Agent skill

Moonpay Auth

by moonpay in moonpay/skills

Set up the MoonPay CLI, authenticate, and manage local wallets.

MITAuto-check passed

Install Moonpay Auth

skills CLI
$ npx skills add moonpay/skills --skill moonpay-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install moonpay/skills moonpay-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/moonpay/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/moonpay-auth .claude/skills/moonpay-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
moonpay-auth
GitHub stars
113
Token cost
~1.2k tokens
SKILL.md length
479 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Set up the MoonPay CLI, authenticate, and manage local wallets.

  • Works in 3 steps: Run mp user retrieve first. → If it succeeds, a session already… → If it fails (no session), proceed with…
  • Create/import wallets
  • SKILL.md covers Install, Verify installation, Auth commands and Before logging in (REQUIRED), plus 6 more sections
  • Calls npm

What it does

Moonpay Auth is an agent skill from moonpay/skills. Set up the MoonPay CLI, authenticate, and manage local wallets. Use when commands fail, for login, or to create/import wallets.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Skills for AI agents to move money — on-ramps, swaps, wallets, deposits, and more via the MoonPay CLI. The licence is MIT.

When your agent uses it

  • Create/import wallets

Example prompts

  • “/moonpay-auth”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Run mp user retrieve first.
  2. If it succeeds, a session already exists. Tell the user which account is signed in and ask whether to switch
  3. If it fails (no session), proceed with mp login as normal.

What it can do on your machine

Read from SKILL.md and the folder at commit aa672ab. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Moonpay Auth loads about 1.2k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 479 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from moonpay/skills at commit aa672ab, republished under its MIT licence (© moonpay). 479 words, ~1,174 tokens.

Download SKILL.mdSave it as .claude/skills/moonpay-auth/SKILL.md (or your agent's skills folder).
name
moonpay-auth
description
Set up the MoonPay CLI, authenticate, and manage local wallets. Use when commands fail, for login, or to create/import wallets.
tags
setup

MoonPay auth and setup

Install

bash
npm i -g @moonpay/cli

This installs the mp (and moonpay) binary globally.

Verify installation

bash
mp --version
mp --help

Auth commands

bash
# Log in — returns a URL. Open it yourself if you can, otherwise share it with the user verbatim; opening it triggers the OTP code email.
mp login --email user@example.com

# Verify OTP code (user pastes it back from their email)
mp verify --email user@example.com --code 123456

# Check current user
mp user retrieve

# Log out
mp logout

mp login returns a URL. If you can open it yourself (e.g., browser access or a programmatic fetch), do that — it triggers the OTP email send. Otherwise, post the URL back to the user verbatim (don't paraphrase or strip query parameters) and let them open it. Either way the OTP lands in the user's email; they paste the code back, and you run mp verify.

Before logging in (REQUIRED)

Never call mp login blindly. Every login attempt must be preceded by a session check:

  1. Run mp user retrieve first.

  2. If it succeeds, a session already exists. Tell the user which account is signed in and ask whether to switch:

    "You're currently signed in as <email>. Log out and sign in as a different user? Reply YES to switch."

    Only on an explicit affirmative, run mp logout and then proceed with mp login. If the user declines or says anything ambiguous, treat the existing session as the one to use and skip the login.

  3. If it fails (no session), proceed with mp login as normal.

This matters because on a chat channel the user cannot see which account a command runs against. Without the confirmation step, an agent on a shared host can silently switch identities — and a "what's my balance" query returns someone else's portfolio. The check is one extra command; the alternative is a privacy incident.

Local wallet management

The CLI manages local wallets stored encrypted in ~/.config/moonpay/wallets.json. Private keys are encrypted with AES-256-GCM using a random key stored in your OS keychain. No password required — keys never leave the machine.

bash
# Create a new HD wallet (Solana, Ethereum, Bitcoin, Tron)
mp wallet create --name "my-wallet"

# Import from a mnemonic (all chains)
mp wallet import --name "restored" --mnemonic "word1 word2 ..."

# Import from a private key (single chain)
mp wallet import --name "imported" --key <hex-key> --chain ethereum

# List all local wallets
mp wallet list

# Get wallet details (by name or address)
mp wallet retrieve --wallet "my-wallet"

# Export mnemonic/key (interactive only — agents cannot run this)
mp wallet export --wallet "my-wallet"

# Delete a wallet (irreversible)
mp wallet delete --wallet "my-wallet" --confirm
Show full SKILL.md (197 more words)Show less

Workflow

  1. Run mp user retrieve to check if authenticated. If a session already exists, follow the prompt rules in Before logging in above before starting a new login.
  2. If no session, run mp login --email <email>, share the returned URL with the user, then run mp verify --email <email> --code <code> once they paste back the code from their email.
  3. Run mp wallet list to see local wallets.
  4. If no wallets, create one: mp wallet create --name "default".

Autonomous login

Agents can log in without human intervention if they have access to the user's email. For example, with the gog CLI (Google Workspace):

bash
# 1. Send OTP
mp login --email user@example.com

# 2. Read the OTP code from email
gog gmail search "Your MoonPay verification code" --max-results 1

# 3. Verify with the code
mp verify --email user@example.com --code <code>

This enables fully autonomous agent setup — no human in the loop.

