Agent skill

Auth Md

by fabricioctelles in fabricioctelles/skills

Generate, validate, and explain auth.md files — the open protocol for AI agent registration.

Apache-2.0Auto-check passedBackend & APIs

Install Auth Md

skills CLI
$ npx skills add fabricioctelles/skills --skill auth-md -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fabricioctelles/skills auth-md --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auth-md .claude/skills/auth-md && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auth-md
GitHub stars
106
Token cost
~4.4k tokens
SKILL.md length
1,763 words
Files
7 (incl. references)
Skills in repo
15
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate, validate, and explain auth.md files — the open protocol for AI agent registration.

  • Works in 8 steps: Scan the codebase → Ask the user only what cannot be inferred → Generate artifacts → …
  • Making apps agent-ready
  • SKILL.md covers Protocol Context, Operation Modes, Workflow: Generate and Workflow: Validate, plus 10 more sections
  • Calls curl and jq; reaches workos.com and isitagentready.com

What it does

Auth Md is an agent skill from fabricioctelles/skills. Generate, validate, and explain auth.md files — the open protocol for AI agent registration. Use when making apps agent-ready, generating Protected Resource Metadata (RFC 9728), validating auth.md files, or implementing agent registration endpoints. Triggers on "auth.md", "agent registration", "agent auth", "make my app agent-ready", "ID-JAG", "identityassertion", "serviceauth", "protected resource metadata", "agentic registration".

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/example-auth-md.md`, `references/implementation-guide.md` and `references/metadata-schema.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect. The repository describes itself as: A collection of skills for AI agents (Kiro, Cursor, Windsurf, Claude Code, and others). Each skill is a reusable module that teaches the agent to perform complex tasks with… The licence is Apache-2.0.

When your agent uses it

  • Making apps agent-ready
  • Generating Protected Resource Metadata (RFC 9728)
  • Validating auth.md files
  • Implementing agent registration endpoints

Example prompts

  • “auth.md”
  • “agent registration”
  • “agent auth”
  • “/auth-md”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Scan the codebase
  2. Ask the user only what cannot be inferred
  3. Generate artifacts
  4. Generate implementation guidance
  5. Generate Agent Provider guide (if role=provider)
  6. Load the auth.md
  7. Run validation at the requested level
  8. Report results

What it can do on your machine

Read from SKILL.md and the folder at commit f1de632. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • workos.com
    • isitagentready.com
    • service.com
    • auth-md.com
    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auth Md loads about 4.4k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 1,763 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fabricioctelles/skills at commit f1de632, republished under its Apache-2.0 licence (© fabricioctelles). 1,763 words, ~4,402 tokens.

Download SKILL.mdSave it as .claude/skills/auth-md/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
auth-md
description
Generate, validate, and explain `auth.md` files — the open protocol for AI agent registration. Use when making apps agent-ready, generating Protected Resource Metadata (RFC 9728), validating auth.md files, or implementing agent registration endpoints. Triggers on "auth.md", "agent registration", "agent auth", "make my app agent-ready", "ID-JAG", "identity_assertion", "service_auth", "protected resource metadata", "agentic registration".
metadata.author
https://ft.ia.br
metadata.version
2.1
metadata.date
2026-09-20
metadata.repository
https://github.com/fabricioctelles/skills
metadata.license
Apache 2.0
metadata.category
library-and-api-reference
metadata.upstream_commit
b53c9edfbfeea679b617727ebca9ba436bade794

auth-md

Generate, validate, and explain the auth.md protocol — the open standard that lets AI agents register for services on behalf of users, without signup forms.


Protocol Context

auth.md is a Markdown file published at a service's root (typically https://service.com/auth.md) that instructs agents on how to register. It works simultaneously as human-readable documentation and as a discoverable runtime artifact for agents.

The protocol extends RFC 9728 (OAuth 2.0 Protected Resource Metadata) with an agent_auth block in the Authorization Server metadata. Registration returns an identity_assertion (service-signed JWT) that the agent exchanges at /oauth2/token for an access_token. Three registration methods are supported:

