Neon Auth
neondatabase/agent-skills
Add authentication to a new app. An agent skill from neondatabase/agent-skills.
Run and verify the convt.app website (apps/web, TanStack Start on Cloudflare Workers) and its billing Worker (apps/billing) locally, with Postgres, Mailpit, the OAuth mock and the Polar and Resend…
$ npx skills add opencoredev/convt --skill test-convt-web -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install opencoredev/convt test-convt-web --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/opencoredev/convt.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/test-convt-web .claude/skills/test-convt-web && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "test-convt-web" agent skill from https://github.com/opencoredev/convt/tree/main/.agents/skills/test-convt-web into .claude/skills/test-convt-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "test-convt-web", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/opencoredev/convt/tree/main/.agents/skills/test-convt-webType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add opencoredev/convt --skill test-convt-web -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install opencoredev/convt test-convt-web --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/opencoredev/convt.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/test-convt-web .agents/skills/test-convt-web && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "test-convt-web" agent skill from https://github.com/opencoredev/convt/tree/main/.agents/skills/test-convt-web into .agents/skills/test-convt-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "test-convt-web", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add opencoredev/convt --skill test-convt-web -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install opencoredev/convt test-convt-web --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/opencoredev/convt.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/test-convt-web .cursor/skills/test-convt-web && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "test-convt-web" agent skill from https://github.com/opencoredev/convt/tree/main/.agents/skills/test-convt-web into .cursor/skills/test-convt-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "test-convt-web", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/opencoredev/convt.git --path .agents/skills/test-convt-web--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add opencoredev/convt --skill test-convt-web -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install opencoredev/convt test-convt-web --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/opencoredev/convt.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/test-convt-web .gemini/skills/test-convt-web && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "test-convt-web" agent skill from https://github.com/opencoredev/convt/tree/main/.agents/skills/test-convt-web into .gemini/skills/test-convt-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "test-convt-web", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install opencoredev/convt test-convt-webInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add opencoredev/convt --skill test-convt-web -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/opencoredev/convt.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/test-convt-web .github/skills/test-convt-web && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "test-convt-web" agent skill from https://github.com/opencoredev/convt/tree/main/.agents/skills/test-convt-web into .github/skills/test-convt-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "test-convt-web", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add opencoredev/convt --skill test-convt-web -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install opencoredev/convt test-convt-web --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/opencoredev/convt.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/test-convt-web .opencode/skills/test-convt-web && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "test-convt-web" agent skill from https://github.com/opencoredev/convt/tree/main/.agents/skills/test-convt-web into .opencode/skills/test-convt-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "test-convt-web", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
test-convt-webRun and verify the convt.app website (apps/web, TanStack Start on Cloudflare Workers) and its billing Worker (apps/billing) locally, with Postgres, Mailpit, the OAuth mock and the Polar and Resend…
Test Convt Web is an agent skill from opencoredev/convt. Run and verify the convt.app website (apps/web, TanStack Start on Cloudflare Workers) and its billing Worker (apps/billing) locally, with Postgres, Mailpit, the OAuth mock and the Polar and Resend mock, signed in as a fixture account, in a browser at desktop and mobile widths. Use when changing anything under apps/web, apps/billing, packages/db, packages/billing, packages/mail, packages/license, tools/oauth-mock or tools/billing-mock, or when asked to preview, screenshot or check the site.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs, covering DataFrames and OAuth and OpenID Connect. It works with PostgreSQL, Cloudflare Workers, TanStack and Vite. The repository describes itself as: Convert any file with a right-click. The licence is AGPL-3.0.
Read from SKILL.md and the folder at commit 9214ba0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunbashcurlwranglerdockerpython3bunxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, wrangler, docker and bunx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
BETTER_AUTH_SECRETLICENSE_PUBLIC_KEYCONVT_WEB_TOKEN_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Test Convt Web loads about 4.1k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 1,753 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
rverVersion}}' # Docker must run; no sudo neededAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from opencoredev/convt at commit 9214ba0, republished under its AGPL-3.0 licence (© opencoredev). 1,753 words, ~4,136 tokens.
