Agent skill

Spring Boot Security JWT

by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit

Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

MITAuto-check: notesBackend & APIs

Install Spring Boot Security JWT

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-security-jwt -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit spring-boot-security-jwt --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-java/skills/spring-boot-security-jwt .claude/skills/spring-boot-security-jwt && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spring-boot-security-jwt
GitHub stars
357
Token cost
~3.9k tokens
SKILL.md length
962 words
Files
21 (incl. scripts, references, assets)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

  • Works in 9 steps: Add Dependencies → Configure application.yml → Implement JwtService → …
  • Implementing authentication
  • SKILL.md covers Overview, When to Use, Quick Reference and Instructions, plus 4 more sections
  • Runs Shell scripts from its folder; needs JWT_SECRET

What it does

Spring Boot Security JWT is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 22 other files, including scripts, reference files and assets (for example `assets/generate-jwt-keys.sh`, `references/authorization-patterns.md` and `references/configuration.md`).

It sits in Backend & APIs, covering Authentication, Authorization and RBAC and Backend development. It works with Spring Boot. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Implementing authentication
  • Authorization in Spring Boot applications

Example prompts

  • “Use the spring-boot-security-jwt skill to provide JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with…”
  • “/spring-boot-security-jwt”

Requirements

  • A Bash shell
  • A credential in JWT_SECRET
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Glob, Grep

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Add Dependencies
  2. Configure application.yml
  3. Implement JwtService
  4. Create JwtAuthenticationFilter
  5. Configure SecurityFilterChain
  6. Create Authentication Endpoints
  7. Implement Refresh Token Strategy
  8. Add Authorization Rules
  9. Write Security Tests

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spring Boot Security JWT loads about 3.9k tokens when it runs, and up to ~102k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 962 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~102k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 962 words, ~3,862 tokens.

Download SKILL.mdSave it as .claude/skills/spring-boot-security-jwt/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.
name
spring-boot-security-jwt
description
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
allowed-tools
Read, Write, Edit, Bash, Glob, Grep

Spring Boot JWT Security

JWT authentication and authorization patterns for Spring Boot 3.5.x using Spring Security 6.x and JJWT. Covers token generation, validation, refresh strategies, RBAC/ABAC, and OAuth2 integration.

Overview

This skill provides implementation patterns for stateless JWT authentication in Spring Boot applications. It covers the complete authentication flow including token generation with JJWT 0.12.6, Bearer/cookie-based authentication, refresh token rotation, and method-level authorization with @PreAuthorize expressions.

Key capabilities:

  • Access and refresh token generation with configurable expiration
  • Bearer token and HttpOnly cookie authentication strategies
  • Integration with Spring Data JPA and OAuth2 providers
  • RBAC with role/permission-based @PreAuthorize rules
  • Token revocation and blacklisting for logout/rotation

When to Use

Activate when user requests involve:

  • "Implement JWT authentication", "secure REST API with tokens"
  • "Spring Security 6.x configuration", "SecurityFilterChain setup"
  • "Role-based access control", "RBAC", `@PreAuthorize`
  • "Refresh token", "token rotation", "token revocation"
  • "OAuth2 integration", "social login", "Google/GitHub auth"
  • "Stateless authentication", "SPA backend security"
  • "JWT filter", "OncePerRequestFilter", "Bearer token"
  • "Cookie-based JWT", "HttpOnly cookie"
  • "Permission-based access control", "custom PermissionEvaluator"

Quick Reference

Dependencies (JJWT 0.12.6)
ArtifactScope
spring-boot-starter-securitycompile
spring-boot-starter-oauth2-resource-servercompile
io.jsonwebtoken:jjwt-api:0.12.6compile
io.jsonwebtoken:jjwt-impl:0.12.6runtime
io.jsonwebtoken:jjwt-jackson:0.12.6runtime
spring-security-testtest

See references/jwt-quick-reference.md for Maven and Gradle snippets.

Key Configuration Properties
PropertyExample ValueNotes
jwt.secret${JWT_SECRET}Min 256 bits, never hardcode
jwt.access-token-expiration90000015 min in milliseconds
jwt.refresh-token-expiration6048000007 days in milliseconds
jwt.issuermy-appValidated on every token
jwt.cookie-namejwt-tokenFor cookie-based auth
jwt.cookie-http-onlytrueAlways true in production
jwt.cookie-securetrueAlways true with HTTPS
Authorization Annotations
AnnotationExample
@PreAuthorize("hasRole('ADMIN')")Role check
@PreAuthorize("hasAuthority('USER_READ')")Permission check
@PreAuthorize("hasPermission(#id, 'Doc', 'READ')")Domain object check
@PreAuthorize("@myService.canAccess(#id)")Spring bean check

Instructions

Step 1 — Add Dependencies

Include spring-boot-starter-security, spring-boot-starter-oauth2-resource-server, and the three JJWT artifacts in your build file. See references/jwt-quick-reference.md for exact Maven/Gradle snippets.

