Official agent skill

Auth

by microsoft in microsoft/apm

Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…

OfficialMITAuto-check passedBackend & APIs

Install Auth

skills CLI
$ npx skills add microsoft/apm --skill auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/apm auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/apm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.apm/skills/auth .claude/skills/auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auth
GitHub stars
4k
Token cost
~756 tokens
SKILL.md length
314 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…

  • Works in 3 steps: ADO_APM_PAT env var if set → AAD bearer via az account… → Otherwise: auth-failed error from…
  • Tasks that involve Authentication
  • SKILL.md covers When to activate, Key rule, Canonical reference and Bearer-token authentication…
  • Calls az and git; needs GITHUB_TOKEN and GH_TOKEN

What it does

Auth is an agent skill from microsoft/apm, published by the product's own GitHub organization. Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth' isn't mentioned explicitly.

Its SKILL.md is about 760 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and Monitoring and alerting. It works with GitHub, Git and Microsoft Azure. The repository describes itself as: Agent Package Manager. The licence is MIT.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve Monitoring and alerting

Example prompts

  • “/auth”

Requirements

  • A credential in GITHUB_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. ADO_APM_PAT env var if set
  2. AAD bearer via az account get-access-token --resource 499b84ac-1321-427f-aa17-267ca6975798 if az is installed and az account show succeeds
  3. Otherwise: auth-failed error from build_error_context

What it can do on your machine

Read from SKILL.md and the folder at commit 280b8a7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auth loads about 756 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 314 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~756

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/apm at commit 280b8a7, republished under its MIT licence (© microsoft). 314 words, ~756 tokens.

Download SKILL.mdSave it as .claude/skills/auth/SKILL.md (or your agent's skills folder).
name
auth
description
Activate when code touches token management, credential resolution, git auth flows, GITHUB_APM_PAT, ADO_APM_PAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth' isn't mentioned explicitly.

Auth Skill

Auth expert persona

When to activate

  • Any change to src/apm_cli/core/auth.py or src/apm_cli/core/token_manager.py
  • Code that reads GITHUB_APM_PAT, GITHUB_TOKEN, GH_TOKEN, ADO_APM_PAT
  • Code using git ls-remote, git clone, or GitHub/ADO API calls
  • Error messages mentioning tokens, authentication, or credentials
  • Changes to github_downloader.py auth paths
  • Per-host or per-org token resolution logic

Key rule

All auth flows MUST go through AuthResolver. No direct os.getenv() for token variables in application code.

Canonical reference

The full per-org -> global -> credential-fill -> fallback resolution flow is in docs/src/content/docs/getting-started/authentication.md (mermaid flowchart). Treat it as the single source of truth; if behavior diverges, fix the diagram in the same PR.

Bearer-token authentication for ADO

ADO hosts (dev.azure.com, *.visualstudio.com) resolve auth in this order:

  1. ADO_APM_PAT env var if set
  2. AAD bearer via az account get-access-token --resource 499b84ac-1321-427f-aa17-267ca6975798 if az is installed and az account show succeeds
  3. Otherwise: auth-failed error from build_error_context

ADO_APM_PAT is the env var name used by the auth flow. The AAD bearer source constant lives in src/apm_cli/core/token_manager.py as GitHubTokenManager.ADO_BEARER_SOURCE = "AAD_BEARER_AZ_CLI".

Stale-PAT silent fallback: if ADO_APM_PAT is rejected with HTTP 401, APM retries with the az bearer and emits:

[!] ADO_APM_PAT was rejected for {host} (HTTP 401); fell back to az cli bearer.
[!]     Consider unsetting the stale variable.

Verbose source line (one per host, emitted under --verbose):

[i] dev.azure.com -- using bearer from az cli (source: AAD_BEARER_AZ_CLI)
[i] dev.azure.com -- token from ADO_APM_PAT

Diagnostic cases (_emit_stale_pat_diagnostic + build_error_context in src/apm_cli/core/auth.py):

  1. No PAT, no az: No ADO_APM_PAT was set and az CLI is not installed. -> install az, run az login --tenant <tenant>, or set ADO_APM_PAT.
  2. No PAT, az not signed in: az CLI is installed but no active session was found. -> run az login --tenant <tenant> against the tenant that owns the org, or set ADO_APM_PAT.
  3. No PAT, wrong tenant: az CLI returned a token but the org does not accept it (likely a tenant mismatch). -> run az login --tenant <correct-tenant>, or set ADO_APM_PAT.
  4. PAT 401, no az fallback: ADO_APM_PAT was rejected (HTTP 401) and no az cli fallback was available. -> rotate the PAT, or install az and run az login --tenant <tenant>.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .apm/skills/auth of microsoft/apm.

