Agent skill

Nip98 URL Query Param Mismatch

by divinevideo in divinevideo/divine-mobile

Fix NIP-98 HTTP authentication 401 errors caused by URL mismatch between the u tag and what the server expects.

MPL-2.0Auto-check passedBackend & APIs

Install Nip98 URL Query Param Mismatch

skills CLI
$ npx skills add divinevideo/divine-mobile --skill nip98-url-query-param-mismatch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile nip98-url-query-param-mismatch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nip98-url-query-param-mismatch .claude/skills/nip98-url-query-param-mismatch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nip98-url-query-param-mismatch
GitHub stars
266
Token cost
~920 tokens
SKILL.md length
332 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Fix NIP-98 HTTP authentication 401 errors caused by URL mismatch between the u tag and what the server expects.

  • Works in 3 steps: After the fix, the URLs in the u tag… → The 401 error should be replaced by… → Check logs to confirm URL matching
  • NIP-98 auth returns 401 with URL mismatch error
  • SKILL.md covers Problem, Context / Trigger Conditions, Root Cause and Solution, plus 4 more sections
  • Reaches relay.dvines.org

What it does

Nip98 URL Query Param Mismatch is an agent skill from divinevideo/divine-mobile. Fix NIP-98 HTTP authentication 401 errors caused by URL mismatch between the u tag and what the server expects. Use when: (1) NIP-98 auth returns 401 with "URL mismatch" error, (2) Token creation succeeds but server rejects authentication, (3) Server logs show expected vs actual URL difference. CRITICAL: Server implementations vary - some strip query params, some don't. Check the actual error message to determine which behavior applies.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. The licence is MPL-2.0.

When your agent uses it

  • NIP-98 auth returns 401 with URL mismatch error
  • Token creation succeeds but server rejects authentication
  • Server logs show expected vs actual URL difference

Example prompts

  • “URL mismatch”
  • “/nip98-url-query-param-mismatch”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. After the fix, the URLs in the u tag should match what server expects
  2. The 401 error should be replaced by successful authentication (200)
  3. Check logs to confirm URL matching

What it can do on your machine

Read from SKILL.md and the folder at commit c3d6f7e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are dart and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • relay.dvines.org

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nip98 URL Query Param Mismatch loads about 920 tokens when it runs. Until then it costs about 118 tokens; SKILL.md has 332 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~920

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit c3d6f7e, republished under its MPL-2.0 licence (© divinevideo). 332 words, ~920 tokens.

Download SKILL.mdSave it as .claude/skills/nip98-url-query-param-mismatch/SKILL.md (or your agent's skills folder).
name
nip98-url-query-param-mismatch
description
Fix NIP-98 HTTP authentication 401 errors caused by URL mismatch between the `u` tag and what the server expects. Use when: (1) NIP-98 auth returns 401 with "URL mismatch" error, (2) Token creation succeeds but server rejects authentication, (3) Server logs show expected vs actual URL difference. CRITICAL: Server implementations vary - some strip query params, some don't. Check the actual error message to determine which behavior applies.
author
Claude Code
version
1.1.0
date
2026-02-01

NIP-98 URL Query Parameter Mismatch

Problem

NIP-98 HTTP authentication fails with 401 Unauthorized even though the token is created successfully and the signature is valid. The actual cause is a URL mismatch between the u tag in the signed event and what the server expects.

Context / Trigger Conditions

  • Server returns 401 Unauthorized for NIP-98 protected endpoints
  • Logs show token creation succeeded (event signed and validated)
  • Error response contains "URL mismatch" with expected vs actual URLs
  • The URLs differ only by query parameters

Example error response:

json
{"error":"Auth failed: URL mismatch: expected .../notifications, got .../notifications?limit=50"}

Root Cause

The NIP-98 spec says:

The u tag MUST be exactly the same as the absolute request URL (including query parameters).

But server implementations vary:

  • Some servers follow the spec strictly (require query params in u tag)
  • Some servers normalize URLs by stripping query params before validation
  • You MUST match what your specific server does

Solution

Step 1: Add logging to see the actual error

dart
} else if (response.statusCode == 401) {
  Log.error(
    'NIP-98 auth failed (401)\n'
    'URL: $url\n'
    'Response: ${response.body}',  // <-- This reveals the actual issue
    ...
  );
}

Step 2: Check the error message

  • If error says "expected .../path?params, got .../path" → Include query params
  • If error says "expected .../path, got .../path?params" → Strip query params

