Passport Development
trypostit/trypost
Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.
Sets the rules and checklist for adding a new quota provider, or changing an existing adapter, in quota-axi, covering credential sources, liveness probes and tests.
$ npx skills add kunchenguid/quota-axi --skill provider-onboarding -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kunchenguid/quota-axi provider-onboarding --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kunchenguid/quota-axi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/provider-onboarding .claude/skills/provider-onboarding && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "provider-onboarding" agent skill from https://github.com/kunchenguid/quota-axi/tree/main/skills/provider-onboarding into .claude/skills/provider-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "provider-onboarding", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kunchenguid/quota-axi/tree/main/skills/provider-onboardingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kunchenguid/quota-axi --skill provider-onboarding -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kunchenguid/quota-axi provider-onboarding --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kunchenguid/quota-axi.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/provider-onboarding .agents/skills/provider-onboarding && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "provider-onboarding" agent skill from https://github.com/kunchenguid/quota-axi/tree/main/skills/provider-onboarding into .agents/skills/provider-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "provider-onboarding", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kunchenguid/quota-axi --skill provider-onboarding -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kunchenguid/quota-axi provider-onboarding --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kunchenguid/quota-axi.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/provider-onboarding .cursor/skills/provider-onboarding && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "provider-onboarding" agent skill from https://github.com/kunchenguid/quota-axi/tree/main/skills/provider-onboarding into .cursor/skills/provider-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "provider-onboarding", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kunchenguid/quota-axi.git --path skills/provider-onboarding--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kunchenguid/quota-axi --skill provider-onboarding -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kunchenguid/quota-axi provider-onboarding --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kunchenguid/quota-axi.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/provider-onboarding .gemini/skills/provider-onboarding && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "provider-onboarding" agent skill from https://github.com/kunchenguid/quota-axi/tree/main/skills/provider-onboarding into .gemini/skills/provider-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "provider-onboarding", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kunchenguid/quota-axi provider-onboardingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kunchenguid/quota-axi --skill provider-onboarding -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kunchenguid/quota-axi.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/provider-onboarding .github/skills/provider-onboarding && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "provider-onboarding" agent skill from https://github.com/kunchenguid/quota-axi/tree/main/skills/provider-onboarding into .github/skills/provider-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "provider-onboarding", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kunchenguid/quota-axi --skill provider-onboarding -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kunchenguid/quota-axi provider-onboarding --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kunchenguid/quota-axi.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/provider-onboarding .opencode/skills/provider-onboarding && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "provider-onboarding" agent skill from https://github.com/kunchenguid/quota-axi/tree/main/skills/provider-onboarding into .opencode/skills/provider-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "provider-onboarding", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
provider-onboardingSets the rules and checklist for adding a new quota provider, or changing an existing adapter, in quota-axi, covering credential sources, liveness probes and tests.
This skill is the project's rulebook for adding quota providers or modifying provider adapters in quota-axi. Adapter behavior must be an original clean-room implementation based on the vendor's own HTTP and OAuth behavior, with no vendored third-party adapter code; the Z.AI adapter is the single credited exception. All remote requests go through providerFetch in src/lib/http.ts so proxy environment variables apply consistently, and process-table reads go through currentUserProcessListArgs in src/lib/process.ts.
The onboarding checklist begins by listing every credential source in order of ownership stability, with the priority set as a named constant. Local resolution distinguishes absent, structurally invalid, unsupported, read error and resolved results, and credentialPresent is derived once from it. A separate, bounded, read-only liveness probe then classifies outcomes as usable, live with no quota, definitively rejected or transient. Expired stored credentials are enrolled rather than skipped, and presence alone never counts as liveness.
Per its description, the skill goes on to cover multi-source handover between credential sources, the delegated refresh contract and the testing rules that provider changes must follow.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8ba593c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
claudeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Quota Provider Onboarding loads about 2.3k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 1,106 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kunchenguid/quota-axi at commit 8ba593c, republished under its MIT licence (© kunchenguid). 1,106 words, ~2,305 tokens.
