Agent skill

Convex Setup Auth

by spokvulcan in spokvulcan/poker-planning

Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.

MITAuto-check passedBackend & APIs

Install Convex Setup Auth

skills CLI
$ npx skills add spokvulcan/poker-planning --skill convex-setup-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spokvulcan/poker-planning convex-setup-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spokvulcan/poker-planning.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/convex-setup-auth .claude/skills/convex-setup-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
convex-setup-auth
GitHub stars
114
Used in
8 other repos
Token cost
~1.8k tokens
SKILL.md length
798 words
Files
7 (incl. references, assets)
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.

  • Works in 3 steps: Ask the user which auth solution they… → If the repo already uses a provider,… → If the user has not chosen a provider…
  • Protected functions
  • SKILL.md covers When to Use, When Not to Use, First Step: Choose the Auth… and After Choosing a Provider, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Convex Setup Auth is an agent skill from spokvulcan/poker-planning. Sets up Convex auth, identity mapping, and access control. Use for login, auth providers, users tables, protected functions, or roles in a Convex app.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files and assets (for example `agents/openai.yaml`, `references/auth0.md` and `references/clerk.md`).

It sits in Backend & APIs, covering Authorization and RBAC and Sprint planning and agile. It works with WorkOS and Auth0. The repository describes itself as: Free open-source planning poker for Scrum teams. No registration required. Real-time estimation for remote agile teams. The licence is MIT.

When your agent uses it

  • Protected functions
  • Roles in a Convex app

Example prompts

  • “/convex-setup-auth”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Ask the user which auth solution they want, unless the repository already
  2. If the repo already uses a provider, continue with that provider unless the
  3. If the user has not chosen a provider and the repo does not make it obvious,

What it can do on your machine

Read from SKILL.md and the folder at commit 665a13f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.convex.dev
    • labs.convex.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Convex Setup Auth loads about 1.8k tokens when it runs, and up to ~8.9k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 798 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spokvulcan/poker-planning at commit 665a13f, republished under its MIT licence (© spokvulcan). 798 words, ~1,772 tokens.

Download SKILL.mdSave it as .claude/skills/convex-setup-auth/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
convex-setup-auth
description
Sets up Convex auth, identity mapping, and access control. Use for login, auth providers, users tables, protected functions, or roles in a Convex app.

Convex Authentication Setup

Implement secure authentication in Convex with user management and access control.

When to Use

  • Setting up authentication for the first time
  • Implementing user management (users table, identity mapping)
  • Creating authentication helper functions
  • Setting up auth providers (Convex Auth, Clerk, WorkOS AuthKit, Auth0, custom JWT)

When Not to Use

  • Auth for a non-Convex backend
  • Pure OAuth/OIDC documentation without a Convex implementation
  • Debugging unrelated bugs that happen to surface near auth code
  • The auth provider is already fully configured and the user only needs a one-line fix

First Step: Choose the Auth Provider

Convex supports multiple authentication approaches. Do not assume a provider.

Before writing setup code:

  1. Ask the user which auth solution they want, unless the repository already makes it obvious
  2. If the repo already uses a provider, continue with that provider unless the user wants to switch
  3. If the user has not chosen a provider and the repo does not make it obvious, ask before proceeding

Common options:

  • Convex Auth - good default when the user wants auth handled directly in Convex
  • Clerk - use when the app already uses Clerk or the user wants Clerk's hosted auth features
  • WorkOS AuthKit - use when the app already uses WorkOS or the user wants AuthKit specifically
  • Auth0 - use when the app already uses Auth0
  • Custom JWT provider - use when integrating an existing auth system not covered above

Look for signals in the repo before asking:

  • Dependencies such as @clerk/*, @workos-inc/*, @auth0/*, or Convex Auth packages
  • Existing files such as convex/auth.config.ts, auth middleware, provider wrappers, or login components
  • Environment variables that clearly point at a provider

After Choosing a Provider

Read the provider's official guide and the matching local reference file:

The local reference files contain the concrete workflow, expected files and env vars, gotchas, and validation checks.

