Agent skill

Admin Gui

by gjovanovicst in gjovanovicst/golang-auth-api

Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.

MITAuto-check passedBackend & APIs

Install Admin Gui

skills CLI
$ npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gjovanovicst/golang-auth-api admin-gui --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/admin-gui .claude/skills/admin-gui && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
admin-gui
GitHub stars
129
Token cost
~2k tokens
SKILL.md length
495 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.

  • Tasks that involve Authentication
  • SKILL.md covers Overview, Architecture, Template Rendering… and Authentication Flow, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Admin Gui is an agent skill from gjovanovicst/golang-auth-api. Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. The repository describes itself as: A modern, production-ready Go REST API for authentication and authorization, featuring social login, email verification, JWT, and Redis integration. The licence is MIT.

When your agent uses it

  • Tasks that involve Authentication

Example prompts

  • “/admin-gui”

What it can do on your machine

Read from SKILL.md and the folder at commit 795d18d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are go).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Admin Gui loads about 2k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 495 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gjovanovicst/golang-auth-api at commit 795d18d, republished under its MIT licence (© gjovanovicst). 495 words, ~1,978 tokens.

Download SKILL.mdSave it as .claude/skills/admin-gui/SKILL.md (or your agent's skills folder).
name
admin-gui
description
Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.
license
MIT

Overview

The admin GUI is an HTMX-powered web interface at /gui/*. It provides a complete management dashboard for the Auth API platform. The main handler is internal/admin/gui_handler.go (4976 lines, the largest file in the project).

Architecture

GUIHandler (internal/admin/gui_handler.go)
  |-- AccountService   -> admin auth, sessions, 2FA, CSRF
  |-- DashboardService -> stats aggregation
  |-- Repository       -> data access (tenants, apps, users, etc.)
  |-- SettingsService  -> system settings management
  |-- EmailService     -> email template/server management
  |-- RBACService      -> role/permission management
  |-- PasskeyService   -> WebAuthn for admin accounts

Template Rendering (web/renderer.go)

Embedded filesystem: //go:embed templates in web/renderer.go

Template structure:

web/templates/
  layouts/     -> base layout files (*.tmpl)
  partials/    -> reusable fragments (*.tmpl) -- also served as standalone for HTMX
  pages/       -> full page templates (*.tmpl)

Parsing strategy:

  • Full pages = layouts + partials + page file (rendered via c.HTML())
  • HTMX fragments = partials rendered standalone (for dynamic swaps)

Template data struct (web.TemplateData):

go
type TemplateData struct {
    ActivePage    string      // Current page identifier for nav highlighting
    AdminUsername string      // From auth context
    AdminID       string      // From auth context
    CSRFToken     string      // From CSRF middleware
    FlashSuccess  string      // Flash messages
    FlashError    string
    Error         string      // Login-specific error
    Username      string      // Pre-filled username on login error
    Redirect      string      // Post-login redirect URL
    TempToken     string      // 2FA temp token
    TwoFAMethod   string      // "totp" or "email"
    Data          interface{} // Page-specific arbitrary data
}

Template functions available (web.defaultFuncMap):

  • formatDate, formatDateTime, formatDateTimeFull -- date formatting
  • timeAgo -- human-readable relative time
  • upper, lower, title -- string transforms
  • safeHTML, safeURL -- mark content as safe (no escaping)
  • eq -- string equality
  • deref -- dereference *time.Time (nil-safe)
  • isExpired -- check if time is in the past
  • add, sub -- arithmetic for pagination

