Agent skill

OAuth Pkce Sessionstorage Lost On Redirect

by divinevideo in divinevideo/divine-mobile

Fix OAuth PKCE "Session not found" or "No code verifier" errors in SPAs after redirect from external auth server.

MPL-2.0Auto-check passedBackend & APIs

Install OAuth Pkce Sessionstorage Lost On Redirect

skills CLI
$ npx skills add divinevideo/divine-mobile --skill oauth-pkce-sessionstorage-lost-on-redirect -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile oauth-pkce-sessionstorage-lost-on-redirect --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/oauth-pkce-sessionstorage-lost-on-redirect .claude/skills/oauth-pkce-sessionstorage-lost-on-redirect && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oauth-pkce-sessionstorage-lost-on-redirect
GitHub stars
266
Token cost
~974 tokens
SKILL.md length
371 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Fix OAuth PKCE "Session not found" or "No code verifier" errors in SPAs after redirect from external auth server.

  • Works in 4 steps: If the auth server opens a new tab or… → Some browsers (especially Safari with… → If the auth server does multiple… → …
  • OAuth callback fails with session/verifier not found despite flow starting correctly
  • SKILL.md covers Problem, Context / Trigger Conditions, Root Cause and Solution, plus 3 more sections
  • Reaches login.divine.video

What it does

OAuth Pkce Sessionstorage Lost On Redirect is an agent skill from divinevideo/divine-mobile. Fix OAuth PKCE "Session not found" or "No code verifier" errors in SPAs after redirect from external auth server. Use when: (1) OAuth callback fails with session/verifier not found despite flow starting correctly, (2) PKCE codeverifier stored in sessionStorage is missing after redirect back from auth server, (3) Error only happens in production or cross-origin redirects, not in local dev. Root cause: sessionStorage is lost when the browser opens a new tab, changes browsing context, or certain browsers clear it…

Its SKILL.md is about 970 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect. The licence is MPL-2.0.

When your agent uses it

  • OAuth callback fails with session/verifier not found despite flow starting correctly
  • PKCE codeverifier stored in sessionStorage is missing after redirect back from auth server
  • Error only happens in production
  • Cross-origin redirects

Example prompts

  • “Session not found”
  • “No code verifier”
  • “/oauth-pkce-sessionstorage-lost-on-redirect”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. If the auth server opens a new tab or popup, the new tab has empty sessionStorage
  2. Some browsers (especially Safari with ITP) may clear sessionStorage during cross-origin
  3. If the auth server does multiple redirects (302 chains), some browsers treat the
  4. Mobile browsers are particularly aggressive about clearing sessionStorage

What it can do on your machine

Read from SKILL.md and the folder at commit c3d6f7e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • login.divine.video

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

OAuth Pkce Sessionstorage Lost On Redirect loads about 974 tokens when it runs. Until then it costs about 162 tokens; SKILL.md has 371 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~162
When it runs · the whole SKILL.md, loaded when a task matches
~974

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit c3d6f7e, republished under its MPL-2.0 licence (© divinevideo). 371 words, ~974 tokens.

Download SKILL.mdSave it as .claude/skills/oauth-pkce-sessionstorage-lost-on-redirect/SKILL.md (or your agent's skills folder).
name
oauth-pkce-sessionstorage-lost-on-redirect
description
Fix OAuth PKCE "Session not found" or "No code verifier" errors in SPAs after redirect from external auth server. Use when: (1) OAuth callback fails with session/verifier not found despite flow starting correctly, (2) PKCE code_verifier stored in sessionStorage is missing after redirect back from auth server, (3) Error only happens in production or cross-origin redirects, not in local dev. Root cause: sessionStorage is lost when the browser opens a new tab, changes browsing context, or certain browsers clear it during cross-origin navigation. Fix: use localStorage instead (clean up after exchange).
author
Claude Code
version
1.0.0
date
2026-03-23

OAuth PKCE sessionStorage Lost on Redirect

Problem

OAuth PKCE flow fails at the code exchange step because the PKCE code verifier stored in sessionStorage is missing after the redirect from the external authorization server. The error message typically says "Session not found" or "No code verifier found" with no indication that the storage backend is the issue.

Context / Trigger Conditions

  • SPA initiates OAuth PKCE flow, storing code_verifier in sessionStorage
  • User is redirected to external auth server (e.g., login.example.com)
  • Auth server redirects back to SPA callback URL with ?code=...&state=...
  • SPA tries to exchange code but can't find the PKCE verifier
  • Error message is about "session not found" or "missing verifier", NOT about storage
  • Works fine in local development (same-origin), fails in production (cross-origin)

Root Cause

sessionStorage is scoped per-tab AND per-origin, and has additional fragility:

  1. If the auth server opens a new tab or popup, the new tab has empty sessionStorage
  2. Some browsers (especially Safari with ITP) may clear sessionStorage during cross-origin navigation chains
  3. If the auth server does multiple redirects (302 chains), some browsers treat the return as a new browsing context
  4. Mobile browsers are particularly aggressive about clearing sessionStorage

Solution

Switch from sessionStorage to localStorage for the PKCE code verifier storage:

typescript
// BEFORE (fragile)
const client = createOAuthClient({
  storage: sessionStorage,
});

