Agent skill

Cometchat Security

by cometchat in cometchat/cometchat-skills

Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group…

MITAuto-check passedBackend & APIs

Install Cometchat Security

skills CLI
$ npx skills add cometchat/cometchat-skills --skill cometchat-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cometchat/cometchat-skills cometchat-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cometchat/cometchat-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cometchat-security .claude/skills/cometchat-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cometchat-security
GitHub stars
129
Used in
1 other repo
Token cost
~1.9k tokens
SKILL.md length
840 words
Files
1
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group…

  • Works in 4 steps: The user signs in through your IdP… → Your backend, on that authenticated… → Your backend mints an auth token: POST… → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Use this skill when, The auth model (get this right…, SSO / OIDC / SAML — through… and Session control & revocation, plus 4 more sections
  • Reaches cometchat.com; needs REST_API_KEY

What it does

Cometchat Security is an agent skill from cometchat/cometchat-skills. Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group scopes). Cross-family: the server/REST side is the same everywhere; client login lands in each family's core/production skill. Triggers: 'add SSO to cometchat', 'SAML/OIDC login', 'okta/auth0/cognito with cometchat', 'role based access control', 'restrict what a user can do', 'revoke a user session', 'rotate/flush auth…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: CometChat REST API v3 (auth tokens · roles · users · group members). Client login via any family's UI Kit / SDK. Server: any language over HTTPS.

It sits in Backend & APIs, covering Authorization and RBAC, OAuth and OpenID Connect and Authentication. It works with CometChat, Auth0 and Okta. The repository describes itself as: Add CometChat chat & messaging and voice & video calls to any React, Next.js, React Native, Angular, Android, iOS, or Flutter project through your AI coding agent. Works with… The licence is MIT.

When your agent uses it

  • Tasks that involve Authorization and RBAC
  • Tasks that involve OAuth and OpenID Connect
  • Tasks that involve Authentication

Example prompts

  • “s core/production skill. Triggers:”
  • “SAML/OIDC login”
  • “okta/auth0/cognito with cometchat”
  • “/cometchat-security”

Requirements

  • A credential in REST_API_KEY
  • Compatibility (from SKILL.md): CometChat REST API v3 (auth tokens · roles · users · group members). Client login via any family's UI Kit / SDK. Server: any language over HTTPS.

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. The user signs in through your IdP (SAML/OIDC) — your normal app auth.
  2. Your backend, on that authenticated session, maps the IdP subject to a CometChat UID (a stable, sanitized id — see…
  3. Your backend mints an auth token: POST /v3/users/{uid}/auth_tokens with the REST API Key ({DOCS_BASE}/rest-api/auth-tokens/create).
  4. It returns the token to the client over the authenticated request; the client logs in with it via its per-family call…

What it can do on your machine

Read from SKILL.md and the folder at commit 911b108. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are http).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cometchat.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • REST_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    CometChat REST API v3 (auth tokens · roles · users · group members). Client login via any family's UI Kit / SDK. Server: any language over HTTPS.

    From compatibility in the SKILL.md frontmatter.

Context cost

Cometchat Security loads about 1.9k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 840 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cometchat/cometchat-skills at commit 911b108, republished under its MIT licence (© cometchat). 840 words, ~1,927 tokens.

Download SKILL.mdSave it as .claude/skills/cometchat-security/SKILL.md (or your agent's skills folder).
name
cometchat-security
description
Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group scopes). Cross-family: the server/REST side is the same everywhere; client login lands in each family's core/production skill. Triggers: 'add SSO to cometchat', 'SAML/OIDC login', 'okta/auth0/cognito with cometchat', 'role based access control', 'restrict what a user can do', 'revoke a user session', 'rotate/flush auth tokens', 'secure cometchat for enterprise', 'multi-tenant cometchat'.
compatibility
CometChat REST API v3 (auth tokens · roles · users · group members). Client login via any family's UI Kit / SDK. Server: any language over HTTPS.
license
MIT
metadata.author
CometChat
metadata.version
1.0.0
metadata.tags
cometchat security sso saml oidc rbac roles auth-token session enterprise multi-tenant

Ground truth: every REST shape here is FETCHED from the live docs — {DOCS_BASE}/rest-api/auth-tokens, /rest-api/roles, /rest-api/rbac-overview, /rest-api/users, /rest-api/group-members (DOCS_BASE = https://www.cometchat.com/docs; append .md for the raw twin). CometChat is NOT an identity provider — it does not do SAML/OIDC for your end users. "SSO with CometChat" means your IdP authenticates the user, then your server mints a CometChat auth token for that user's UID. Verify signatures against the docs; never invent an endpoint.

Use this skill when

Taking a CometChat integration through an enterprise security review: SSO with your IdP, role-based permissions, session revocation, multi-tenant isolation, or "make our chat secure/compliant to ship." Client-side login wiring itself lives in cometchat-<family>-core / -production; this skill owns the server + access-control model those depend on.

