Agent skill

Authendpoints

by madeyoga in madeyoga/AuthEndpoints

Compose AuthEndpoints 3.x in an ASP.NET Core host — AddAuthEndpoints, UseAuthEndpoints, MapAuthEndpoints, cookie vs Identity bearer vs Simple JWT, passkeys, CSRF, ReAuth, and production options.

MITAuto-check passedBackend & APIs

Install Authendpoints

skills CLI
$ npx skills add madeyoga/AuthEndpoints --skill authendpoints -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install madeyoga/AuthEndpoints authendpoints --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/madeyoga/AuthEndpoints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/authendpoints .claude/skills/authendpoints && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authendpoints
GitHub stars
121
Token cost
~3.1k tokens
SKILL.md length
1,124 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Compose AuthEndpoints 3.x in an ASP.NET Core host — AddAuthEndpoints, UseAuthEndpoints, MapAuthEndpoints, cookie vs Identity bearer vs Simple JWT, passkeys, CSRF, ReAuth, and production options.

  • Works in 3 steps: GET {IdentityPath}/csrfToken (default… → Send the token in the antiforgery header. → Send cookies (credentials: "include" /…
  • The project has the AuthEndpoints NuGet package
  • SKILL.md covers Install, Prefer the facade, Choose cookie vs bearer vs JWT and Login query flags, plus 7 more sections
  • Calls dotnet

What it does

Authendpoints is an agent skill from madeyoga/AuthEndpoints. Compose AuthEndpoints 3.x in an ASP.NET Core host — AddAuthEndpoints, UseAuthEndpoints, MapAuthEndpoints, cookie vs Identity bearer vs Simple JWT, passkeys, CSRF, ReAuth, and production options. Use when the project has the AuthEndpoints NuGet package, the user asks to add Identity auth API endpoints, or an agent is wiring login/register/session/token flows for a first-party web or mobile client.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication, Web application vulnerabilities and REST APIs. It works with ASP.NET Core. The repository describes itself as: A composable authentication endpoints library for aspnetcore. The licence is MIT.

When your agent uses it

  • The project has the AuthEndpoints NuGet package
  • The user asks to add Identity auth API endpoints
  • An agent is wiring login/register/session/token flows for a first-party web

Example prompts

  • “/authendpoints”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. GET {IdentityPath}/csrfToken (default /identity/csrfToken; JWT: {Jwt.Path}/csrfToken, default /auth/csrfToken) → JSON csrfToken.
  2. Send the token in the antiforgery header.
  3. Send cookies (credentials: "include" / Axios withCredentials).

What it can do on your machine

Read from SKILL.md and the folder at commit 70db53d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • authendpoints.harten.id

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authendpoints loads about 3.1k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,124 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from madeyoga/AuthEndpoints at commit 70db53d, republished under its MIT licence (© madeyoga). 1,124 words, ~3,124 tokens.

Download SKILL.mdSave it as .claude/skills/authendpoints/SKILL.md (or your agent's skills folder).
name
authendpoints
description
Compose AuthEndpoints 3.x in an ASP.NET Core host — AddAuthEndpoints, UseAuthEndpoints, MapAuthEndpoints, cookie vs Identity bearer vs Simple JWT, passkeys, CSRF, ReAuth, and production options. Use when the project has the AuthEndpoints NuGet package, the user asks to add Identity auth API endpoints, or an agent is wiring login/register/session/token flows for a first-party web or mobile client.
license
MIT

AuthEndpoints 3.x (library users)

Ready-made Identity auth API endpoints for first-party web and mobile clients. This skill is for apps that consume the NuGet package, not for changing the AuthEndpoints source repo.

Canonical docs: https://authendpoints.harten.id — follow those pages; do not invent APIs.