Step 2 — Configure application.yml
yaml
jwt:
  secret: ${JWT_SECRET:change-me-min-32-chars-in-production}
  access-token-expiration: 900000
  refresh-token-expiration: 604800000
  issuer: my-app
  cookie-name: jwt-token
  cookie-http-only: true
  cookie-secure: false   # true in production

See references/jwt-complete-configuration.md for the full properties reference.

Step 3 — Implement JwtService

Core operations: generate access token, generate refresh token, extract username, validate token.

java
@Service
public class JwtService {

    public String generateAccessToken(UserDetails userDetails) {
        return Jwts.builder()
            .subject(userDetails.getUsername())
            .issuer(issuer)
            .issuedAt(new Date())
            .expiration(new Date(System.currentTimeMillis() + accessTokenExpiration))
            .claim("authorities", getAuthorities(userDetails))
            .signWith(getSigningKey())
            .compact();
    }

    public boolean isTokenValid(String token, UserDetails userDetails) {
        try {
            String username = extractUsername(token);
            return username.equals(userDetails.getUsername()) && !isTokenExpired(token);
        } catch (JwtException e) {
            return false;
        }
    }
}

See references/jwt-complete-configuration.md for the complete JwtService including key management and claim extraction.

Step 4 — Create JwtAuthenticationFilter

Extend OncePerRequestFilter to extract a JWT from the Authorization: Bearer header (or HttpOnly cookie), validate it, and set the SecurityContext.

java
@Component
public class JwtAuthenticationFilter extends OncePerRequestFilter {

    @Override
    protected void doFilterInternal(HttpServletRequest request,
            HttpServletResponse response, FilterChain chain)
            throws ServletException, IOException {
        String authHeader = request.getHeader("Authorization");
        if (authHeader == null || !authHeader.startsWith("Bearer ")) {
            chain.doFilter(request, response);
            return;
        }
        String jwt = authHeader.substring(7);
        String username = jwtService.extractUsername(jwt);
        if (username != null && SecurityContextHolder.getContext().getAuthentication() == null) {
            UserDetails userDetails = userDetailsService.loadUserByUsername(username);
            if (jwtService.isTokenValid(jwt, userDetails)) {
                UsernamePasswordAuthenticationToken authToken =
                    new UsernamePasswordAuthenticationToken(
                        userDetails, null, userDetails.getAuthorities());
                authToken.setDetails(new WebAuthenticationDetailsSource().buildDetails(request));
                SecurityContextHolder.getContext().setAuthentication(authToken);
            }
        }
        chain.doFilter(request, response);
    }
}

See references/configuration.md for the cookie-based variant.

Step 5 — Configure SecurityFilterChain
java
@Configuration
@EnableWebSecurity
@EnableMethodSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        return http
            .csrf(AbstractHttpConfigurer::disable)
            .sessionManagement(s -> s.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/api/auth/**", "/swagger-ui/**").permitAll()
                .anyRequest().authenticated()
            )
            .authenticationProvider(authenticationProvider)
            .addFilterBefore(jwtAuthFilter, UsernamePasswordAuthenticationFilter.class)
            .build();
    }
}

See references/jwt-complete-configuration.md for CORS, logout handler, and OAuth2 login integration.

Step 6 — Create Authentication Endpoints

Expose /register, /authenticate, /refresh, and /logout via @RestController. Return accessToken + refreshToken in the response body (and optionally set an HttpOnly cookie).

See references/examples.md for the complete AuthenticationController and AuthenticationService.

Step 7 — Implement Refresh Token Strategy

Store refresh tokens in the database with user_id, expiry_date, revoked, and expired columns. On /refresh, verify the stored token, revoke it, and issue a new pair (token rotation).

See references/token-management.md for RefreshToken entity, rotation logic, and Redis-based blacklisting.

Step 8 — Add Authorization Rules

Use @EnableMethodSecurity and @PreAuthorize annotations for fine-grained control:

java
@PreAuthorize("hasRole('ADMIN')")
public Page<UserResponse> getAllUsers(Pageable pageable) { ... }

@PreAuthorize("hasPermission(#documentId, 'Document', 'READ')")
public Document getDocument(Long documentId) { ... }

See references/authorization-patterns.md for RBAC entity model, PermissionEvaluator, and ABAC patterns.