FlowMechanismWhen to use
identity_assertionProvider signs an ID-JAG (with auth_time) asserting user identity. Service verifies JWKS, returns identity_assertion. Agent exchanges at /oauth2/token.Service does JIT provisioning from OIDC/SAML; wants zero-friction registration.
service_authEmail hint + browser-based ceremony. Agent receives user_code + verification_uri; user signs in and types code. Agent polls /oauth2/token.Agents on platforms that can't mint ID-JAGs; self-serve without trust list.
anonymousNo identity upfront. Immediate identity_assertion with pre-claim scopes. Optional deferred claim for scope upgrade.Agent needs basic access immediately; human ownership binding deferred.
Protocol Endpoints
EndpointPurpose
/.well-known/oauth-protected-resourceDiscovery — resource metadata (RFC 9728)
/.well-known/oauth-authorization-serverDiscovery — AS metadata with agent_auth block
POST /agent/identityRegistration — dispatches on type field
POST /agent/identity/claimClaim initiation (anonymous deferred, or re-initiate expired user_code)
POST /oauth2/tokenToken exchange (JWT-bearer grant) + claim polling (claim grant)
POST /oauth2/revokeCredential-layer revocation (RFC 7009)
events_endpointRegistration-layer revocation (receives SETs, RFC 8935)
Token Lifecycle

Registration never returns an access_token directly. The flow is:

  1. Registration → identity_assertion (service-signed JWT, reusable until expiry)
  2. Exchange → POST /oauth2/token with grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer → access_token
  3. Refresh → re-exchange same identity_assertion when access_token expires
  4. Expired assertion → restart at registration (Step 3)
Claim Ceremony (v2 — Browser-Based)

The claim ceremony uses RFC 8628-style device authorization:

  1. Registration returns user_code + verification_uri in a claim block
  2. Agent surfaces both to the user
  3. User opens verification_uri, signs in to the service, types the 6-digit code
  4. Agent polls POST /oauth2/token with grant_type=urn:workos:agent-auth:grant-type:claim + claim_token
  5. On success: receives access_token + fresh identity_assertion

Operation Modes

ParameterDefaultDescription
modegenerategenerate = create auth.md + metadata; validate = check existing auth.md; explain = explain the protocol
validation_levelbasicbasic = structure + fields + consistency (offline); full = basic + live endpoint fetch
flowsallWhich flows to include: identity_assertion, service_auth, anonymous, all
roleappPerspective: app = service accepting registrations; provider = platform minting ID-JAGs

Workflow: Generate

1. Scan the codebase

Look for:

  • Existing API routes and authentication patterns
  • Defined scopes/permissions
  • Framework (Express, Django, Rails, FastAPI, NestJS, etc.)
  • Base URL and auth server URL configuration
  • Existing authentication middleware
  • User models and provisioning mechanisms
2. Ask the user only what cannot be inferred
  • Which flows to support (identity_assertion, service_auth, anonymous, or combination)
  • Pre-claim scopes vs post-claim scopes (if anonymous)
  • Trusted agent providers and trust list policy (if identity_assertion)
  • Whether the service already does JIT provisioning or requires manual onboarding
  • idJagMaxAuthAgeSeconds value (default: 3600)
  • Desired rate limiting policy
3. Generate artifacts

Produce three artifacts:

a) auth.md — Markdown file following the protocol template (see references/protocol-template.md). Must contain:

  • Title and intro addressed to the agent
  • Step 1 — Discover (two hops: PRM → AS metadata)
  • Step 2 — Pick a method (decision tree)
  • Step 3 — Register (one subsection per supported method)
  • Step 4 — Claim ceremony (if service_auth or anonymous with claim)
  • Step 5 — Exchange the assertion (POST /oauth2/token with jwt-bearer grant)
  • Step 6 — Use the access_token
  • Errors (complete table with all applicable codes)
  • Revocation (two layers)

b) oauth-protected-resource.json — JSON for /.well-known/oauth-protected-resource with resource_name and resource_logo_uri

c) oauth-authorization-server.json — JSON for /.well-known/oauth-authorization-server with:

  • issuer, token_endpoint, revocation_endpoint, grant_types_supported
  • Complete agent_auth block with identity_endpoint, claim_endpoint, events_endpoint
4. Generate implementation guidance

"Next Steps" section with:

  • How to serve auth.md at the domain root
  • How to serve metadata at the well-known paths
  • How to add WWW-Authenticate header to 401 responses
  • Endpoint implementation guidance (without generating framework-specific code unless requested)
  • Token exchange implementation at /oauth2/token
  • Claim page hosting (verification_uri → login → code input → confirm)
  • Recommended rate limiting configuration
  • Recommended audit events
  • Security considerations (token hashing, auth_time validation, replay protection, claim_token handling)
5. Generate Agent Provider guide (if role=provider)

When the user is an agent provider (not an app), generate:

  • How to mint audience-specific ID-JAGs with auth_time
  • Token structure (header + payload with required and optional claims)
  • How to publish JWKS
  • Optionally: how to publish a CIMD (Client ID Metadata Document)
  • How to implement revocation (POST SET to events_endpoint)
  • How to present consent to the user before asserting identity (using resource_name + resource_logo_uri)

Workflow: Validate

1. Load the auth.md

From a local file path or URL.