.claude/skills/test-convt-web/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.apps/web is a TanStack Start app built with Vite and the Cloudflare plugin, deployed with Wrangler as the convt-web Worker. apps/billing is the convt-billing Worker: the Polar webhook route, the billing crons, and the BillingRpc entrypoint the site calls through its BILLING service binding. It holds every billing secret and the license signing key; the site holds none. The landing page is static. The account pages (/sign-in, /dashboard, /dashboard/licenses, /dashboard/billing, /dashboard/api, /account) use Better Auth and read Postgres through the HYPERDRIVE binding. Locally everything runs on this machine: a Postgres and a Mailpit container per checkout, an OAuth mock that stands in for GitHub and Google, and a billing mock (tools/billing-mock) that speaks the parts of Polar's API and Resend's /emails that convt-billing calls, serves Polar-like checkout and portal pages, and signs webhooks with Polar's real scheme. No real email, OAuth app, payment account or database is ever used, and convt-billing signs keys with the local dev key in .convt-dev/license.key.
docker info --format '{{.ServerVersion}}' # Docker must run; no sudo needed
bash scripts/db.sh status # this checkout's containers and ports
ss -ltnp 'sport = :3000' # who owns the default web portscripts/db.sh names its containers convt-pg-<hash> and convt-mail-<hash> after a hash of the checkout path and labels them convt.checkout=<path>, so other checkouts and other projects' Postgres containers are never touched. Ports are random on 127.0.0.1; .convt-dev/services.env (mode 0600, gitignored) records them with generated passwords and BETTER_AUTH_SECRET.
work=$(mktemp -d /tmp/convt-web.XXXXXX)
setsid bun run dev:web >"$work/dev.log" 2>&1 </dev/null &
sleep 1; ps -o pgid= -p $! | tr -d ' ' >"$work/pgid"
for _ in $(seq 90); do grep -q 'dev-web: http' "$work/dev.log" && break; sleep 1; done
origin=$(grep -o 'dev-web: http://localhost:[0-9]*' "$work/dev.log" | cut -d' ' -f2)
curl -fsS "$origin/api/auth/ok" # {"ok":true}
bun run db:seed # fixture accounts; safe to repeatbun run dev:web runs scripts/dev-web.sh: db.sh up, migrations, the OAuth mock on OAUTH_MOCK_PORT, the billing mock on BILLING_MOCK_PORT (delivering webhooks to the site's /webhooks/polar), apps/web/.dev.vars and apps/billing/.dev.vars from services.env, then Vite on 3000 or the next free port with BETTER_AUTH_URL set to match. convt-billing runs inside Vite as an auxiliary Worker; outside production the site forwards /webhooks/* and /__billing/* to it, because an auxiliary Worker has no port of its own. After seeding, mirror the fixtures into the billing mock with bun tools/billing-mock/src/preload.ts (it is in-memory, so repeat it after every restart). Readiness is /api/auth/ok returning 200. Server-side errors appear in dev.log, not the browser console. setsid puts Vite and the mock in one process group so cleanup can stop exactly those.
For a production-like check, build and serve the Worker with Wrangler. Pass the database through the Hyperdrive variable and point BETTER_AUTH_URL at Wrangler's port:
set -a; . .convt-dev/services.env; set +a
bun run build
cd apps/web && CLOUDFLARE_HYPERDRIVE_LOCAL_CONNECTION_STRING_HYPERDRIVE=$DATABASE_URL \
setsid bunx wrangler dev --port 8788 --ip 127.0.0.1 --var BETTER_AUTH_URL:http://localhost:8788 &It reads the other values from .dev.vars, which the build copies into dist/server. Never run bun run deploy or wrangler deploy without the user's explicit authorization.
All fixtures are on the reserved .test domain and exist only in local databases:
| Shows | |
|---|---|
new@convt.test | Signed in, bought nothing. |
trial@convt.test | Pro monthly trial ending in 3 days, trial key. |
desktop@convt.test | Desktop order, key, invoice and one Mac. |
pro@convt.test | Pro yearly, older Desktop key, two Macs, API with two keys and usage, GitHub linked. |
lapsed@convt.test | Pro ended last month, last key, a failed invoice. |
api@convt.test | API only: one key, usage, six failed jobs. |
unclaimed@convt.test | No account: a Desktop purchase that signing up with this address claims. |
refunded@convt.test | A Desktop purchase refunded in full: the key shows REFUNDED. |
pastdue@convt.test | Pro monthly whose renewal failed: past due, last month's key. |
disputed@convt.test | A Desktop purchase with a lost chargeback: the key shows DISPUTED. |
apipending@convt.test | API enrollment waiting for a card (pending). |
trial@ has no key (a trial is not paid coverage); a database seeded before P7 keeps its old trial key, because licenses are never deleted. Every subscription fixture has payment coverage and a billing_customers row with mock ids.
