Supabase Development and Debugging
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
This skill should be used when the user asks about "authentication in Next.js", "NextAuth", "Auth.js", "middleware auth", "protected routes", "session management", "JWT", "login flow", or needs…
$ npx skills add davepoon/buildwithclaude --skill auth-patterns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install davepoon/buildwithclaude auth-patterns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/nextjs-expert/skills/auth-patterns .claude/skills/auth-patterns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auth-patterns" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/nextjs-expert/skills/auth-patterns into .claude/skills/auth-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-patterns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/davepoon/buildwithclaude/tree/main/plugins/nextjs-expert/skills/auth-patternsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add davepoon/buildwithclaude --skill auth-patterns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install davepoon/buildwithclaude auth-patterns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/nextjs-expert/skills/auth-patterns .agents/skills/auth-patterns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auth-patterns" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/nextjs-expert/skills/auth-patterns into .agents/skills/auth-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-patterns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davepoon/buildwithclaude --skill auth-patterns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install davepoon/buildwithclaude auth-patterns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/nextjs-expert/skills/auth-patterns .cursor/skills/auth-patterns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auth-patterns" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/nextjs-expert/skills/auth-patterns into .cursor/skills/auth-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-patterns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/davepoon/buildwithclaude.git --path plugins/nextjs-expert/skills/auth-patterns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add davepoon/buildwithclaude --skill auth-patterns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install davepoon/buildwithclaude auth-patterns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/nextjs-expert/skills/auth-patterns .gemini/skills/auth-patterns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auth-patterns" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/nextjs-expert/skills/auth-patterns into .gemini/skills/auth-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-patterns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install davepoon/buildwithclaude auth-patternsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add davepoon/buildwithclaude --skill auth-patterns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/nextjs-expert/skills/auth-patterns .github/skills/auth-patterns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auth-patterns" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/nextjs-expert/skills/auth-patterns into .github/skills/auth-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-patterns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davepoon/buildwithclaude --skill auth-patterns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install davepoon/buildwithclaude auth-patterns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/nextjs-expert/skills/auth-patterns .opencode/skills/auth-patterns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auth-patterns" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/nextjs-expert/skills/auth-patterns into .opencode/skills/auth-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-patterns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auth-patternsThis skill should be used when the user asks about "authentication in Next.js", "NextAuth", "Auth.js", "middleware auth", "protected routes", "session management", "JWT", "login flow", or needs…
Auth Patterns is an agent skill from davepoon/buildwithclaude. This skill should be used when the user asks about "authentication in Next.js", "NextAuth", "Auth.js", "middleware auth", "protected routes", "session management", "JWT", "login flow", or needs guidance on implementing authentication and authorization in Next.js applications.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `examples/nextauth-setup.md`, `references/middleware-auth.md` and `references/session-management.md`).
It sits in Backend & APIs, covering Authentication. It works with Next.js. The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 10bfc43. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_SECRETJWT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auth Patterns loads about 2.1k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 73 tokens; SKILL.md has 167 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from davepoon/buildwithclaude at commit 10bfc43, republished under its MIT licence (© davepoon). 167 words, ~2,114 tokens.
.claude/skills/auth-patterns/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Next.js supports multiple authentication strategies. This skill covers common patterns including NextAuth.js (Auth.js), middleware-based protection, and session management.