Requires .NET 10, ASP.NET Core Identity, and EF Core. The host DbContext is typically IdentityDbContext<TUser> (or with roles). TUser may use any Identity key type (string, Guid, long, …). Passwordless passkey account register needs a string or Guid key. The minted user id defaults to Guid.NewGuid() (UUID v4); register IPasskeyUserIdFactory to choose a different id.

Install

bash
dotnet add package AuthEndpoints

GitHub/Google OAuth is compose-only (independent preview versioning, not inside MapAuthEndpoints). Install the provider package you use. It depends on AuthEndpoints.External.OAuth. The core OAuth nupkg does not reference GitHub or Google handlers.

bash
dotnet add package AuthEndpoints.OAuth.GitHub --prerelease
dotnet add package AuthEndpoints.OAuth.Google --prerelease

AutoLinkByEmail defaults to false. Opt in only when a verified provider email should attach to a local account whose email is already confirmed. Host a page at ErrorPath. Unlink requires the application cookie, an antiforgery token, and a ReAuth principal, and it refuses the last sign-in method.

Docs: https://authendpoints.harten.id/modules/external-oauth

Prefer the facade

One Add / Use / Map triad. Cookie is the default sign-in. Native/mobile uses AuthEndpointsSignIn.IdentityBearer. Compose modules yourself only for JWT-only hosts, custom prefixes, or a mix the facade does not cover.

Default: Identity management + cookie sign-in at IdentityPath (/identity) and passkeys at PasskeyPath (/account). JWT is opt-in.

cs
builder.Services.AddDbContext<AppDbContext>(/* your provider */);

builder.Services.AddAuthEndpoints<AppUser, AppDbContext>(o =>
{
    o.Passkeys.ServerDomain = "example.com"; // required in Production when passkeys are enabled
});

// Required in Production (Identity's no-op sender is rejected).
builder.Services.AddTransient<IEmailSender<AppUser>, MyEmailSender>();

var app = builder.Build();

app.UseAuthEndpoints();          // authentication, authorization, rate limiting, antiforgery
app.MapAuthEndpoints<AppUser>(); // /identity (management + cookie) + /account (passkeys)
app.Run();
Identity bearer (native / mobile)

Same methods and pipeline. Maps Identity Login (JSON access and refresh tokens) instead of LoginCookie.

cs
builder.Services.AddAuthEndpoints<AppUser, AppDbContext>(AuthEndpointsSignIn.IdentityBearer, o =>
{
    o.Passkeys.ServerDomain = "example.com";
});

builder.Services.AddTransient<IEmailSender<AppUser>, MyEmailSender>();

var app = builder.Build();

app.UseAuthEndpoints();
app.MapAuthEndpoints<AppUser>(); // /identity (management + bearer login/refresh) + /account (passkeys)
app.Run();

AddAuthEndpoints returns IdentityBuilder for optional chaining. It registers Identity API endpoints, EF stores, IdentitySchemaVersions.Version3 (required for passkey credential storage), antiforgery, cookie or bearer auth helpers, ReAuth, and rate limits.

UseAuthEndpoints must run after exception-handling middleware. Enable HTTPS in Production separately. Safe to call once; a second call is a no-op.

Quick start: https://authendpoints.harten.id/getting-started/quick-start

Roles

Use the three-type overload so AddRoles runs before AddEntityFrameworkStores:

cs
builder.Services.AddAuthEndpoints<AppUser, AppRole, AppDbContext>(o =>
{
    o.Passkeys.ServerDomain = "example.com";
});

DbContext should be IdentityDbContext<AppUser, AppRole, TKey> (or equivalent). Do not chain bare .AddRoles<TRole>() after the two-type overload.

StackTypical clientHow to select
CookieFirst-party browser / SPAAddAuthEndpoints + MapAuthEndpoints
Identity bearerNative / mobile (tokens in JSON, no cookie jar)AddAuthEndpoints(..., AuthEndpointsSignIn.IdentityBearer) + MapAuthEndpoints
Simple JWTBrowser that wants a Bearer access token + HttpOnly refresh cookieFacade o.Jwt.Enabled = true and modelBuilder.UseRefreshToken()

Mixed web + native: map separate sign-in groups (or hosts) per client type. Do not map cookie and bearer login on the same path without separate groups.

