Agent skill

Pinme Auth

by glitternetwork in glitternetwork/pinme

A skill your agent uses when a PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users, verifying idtokens, querying user info, or listing users via…

MITAuto-check passedBackend & APIs

Install Pinme Auth

skills CLI
$ npx skills add glitternetwork/pinme --skill pinme-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install glitternetwork/pinme pinme-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/glitternetwork/pinme.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pinme-auth .claude/skills/pinme-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pinme-auth
GitHub stars
3.7k
Token cost
~2.6k tokens
SKILL.md length
376 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users, verifying idtokens, querying user info, or listing users via…

  • Works in 5 steps: create_user → 创建用户并发出验证邮件 → 用户点击邮件链接完成验证 → 前端登录拿到 id_token → …
  • A PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users
  • SKILL.md covers Environment Variables, 认证方式(所有接口通用), 通用错误 and 通用 TypeScript 类型, plus 7 more sections
  • Reaches pinme.cloud; needs API_KEY

What it does

Pinme Auth is an agent skill from glitternetwork/pinme. Use when a PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users, verifying idtokens, querying user info, or listing users via Identity Platform auth proxy APIs.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with TypeScript. The repository describes itself as: Deploy Your Frontend in a Single Command. Claude Code Skills supported. The licence is MIT.

When your agent uses it

  • A PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users
  • Verifying idtokens
  • Querying user info
  • Listing users via Identity Platform auth proxy APIs

Example prompts

  • “/pinme-auth”

Requirements

  • A credential in API_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. create_user → 创建用户并发出验证邮件
  2. 用户点击邮件链接完成验证
  3. 前端登录拿到 id_token
  4. verify_token → 校验 token,取得 uid
  5. 需要时再调 getAuthUser 读取完整用户信息

What it can do on your machine

Read from SKILL.md and the folder at commit 7822b05. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • pinme.cloud

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pinme Auth loads about 2.6k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 376 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from glitternetwork/pinme at commit 7822b05, republished under its MIT licence (© glitternetwork). 376 words, ~2,561 tokens.

Download SKILL.mdSave it as .claude/skills/pinme-auth/SKILL.md (or your agent's skills folder).
name
pinme-auth
description
Use when a PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users, verifying id_tokens, querying user info, or listing users via Identity Platform auth proxy APIs.

PinMe Worker Auth API Integration

Guides how to call PinMe platform's Identity Platform auth proxy APIs in a PinMe Worker (TypeScript).

Environment Variables

typescript
// backend/src/worker.ts
export interface Env {
  DB: D1Database;
  API_KEY: string;       // 项目 API Key — 用于所有 auth 接口认证
  PROJECT_NAME: string;  // 项目名 — 所有 auth 接口必须同时传递
  BASE_URL?: string;     // 可选,默认 https://pinme.cloud
}

API_KEY 和 PROJECT_NAME 是所有 auth 接口的必填凭证,缺一不可。


认证方式(所有接口通用)

参数传递方式必填说明
X-API-Key请求头是项目 API Key
project_nameQuery 参数是必须与 X-API-Key 对应同一个项目

服务端会先校验这两个字段是否匹配同一个项目,再从项目配置中取出 tenant_id,然后转调 Identity Platform。


通用错误

场景HTTPdata.error
缺少 X-API-Key401X-API-Key header is required
缺少 project_name400project_name is required
API Key 和项目不匹配401Invalid API key or project name
项目未配置认证租户400Auth service not configured for this project

通用 TypeScript 类型

typescript
type ApiEnvelope<T> = {
  code: number   // 200=成功,其他=失败
  msg: string    // "ok" | "fail" | "invalid param"
  data: T
}

type ApiErrorData = { error?: string }

type UserInfo = {
  uid: string
  email: string
  display_name: string
  photo_url?: string
  disabled: boolean
  email_verified: boolean
}