Use those sources for:

  • package installation
  • client provider wiring
  • environment variables
  • convex/auth.config.ts setup
  • login and logout UI patterns
  • framework-specific setup for React, Vite, or Next.js

For shared auth behavior, use the official Convex docs as the source of truth:

Prefer official docs over recalled steps, because provider CLIs and Convex Auth internals change between versions. Inventing setup from memory risks outdated patterns. For third-party providers, only add app-level user storage if the app actually needs user documents in Convex. Not every app needs a users table. For Convex Auth, follow the Convex Auth docs and built-in auth tables rather than adding a parallel users table plus storeUser flow, because Convex Auth already manages user records internally. After running provider initialization commands, verify generated files and complete the post-init wiring steps the provider reference calls out. Initialization commands rarely finish the entire integration.

Show full SKILL.md (303 more words)Show less

Core Pattern: Protecting Backend Functions

The most common auth task is checking identity in Convex functions.

ts
// Bad: trusting a client-provided userId
export const getMyProfile = query({
  args: { userId: v.id("users") },
  handler: async (ctx, args) => {
    return await ctx.db.get(args.userId);
  },
});
ts
// Good: verifying identity server-side
export const getMyProfile = query({
  args: {},
  handler: async (ctx) => {
    const identity = await ctx.auth.getUserIdentity();
    if (!identity) throw new Error("Not authenticated");

    return await ctx.db
      .query("users")
      .withIndex("by_tokenIdentifier", (q) =>
        q.eq("tokenIdentifier", identity.tokenIdentifier),
      )
      .unique();
  },
});

Workflow

  1. Determine the provider, either by asking the user or inferring from the repo
  2. Ask whether the user wants local-only setup or production-ready setup now
  3. Read the matching provider reference file
  4. Follow the official provider docs for current setup details
  5. Follow the official Convex docs for shared backend auth behavior, user storage, and authorization patterns
  6. Only add app-level user storage if the docs and app requirements call for it
  7. Add authorization checks for ownership, roles, or team access only where the app needs them
  8. Verify login state, protected queries, environment variables, and production configuration if requested

If the flow blocks on interactive provider or deployment setup, ask the user explicitly for the exact human step needed, then continue after they complete it. For UI-facing auth flows, offer to validate the real sign-up or sign-in flow after setup is done. If the environment has browser automation tools, you can use them. If it does not, give the user a short manual validation checklist instead.

Reference Files

Provider References
  • references/convex-auth.md
  • references/clerk.md
  • references/workos-authkit.md
  • references/auth0.md

Checklist

  • Chosen the correct auth provider before writing setup code
  • Read the relevant provider reference file
  • Asked whether the user wants local-only setup or production-ready setup
  • Used the official provider docs for provider-specific wiring
  • Used the official Convex docs for shared auth behavior and authorization patterns
  • Only added app-level user storage if the app actually needs it
  • Did not invent a cross-provider users table or storeUser flow for Convex Auth
  • Added authentication checks in protected backend functions
  • Added authorization checks where the app actually needs them
  • Clear error messages ("Not authenticated", "Unauthorized")
  • Client auth provider configured for the chosen provider
  • If requested, production auth setup is covered too

© spokvulcan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references, assets) in .agents/skills/convex-setup-auth of spokvulcan/poker-planning.

  • SKILL.md
  • agents/openai.yaml
  • assets/icon.svg
  • references/auth0.md
  • references/clerk.md
  • references/convex-auth.md
  • references/workos-authkit.md

Open the folder on GitHubat commit 665a13f

Used in 8 other repositories

We found 9 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 8 other GitHub owners. This page covers the copy in spokvulcan/poker-planning, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Convex Setup Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Convex Setup Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Convex Setup Auth this skillspokvulcan/poker-planning1148 repos~1.8kAutomated safety check: PassMIT
Convex Setup Authwaynesutton/markdown-site628—~1.4kAutomated safety check: PassMIT
Workosusenotra/notra255—~6.2kAutomated safety check: PassAGPL-3.0
Convex Setup Authvvedantb/eva101—~1.5kAutomated safety check: PassMIT
Convex AuthIgorWarzocha/Opencode-Workflows122—~744Automated safety check: PassNone
Frontmcp Authoritiesagentfront/frontmcp146—~7.1kAutomated safety check: PassApache-2.0

Similar skills

  • Convex Setup Auth

    waynesutton/markdown-site

    Set up Convex authentication with proper user management, identity mapping, and access control patterns.

