Better Auth
einverne/dotfiles
Guide for implementing Better Auth - a framework-agnostic authentication and authorization framework for TypeScript.
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
$ npx skills add payloadcms/payload --skill payload -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install payloadcms/payload payload --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/payload/skills/payload .claude/skills/payload && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "payload" agent skill from https://github.com/payloadcms/payload/tree/main/packages/payload/skills/payload into .claude/skills/payload/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payload", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/payloadcms/payload/tree/main/packages/payload/skills/payloadType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add payloadcms/payload --skill payload -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install payloadcms/payload payload --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/payload/skills/payload .agents/skills/payload && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "payload" agent skill from https://github.com/payloadcms/payload/tree/main/packages/payload/skills/payload into .agents/skills/payload/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payload", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add payloadcms/payload --skill payload -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install payloadcms/payload payload --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/payload/skills/payload .cursor/skills/payload && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "payload" agent skill from https://github.com/payloadcms/payload/tree/main/packages/payload/skills/payload into .cursor/skills/payload/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payload", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/payloadcms/payload.git --path packages/payload/skills/payload--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add payloadcms/payload --skill payload -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install payloadcms/payload payload --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/payload/skills/payload .gemini/skills/payload && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "payload" agent skill from https://github.com/payloadcms/payload/tree/main/packages/payload/skills/payload into .gemini/skills/payload/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payload", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install payloadcms/payload payloadInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add payloadcms/payload --skill payload -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/payload/skills/payload .github/skills/payload && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "payload" agent skill from https://github.com/payloadcms/payload/tree/main/packages/payload/skills/payload into .github/skills/payload/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payload", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add payloadcms/payload --skill payload -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install payloadcms/payload payload --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/payload/skills/payload .opencode/skills/payload && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "payload" agent skill from https://github.com/payloadcms/payload/tree/main/packages/payload/skills/payload into .opencode/skills/payload/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "payload", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
payloadA skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
Payload is an agent skill from payloadcms/payload. Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.
Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files (for example `reference/ACCESS-CONTROL-ADVANCED.md`, `reference/ACCESS-CONTROL.md` and `reference/ADAPTERS.md`).
It sits in Backend & APIs, covering Authorization and RBAC. It works with Payload CMS, Next.js and TypeScript. The repository describes itself as: Payload is the open-source, fullstack Next.js framework, giving you instant backend superpowers. Get a full TypeScript backend and admin panel instantly. Use Payload as a… The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ed6a954. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxpnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
payloadcms.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
PAYLOAD_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Payload loads about 6.2k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 1,391 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from payloadcms/payload at commit ed6a954, republished under its MIT licence (© payloadcms). 1,391 words, ~6,213 tokens.
.claude/skills/payload/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.Payload is a Next.js native CMS with TypeScript-first architecture, providing admin panel, database management, REST/GraphQL APIs, authentication, and file storage.
| Task | Solution | Details |
|---|---|---|
| Auto-generate slugs | { type: 'slug', useAsSlug: 'title' } | FIELDS.md#slug-field |
| Restrict content by user | Access control with query | ACCESS-CONTROL.md#row-level-security-with-complex-queries |
| Local API user ops | user + overrideAccess: false | QUERIES.md#access-control-in-local-api |
| Draft/publish workflow | versions: { drafts: true } | COLLECTIONS.md#versioning--drafts |
| Computed fields | virtual: true with field-level hooks.afterRead returning the value | FIELDS.md#virtual-fields |
| Document titles | Stored top-level field in admin.useAsTitle | COLLECTIONS.md#useastitle |
| Conditional fields | admin.condition | FIELDS.md#conditional-fields |
| Custom field validation | validate function | FIELDS.md#validation |
| Filter relationship list | filterOptions on field | FIELDS.md#relationship |
| Select specific fields | select parameter | QUERIES.md#field-selection |
| Auto-set author/dates | beforeChange hook | HOOKS.md#collection-hooks |