2. Run validation at the requested level

Basic (offline):

  • All required headings present (Step 1–6, Errors, Revocation)
  • At least one flow documented
  • Valid JSON in fenced code blocks for request/response shapes
  • AS metadata contains identity_endpoint, token_endpoint, grant_types_supported
  • Error table with standard error codes
  • Consistency: flows in prose match identity_types_supported in metadata JSON
  • No unreplaced placeholders

Full (live):

  • All basic checks, plus:
  • Fetch /.well-known/oauth-protected-resource from the declared base URL
  • Verify agent_auth block exists in AS metadata
  • Fetch /.well-known/oauth-authorization-server and verify consistency
  • Check that identity_endpoint, token_endpoint, revocation_endpoint respond (accept 400/401/422, reject 404/405)
  • Verify API returns 401 with WWW-Authenticate containing resource_metadata
3. Report results

Checklist with ✅/❌ per rule, grouped by category:

  • Structure — headings and order
  • Fields — required fields in JSONs
  • Consistency — cross-references between prose and metadata
  • Format — valid JSON, valid HTTP, no placeholders
  • Endpoints (full only) — reachability and correct responses

Include severity: 🔴 Error (agents will fail), 🟡 Warning (degraded experience), 🟢 Info (suggestion).

See references/validation-rules.md for the complete ruleset.


Workflow: Explain

When the user wants to understand the protocol without generating or validating:

  1. Identify what the user wants to know (overview, specific flow, specific endpoint, security, etc.)
  2. Explain using the protocol context above and the references
  3. Use text-based sequence diagrams when helpful
  4. Point to official documentation when relevant

User Matching and JIT Provisioning

The identity_assertion flow needs to decide which service user a registration represents. Recommended resolution order:

  1. Delegation record match — if (iss, sub) has a delegation on file, route to same user
  2. Verified email match — if a user exists with same verified email BUT no (iss, sub) delegation → interaction_required (401) with claim block for user to confirm linking
  3. Verified phone match — same pattern
  4. No match → JIT — create a new user per provisioning policy, or refuse

Reject ID-JAGs with neither a verified email nor a verified phone — there's no basis for matching.


Show full SKILL.md (713 more words)Show less

Rate Limiting

The /agent/identity endpoint is unauthenticated for anonymous registration. Implement two tiers:

  1. Per-IP (checked first) — prevents a single source from consuming the tenant's budget. Default: 5/hour anonymous, 60/hour identity_assertion.
  2. Per-tenant (checked second) — global cap across IPs. Default: 100/hour anonymous, 1000/hour identity_assertion.

Also rate-limit /oauth2/token polling — enforce interval from the claim block, reject with slow_down if too fast.


EventWhenData
registration.createdSuccessful POST /agent/identityregistration_id, registration_type, iss, sub
registration.interaction_required401 interaction_requiredregistration_id, iss, sub, matched_user_id
registration.login_required401 login_requirediss, sub, auth_time, max_age
claim.initiated/agent/identity/claim calledregistration_id, email
claim.completedUser submitted correct user_coderegistration_id, claimed_by_user_id
claim.expireduser_code window or registration expiredregistration_id
token.exchanged/oauth2/token jwt-bearer successregistration_id, access_token_id
token.revoked/oauth2/revoke calledaccess_token_id
registration.revokedSET processed at events_endpointregistration_id, iss, sub

Security Considerations

  • auth_time validation — auth_time is required in ID-JAGs. Service validates against idJagMaxAuthAgeSeconds. If too old, returns login_required (401) — agent must get user to re-authenticate at provider.
  • claim_token handling — returned exactly once in the registration response. Agent holds in memory only for ceremony duration. Do not persist past Step 4.
  • Token hashing — claim_token is a bearer secret. Store only SHA-256 hash server-side.
  • Consent UX — surface resource_name and resource_logo_uri from PRM to the user before asserting identity. This is the user's only consent gate.
  • Two revocation layers — credential layer (agent-callable, /oauth2/revoke, kills one access_token) vs registration layer (provider-driven SETs at events_endpoint, tears down the whole delegation: identity_assertion + derived tokens + registration + claim handle — not tokens alone; see sample #21).
  • Replay protection — cache jti values with TTL of at least exp - iat + clock skew (typically 6 min).
  • CIMD resolution — if client_id is a URL, fetch as Client ID Metadata Document and verify jwks_uri.
  • Bulk revocation — provide operator-facing mechanism to revoke all outstanding identity_assertions for a tenant.

