Spa Auth Development
gdarko/laravel-vue-starter
Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.
Covers developing the LangBot core backend and web UI: dev setup, repo layout, API auth types, adding endpoints, migrations and keeping the MCP server in step.
$ npx skills add langbot-app/LangBot --skill langbot-dev -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install langbot-app/LangBot langbot-dev --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/langbot-app/LangBot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skills/langbot-dev .claude/skills/langbot-dev && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "langbot-dev" agent skill from https://github.com/langbot-app/LangBot/tree/master/skills/skills/langbot-dev into .claude/skills/langbot-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langbot-dev", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/langbot-app/LangBot/tree/master/skills/skills/langbot-devType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add langbot-app/LangBot --skill langbot-dev -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install langbot-app/LangBot langbot-dev --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbot-app/LangBot.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/skills/langbot-dev .agents/skills/langbot-dev && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "langbot-dev" agent skill from https://github.com/langbot-app/LangBot/tree/master/skills/skills/langbot-dev into .agents/skills/langbot-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langbot-dev", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbot-app/LangBot --skill langbot-dev -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install langbot-app/LangBot langbot-dev --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbot-app/LangBot.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/skills/langbot-dev .cursor/skills/langbot-dev && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "langbot-dev" agent skill from https://github.com/langbot-app/LangBot/tree/master/skills/skills/langbot-dev into .cursor/skills/langbot-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langbot-dev", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/langbot-app/LangBot.git --path skills/skills/langbot-dev--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add langbot-app/LangBot --skill langbot-dev -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install langbot-app/LangBot langbot-dev --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbot-app/LangBot.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/skills/langbot-dev .gemini/skills/langbot-dev && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "langbot-dev" agent skill from https://github.com/langbot-app/LangBot/tree/master/skills/skills/langbot-dev into .gemini/skills/langbot-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langbot-dev", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install langbot-app/LangBot langbot-devInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add langbot-app/LangBot --skill langbot-dev -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/langbot-app/LangBot.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/skills/langbot-dev .github/skills/langbot-dev && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "langbot-dev" agent skill from https://github.com/langbot-app/LangBot/tree/master/skills/skills/langbot-dev into .github/skills/langbot-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langbot-dev", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbot-app/LangBot --skill langbot-dev -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install langbot-app/LangBot langbot-dev --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbot-app/LangBot.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/skills/langbot-dev .opencode/skills/langbot-dev && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "langbot-dev" agent skill from https://github.com/langbot-app/LangBot/tree/master/skills/skills/langbot-dev into .opencode/skills/langbot-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langbot-dev", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
langbot-devCovers developing the LangBot core backend and web UI: dev setup, repo layout, API auth types, adding endpoints, migrations and keeping the MCP server in step.
This skill is for work inside the main LangBot repository, as opposed to plugin development or deployment, which have their own skills. The backend is Python on the Quart framework with dependencies managed by `uv`, and the web UI under `web/` is Vite with React Router, shadcn/ui and Tailwind, managed with `pnpm`. It notes that the UI is not Next.js, since the dev script runs `vite`.
The first run generates `data/config.yaml`, the database defaults to SQLite with PostgreSQL supported, and migrations run automatically on startup. Route authentication is declared per route as `NONE`, `USER_TOKEN`, `API_KEY` or `USER_TOKEN_OR_API_KEY`; authenticated routes receive an immutable request context, and API keys take their workspace from the key record, not from a request header. New endpoints need a controller, a matching service method and the right auth type, and the description adds that API changes must also update the MCP server and skills.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit de886ed. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvpnpmpipFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
USER_TOKENAPI_KEYUSER_TOKEN_OR_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
LangBot Core Development loads about 1.4k tokens when it runs. Until then it costs about 142 tokens; SKILL.md has 403 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
cp .env.example .envAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from langbot-app/LangBot at commit de886ed, republished under its Apache-2.0 licence (© langbot-app). 403 words, ~1,396 tokens.
.claude/skills/langbot-dev/SKILL.md (or your agent's skills folder).This skill covers developing the LangBot core (the main repo), distinct from
plugin development (see langbot-plugin-dev) and deployment (langbot-deploy).
