Agent skill

Auth

by kid-sid in kid-sid/claude-spellbook

A skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…

MITAuto-check passedBackend & APIs

Install Auth

skills CLI
$ npx skills add kid-sid/claude-spellbook --skill auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kid-sid/claude-spellbook auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auth .claude/skills/auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auth
GitHub stars
189
Token cost
~3.2k tokens
SKILL.md length
789 words
Files
1
Skills in repo
54
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…

  • Implementing login flows
  • SKILL.md covers When to Activate, Core Concepts, JWT Patterns and OAuth2 / OIDC, plus 6 more sections
  • Needs JWT_SECRET
  • Validating JWTs

What it does

Auth is an agent skill from kid-sid/claude-spellbook. Use when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API endpoints, or handling token refresh and revocation.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect, Authorization and RBAC and Authentication. The repository describes itself as: A curated collection of skills, prompts, and workflows that extend Claude's capabilities — your personal grimoire for AI-powered development. The licence is MIT.

When your agent uses it

  • Implementing login flows
  • Validating JWTs
  • Setting up OAuth2/OIDC with a provider
  • Designing role-based

Example prompts

  • “/auth”

Requirements

  • Python 3
  • A credential in JWT_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit a7c2ac9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, typescript and go).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auth loads about 3.2k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 789 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kid-sid/claude-spellbook at commit a7c2ac9, republished under its MIT licence (© kid-sid). 789 words, ~3,212 tokens.

Download SKILL.mdSave it as .claude/skills/auth/SKILL.md (or your agent's skills folder).
name
auth
description
Use when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API endpoints, or handling token refresh and revocation.

Authentication & Authorization

Patterns for identity, token management, and access control across web APIs and services.

When to Activate

  • Implementing login, logout, or registration flows
  • Issuing, validating, or refreshing JWTs
  • Integrating an OAuth2/OIDC provider (Google, GitHub, Auth0, Keycloak)
  • Designing role-based (RBAC) or attribute-based (ABAC) access control
  • Securing REST or GraphQL endpoints with middleware/guards
  • Handling token revocation, rotation, or blacklisting
  • Auditing an existing auth implementation for security gaps

Core Concepts

Authentication vs. Authorization
ConceptQuestion answeredExample
AuthenticationWho are you?Login with email + password
AuthorizationWhat can you do?Admin can delete; viewer can only read
IdentityWhat do we know about you?Email, roles, tenant ID in the token
Token Types
TypeStorageLifespanUse for
Access token (JWT)Memory / header5–60 minAPI calls
Refresh token (opaque)HttpOnly cookieDays–weeksObtain new access tokens
Session cookieHttpOnly cookieSession or slidingTraditional web apps
API keyServer-side onlyLong-livedM2M, developer integrations

JWT Patterns

Structure and Signing
python
# Python — PyJWT
import jwt
from datetime import datetime, timedelta, UTC

SECRET = "..."  # use RS256 with a key pair in production

def issue_token(user_id: str, roles: list[str]) -> str:
    return jwt.encode(
        {
            "sub": user_id,
            "roles": roles,
            "iat": datetime.now(UTC),
            "exp": datetime.now(UTC) + timedelta(minutes=15),
        },
        SECRET,
        algorithm="HS256",
    )

def verify_token(token: str) -> dict:
    return jwt.decode(token, SECRET, algorithms=["HS256"])
typescript
// TypeScript — jose
import { SignJWT, jwtVerify } from "jose";

const secret = new TextEncoder().encode(process.env.JWT_SECRET);

async function issueToken(userId: string, roles: string[]): Promise<string> {
  return new SignJWT({ sub: userId, roles })
    .setProtectedHeader({ alg: "HS256" })
    .setIssuedAt()
    .setExpirationTime("15m")
    .sign(secret);
}

async function verifyToken(token: string) {
  const { payload } = await jwtVerify(token, secret);
  return payload;
}
go
// Go — golang-jwt/jwt
import (
    "github.com/golang-jwt/jwt/v5"
    "time"
)

type Claims struct {
    Roles []string `json:"roles"`
    jwt.RegisteredClaims
}

func IssueToken(userID string, roles []string, secret []byte) (string, error) {
    claims := Claims{
        Roles: roles,
        RegisteredClaims: jwt.RegisteredClaims{
            Subject:   userID,
            IssuedAt:  jwt.NewNumericDate(time.Now()),
            ExpiresAt: jwt.NewNumericDate(time.Now().Add(15 * time.Minute)),
        },
    }
    return jwt.NewWithClaims(jwt.SigningMethodHS256, claims).SignedString(secret)
}
RS256 vs HS256
HS256RS256
Key typeShared secretPrivate/public key pair
Who can verifyAnyone with the secretAnyone with the public key
Best forSingle serviceMicroservices, public JWKS endpoint
RotationRequires coordinated redeployRotate private key; publish new JWKS

Use RS256 in production when multiple services verify tokens, or when tokens are issued by an identity provider.