Error Codes Reference

CodeWhereMeaning
anonymous_not_enabled/agent/identityService doesn't accept anonymous
service_auth_not_enabled/agent/identityservice_auth disabled
issuer_not_enabled/agent/identityProvider not on trust list
invalid_request/agent/identityBody/claim/signature/jti/aud problems
interaction_required (401)/agent/identityID-JAG matched account, no delegation — claim needed
login_required (401)/agent/identityauth_time too old — re-authenticate at provider
invalid_claim_token/agent/identity/claimToken wrong or expired
claimed_or_in_flight/agent/identity/claimAlready claimed or wrong endpoint
claim_expired/agent/identity/claimRegistration expired
invalid_grant/oauth2/tokenAssertion expired/revoked
invalid_client/oauth2/tokenclient_id not recognized
unsupported_grant_type/oauth2/tokenNot jwt-bearer or claim grant
authorization_pending/oauth2/token (claim)User hasn't completed ceremony
expired_token/oauth2/token (claim)user_code window closed
slow_down/oauth2/token (claim)Polling too fast
rate_limited (429)anyBack off and retry

Agent Readiness Scanner Check

The isitagentready.com scanner validates auth.md as the authMd check. Pass criteria:

  1. /auth.md served from site root with HTTP 200
  2. Content is Markdown with H1 heading containing "auth.md"
  3. Optionally validates OAuth Protected Resource Metadata at /.well-known/oauth-protected-resource
  4. Optionally validates Authorization Server metadata at /.well-known/oauth-authorization-server

To pass the check minimally:

markdown
# auth.md

This service accepts AI agent registrations.

## Authentication

Agents can register via POST /agent/identity with a valid ID-JAG.
See below for supported methods.

To pass with full marks (all metadata):

  • Serve /auth.md with proper heading
  • Publish /.well-known/oauth-protected-resource with resource, resource_name, resource_logo_uri, authorization_servers, scopes_supported, bearer_methods_supported: ["header"]
  • Publish /.well-known/oauth-authorization-server with issuer, token_endpoint, revocation_endpoint, grant_types_supported, and agent_auth block containing skill, identity_endpoint, claim_endpoint, events_endpoint, and registration methods

Scan command:

bash
curl -s -X POST 'https://isitagentready.com/api/scan' \
  -H 'Content-Type: application/json' \
  -d '{"url":"https://YOUR-DOMAIN/","enabledChecks":["authMd"]}' | jq '.checks.discovery.authMd'

Quality Checklist

Before delivering output, verify:

  • Generated auth.md contains all required steps (1-6) + Errors + Revocation
  • AS metadata includes issuer, token_endpoint, revocation_endpoint, grant_types_supported
  • agent_auth block includes identity_endpoint, claim_endpoint, events_endpoint
  • identity_types_supported matches the flows the user chose
  • scopes_supported reflects actual API scopes found in codebase
  • Base URLs are consistent between auth.md and metadata JSON
  • Error codes table includes all standard codes for the supported flows
  • Step 5 documents token exchange at /oauth2/token with jwt-bearer grant
  • Revocation section documents both layers (credential + registration)
  • No unreplaced placeholder values ({{...}}, <your-...>, [YOUR_...])
  • Validation report covers all rules for the requested level
  • Rate limiting documented (including /oauth2/token polling)
  • Security considerations included (auth_time, claim_token, consent UX)
  • If role=provider: ID-JAG structure with auth_time documented

References

  • references/protocol-template.md — Complete auth.md template with all sections and placeholders
  • references/validation-rules.md — Full validation ruleset with error messages and severities
  • references/metadata-schema.md — JSON schema for PRM, AS metadata, ID-JAG, and identity_assertion
  • references/example-auth-md.md — Working example of a complete auth.md file (Acme Notes)
  • references/implementation-guide.md — Server-side implementation guide with token exchange, claim ceremony, revocation, and security

Updating Protocol Knowledge

This skill ships with a snapshot of the auth.md protocol specification (v2, June 2026). When possible, fetch the latest version from:

  • Skill Home and Doc Hub: https://auth-md.com
  • Spec: https://raw.githubusercontent.com/workos/auth.md/refs/heads/main/AUTH.md
  • Docs overview: https://workos.com/auth-md/docs
  • Apps guide: https://workos.com/auth-md/docs/apps
  • Agent providers guide: https://workos.com/auth-md/docs/agent-providers
  • File anatomy: https://workos.com/auth-md/docs/auth-md

If fetch fails, use the bundled references/ as the source of truth.