Sign in at /sign-in with the email, then read the code from Mailpit (its web UI is $MAILPIT_URL):
curl -fsS "$MAILPIT_URL/api/v1/search?query=to:pro@convt.test" \
| python3 -c 'import json,re,sys; print(re.search(r"\d{6}", json.load(sys.stdin)["messages"][0]["Subject"]).group())'Each address may receive 3 codes per 15 minutes and each IP 10 per hour; every local request comes from the same IP. To clear the limits in this checkout's own database: bash scripts/db.sh psql owner -c 'delete from otp_send_limits; delete from rate_limits'.
GitHub and Google buttons go to the OAuth mock's authorize page, which lists its identities: google-gmail and google-workspace (verified addresses), google-thirdparty and google-unverified (must confirm by code), github-verified, github-public-differs, github-no-email, github-pro (signs in to pro@convt.test), and error (access denied). Append &identity=<name> to the authorize URL to skip the page and &email=<address> to sign up with another address.
Use headless agent-browser for UI verification, with a named session and its own persistent profile. Put both --session and --profile on every invocation. Never use a personal browser profile. UI work includes opening the real page and inspecting desktop and mobile screenshots in both themes.
The repeatable checks are scripts in apps/web/e2e, each printing PASS or FAIL lines and saving screenshots:
cd apps/web
E2E_SESSION=convt-web E2E_SHOTS=$work/shots bash e2e/sign-in.sh # code, emailed link, OAuth identities, verify-email
E2E_SESSION=convt-web E2E_SHOTS=$work/shots bash e2e/fixtures.sh # every fixture, 5 pages, 1280 and 390 px, light and dark
E2E_SESSION=convt-web E2E_SHOTS=$work/shots bash e2e/account.sh # activate, copy key, rename, change email, connect, sign out
E2E_SESSION=convt-web E2E_SHOTS=$work/shots bash e2e/billing.sh # checkout, keys, trial, switch, refund, API, emails, deletionThey read the site origin from apps/web/.dev.vars; set E2E_URL to test Wrangler instead. billing.sh drives the mock's hosted checkout and its /admin/* endpoints (end a trial, renew, fail a card, refund, change settings), runs crons through $E2E_URL/__billing/scheduled?cron=..., and screenshots each billing screen and the four emails (Mailpit's /view/<id>.html) in both themes. Run it once per fresh dev:web: it changes mock settings and deletes an account. account.sh calls a source module directly to prove getLicenseKey refuses another user's license, which only works under Vite. A layout change needs desktop and 390 px screenshots in both themes; look at each one with the Read tool.
Activate opens convt://activate?key=<token> through a temporary link. account.sh stubs HTMLAnchorElement.prototype.click to check the URL, because Chrome lets no page script stub location. Opening the link in the real desktop app is a GUI check (see test-convt-desktop): register the handler with integrations/linux/install.py and use CONVT_LICENSE_STORE=file with HOME and the XDG directories in a mktemp directory. Seeded keys are signed with .convt-dev/license.key, whose public half local builds embed.
/device is the page the desktop app opens to sign in (P8). It needs a signed-in, verified session, so a signed-out visit goes through /sign-in and comes back. Approve stores a five-minute one-time code in verifications and opens convt://auth?state=...&code=...; Cancel opens ...&error=access_denied. The app then calls POST /api/device/token (code and verifier), POST /api/device/license (bearer device token; returns the Pro key from convt-billing's currentProKey) and POST /api/device/sign-out. These routes use no cookies and skip the Origin check; the logic and limits are in src/server/device-auth.ts. test/integration/device.test.ts covers the flow, one-use codes, revocation, cross-account isolation and rate limits. A full run with the real app is in test-convt-desktop, "Sign-in and renewal". Signed-in devices appear under Macs on the dashboard, where Sign out revokes their token.
