Agent skill

Yida Login

by openyida in openyida/openyida

宜搭登录态管理。以 OpenYida auth snapshot 为准;默认 OAuth token,snapshot 返回 env 注入状态时使用运行环境注入 token。

MITAuto-check: notesBackend & APIs

Install Yida Login

skills CLI
$ npx skills add openyida/openyida --skill yida-login -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openyida/openyida yida-login --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openyida/openyida.git skills-src && mkdir -p .claude/skills && cp -r skills-src/yida-skills/skills/yida-login .claude/skills/yida-login && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
yida-login
GitHub stars
220
Token cost
~1.2k tokens
SKILL.md length
331 words
Files
1
Skills in repo
58
Repo updated
First seen
Licence
MIT

At a glance

宜搭登录态管理。以 OpenYida auth snapshot 为准;默认 OAuth token,snapshot 返回 env 注入状态时使用运行环境注入 token。

  • Works in 5 steps: 只执行一次 openyida login,并持续等待同一个命令。 → CLI 默认自动打开系统浏览器;Agent 禁止提取授权 URL 后再次打开。 → 用户授权可能需要较长时间,登录进程默认可等待约 5 分钟。 → …
  • Tasks that involve OAuth and OpenID Connect
  • SKILL.md covers 模式, 前置检查, 判断表 and Token 模式命令, plus 5 more sections
  • Reaches yida-group.alibaba-inc.com; needs OPENYIDA_ACCESS_TOKEN and OPENYIDA_REFRESH_TOKEN

What it does

Yida Login is an agent skill from openyida/openyida. 宜搭登录态管理。以 OpenYida auth snapshot 为准;默认 OAuth token,snapshot 返回 env 注入状态时使用运行环境注入 token。

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect. The repository describes itself as: Your own personal YiDA AI assistant! The licence is MIT.

When your agent uses it

  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/yida-login”

Requirements

  • A credential in OPENYIDA_ACCESS_TOKEN
  • A credential in OPENYIDA_REFRESH_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 只执行一次 openyida login,并持续等待同一个命令。
  2. CLI 默认自动打开系统浏览器;Agent 禁止提取授权 URL 后再次打开。
  3. 用户授权可能需要较长时间,登录进程默认可等待约 5 分钟。
  4. 只有原命令成功退出,且最终 JSON 返回 ok=true 与 can_auto_use=true,才能判定登录成功。
  5. 用户未授权就关闭浏览器时,CLI 无法可靠感知窗口关闭。继续等待原命令,直到用户停止或命令超时;不要自动发起第二次登录。

What it can do on your machine

Read from SKILL.md and the folder at commit b52e65e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • yida-group.alibaba-inc.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENYIDA_ACCESS_TOKEN
    • OPENYIDA_REFRESH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Yida Login loads about 1.2k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 331 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:129
    - 不要手动读写 `.env`、token 文件或 Cookie 文件。

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openyida/openyida at commit b52e65e, republished under its MIT licence (© openyida). 331 words, ~1,166 tokens.

Download SKILL.mdSave it as .claude/skills/yida-login/SKILL.md (or your agent's skills folder).
name
yida-login
description
宜搭登录态管理。以 OpenYida auth snapshot 为准;默认 OAuth token,snapshot 返回 env 注入状态时使用运行环境注入 token。

yida-login

模式

  • Codex、yida-agent 等宿主都使用同一套 OpenYida auth snapshot 规则。
  • 不要根据 agent 名称、宿主产品、workspace 路径或猜测的环境变量推断认证模式。
  • 先读 openyida agent-capabilities --summary-json;只有需要更多信息时,才降级执行 openyida login --check-only --json。
  • snapshot 返回 login.auth_source=env 或 failure_reason=env_token_missing 时,进入运行环境注入 token 模式。凭证只来自运行环境注入的 OPENYIDA_ACCESS_TOKEN、OPENYIDA_REFRESH_TOKEN 等环境变量。
  • 其他 auth_mode=token 场景使用默认 OAuth token session。
  • 不要从 .cache/cookies*.json 推断登录态。
  • 浏览器归属以 builder_path.interactive_login.mode 为准:not_required 不触发 OAuth;cli_auto_open 执行 openyida login 并等待;caller_open_url 执行 openyida login --no-browser,由 Agent 优先调用沙箱浏览器 / 内置 Browser 打开 CLI 输出的授权 URL 一次;unsupported 停止并说明没有可用浏览器能力,不要默认安装 Playwright。
  • caller_open_url 模式下,Agent 不要只把 URL 贴给用户然后等待。只有当前宿主没有浏览器工具,或浏览器工具调用失败时,才退回让用户手动打开 URL。

