Agent skill

Spa Auth Development

by gdarko in gdarko/laravel-vue-starter

Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

MITAuto-check: notesBackend & APIs

Install Spa Auth Development

skills CLI
$ npx skills add gdarko/laravel-vue-starter --skill spa-auth-development -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gdarko/laravel-vue-starter spa-auth-development --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gdarko/laravel-vue-starter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.junie/skills/spa-auth-development .claude/skills/spa-auth-development && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spa-auth-development
GitHub stars
145
Token cost
~668 tokens
SKILL.md length
245 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

  • Works in 5 steps: Vue app calls GET /sanctum/csrf-cookie… → User submits login form → POST /login… → Laravel returns session cookie + user data → …
  • Tasks that involve Backend development
  • SKILL.md covers Auth Flow, Key Files, CORS Configuration and Route Guards, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Spa Auth Development is an agent skill from gdarko/laravel-vue-starter. Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration. Covers the full auth lifecycle from CSRF cookie to protected API calls.

Its SKILL.md is about 670 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development, Web application vulnerabilities and Authentication. It works with Vue.js, Laravel, Tailwind CSS and PHP. The repository describes itself as: AI-native Laravel/Vue boilerplate. Tailwind + DaisyUI, Sanctum, Fortify, Pinia. Built-in agent skills for Claude Code, Cursor, Copilot, Gemini & Junie. The licence is MIT.

When your agent uses it

  • Tasks that involve Backend development
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Authentication

Example prompts

  • “/spa-auth-development”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Vue app calls GET /sanctum/csrf-cookie to get XSRF token
  2. User submits login form → POST /login (Fortify handles this)
  3. Laravel returns session cookie + user data
  4. All subsequent API calls include the session cookie automatically (withCredentials: true)
  5. Protected routes use auth:sanctum middleware

What it can do on your machine

Read from SKILL.md and the folder at commit 2b8eb53. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spa Auth Development loads about 668 tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 245 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~668

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:40
    For the SPA to work, these `.env` values must match:

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gdarko/laravel-vue-starter at commit 2b8eb53, republished under its MIT licence (© gdarko). 245 words, ~668 tokens.

Download SKILL.mdSave it as .claude/skills/spa-auth-development/SKILL.md (or your agent's skills folder).
name
spa-auth-development
description
Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration. Covers the full auth lifecycle from CSRF cookie to protected API calls.
license
MIT
metadata.author
project

SPA Authentication Development

This project uses a decoupled SPA architecture where Vue handles all routing and Laravel serves as a JSON API with Sanctum cookie-based authentication.

Auth Flow

  1. Vue app calls GET /sanctum/csrf-cookie to get XSRF token
  2. User submits login form → POST /login (Fortify handles this)
  3. Laravel returns session cookie + user data
  4. All subsequent API calls include the session cookie automatically (withCredentials: true)
  5. Protected routes use auth:sanctum middleware

Key Files

Backend
  • config/sanctum.php — Stateful domains, guards, CSRF middleware
  • config/cors.php — CORS paths (api/*, login, logout, register, etc.) with supports_credentials: true
  • config/fortify.php — Auth features (registration, password reset, email verification)
  • app/Providers/FortifyServiceProvider.php — Binds Fortify actions and custom LoginResponse
  • app/Http/Responses/LoginResponse.php — Returns JSON with user data for SPA
  • app/Http/Middleware/ApplyLocale.php — Sets locale from X-Locale header
  • bootstrap/app.php — statefulApi() middleware, apply_locale alias
Frontend
  • stores/auth.js — Pinia store with login, register, logout, getCurrentUser
  • services/AuthService.ts — API calls for auth endpoints (login, register, forgot/reset password, etc.)
  • router/index.js — Navigation guards checking requiresAuth and requiresAbility route meta
  • plugins/axios.js — Axios configured with withCredentials, X-Locale header, base URL from window.AppConfig

CORS Configuration

For the SPA to work, these .env values must match:

APP_URL=http://localhost:8000
SANCTUM_STATEFUL_DOMAINS=localhost:8000
SESSION_DOMAIN=localhost