Open the folder on GitHubat commit 280b8a7

Compare with similar skills

Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auth this skillmicrosoft/apm4k—~756Automated safety check: PassMIT
GitHub AuthRedWoodOG/Hermes-Desktop1773 repos~1.9kAutomated safety check: WarnMIT
Admingrafana/skills278—~1.5kAutomated safety check: PassApache-2.0
Star History Chartdavila7/claude-code-templates32k—~1.1kAutomated safety check: PassMIT
Setting Up Cloudwatch Observabilityaws/agent-toolkit-for-aws2.8k—~5kAutomated safety check: PassApache-2.0
Atmos Authcloudposse/atmos1.4k—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • GitHub Auth

    RedWoodOG/Hermes-Desktop

    Set up GitHub authentication for the agent using git (universally available) or the gh CLI.

    177 GitHub starsUsed in 3 repos~1.9k tokens
    Backend & APIsAuto-check: warnings
  • Admin

    grafana/skills

    Official

    Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

    278 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Star History Chart

    davila7/claude-code-templates

    Add a self-hosted "Stargazers over time" chart to any GitHub repo's README.

    32k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Setting Up Cloudwatch Observability

    aws/agent-toolkit-for-aws

    Official

    Sets up CloudWatch observability for the first time - Omni (CloudWatch Application Observability) and classic CloudWatch.

    2.8k GitHub stars~5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Atmos Auth

    cloudposse/atmos

    Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

    1.4k GitHub stars~4.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Managing Cloud Identity With Okta

    mukul975/Anthropic-Cybersecurity-Skills

    Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from microsoft/apm

All 27 skills in this repo
  • Cut Release

    microsoft/apm

    Official

    A skill your agent uses to cut an APM release from the current worktree: assess whether the cycle since the last tag warrants a patch or minor bump (semver discipline against the…

    4k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Docs Corpus Audit

    microsoft/apm

    Official

    A skill your agent uses to run a holistic regrounding pass on the entire microsoft/apm documentation corpus against current source code, page-by-page, and emit surgical fixes for stale claims.

    4k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Official

    A skill your agent uses to verify CLAIM-LEVEL grounding of a documentation page (or set of pages) against the source code.

    4k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Official

    A skill your agent uses to write the PR description (PR body) for any pull request opened against microsoft/apm.

    4k GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Official

    A skill your agent uses to implement ONE microsoft/apm issue already selected by autopilot-issue-delivery-scheduler.

    4k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Official

    Drive ONE already selected open pull request in microsoft/apm to mergeable.

    4k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed

Questions about Auth

What does Auth do?

Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…. Auth is an agent skill from microsoft/apm, published by the product's own GitHub organization. Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth' isn't mentioned explicitly.

When should I use Auth?

Auth fits situations like: tasks that involve Authentication; tasks that involve Monitoring and alerting.

How do I install Auth in Claude Code?

Run `npx skills add microsoft/apm --skill auth -a claude-code`. Or copy the skill folder (.apm/skills/auth in microsoft/apm) into .claude/skills/auth in your project. Claude Code loads it when a task matches its description.

How do I install Auth in Codex?

Run `npx skills add microsoft/apm --skill auth -a codex`. Or copy the skill folder (.apm/skills/auth in microsoft/apm) into .agents/skills/auth in your project. Codex loads it when a task matches its description.

Can I use Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/apm --skill auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth, .gemini/skills/auth, .github/skills/auth and .opencode/skills/auth in your project.

What does Auth need to run?

Going by SKILL.md and its folder, Auth needs the command-line tools its instructions call (az and git) and credentials named GITHUB_TOKEN and GH_TOKEN. Our summary lists: A credential in GITHUB_TOKEN.

Does Auth access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auth use?

Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auth use?

About 756 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auth?

Skills that share tags, products or a category with Auth: GitHub Auth (RedWoodOG/Hermes-Desktop, 177 stars), Admin (grafana/skills, 278 stars), Star History Chart (davila7/claude-code-templates, 32k stars) and Setting Up Cloudwatch Observability (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auth?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/apm, which has 3,968 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/apm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.