Agent skill

JWT Authentication

by cohen-liel in cohen-liel/hivemind

JWT authentication implementation patterns. An agent skill from cohen-liel/hivemind.

Apache-2.0Auto-check passedBackend & APIs

Install JWT Authentication

skills CLI
$ npx skills add cohen-liel/hivemind --skill jwt-authentication -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cohen-liel/hivemind jwt-authentication --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cohen-liel/hivemind.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/jwt-authentication .claude/skills/jwt-authentication && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
jwt-authentication
GitHub stars
110
Token cost
~1.1k tokens
SKILL.md length
95 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

JWT authentication implementation patterns. An agent skill from cohen-liel/hivemind.

  • Implementing login
  • SKILL.md covers Token Strategy, Implementation (FastAPI +…, Login Endpoint and Auth Dependency, plus 2 more sections
  • Needs SECRET_KEY
  • Any authentication/authorization system

What it does

JWT Authentication is an agent skill from cohen-liel/hivemind. JWT authentication implementation patterns. Use when implementing login, registration, token refresh, password reset, or any authentication/authorization system.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. The repository describes itself as: One prompt. A full AI engineering team. Go lie on the couch. 🧠. The licence is Apache-2.0.

When your agent uses it

  • Implementing login
  • Any authentication/authorization system

Example prompts

  • “/jwt-authentication”

Requirements

  • Python 3
  • A credential in SECRET_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 918dd9b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

JWT Authentication loads about 1.1k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 95 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cohen-liel/hivemind at commit 918dd9b, republished under its Apache-2.0 licence (© cohen-liel). 95 words, ~1,144 tokens.

Download SKILL.mdSave it as .claude/skills/jwt-authentication/SKILL.md (or your agent's skills folder).
name
jwt-authentication
description
JWT authentication implementation patterns. Use when implementing login, registration, token refresh, password reset, or any authentication/authorization system.

JWT Authentication Patterns

Token Strategy

  • Access token: short-lived (15 min), stateless JWT
  • Refresh token: long-lived (7 days), stored in DB for revocation
  • Storage: access in memory (JS var), refresh in httpOnly cookie

Implementation (FastAPI + Python-Jose)

python
# auth/tokens.py
from datetime import datetime, timedelta
from jose import JWTError, jwt
from passlib.context import CryptContext

SECRET_KEY = settings.SECRET_KEY  # 32+ char random string from env
ALGORITHM = "HS256"
ACCESS_TOKEN_EXPIRE = timedelta(minutes=15)
REFRESH_TOKEN_EXPIRE = timedelta(days=7)

pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto")

def hash_password(password: str) -> str:
    return pwd_context.hash(password)

def verify_password(plain: str, hashed: str) -> bool:
    return pwd_context.verify(plain, hashed)

def create_access_token(user_id: int) -> str:
    return jwt.encode(
        {"sub": str(user_id), "exp": datetime.utcnow() + ACCESS_TOKEN_EXPIRE, "type": "access"},
        SECRET_KEY, algorithm=ALGORITHM
    )

def create_refresh_token(user_id: int) -> str:
    return jwt.encode(
        {"sub": str(user_id), "exp": datetime.utcnow() + REFRESH_TOKEN_EXPIRE, "type": "refresh"},
        SECRET_KEY, algorithm=ALGORITHM
    )

def decode_token(token: str) -> dict:
    try:
        payload = jwt.decode(token, SECRET_KEY, algorithms=[ALGORITHM])
        return payload
    except JWTError:
        raise HTTPException(status_code=401, detail="Invalid or expired token")

Login Endpoint

python
@router.post("/login", response_model=TokenResponse)
async def login(form: OAuth2PasswordRequestForm = Depends(), db: AsyncSession = Depends(get_db)):
    user = await get_user_by_email(db, form.username)
    if not user or not verify_password(form.password, user.hashed_password):
        # Same error for both cases — don't reveal which field was wrong
        raise HTTPException(status_code=401, detail="Invalid credentials")

    # Rate limit check (use Redis counter)
    await check_login_rate_limit(user.id)

    access_token = create_access_token(user.id)
    refresh_token = create_refresh_token(user.id)

    # Store refresh token hash in DB for revocation
    await store_refresh_token(db, user.id, refresh_token)

    response = JSONResponse({"access_token": access_token, "token_type": "bearer"})
    response.set_cookie("refresh_token", refresh_token, httponly=True, secure=True, samesite="lax")
    return response

Auth Dependency

python
oauth2_scheme = OAuth2PasswordBearer(tokenUrl="/auth/login")

async def get_current_user(
    token: str = Depends(oauth2_scheme),
    db: AsyncSession = Depends(get_db)
) -> User:
    payload = decode_token(token)
    if payload.get("type") != "access":
        raise HTTPException(status_code=401, detail="Invalid token type")
    user = await db.get(User, int(payload["sub"]))
    if not user or user.is_disabled:
        raise HTTPException(status_code=401, detail="User not found or disabled")
    return user

