Discover API
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.
$ npx skills add gjovanovicst/golang-auth-api --skill project-map -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install gjovanovicst/golang-auth-api project-map --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/project-map .claude/skills/project-map && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "project-map" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/project-map into .claude/skills/project-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-map", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/project-mapType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add gjovanovicst/golang-auth-api --skill project-map -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install gjovanovicst/golang-auth-api project-map --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.opencode/skills/project-map .agents/skills/project-map && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "project-map" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/project-map into .agents/skills/project-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-map", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gjovanovicst/golang-auth-api --skill project-map -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install gjovanovicst/golang-auth-api project-map --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.opencode/skills/project-map .cursor/skills/project-map && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "project-map" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/project-map into .cursor/skills/project-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-map", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/gjovanovicst/golang-auth-api.git --path .opencode/skills/project-map--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add gjovanovicst/golang-auth-api --skill project-map -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install gjovanovicst/golang-auth-api project-map --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.opencode/skills/project-map .gemini/skills/project-map && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "project-map" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/project-map into .gemini/skills/project-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-map", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install gjovanovicst/golang-auth-api project-mapInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add gjovanovicst/golang-auth-api --skill project-map -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .github/skills && cp -r skills-src/.opencode/skills/project-map .github/skills/project-map && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "project-map" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/project-map into .github/skills/project-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-map", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gjovanovicst/golang-auth-api --skill project-map -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install gjovanovicst/golang-auth-api project-map --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.opencode/skills/project-map .opencode/skills/project-map && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "project-map" agent skill from https://github.com/gjovanovicst/golang-auth-api/tree/main/.opencode/skills/project-map into .opencode/skills/project-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-map", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
project-mapComplete module inventory of the Auth API project with file paths, dependencies, and architecture overview.
Project Map is an agent skill from gjovanovicst/golang-auth-api. Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview. Load this first in any new session.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication, Authorization and RBAC and REST APIs. It works with PostgreSQL and Redis. The repository describes itself as: A modern, production-ready Go REST API for authentication and authorization, featuring social login, email verification, JWT, and Redis integration. The licence is MIT.
Read from SKILL.md and the folder at commit 795d18d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Project Map loads about 2.6k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 860 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from gjovanovicst/golang-auth-api at commit 795d18d, republished under its MIT licence (© gjovanovicst). 860 words, ~2,598 tokens.
.claude/skills/project-map/SKILL.md (or your agent's skills folder).A multi-tenant authentication and authorization REST API in Go 1.23+, using Gin, PostgreSQL (GORM), and Redis. It provides user registration, login, OAuth2 social login, TOTP/email/SMS/backup-email 2FA, WebAuthn/passkeys, magic links, RBAC, session management, OIDC provider, webhooks, brute-force protection, GeoIP IP rules, health/metrics, and a full admin interface (JSON API + HTMX GUI).
Pattern: Repository -> Service -> Handler (Clean Architecture)
Key design decisions:
RoleLookupFunc, AssignDefaultRoleFunc)AppID (UUID), with default app 00000000-0000-0000-0000-000000000001cmd/api/main.go -- Dependency injection, route setup, server startupTenant/app CRUD, OAuth provider configuration, email management, API key management, admin account authentication, 2FA for admin accounts, system settings (env -> DB -> default resolution), dashboard stats, HTMX GUI handler.
| File | Purpose |
|---|---|
gui_handler.go | HTMX admin GUI (4976 lines, largest file) |
handler.go | Admin JSON REST API (1146 lines) |
repository.go | Data access for tenants, apps, OAuth, users, API keys, logs (952 lines) |
account_service.go | Admin auth, sessions, 2FA, CSRF, password ops |
account_repository.go | AdminAccount GORM queries |
dashboard_service.go | Dashboard stats aggregation (PostgreSQL + Redis) |
settings_service.go | System settings with 3-tier resolution (env > DB > default) |
settings_repository.go | SystemSetting GORM queries with upsert |
apikey_util.go | API key generation (SHA-256 hash, prefix/suffix) |
apikey_util_test.go | Tests for API key utilities |
account_service_test.go | Tests for admin account service |
Registration, login (with self-healing role assignment), password reset, magic link auth, email change with verification, profile management.
| File | Purpose |
|---|---|
handler.go | User HTTP handlers |
service.go | User business logic |
repository.go | User GORM queries |
handler_test.go | Handler tests |
service_test.go | Service tests |
Google, Facebook, GitHub OAuth2 flows. Supports account linking and direct social login/registration.
| File | Purpose |
|---|---|
handler.go | OAuth2 HTTP handlers (login, callback, link) |
service.go | OAuth2 business logic |
repository.go | SocialAccount GORM queries |
oauth_state.go | OAuth state parameter encoding (appID, provider, action, HMAC) |
TOTP (authenticator apps), email-based 2FA codes, SMS 2FA (Twilio), backup email 2FA, recovery codes, trusted devices.
