Fortify Development
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
JWT authentication implementation patterns. An agent skill from cohen-liel/hivemind.
$ npx skills add cohen-liel/hivemind --skill jwt-authentication -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cohen-liel/hivemind jwt-authentication --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cohen-liel/hivemind.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/jwt-authentication .claude/skills/jwt-authentication && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "jwt-authentication" agent skill from https://github.com/cohen-liel/hivemind/tree/main/.claude/skills/jwt-authentication into .claude/skills/jwt-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jwt-authentication", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cohen-liel/hivemind/tree/main/.claude/skills/jwt-authenticationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cohen-liel/hivemind --skill jwt-authentication -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cohen-liel/hivemind jwt-authentication --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cohen-liel/hivemind.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/jwt-authentication .agents/skills/jwt-authentication && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "jwt-authentication" agent skill from https://github.com/cohen-liel/hivemind/tree/main/.claude/skills/jwt-authentication into .agents/skills/jwt-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jwt-authentication", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cohen-liel/hivemind --skill jwt-authentication -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cohen-liel/hivemind jwt-authentication --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cohen-liel/hivemind.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/jwt-authentication .cursor/skills/jwt-authentication && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "jwt-authentication" agent skill from https://github.com/cohen-liel/hivemind/tree/main/.claude/skills/jwt-authentication into .cursor/skills/jwt-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jwt-authentication", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cohen-liel/hivemind.git --path .claude/skills/jwt-authentication--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cohen-liel/hivemind --skill jwt-authentication -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cohen-liel/hivemind jwt-authentication --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cohen-liel/hivemind.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/jwt-authentication .gemini/skills/jwt-authentication && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "jwt-authentication" agent skill from https://github.com/cohen-liel/hivemind/tree/main/.claude/skills/jwt-authentication into .gemini/skills/jwt-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jwt-authentication", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cohen-liel/hivemind jwt-authenticationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cohen-liel/hivemind --skill jwt-authentication -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cohen-liel/hivemind.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/jwt-authentication .github/skills/jwt-authentication && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "jwt-authentication" agent skill from https://github.com/cohen-liel/hivemind/tree/main/.claude/skills/jwt-authentication into .github/skills/jwt-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jwt-authentication", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cohen-liel/hivemind --skill jwt-authentication -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cohen-liel/hivemind jwt-authentication --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cohen-liel/hivemind.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/jwt-authentication .opencode/skills/jwt-authentication && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "jwt-authentication" agent skill from https://github.com/cohen-liel/hivemind/tree/main/.claude/skills/jwt-authentication into .opencode/skills/jwt-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jwt-authentication", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
jwt-authenticationJWT authentication implementation patterns. An agent skill from cohen-liel/hivemind.
JWT Authentication is an agent skill from cohen-liel/hivemind. JWT authentication implementation patterns. Use when implementing login, registration, token refresh, password reset, or any authentication/authorization system.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication. The repository describes itself as: One prompt. A full AI engineering team. Go lie on the couch. 🧠. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 918dd9b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
JWT Authentication loads about 1.1k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 95 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cohen-liel/hivemind at commit 918dd9b, republished under its Apache-2.0 licence (© cohen-liel). 95 words, ~1,144 tokens.
.claude/skills/jwt-authentication/SKILL.md (or your agent's skills folder).# auth/tokens.py
from datetime import datetime, timedelta
from jose import JWTError, jwt
from passlib.context import CryptContext
SECRET_KEY = settings.SECRET_KEY # 32+ char random string from env
ALGORITHM = "HS256"
ACCESS_TOKEN_EXPIRE = timedelta(minutes=15)
REFRESH_TOKEN_EXPIRE = timedelta(days=7)
pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto")
def hash_password(password: str) -> str:
return pwd_context.hash(password)
def verify_password(plain: str, hashed: str) -> bool:
return pwd_context.verify(plain, hashed)
def create_access_token(user_id: int) -> str:
return jwt.encode(
