Agent skill

Fortify Development

by coollabsio in coollabsio/coolify

ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

MITAuto-check passedBackend & APIs

Install Fortify Development

skills CLI
$ npx skills add coollabsio/coolify --skill fortify-development -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coollabsio/coolify fortify-development --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coollabsio/coolify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fortify-development .claude/skills/fortify-development && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fortify-development
GitHub stars
63k
Used in
4 other repos
Token cost
~1.9k tokens
SKILL.md length
396 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

  • Works on authentication in Laravel
  • SKILL.md covers Documentation, Usage, Available Features and Setup Workflows, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Mentions Fortify

What it does

Fortify Development is an agent skill from coollabsio/coolify. ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and controllers. Activate when the user mentions Fortify, auth, authentication, login, register, signup, forgot password, verify email, 2FA, passkeys, WebAuthn, or references app/Actions/Fortify/, CreateNewUser, UpdateUserProfileInformation…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development, OAuth and OpenID Connect and Authentication. It works with Laravel, PHP and Docker. The repository describes itself as: An open-source, self-hostable PaaS alternative to Vercel, Heroku & Netlify that lets you easily deploy static sites, databases, full-stack applications and 280+ one-click… The licence is MIT.

When your agent uses it

  • Works on authentication in Laravel
  • Mentions Fortify
  • Forgot password
  • References app/Actions/Fortify/

Example prompts

  • “/fortify-development”

What it can do on your machine

Read from SKILL.md and the folder at commit 81239e6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fortify Development loads about 1.9k tokens when it runs. Until then it costs about 250 tokens; SKILL.md has 396 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~250
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coollabsio/coolify at commit 81239e6, republished under its MIT licence (© coollabsio). 396 words, ~1,894 tokens.

Download SKILL.mdSave it as .claude/skills/fortify-development/SKILL.md (or your agent's skills folder).
name
fortify-development
description
ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and controllers. Activate when the user mentions Fortify, auth, authentication, login, register, signup, forgot password, verify email, 2FA, passkeys, WebAuthn, or references app/Actions/Fortify/, CreateNewUser, UpdateUserProfileInformation, FortifyServiceProvider, config/fortify.php, or auth guards. Fortify is the frontend-agnostic authentication backend for Laravel that registers all auth routes and controllers. Also activate when building SPA or headless authentication, customizing login redirects, overriding response contracts like LoginResponse, or configuring login throttling. Do NOT activate for Laravel Passport (OAuth2 API tokens), Socialite (OAuth social login), or non-auth Laravel features.
license
MIT
metadata.author
laravel

Laravel Fortify Development

Fortify is a headless authentication backend that provides authentication routes and controllers for Laravel applications.

Documentation

Use search-docs for detailed Laravel Fortify patterns and documentation.

Usage

  • Routes: Use list-routes with only_vendor: true and action: "Fortify" to see all registered endpoints
  • Actions: Check app/Actions/Fortify/ for customizable business logic (user creation, password validation, etc.)
  • Config: See config/fortify.php for all options including features, guards, rate limiters, and username field
  • Contracts: Look in Laravel\Fortify\Contracts\ for overridable response classes (LoginResponse, LogoutResponse, etc.)
  • Views: All view callbacks are set in FortifyServiceProvider::boot() using Fortify::loginView(), Fortify::registerView(), etc.

Available Features

Enable in config/fortify.php features array:

  • Features::registration() - User registration
  • Features::resetPasswords() - Password reset via email
  • Features::emailVerification() - Requires User to implement MustVerifyEmail
  • Features::updateProfileInformation() - Profile updates
  • Features::updatePasswords() - Password changes
  • Features::twoFactorAuthentication() - 2FA with QR codes and recovery codes
  • Features::passkeys() - Passwordless authentication with WebAuthn passkeys

Use search-docs for feature configuration options and customization patterns.

Setup Workflows

Two-Factor Authentication Setup
- [ ] Add TwoFactorAuthenticatable trait to User model
- [ ] Enable feature in config/fortify.php
- [ ] If the `*_add_two_factor_columns_to_users_table.php` migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate
- [ ] Set up view callbacks in FortifyServiceProvider
- [ ] Create 2FA management UI
- [ ] Test QR code and recovery codes

Use search-docs for TOTP implementation and recovery code handling patterns.

Passkeys Setup
- [ ] Add PasskeyAuthenticatable trait to User model and implement PasskeyUser
- [ ] Enable passkeys feature in config/fortify.php
- [ ] If the passkeys table migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate
- [ ] Configure passkeys relying_party_id, allowed_origins, user_handle_secret, and timeout if defaults are not suitable
- [ ] Build UI with @laravel/passkeys for registration, login, confirmation, and deletion

Use search-docs for passkey configuration options. For @laravel/passkeys frontend usage, refer to the package's README on npm.

Email Verification Setup
- [ ] Enable emailVerification feature in config
- [ ] Implement MustVerifyEmail interface on User model
- [ ] Set up verifyEmailView callback
- [ ] Add verified middleware to protected routes
- [ ] Test verification email flow

Use search-docs for MustVerifyEmail implementation patterns.

Password Reset Setup
- [ ] Enable resetPasswords feature in config
- [ ] Set up requestPasswordResetLinkView callback
- [ ] Set up resetPasswordView callback
- [ ] Define password.reset named route (if views disabled)
- [ ] Test reset email and link flow

Use search-docs for custom password reset flow patterns.