API 1: 创建用户

Endpoint: POST {BASE_URL}/api/v1/auth/create_user?project_name={project_name}

仅用于邮箱密码注册。成功时用户已创建且验证邮件已发出;失败时自动回滚,不会留下僵尸账号。

创建成功后用户默认仍是"未验证"状态,需点击邮件验证链接后,verify_token 才能通过校验。

请求体
json
{ "email": "alice@example.com", "password": "Test@12345678", "display_name": "Alice" }
字段类型必填
emailstring是
passwordstring是
display_namestring否
错误
场景HTTPdata.error
缺少 email/password400email and password are required
上游创建失败502Failed to create user
发送验证邮件失败500Failed to send verification email. Please try again.
TypeScript 示例
typescript
async function createAuthUser(
  env: Env,
  payload: { email: string; password: string; display_name?: string }
): Promise<{ user?: UserInfo; error?: string }> {
  const baseUrl = env.BASE_URL ?? 'https://pinme.cloud';
  const resp = await fetch(
    `${baseUrl}/api/v1/auth/create_user?project_name=${encodeURIComponent(env.PROJECT_NAME)}`,
    {
      method: 'POST',
      headers: { 'X-API-Key': env.API_KEY, 'Content-Type': 'application/json' },
      body: JSON.stringify(payload),
    }
  );
  const result = await resp.json() as ApiEnvelope<UserInfo | ApiErrorData>;
  if (!resp.ok || result.code !== 200) {
    return { error: (result.data as ApiErrorData)?.error ?? result.msg };
  }
  return { user: result.data as UserInfo };
}

API 2: 校验 id_token

Endpoint: POST {BASE_URL}/api/v1/auth/verify_token?project_name={project_name}

校验前端登录后拿到的 id_token(邮箱密码或 Google 登录均适用)。

注意: token 合法但邮箱未验证时返回 403,不是 401。

请求体
json
{ "id_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6..." }
成功响应 data
typescript
type VerifyTokenData = {
  uid: string
  email?: string
  tenant_id: string
  claims: Record<string, unknown>
}
错误
场景HTTPdata.error
缺少 id_token400id_token is required
token 无效或过期401Invalid or expired token
邮箱未验证403Email not verified. Please check your inbox and verify your email address.
TypeScript 示例
typescript
async function verifyAuthToken(
  env: Env,
  idToken: string
): Promise<{ uid?: string; email?: string; error?: string; emailNotVerified?: boolean }> {
  const baseUrl = env.BASE_URL ?? 'https://pinme.cloud';
  const resp = await fetch(
    `${baseUrl}/api/v1/auth/verify_token?project_name=${encodeURIComponent(env.PROJECT_NAME)}`,
    {
      method: 'POST',
      headers: { 'X-API-Key': env.API_KEY, 'Content-Type': 'application/json' },
      body: JSON.stringify({ id_token: idToken }),
    }
  );
  const result = await resp.json() as ApiEnvelope<VerifyTokenData | ApiErrorData>;
  if (!resp.ok || result.code !== 200) {
    const error = (result.data as ApiErrorData)?.error ?? result.msg;
    return { error, emailNotVerified: resp.status === 403 };
  }
  const data = result.data as VerifyTokenData;
  return { uid: data.uid, email: data.email };
}

API 3: 查询单个用户

Endpoint: GET {BASE_URL}/api/v1/auth/user?project_name={project_name}&uid={uid}

错误
场景HTTPdata.error
缺少 uid400uid is required
用户不存在404User not found
上游查询失败502Failed to get user
TypeScript 示例
typescript
async function getAuthUser(env: Env, uid: string): Promise<{ user?: UserInfo; error?: string }> {
  const baseUrl = env.BASE_URL ?? 'https://pinme.cloud';
  const resp = await fetch(
    `${baseUrl}/api/v1/auth/user?project_name=${encodeURIComponent(env.PROJECT_NAME)}&uid=${encodeURIComponent(uid)}`,
    { method: 'GET', headers: { 'X-API-Key': env.API_KEY } }
  );
  const result = await resp.json() as ApiEnvelope<UserInfo | ApiErrorData>;
  if (!resp.ok || result.code !== 200) {
    return { error: (result.data as ApiErrorData)?.error ?? result.msg };
  }
  return { user: result.data as UserInfo };
}

Show full SKILL.md (153 more words)Show less

API 4: 列出用户(分页)

Endpoint: GET {BASE_URL}/api/v1/auth/list_users?project_name={project_name}

默认 max_results=100,最大 1000。通过 next_page_token 循环翻页。

Query 参数
参数必填说明
project_name是项目名
page_token否分页游标
max_results否每页数量,1–1000
TypeScript 示例
typescript
async function listAuthUsers(
  env: Env,
  options: { pageToken?: string; maxResults?: number } = {}
): Promise<{ users?: UserInfo[]; nextPageToken?: string; error?: string }> {
  const baseUrl = env.BASE_URL ?? 'https://pinme.cloud';
  const url = new URL('/api/v1/auth/list_users', baseUrl);
  url.searchParams.set('project_name', env.PROJECT_NAME);
  if (options.pageToken) url.searchParams.set('page_token', options.pageToken);
  if (options.maxResults) url.searchParams.set('max_results', String(options.maxResults));

  const resp = await fetch(url.toString(), { method: 'GET', headers: { 'X-API-Key': env.API_KEY } });
  const result = await resp.json() as ApiEnvelope<{ users: UserInfo[]; next_page_token?: string } | ApiErrorData>;
  if (!resp.ok || result.code !== 200) {
    return { error: (result.data as ApiErrorData)?.error ?? result.msg };
  }
  const data = result.data as { users: UserInfo[]; next_page_token?: string };
  return { users: data.users, nextPageToken: data.next_page_token };
}