The auth model (get this right first)

Three credentials, three homes — mixing them up is the #1 security defect:

CredentialWho holds itPurpose
Auth Keyclient, dev onlyquick login(uid) in development; can mint a session for ANY user — never ship it
Auth tokenclient, per userproduction login with a per-user token — the call is per family (web/Angular/Android/Flutter loginWithAuthToken(token), iOS login(authToken:), React Native login({ authToken })); tied to one UID; revocable
REST API Keyserver onlymint tokens, manage users/roles; full power — never in a client

Production login is always auth token, never the Auth Key. Detail + the per-framework client call: cometchat-<family>-production.

SSO / OIDC / SAML — through YOUR IdP

CometChat rides on the identity you already have. The flow is the same whether your IdP is Okta, Auth0, Cognito, Entra ID, Google Workspace, or your own:

  1. The user signs in through your IdP (SAML/OIDC) — your normal app auth.
  2. Your backend, on that authenticated session, maps the IdP subject to a CometChat UID (a stable, sanitized id — see cometchat-migrate-from-* toCometChatId for the alpha-dash/≤100/lowercase rules) and, if the user is new, creates it (POST {DOCS_BASE}/rest-api/users, withAuthToken: true returns a token in the same call).
  3. Your backend mints an auth token: POST /v3/users/{uid}/auth_tokens with the REST API Key ({DOCS_BASE}/rest-api/auth-tokens/create).
  4. It returns the token to the client over the authenticated request; the client logs in with it via its per-family call (web/Angular/Android/Flutter loginWithAuthToken(token), iOS login(authToken:), React Native login({ authToken }) — see cometchat-<family>-production).

The UID must come from the server session, never a request parameter. Accepting ?uid= lets any caller impersonate anyone — the single most common CometChat auth hole.

http
POST https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}/auth_tokens
apikey: {REST_API_KEY}          # server-side secret
content-type: application/json

Session control & revocation

Auth tokens do not expire by default and CometChat keeps a rolling 100 per user (oldest auto-archived). For enterprise session control:

  • Log out one device → DELETE /v3/users/{uid}/auth_tokens/{authToken}.
  • Kill every session (deprovisioned employee, suspected compromise) → DELETE /v3/users/{uid}/auth_tokens (flush all).
  • Rotate on privilege change / password reset → mint a fresh token, flush the rest.
  • Short-lived sessions → issue a token per login and flush on logout; don't reuse one token forever. Pages: {DOCS_BASE}/rest-api/auth-tokens/{delete,flush}.
Show full SKILL.md (383 more words)Show less

Access control — RBAC (app-wide) + SBAC (per group)

CometChat has two layers; an action must pass both or the API returns ERR_PERMISSION_DENIED:

LayerScopeSet viaUse it for
Role (RBAC)whole app, one role per useruser create/update (/rest-api/users), roles (/rest-api/roles)who may create groups, send messages, start calls, …
Scope (SBAC)inside one groupgroup membership (/rest-api/group-members/change-scope)admin / moderator / participant within that group
  • Define roles server-side via the REST Roles endpoint (POST https://{APP_ID}.api-{REGION}.cometchat.io/v3/roles; see the docs at {DOCS_BASE}/rest-api/roles) — each user gets exactly one; unspecified → default.
  • Set the fine-grained permissions per role via RBAC ({DOCS_BASE}/rest-api/rbac-overview). (The older per-role restrict-features API is deprecated — use RBAC.)
  • Group scopes (admin/moderator/participant) are the SBAC layer; change with the change-scope API. Model least privilege: a locked-down default role, elevated roles for staff/moderators, plus group scopes for in-group moderation.

Multi-tenant isolation

  • Strongest: one CometChat app per tenant (separate App ID/keys — full data isolation). Best for regulated or contractual isolation.
  • Lighter: one app, tenant-scoped groups + a tenant id in user/message metadata, enforced by your token server (a user only ever gets a token for their tenant's UID) + RBAC. Cheaper, but isolation is only as strong as your server checks. Pick per your compliance bar; document which you chose. Data residency/region selection is cometchat-compliance; self-hosting for full sovereignty is cometchat-self-host.

Common pitfalls

  1. Auth Key shipped to the client in production — it can log in as anyone. Grep the bundle/binary (cometchat-<family>-production).
  2. Token endpoint trusting a client-supplied UID — impersonation. Derive the UID from the server session.
  3. "CometChat SSO" misread as CometChat being the IdP — it isn't; integrate your IdP, then mint a token.
  4. No revocation on offboarding — a deprovisioned user keeps chatting until you flush their tokens.
  5. RBAC assumed but never configured — every user sits on default; define roles + permissions explicitly.
  6. Using the deprecated restrict-features instead of RBAC.
  7. REST API Key in client or repo — server-only; store in a secret manager.

Verify it works

IdP login → server mints a token from the session UID → the client's per-family auth-token login succeeds (loginWithAuthToken / iOS login(authToken:) / RN login({ authToken })) · a tampered/?uid= request is rejected · flushing a user's tokens ends their sessions on every device · a default-role user is denied a restricted action (ERR_PERMISSION_DENIED) while an elevated role is allowed · no Auth Key or REST API Key anywhere in client code.