| Library | Best For |
|---|---|
| NextAuth.js (Auth.js) | Full-featured auth with providers |
| Clerk | Managed auth service |
| Lucia | Lightweight, flexible auth |
| Supabase Auth | Supabase ecosystem |
| Custom JWT | Full control |
npm install next-auth@beta// auth.ts
import NextAuth from 'next-auth'
import GitHub from 'next-auth/providers/github'
import Credentials from 'next-auth/providers/credentials'
export const { handlers, auth, signIn, signOut } = NextAuth({
providers: [
GitHub({
clientId: process.env.GITHUB_ID,
clientSecret: process.env.GITHUB_SECRET,
}),
Credentials({
credentials: {
email: { label: 'Email', type: 'email' },
password: { label: 'Password', type: 'password' },
},
authorize: async (credentials) => {
const user = await getUserByEmail(credentials.email)
if (!user || !verifyPassword(credentials.password, user.password)) {
return null
}
return user
},
}),
],
callbacks: {
authorized: async ({ auth }) => {
return !!auth
},
},
})// app/api/auth/[...nextauth]/route.ts
import { handlers } from '@/auth'
export const { GET, POST } = handlers// middleware.ts
export { auth as middleware } from '@/auth'
export const config = {
matcher: ['/dashboard/:path*', '/api/protected/:path*'],
}// app/dashboard/page.tsx
import { auth } from '@/auth'
import { redirect } from 'next/navigation'
export default async function DashboardPage() {
const session = await auth()
if (!session) {
redirect('/login')
}
return (
<div>
<h1>Welcome, {session.user?.name}</h1>
</div>
)
}// components/user-menu.tsx
'use client'
import { useSession } from 'next-auth/react'
export function UserMenu() {
const { data: session, status } = useSession()
if (status === 'loading') {
return <div>Loading...</div>
}
if (!session) {
return <SignInButton />
}
return (
<div>
<span>{session.user?.name}</span>
<SignOutButton />
</div>
)
}// app/providers.tsx
'use client'
import { SessionProvider } from 'next-auth/react'
export function Providers({ children }: { children: React.ReactNode }) {
return <SessionProvider>{children}</SessionProvider>
}
// app/layout.tsx
import { Providers } from './providers'
export default function RootLayout({ children }) {
return (
<html>
<body>
<Providers>{children}</Providers>
</body>
</html>
)
}// components/auth-buttons.tsx
import { signIn, signOut } from '@/auth'
export function SignInButton() {
return (
<form
action={async () => {
'use server'
await signIn('github')
}}
>
<button type="submit">Sign in with GitHub</button>
</form>
)
}
export function SignOutButton() {
return (
<form
action={async () => {
'use server'
await signOut()
}}
>
<button type="submit">Sign out</button>
</form>
)
}// middleware.ts
import { NextResponse } from 'next/server'
import type { NextRequest } from 'next/server'
const protectedRoutes = ['/dashboard', '/settings', '/api/protected']
const authRoutes = ['/login', '/signup']
export function middleware(request: NextRequest) {
const token = request.cookies.get('session')?.value
const { pathname } = request.nextUrl
// Redirect authenticated users away from auth pages
if (authRoutes.some(route => pathname.startsWith(route))) {
if (token) {
return NextResponse.redirect(new URL('/dashboard', request.url))
}
return NextResponse.next()
}
// Protect routes
if (protectedRoutes.some(route => pathname.startsWith(route))) {
if (!token) {
const loginUrl = new URL('/login', request.url)
loginUrl.searchParams.set('callbackUrl', pathname)
return NextResponse.redirect(loginUrl)
}
}
return NextResponse.next()
}
export const config = {
matcher: ['/((?!_next/static|_next/image|favicon.ico).*)'],
}// middleware.ts
import { NextResponse } from 'next/server'
import { jwtVerify } from 'jose'
const secret = new TextEncoder().encode(process.env.JWT_SECRET)
export async function middleware(request: NextRequest) {
const token = request.cookies.get('token')?.value
if (!token) {
return NextResponse.redirect(new URL('/login', request.url))
}
try {
const { payload } = await jwtVerify(token, secret)
// Token is valid, continue
return NextResponse.next()
} catch {
// Token is invalid
return NextResponse.redirect(new URL('/login', request.url))
}
}// types/next-auth.d.ts
import { DefaultSession } from 'next-auth'
declare module 'next-auth' {
interface Session {
user: {
role: 'user' | 'admin'
} & DefaultSession['user']
}
}
// auth.ts
export const { handlers, auth } = NextAuth({
callbacks: {
session: ({ session, token }) => ({
...session,
user: {
...session.user,
role: token.role,
},
}),
jwt: ({ token, user }) => {
if (user) {
token.role = user.role
}
return token
},
},
})// components/admin-only.tsx
import { auth } from '@/auth'
import { redirect } from 'next/navigation'
export async function AdminOnly({ children }: { children: React.ReactNode }) {
const session = await auth()
if (session?.user?.role !== 'admin') {
redirect('/unauthorized')
}
return <>{children}</>
}
// Usage
export default async function AdminPage() {
return (
<AdminOnly>
<AdminDashboard />
</AdminOnly>
)
}// auth.ts
export const { auth } = NextAuth({
session: { strategy: 'jwt' },
// JWT stored in cookies, no database needed
})// auth.ts
import { PrismaAdapter } from '@auth/prisma-adapter'
import { prisma } from '@/lib/prisma'
export const { auth } = NextAuth({
adapter: PrismaAdapter(prisma),
session: { strategy: 'database' },
// Sessions stored in database
})// app/login/page.tsx
'use client'
import { signIn } from 'next-auth/react'
import { useSearchParams } from 'next/navigation'
export default function LoginPage() {
const searchParams = useSearchParams()
const callbackUrl = searchParams.get('callbackUrl') || '/dashboard'
return (
<div className="flex flex-col gap-4">
<button
onClick={() => signIn('github', { callbackUrl })}
className="btn"
>
Sign in with GitHub
</button>
<button
onClick={() => signIn('google', { callbackUrl })}
className="btn"
>
Sign in with Google
</button>
</div>
)
}For detailed patterns, see:
references/middleware-auth.md - Advanced middleware patternsreferences/session-management.md - Session strategiesexamples/nextauth-setup.md - Complete NextAuth.js setup© davepoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in plugins/nextjs-expert/skills/auth-patterns of davepoon/buildwithclaude.
