (React, Next.js, or static HTML) to a live URL on Butterbase, or when troubleshooting deployment issues like MIME type errors or blank pages

    534 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed
  • Durable Objects

    butterbase-ai/butterbase-skills

    A skill your agent uses when building stateful per-key actors — chat rooms, multiplayer rooms, rate limiters, long-running agents, leaderboards — that need persistent in-memory + storage state…

    534 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Auth Setup

What does Auth Setup do?

A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys. Auth Setup is an agent skill from butterbase-ai/butterbase-skills.

When should I use Auth Setup?

Auth Setup fits situations like: configuring OAuth providers (Google/GitHub/Apple/X/etc.); setting up post-login auth hooks; tuning JWT lifetimes; generating service API keys.

How do I install Auth Setup in Claude Code?

Run `npx skills add butterbase-ai/butterbase-skills --skill auth-setup -a claude-code`. Or copy the skill folder (skills/auth-setup in butterbase-ai/butterbase-skills) into .claude/skills/auth-setup in your project. Claude Code loads it when a task matches its description.

How do I install Auth Setup in Codex?

Run `npx skills add butterbase-ai/butterbase-skills --skill auth-setup -a codex`. Or copy the skill folder (skills/auth-setup in butterbase-ai/butterbase-skills) into .agents/skills/auth-setup in your project. Codex loads it when a task matches its description.

Can I use Auth Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add butterbase-ai/butterbase-skills --skill auth-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth-setup, .gemini/skills/auth-setup, .github/skills/auth-setup and .opencode/skills/auth-setup in your project.

What does Auth Setup need to run?

Going by SKILL.md and its folder, Auth Setup needs credentials named RESEND_API_KEY. Our summary lists: A credential in RESEND_API_KEY.

Does Auth Setup access the network?

SKILL.md names 1 domain. In commands or code: api.butterbase.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Auth Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auth Setup use?

Auth Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auth Setup use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auth Setup?

Skills that share tags, products or a category with Auth Setup: GitHub OAuth Nango Integration (AgentWorkforce/relay, 866 stars), Atmos Auth (cloudposse/atmos, 1.4k stars), Nuxt Studio (secondsky/claude-skills, 227 stars) and OAuth (hashgraph-online/awesome-codex-plugins, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auth Setup?

butterbase-ai (a GitHub organization) maintains it in butterbase-ai/butterbase-skills, which has 534 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 5, 2026.

Source: butterbase-ai/butterbase-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.