Step 3: Adjust URL normalization accordingly

For servers that STRIP query params (like Divine Relay):

dart
final uri = Uri.parse(url);
// Server strips query params before NIP-98 validation
final normalizedUrl = '${uri.scheme}://${uri.host}${uri.path}';

For servers that REQUIRE query params (per NIP-98 spec):

dart
final uri = Uri.parse(url);
final normalizedUrl = uri.hasQuery
    ? '${uri.scheme}://${uri.host}${uri.path}?${uri.query}'
    : '${uri.scheme}://${uri.host}${uri.path}';

Verification

  1. After the fix, the URLs in the u tag should match what server expects
  2. The 401 error should be replaced by successful authentication (200)
  3. Check logs to confirm URL matching

Example

Divine Relay behavior (strips query params):

  • Request URL: https://relay.dvines.org/api/users/abc/notifications?limit=50
  • Server validates against: https://relay.dvines.org/api/users/abc/notifications
  • u tag must be: https://relay.dvines.org/api/users/abc/notifications

Notes

  • The NIP-98 spec is clear about including query params, but not all servers follow it
  • Always check the actual error response to determine server behavior
  • When in doubt, try both approaches and see which works
  • Consider filing a bug with servers that don't follow the spec

References

  • NIP-98 HTTP Auth Specification
  • Spec quote: "The u tag MUST be exactly the same as the absolute request URL (including query parameters)"
  • Reality: Server implementations vary, always check actual behavior

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/nip98-url-query-param-mismatch of divinevideo/divine-mobile.

Open the folder on GitHubat commit c3d6f7e

Compare with similar skills

Nip98 URL Query Param Mismatch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nip98 URL Query Param Mismatch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nip98 URL Query Param Mismatch this skilldivinevideo/divine-mobile266—~920Automated safety check: PassMPL-2.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Gitnexus Exploringaws-samples/sample-kolya-br-proxy10612 repos~749Automated safety check: PassMIT-0
Supabasecurvenote/curvenote1705 repos~2.2kAutomated safety check: PassCustom licence

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Gitnexus Exploring

    aws-samples/sample-kolya-br-proxy

    Official

    A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.

    106 GitHub starsUsed in 12 repos~749 tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    170 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    266 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    266 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    266 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    266 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    266 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    266 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Nip98 URL Query Param Mismatch

What does Nip98 URL Query Param Mismatch do?

Fix NIP-98 HTTP authentication 401 errors caused by URL mismatch between the u tag and what the server expects. Nip98 URL Query Param Mismatch is an agent skill from divinevideo/divine-mobile. Fix NIP-98 HTTP authentication 401 errors caused by URL mismatch between the u tag and what the server expects.

When should I use Nip98 URL Query Param Mismatch?

Nip98 URL Query Param Mismatch fits situations like: NIP-98 auth returns 401 with URL mismatch error; token creation succeeds but server rejects authentication; server logs show expected vs actual URL difference.

How do I install Nip98 URL Query Param Mismatch in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill nip98-url-query-param-mismatch -a claude-code`. Or copy the skill folder (.agents/skills/nip98-url-query-param-mismatch in divinevideo/divine-mobile) into .claude/skills/nip98-url-query-param-mismatch in your project. Claude Code loads it when a task matches its description.

How do I install Nip98 URL Query Param Mismatch in Codex?

Run `npx skills add divinevideo/divine-mobile --skill nip98-url-query-param-mismatch -a codex`. Or copy the skill folder (.agents/skills/nip98-url-query-param-mismatch in divinevideo/divine-mobile) into .agents/skills/nip98-url-query-param-mismatch in your project. Codex loads it when a task matches its description.

Can I use Nip98 URL Query Param Mismatch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill nip98-url-query-param-mismatch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nip98-url-query-param-mismatch, .gemini/skills/nip98-url-query-param-mismatch, .github/skills/nip98-url-query-param-mismatch and .opencode/skills/nip98-url-query-param-mismatch in your project.

What does Nip98 URL Query Param Mismatch need to run?

SKILL.md names no scripts, command-line tools or credentials: Nip98 URL Query Param Mismatch is instructions for the agent only.

Does Nip98 URL Query Param Mismatch access the network?

SKILL.md names 2 domains. In commands or code: relay.dvines.org; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Nip98 URL Query Param Mismatch safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nip98 URL Query Param Mismatch use?

Nip98 URL Query Param Mismatch is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nip98 URL Query Param Mismatch use?

About 920 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nip98 URL Query Param Mismatch?

Skills that share tags, products or a category with Nip98 URL Query Param Mismatch: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Gitnexus Exploring (aws-samples/sample-kolya-br-proxy, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nip98 URL Query Param Mismatch?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 10, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.