.claude/skills/provider-onboarding/SKILL.md (or your agent's skills folder).This document defines the requirements, shared machinery, and safety invariants for onboarding new quota providers or modifying existing adapters in quota-axi.
src/providers/zai.ts.src/lib/http.ts (providerFetch) so standard HTTP_PROXY, HTTPS_PROXY, and NO_PROXY policies apply consistently without leaking proxy credentials in logs. Do not use global fetch directly.src/lib/http.ts pairs the installed undici build's ProxyAgent with that same build's fetch because Node's built-in global fetch only accepts dispatchers from its bundled undici, and Node 26 rejects external ProxyAgent instances with InvalidArgumentError: invalid onError method.currentUserProcessListArgs in src/lib/process.ts to handle platform flag differences portably (Linux procps rejects BSD -x alongside -u).When adding a new provider or migrating an existing adapter:
Enumerate every source in ownership-stability order:
COPILOT_SOURCE_ORDER).absent, structurally_invalid, unsupported, read_error, and resolved (stored-valid or stored-expired) at the typed local resolution boundary.classifyPiAuthEntry in src/lib/pi-auth-store.ts.credentialPresent once from local resolution rather than ad hoc at call sites.Separate local resolution from the bounded read-only liveness probe:
usable, live_no_quota, definitively_rejected, or transient.Handover only after definitive credential failure:
state.degradedSources).Add comprehensive adapter regression tests:
test/credential-contract.test.ts.Credential selection is shared in src/providers/credential-selection.ts:
expiresAt or expired fields are advisory only within a source, never a verdict or a reason to reorder declared sources.selectCredential. Codex, Kimi, Copilot, and Devin call it once per source so each provider's ownership-stability order remains authoritative.expired resolution carries the stored token for probe use only; it must never be logged, cached, or rendered.--profile-only is the fail-closed single-account quota probe for Claude and Codex: it requires CLAUDE_CONFIG_DIR or CODEX_HOME, reads only that profile's native credential file, and bypasses alternate sources, delegated refresh, and quota cache access (full JSON keeps non-secret account/source/attempt evidence; ordinary output stays redacted). Omitting the flag must preserve legacy discovery and cache behavior. Contract: README Profile-only quota reads.src/lib/source-attempts.ts classifies attempts as status: "failed" or skipped with credentialPresent. Adapters set degraded: false on non-credential attempts (e.g. Grok's live model catalog probe).withQuotaSemantics in src/interpretation.ts publishes state.degradedSources on fresh readings only. src/render.ts emits the degraded_source attention row.Shared machinery lives in src/providers/delegated-refresh.ts. It is the single carve-out to quota-axi's read-only boundary:
Eligibility criteria: A delegate is eligible ONLY when:
Mechanism: quota-axi executes the vendor CLI's own smallest non-interactive rotation command (e.g. claude doctor, grok models) and re-reads the file/store that CLI updated.
Never exchange tokens: quota-axi must never perform an OAuth refresh-token exchange itself. These tokens rotate on use; a second exchange signs the user out of the measured tool.
Presence only: Delegated refresh inspects the refresh token's presence only (Object.hasOwn(credential, "refresh_token")). quota-axi never retains, logs, renders, caches, or sends its value. Pi brokers may read a stored refresh value only to classify it as a usable literal, then discard it.
Never signal the child: Quota-axi never signals or force-kills a delegated child process. The budget bounds only how long quota-axi waits. The child runs in its own process group (detached: true) so Ctrl+C on a live TUI does not abort it. If the command exceeds budget, resolve as unconfirmed/refresh_timed_out (reported as unmeasured or stale, never as sign-out, and never retiring cache).
Claude safety check: Before delegating Claude refresh, src/lib/running-processes.ts must confirm no Claude Code process is running, since Claude Code owns that session's refresh. If the process table cannot be listed, stay read-only. The check and spawn are not atomic - the check only narrows the common repeated --tui versus live-session collision; together with never signaling the delegate it is strictly safer than force-killing without adding a failure mode. Contract: README Delegated credential refresh.
Approved delegates: Only commands whose rotation behavior is empirically established from the vendor CLI are permitted:
claude doctorgrok modelsapp-server JSON-RPC probeAll other providers (Cursor, Copilot, Kimi, Z.AI, Alibaba, OpenCode Go, Antigravity, Command Code, MiniMax, MiMo, DeepSeek, OpenRouter, ElevenLabs, Devin, Muse, Higgsfield) remain strictly read-only.