curl -X POST $BILLING_MOCK_URL/admin/<name> -d '{...}' with state (GET), clock (advanceDays), trial-end, renew, card (decline), retry-payment, refund (order_id, amount), dispute (open, then lost/won/prevented), settings (allow_multiple_subscriptions), product (price drift), webhooks (mode auto or hold, dropNext, duplicate, delayMs, reorder, forgeNext, scheme standard or legacy, url), flush, resend-fault (timeout, delay, 5xx), complete-checkout. Polar sends no dispute webhook; disputes arrive through the reconciler (cron=*/15 * * * *).curl "$origin/__billing/scheduled?cron=*+*+*+*+*" drains the outbox and advances deletions; *%2F15+*+*+*+* runs the reconciler; 17+3+*+*+* the daily check and digest (to alerts@convt.test in Mailpit).bun run billing:outbox list shows ambiguous and dead emails; resolve <id> sent|resend records Leo's decision.cd apps/billing && CLOUDFLARE_HYPERDRIVE_LOCAL_CONNECTION_STRING_HYPERDRIVE_BILLING=$BILLING_DATABASE_URL bunx wrangler dev --port 8790 --test-scheduled, with the mock's webhook URL set to it (admin/webhooks url). The site under wrangler dev reaches it through the dev registry; on a machine short of file watches (EMFILE in the log) that registry never finishes starting.packages/billing/src/env.ts. In production it refuses loopback provider or mail URLs and a signing key that does not match LICENSE_PUBLIC_KEY or is a dev key.cd apps/web && bun test test/unit # views, redirects, Origin, redactor, env, table shape
bun run --cwd apps/web test:integration # Better Auth in process against a throwaway Postgres
bun run db:ci # schema drift, down files, all integration tests, convt-server
cd packages/billing && bun test test/unit && bun run test:integration # verifier, catalog, guards; ingest, keys, outbox, reconciler, deletion
cd tools/billing-mock && bun test # the mock through the real SDK client, validateEvent, Resend idempotency
cd packages/mail && bun test # template snapshots and escaping, Resend outcomesThe billing integration tests run the mock in process through the real Polar SDK client, as convt_billing against a disposable database, with an injected clock; one test builds convt-cli and activates an issued key with CONVT_LICENSE_STORE=file in a temporary HOME. A change to an email template changes its snapshot: bump templateVersion in packages/mail/src/templates.ts with it.
Integration tests and db:ci start their own labeled tmpfs Postgres and remove it by id on exit.
Secure cookies are off in development, but the sign-in origin must be the one the device uses. Start with PUBLIC_ORIGIN=http://<tailnet-host>:<port> PORT=<port> MOCK_HOST=0.0.0.0 MOCK_PUBLIC_URL=http://<tailnet-host>:<mock-port> bun run dev:web, which binds Vite to all interfaces and sets BETTER_AUTH_URL and the mock's authorize URL to those addresses. This path was not exercised when P6 was verified, so check sign-in end to end the first time. Verify the URL from the device that will open it, and report which devices actually loaded the page. Read the remote-preview skill before starting or sharing a preview. Bind to the verified Tailscale address and report which devices actually loaded the page.
bun run check && bun run check-types && bun run buildkill -- -"$(cat "$work/pgid")" stops Vite and the OAuth mock you started (only that process group). Close browser sessions with agent-browser --session <name> close. The containers stay for reuse; bun run db:down removes this checkout's containers and its database volume (after the ownership guard), and bash scripts/db.sh prune removes those of checkouts that no longer exist.
Read test-convt-server and docs/p9-cloud-plan.md to start the API, MinIO and sandbox worker. Configure CONVT_API_URL and the shared CONVT_WEB_TOKEN_SECRET in the local web Worker. Use the task session convt-p9 and profile ~/.agent-browser/profiles/convt-p9, on every command.
Check /dashboard/api: create a named key, inspect the shown-once field, dismiss it, reload, revoke it and verify a revoked key fails authentication. Inspect spend, reservations, cap reached and not-enrolled states. Check /dashboard/api/convert: pick a real file, choose a supported target, observe upload and job progress, download and inspect the result. Test malformed input, cancellation, an unavailable cancel endpoint and the retry button, the 2 GB file guard, exhausted monthly allowance, unpaid and trial states. Temporary reservations used to reach a limit must be cancelled afterward; restore any temporary cap only if it still has the value the test set. Never rewrite settled usage to stage a screenshot.
Capture desktop and 390 px screenshots in light and dark, inspect each image, and verify no horizontal overflow. Check keyboard focus and accessible names. Save P9 evidence in /home/leo/projects/convt-ui-brief/screens/p9/. If Vite hits EMFILE, restart only the owned process with CHOKIDAR_USEPOLLING=1. Hot reload can reset a selected file; finish source edits before the final browser run. Production Worker, Railway Buckets CORS and real payment enrollment remain separate launch checks.