// 批量遍历所有用户示例
async function* iterAllUsers(env: Env) {
  let pageToken: string | undefined;
  do {
    const { users, nextPageToken, error } = await listAuthUsers(env, { pageToken, maxResults: 1000 });
    if (error) throw new Error(error);
    for (const user of users ?? []) yield user;
    pageToken = nextPageToken;
  } while (pageToken);
}

前端集成(Firebase Auth)

create_worker 响应中包含 public_client_config,前端用它初始化 Firebase Auth SDK。

两种 api_key 区分
字段用途是否可暴露到浏览器
data.api_key项目 API Key,调用本文所有代理接口不能,只给 Worker/服务端
data.public_client_config.auth_api_keyFirebase Web API Key,初始化前端登录 SDK可以
public_client_config 字段说明
字段前端用途
public_client_config.auth_api_keyinitializeApp({ apiKey })
public_client_config.auth_domaininitializeApp({ authDomain })
public_client_config.auth_project_idinitializeApp({ projectId })
public_client_config.tenant_idauth.tenantId = config.tenant_id(必须设置,否则 token 归属错误)
前端 TypeScript 示例
typescript
import { initializeApp } from 'firebase/app'
import {
  type Auth,
  getAuth,
  GoogleAuthProvider,
  signInWithEmailAndPassword,
  signInWithPopup,
} from 'firebase/auth'

type PublicClientConfig = {
  tenant_id: string
  auth_api_key: string
  auth_domain: string
  auth_project_id: string
}

export function createProjectAuth(config: PublicClientConfig): Auth {
  const app = initializeApp({
    apiKey: config.auth_api_key,
    authDomain: config.auth_domain,
    projectId: config.auth_project_id,
  })
  const auth = getAuth(app)
  auth.tenantId = config.tenant_id  // 必须设置,确保 token 归属正确租户
  return auth
}

// 邮箱密码登录,返回 id_token
export async function loginWithEmail(auth: Auth, email: string, password: string): Promise<string> {
  const credential = await signInWithEmailAndPassword(auth, email, password)
  return credential.user.getIdToken()
}

// Google 登录,返回 id_token
export async function loginWithGoogle(auth: Auth): Promise<string> {
  const credential = await signInWithPopup(auth, new GoogleAuthProvider())
  return credential.user.getIdToken()
}

// 用法示例
// pinme create 会自动将 public_client_config 写入 frontend/src/utils/config.ts
import { public_client_config } from '../utils/config'

const auth = createProjectAuth(public_client_config)
const idToken = await loginWithGoogle(auth)
// 然后把 idToken 发给自己的 Worker,由 Worker 调用 verify_token

前端只负责登录和拿 id_token,不要直接持有项目 api_key。verify_token 必须由 Worker/服务端代调。 frontend/src/utils/config.ts 由 pinme create 自动生成,无需手动创建。


典型调用链路

邮箱密码注册流程:

  1. create_user → 创建用户并发出验证邮件
  2. 用户点击邮件链接完成验证
  3. 前端登录拿到 id_token
  4. verify_token → 校验 token,取得 uid
  5. 需要时再调 getAuthUser 读取完整用户信息

Google 登录流程:

  1. 前端完成 Google Sign-In,拿到 id_token
  2. verify_token → 校验 token(无需调用 create_user)

易错点

错误正确做法
只传 X-API-Key,忘记 project_name每个请求都要同时带 X-API-Key header 和 project_name query
verify_token 返回 403 时当 token 失效处理403 = 邮箱未验证,提示用户检查邮箱;401 才是 token 失效
create_user 成功就认为邮箱已验证创建成功只代表验证邮件已发,用户必须点击后才算验证
list_users 只取第一页有 next_page_token 时需继续请求,直到为空
成功判断只看 resp.ok同时判断 resp.ok && result.code === 200

© glitternetwork, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/pinme-auth of glitternetwork/pinme.

Open the folder on GitHubat commit 7822b05

Compare with similar skills

Pinme Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pinme Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pinme Auth this skillglitternetwork/pinme3.7k—~2.6kAutomated safety check: PassMIT
Node Backend Development Guidelinesdiet103/claude-code-infrastructure-showcase10k2 repos~2kAutomated safety check: PassMIT
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0
cmux Backend Rulesmanaflow-ai/cmux28k1 repos~682Automated safety check: PassCustom licence
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT

Similar skills

  • Node Backend Development Guidelines

    diet103/claude-code-infrastructure-showcase

    Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.