| Prevent hook loops | req.context check | HOOKS.md#context |
| Cascading deletes | beforeDelete hook | HOOKS.md#collection-hooks |
| Geospatial queries | point field with near/within | FIELDS.md#point-geolocation |
| Reverse relationships | join field type | FIELDS.md#join-fields |
| Next.js revalidation | Context control in afterChange | HOOKS.md#nextjs-revalidation-with-context-control |
| Query by relationship | Nested property syntax | QUERIES.md#nested-properties |
| Complex queries | AND/OR logic | QUERIES.md#andor-logic |
| Transactions | Pass req to operations | ADAPTERS.md#threading-req-through-operations |
| Background jobs | Jobs queue with tasks | ADVANCED.md#jobs-queue |
| Custom API routes | Collection custom endpoints | ADVANCED.md#custom-endpoints |
| Cloud storage | Storage adapter plugins | ADAPTERS.md#storage-adapters |
| Multi-language | localization config + localized: true | ADVANCED.md#localization |
| Create plugin | (options) => (config) => Config | PLUGIN-DEVELOPMENT.md#plugin-architecture |
| Plugin package setup | Package structure with SWC | PLUGIN-DEVELOPMENT.md#plugin-package-structure |
| Add fields to collection | Map collections, spread fields | PLUGIN-DEVELOPMENT.md#adding-fields-to-collections |
| Plugin hooks | Preserve existing hooks in array | PLUGIN-DEVELOPMENT.md#adding-hooks |
| Check field type | Type guard functions | FIELD-TYPE-GUARDS.md |
npx create-payload-app@latest my-app
cd my-app
pnpm devimport { buildConfig } from 'payload'
import { mongooseAdapter } from '@payloadcms/db-mongodb'
import { lexicalEditor } from '@payloadcms/richtext-lexical'
import path from 'path'
import { fileURLToPath } from 'url'
const filename = fileURLToPath(import.meta.url)
const dirname = path.dirname(filename)
export default buildConfig({
admin: {
user: 'users',
importMap: {
baseDir: path.resolve(dirname),
},
},
collections: [Users, Media],
editor: lexicalEditor(),
secret: process.env.PAYLOAD_SECRET,
typescript: {
outputFile: path.resolve(dirname, 'payload-types.ts'),
},
db: mongooseAdapter({
url: process.env.DATABASE_URL,
}),
})Apply these defaults when modeling content unless there's a clear reason not to:
versions: { drafts: true }. This is the
recommended starting point for any content collection. It auto-injects a
_status field (draft / published / changed) — don't add your own
status field, it's redundant. Only skip versions for collections that have
no publish/draft lifecycle (e.g. internal join tables, settings).slug field type for all slugs instead of hand-rolling
{ name: 'slug', type: 'text', unique: true }. It auto-generates the slug from
a source field, adds a regenerate toggle, and defaults to required, unique,
index, and position: 'sidebar'. useAsSlug is required — name the
source field to generate from: { name: 'slug', type: 'slug', useAsSlug: 'title' }.position: 'sidebar' is for short, at-a-glance fields — status, category,
author, publish date. Avoid it for long fields that need horizontal space to be
usable (description, rich text content, long text). Those belong in the main
document area.admin.useAsTitle. Never set
admin.useAsTitle to a computed field configured with virtual: true; these
fields are not queryable and Payload rejects the configuration. A
relationship-path virtual such as virtual: 'author.name' is supported, but
use it only when the title must come from a related document.import type { CollectionConfig } from 'payload'
export const Posts: CollectionConfig = {
slug: 'posts',
admin: {
useAsTitle: 'title',
// _status (from versions.drafts) shows the draft/published state — no custom status field needed
defaultColumns: ['title', 'author', '_status', 'createdAt'],
},
versions: {
drafts: true,
},
fields: [
{ name: 'title', type: 'text', required: true },
{ name: 'slug', type: 'slug', useAsSlug: 'title' }, // auto-generates from `title`, unique + indexed, sidebar position
{ name: 'content', type: 'richText' }, // long field — stays in the main area, not the sidebar
// short, at-a-glance field — good sidebar candidate
{ name: 'author', type: 'relationship', relationTo: 'users', admin: { position: 'sidebar' } },
],
timestamps: true,
}For more collection patterns (auth, upload, drafts, live preview), see COLLECTIONS.md.
// Text field
{ name: 'title', type: 'text', required: true }
// Relationship
{ name: 'author', type: 'relationship', relationTo: 'users', required: true }
// Rich text
{ name: 'content', type: 'richText', required: true }
// Slug — use the native field type instead of a hand-rolled text field
{ name: 'slug', type: 'slug', useAsSlug: 'title' }
// Select (for genuine taxonomy — NOT publish state; use versions.drafts + _status for that)
{ name: 'category', type: 'select', options: ['news', 'tutorial', 'opinion'] }
// Upload
{ name: 'image', type: 'upload', relationTo: 'media' }For all field types (array, blocks, point, join, virtual, conditional, etc.), see FIELDS.md.
Hooks live at one of two levels and they are not interchangeable. Collection hooks receive { doc, data, req, operation, ... } and act on the whole document. Field hooks live inside an individual field's hooks object, receive { value, siblingData, ... }, and return the new value for that field. Computed/virtual fields, per-field formatters, and per-field access masking are field hooks; cross-field business logic is a collection hook.
// Collection-level: business logic across the document
export const Posts: CollectionConfig = {
slug: 'posts',
hooks: {
beforeChange: [
async ({ data, operation }) => {
if (operation === 'create') {
data.slug = slugify(data.title)
}
return data
},
],
},
fields: [{ name: 'title', type: 'text' }],
}
// Field-level: compute / format a single field's value (virtual fields use this)
export const Users: CollectionConfig = {
slug: 'users',
fields: [
{ name: 'firstName', type: 'text' },
{ name: 'lastName', type: 'text' },
{
name: 'fullName',
type: 'text',
virtual: true,
hooks: {
afterRead: [({ siblingData }) => `${siblingData.firstName} ${siblingData.lastName}`],
},
},
],
}When asked to "compute a field" or "populate a field's value in a hook", use a field-level hook on that field — never a collection-level afterRead that mutates doc.