前置检查

先执行:

bash
openyida agent-capabilities --summary-json

必要时降级:

bash
openyida env --json
openyida login --check-only --json

判断表

状态动作
auth_mode=token 且 status=ok 或 can_auto_use=true继续执行业务命令
status=profile_required 且返回 candidates / next_step不猜组织;先执行 openyida auth profiles,再用 openyida auth profile switch <auth_profile> 切到用户确认或目标匹配的已有 profile
auth_source=env / failure_reason=env_token_missing进入运行环境注入 token 模式;缺 token 时停止,让 Codex、yida-agent 等宿主注入 OPENYIDA_ACCESS_TOKEN 或 OPENYIDA_REFRESH_TOKEN;不要执行 OAuth
auth_mode=token,未登录,且 interactive_login.mode=cli_auto_open只执行一次 openyida login,等待该命令结束,并使用其最终 JSON 判断结果
auth_mode=token,未登录,且 interactive_login.mode=caller_open_url只执行一次 openyida login --no-browser,由 Agent 优先调用沙箱浏览器 / 内置 Browser 打开输出 URL 一次,并等待原命令结束;无浏览器工具或调用失败时才让用户手动打开
auth_mode=token,未登录,且 interactive_login.mode=unsupported停止并向用户说明当前运行环境没有桌面浏览器或 Agent 浏览器能力

Token 模式命令

只有 auth snapshot 未返回 env 注入模式时,才使用 OAuth 登录。

bash
openyida login
openyida login --check-only --json
openyida auth status
openyida auth profiles
openyida auth profile switch <auth_profile>
openyida auth refresh
openyida auth logout

生成新命令统一使用 openyida auth profiles --json。CLI 同时兼容旧写法 openyida auth profile list --json,两者都只查询,不切换组织或登录态。

Profile 选择原则

  • 当前已有多个 profile 且 snapshot 返回 profile_required 时,不要根据目录、组织名片段或最近操作猜测组织。
  • 先执行 openyida auth profiles 查看 corp_name、corp_id、user_id、auth_profile、last_used_at 和 auth_store。
  • 目标 profile 已存在时,执行 openyida auth profile switch <auth_profile>;这是非破坏性切换,只更新当前项目 pointer。
  • 目标 profile 不存在时,再执行 openyida login 新增登录态;登录完成后重新执行 openyida auth profiles 并切到新增 profile。
  • 运行环境注入 token 模式下,不要切换或删除本地 profile,让宿主注入目标组织的 token。

Agent OAuth 登录编排

interactive_login.mode=cli_auto_open 的默认流程:

  1. 只执行一次 openyida login,并持续等待同一个命令。
  2. CLI 默认自动打开系统浏览器;Agent 禁止提取授权 URL 后再次打开。
  3. 用户授权可能需要较长时间,登录进程默认可等待约 5 分钟。
  4. 只有原命令成功退出,且最终 JSON 返回 ok=true 与 can_auto_use=true,才能判定登录成功。
  5. 用户未授权就关闭浏览器时,CLI 无法可靠感知窗口关闭。继续等待原命令,直到用户停止或命令超时;不要自动发起第二次登录。

interactive_login.mode=caller_open_url 或调用方必须接管浏览器时,显式关闭 CLI 自动打开:

bash
openyida login --no-browser
# 兼容写法:
OPENYIDA_NO_BROWSER=1 openyida login

只有这种模式下,Agent 才能打开输出的授权 URL,并且只能打开一次。若当前宿主提供沙箱浏览器 / 内置 Browser,必须优先调用该工具打开 URL,不要把 URL 只作为聊天文本交给用户;无浏览器工具或工具失败时才提示用户手动打开。--quiet 只控制文本输出,不决定浏览器归属。

openyida login --check-only --json 仅用于恢复或防御性验证。不要把固定 sleep 或重复执行 check-only 当作默认完成机制。

用户给出宜搭入口 URL 时,原样传入:

bash
openyida login https://yida-group.alibaba-inc.com/
openyida login --alibaba
openyida login --intl

海外 / international / global / Japan / Global YiDA 使用 --intl 或等价入口。

运行环境注入 Token 模式命令

只有 auth snapshot 返回 auth_source=env 或 failure_reason=env_token_missing 后,才进入本模式。

bash
openyida agent-capabilities --summary-json
openyida env --json
openyida login --check-only --json
openyida auth status
openyida auth refresh

可继续执行的结果:

json
{
  "auth_mode": "token",
  "auth_source": "env",
  "status": "ok",
  "can_auto_use": true
}

如果运行环境没有注入 token,auth snapshot 会返回 failure_reason=env_token_missing;停止任务,让 Codex、yida-agent 等宿主补齐 token 注入,不要触发 OAuth。

禁止

  • 不要硬编码或打印 access_token、refresh_token、Cookie 或 CSRF。
  • 不要手动读写 .env、token 文件或 Cookie 文件。
  • 运行环境注入 token 模式下,不要再执行 openyida login 触发 OAuth。
  • 运行环境注入 token 模式下,缺 token 时让 Codex、yida-agent 等宿主修复注入,不要查找本地 .cache/cookies*.json。
  • 不要在业务命令里手动传 Cookie、_csrf_token 或 Bearer token。
  • 默认模式下,不要后台执行 openyida login、提取 URL 后再次执行 open。
  • 不要固定 sleep 后再检查登录态。
  • 不要仅凭浏览器关闭或 OAuth 回调到达就判定最终登录成功。

完成条件

  • Login/auth snapshot 返回可用登录态;或
  • 运行环境注入 token 模式返回明确停止原因,交由宿主修复。

© openyida, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in yida-skills/skills/yida-login of openyida/openyida.