{"sub": str(user_id), "exp": datetime.utcnow() + ACCESS_TOKEN_EXPIRE, "type": "access"},
SECRET_KEY, algorithm=ALGORITHM
)
def create_refresh_token(user_id: int) -> str:
return jwt.encode(
{"sub": str(user_id), "exp": datetime.utcnow() + REFRESH_TOKEN_EXPIRE, "type": "refresh"},
SECRET_KEY, algorithm=ALGORITHM
)
def decode_token(token: str) -> dict:
try:
payload = jwt.decode(token, SECRET_KEY, algorithms=[ALGORITHM])
return payload
except JWTError:
raise HTTPException(status_code=401, detail="Invalid or expired token")@router.post("/login", response_model=TokenResponse)
async def login(form: OAuth2PasswordRequestForm = Depends(), db: AsyncSession = Depends(get_db)):
user = await get_user_by_email(db, form.username)
if not user or not verify_password(form.password, user.hashed_password):
# Same error for both cases — don't reveal which field was wrong
raise HTTPException(status_code=401, detail="Invalid credentials")
# Rate limit check (use Redis counter)
await check_login_rate_limit(user.id)
access_token = create_access_token(user.id)
refresh_token = create_refresh_token(user.id)
# Store refresh token hash in DB for revocation
await store_refresh_token(db, user.id, refresh_token)
response = JSONResponse({"access_token": access_token, "token_type": "bearer"})
response.set_cookie("refresh_token", refresh_token, httponly=True, secure=True, samesite="lax")
return responseoauth2_scheme = OAuth2PasswordBearer(tokenUrl="/auth/login")
async def get_current_user(
token: str = Depends(oauth2_scheme),
db: AsyncSession = Depends(get_db)
) -> User:
payload = decode_token(token)
if payload.get("type") != "access":
raise HTTPException(status_code=401, detail="Invalid token type")
user = await db.get(User, int(payload["sub"]))
if not user or user.is_disabled:
raise HTTPException(status_code=401, detail="User not found or disabled")
return user@router.post("/refresh")
async def refresh(request: Request, db: AsyncSession = Depends(get_db)):
refresh_token = request.cookies.get("refresh_token")
if not refresh_token:
raise HTTPException(status_code=401, detail="No refresh token")
payload = decode_token(refresh_token)
# Verify token exists in DB (revocation check)
stored = await get_refresh_token(db, refresh_token)
if not stored:
raise HTTPException(status_code=401, detail="Token revoked")
# Rotate: delete old, issue new
await delete_refresh_token(db, refresh_token)
new_access = create_access_token(int(payload["sub"]))
new_refresh = create_refresh_token(int(payload["sub"]))
await store_refresh_token(db, int(payload["sub"]), new_refresh)
response = JSONResponse({"access_token": new_access})
response.set_cookie("refresh_token", new_refresh, httponly=True, secure=True, samesite="lax")
return response© cohen-liel, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/jwt-authentication of cohen-liel/hivemind.
Open the folder on GitHubat commit 918dd9b
JWT Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| JWT Authentication this skillcohen-liel/hivemind | 110 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Gitnexus Exploringaws-samples/sample-kolya-br-proxy | 106 | 12 repos | ~749 | Automated safety check: Pass | MIT-0 | |
| Supabasecurvenote/curvenote | 170 | 5 repos | ~2.2k | Automated safety check: Pass | Custom licence |
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
aws-samples/sample-kolya-br-proxy
A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
google-gemini/gemini-skills
A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.
cohen-liel/hivemind
REST API design principles and best practices. An agent skill from cohen-liel/hivemind.
cohen-liel/hivemind
Python asyncio patterns for high-performance async code. An agent skill from cohen-liel/hivemind.
cohen-liel/hivemind
Celery background task patterns for Python apps. An agent skill from cohen-liel/hivemind.
cohen-liel/hivemind
Docker, docker-compose, and deployment configuration best practices.
cohen-liel/hivemind
End-to-end testing patterns with Playwright. An agent skill from cohen-liel/hivemind.
cohen-liel/hivemind
Email sending patterns for transactional and marketing emails.
Categories
JWT authentication implementation patterns. An agent skill from cohen-liel/hivemind. JWT Authentication is an agent skill from cohen-liel/hivemind. JWT authentication implementation patterns.
JWT Authentication fits situations like: implementing login; any authentication/authorization system.
Run `npx skills add cohen-liel/hivemind --skill jwt-authentication -a claude-code`. Or copy the skill folder (.claude/skills/jwt-authentication in cohen-liel/hivemind) into .claude/skills/jwt-authentication in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cohen-liel/hivemind --skill jwt-authentication -a codex`. Or copy the skill folder (.claude/skills/jwt-authentication in cohen-liel/hivemind) into .agents/skills/jwt-authentication in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cohen-liel/hivemind --skill jwt-authentication -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jwt-authentication, .gemini/skills/jwt-authentication, .github/skills/jwt-authentication and .opencode/skills/jwt-authentication in your project.
Going by SKILL.md and its folder, JWT Authentication needs credentials named SECRET_KEY. Our summary lists: Python 3; A credential in SECRET_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
JWT Authentication is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with JWT Authentication: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Gitnexus Exploring (aws-samples/sample-kolya-br-proxy, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cohen-liel (a GitHub user) maintains it in cohen-liel/hivemind, which has 110 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on April 18, 2026.
Source: cohen-liel/hivemind on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.