>=3.11,<4.0, deps via uv. Framework: Quart (async
Flask). Serves the HTTP API + pre-built web UI on http://127.0.0.1:5300.web/): Vite + React Router 7 + shadcn/ui + Tailwind,
managed by pnpm. Dev server on :3000. (NOT Next.js — dev script is vite.)# Backend
pip install uv
uv sync --dev
uv run main.py # API + UI on http://127.0.0.1:5300
# Frontend (separate terminal)
cd web
cp .env.example .env
pnpm install
pnpm dev # http://127.0.0.1:3000 (reads VITE_API_BASE_URL)
# Lint/format hooks (CI runs the same checks)
uv run pre-commit installFirst run generates data/config.yaml; DB defaults to SQLite (PostgreSQL
supported). Migrations run automatically on startup.
src/langbot/
├── __main__.py # entrypoint, CLI flags (--standalone-runtime/-box/--debug)
├── pkg/
│ ├── api/
│ │ ├── http/ # Quart controllers + services
│ │ │ ├── controller/groups/ # route groups (@group.group_class)
│ │ │ └── service/ # business logic (called by controllers AND MCP)
│ │ └── mcp/ # MCP server (server.py = tools, mount.py = ASGI dispatch)
│ ├── core/ # app bootstrap, stages, task manager
│ ├── platform/ provider/ pipeline/ plugin/ box/ skill/ rag/ vector/
│ ├── command/ persistence/ storage/ config/ entity/ telemetry/
│ └── templates/config.yaml # config template (top-level: api, system, plugin, box, space...)
├── web/ # Vite SPA
└── docker/ # compose deploymentRoute auth is declared per-route via AuthType in
pkg/api/http/controller/group.py:
NONE — public.USER_TOKEN — web UI JWT (Authorization: Bearer <jwt>).API_KEY — X-API-Key or Authorization: Bearer <key>.USER_TOKEN_OR_API_KEY — either.Authenticated routes receive an immutable RequestContext containing the
principal, authorized Workspace membership, fixed-role permissions, instance,
request id, and placement generation. A browser's X-Workspace-Id is only a
selector and is always checked against the Account membership. Tenant services
must accept this context (or an explicit trusted execution context) and fail
closed when it is absent.
API-key authentication accepts:
config.yaml api.global_api_key only for a
community instance with exactly one local Workspace, thenlbk_ secret is stored only as a hash and is
bound to one Workspace, explicit scopes, status, and optional expiry.An API key derives its Workspace from the key record and ignores a caller's Workspace selector. Public Bot/Webhook routes similarly derive Workspace from the opaque owning resource rather than a header.
Route groups self-register via @group.group_class(name, path) and are
discovered by importutil.import_modules_in_pkg.
pkg/api/http/controller/groups/ and the matching
service method in pkg/api/http/service/.AuthType.pkg/api/mcp/server.py and update the langbot-mcp-ops skill. API and
MCP surface must stay aligned (see AGENTS.md).lbctl uses the route or capability, check the separate
langbot-cli client for compatibility.docs/service-api-openapi.json if you maintain the OpenAPI overview.Single migration set supports SQLite + PostgreSQL. Files in
src/langbot/pkg/persistence/alembic/versions/.
# From project root (needs data/config.yaml)
uv run python -m langbot.pkg.persistence.alembic_runner autogenerate "description"en_US + zh_Hans minimum, ja_JP where present).<type>(<scope>): <subject> (feat/fix/docs/refactor/...).uv run pytest tests/unit_tests -q # unit tests
uv run pytest tests/unit_tests/api -q # API service tests
uv run python tests/manual/mcp_smoke.py # MCP server e2e smokelangbot-plugin-dev — plugin SDK / runtime development.langbot-testing — WebUI/e2e QA harness (bin/lbs).langbot-deploy — Docker/compose deployment + config.langbot-mcp-ops — operating the LangBot MCP server.langbot-cli — lbctl, a standalone Service API client for managing running Workspaces.© langbot-app, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/skills/langbot-dev of langbot-app/LangBot.