    628 GitHub stars~1.4k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    255 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    vvedantb/eva

    Set up Convex authentication with proper user management, identity mapping, and access control patterns.

    101 GitHub stars~1.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Convex Auth

    IgorWarzocha/Opencode-Workflows

    Implement Convex authentication and authorization patterns with OIDC providers or Convex Auth.

    122 GitHub stars~744 tokensUpdated 8 mo ago
    Backend & APIsAuto-check passed
  • Frontmcp Authorities

    agentfront/frontmcp

    A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.

    146 GitHub stars~7.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Securing Authentication

    ancoleman/ai-design-components

    Authentication, authorization, and API security implementation.

    526 GitHub stars~3.4k tokensUpdated 10 mo ago
    Backend & APIsAuto-check passed

More from spokvulcan/poker-planning

  • Convex Create Component

    spokvulcan/poker-planning

    Builds reusable Convex components with isolated tables and app-facing APIs.

    114 GitHub starsUsed in 8 repos~2.6k tokens
    Auto-check passed
  • Convex Migration Helper

    spokvulcan/poker-planning

    Plans Convex schema and data migrations with widen-migrate-narrow and @convex-dev/migrations.

    114 GitHub starsUsed in 8 repos~1.4k tokens
    Auto-check passed
  • Convex Quickstart

    spokvulcan/poker-planning

    Creates or adds Convex to an app. An agent skill from spokvulcan/poker-planning.

    114 GitHub starsUsed in 6 repos~3.5k tokens
    Auto-check: notes
  • Convex Performance Audit

    spokvulcan/poker-planning

    Audits Convex performance for reads, subscriptions, write contention, and function limits.

    114 GitHub starsUsed in 7 repos~1.9k tokens
    Auto-check passed
  • Convex

    spokvulcan/poker-planning

    Routes general Convex requests to the right project skill. An agent skill from spokvulcan/poker-planning.

    114 GitHub starsUsed in 6 repos~399 tokens
    Auto-check passed

Works with

Questions about Convex Setup Auth

What does Convex Setup Auth do?

Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning. Convex Setup Auth is an agent skill from spokvulcan/poker-planning. Sets up Convex auth, identity mapping, and access control.

When should I use Convex Setup Auth?

Convex Setup Auth fits situations like: protected functions; roles in a Convex app.

How do I install Convex Setup Auth in Claude Code?

Run `npx skills add spokvulcan/poker-planning --skill convex-setup-auth -a claude-code`. Or copy the skill folder (.agents/skills/convex-setup-auth in spokvulcan/poker-planning) into .claude/skills/convex-setup-auth in your project. Claude Code loads it when a task matches its description.

How do I install Convex Setup Auth in Codex?

Run `npx skills add spokvulcan/poker-planning --skill convex-setup-auth -a codex`. Or copy the skill folder (.agents/skills/convex-setup-auth in spokvulcan/poker-planning) into .agents/skills/convex-setup-auth in your project. Codex loads it when a task matches its description.

Can I use Convex Setup Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spokvulcan/poker-planning --skill convex-setup-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/convex-setup-auth, .gemini/skills/convex-setup-auth, .github/skills/convex-setup-auth and .opencode/skills/convex-setup-auth in your project.

What does Convex Setup Auth need to run?

SKILL.md names no scripts, command-line tools or credentials: Convex Setup Auth is instructions for the agent only.

Does Convex Setup Auth access the network?

SKILL.md names 2 domains. As links in the text: docs.convex.dev and labs.convex.dev. This is read from the text; nothing was executed.

Is Convex Setup Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Convex Setup Auth use?

Convex Setup Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Convex Setup Auth use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.2k tokens, read only when the agent opens those files.

What are the alternatives to Convex Setup Auth?

Skills that share tags, products or a category with Convex Setup Auth: Convex Setup Auth (waynesutton/markdown-site, 628 stars), Workos (usenotra/notra, 255 stars), Convex Setup Auth (vvedantb/eva, 101 stars) and Convex Auth (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Convex Setup Auth?

spokvulcan (a GitHub user) maintains it in spokvulcan/poker-planning, which has 114 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 4, 2026.

Source: spokvulcan/poker-planning on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.