Open the folder on GitHubat commit b52e65e

Compare with similar skills

Yida Login next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Yida Login compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Yida Login this skillopenyida/openyida220—~1.2kAutomated safety check: NotesMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
OmniRoute Provider Managementdiegosouzapw/OmniRoute74k—~2.4kAutomated safety check: PassMIT
Antipattern Preventiondoorkeeper-gem/doorkeeper5.5k—~1.1kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    74k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    175 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed

More from openyida/openyida

All 58 skills in this repo
  • Yida Canvas Custom Page

    openyida/openyida

    宜搭自定义页面开发规范,使用 YidaCodeCanvas 组件实现现代 React18 自定义页面。用于官网、看板、工作台、列表、详情、门户壳、可视化、hooks 交互、表单入口,以及需要门户组件、数据管理视图、成员、部门或上传组件的场景;发布层自动注入 yida/utils window 桥。

    220 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Openyida Release

    openyida/openyida

    快速发布 OpenYida npm 正式版或测试版。用户说“发布正式版”“发布测试版”“发 beta”或要求按当天日期生成版本 tag 时使用;不用于宜搭应用或自定义页面发布。

    220 GitHub stars~520 tokensUpdated today
    Auto-check passed
  • Yida Design Plan

    openyida/openyida

    Plan 模式的视觉设计分支。基于需求选择视觉方向,再结合业务页面规划维护 build-plan.json 的 visualStyle,供 CLI 派生 design.md。

    220 GitHub stars~756 tokensUpdated today
    Auto-check passed
  • Prevent stale local OpenYida custom page source from overwriting live designer edits.

    220 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Codemap

    openyida/openyida

    Generate, update, or drift-check agent-facing CodeMaps as progressive code terrain indexes for projects, features, capabilities, functions, modules, or bug chains.

    220 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Sdd Riper One Light

    openyida/openyida

    面向 GPT-5.5 等强模型和熟练用户的轻量 AI Agent Harness / checkpoint-driven coding skill。默认用户已经把任务切到基本可执行的最小混沌单元;模型自行分解、探索与推进,人类通过最终目标、最小 spec、复述、checkpoint、证据验证与回写来低干扰控盘。

    220 GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Categories

Questions about Yida Login

What does Yida Login do?

宜搭登录态管理。以 OpenYida auth snapshot 为准;默认 OAuth token,snapshot 返回 env 注入状态时使用运行环境注入 token。. Yida Login is an agent skill from openyida/openyida.

When should I use Yida Login?

Yida Login fits situations like: tasks that involve OAuth and OpenID Connect.

How do I install Yida Login in Claude Code?

Run `npx skills add openyida/openyida --skill yida-login -a claude-code`. Or copy the skill folder (yida-skills/skills/yida-login in openyida/openyida) into .claude/skills/yida-login in your project. Claude Code loads it when a task matches its description.

How do I install Yida Login in Codex?

Run `npx skills add openyida/openyida --skill yida-login -a codex`. Or copy the skill folder (yida-skills/skills/yida-login in openyida/openyida) into .agents/skills/yida-login in your project. Codex loads it when a task matches its description.

Can I use Yida Login in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openyida/openyida --skill yida-login -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/yida-login, .gemini/skills/yida-login, .github/skills/yida-login and .opencode/skills/yida-login in your project.

What does Yida Login need to run?

Going by SKILL.md and its folder, Yida Login needs credentials named OPENYIDA_ACCESS_TOKEN and OPENYIDA_REFRESH_TOKEN. Our summary lists: A credential in OPENYIDA_ACCESS_TOKEN; A credential in OPENYIDA_REFRESH_TOKEN.

Does Yida Login access the network?

SKILL.md names 1 domain. In commands or code: yida-group.alibaba-inc.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Yida Login safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Yida Login use?

Yida Login is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Yida Login use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Yida Login?

Skills that share tags, products or a category with Yida Login: Fortify Development (coollabsio/coolify, 63k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 74k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Yida Login?

openyida (a GitHub organization) maintains it in openyida/openyida, which has 220 GitHub stars. The repository holds 58 skills in this directory. The repository was last updated on October 8, 2026.

Source: openyida/openyida on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.