Cognito
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
A skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…
$ npx skills add kid-sid/claude-spellbook --skill auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kid-sid/claude-spellbook auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auth .claude/skills/auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auth" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/auth into .claude/skills/auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kid-sid/claude-spellbook/tree/main/skills/authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kid-sid/claude-spellbook --skill auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kid-sid/claude-spellbook auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/auth .agents/skills/auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auth" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/auth into .agents/skills/auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kid-sid/claude-spellbook --skill auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kid-sid/claude-spellbook auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/auth .cursor/skills/auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auth" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/auth into .cursor/skills/auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kid-sid/claude-spellbook.git --path skills/auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kid-sid/claude-spellbook --skill auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kid-sid/claude-spellbook auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/auth .gemini/skills/auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auth" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/auth into .gemini/skills/auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kid-sid/claude-spellbook authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kid-sid/claude-spellbook --skill auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/auth .github/skills/auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auth" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/auth into .github/skills/auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kid-sid/claude-spellbook --skill auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kid-sid/claude-spellbook auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/auth .opencode/skills/auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auth" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/auth into .opencode/skills/auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
authA skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…
Auth is an agent skill from kid-sid/claude-spellbook. Use when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API endpoints, or handling token refresh and revocation.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering OAuth and OpenID Connect, Authorization and RBAC and Authentication. The repository describes itself as: A curated collection of skills, prompts, and workflows that extend Claude's capabilities — your personal grimoire for AI-powered development. The licence is MIT.
Read from SKILL.md and the folder at commit a7c2ac9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python, typescript and go).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
JWT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auth loads about 3.2k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 789 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kid-sid/claude-spellbook at commit a7c2ac9, republished under its MIT licence (© kid-sid). 789 words, ~3,212 tokens.
.claude/skills/auth/SKILL.md (or your agent's skills folder).Patterns for identity, token management, and access control across web APIs and services.
| Concept | Question answered | Example |
|---|---|---|
| Authentication | Who are you? | Login with email + password |
| Authorization | What can you do? | Admin can delete; viewer can only read |
| Identity | What do we know about you? | Email, roles, tenant ID in the token |
| Type | Storage | Lifespan | Use for |
|---|---|---|---|
| Access token (JWT) | Memory / header | 5–60 min | API calls |
| Refresh token (opaque) | HttpOnly cookie | Days–weeks | Obtain new access tokens |
| Session cookie | HttpOnly cookie | Session or sliding | Traditional web apps |
| API key | Server-side only | Long-lived | M2M, developer integrations |
# Python — PyJWT
import jwt
from datetime import datetime, timedelta, UTC
SECRET = "..." # use RS256 with a key pair in production
def issue_token(user_id: str, roles: list[str]) -> str:
return jwt.encode(
{
"sub": user_id,
"roles": roles,
"iat": datetime.now(UTC),
"exp": datetime.now(UTC) + timedelta(minutes=15),
},
SECRET,
algorithm="HS256",
)
def verify_token(token: str) -> dict:
return jwt.decode(token, SECRET, algorithms=["HS256"])// TypeScript — jose
import { SignJWT, jwtVerify } from "jose";
const secret = new TextEncoder().encode(process.env.JWT_SECRET);
async function issueToken(userId: string, roles: string[]): Promise<string> {
return new SignJWT({ sub: userId, roles })
.setProtectedHeader({ alg: "HS256" })
.setIssuedAt()
.setExpirationTime("15m")
.sign(secret);
}
async function verifyToken(token: string) {
const { payload } = await jwtVerify(token, secret);
return payload;
}// Go — golang-jwt/jwt
import (
"github.com/golang-jwt/jwt/v5"
"time"
)
type Claims struct {
Roles []string `json:"roles"`
jwt.RegisteredClaims
}
func IssueToken(userID string, roles []string, secret []byte) (string, error) {
claims := Claims{
Roles: roles,
RegisteredClaims: jwt.RegisteredClaims{
Subject: userID,
IssuedAt: jwt.NewNumericDate(time.Now()),
ExpiresAt: jwt.NewNumericDate(time.Now().Add(15 * time.Minute)),
},
}
return jwt.NewWithClaims(jwt.SigningMethodHS256, claims).SignedString(secret)
}| HS256 | RS256 | |
|---|---|---|
| Key type | Shared secret | Private/public key pair |
| Who can verify | Anyone with the secret | Anyone with the public key |
| Best for | Single service | Microservices, public JWKS endpoint |
| Rotation | Requires coordinated redeploy | Rotate private key; publish new JWKS |
Use RS256 in production when multiple services verify tokens, or when tokens are issued by an identity provider.
| Flow | Use when | Notes |
|---|---|---|
| Authorization Code + PKCE | Browser SPA, mobile app | No client secret on device |
| Authorization Code | Server-side web app | Store client secret server-side |
| Client Credentials | M2M / service accounts | No user involved |
| Device Code | CLI tools, smart TVs | User authenticates on a second device |
Never use Implicit flow — it is deprecated (RFC 9700).
