Fortify Development
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.
$ npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install gjovanovicst/golang-auth-api admin-gui --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/admin-gui .claude/skills/admin-gui && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "admin-gui" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/admin-gui into .claude/skills/admin-gui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin-gui", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/admin-guiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install gjovanovicst/golang-auth-api admin-gui --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.opencode/skills/admin-gui .agents/skills/admin-gui && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "admin-gui" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/admin-gui into .agents/skills/admin-gui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin-gui", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install gjovanovicst/golang-auth-api admin-gui --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.opencode/skills/admin-gui .cursor/skills/admin-gui && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "admin-gui" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/admin-gui into .cursor/skills/admin-gui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin-gui", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/gjovanovicst/golang-auth-api.git --path .opencode/skills/admin-gui--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install gjovanovicst/golang-auth-api admin-gui --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.opencode/skills/admin-gui .gemini/skills/admin-gui && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "admin-gui" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/admin-gui into .gemini/skills/admin-gui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin-gui", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install gjovanovicst/golang-auth-api admin-guiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .github/skills && cp -r skills-src/.opencode/skills/admin-gui .github/skills/admin-gui && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "admin-gui" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/admin-gui into .github/skills/admin-gui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin-gui", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install gjovanovicst/golang-auth-api admin-gui --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.opencode/skills/admin-gui .opencode/skills/admin-gui && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "admin-gui" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/admin-gui into .opencode/skills/admin-gui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin-gui", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
admin-guiDocumentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.
Admin Gui is an agent skill from gjovanovicst/golang-auth-api. Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication. The repository describes itself as: A modern, production-ready Go REST API for authentication and authorization, featuring social login, email verification, JWT, and Redis integration. The licence is MIT.
Read from SKILL.md and the folder at commit 795d18d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are go).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Admin Gui loads about 2k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 495 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from gjovanovicst/golang-auth-api at commit 795d18d, republished under its MIT licence (© gjovanovicst). 495 words, ~1,978 tokens.
.claude/skills/admin-gui/SKILL.md (or your agent's skills folder).The admin GUI is an HTMX-powered web interface at /gui/*. It provides a complete management dashboard for the Auth API platform. The main handler is internal/admin/gui_handler.go (4976 lines, the largest file in the project).
GUIHandler (internal/admin/gui_handler.go)
|-- AccountService -> admin auth, sessions, 2FA, CSRF
|-- DashboardService -> stats aggregation
|-- Repository -> data access (tenants, apps, users, etc.)
|-- SettingsService -> system settings management
|-- EmailService -> email template/server management
|-- RBACService -> role/permission management
|-- PasskeyService -> WebAuthn for admin accountsweb/renderer.go)Embedded filesystem: //go:embed templates in web/renderer.go
Template structure:
web/templates/
layouts/ -> base layout files (*.tmpl)
partials/ -> reusable fragments (*.tmpl) -- also served as standalone for HTMX
pages/ -> full page templates (*.tmpl)Parsing strategy:
c.HTML())Template data struct (web.TemplateData):
type TemplateData struct {
ActivePage string // Current page identifier for nav highlighting
AdminUsername string // From auth context
AdminID string // From auth context
CSRFToken string // From CSRF middleware
FlashSuccess string // Flash messages
FlashError string
Error string // Login-specific error
Username string // Pre-filled username on login error
Redirect string // Post-login redirect URL
TempToken string // 2FA temp token
TwoFAMethod string // "totp" or "email"
Data interface{} // Page-specific arbitrary data
}Template functions available (web.defaultFuncMap):
formatDate, formatDateTime, formatDateTimeFull -- date formattingtimeAgo -- human-readable relative timeupper, lower, title -- string transformssafeHTML, safeURL -- mark content as safe (no escaping)eq -- string equalityderef -- dereference *time.Time (nil-safe)isExpired -- check if time is in the pastadd, sub -- arithmetic for paginationGET /gui/login -> LoginPage (render login form)
POST /gui/login -> LoginSubmit [rate limited: 5/min]
-> accountService.Authenticate(username, password)
-> If 2FA: CreatePending2FASession -> redirect to /gui/2fa-verify
-> If no 2FA: CreateSession -> set cookie -> redirect to /gui/GET /gui/2fa-verify -> TwoFAVerifyPage (render 2FA form)
POST /gui/2fa-verify -> TwoFAVerifySubmit
-> Validate TOTP code, email code, or recovery code
-> PromotePendingSession -> set cookie -> redirectPOST /gui/passkey-login/begin -> PasskeyLoginBegin (returns JSON challenge)
POST /gui/passkey-login/finish -> PasskeyLoginFinish (validates assertion)
-> CreateSession -> set cookie -> return JSON successPOST /gui/magic-link-login -> MagicLinkLoginRequest
-> Generate token in Redis (10 min) -> send email
GET /gui/magic-link-login/verify -> MagicLinkLoginVerify
-> Validate token -> CreateSession -> set cookie -> redirectadmin_session (constant: web.AdminSessionCookie)/guiweb.SetSessionCookie(), cleared via web.ClearSessionCookie()Every entity domain follows a consistent pattern. Example for tenants:
GET /gui/tenants -> TenantPage (full page with layout)
GET /gui/tenants/list -> TenantList (HTMX partial, paginated table)
GET /gui/tenants/new -> TenantCreateForm (HTMX partial, form)
POST /gui/tenants -> TenantCreate (creates, returns alert + triggers list refresh)
GET /gui/tenants/form-cancel -> TenantFormCancel (empty response, cancels form)
GET /gui/tenants/:id/edit -> TenantEditForm (HTMX partial, pre-filled form)
PUT /gui/tenants/:id -> TenantUpdate (updates, returns alert + triggers list refresh)
GET /gui/tenants/:id/delete -> TenantDeleteConfirm (HTMX partial, confirmation modal)
DELETE /gui/tenants/:id -> TenantDelete (deletes, triggers list refresh)HTMX signals: Methods set HX-Trigger headers to signal events:
tenantDeleted, roleDeleted, sessionListRefresh, socialAccountUnlinked, permissionsSaved, etc.Error handling: Errors are returned as Bootstrap alert HTML snippets via c.String() or c.HTML().
