Agent skill

Two Factor Authentication Best Practices

by ever-works in ever-works/ever-works

Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.

AGPL-3.0Auto-check passedBackend & APIs

Install Two Factor Authentication Best Practices

skills CLI
$ npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ever-works/ever-works two-factor-authentication-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/two-factor-authentication-best-practices .claude/skills/two-factor-authentication-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
two-factor-authentication-best-practices
GitHub stars
158
Used in
2 other repos
Token cost
~1.8k tokens
SKILL.md length
301 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.

  • Works in 4 steps: Add twoFactor() plugin to server config… → Add twoFactorClient() plugin to client… → Run npx @better-auth/cli migrate → …
  • Multi-factor authentication
  • SKILL.md covers Setup, Enabling 2FA for Users, TOTP (Authenticator App) and OTP (Email/SMS), plus 6 more sections
  • Calls npx

What it does

Two Factor Authentication Best Practices is an agent skill from ever-works/ever-works. Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with Better Auth. The repository describes itself as: Ever® Works™ - The Workshop for AI. An open agentic runtime that autonomously researches, ships, and maintains entire businesses, 24/7 - https://ever.works. The licence is AGPL-3.0.

When your agent uses it

  • Multi-factor authentication
  • Authenticator setup
  • Login security with Better Auth

Example prompts

  • “/two-factor-authentication-best-practices”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Add twoFactor() plugin to server config with issuer
  2. Add twoFactorClient() plugin to client config
  3. Run npx @better-auth/cli migrate
  4. Verify: check that twoFactorSecret column exists on user table

What it can do on your machine

Read from SKILL.md and the folder at commit 11d15aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Two Factor Authentication Best Practices loads about 1.8k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 301 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ever-works/ever-works at commit 11d15aa, republished under its AGPL-3.0 licence (© ever-works). 301 words, ~1,803 tokens.

Download SKILL.mdSave it as .claude/skills/two-factor-authentication-best-practices/SKILL.md (or your agent's skills folder).
name
two-factor-authentication-best-practices
description
Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.

Setup

  1. Add twoFactor() plugin to server config with issuer
  2. Add twoFactorClient() plugin to client config
  3. Run npx @better-auth/cli migrate
  4. Verify: check that twoFactorSecret column exists on user table
ts
import { betterAuth } from 'better-auth';
import { twoFactor } from 'better-auth/plugins';

export const auth = betterAuth({
	appName: 'My App',
	plugins: [
		twoFactor({
			issuer: 'My App'
		})
	]
});
Client-Side Setup
ts
import { createAuthClient } from 'better-auth/client';
import { twoFactorClient } from 'better-auth/client/plugins';

export const authClient = createAuthClient({
	plugins: [
		twoFactorClient({
			onTwoFactorRedirect() {
				window.location.href = '/2fa';
			}
		})
	]
});

Enabling 2FA for Users

Requires password verification. Returns TOTP URI (for QR code) and backup codes.

ts
const enable2FA = async (password: string) => {
	const { data, error } = await authClient.twoFactor.enable({
		password
	});

	if (data) {
		// data.totpURI — generate a QR code from this
		// data.backupCodes — display to user
	}
};

twoFactorEnabled is not set to true until first TOTP verification succeeds. Override with skipVerificationOnEnable: true (not recommended).

TOTP (Authenticator App)

Displaying the QR Code
tsx
import QRCode from 'react-qr-code';

const TotpSetup = ({ totpURI }: { totpURI: string }) => {
	return <QRCode value={totpURI} />;
};
Verifying TOTP Codes

Accepts codes from one period before/after current time:

ts
const verifyTotp = async (code: string) => {
	const { data, error } = await authClient.twoFactor.verifyTotp({
		code,
		trustDevice: true
	});
};
TOTP Configuration Options
ts
twoFactor({
	totpOptions: {
		digits: 6, // 6 or 8 digits (default: 6)
		period: 30 // Code validity period in seconds (default: 30)
	}
});

OTP (Email/SMS)

Configuring OTP Delivery
ts
import { betterAuth } from 'better-auth';
import { twoFactor } from 'better-auth/plugins';
import { sendEmail } from './email';

export const auth = betterAuth({
	plugins: [
		twoFactor({
			otpOptions: {
				sendOTP: async ({ user, otp }, ctx) => {
					await sendEmail({
						to: user.email,
						subject: 'Your verification code',
						text: `Your code is: ${otp}`
					});
				},
				period: 5, // Code validity in minutes (default: 3)
				digits: 6, // Number of digits (default: 6)
				allowedAttempts: 5 // Max verification attempts (default: 5)
			}
		})
	]
});
Sending and Verifying OTP

Send: authClient.twoFactor.sendOtp(). Verify: authClient.twoFactor.verifyOtp({ code, trustDevice: true }).