Recipes: https://authendpoints.harten.id/composables/recipes

Paths below use IdentityPath (default /identity). Hosts that change o.IdentityPath must use that prefix instead.

MethodPathContract
POST{IdentityPath}/register{ email, password }. No session. Duplicate email returns 200.
POST{IdentityPath}/loginLoginRequest: { email, password, twoFactorCode?, twoFactorRecoveryCode? }. Cookie: empty body + Set-Cookie. Bearer: { accessToken, refreshToken }. No CSRF.
GET{IdentityPath}/csrfToken{ csrfToken }. Send as header RequestVerificationToken unless the host renamed it.
POST{IdentityPath}/logoutCSRF when the application cookie is in use.
POST{IdentityPath}/refreshIdentity bearer only. JSON refresh; returns { accessToken, refreshToken }.

Login query flags

Which handler is mapped decides which query flags work. Cookie facade / MapCookieAuthEndpoints maps LoginCookie. Bearer facade / MapBearerAuthEndpoints maps Identity Login. useCookies on the cookie-facade login URL does nothing.

Always the application cookie. Only useSessionCookies is read. useCookies is ignored.

QueryResult
omitted or useSessionCookies=truesession cookie (isPersistent = false)
useSessionCookies=falsepersistent cookie

Body is Identity LoginRequest (email, password, optional twoFactorCode / twoFactorRecoveryCode). POST {IdentityPath}/login (default /identity/login) does not need CSRF. Lockout on failure. Rate-limited.

Bearer facade → Identity Login

Cookie iff useCookies==true || useSessionCookies==true. Persistent iff useCookies==true && useSessionCookies!=true. Neither flag → Identity bearer tokens (accessToken, refreshToken).

QueryResult
neither flagIdentity bearer tokens
useCookies=true (and useSessionCookies not true)persistent application cookie
useSessionCookies=truesession application cookie

Default passkey completer (IdentityPasskeySignInCompleter) uses these Identity Login rules, not LoginCookie — even when password login uses the cookie facade.

Cookie sessions and the JWT refresh cookie need antiforgery on unsafe methods (POST / PUT / PATCH / DELETE). Login does not.

  1. GET {IdentityPath}/csrfToken (default /identity/csrfToken; JWT: {Jwt.Path}/csrfToken, default /auth/csrfToken) → JSON csrfToken.
  2. Send the token in the antiforgery header.
  3. Send cookies (credentials: "include" / Axios withCredentials).

The library calls AddAntiforgery() with no header override. ASP.NET Core's default header name is RequestVerificationToken. Hosts may set AntiforgeryOptions.HeaderName to X-CSRF-TOKEN (common for SPAs). Clients must use the header the host configured.

CSRF is skipped when the request is authenticated via Identity bearer or JWT Bearer and not via the application/external cookie. Cookie sessions still require CSRF even if a bearer token is also present.

Show full SKILL.md (396 more words)Show less

Facade options

PropertyDefaultNotes
IdentityPath/identityManagement + the configured sign-in stack
SignInCookieCookie or IdentityBearer. Pass IdentityBearer to AddAuthEndpoints, or set o.SignIn.
PasskeyPath/accountPasskey routes
RequireConfirmedAccounttrueConfirmed email required before sign-in. Set false only if the host accepts unconfirmed sign-in.
Passkeys.EnabledtrueWhen false, passkey DI and mapping are skipped
Passkeys.ServerDomainnullWebAuthn RP domain. Required in Production when enabled
Jwt.EnabledfalseWhen true, registers and maps JWT
Jwt.Path/authJWT route prefix
Jwt.ConfigurenullAction<SimpleJwtOptions> (issuer, audience, signing, lifetimes)
ConfigureIdentitynullAfter secure Identity defaults
ConfigurePasskeysnullAfter ServerDomain is applied
RequireEmailSenderInProductiontrueProduction must register a real IEmailSender<TUser>