OAuth2 / OIDC

Flow Selection
FlowUse whenNotes
Authorization Code + PKCEBrowser SPA, mobile appNo client secret on device
Authorization CodeServer-side web appStore client secret server-side
Client CredentialsM2M / service accountsNo user involved
Device CodeCLI tools, smart TVsUser authenticates on a second device

Never use Implicit flow — it is deprecated (RFC 9700).

Authorization Code + PKCE (SPA)
typescript
// 1. Generate PKCE values
function generateCodeVerifier(): string {
  const array = new Uint8Array(32);
  crypto.getRandomValues(array);
  return btoa(String.fromCharCode(...array)).replace(/[+/=]/g, (c) =>
    ({ "+": "-", "/": "_", "=": "" })[c]!
  );
}

async function generateCodeChallenge(verifier: string): Promise<string> {
  const data = new TextEncoder().encode(verifier);
  const digest = await crypto.subtle.digest("SHA-256", data);
  return btoa(String.fromCharCode(...new Uint8Array(digest)))
    .replace(/[+/=]/g, (c) => ({ "+": "-", "/": "_", "=": "" })[c]!);
}

// 2. Redirect to provider
const verifier = generateCodeVerifier();
sessionStorage.setItem("pkce_verifier", verifier);
const challenge = await generateCodeChallenge(verifier);

const params = new URLSearchParams({
  response_type: "code",
  client_id: CLIENT_ID,
  redirect_uri: REDIRECT_URI,
  scope: "openid profile email",
  code_challenge: challenge,
  code_challenge_method: "S256",
  state: crypto.randomUUID(), // store and verify on return
});
window.location.href = `${PROVIDER_URL}/authorize?${params}`;

// 3. Exchange code for tokens (on redirect back)
async function handleCallback(code: string): Promise<void> {
  const verifier = sessionStorage.getItem("pkce_verifier")!;
  const res = await fetch(`${PROVIDER_URL}/token`, {
    method: "POST",
    headers: { "Content-Type": "application/x-www-form-urlencoded" },
    body: new URLSearchParams({
      grant_type: "authorization_code",
      code,
      redirect_uri: REDIRECT_URI,
      client_id: CLIENT_ID,
      code_verifier: verifier,
    }),
  });
  const { access_token, refresh_token, id_token } = await res.json();
  // store access_token in memory, refresh_token in HttpOnly cookie via backend
}
Client Credentials (M2M)
python
# Python — httpx
import httpx

def get_m2m_token(client_id: str, client_secret: str, token_url: str) -> str:
    r = httpx.post(
        token_url,
        data={
            "grant_type": "client_credentials",
            "client_id": client_id,
            "client_secret": client_secret,
            "scope": "api:read api:write",
        },
    )
    r.raise_for_status()
    return r.json()["access_token"]

Token Storage

LocationXSS safeCSRF safeNotes
Memory (JS variable)YesYesLost on page refresh; best for SPAs
HttpOnly cookieYesNo — add CSRF tokenBest for refresh tokens
localStorageNoYesNever store tokens here
sessionStorageNoYesCleared on tab close; still XSS-vulnerable

Rule: Store access tokens in memory. Store refresh tokens in HttpOnly, SameSite=Strict cookies. Never put tokens in localStorage.