OTP Storage Security

Configure how OTP codes are stored in the database:

ts
twoFactor({
	otpOptions: {
		storeOTP: 'encrypted' // Options: "plain", "encrypted", "hashed"
	}
});

For custom encryption:

ts
twoFactor({
	otpOptions: {
		storeOTP: {
			encrypt: async (token) => myEncrypt(token),
			decrypt: async (token) => myDecrypt(token)
		}
	}
});

Backup Codes

Generated automatically when 2FA is enabled. Each code is single-use.

Displaying Backup Codes
tsx
const BackupCodes = ({ codes }: { codes: string[] }) => {
	return (
		<div>
			<p>Save these codes in a secure location:</p>
			<ul>
				{codes.map((code, i) => (
					<li key={i}>{code}</li>
				))}
			</ul>
		</div>
	);
};
Regenerating Backup Codes

Invalidates all previous codes:

ts
const regenerateBackupCodes = async (password: string) => {
	const { data, error } = await authClient.twoFactor.generateBackupCodes({
		password
	});
	// data.backupCodes contains the new codes
};
Using Backup Codes for Recovery
ts
const verifyBackupCode = async (code: string) => {
	const { data, error } = await authClient.twoFactor.verifyBackupCode({
		code,
		trustDevice: true
	});
};
Backup Code Configuration
ts
twoFactor({
	backupCodeOptions: {
		amount: 10, // Number of codes to generate (default: 10)
		length: 10, // Length of each code (default: 10)
		storeBackupCodes: 'encrypted' // Options: "plain", "encrypted"
	}
});

Handling 2FA During Sign-In

Response includes twoFactorRedirect: true when 2FA is required:

Sign-In Flow
  1. Call signIn.email({ email, password })
  2. Check context.data.twoFactorRedirect in onSuccess
  3. If true, redirect to /2fa verification page
  4. Verify via TOTP, OTP, or backup code
  5. Session cookie is created on successful verification
ts
const signIn = async (email: string, password: string) => {
	const { data, error } = await authClient.signIn.email(
		{ email, password },
		{
			onSuccess(context) {
				if (context.data.twoFactorRedirect) {
					window.location.href = '/2fa';
				}
			}
		}
	);
};

Server-side: check "twoFactorRedirect" in response when using auth.api.signInEmail.

Trusted Devices

Pass trustDevice: true when verifying. Default trust duration: 30 days (trustDeviceMaxAge). Refreshes on each sign-in.

Security Considerations

Session Management

Flow: credentials → session removed → temporary 2FA cookie (10 min default) → verify → session created.

ts
twoFactor({
	twoFactorCookieMaxAge: 600 // 10 minutes in seconds (default)
});
Rate Limiting

Built-in: 3 requests per 10 seconds for all 2FA endpoints. OTP has additional attempt limiting:

ts
twoFactor({
	otpOptions: {
		allowedAttempts: 5 // Max attempts per OTP code (default: 5)
	}
});
Encryption at Rest

TOTP secrets: encrypted with auth secret. Backup codes: encrypted by default. OTP: configurable ("plain", "encrypted", "hashed"). Uses constant-time comparison for verification.

2FA can only be enabled for credential (email/password) accounts.

Disabling 2FA

Requires password confirmation. Revokes trusted device records:

ts
const disable2FA = async (password: string) => {
	const { data, error } = await authClient.twoFactor.disable({
		password
	});
};

Complete Configuration Example

ts
import { betterAuth } from 'better-auth';
import { twoFactor } from 'better-auth/plugins';
import { sendEmail } from './email';

export const auth = betterAuth({
	appName: 'My App',
	plugins: [
		twoFactor({
			// TOTP settings
			issuer: 'My App',
			totpOptions: {
				digits: 6,
				period: 30
			},
			// OTP settings
			otpOptions: {
				sendOTP: async ({ user, otp }) => {
					await sendEmail({
						to: user.email,
						subject: 'Your verification code',
						text: `Your code is: ${otp}`
					});
				},
				period: 5,
				allowedAttempts: 5,
				storeOTP: 'encrypted'
			},
			// Backup code settings
			backupCodeOptions: {
				amount: 10,
				length: 10,
				storeBackupCodes: 'encrypted'
			},
			// Session settings
			twoFactorCookieMaxAge: 600, // 10 minutes
			trustDeviceMaxAge: 30 * 24 * 60 * 60 // 30 days
		})
	]
});

© ever-works, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/two-factor-authentication-best-practices of ever-works/ever-works.