Open the folder on GitHubat commit de886ed
LangBot Core Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| LangBot Core Development this skilllangbot-app/LangBot | 18k | — | ~1.4k | Automated safety check: Notes | Apache-2.0 | |
| Spa Auth Developmentgdarko/laravel-vue-starter | 145 | — | ~668 | Automated safety check: Notes | MIT | |
| Vue Component Developmentgdarko/laravel-vue-starter | 145 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Fastapi Appccplugins/awesome-claude-code-plugins | 967 | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Fullstack DevHHU3637kr/skills | 145 | 3 repos | ~8.6k | Automated safety check: Notes | MIT | |
| Fullstack Devinfometa/workbuddyskills | 342 | — | ~1k | Automated safety check: Pass | MIT |
gdarko/laravel-vue-starter
Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.
gdarko/laravel-vue-starter
Activate when creating or modifying Vue 3 components, pages, layouts, stores, or services in the frontend.
ccplugins/awesome-claude-code-plugins
Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.
HHU3637kr/skills
Full-stack backend architecture and frontend-backend integration guide.
infometa/workbuddyskills
Full-stack backend architecture and frontend-backend integration guide.
SpillwaveSolutions/agent-brain
Modern Python coaching covering language foundations through advanced production patterns.
langbot-app/LangBot
Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
langbot-app/LangBot
Guides building, migrating and testing LangBot messaging-platform adapters for the Event-Based Agents layout, with unified event and message conversion.
langbot-app/LangBot
Manages a LangBot instance over its built-in MCP server: endpoint, API-key authentication, client config and the tool set for bots, processors and more.
langbot-app/LangBot
Browses and searches the LangBot Space marketplaces for plugins, MCP servers and skills through its read-only MCP server, authenticated with a personal access token.
langbot-app/LangBot
Prepares a LangBot development and testing environment for an agent, covering service startup, proxy settings and browser access through Computer Use or Playwright MCP.
Categories
Covers developing the LangBot core backend and web UI: dev setup, repo layout, API auth types, adding endpoints, migrations and keeping the MCP server in step. This skill is for work inside the main LangBot repository, as opposed to plugin development or deployment, which have their own skills. The backend is Python on the Quart framework with dependencies managed by `uv`, and the web UI under `web/` is Vite with React Router, shadcn/ui and Tailwind, managed with `pnpm`.
LangBot Core Development fits situations like: adding an HTTP API endpoint to the LangBot backend; choosing between user token, API key and public access for a route; setting up the Python and pnpm dev environment for LangBot; writing an Alembic migration for a LangBot schema change.
Run `npx skills add langbot-app/LangBot --skill langbot-dev -a claude-code`. Or copy the skill folder (skills/skills/langbot-dev in langbot-app/LangBot) into .claude/skills/langbot-dev in your project. Claude Code loads it when a task matches its description.
Run `npx skills add langbot-app/LangBot --skill langbot-dev -a codex`. Or copy the skill folder (skills/skills/langbot-dev in langbot-app/LangBot) into .agents/skills/langbot-dev in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbot-app/LangBot --skill langbot-dev -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/langbot-dev, .gemini/skills/langbot-dev, .github/skills/langbot-dev and .opencode/skills/langbot-dev in your project.
Going by SKILL.md and its folder, LangBot Core Development needs the command-line tools its instructions call (uv, pnpm and pip) and credentials named USER_TOKEN, API_KEY and USER_TOKEN_OR_API_KEY. Our summary lists: Python with `uv`; pnpm for the web frontend.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
LangBot Core Development is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with LangBot Core Development: Spa Auth Development (gdarko/laravel-vue-starter, 145 stars), Vue Component Development (gdarko/laravel-vue-starter, 145 stars), Fastapi App (ccplugins/awesome-claude-code-plugins, 967 stars) and Fullstack Dev (HHU3637kr/skills, 145 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
langbot-app (a GitHub organization) maintains it in langbot-app/LangBot, which has 18,033 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: langbot-app/LangBot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.