Full table: https://authendpoints.harten.id/modules/configuration/

POST {IdentityPath}/register (default /identity/register) does not sign the user in. Duplicate email returns 200 OK (no enumeration). With the default confirmed-account policy, unconfirmed login is 401. Passwordless passkey register that creates a user sends the same confirmation email; the completer still skips a session until the account can sign in.

Passkeys

Enabled by default. In Production set Passkeys.ServerDomain, or disable with o.Passkeys.Enabled = false.

Mapped under {PasskeyPath}/passkeys (default /account/passkeys). CSRF is required for WebAuthn ceremonies. Add/rename/delete/creationOptions also require ReAuth. Passwordless register mints Guid.NewGuid() (UUID v4) unless the host registers IPasskeyUserIdFactory. POST {PasskeyPath}/passkeys/requestOptions takes optional JSON { email }. Empty or unknown email still returns 200 options. Identifier-first may reveal passkey presence via allowCredentials. Omit email for usernameless/discoverable login.

Facade JWT opt-in does not auto-select JwtPasskeySignInCompleter. Register it explicitly when passkey register/login should issue Simple JWT (access token + refresh cookie); that completer ignores cookie query flags.

Module: https://authendpoints.harten.id/modules/passkeys

Simple JWT (opt-in)

When o.Jwt.Enabled = true:

  • Call modelBuilder.UseRefreshToken() and migrate (AuthEndpoints.AuthEndpointsRefreshTokens).
  • Production: non-default issuer and audience; symmetric key ≥ 32 UTF-8 bytes (or RSA/ECDSA/X509).
  • Refresh cookie name: AuthEndpoints.Jwt.RefreshToken. Recreate the table if upgrading from plaintext storage.

Module: https://authendpoints.harten.id/modules/jwt

Compose when the facade does not fit

Custom prefixes, JWT-only, or a custom mix. Match DI to maps. Pipeline equivalent of UseAuthEndpoints:

cs
app.UseAuthentication();
app.UseAuthorization();
app.UseRateLimiter();
app.UseAntiforgery();
You mapYou register
MapIdentityManagementApiIdentity API endpoints + EF stores + token providers
MapCookieAuthEndpointsAddCookieAuthEndpoints() + AddAntiforgery()
MapBearerAuthEndpointsAddBearerAuthEndpoints()
MapJwtAuthEndpointsAddJwtEndpoints<TUser, TContext>(…) + UseRefreshToken()
MapPasskeyEndpointsAddPasskeyEndpoints<TUser>()

Map MapIdentityManagementApi once in production. Pair it with one of cookie | bearer | JWT per prefix.

https://authendpoints.harten.id/composables

ReAuth (step-up)

Manage 2FA/info mutations and sensitive passkey routes require ReAuth plus CSRF where applicable. Header: X-AuthEndpoints-Reauth with reauthToken. Cookie scheme: AuthEndpoints.ReAuth. Protect host endpoints with .RequireReauth().

https://authendpoints.harten.id/modules/reauth

Production checklist

  • HTTPS
  • Real IEmailSender<TUser>
  • Passkeys.ServerDomain if passkeys stay enabled; otherwise Passkeys.Enabled = false
  • JWT: UseRefreshToken(), real issuer/audience/signing material

https://authendpoints.harten.id/guides/production/

© madeyoga, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/authendpoints of madeyoga/AuthEndpoints.

