Agent skill

Authentication Authorization

by cosmicstack-labs in cosmicstack-labs/mercury-agent-skills

JWT, OAuth2, SAML, session management, RBAC, ABAC, and MFA implementation

MITAuto-check passedBackend & APIs

Install Authentication Authorization

skills CLI
$ npx skills add cosmicstack-labs/mercury-agent-skills --skill authentication-authorization -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cosmicstack-labs/mercury-agent-skills authentication-authorization --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cosmicstack-labs/mercury-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/categories/backend/authentication-authorization .claude/skills/authentication-authorization && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authentication-authorization
GitHub stars
476
Token cost
~523 tokens
SKILL.md length
189 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

JWT, OAuth2, SAML, session management, RBAC, ABAC, and MFA implementation

  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Authentication Methods, Authorization Models, MFA Implementation and Session Management
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Authentication

What it does

Authentication Authorization is an agent skill from cosmicstack-labs/mercury-agent-skills. JWT, OAuth2, SAML, session management, RBAC, ABAC, and MFA implementation

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and Authentication. The repository describes itself as: A curated registry of reusable Mercury Agent, Open Claw or Hermes Agent skills designed for real developer workflows, persistent memory, and token-efficient execution. The licence is MIT.

When your agent uses it

  • Tasks that involve Authorization and RBAC
  • Tasks that involve Authentication

Example prompts

  • “/authentication-authorization”

What it can do on your machine

Read from SKILL.md and the folder at commit 30392fb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authentication Authorization loads about 523 tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~26
When it runs · the whole SKILL.md, loaded when a task matches
~523

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cosmicstack-labs/mercury-agent-skills at commit 30392fb, republished under its MIT licence (© cosmicstack-labs). 189 words, ~523 tokens.

Download SKILL.mdSave it as .claude/skills/authentication-authorization/SKILL.md (or your agent's skills folder).
name
authentication-authorization
description
JWT, OAuth2, SAML, session management, RBAC, ABAC, and MFA implementation
metadata.author
cosmicstack-labs
metadata.version
1.0.0
metadata.category
backend
metadata.tags
authentication, authorization, security, jwt, oauth, rbac

Authentication & Authorization

Implement secure auth in your applications.

Authentication Methods

MethodUse CaseSecurity Level
Session/CookieServer-rendered appsHigh (HTTP-only, secure flags)
JWTAPIs, SPAsMedium (stateless, revocable with blacklist)
OAuth2Third-party loginHigh (delegate to providers)
SAMLEnterprise SSOHigh (enterprise identity)
WebAuthnPasswordlessVery high (biometric, hardware keys)
JWT Best Practices
  • Short expiry (15 min access, 7 day refresh)
  • Store refresh tokens in HTTP-only cookies (not localStorage)
  • Use RS256 (asymmetric) not HS256 in microservices
  • Include minimal claims (sub, exp, iat, scope)
  • Always validate signature + expiry + audience

Authorization Models

RBAC (Role-Based)
json
{
  "roles": ["admin", "editor", "viewer"],
  "permissions": {
    "admin": ["read:*", "write:*", "delete:*"],
    "editor": ["read:*", "write:*"],
    "viewer": ["read:*"]
  }
}
ABAC (Attribute-Based)

Policy engine evaluates: user attributes + resource attributes + environment "Allow access if user.department == resource.department AND user.clearance >= resource.classification"

MFA Implementation

  • TOTP (Google Authenticator) — standard
  • SMS — least secure, avoid if possible
  • Push notification — good UX
  • Hardware keys (WebAuthn) — most secure
Enforcement
  • Require MFA for admin actions
  • Require MFA on new device login
  • Remember device with a trust token (30 days max)
  • Rate-limit MFA attempts

Session Management

  • Rotate session ID on login
  • Invalidate on password change
  • Show active sessions to user (allow remote logout)
  • Absolute session timeout (24h) + idle timeout (2h)
  • Log all auth events (login, logout, failure, MFA)

© cosmicstack-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in categories/backend/authentication-authorization of cosmicstack-labs/mercury-agent-skills.