Token Refresh and Revocation

Silent Refresh Pattern
typescript
let accessToken: string | null = null;

async function getValidToken(): Promise<string> {
  if (accessToken && !isExpiringSoon(accessToken)) return accessToken;

  const res = await fetch("/auth/refresh", {
    method: "POST",
    credentials: "include", // sends HttpOnly refresh token cookie
  });
  if (!res.ok) {
    // refresh token expired — redirect to login
    window.location.href = "/login";
    throw new Error("Session expired");
  }
  accessToken = (await res.json()).access_token;
  return accessToken;
}

function isExpiringSoon(token: string): boolean {
  const { exp } = JSON.parse(atob(token.split(".")[1]));
  return exp * 1000 - Date.now() < 60_000; // refresh if < 60s left
}
Revocation Strategies
StrategyHowTrade-off
Short expiry5–15 min access tokensNo revocation needed; stale window is small
Token blacklistStore revoked JTIs in RedisInstant revocation; requires Redis lookup per request
Refresh token rotationIssue new refresh token on each use; invalidate oldDetects theft; one-time-use tokens
Opaque tokens + introspectionValidate tokens against auth serverInstant revocation; adds latency

Access Control (RBAC / ABAC)

RBAC Middleware
python
# FastAPI
from functools import wraps
from fastapi import Depends, HTTPException, status
from typing import Callable

def require_roles(*roles: str) -> Callable:
    def dependency(token_data: dict = Depends(get_current_user)):
        user_roles = set(token_data.get("roles", []))
        if not user_roles.intersection(roles):
            raise HTTPException(status_code=status.HTTP_403_FORBIDDEN)
        return token_data
    return dependency

@router.delete("/users/{user_id}")
async def delete_user(
    user_id: str,
    _=Depends(require_roles("admin")),
):
    ...
typescript
// Express middleware
function requireRoles(...roles: string[]) {
  return (req: Request, res: Response, next: NextFunction) => {
    const userRoles: string[] = res.locals.user?.roles ?? [];
    if (!roles.some((r) => userRoles.includes(r))) {
      return res.status(403).json({ error: "Forbidden" });
    }
    next();
  };
}

router.delete("/users/:id", requireRoles("admin"), deleteUserHandler);
ABAC Policy Check
python
# Simple policy engine
def can(user: dict, action: str, resource: dict) -> bool:
    if "admin" in user["roles"]:
        return True
    if action == "read" and resource["public"]:
        return True
    if action in ("update", "delete") and resource["owner_id"] == user["id"]:
        return True
    return False

# Usage
if not can(current_user, "delete", post):
    raise HTTPException(status_code=403)

Password Hashing

Always use a slow, salted hashing algorithm. Never use MD5, SHA-1, or SHA-256 for passwords.

AlgorithmLibrary (Python)Library (Node)Recommended?
bcryptbcryptbcrypt / argon2-browserYes
Argon2idargon2-cffiargon2-browserYes — preferred
scryptstdlib hashlibstdlib cryptoYes
PBKDF2stdlib hashlibstdlib cryptoAcceptable
MD5 / SHA-*——Never
python
# Python — argon2-cffi
from argon2 import PasswordHasher

ph = PasswordHasher()

def hash_password(password: str) -> str:
    return ph.hash(password)

def verify_password(hashed: str, password: str) -> bool:
    try:
        return ph.verify(hashed, password)
    except Exception:
        return False

Show full SKILL.md (317 more words)Show less

Red Flags

  • Storing tokens in localStorage — XSS can steal every token; use HttpOnly cookies for refresh tokens and in-memory for access tokens.
  • Using HS256 across multiple services — all services share the secret; a compromise of one exposes all; use RS256 with a JWKS endpoint.
  • Long-lived access tokens — a 24-hour JWT cannot be revoked without a blacklist; keep them under 15 minutes.
  • Skipping state parameter in OAuth2 — omitting state enables CSRF attacks on the callback endpoint.
  • Rolling your own crypto — never implement JWT signing, hashing, or encryption from scratch; use audited libraries.
  • Trusting the alg header from the token — an attacker can set alg: none; always pin the algorithm server-side.
  • Returning 404 instead of 403 — security-by-obscurity doesn't prevent enumeration; return 403 Forbidden for authorization failures.
  • No token rotation on refresh — refresh tokens that never rotate are permanent credentials; rotate on every use and invalidate the old one.
  • Putting secrets in JWTs — JWTs are base64-encoded, not encrypted; any party with the token can read the payload.
  • Broad OAuth scopes — request only the minimum scopes needed; * or admin scopes violate least privilege.