Step 9 — Write Security Tests
java
@SpringBootTest
@AutoConfigureMockMvc
class AuthControllerTest {

    @Test
    void shouldDenyAccessWithoutToken() throws Exception {
        mockMvc.perform(get("/api/orders"))
            .andExpect(status().isUnauthorized());
    }

    @Test
    @WithMockUser(roles = "ADMIN")
    void shouldAllowAdminAccess() throws Exception {
        mockMvc.perform(get("/api/admin/users"))
            .andExpect(status().isOk());
    }
}

See references/testing.md and references/jwt-testing-guide.md for full test suites, Testcontainers setup, and a security test checklist.

Best Practices

Token Security
  • Use minimum 256-bit secret keys — load from environment variables, never hardcode
  • Set short access token lifetimes (15 min); use refresh tokens for longer sessions
  • Implement token rotation: revoke old refresh token when issuing a new one
  • Use jti (JWT ID) claim for blacklisting on logout
  • Prefer HttpOnly cookies for browser clients (XSS-safe)
  • Use Authorization: Bearer header for mobile/API clients
  • Set Secure, SameSite=Lax or Strict on cookies in production
Spring Security 6.x
  • Use SecurityFilterChain bean — never extend WebSecurityConfigurerAdapter
  • Disable CSRF only for stateless APIs; keep it enabled for session-based flows
  • Use @EnableMethodSecurity instead of deprecated @EnableGlobalMethodSecurity
  • Validate iss and aud claims; reject tokens from untrusted issuers
Show full SKILL.md (367 more words)Show less
Performance
  • Cache UserDetails with @Cacheable to avoid DB lookup on every request
  • Cache signing key derivation (avoid re-computing HMAC key per request)
  • Use Redis for refresh token storage at scale
What NOT to Do
  • Do not store sensitive data (passwords, PII) in JWT claims — claims are only signed, not encrypted
  • Do not issue tokens with infinite lifetime
  • Do not accept tokens without validating signature and expiration
  • Do not share signing keys across environments

Examples

Basic Authentication Flow
java
@RestController
@RequestMapping("/api/auth")
@RequiredArgsConstructor
public class AuthController {

    private final AuthService authService;

    @PostMapping("/authenticate")
    public ResponseEntity<AuthResponse> authenticate(
            @RequestBody LoginRequest request) {
        return ResponseEntity.ok(authService.authenticate(request));
    }

    @PostMapping("/refresh")
    public ResponseEntity<AuthResponse> refresh(@RequestBody RefreshRequest request) {
        return ResponseEntity.ok(authService.refreshToken(request.refreshToken()));
    }

    @PostMapping("/logout")
    public ResponseEntity<Void> logout() {
        authService.logout();
        return ResponseEntity.ok().build();
    }
}
JWT Authorization on Controller Method
java
@RestController
@RequestMapping("/api/admin")
@PreAuthorize("hasRole('ADMIN')")
public class AdminController {

    @GetMapping("/users")
    public ResponseEntity<List<UserResponse>> getAllUsers() {
        return ResponseEntity.ok(adminService.getAllUsers());
    }
}

See references/examples.md for complete entity models and service implementations.

References

FileContent
references/jwt-quick-reference.mdDependencies, minimal service, common patterns
references/jwt-complete-configuration.mdFull config: properties, SecurityFilterChain, JwtService, OAuth2 RS
references/configuration.mdJWT config beans, CORS, CSRF, error handling, session options
references/examples.mdComplete application setup: controllers, services, entities
references/authorization-patterns.mdRBAC/ABAC entity model, PermissionEvaluator, SpEL expressions
references/token-management.mdRefresh token entity, rotation, blacklisting with Redis
references/testing.mdUnit and MockMvc tests, test utilities
references/jwt-testing-guide.mdTestcontainers, load testing, security test checklist
references/security-hardening.mdSecurity headers, HSTS, rate limiting, audit logging
references/performance-optimization.mdCaffeine cache config, async validation, connection pooling
references/oauth2-integration.mdGoogle/GitHub OAuth2 login, OAuth2UserService
references/microservices-security.mdInter-service JWT propagation, resource server config
references/migration-spring-security-6x.mdMigration from Spring Security 5.x
references/troubleshooting.mdCommon errors, debugging tips

Constraints and Warnings

Security Constraints
  • JWT tokens are signed but not encrypted — do not include sensitive data in claims
  • Always validate exp, iss, and aud claims before trusting the token
  • Signing keys must be at least 256 bits; never use weak keys in production
  • Load secrets from environment variables or secure vaults, never from config files
  • SameSite cookie attribute is essential for CSRF protection in cookie-based flows
Spring Security 6.x Constraints
  • WebSecurityConfigurerAdapter is removed — use SecurityFilterChain beans only
  • @EnableGlobalMethodSecurity is deprecated — use @EnableMethodSecurity
  • Lambda DSL is required for HttpSecurity configuration (no method chaining)
  • WebSecurityConfigurerAdapter.order() replaced by @Order on @Configuration classes
Token Constraints
  • Access tokens should expire in 5-15 minutes for security
  • Refresh tokens should be stored server-side (DB or Redis), never in localStorage
  • Implement token blacklisting for immediate revocation on logout
  • jti claim is required for token blacklisting to work correctly
  • spring-boot-dependency-injection — Constructor injection patterns used throughout
  • spring-boot-rest-api-standards — REST API security patterns and error handling
  • unit-test-security-authorization — Testing Spring Security configurations
  • spring-data-jpa — User entity and repository patterns
  • spring-boot-actuator — Security monitoring and health endpoints