Route Guards

Routes use meta fields for auth:

  • requiresAuth: true — Redirects to login if not authenticated
  • requiresAbility: 'ability_name' — Checks user abilities via Bouncer
  • isPublicAuthPage: true — Redirects to dashboard if already authenticated
  • isOwner: true — Owner-only routes

Authorization

Uses Silber Bouncer with abilities:

  • Abilities defined in resources/app/stub/abilities.js (CREATE_USER, EDIT_USER, etc.)
  • Checked in Vue Router guards and sidebar menu visibility
  • Backend uses Gate::authorize() in controllers
  • Roles seeded in database/seeders/BouncerSeeder.php

© gdarko, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .junie/skills/spa-auth-development of gdarko/laravel-vue-starter.

Open the folder on GitHubat commit 2b8eb53

Compare with similar skills

Spa Auth Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spa Auth Development compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spa Auth Development this skillgdarko/laravel-vue-starter145—~668Automated safety check: NotesMIT
Passport Developmenttrypostit/trypost678—~1.9kAutomated safety check: PassMIT
MCP Developmentcoollabsio/coolify63k1 repos~949Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Livewire Developmentcoollabsio/coolify63k—~964Automated safety check: PassMIT
Livewire Developmentyungifez/skuul4091 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    678 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Livewire Development

    coollabsio/coolify

    A skill your agent uses for any task or question involving Livewire.

    63k GitHub stars~964 tokensUpdated today
    Backend & APIsAuto-check passed
  • Livewire Development

    yungifez/skuul

    A skill your agent uses for any task or question involving Livewire.

    409 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed

More from gdarko/laravel-vue-starter

  • Medialibrary Development

    gdarko/laravel-vue-starter

    Build and work with spatie/laravel-medialibrary features including associating files with Eloquent models, defining media collections and conversions, generating responsive images, and retrieving…

    145 GitHub starsUsed in 3 repos~880 tokens
    Auto-check passed
  • Vue Component Development

    gdarko/laravel-vue-starter

    Activate when creating or modifying Vue 3 components, pages, layouts, stores, or services in the frontend.

    145 GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Spa Auth Development

What does Spa Auth Development do?

Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration. Spa Auth Development is an agent skill from gdarko/laravel-vue-starter. Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

When should I use Spa Auth Development?

Spa Auth Development fits situations like: tasks that involve Backend development; tasks that involve Web application vulnerabilities; tasks that involve Authentication.

How do I install Spa Auth Development in Claude Code?

Run `npx skills add gdarko/laravel-vue-starter --skill spa-auth-development -a claude-code`. Or copy the skill folder (.junie/skills/spa-auth-development in gdarko/laravel-vue-starter) into .claude/skills/spa-auth-development in your project. Claude Code loads it when a task matches its description.

How do I install Spa Auth Development in Codex?

Run `npx skills add gdarko/laravel-vue-starter --skill spa-auth-development -a codex`. Or copy the skill folder (.junie/skills/spa-auth-development in gdarko/laravel-vue-starter) into .agents/skills/spa-auth-development in your project. Codex loads it when a task matches its description.

Can I use Spa Auth Development in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gdarko/laravel-vue-starter --skill spa-auth-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spa-auth-development, .gemini/skills/spa-auth-development, .github/skills/spa-auth-development and .opencode/skills/spa-auth-development in your project.

What does Spa Auth Development need to run?

SKILL.md names no scripts, command-line tools or credentials: Spa Auth Development is instructions for the agent only.

Does Spa Auth Development access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spa Auth Development safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Spa Auth Development use?

Spa Auth Development is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spa Auth Development use?

About 668 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spa Auth Development?

Skills that share tags, products or a category with Spa Auth Development: Passport Development (trypostit/trypost, 678 stars), MCP Development (coollabsio/coolify, 63k stars), Fortify Development (coollabsio/coolify, 63k stars) and Livewire Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spa Auth Development?

gdarko (a GitHub user) maintains it in gdarko/laravel-vue-starter, which has 145 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on April 1, 2026.

Source: gdarko/laravel-vue-starter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.