Option gating: Delegated refresh is gated by ProviderOptions.refreshCredentials. --no-credential-refresh disables it; the auth command always passes false. Tests must specify it explicitly to prevent accidental CLI spawning.
test/fixtures/. Never use real secrets or developer tokens.security), Windows Credential Manager (CredReadW), process table (ps), and remote HTTP requests.© kunchenguid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/provider-onboarding of kunchenguid/quota-axi.
Open the folder on GitHubat commit 8ba593c
Quota Provider Onboarding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Quota Provider Onboarding this skillkunchenguid/quota-axi | 146 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Passport Developmenttrypostit/trypost | 685 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Soundcloud API Integrationsoundcloud/api | 259 | — | ~787 | Automated safety check: Pass | None | |
| MCP API Key AuthenticationYourdaylight/stock_datasource | 189 | — | ~1.2k | Automated safety check: Pass | MIT | |
| OmniRoute API Keysdiegosouzapw/OmniRoute | 74k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Venice API Keysveniceai/skills | 143 | — | ~3.8k | Automated safety check: Pass | MIT |
trypostit/trypost
Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.
soundcloud/api
Integrates applications with the SoundCloud HTTP API using OAuth 2.1, OpenAPI, and developer docs.
Yourdaylight/stock_datasource
Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics.
diegosouzapw/OmniRoute
Documents the OmniRoute REST endpoints for creating, listing, updating, regenerating and deleting API keys, with per-key scopes, spending limits, expiry and device lists.
veniceai/skills
Manages Venice API keys through the /api_keys endpoints: create, list, update and revoke keys, set spending limits, and read rate limits.
veniceai/skills
High-level map of the Venice.ai API: base URL, auth modes per endpoint, endpoint categories, response headers, pricing model, error shape and versioning.
kunchenguid/quota-axi
Documents release automation, CI workflow constraints, the contribution gate and generated-file rules for the quota-axi repository, driven by release-please.
kunchenguid/quota-axi
Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts.
kunchenguid/quota-axi
Reference of credential sources, quota windows, endpoint shapes, error recovery and quirks for each provider supported by the quota-axi tool.
kunchenguid/quota-axi
Specifies how quota-axi reads LLM subscription quota windows, derives pace and runway, computes a selection signal and renders output in TOON, JSON and TUI tiers.
kunchenguid/quota-axi
Report local Claude, Codex, Cursor, GitHub Copilot, Grok, Kimi, Z.AI, Alibaba, OpenCode Go, Antigravity, Command Code, MiniMax, MiMo, DeepSeek, OpenRouter, ElevenLabs, Devin, Muse, and Higgsfield…
Categories
Sets the rules and checklist for adding a new quota provider, or changing an existing adapter, in quota-axi, covering credential sources, liveness probes and tests. This skill is the project's rulebook for adding quota providers or modifying provider adapters in quota-axi.AI adapter is the single credited exception.
Quota Provider Onboarding fits situations like: adding support for a new quota provider to quota-axi; modifying an existing provider adapter's credential lookup or refresh logic; reviewing a provider pull request against the project's credential and proxy rules; deciding how to classify a credential that is stored but expired.
Run `npx skills add kunchenguid/quota-axi --skill provider-onboarding -a claude-code`. Or copy the skill folder (skills/provider-onboarding in kunchenguid/quota-axi) into .claude/skills/provider-onboarding in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kunchenguid/quota-axi --skill provider-onboarding -a codex`. Or copy the skill folder (skills/provider-onboarding in kunchenguid/quota-axi) into .agents/skills/provider-onboarding in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kunchenguid/quota-axi --skill provider-onboarding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/provider-onboarding, .gemini/skills/provider-onboarding, .github/skills/provider-onboarding and .opencode/skills/provider-onboarding in your project.
Going by SKILL.md and its folder, Quota Provider Onboarding needs the command-line tools its instructions call (claude). Our summary lists: A checkout of the quota-axi repository.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Quota Provider Onboarding is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Quota Provider Onboarding: Passport Development (trypostit/trypost, 685 stars), Soundcloud API Integration (soundcloud/api, 259 stars), MCP API Key Authentication (Yourdaylight/stock_datasource, 189 stars) and OmniRoute API Keys (diegosouzapw/OmniRoute, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kunchenguid (a GitHub user) maintains it in kunchenguid/quota-axi, which has 146 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.
Source: kunchenguid/quota-axi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.