Open the folder on GitHubat commit 10bfc43
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in davepoon/buildwithclaude, which our catalogue first saw on October 7, 2026.
Auth Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auth Patterns this skilldavepoon/buildwithclaude | 3.6k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Supabasecurvenote/curvenote | 169 | 5 repos | ~2.2k | Automated safety check: Pass | Custom licence | |
| Edgeone Pages Website SkeletonTencentEdgeOne/awesome-website-prompts-and-skills | 183 | — | ~2.2k | Automated safety check: Notes | MIT | |
| Clerk Setupgrowupanand/ConvoForm | 101 | — | ~3k | Automated safety check: Pass | MIT | |
| Wp Headless And Wpgraphqljorgerosal/wordpress-skills | 100 | — | ~1.7k | Automated safety check: Pass | MIT |
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
TencentEdgeOne/awesome-website-prompts-and-skills
基于 EdgeOne Pages 的全栈网站生成方案。用户说一句话(如「帮我建一个电商站」「做一个AI客服站」「做个管理后台」),AI 自动组合 Auth、Cart、Payment、AI Chat、Admin 五大模块,生成完整 Next.js 前后端代码并部署到 EdgeOne Pages 全球 CDN。支持电商、AI 助手、SaaS 管理后台三大模板。底层使用 Edge…
growupanand/ConvoForm
Set up Clerk authentication in any project with the Clerk CLI and official framework quickstarts.
jorgerosal/wordpress-skills
Headless WordPress and WPGraphQL review guidance. An agent skill from jorgerosal/wordpress-skills.
HHU3637kr/skills
Full-stack backend architecture and frontend-backend integration guide.
davepoon/buildwithclaude
A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…
davepoon/buildwithclaude
Activate this agent for any future-oriented question that requires deep quantitative analysis, historical precedents, and structured scenario planning.
davepoon/buildwithclaude
Build, update, and apply iOS design specifications using Apple Human Interface Guidelines (HIG) source data.
davepoon/buildwithclaude
Download YouTube videos with customizable quality and format options.
davepoon/buildwithclaude
Discover Atlas Cloud image and video models, inspect their live schemas, and submit one confirmed media generation request with bounded GET polling.
davepoon/buildwithclaude
Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.
Works with
Categories
This skill should be used when the user asks about "authentication in Next.js", "NextAuth", "Auth.js", "middleware auth", "protected routes", "session management", "JWT", "login flow", or needs…. Auth Patterns is an agent skill from davepoon/buildwithclaude.js applications.
Auth Patterns fits situations like: asks about authentication in Next.js; middleware auth; protected routes; session management.
Run `npx skills add davepoon/buildwithclaude --skill auth-patterns -a claude-code`. Or copy the skill folder (plugins/nextjs-expert/skills/auth-patterns in davepoon/buildwithclaude) into .claude/skills/auth-patterns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add davepoon/buildwithclaude --skill auth-patterns -a codex`. Or copy the skill folder (plugins/nextjs-expert/skills/auth-patterns in davepoon/buildwithclaude) into .agents/skills/auth-patterns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill auth-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth-patterns, .gemini/skills/auth-patterns, .github/skills/auth-patterns and .opencode/skills/auth-patterns in your project.
Going by SKILL.md and its folder, Auth Patterns needs the command-line tools its instructions call (npm) and credentials named GITHUB_SECRET and JWT_SECRET. Our summary lists: Node.js; A credential in GITHUB_SECRET; A credential in JWT_SECRET.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Auth Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Auth Patterns: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Supabase (curvenote/curvenote, 169 stars), Edgeone Pages Website Skeleton (TencentEdgeOne/awesome-website-prompts-and-skills, 183 stars) and Clerk Setup (growupanand/ConvoForm, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,601 GitHub stars. The repository holds 246 skills in this directory. The repository was last updated on October 6, 2026.
Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.