| File | Purpose |
|---|---|
handler.go | 2FA HTTP handlers (TOTP, email, SMS, backup email, trusted devices, phone management) |
service.go | 2FA business logic (TOTP + email + SMS + backup email codes, trusted device validation) |
trusted_device_repository.go | TrustedDevice GORM queries |
Full WebAuthn support for users and admin accounts.
| File | Purpose |
|---|---|
handler.go | Passkey HTTP handlers |
service.go | WebAuthn ceremony logic |
repository.go | WebAuthnCredential GORM queries |
config.go | Relying party configuration |
user_adapter.go | Adapts User/AdminAccount to WebAuthn user interface |
Redis-backed sessions with refresh token rotation, multi-device tracking.
| File | Purpose |
|---|---|
service.go | Session lifecycle (create, refresh, revoke, list) |
handler.go | Session API endpoints |
Roles per-application, permissions as resource:action, Redis-cached authorization.
| File | Purpose |
|---|---|
service.go | RBAC logic with Redis caching |
repository.go | Role/Permission/UserRole GORM queries |
handler.go | RBAC API endpoints |
Multi-layered email system: Service -> VariableResolver + Renderer + Sender.
| File | Purpose |
|---|---|
service.go | Orchestrator (send pipeline, template/SMTP resolution) |
resolver.go | Variable resolution pipeline (4 layers) |
renderer.go | Three template engines (go_template, placeholder, raw_html) |
sender.go | SMTP sending via gopkg.in/mail.v2 |
types.go | Constants, structs, variable registry |
defaults.go | 7 hardcoded default email templates |
repository.go | Email types, templates, server configs GORM queries |
email_integration_test.go | Integration tests |
Async channel-based logging with anomaly detection.
| File | Purpose |
|---|---|
service.go | Async log service (buffered channel, background worker) |
anomaly.go | Anomaly detection (new IP, new UA, unusual time) |
cleanup.go | Scheduled log retention/cleanup |
query_service.go | Filtered, paginated log querying |
handler.go | Log API endpoints |
repository.go | ActivityLog GORM queries |
| File | Purpose |
|---|---|
auth.go | JWT auth + token blacklist checking |
admin_auth.go | Admin API Key auth (static env + DB-backed) |
app_api_key.go | Per-app API Key auth |
gui_auth.go | Admin GUI cookie session auth |
csrf.go | CSRF protection for GUI |
app_id.go | X-App-ID header extraction |
app_route_guard.go | Cross-app URL parameter validation |
rate_limit.go | Redis + in-memory fallback rate limiting |
cors.go | CORS configuration |
security_headers.go | CSP, HSTS, X-Frame-Options |
auth_test.go | Auth middleware tests |
rate_limit_test.go | Rate limit tests |
security_headers_test.go | Security header tests |
| Package | File | Purpose |
|---|---|---|
internal/oidc/ | 7 files | Full OIDC provider: discovery, authorize, token, userinfo, introspect, revoke, end_session, JWKS, RS256 id_token signing |
internal/webhook/ | 3 files | Webhook endpoint registry, async delivery dispatcher, retry queue, HMAC-SHA256 signing |
internal/bruteforce/ | 2 files | Account lockout, progressive login delays, CAPTCHA trigger threshold |
internal/geoip/ | 3 files | MaxMind GeoLite2 service, IP rule repository, IP rule evaluator (CIDR/country per app) |
internal/health/ | 1 file | GET /health liveness, GET /metrics Prometheus, PrometheusMiddleware, MetricsSummary |
internal/sms/ | 3 files | SMS sender interface, Twilio implementation, config loader |
internal/database/ | db.go | PostgreSQL connection + GORM auto-migration |
internal/redis/ | redis.go | Redis connection + token blacklisting + session helpers |
internal/config/ | logging.go | Logging configuration |
internal/util/ | client_info.go, frontend_url.go | Client info extraction, frontend URL resolution |
| Package | Files | Purpose |
|---|---|---|
pkg/models/ | 17+ model files | GORM models: User, Tenant, Application, Role, Permission, UserRole, AdminAccount, SocialAccount, WebAuthnCredential, ActivityLog, ApiKey, ApiKeyUsage, EmailType, EmailTemplate, EmailServerConfig, OAuthProviderConfig, SystemSetting, SchemaMigration, OIDCClient, OIDCAuthCode, WebhookEndpoint, WebhookDelivery, IPRule, TrustedDevice |
pkg/dto/ | 7+ files | Request/response DTOs: auth, admin, session, RBAC, WebAuthn, email, activity_log, oidc, webhook, geoip |
pkg/errors/ | errors.go, errors_test.go | AppError type with 6 HTTP status code mappings |
pkg/jwt/ | jwt.go, jwt_test.go | JWT Claims (UserID, AppID, SessionID, TokenType, Roles), generate/parse |
| File | Purpose |
|---|---|
renderer.go | HTML template renderer (embedded templates, funcMap) |
context_keys.go | Shared context keys, SessionValidator/ApiKeyValidator interfaces, cookie helpers |
static/embed.go | Embedded static files (CSS/JS) |
main.go wires everything:
user.Service depends on: user.Repository, email.Service, rbac.Service (via callbacks), session.Service, webhook.Service, sms.Sender
social.Service depends on: user.Repository, social.Repository, rbac.Service (via callbacks), session.Service, webhook.Service
twofa.Service depends on: user.Repository, email.Service, sms.Sender, trusted_device.Repository
twofa.Handler depends on: rbac.Service (via callbacks), session.Service, trusted_device.Repository