Config locations

  • Wallets: ~/.config/moonpay/wallets.json (encrypted, AES-256-GCM)
  • Encryption key: OS keychain (moonpay-cli / encryption-key)
  • Credentials: ~/.config/moonpay/credentials.json (encrypted, AES-256-GCM)
  • Config: ~/.config/moonpay/config.json (base URL, client ID)

Security

  • Wallet secrets are always encrypted on disk
  • Encryption key is stored in macOS Keychain / Linux libsecret
  • No password to remember — the OS handles authentication
  • wallet export requires an interactive terminal (TTY) — agents and scripts cannot extract secrets
  • 24-word BIP39 mnemonics (256-bit entropy)
  • moonpay-swap-tokens — Swap or bridge tokens using local wallets.
  • moonpay-check-wallet — Check wallet balances.

© moonpay, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/moonpay-auth of moonpay/skills.

Open the folder on GitHubat commit aa672ab

Compare with similar skills

Moonpay Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Moonpay Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Moonpay Auth this skillmoonpay/skills113—~1.2kAutomated safety check: PassMIT
Clerk Authdavila7/claude-code-templates32k4 repos~376Automated safety check: PassMIT
Authmicrosoft/apm4k—~756Automated safety check: PassMIT
Agent Authenticationruvnet/ruflo74k3 repos~711Automated safety check: PassMIT
Browser Auth Flowruvnet/ruflo74k—~805Automated safety check: NotesMIT
OmniRoute Authenticationdiegosouzapw/OmniRoute74k—~1.8kAutomated safety check: PassMIT

Similar skills

  • Clerk Auth

    davila7/claude-code-templates

    Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user authentication, sign in, sign up.

    32k GitHub starsUsed in 4 repos~376 tokens
    Backend & APIsAuto-check passed
  • Auth

    microsoft/apm

    Official

    Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…

    4k GitHub stars~756 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Agent skill for authentication - invoke with $agent-authentication

    74k GitHub starsUsed in 3 repos~711 tokens
    Backend & APIsAuto-check passed
  • Browser Auth Flow

    ruvnet/ruflo

    Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md

    74k GitHub stars~805 tokensUpdated today
    Backend & APIsAuto-check: notes
  • OmniRoute Authentication

    diegosouzapw/OmniRoute

    Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard.

    74k GitHub stars~1.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Auth

    EpicenterHQ/epicenter

    Epicenter auth packages: @epicenter/auth and the Svelte adapter at @epicenter/auth/svelte, OAuth sessions, identity state, auth-owned fetch/WebSocket, and the reload gate that makes a page lifetime…

    4.8k GitHub stars~7k tokensUpdated today
    Backend & APIsAuto-check passed

More from moonpay/skills

All 39 skills in this repo
  • A skill your agent uses when accessing Alchemy APIs for RPC calls, token balances, NFT metadata, asset transfers, transaction simulation, or Alchemy-specific features.

    113 GitHub stars~2.1k tokensUpdated 27 days ago
    Auto-check: notes
  • Alchemy API

    moonpay/skills

    Integrates Alchemy blockchain APIs using an API key. An agent skill from moonpay/skills.

    113 GitHub stars~2.1k tokensUpdated 27 days ago
    Auto-check passed
  • Allium Onchain Data

    moonpay/skills

    Query blockchain data via Allium APIs. An agent skill from moonpay/skills.

    113 GitHub stars~1.9k tokensUpdated 27 days ago
    Auto-check passed
  • Corbits Marketplace

    moonpay/skills

    Paid API marketplace for AI agents via Corbits. An agent skill from moonpay/skills.

    113 GitHub stars~1.5k tokensUpdated 27 days ago
    Auto-check passed
  • Dune Analytics

    moonpay/skills

    Blockchain analytics via Dune REST API — execute DuneSQL queries against live on-chain data, discover decoded contract tables, and monitor credit usage.

    113 GitHub stars~1.3k tokensUpdated 27 days ago
    Auto-check passed
  • Moonpay Check Wallet

    moonpay/skills

    Check wallet balances and holdings. An agent skill from moonpay/skills.

    113 GitHub stars~450 tokensUpdated 27 days ago
    Auto-check passed

Questions about Moonpay Auth

What does Moonpay Auth do?

Set up the MoonPay CLI, authenticate, and manage local wallets. Moonpay Auth is an agent skill from moonpay/skills. Set up the MoonPay CLI, authenticate, and manage local wallets.

When should I use Moonpay Auth?

Moonpay Auth fits situations like: create/import wallets.

How do I install Moonpay Auth in Claude Code?

Run `npx skills add moonpay/skills --skill moonpay-auth -a claude-code`. Or copy the skill folder (skills/moonpay-auth in moonpay/skills) into .claude/skills/moonpay-auth in your project. Claude Code loads it when a task matches its description.

How do I install Moonpay Auth in Codex?

Run `npx skills add moonpay/skills --skill moonpay-auth -a codex`. Or copy the skill folder (skills/moonpay-auth in moonpay/skills) into .agents/skills/moonpay-auth in your project. Codex loads it when a task matches its description.

Can I use Moonpay Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add moonpay/skills --skill moonpay-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/moonpay-auth, .gemini/skills/moonpay-auth, .github/skills/moonpay-auth and .opencode/skills/moonpay-auth in your project.

What does Moonpay Auth need to run?

Going by SKILL.md and its folder, Moonpay Auth needs the command-line tools its instructions call (npm). Our summary lists: Node.js.

Does Moonpay Auth access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Moonpay Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Moonpay Auth use?

Moonpay Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Moonpay Auth use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Moonpay Auth?

Skills that share tags, products or a category with Moonpay Auth: Clerk Auth (davila7/claude-code-templates, 32k stars), Auth (microsoft/apm, 4k stars), Agent Authentication (ruvnet/ruflo, 74k stars) and Browser Auth Flow (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Moonpay Auth?

moonpay (a GitHub organization) maintains it in moonpay/skills, which has 113 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on September 10, 2026.

Source: moonpay/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.