    10k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • cmux Backend Rules

    manaflow-ai/cmux

    Sets the backend TypeScript and Cloud VM rules for cmux: Effect-based services, thin route handlers, Postgres as source of truth, migrations and provider secrets.

    28k GitHub starsUsed in 1 repo~682 tokens
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Contributor guide for step three of adding a syncable entity to the Twenty server: write the validator, the migration action builder and the orchestrator wiring.

    58k GitHub stars~3.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from glitternetwork/pinme

  • Pinme LLM

    glitternetwork/pinme

    A skill your agent uses when a PinMe project (Worker TypeScript) needs to call OpenRouter-backed LLM APIs, including models, chat/completions, streaming, or OpenRouter web search.

    3.7k GitHub starsUsed in 1 repo~2.8k tokens
    Auto-check passed
  • Pinme

    glitternetwork/pinme

    A skill your agent uses when the user mentions "pinme", or needs to upload files, store to IPFS, create/publish/deploy websites or full-stack services (including frontend pages, backend APIs…

    3.7k GitHub stars~3.8k tokensUpdated 26 days ago
    Auto-check: notes
  • Pinme Email

    glitternetwork/pinme

    A skill your agent uses when a PinMe project (Worker TypeScript) needs to integrate email sending (sendemail).

    3.7k GitHub stars~1.2k tokensUpdated 26 days ago
    Auto-check passed
  • Pinme R2

    glitternetwork/pinme

    A skill your agent uses when a PinMe Cloudflare Worker needs R2 object storage, including secure file or image upload, streaming download, metadata lookup, deletion, listing, Range requests, or…

    3.7k GitHub stars~3.6k tokensUpdated 26 days ago
    Auto-check passed
  • Pinme Uniwebpay

    glitternetwork/pinme

    A skill your agent uses when generating, modifying, or reviewing PinMe Worker (Cloudflare Worker TypeScript) code that accepts payments through UniwebPay — payment links, products/prices, checkout…

    3.7k GitHub starsUsed in 1 repo~7.3k tokens
    Auto-check passed
  • Pinme Share

    glitternetwork/pinme

    A skill your agent uses when the user wants to share, publish, or upload a static result through PinMe, especially by generating a static HTML share page for a PinMe project link, deployed…

    3.7k GitHub stars~1.2k tokensUpdated 26 days ago
    Auto-check: notes

Works with

Categories

Questions about Pinme Auth

What does Pinme Auth do?

A skill your agent uses when a PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users, verifying idtokens, querying user info, or listing users via…. Pinme Auth is an agent skill from glitternetwork/pinme. Use when a PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users, verifying idtokens, querying user info, or listing users via Identity Platform auth proxy APIs.

When should I use Pinme Auth?

Pinme Auth fits situations like: A PinMe project (Worker TypeScript) needs to integrate user authentication — creating email/password users; verifying idtokens; querying user info; listing users via Identity Platform auth proxy APIs.

How do I install Pinme Auth in Claude Code?

Run `npx skills add glitternetwork/pinme --skill pinme-auth -a claude-code`. Or copy the skill folder (skills/pinme-auth in glitternetwork/pinme) into .claude/skills/pinme-auth in your project. Claude Code loads it when a task matches its description.

How do I install Pinme Auth in Codex?

Run `npx skills add glitternetwork/pinme --skill pinme-auth -a codex`. Or copy the skill folder (skills/pinme-auth in glitternetwork/pinme) into .agents/skills/pinme-auth in your project. Codex loads it when a task matches its description.

Can I use Pinme Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add glitternetwork/pinme --skill pinme-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pinme-auth, .gemini/skills/pinme-auth, .github/skills/pinme-auth and .opencode/skills/pinme-auth in your project.

What does Pinme Auth need to run?

Going by SKILL.md and its folder, Pinme Auth needs credentials named API_KEY. Our summary lists: A credential in API_KEY.

Does Pinme Auth access the network?

SKILL.md names 1 domain. In commands or code: pinme.cloud; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Pinme Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pinme Auth use?

Pinme Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pinme Auth use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pinme Auth?

Skills that share tags, products or a category with Pinme Auth: Node Backend Development Guidelines (diet103/claude-code-infrastructure-showcase, 10k stars), OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars), cmux Backend Rules (manaflow-ai/cmux, 28k stars) and Payload (payloadcms/payload, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pinme Auth?

glitternetwork (a GitHub organization) maintains it in glitternetwork/pinme, which has 3,746 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on September 12, 2026.

Source: glitternetwork/pinme on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.