Run bun test apps/billing/test to verify the public webhook body's streaming reader. A body without Content-Length must stop and cancel when it crosses 256 KiB, exact-limit raw bytes must survive unchanged, and non-POST requests must consume no body. The billing integration deletion case includes Pro usage and pending API usage: only the API fact for the subscription being revoked may delay deletion. bun audit and the database dependency test must reject vulnerable esbuild versions; bun run db:ci checks the overridden loader against real migration tooling.
© opencoredev, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/test-convt-web of opencoredev/convt.
Open the folder on GitHubat commit 9214ba0
Test Convt Web next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Test Convt Web this skillopencoredev/convt | 187 | — | ~4.1k | Automated safety check: Notes | AGPL-3.0 | |
| Neon Authneondatabase/agent-skills | 100 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Authenticationlatitude-dev/latitude-llm | 4.7k | — | ~303 | Automated safety check: Pass | MIT | |
| Better Authsecondsky/claude-skills | 227 | — | ~7.5k | Automated safety check: Pass | MIT | |
| Add Backendahpxex/open-dashboard | 146 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Sync Templatetsu-moe/tsu-stack | 127 | — | ~2k | Automated safety check: Pass | MIT |
neondatabase/agent-skills
Add authentication to a new app. An agent skill from neondatabase/agent-skills.
latitude-dev/latitude-llm
Sessions, sign-in/sign-up flows, OAuth, magic links, or organization context on the session.
secondsky/claude-skills
Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks.
ahpxex/open-dashboard
Everything about the data layer — pick one of six ready-to-run backend templates (TanStack Start + Drizzle + better-auth, Hono + Drizzle + better-auth, Hono + Prisma + better-auth, Hono + Drizzle +…
tsu-moe/tsu-stack
Compare or update a project derived from tsu-moe/tsu-stack while preserving application features, identity, configuration, and deployment behavior.
secondsky/claude-skills
TanStack Router type-safe file-based routing for React. An agent skill from secondsky/claude-skills.
opencoredev/convt
Test convt conversions end to end through the convt CLI, the engines in convt-engines, routing in convt-core, and the Linux file-manager menus in integrations/linux.
opencoredev/convt
Run the headless window tests for the convt GPUI desktop app (crates/convt-app), and build, launch and screenshot it under Xvfb or natively on macOS and Windows.
opencoredev/convt
Run and verify the convt jobs API, Postgres queue, object storage, sandbox worker and metering locally.
Categories
Run and verify the convt.app website (apps/web, TanStack Start on Cloudflare Workers) and its billing Worker (apps/billing) locally, with Postgres, Mailpit, the OAuth mock and the Polar and Resend…. Test Convt Web is an agent skill from opencoredev/convt.app website (apps/web, TanStack Start on Cloudflare Workers) and its billing Worker (apps/billing) locally, with Postgres, Mailpit, the OAuth mock and the Polar and Resend mock, signed in as a fixture account, in a browser at desktop and mobile widths.
Test Convt Web fits situations like: changing anything under apps/web; packages/billing; packages/license; tools/oauth-mock.
Run `npx skills add opencoredev/convt --skill test-convt-web -a claude-code`. Or copy the skill folder (.agents/skills/test-convt-web in opencoredev/convt) into .claude/skills/test-convt-web in your project. Claude Code loads it when a task matches its description.
Run `npx skills add opencoredev/convt --skill test-convt-web -a codex`. Or copy the skill folder (.agents/skills/test-convt-web in opencoredev/convt) into .agents/skills/test-convt-web in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add opencoredev/convt --skill test-convt-web -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/test-convt-web, .gemini/skills/test-convt-web, .github/skills/test-convt-web and .opencode/skills/test-convt-web in your project.
Going by SKILL.md and its folder, Test Convt Web needs the command-line tools its instructions call (bun, bash, curl, wrangler, docker and python3) and credentials named BETTER_AUTH_SECRET, LICENSE_PUBLIC_KEY and CONVT_WEB_TOKEN_SECRET. Our summary lists: Python 3; Docker; A credential in BETTER_AUTH_SECRET; A credential in LICENSE_PUBLIC_KEY.
SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Test Convt Web is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Test Convt Web: Neon Auth (neondatabase/agent-skills, 100 stars), Authentication (latitude-dev/latitude-llm, 4.7k stars), Better Auth (secondsky/claude-skills, 227 stars) and Add Backend (ahpxex/open-dashboard, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
opencoredev (a GitHub organization) maintains it in opencoredev/convt, which has 187 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 8, 2026.
Source: opencoredev/convt on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.