// AFTER (reliable)
const client = createOAuthClient({
  storage: localStorage,
});

The security concern with localStorage (verifier persists longer) is mitigated because:

  • The PKCE verifier is single-use; the auth server rejects it after first exchange
  • Most OAuth SDKs clean up the verifier after successful exchangeCode()
  • getAuthorizationUrl() overwrites any stale verifier on new flow start
Show full SKILL.md (122 more words)Show less

Verification

  1. Start OAuth flow on the SPA
  2. Complete auth on the external server
  3. Callback should successfully exchange the code without "session not found" errors
  4. Check localStorage — the divine_pkce (or equivalent) key should be cleaned up after successful exchange

Example

From @divinevideo/login SDK integration:

typescript
function createClient() {
  return createDivineClient({
    serverUrl: 'https://login.divine.video',
    clientId: 'divine-web',
    redirectUri: buildCallbackUrl(),
    // localStorage survives cross-origin redirects more reliably than sessionStorage
    storage: localStorage,
  });
}

Notes

  • If the OAuth SDK doesn't accept a storage parameter, you may need to manually store/retrieve the verifier in localStorage and pass it to exchangeCode(verifier)
  • Also move any return-path or state data from sessionStorage to localStorage if it needs to survive the redirect
  • In test environments (jsdom/vitest), localStorage may not be fully implemented; provide an in-memory Storage stub in test setup
  • The SDK's README often recommends localStorage — check docs before defaulting to sessionStorage for "security"

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/oauth-pkce-sessionstorage-lost-on-redirect of divinevideo/divine-mobile.

Open the folder on GitHubat commit c3d6f7e

Compare with similar skills

OAuth Pkce Sessionstorage Lost On Redirect next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

OAuth Pkce Sessionstorage Lost On Redirect compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
OAuth Pkce Sessionstorage Lost On Redirect this skilldivinevideo/divine-mobile266—~974Automated safety check: PassMPL-2.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
OmniRoute Provider Managementdiegosouzapw/OmniRoute75k—~2.4kAutomated safety check: PassMIT
Antipattern Preventiondoorkeeper-gem/doorkeeper5.5k—~1.1kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    75k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    173 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    266 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    266 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    266 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    266 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    266 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    266 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about OAuth Pkce Sessionstorage Lost On Redirect

What does OAuth Pkce Sessionstorage Lost On Redirect do?

Fix OAuth PKCE "Session not found" or "No code verifier" errors in SPAs after redirect from external auth server. OAuth Pkce Sessionstorage Lost On Redirect is an agent skill from divinevideo/divine-mobile. Fix OAuth PKCE "Session not found" or "No code verifier" errors in SPAs after redirect from external auth server.

When should I use OAuth Pkce Sessionstorage Lost On Redirect?

OAuth Pkce Sessionstorage Lost On Redirect fits situations like: OAuth callback fails with session/verifier not found despite flow starting correctly; PKCE codeverifier stored in sessionStorage is missing after redirect back from auth server; error only happens in production; cross-origin redirects.

How do I install OAuth Pkce Sessionstorage Lost On Redirect in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill oauth-pkce-sessionstorage-lost-on-redirect -a claude-code`. Or copy the skill folder (.agents/skills/oauth-pkce-sessionstorage-lost-on-redirect in divinevideo/divine-mobile) into .claude/skills/oauth-pkce-sessionstorage-lost-on-redirect in your project. Claude Code loads it when a task matches its description.

How do I install OAuth Pkce Sessionstorage Lost On Redirect in Codex?

Run `npx skills add divinevideo/divine-mobile --skill oauth-pkce-sessionstorage-lost-on-redirect -a codex`. Or copy the skill folder (.agents/skills/oauth-pkce-sessionstorage-lost-on-redirect in divinevideo/divine-mobile) into .agents/skills/oauth-pkce-sessionstorage-lost-on-redirect in your project. Codex loads it when a task matches its description.

Can I use OAuth Pkce Sessionstorage Lost On Redirect in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill oauth-pkce-sessionstorage-lost-on-redirect -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oauth-pkce-sessionstorage-lost-on-redirect, .gemini/skills/oauth-pkce-sessionstorage-lost-on-redirect, .github/skills/oauth-pkce-sessionstorage-lost-on-redirect and .opencode/skills/oauth-pkce-sessionstorage-lost-on-redirect in your project.

What does OAuth Pkce Sessionstorage Lost On Redirect need to run?

SKILL.md names no scripts, command-line tools or credentials: OAuth Pkce Sessionstorage Lost On Redirect is instructions for the agent only.

Does OAuth Pkce Sessionstorage Lost On Redirect access the network?

SKILL.md names 1 domain. In commands or code: login.divine.video; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is OAuth Pkce Sessionstorage Lost On Redirect safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does OAuth Pkce Sessionstorage Lost On Redirect use?

OAuth Pkce Sessionstorage Lost On Redirect is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does OAuth Pkce Sessionstorage Lost On Redirect use?

About 974 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to OAuth Pkce Sessionstorage Lost On Redirect?

Skills that share tags, products or a category with OAuth Pkce Sessionstorage Lost On Redirect: Fortify Development (coollabsio/coolify, 63k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 75k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains OAuth Pkce Sessionstorage Lost On Redirect?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 10, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.