Authentication Flow

Standard Login
GET  /gui/login          -> LoginPage (render login form)
POST /gui/login          -> LoginSubmit [rate limited: 5/min]
  -> accountService.Authenticate(username, password)
  -> If 2FA: CreatePending2FASession -> redirect to /gui/2fa-verify
  -> If no 2FA: CreateSession -> set cookie -> redirect to /gui/
2FA Verification
GET  /gui/2fa-verify     -> TwoFAVerifyPage (render 2FA form)
POST /gui/2fa-verify     -> TwoFAVerifySubmit
  -> Validate TOTP code, email code, or recovery code
  -> PromotePendingSession -> set cookie -> redirect
Passkey Login (passwordless)
POST /gui/passkey-login/begin  -> PasskeyLoginBegin (returns JSON challenge)
POST /gui/passkey-login/finish -> PasskeyLoginFinish (validates assertion)
  -> CreateSession -> set cookie -> return JSON success
POST /gui/magic-link-login         -> MagicLinkLoginRequest
  -> Generate token in Redis (10 min) -> send email
GET  /gui/magic-link-login/verify  -> MagicLinkLoginVerify
  -> Validate token -> CreateSession -> set cookie -> redirect
  • Name: admin_session (constant: web.AdminSessionCookie)
  • Path: /gui
  • Flags: HttpOnly, SameSite=Strict, Secure (auto-detected)
  • Set via web.SetSessionCookie(), cleared via web.ClearSessionCookie()

HTMX CRUD Pattern

Every entity domain follows a consistent pattern. Example for tenants:

GET  /gui/tenants              -> TenantPage (full page with layout)
GET  /gui/tenants/list         -> TenantList (HTMX partial, paginated table)
GET  /gui/tenants/new          -> TenantCreateForm (HTMX partial, form)
POST /gui/tenants              -> TenantCreate (creates, returns alert + triggers list refresh)
GET  /gui/tenants/form-cancel  -> TenantFormCancel (empty response, cancels form)
GET  /gui/tenants/:id/edit     -> TenantEditForm (HTMX partial, pre-filled form)
PUT  /gui/tenants/:id          -> TenantUpdate (updates, returns alert + triggers list refresh)
GET  /gui/tenants/:id/delete   -> TenantDeleteConfirm (HTMX partial, confirmation modal)
DELETE /gui/tenants/:id        -> TenantDelete (deletes, triggers list refresh)

HTMX signals: Methods set HX-Trigger headers to signal events:

  • Entity events: tenantDeleted, roleDeleted, sessionListRefresh, socialAccountUnlinked, permissionsSaved, etc.
  • These trigger list refreshes and modal closes on the client side

Error handling: Errors are returned as Bootstrap alert HTML snippets via c.String() or c.HTML().

GUIHandler Method Groups

Approx LinesSectionEntity/Feature
1-120AuthLogin, Logout, 2FA verify
120-200DashboardStats display
200-550TenantsFull CRUD
550-950ApplicationsFull CRUD
950-1350OAuth ConfigsFull CRUD + toggle enabled
1350-1900UsersList (paginated, searchable), detail, toggle active
1900-2200Activity LogsList (paginated, filterable), detail
2200-2600API KeysCRUD + revoke
2600-2850SettingsThree-tier resolution display, update, reset
2850-3050Email (Servers/Templates/Types)Full CRUD for each
3050-3100My Account (Email/Password)Profile management
3100-3330My Account (2FA)TOTP generate/verify, email 2FA, recovery codes
3335-3480My Account (Passkeys)Register, delete, rename
3480-3715RolesCRUD + permission assignment modal
3715-3865PermissionsList, create
3865-4115User RolesAssign, revoke, search users, dynamic dropdowns
4115-4210Social Account MgmtUnlink (with lockout prevention)
4215-4290Passkey Mgmt (for users)Delete user's passkey
4290-4340HelpersparseVariablesFromForm, escapeHTML
4340-4420Passkey LoginWebAuthn discoverable login ceremony
4420-4600Magic Link LoginRequest, verify
4600-4976Session ManagementList (cross-app), detail, revoke, per-user sessions
Show full SKILL.md (142 more words)Show less

CSRF Protection

Middleware: internal/middleware/csrf.go

  • GET requests: generate CSRF token, set in context as csrf_token
  • POST/PUT/DELETE: read from X-CSRF-Token header (HTMX) or _csrf form field
  • Token validated against session via sessionValidator.ValidateCSRFToken()

HTMX sends CSRF token via header: templates set hx-headers='{"X-CSRF-Token": "{{.CSRFToken}}"}'

Rate Limiting (GUI-specific)

EndpointLimitWindowLockout
POST /gui/login5/min60s10 -> 15min
POST /gui/passkey-login/*10/min60s20 -> 15min
POST /gui/magic-link-login3/15min15minnone

GUI rate limiting sets web.RateLimitErrorKey in context (doesn't abort), letting the handler render the error in the form.