| Approx Lines | Section | Entity/Feature |
|---|---|---|
| 1-120 | Auth | Login, Logout, 2FA verify |
| 120-200 | Dashboard | Stats display |
| 200-550 | Tenants | Full CRUD |
| 550-950 | Applications | Full CRUD |
| 950-1350 | OAuth Configs | Full CRUD + toggle enabled |
| 1350-1900 | Users | List (paginated, searchable), detail, toggle active |
| 1900-2200 | Activity Logs | List (paginated, filterable), detail |
| 2200-2600 | API Keys | CRUD + revoke |
| 2600-2850 | Settings | Three-tier resolution display, update, reset |
| 2850-3050 | Email (Servers/Templates/Types) | Full CRUD for each |
| 3050-3100 | My Account (Email/Password) | Profile management |
| 3100-3330 | My Account (2FA) | TOTP generate/verify, email 2FA, recovery codes |
| 3335-3480 | My Account (Passkeys) | Register, delete, rename |
| 3480-3715 | Roles | CRUD + permission assignment modal |
| 3715-3865 | Permissions | List, create |
| 3865-4115 | User Roles | Assign, revoke, search users, dynamic dropdowns |
| 4115-4210 | Social Account Mgmt | Unlink (with lockout prevention) |
| 4215-4290 | Passkey Mgmt (for users) | Delete user's passkey |
| 4290-4340 | Helpers | parseVariablesFromForm, escapeHTML |
| 4340-4420 | Passkey Login | WebAuthn discoverable login ceremony |
| 4420-4600 | Magic Link Login | Request, verify |
| 4600-4976 | Session Management | List (cross-app), detail, revoke, per-user sessions |
Middleware: internal/middleware/csrf.go
csrf_tokenX-CSRF-Token header (HTMX) or _csrf form fieldsessionValidator.ValidateCSRFToken()HTMX sends CSRF token via header: templates set hx-headers='{"X-CSRF-Token": "{{.CSRFToken}}"}'
| Endpoint | Limit | Window | Lockout |
|---|---|---|---|
| POST /gui/login | 5/min | 60s | 10 -> 15min |
| POST /gui/passkey-login/* | 10/min | 60s | 20 -> 15min |
| POST /gui/magic-link-login | 3/15min | 15min | none |
GUI rate limiting sets web.RateLimitErrorKey in context (doesn't abort), letting the handler render the error in the form.
Embedded via web/static/embed.go using //go:embed. Served at /gui/static/*.
admin.AccountService implements web.SessionValidator (for GUI auth + CSRF middleware)admin.Repository implements web.ApiKeyValidator (for admin/app API key middleware)web/context_keys.go to avoid import cyclesLoad this skill when working on the admin web interface, HTMX templates, GUI authentication, or any /gui/* route.
© gjovanovicst, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .opencode/skills/admin-gui of gjovanovicst/golang-auth-api.
Open the folder on GitHubat commit 795d18d
Admin Gui next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Admin Gui this skillgjovanovicst/golang-auth-api | 129 | — | ~2k | Automated safety check: Pass | MIT | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Supabasecurvenote/curvenote | 169 | 5 repos | ~2.2k | Automated safety check: Pass | Custom licence | |
| Gitnexus Exploringaws-samples/sample-kolya-br-proxy | 106 | 11 repos | ~749 | Automated safety check: Pass | MIT-0 |
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
aws-samples/sample-kolya-br-proxy
A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.
google-gemini/gemini-skills
A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.
gjovanovicst/golang-auth-api
Detailed documentation of the 4 authentication systems, token lifecycle, middleware pipeline, session management, and RBAC authorization.
gjovanovicst/golang-auth-api
All 17 GORM database models with fields, relationships, indexes, and the entity relationship diagram for the Auth API.
gjovanovicst/golang-auth-api
Complete documentation of the email subsystem including template resolution, variable pipeline, rendering engines, SMTP config, and default templates.
gjovanovicst/golang-auth-api
Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.
gjovanovicst/golang-auth-api
Complete HTTP route structure with auth layers, middleware chains, rate limiting, and handler mappings for all API and GUI endpoints.
Categories
Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure. Admin Gui is an agent skill from gjovanovicst/golang-auth-api. Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.
Admin Gui fits situations like: tasks that involve Authentication.
Run `npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a claude-code`. Or copy the skill folder (.opencode/skills/admin-gui in gjovanovicst/golang-auth-api) into .claude/skills/admin-gui in your project. Claude Code loads it when a task matches its description.
Run `npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a codex`. Or copy the skill folder (.opencode/skills/admin-gui in gjovanovicst/golang-auth-api) into .agents/skills/admin-gui in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gjovanovicst/golang-auth-api --skill admin-gui -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/admin-gui, .gemini/skills/admin-gui, .github/skills/admin-gui and .opencode/skills/admin-gui in your project.
SKILL.md names no scripts, command-line tools or credentials: Admin Gui is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Admin Gui is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Admin Gui: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Supabase (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
gjovanovicst (a GitHub user) maintains it in gjovanovicst/golang-auth-api, which has 129 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on July 30, 2026.
Source: gjovanovicst/golang-auth-api on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.