Checklist

  • Access tokens expire in 15 minutes or less
  • Refresh tokens stored in HttpOnly, SameSite=Strict cookies — not localStorage
  • Access tokens stored in memory only — never persisted to storage
  • JWT algorithm pinned server-side — alg: none and algorithm-confusion attacks blocked
  • OAuth2 state parameter generated, stored, and verified on callback
  • PKCE used for all browser and mobile OAuth2 flows
  • Passwords hashed with Argon2id or bcrypt — never SHA-* or MD5
  • Refresh token rotation enabled — old token invalidated on each use
  • Role/permission check applied at the handler level, not just the route group
  • 401 returned for unauthenticated requests, 403 for unauthorized — never 404
  • Sensitive claims (PII, internal IDs) not included in JWT payload
  • HTTPS enforced on all auth endpoints — no token transmission over HTTP
  • Rate limiting applied to login, register, and token endpoints
  • Token revocation strategy documented and implemented (blacklist or short expiry)

© kid-sid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/auth of kid-sid/claude-spellbook.

Open the folder on GitHubat commit a7c2ac9

Compare with similar skills

Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auth this skillkid-sid/claude-spellbook189—~3.2kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS6179 repos~4.4kAutomated safety check: PassNone
Passport Developmenttrypostit/trypost676—~1.9kAutomated safety check: PassMIT
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Authenticationcodewithmukesh/dotnet-claude-kit7511 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 9 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    676 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed

More from kid-sid/claude-spellbook

All 54 skills in this repo
  • Accessibility

    kid-sid/claude-spellbook

    A skill your agent uses when building or reviewing UI components for keyboard and screen reader compatibility, adding ARIA to custom widgets, auditing a page for WCAG AA conformance, or preparing…

    189 GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Agentex

    kid-sid/claude-spellbook

    A skill your agent uses when building, wiring, or debugging an Agentex agent — choosing agent type, configuring acp.py and manifest.yaml, using adk.messages or adk.state, or resolving…

    189 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • AI Engineer

    kid-sid/claude-spellbook

    A skill your agent uses when building production LLM applications — designing RAG pipelines, choosing vector databases, implementing agent orchestration, optimizing cost, or adding AI safety…

    189 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Angular

    kid-sid/claude-spellbook

    A skill your agent uses when building or refactoring Angular applications — choosing between signals, RxJS, and NgRx for state, configuring routing with guards and lazy loading, optimizing change…

    189 GitHub stars~5k tokensUpdated 2 mo ago
    Auto-check passed
  • API Design

    kid-sid/claude-spellbook

    A skill your agent uses when designing new REST endpoints, reviewing an existing API contract, adding pagination or filtering, planning a versioning strategy, or building a public or partner-facing…

    189 GitHub stars~3.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Azure

    kid-sid/claude-spellbook

    A skill your agent uses when writing Python code that integrates with Azure Blob Storage, AI Search, Document Intelligence, or Key Vault — or when configuring Managed Identity auth, designing a…

    189 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check: notes

Categories

Questions about Auth

What does Auth do?

A skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…. Auth is an agent skill from kid-sid/claude-spellbook. Use when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API endpoints, or handling token refresh and revocation.

When should I use Auth?

Auth fits situations like: implementing login flows; validating JWTs; setting up OAuth2/OIDC with a provider; designing role-based.

How do I install Auth in Claude Code?

Run `npx skills add kid-sid/claude-spellbook --skill auth -a claude-code`. Or copy the skill folder (skills/auth in kid-sid/claude-spellbook) into .claude/skills/auth in your project. Claude Code loads it when a task matches its description.

How do I install Auth in Codex?

Run `npx skills add kid-sid/claude-spellbook --skill auth -a codex`. Or copy the skill folder (skills/auth in kid-sid/claude-spellbook) into .agents/skills/auth in your project. Codex loads it when a task matches its description.

Can I use Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kid-sid/claude-spellbook --skill auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth, .gemini/skills/auth, .github/skills/auth and .opencode/skills/auth in your project.

What does Auth need to run?

Going by SKILL.md and its folder, Auth needs credentials named JWT_SECRET. Our summary lists: Python 3; A credential in JWT_SECRET.

Does Auth access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auth use?

Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auth use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auth?

Skills that share tags, products or a category with Auth: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars), Passport Development (trypostit/trypost, 676 stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auth?

kid-sid (a GitHub user) maintains it in kid-sid/claude-spellbook, which has 189 GitHub stars. The repository holds 54 skills in this directory. The repository was last updated on August 5, 2026.

Source: kid-sid/claude-spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.