Refresh Token Rotation

python
@router.post("/refresh")
async def refresh(request: Request, db: AsyncSession = Depends(get_db)):
    refresh_token = request.cookies.get("refresh_token")
    if not refresh_token:
        raise HTTPException(status_code=401, detail="No refresh token")
    payload = decode_token(refresh_token)
    # Verify token exists in DB (revocation check)
    stored = await get_refresh_token(db, refresh_token)
    if not stored:
        raise HTTPException(status_code=401, detail="Token revoked")
    # Rotate: delete old, issue new
    await delete_refresh_token(db, refresh_token)
    new_access = create_access_token(int(payload["sub"]))
    new_refresh = create_refresh_token(int(payload["sub"]))
    await store_refresh_token(db, int(payload["sub"]), new_refresh)
    response = JSONResponse({"access_token": new_access})
    response.set_cookie("refresh_token", new_refresh, httponly=True, secure=True, samesite="lax")
    return response

Rules

  • httpOnly cookies for refresh tokens (XSS can't steal them)
  • Never store access tokens in localStorage (XSS risk)
  • Refresh token rotation: old token invalidated immediately on use
  • Rate limit login: 5 attempts per IP per 15 minutes
  • Same error message for wrong email AND wrong password
  • Logout must invalidate refresh token in DB

© cohen-liel, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/jwt-authentication of cohen-liel/hivemind.

Open the folder on GitHubat commit 918dd9b

Compare with similar skills

JWT Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

JWT Authentication compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
JWT Authentication this skillcohen-liel/hivemind110—~1.1kAutomated safety check: PassApache-2.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Gitnexus Exploringaws-samples/sample-kolya-br-proxy10612 repos~749Automated safety check: PassMIT-0
Supabasecurvenote/curvenote1705 repos~2.2kAutomated safety check: PassCustom licence

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Gitnexus Exploring

    aws-samples/sample-kolya-br-proxy

    Official

    A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.

    106 GitHub starsUsed in 12 repos~749 tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    170 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from cohen-liel/hivemind

All 33 skills in this repo
  • API Design

    cohen-liel/hivemind

    REST API design principles and best practices. An agent skill from cohen-liel/hivemind.

    110 GitHub stars~857 tokensUpdated 5 mo ago
    Auto-check passed
  • Async Python

    cohen-liel/hivemind

    Python asyncio patterns for high-performance async code. An agent skill from cohen-liel/hivemind.

    110 GitHub stars~992 tokensUpdated 5 mo ago
    Auto-check passed
  • Celery Tasks

    cohen-liel/hivemind

    Celery background task patterns for Python apps. An agent skill from cohen-liel/hivemind.

    110 GitHub stars~1.1k tokensUpdated 5 mo ago
    Auto-check passed
  • Docker Deployment

    cohen-liel/hivemind

    Docker, docker-compose, and deployment configuration best practices.

    110 GitHub stars~674 tokensUpdated 5 mo ago
    Auto-check passed
  • E2E Testing

    cohen-liel/hivemind

    End-to-end testing patterns with Playwright. An agent skill from cohen-liel/hivemind.

    110 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check passed
  • Email Service

    cohen-liel/hivemind

    Email sending patterns for transactional and marketing emails.

    110 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about JWT Authentication

What does JWT Authentication do?

JWT authentication implementation patterns. An agent skill from cohen-liel/hivemind. JWT Authentication is an agent skill from cohen-liel/hivemind. JWT authentication implementation patterns.

When should I use JWT Authentication?

JWT Authentication fits situations like: implementing login; any authentication/authorization system.

How do I install JWT Authentication in Claude Code?

Run `npx skills add cohen-liel/hivemind --skill jwt-authentication -a claude-code`. Or copy the skill folder (.claude/skills/jwt-authentication in cohen-liel/hivemind) into .claude/skills/jwt-authentication in your project. Claude Code loads it when a task matches its description.

How do I install JWT Authentication in Codex?

Run `npx skills add cohen-liel/hivemind --skill jwt-authentication -a codex`. Or copy the skill folder (.claude/skills/jwt-authentication in cohen-liel/hivemind) into .agents/skills/jwt-authentication in your project. Codex loads it when a task matches its description.

Can I use JWT Authentication in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cohen-liel/hivemind --skill jwt-authentication -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jwt-authentication, .gemini/skills/jwt-authentication, .github/skills/jwt-authentication and .opencode/skills/jwt-authentication in your project.

What does JWT Authentication need to run?

Going by SKILL.md and its folder, JWT Authentication needs credentials named SECRET_KEY. Our summary lists: Python 3; A credential in SECRET_KEY.

Does JWT Authentication access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is JWT Authentication safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does JWT Authentication use?

JWT Authentication is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does JWT Authentication use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to JWT Authentication?

Skills that share tags, products or a category with JWT Authentication: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Gitnexus Exploring (aws-samples/sample-kolya-br-proxy, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains JWT Authentication?

cohen-liel (a GitHub user) maintains it in cohen-liel/hivemind, which has 110 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on April 18, 2026.

Source: cohen-liel/hivemind on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.