webauthn.Service depends on: webauthn.Repository, user.Repository
webauthn.Handler depends on: rbac.Service (via callbacks), session.Service, webhook.Service
oidc.Service depends on: oidc.Repository, rbac.Service (GetUserRoleNames)
webhook.Service depends on: webhook.Repository
bruteforce.Service depends on: database.DB (Redis-less, PostgreSQL counters)
geoip.IPRuleEvaluator depends on: geoip.IPRuleRepository, geoip.Service
health.Handler depends on: database.DB, redis.Rdb, SMTP address
rbac.Service depends on: rbac.Repository
session.Service depends on: Redis
email.Service depends on: email.Repository, VariableResolver, Renderer, Sender
log.Service depends on: log.Repository, AnomalyDetector
admin.Handler depends on: admin.Repository, email.Service, trusted_device.Repository
admin.GUIHandler depends on: AccountService, DashboardService, admin.Repository, SettingsService, email.Service, rbac.Service, webauthn.Service, webhook.Service, oidc.Service, health.Handler, trusted_device.RepositoryLoad this skill at the start of any session to understand the project structure. For domain-specific deep dives, also load the relevant skill: route-map, data-model, auth-flows, email-system, or admin-gui.
© gjovanovicst, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .opencode/skills/project-map of gjovanovicst/golang-auth-api.
Open the folder on GitHubat commit 795d18d
Project Map next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Project Map this skillgjovanovicst/golang-auth-api | 129 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Discover APIrand/cc-polymath | 181 | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Spring Security ConfigurationAmplicode/spring-skills | 126 | — | ~4.3k | Automated safety check: Pass | None | |
| Cognitoitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Auth Implementation Patternsynulihao/AgentSkillOS | 617 | 9 repos | ~4.4k | Automated safety check: Pass | None | |
| Nodejs Express Serverever-works/ever-works | 158 | — | ~965 | Automated safety check: Pass | AGPL-3.0 |
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
Amplicode/spring-skills
Creates a Spring Security configuration class with authentication, authorization, and HTTP protection setup.
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
ynulihao/AgentSkillOS
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.
ever-works/ever-works
Build production-ready Express.js servers with middleware, authentication, routing, and database integration.
trypostit/trypost
Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.
gjovanovicst/golang-auth-api
Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.
gjovanovicst/golang-auth-api
Detailed documentation of the 4 authentication systems, token lifecycle, middleware pipeline, session management, and RBAC authorization.
gjovanovicst/golang-auth-api
All 17 GORM database models with fields, relationships, indexes, and the entity relationship diagram for the Auth API.
gjovanovicst/golang-auth-api
Complete documentation of the email subsystem including template resolution, variable pipeline, rendering engines, SMTP config, and default templates.
gjovanovicst/golang-auth-api
Complete HTTP route structure with auth layers, middleware chains, rate limiting, and handler mappings for all API and GUI endpoints.
Works with
Categories
Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview. Project Map is an agent skill from gjovanovicst/golang-auth-api. Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.
Project Map fits situations like: tasks that involve Authentication; tasks that involve Authorization and RBAC; tasks that involve REST APIs.
Run `npx skills add gjovanovicst/golang-auth-api --skill project-map -a claude-code`. Or copy the skill folder (.opencode/skills/project-map in gjovanovicst/golang-auth-api) into .claude/skills/project-map in your project. Claude Code loads it when a task matches its description.
Run `npx skills add gjovanovicst/golang-auth-api --skill project-map -a codex`. Or copy the skill folder (.opencode/skills/project-map in gjovanovicst/golang-auth-api) into .agents/skills/project-map in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gjovanovicst/golang-auth-api --skill project-map -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-map, .gemini/skills/project-map, .github/skills/project-map and .opencode/skills/project-map in your project.
SKILL.md names no scripts, command-line tools or credentials: Project Map is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Project Map is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Project Map: Discover API (rand/cc-polymath, 181 stars), Spring Security Configuration (Amplicode/spring-skills, 126 stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars) and Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
gjovanovicst (a GitHub user) maintains it in gjovanovicst/golang-auth-api, which has 129 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on July 30, 2026.
Source: gjovanovicst/golang-auth-api on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.