Open the folder on GitHubat commit 70db53d

Compare with similar skills

Authendpoints next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authendpoints compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authendpoints this skillmadeyoga/AuthEndpoints121—~3.1kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~4kAutomated safety check: PassMIT
Dotnet APInovotnyllc/dotnet-artisan233—~1.6kAutomated safety check: PassMIT
Writing Csharp Codemicrosoft-foundry/foundry-agent-webapp127—~3.2kAutomated safety check: NotesMIT
Security ProtocolNoobyGains/godmode107—~2.4kAutomated safety check: NotesMIT

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Frappe Errors API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.

    187 GitHub starsUsed in 1 repo~4k tokens
    Backend & APIsAuto-check passed
  • Dotnet API

    novotnyllc/dotnet-artisan

    Builds ASP.NET Core APIs, EF Core data access, gRPC, SignalR, and backend services with middleware, security (OAuth, JWT, OWASP), resilience, messaging, OpenAPI, .NET Aspire, Semantic Kernel…

    233 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Writing Csharp Code

    microsoft-foundry/foundry-agent-webapp

    Provides C and ASP.NET Core coding standards for this repository.

    127 GitHub stars~3.2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Security Protocol

    NoobyGains/godmode

    A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…

    107 GitHub stars~2.4k tokensUpdated 7 mo ago
    Backend & APIsAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes

More from madeyoga/AuthEndpoints

  • Verify Authendpoints

    madeyoga/AuthEndpoints

    Drive the AuthEndpoints HTTP API via the in-repo test host (cookie sessions, Identity bearer, Simple JWT, CSRF, ReAuth).

    121 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Authendpoints

What does Authendpoints do?

Compose AuthEndpoints 3.x in an ASP.NET Core host — AddAuthEndpoints, UseAuthEndpoints, MapAuthEndpoints, cookie vs Identity bearer vs Simple JWT, passkeys, CSRF, ReAuth, and production options. Authendpoints is an agent skill from madeyoga/AuthEndpoints.NET Core host — AddAuthEndpoints, UseAuthEndpoints, MapAuthEndpoints, cookie vs Identity bearer vs Simple JWT, passkeys, CSRF, ReAuth, and production options.

When should I use Authendpoints?

Authendpoints fits situations like: the project has the AuthEndpoints NuGet package; the user asks to add Identity auth API endpoints; an agent is wiring login/register/session/token flows for a first-party web.

How do I install Authendpoints in Claude Code?

Run `npx skills add madeyoga/AuthEndpoints --skill authendpoints -a claude-code`. Or copy the skill folder (skills/authendpoints in madeyoga/AuthEndpoints) into .claude/skills/authendpoints in your project. Claude Code loads it when a task matches its description.

How do I install Authendpoints in Codex?

Run `npx skills add madeyoga/AuthEndpoints --skill authendpoints -a codex`. Or copy the skill folder (skills/authendpoints in madeyoga/AuthEndpoints) into .agents/skills/authendpoints in your project. Codex loads it when a task matches its description.

Can I use Authendpoints in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add madeyoga/AuthEndpoints --skill authendpoints -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authendpoints, .gemini/skills/authendpoints, .github/skills/authendpoints and .opencode/skills/authendpoints in your project.

What does Authendpoints need to run?

Going by SKILL.md and its folder, Authendpoints needs the command-line tools its instructions call (dotnet).

Does Authendpoints access the network?

SKILL.md names 1 domain. As links in the text: authendpoints.harten.id. This is read from the text; nothing was executed.

Is Authendpoints safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authendpoints use?

Authendpoints is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authendpoints use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authendpoints?

Skills that share tags, products or a category with Authendpoints: API Audit (briiirussell/cybersecurity-skills, 413 stars), Frappe Errors API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars), Dotnet API (novotnyllc/dotnet-artisan, 233 stars) and Writing Csharp Code (microsoft-foundry/foundry-agent-webapp, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authendpoints?

madeyoga (a GitHub user) maintains it in madeyoga/AuthEndpoints, which has 121 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 8, 2026.

Source: madeyoga/AuthEndpoints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.