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 20 other files (scripts, references, assets) in plugins/developer-kit-java/skills/spring-boot-security-jwt of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • assets/generate-jwt-keys.sh
  • references/authorization-patterns.md
  • references/configuration.md
  • references/examples.md
  • references/jwt-complete-configuration.md
  • references/jwt-configuration.md
  • references/jwt-quick-reference.md
  • references/jwt-testing-guide.md
  • references/microservices-security.md
  • references/migration-spring-security-6x.md
  • references/oauth2-integration.md
  • references/performance-optimization.md
  • references/security-hardening.md
  • references/structure.md
  • references/testing-jwt-security.md
  • references/testing.md
  • references/token-management.md
  • references/troubleshooting.md
  • … and 2 more

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

Spring Boot Security JWT next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spring Boot Security JWT compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spring Boot Security JWT this skillgiuseppe-trisciuoglio/developer-kit357—~3.9kAutomated safety check: NotesMIT
Springboot Securityaffaan-m/ECC277k5 repos~2kAutomated safety check: PassMIT
Java ArchitectJeffallan/claude-skills12k—~1.5kAutomated safety check: PassMIT
Oauth2 Resource Serverrrezartprebreza/spring-boot-skills301—~1.2kAutomated safety check: PassMIT
JWT Authaiskillstore/marketplace433—~1.2kAutomated safety check: PassNone
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

    277k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check passed
  • Java Architect

    Jeffallan/claude-skills

    Builds Spring Boot 3.x services on Java 21 with domain-driven design, WebFlux, JPA tuning and Spring Security using OAuth2 and JWT, verified by Maven or Gradle builds.

    12k GitHub stars~1.5k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Oauth2 Resource Server

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing…

    301 GitHub stars~1.2k tokensUpdated 19 days ago
    Backend & APIsAuto-check passed
  • JWT Auth

    aiskillstore/marketplace

    A skill your agent uses when implementing JWT authentication in FastAPI or Python projects.

    433 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS SDK Java V2 Secrets Manager

    giuseppe-trisciuoglio/developer-kit

    Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration.

    357 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Categories

Questions about Spring Boot Security JWT

What does Spring Boot Security JWT do?

Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…. Spring Boot Security JWT is an agent skill from giuseppe-trisciuoglio/developer-kit.x.

When should I use Spring Boot Security JWT?

Spring Boot Security JWT fits situations like: implementing authentication; authorization in Spring Boot applications.

How do I install Spring Boot Security JWT in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-security-jwt -a claude-code`. Or copy the skill folder (plugins/developer-kit-java/skills/spring-boot-security-jwt in giuseppe-trisciuoglio/developer-kit) into .claude/skills/spring-boot-security-jwt in your project. Claude Code loads it when a task matches its description.

How do I install Spring Boot Security JWT in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-security-jwt -a codex`. Or copy the skill folder (plugins/developer-kit-java/skills/spring-boot-security-jwt in giuseppe-trisciuoglio/developer-kit) into .agents/skills/spring-boot-security-jwt in your project. Codex loads it when a task matches its description.

Can I use Spring Boot Security JWT in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-security-jwt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spring-boot-security-jwt, .gemini/skills/spring-boot-security-jwt, .github/skills/spring-boot-security-jwt and .opencode/skills/spring-boot-security-jwt in your project.

What does Spring Boot Security JWT need to run?

Going by SKILL.md and its folder, Spring Boot Security JWT needs a shell for the scripts in its folder and credentials named JWT_SECRET. Our summary lists: A Bash shell; A credential in JWT_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep.

Does Spring Boot Security JWT access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spring Boot Security JWT safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Spring Boot Security JWT use?

Spring Boot Security JWT is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spring Boot Security JWT use?

About 3.9k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 98k tokens, read only when the agent opens those files.

What are the alternatives to Spring Boot Security JWT?

Skills that share tags, products or a category with Spring Boot Security JWT: Springboot Security (affaan-m/ECC, 277k stars), Java Architect (Jeffallan/claude-skills, 12k stars), Oauth2 Resource Server (rrezartprebreza/spring-boot-skills, 301 stars) and JWT Auth (aiskillstore/marketplace, 433 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spring Boot Security JWT?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.