// 1. Generate PKCE values
function generateCodeVerifier(): string {
const array = new Uint8Array(32);
crypto.getRandomValues(array);
return btoa(String.fromCharCode(...array)).replace(/[+/=]/g, (c) =>
({ "+": "-", "/": "_", "=": "" })[c]!
);
}
async function generateCodeChallenge(verifier: string): Promise<string> {
const data = new TextEncoder().encode(verifier);
const digest = await crypto.subtle.digest("SHA-256", data);
return btoa(String.fromCharCode(...new Uint8Array(digest)))
.replace(/[+/=]/g, (c) => ({ "+": "-", "/": "_", "=": "" })[c]!);
}
// 2. Redirect to provider
const verifier = generateCodeVerifier();
sessionStorage.setItem("pkce_verifier", verifier);
const challenge = await generateCodeChallenge(verifier);
const params = new URLSearchParams({
response_type: "code",
client_id: CLIENT_ID,
redirect_uri: REDIRECT_URI,
scope: "openid profile email",
code_challenge: challenge,
code_challenge_method: "S256",
state: crypto.randomUUID(), // store and verify on return
});
window.location.href = `${PROVIDER_URL}/authorize?${params}`;
// 3. Exchange code for tokens (on redirect back)
async function handleCallback(code: string): Promise<void> {
const verifier = sessionStorage.getItem("pkce_verifier")!;
const res = await fetch(`${PROVIDER_URL}/token`, {
method: "POST",
headers: { "Content-Type": "application/x-www-form-urlencoded" },
body: new URLSearchParams({
grant_type: "authorization_code",
code,
redirect_uri: REDIRECT_URI,
client_id: CLIENT_ID,
code_verifier: verifier,
}),
});
const { access_token, refresh_token, id_token } = await res.json();
// store access_token in memory, refresh_token in HttpOnly cookie via backend
}# Python — httpx
import httpx
def get_m2m_token(client_id: str, client_secret: str, token_url: str) -> str:
r = httpx.post(
token_url,
data={
"grant_type": "client_credentials",
"client_id": client_id,
"client_secret": client_secret,
"scope": "api:read api:write",
},
)
r.raise_for_status()
return r.json()["access_token"]| Location | XSS safe | CSRF safe | Notes |
|---|---|---|---|
| Memory (JS variable) | Yes | Yes | Lost on page refresh; best for SPAs |
| HttpOnly cookie | Yes | No — add CSRF token | Best for refresh tokens |
| localStorage | No | Yes | Never store tokens here |
| sessionStorage | No | Yes | Cleared on tab close; still XSS-vulnerable |
Rule: Store access tokens in memory. Store refresh tokens in HttpOnly, SameSite=Strict cookies. Never put tokens in localStorage.
let accessToken: string | null = null;
async function getValidToken(): Promise<string> {
if (accessToken && !isExpiringSoon(accessToken)) return accessToken;
const res = await fetch("/auth/refresh", {
method: "POST",
credentials: "include", // sends HttpOnly refresh token cookie
});
if (!res.ok) {
// refresh token expired — redirect to login
window.location.href = "/login";
throw new Error("Session expired");
}
accessToken = (await res.json()).access_token;
return accessToken;
}
function isExpiringSoon(token: string): boolean {
const { exp } = JSON.parse(atob(token.split(".")[1]));
return exp * 1000 - Date.now() < 60_000; // refresh if < 60s left
}| Strategy | How | Trade-off |
|---|---|---|
| Short expiry | 5–15 min access tokens | No revocation needed; stale window is small |
| Token blacklist | Store revoked JTIs in Redis | Instant revocation; requires Redis lookup per request |
| Refresh token rotation | Issue new refresh token on each use; invalidate old | Detects theft; one-time-use tokens |
| Opaque tokens + introspection | Validate tokens against auth server | Instant revocation; adds latency |
# FastAPI
from functools import wraps
from fastapi import Depends, HTTPException, status
from typing import Callable
def require_roles(*roles: str) -> Callable:
def dependency(token_data: dict = Depends(get_current_user)):
user_roles = set(token_data.get("roles", []))
if not user_roles.intersection(roles):
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN)
return token_data
return dependency
@router.delete("/users/{user_id}")
async def delete_user(
user_id: str,
_=Depends(require_roles("admin")),
):
...// Express middleware
function requireRoles(...roles: string[]) {
return (req: Request, res: Response, next: NextFunction) => {
const userRoles: string[] = res.locals.user?.roles ?? [];
if (!roles.some((r) => userRoles.includes(r))) {
return res.status(403).json({ error: "Forbidden" });
}
next();
};
}
router.delete("/users/:id", requireRoles("admin"), deleteUserHandler);# Simple policy engine
def can(user: dict, action: str, resource: dict) -> bool:
if "admin" in user["roles"]:
return True
if action == "read" and resource["public"]:
return True
if action in ("update", "delete") and resource["owner_id"] == user["id"]:
return True
return False
# Usage
if not can(current_user, "delete", post):
raise HTTPException(status_code=403)Always use a slow, salted hashing algorithm. Never use MD5, SHA-1, or SHA-256 for passwords.