SPA Authentication Setup
- [ ] Set 'views' => false in config/fortify.php
- [ ] Install and configure Laravel Sanctum for session-based SPA authentication
- [ ] Use the 'web' guard in config/fortify.php (required for session-based authentication)
- [ ] Set up CSRF token handling
- [ ] Test XHR authentication flows

Use search-docs for integration and SPA authentication patterns.

Two-Factor Authentication in SPA Mode

When views is set to false, Fortify returns JSON responses instead of redirects.

If a user attempts to log in and two-factor authentication is enabled, the login request will return a JSON response indicating that a two-factor challenge is required:

json
{
    "two_factor": true
}
Show full SKILL.md (144 more words)Show less

Best Practices

Custom Authentication Logic

Override authentication behavior using Fortify::authenticateUsing() for custom user retrieval or Fortify::authenticateThrough() to customize the authentication pipeline. Override response contracts in AppServiceProvider for custom redirects.

Registration Customization

Modify app/Actions/Fortify/CreateNewUser.php to customize user creation logic, validation rules, and additional fields.

Rate Limiting

Configure via fortify.limiters.login in config. Default configuration throttles by username + IP combination.

Key Endpoints

FeatureMethodEndpoint
LoginPOST/login
LogoutPOST/logout
RegisterPOST/register
Password Reset RequestPOST/forgot-password
Password ResetPOST/reset-password
Email Verify NoticeGET/email/verify
Resend VerificationPOST/email/verification-notification
Password ConfirmPOST/user/confirm-password
Enable 2FAPOST/user/two-factor-authentication
Confirm 2FAPOST/user/confirmed-two-factor-authentication
2FA ChallengePOST/two-factor-challenge
Get QR CodeGET/user/two-factor-qr-code
Recovery CodesGET/POST/user/two-factor-recovery-codes
Passkey Login OptionsGET/passkeys/login/options
Passkey LoginPOST/passkeys/login
Passkey Confirm OptionsGET/passkeys/confirm/options
Passkey ConfirmPOST/passkeys/confirm
Passkey OptionsGET/user/passkeys/options
Register PasskeyPOST/user/passkeys
Delete PasskeyDELETE/user/passkeys/{passkey}

© coollabsio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/fortify-development of coollabsio/coolify.

Open the folder on GitHubat commit 81239e6

Used in 6 other repositories

We found 14 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in coollabsio/coolify, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Fortify Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fortify Development compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fortify Development this skillcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Passport Developmenttrypostit/trypost678—~1.9kAutomated safety check: PassMIT
Laravel SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Socialite Developmenthexlet-volunteers/hexlet-sicp1145 repos~1.2kAutomated safety check: PassMIT
Spa Auth Developmentgdarko/laravel-vue-starter145—~668Automated safety check: NotesMIT
Developing With Fortifyslimani-dev/muraqib128—~1.3kAutomated safety check: PassMIT

Similar skills

  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    678 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Spa Auth Development

    gdarko/laravel-vue-starter

    Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

    145 GitHub stars~668 tokensUpdated 6 mo ago
    Backend & APIsAuto-check: notes
  • Developing With Fortify

    slimani-dev/muraqib

    Laravel Fortify headless authentication backend development.

    128 GitHub stars~1.3k tokensUpdated 8 days ago
    Backend & APIsAuto-check passed
  • Laravel Best Practices

    anonaddy/anonaddy

    Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code.

    4.9k GitHub starsUsed in 13 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from coollabsio/coolify

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Auto-check passed
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Auto-check passed
  • Laravel Actions

    coollabsio/coolify

    Build, refactor, and troubleshoot Laravel Actions using lorisleiva/laravel-actions.

    63k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Livewire Development

    coollabsio/coolify

    A skill your agent uses for any task or question involving Livewire.

    63k GitHub stars~964 tokensUpdated today
    Auto-check passed

Categories

Questions about Fortify Development

What does Fortify Development do?

ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify. Fortify Development is an agent skill from coollabsio/coolify. ACTIVATE when the user works on authentication in Laravel.

When should I use Fortify Development?

Fortify Development fits situations like: works on authentication in Laravel; mentions Fortify; forgot password; references app/Actions/Fortify/.

How do I install Fortify Development in Claude Code?

Run `npx skills add coollabsio/coolify --skill fortify-development -a claude-code`. Or copy the skill folder (.agents/skills/fortify-development in coollabsio/coolify) into .claude/skills/fortify-development in your project. Claude Code loads it when a task matches its description.

How do I install Fortify Development in Codex?

Run `npx skills add coollabsio/coolify --skill fortify-development -a codex`. Or copy the skill folder (.agents/skills/fortify-development in coollabsio/coolify) into .agents/skills/fortify-development in your project. Codex loads it when a task matches its description.

Can I use Fortify Development in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coollabsio/coolify --skill fortify-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fortify-development, .gemini/skills/fortify-development, .github/skills/fortify-development and .opencode/skills/fortify-development in your project.

What does Fortify Development need to run?

SKILL.md names no scripts, command-line tools or credentials: Fortify Development is instructions for the agent only.

Does Fortify Development access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fortify Development safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fortify Development use?

Fortify Development is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fortify Development use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fortify Development?

Skills that share tags, products or a category with Fortify Development: Passport Development (trypostit/trypost, 678 stars), Laravel Specialist (Jeffallan/claude-skills, 12k stars), Socialite Development (hexlet-volunteers/hexlet-sicp, 114 stars) and Spa Auth Development (gdarko/laravel-vue-starter, 145 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fortify Development?

coollabsio (a GitHub organization) maintains it in coollabsio/coolify, which has 62,702 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 7, 2026.

Source: coollabsio/coolify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.