Open the folder on GitHubat commit 11d15aa

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in ever-works/ever-works, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Two Factor Authentication Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Two Factor Authentication Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Two Factor Authentication Best Practices this skillever-works/ever-works1582 repos~1.8kAutomated safety check: PassAGPL-3.0
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Neon Authneondatabase/agent-skills100—~3.1kAutomated safety check: PassApache-2.0
Workosusenotra/notra256—~6.2kAutomated safety check: PassAGPL-3.0
Lunora Setup Authanolilab/lunora283—~2.8kAutomated safety check: PassCustom licence
Authenticationlatitude-dev/latitude-llm4.7k—~303Automated safety check: PassMIT

Similar skills

  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Neon Auth

    neondatabase/agent-skills

    Official

    Add authentication to a new app. An agent skill from neondatabase/agent-skills.

    100 GitHub stars~3.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    256 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Lunora Setup Auth

    anolilab/lunora

    Adds authentication to a Lunora app with the auth registry item (better-auth via @lunora/auth, users and sessions in D1).

    283 GitHub stars~2.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Authentication

    latitude-dev/latitude-llm

    Sessions, sign-in/sign-up flows, OAuth, magic links, or organization context on the session.

    4.7k GitHub stars~303 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Better Auth

    giuseppe-trisciuoglio/developer-kit

    Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL.

    355 GitHub stars~2.4k tokensUpdated 28 days ago
    Backend & APIsAuto-check: notes

More from ever-works/ever-works

All 14 skills in this repo
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 18 repos~4k tokens
    Auto-check passed
  • Accessibility

    ever-works/ever-works

    Audit and improve web accessibility following WCAG 2.2 guidelines.

    158 GitHub starsUsed in 6 repos~3.2k tokens
    Auto-check passed
  • Tailwind CSS Patterns

    ever-works/ever-works

    Provides comprehensive Tailwind CSS utility-first styling patterns including responsive design, layout utilities, flexbox, grid, spacing, typography, colors, and modern CSS best practices.

    158 GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check: notes
  • SEO

    ever-works/ever-works

    Optimize for search engine visibility and ranking. An agent skill from ever-works/ever-works.

    158 GitHub starsUsed in 10 repos~2.9k tokens
    Auto-check passed
  • Nodejs Express Server

    ever-works/ever-works

    Build production-ready Express.js servers with middleware, authentication, routing, and database integration.

    158 GitHub stars~965 tokensUpdated 3 days ago
    Auto-check passed
  • Tailwind V4 Shadcn

    ever-works/ever-works

    Production-tested setup for Tailwind CSS v4 with shadcn/ui, Vite, and React.

    158 GitHub starsUsed in 2 repos~3.8k tokens
    Auto-check passed

Works with

Categories

Questions about Two Factor Authentication Best Practices

What does Two Factor Authentication Best Practices do?

Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Two Factor Authentication Best Practices is an agent skill from ever-works/ever-works. Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.

When should I use Two Factor Authentication Best Practices?

Two Factor Authentication Best Practices fits situations like: multi-factor authentication; authenticator setup; login security with Better Auth.

How do I install Two Factor Authentication Best Practices in Claude Code?

Run `npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/two-factor-authentication-best-practices in ever-works/ever-works) into .claude/skills/two-factor-authentication-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Two Factor Authentication Best Practices in Codex?

Run `npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a codex`. Or copy the skill folder (.agents/skills/two-factor-authentication-best-practices in ever-works/ever-works) into .agents/skills/two-factor-authentication-best-practices in your project. Codex loads it when a task matches its description.

Can I use Two Factor Authentication Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/two-factor-authentication-best-practices, .gemini/skills/two-factor-authentication-best-practices, .github/skills/two-factor-authentication-best-practices and .opencode/skills/two-factor-authentication-best-practices in your project.

What does Two Factor Authentication Best Practices need to run?

Going by SKILL.md and its folder, Two Factor Authentication Best Practices needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Two Factor Authentication Best Practices access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Two Factor Authentication Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Two Factor Authentication Best Practices use?

Two Factor Authentication Best Practices is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Two Factor Authentication Best Practices use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Two Factor Authentication Best Practices?

Skills that share tags, products or a category with Two Factor Authentication Best Practices: Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Neon Auth (neondatabase/agent-skills, 100 stars), Workos (usenotra/notra, 256 stars) and Lunora Setup Auth (anolilab/lunora, 283 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Two Factor Authentication Best Practices?

ever-works (a GitHub organization) maintains it in ever-works/ever-works, which has 158 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 5, 2026.

Source: ever-works/ever-works on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.