© cometchat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cometchat-security of cometchat/cometchat-skills.

Open the folder on GitHubat commit 911b108

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in cometchat/cometchat-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cometchat Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cometchat Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cometchat Security this skillcometchat/cometchat-skills1291 repos~1.9kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills412—~3.1kAutomated safety check: NotesMIT
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Frontmcp Authoritiesagentfront/frontmcp146—~7.1kAutomated safety check: PassApache-2.0
Securing Authenticationancoleman/ai-design-components526—~3.4kAutomated safety check: PassMIT
Oauth2 Resource Serverrrezartprebreza/spring-boot-skills296—~1.2kAutomated safety check: PassMIT

Similar skills

  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    412 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frontmcp Authorities

    agentfront/frontmcp

    A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.

    146 GitHub stars~7.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Securing Authentication

    ancoleman/ai-design-components

    Authentication, authorization, and API security implementation.

    526 GitHub stars~3.4k tokensUpdated 10 mo ago
    Backend & APIsAuto-check passed
  • Oauth2 Resource Server

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing…

    296 GitHub stars~1.2k tokensUpdated 16 days ago
    Backend & APIsAuto-check passed
  • Spring Security JWT

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security.

    296 GitHub stars~1.7k tokensUpdated 16 days ago
    Backend & APIsAuto-check passed

More from cometchat/cometchat-skills

All 97 skills in this repo
  • CometChat Android Calls SDK v5

    cometchat/cometchat-skills

    Adds voice and video calling to an Android app in Kotlin with the headless CometChat Calls SDK v5, covering meeting-style rooms, 1:1 ringing calls, call logs and recording.

    129 GitHub stars~5.2k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Android v5 Headless SDK

    cometchat/cometchat-skills

    Builds chat on Android with your own UI against the headless CometChat Chat SDK v5, covering install, Jetifier conflicts, credentials and init-before-login ordering.

    129 GitHub stars~4k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Component Picker

    cometchat/cometchat-skills

    Picks and customizes CometChat's Angular UI Kit components by their verified component list, exact input and output event names, and the surfaces that have no kit component at all.

    129 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Features

    cometchat/cometchat-skills

    Enables or builds CometChat features such as polls, reactions, smart replies and pinned messages in an Angular app, first classifying how much client code each one needs.

    129 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Chat Placement

    cometchat/cometchat-skills

    Decides where CometChat chat UI goes in an Angular app: a dedicated route, a dashboard panel, a support widget or the full multi-pane app, with thread and search panels.

    129 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Cometchat iOS V5 SDK

    cometchat/cometchat-skills

    Add voice & video calling to any iOS app FROM SCRATCH with the headless CometChat Calls SDK v5 (CometChatCallsSDK, via Swift Package Manager) — no UI Kit.

    129 GitHub stars~5.2k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Cometchat Security

What does Cometchat Security do?

Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group…. Cometchat Security is an agent skill from cometchat/cometchat-skills. Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group scopes).

When should I use Cometchat Security?

Cometchat Security fits situations like: tasks that involve Authorization and RBAC; tasks that involve OAuth and OpenID Connect; tasks that involve Authentication.

How do I install Cometchat Security in Claude Code?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-security -a claude-code`. Or copy the skill folder (skills/cometchat-security in cometchat/cometchat-skills) into .claude/skills/cometchat-security in your project. Claude Code loads it when a task matches its description.

How do I install Cometchat Security in Codex?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-security -a codex`. Or copy the skill folder (skills/cometchat-security in cometchat/cometchat-skills) into .agents/skills/cometchat-security in your project. Codex loads it when a task matches its description.

Can I use Cometchat Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cometchat/cometchat-skills --skill cometchat-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cometchat-security, .gemini/skills/cometchat-security, .github/skills/cometchat-security and .opencode/skills/cometchat-security in your project.

What does Cometchat Security need to run?

Going by SKILL.md and its folder, Cometchat Security needs credentials named REST_API_KEY. Our summary lists: A credential in REST_API_KEY. Compatibility (from SKILL.md): CometChat REST API v3 (auth tokens · roles · users · group members). Client login via any family's UI Kit / SDK. Server: any language over HTTPS..

Does Cometchat Security access the network?

SKILL.md names 1 domain. In commands or code: cometchat.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cometchat Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cometchat Security use?

Cometchat Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cometchat Security use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cometchat Security?

Skills that share tags, products or a category with Cometchat Security: Iam Audit (briiirussell/cybersecurity-skills, 412 stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars), Frontmcp Authorities (agentfront/frontmcp, 146 stars) and Securing Authentication (ancoleman/ai-design-components, 526 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cometchat Security?

cometchat (a GitHub organization) maintains it in cometchat/cometchat-skills, which has 129 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 5, 2026.

Source: cometchat/cometchat-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.