© fabricioctelles, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/auth-md of fabricioctelles/skills.

  • SKILL.md
  • UPSTREAM_COMMIT
  • references/example-auth-md.md
  • references/implementation-guide.md
  • references/metadata-schema.md
  • references/protocol-template.md
  • references/validation-rules.md

Open the folder on GitHubat commit f1de632

Compare with similar skills

Auth Md next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auth Md compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auth Md this skillfabricioctelles/skills106—~4.4kAutomated safety check: PassApache-2.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
OmniRoute Provider Managementdiegosouzapw/OmniRoute75k—~2.4kAutomated safety check: PassMIT
Antipattern Preventiondoorkeeper-gem/doorkeeper5.5k—~1.1kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    75k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    173 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed

More from fabricioctelles/skills

All 15 skills in this repo
  • Motion Ad

    fabricioctelles/skills

    Produce a short motion-graphics video ad — a 15s Facebook/Instagram/TikTok spot — as a rendered MP4.

    106 GitHub stars~4.1k tokensUpdated 6 days ago
    Auto-check passed
  • Agent Plugin Eval

    fabricioctelles/skills

    Audit, score, and compare repositories containing portable Agent Plugins against the official Agent Plugins specification.

    106 GitHub stars~2.1k tokensUpdated 6 days ago
    Auto-check passed
  • Loop Architect

    fabricioctelles/skills

    Design well-structured agent loops with best-practice coaching and cross-model review gates before you run them.

    106 GitHub stars~2.1k tokensUpdated 6 days ago
    Auto-check: notes
  • Pier Cloud

    fabricioctelles/skills

    This skill should be used when the user needs to consume the Pier Cloud (Lighthouse) API for cloud cost management — including JWT authentication, listing contexts, workspaces, workspace groups, and…

    106 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check: notes
  • Ralph Loop Kiro Specs

    fabricioctelles/skills

    Automated iterative agent runner for spec-based development in Kiro.

    106 GitHub stars~2.6k tokensUpdated 6 days ago
    Auto-check passed
  • Security Specialist

    fabricioctelles/skills

    Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.

    106 GitHub stars~2.8k tokensUpdated 6 days ago
    Auto-check passed

Categories

Questions about Auth Md

What does Auth Md do?

Generate, validate, and explain auth.md files — the open protocol for AI agent registration. Auth Md is an agent skill from fabricioctelles/skills.md files — the open protocol for AI agent registration.

When should I use Auth Md?

Auth Md fits situations like: making apps agent-ready; generating Protected Resource Metadata (RFC 9728); validating auth.md files; implementing agent registration endpoints.

How do I install Auth Md in Claude Code?

Run `npx skills add fabricioctelles/skills --skill auth-md -a claude-code`. Or copy the skill folder (skills/auth-md in fabricioctelles/skills) into .claude/skills/auth-md in your project. Claude Code loads it when a task matches its description.

How do I install Auth Md in Codex?

Run `npx skills add fabricioctelles/skills --skill auth-md -a codex`. Or copy the skill folder (skills/auth-md in fabricioctelles/skills) into .agents/skills/auth-md in your project. Codex loads it when a task matches its description.

Can I use Auth Md in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fabricioctelles/skills --skill auth-md -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth-md, .gemini/skills/auth-md, .github/skills/auth-md and .opencode/skills/auth-md in your project.

What does Auth Md need to run?

Going by SKILL.md and its folder, Auth Md needs the command-line tools its instructions call (curl and jq).

Does Auth Md access the network?

SKILL.md names 5 domains. In commands or code: workos.com, isitagentready.com, service.com, auth-md.com and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Auth Md safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auth Md use?

Auth Md is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auth Md use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Auth Md?

Skills that share tags, products or a category with Auth Md: Fortify Development (coollabsio/coolify, 63k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 75k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auth Md?

fabricioctelles (a GitHub user) maintains it in fabricioctelles/skills, which has 106 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 4, 2026.

Source: fabricioctelles/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.