| Algorithm | Library (Python) | Library (Node) | Recommended? |
|---|---|---|---|
| bcrypt | bcrypt | bcrypt / argon2-browser | Yes |
| Argon2id | argon2-cffi | argon2-browser | Yes — preferred |
| scrypt | stdlib hashlib | stdlib crypto | Yes |
| PBKDF2 | stdlib hashlib | stdlib crypto | Acceptable |
| MD5 / SHA-* | — | — | Never |
# Python — argon2-cffi
from argon2 import PasswordHasher
ph = PasswordHasher()
def hash_password(password: str) -> str:
return ph.hash(password)
def verify_password(hashed: str, password: str) -> bool:
try:
return ph.verify(hashed, password)
except Exception:
return Falsestate parameter in OAuth2 — omitting state enables CSRF attacks on the callback endpoint.alg header from the token — an attacker can set alg: none; always pin the algorithm server-side.* or admin scopes violate least privilege.alg: none and algorithm-confusion attacks blockedstate parameter generated, stored, and verified on callback© kid-sid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/auth of kid-sid/claude-spellbook.
Open the folder on GitHubat commit a7c2ac9
Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auth this skillkid-sid/claude-spellbook | 189 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Cognitoitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Auth Implementation Patternsynulihao/AgentSkillOS | 617 | 9 repos | ~4.4k | Automated safety check: Pass | None | |
| Passport Developmenttrypostit/trypost | 676 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Supercheck Security Authsupercheck-io/supercheck | 215 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | |
| Authenticationcodewithmukesh/dotnet-claude-kit | 751 | 1 repos | ~1.9k | Automated safety check: Pass | MIT |
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
ynulihao/AgentSkillOS
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.
trypostit/trypost
Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.
supercheck-io/supercheck
Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…
codewithmukesh/dotnet-claude-kit
Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
kid-sid/claude-spellbook
A skill your agent uses when building or reviewing UI components for keyboard and screen reader compatibility, adding ARIA to custom widgets, auditing a page for WCAG AA conformance, or preparing…
kid-sid/claude-spellbook
A skill your agent uses when building, wiring, or debugging an Agentex agent — choosing agent type, configuring acp.py and manifest.yaml, using adk.messages or adk.state, or resolving…
kid-sid/claude-spellbook
A skill your agent uses when building production LLM applications — designing RAG pipelines, choosing vector databases, implementing agent orchestration, optimizing cost, or adding AI safety…
kid-sid/claude-spellbook
A skill your agent uses when building or refactoring Angular applications — choosing between signals, RxJS, and NgRx for state, configuring routing with guards and lazy loading, optimizing change…
kid-sid/claude-spellbook
A skill your agent uses when designing new REST endpoints, reviewing an existing API contract, adding pagination or filtering, planning a versioning strategy, or building a public or partner-facing…
kid-sid/claude-spellbook
A skill your agent uses when writing Python code that integrates with Azure Blob Storage, AI Search, Document Intelligence, or Key Vault — or when configuring Managed Identity auth, designing a…
Categories
A skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…. Auth is an agent skill from kid-sid/claude-spellbook. Use when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API endpoints, or handling token refresh and revocation.
Auth fits situations like: implementing login flows; validating JWTs; setting up OAuth2/OIDC with a provider; designing role-based.
Run `npx skills add kid-sid/claude-spellbook --skill auth -a claude-code`. Or copy the skill folder (skills/auth in kid-sid/claude-spellbook) into .claude/skills/auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kid-sid/claude-spellbook --skill auth -a codex`. Or copy the skill folder (skills/auth in kid-sid/claude-spellbook) into .agents/skills/auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kid-sid/claude-spellbook --skill auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth, .gemini/skills/auth, .github/skills/auth and .opencode/skills/auth in your project.
Going by SKILL.md and its folder, Auth needs credentials named JWT_SECRET. Our summary lists: Python 3; A credential in JWT_SECRET.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Auth: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars), Passport Development (trypostit/trypost, 676 stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kid-sid (a GitHub user) maintains it in kid-sid/claude-spellbook, which has 189 GitHub stars. The repository holds 54 skills in this directory. The repository was last updated on August 5, 2026.
Source: kid-sid/claude-spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.