Open the folder on GitHubat commit 30392fb

Compare with similar skills

Authentication Authorization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authentication Authorization compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authentication Authorization this skillcosmicstack-labs/mercury-agent-skills476—~523Automated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61710 repos~4.4kAutomated safety check: PassNone
Configuration Cryptogreenpau/caddy-security2.3k—~3.5kAutomated safety check: PassApache-2.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Bkend Authww-w-ai/bkit-claude-code601—~937Automated safety check: NotesApache-2.0

Similar skills

  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Bkend Auth

    ww-w-ai/bkit-claude-code

    bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.

    601 GitHub stars~937 tokensUpdated 11 days ago
    Backend & APIsAuto-check: notes
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed

More from cosmicstack-labs/mercury-agent-skills

All 12 skills in this repo
  • Before You Build

    cosmicstack-labs/mercury-agent-skills

    Use this before implementing a product, feature, SaaS, AI app, or side project to score product risk and choose the smallest validation step.

    476 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Hyperframes CLI

    cosmicstack-labs/mercury-agent-skills

    HyperFrames CLI dev loop — project scaffolding, validation (lint/inspect), browser preview with live reload, MP4/WebM rendering, and environment troubleshooting (doctor, browser, info, upgrade).

    476 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Hyperframes Media

    cosmicstack-labs/mercury-agent-skills

    Asset preprocessing for HyperFrames compositions — local text-to-speech narration (Kokoro-82M, no API key), audio/video transcription (Whisper), and background removal for transparent overlays…

    476 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Agent Handoff Protocols

    cosmicstack-labs/mercury-agent-skills

    Design and implement agent-to-agent handoff protocols for multi-agent systems.

    476 GitHub stars~4.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Agent Health Monitoring

    cosmicstack-labs/mercury-agent-skills

    Monitor AI agent health, detect anomalies, set up alerting, and maintain observability dashboards for production multi-agent systems.

    476 GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Agent Task Delegation

    cosmicstack-labs/mercury-agent-skills

    Design and operate task delegation systems for multi-agent fleets.

    476 GitHub stars~3.4k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Authentication Authorization

What does Authentication Authorization do?

JWT, OAuth2, SAML, session management, RBAC, ABAC, and MFA implementation. Authentication Authorization is an agent skill from cosmicstack-labs/mercury-agent-skills.

When should I use Authentication Authorization?

Authentication Authorization fits situations like: tasks that involve Authorization and RBAC; tasks that involve Authentication.

How do I install Authentication Authorization in Claude Code?

Run `npx skills add cosmicstack-labs/mercury-agent-skills --skill authentication-authorization -a claude-code`. Or copy the skill folder (categories/backend/authentication-authorization in cosmicstack-labs/mercury-agent-skills) into .claude/skills/authentication-authorization in your project. Claude Code loads it when a task matches its description.

How do I install Authentication Authorization in Codex?

Run `npx skills add cosmicstack-labs/mercury-agent-skills --skill authentication-authorization -a codex`. Or copy the skill folder (categories/backend/authentication-authorization in cosmicstack-labs/mercury-agent-skills) into .agents/skills/authentication-authorization in your project. Codex loads it when a task matches its description.

Can I use Authentication Authorization in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cosmicstack-labs/mercury-agent-skills --skill authentication-authorization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authentication-authorization, .gemini/skills/authentication-authorization, .github/skills/authentication-authorization and .opencode/skills/authentication-authorization in your project.

What does Authentication Authorization need to run?

SKILL.md names no scripts, command-line tools or credentials: Authentication Authorization is instructions for the agent only.

Does Authentication Authorization access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Authentication Authorization safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authentication Authorization use?

Authentication Authorization is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authentication Authorization use?

About 523 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authentication Authorization?

Skills that share tags, products or a category with Authentication Authorization: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars), Configuration Crypto (greenpau/caddy-security, 2.3k stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authentication Authorization?

cosmicstack-labs (a GitHub organization) maintains it in cosmicstack-labs/mercury-agent-skills, which has 476 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 25, 2026.

Source: cosmicstack-labs/mercury-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.