Static Assets

Embedded via web/static/embed.go using //go:embed. Served at /gui/static/*.

Key Dependencies

  • admin.AccountService implements web.SessionValidator (for GUI auth + CSRF middleware)
  • admin.Repository implements web.ApiKeyValidator (for admin/app API key middleware)
  • Both interfaces defined in web/context_keys.go to avoid import cycles

When To Use This Skill

Load this skill when working on the admin web interface, HTMX templates, GUI authentication, or any /gui/* route.

© gjovanovicst, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .opencode/skills/admin-gui of gjovanovicst/golang-auth-api.

Open the folder on GitHubat commit 795d18d

Compare with similar skills

Admin Gui next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Admin Gui compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Admin Gui this skillgjovanovicst/golang-auth-api129—~2kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Supabasecurvenote/curvenote1695 repos~2.2kAutomated safety check: PassCustom licence
Gitnexus Exploringaws-samples/sample-kolya-br-proxy10611 repos~749Automated safety check: PassMIT-0

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    169 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Gitnexus Exploring

    aws-samples/sample-kolya-br-proxy

    Official

    A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.

    106 GitHub starsUsed in 11 repos~749 tokens
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from gjovanovicst/golang-auth-api

  • Auth Flows

    gjovanovicst/golang-auth-api

    Detailed documentation of the 4 authentication systems, token lifecycle, middleware pipeline, session management, and RBAC authorization.

    129 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Data Model

    gjovanovicst/golang-auth-api

    All 17 GORM database models with fields, relationships, indexes, and the entity relationship diagram for the Auth API.

    129 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Email System

    gjovanovicst/golang-auth-api

    Complete documentation of the email subsystem including template resolution, variable pipeline, rendering engines, SMTP config, and default templates.

    129 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Project Map

    gjovanovicst/golang-auth-api

    Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.

    129 GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Route Map

    gjovanovicst/golang-auth-api

    Complete HTTP route structure with auth layers, middleware chains, rate limiting, and handler mappings for all API and GUI endpoints.

    129 GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Admin Gui

What does Admin Gui do?

Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure. Admin Gui is an agent skill from gjovanovicst/golang-auth-api. Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.

When should I use Admin Gui?

Admin Gui fits situations like: tasks that involve Authentication.

How do I install Admin Gui in Claude Code?

Run `npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a claude-code`. Or copy the skill folder (.opencode/skills/admin-gui in gjovanovicst/golang-auth-api) into .claude/skills/admin-gui in your project. Claude Code loads it when a task matches its description.

How do I install Admin Gui in Codex?

Run `npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a codex`. Or copy the skill folder (.opencode/skills/admin-gui in gjovanovicst/golang-auth-api) into .agents/skills/admin-gui in your project. Codex loads it when a task matches its description.

Can I use Admin Gui in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/admin-gui, .gemini/skills/admin-gui, .github/skills/admin-gui and .opencode/skills/admin-gui in your project.

What does Admin Gui need to run?

SKILL.md names no scripts, command-line tools or credentials: Admin Gui is instructions for the agent only.

Does Admin Gui access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Admin Gui safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Admin Gui use?

Admin Gui is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Admin Gui use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Admin Gui?

Skills that share tags, products or a category with Admin Gui: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Supabase (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Admin Gui?

gjovanovicst (a GitHub user) maintains it in gjovanovicst/golang-auth-api, which has 129 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on July 30, 2026.

Source: gjovanovicst/golang-auth-api on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.