For all hook patterns, see HOOKS.md. For access control, see ACCESS-CONTROL.md.
import type { Access } from 'payload'
import type { User } from '@/payload-types'
// Type-safe access control
export const adminOnly: Access = ({ req }) => {
const user = req.user as User
return user?.roles?.includes('admin') || false
}
// Row-level access control
export const ownPostsOnly: Access = ({ req }) => {
const user = req.user as User
if (!user) return false
if (user.roles?.includes('admin')) return true
return {
author: { equals: user.id },
}
}// Local API
const posts = await payload.find({
collection: 'posts',
overrideAccess: true,
where: {
status: { equals: 'published' },
'author.name': { contains: 'john' },
},
depth: 2,
limit: 10,
sort: '-createdAt',
})
// Query with populated relationships
const post = await payload.findByID({
collection: 'posts',
overrideAccess: true,
id: '123',
depth: 2, // Populates relationships (default is 2)
})
// Returns: { author: { id: "user123", name: "John" } }
// Without depth, relationships return IDs only
const post = await payload.findByID({
collection: 'posts',
overrideAccess: true,
id: '123',
depth: 0,
})
// Returns: { author: "user123" }For all query operators and REST/GraphQL examples, see QUERIES.md.
// In API routes (Next.js)
import { getPayload } from 'payload'
import config from '@payload-config'
export async function GET(request: Request) {
const payload = await getPayload({ config })
const { user } = await payload.auth({ headers: request.headers })
const posts = await payload.find({
collection: 'posts',
overrideAccess: false, // this route answers for whoever called it
user,
})
return Response.json(posts)
}
// In Server Components
import { headers } from 'next/headers'
import { getPayload } from 'payload'
import config from '@payload-config'
export default async function Page() {
const payload = await getPayload({ config })
const { user } = await payload.auth({ headers: await headers() })
const { docs } = await payload.find({
collection: 'posts',
overrideAccess: false,
user,
})
return <div>{docs.map(post => <h1 key={post.id}>{post.title}</h1>)}</div>
}overrideAccess: true bypasses ALL access control, even when a user is passed.
// ❌ SECURITY BUG: Passes user but bypasses their permissions anyway
await payload.find({
collection: 'posts',
user: someUser,
overrideAccess: true, // Access control is BYPASSED!
})
// ✅ SECURE: Respects the user's permissions — this is the default, overrideAccess can be omitted
await payload.find({
collection: 'posts',
user: someUser,
})On Local API operations where overrideAccess is optional, it defaults to false — Access Control is respected unless explicitly bypassed.
overrideAccess: false - operating on behalf of a user (API routes, user-facing server functions, and webhooks acting as a user). Pass user alongside it.overrideAccess: true - trusted system work (cron jobs, seeds, migrations, system tasks, and independently authenticated webhooks intentionally granted full permissions)Never set overrideAccess: true out of habit or by copying a nearby call — pick the value this call means.
See QUERIES.md#access-control-in-local-api.
Nested operations in hooks without req break transaction atomicity.
// ❌ DATA CORRUPTION RISK: Separate transaction
hooks: {
afterChange: [
async ({ doc, req }) => {
await req.payload.create({
collection: 'audit-log',
overrideAccess: true,
data: { docId: doc.id },
// Missing req - runs in separate transaction!
})
},
]
}
// ✅ ATOMIC: Same transaction
hooks: {
afterChange: [
async ({ doc, req }) => {
await req.payload.create({
collection: 'audit-log',
overrideAccess: true,
data: { docId: doc.id },
req, // Maintains atomicity
})
},
]
}See ADAPTERS.md#threading-req-through-operations.
Hooks triggering operations that trigger the same hooks create infinite loops.
// ❌ INFINITE LOOP
hooks: {
afterChange: [
async ({ doc, req }) => {
await req.payload.update({
collection: 'posts',
overrideAccess: true,
id: doc.id,
data: { views: doc.views + 1 },
req,
}) // Triggers afterChange again!
},
]
}
// ✅ SAFE: Use context flag
hooks: {
afterChange: [
async ({ doc, req, context }) => {
if (context.skipHooks) return
await req.payload.update({
collection: 'posts',
overrideAccess: true,
id: doc.id,
data: { views: doc.views + 1 },
context: { skipHooks: true },
req,
})
},
]
}See HOOKS.md#context.
src/
├── app/
│ ├── (frontend)/
│ │ └── page.tsx
│ └── (payload)/
│ └── admin/[[...segments]]/page.tsx
├── collections/
│ ├── Posts.ts
│ ├── Media.ts
│ └── Users.ts
├── globals/
│ └── Header.ts
├── components/
│ └── CustomField.tsx
├── hooks/
│ └── slugify.ts
└── payload.config.tsPayload generates payload-types.ts for you — you rarely need to run generate:types by hand.
typescript.autoGenerate defaults to true, so the dev
server regenerates types automatically whenever your config changes. Don't run
generate:types manually while the dev server is running — it's redundant.payload build generates the import map and types before
running next build. Prefer it over calling next build directly so neither is
ever stale. Pass --no-types to skip type generation.payload generate:types) is an escape hatch — only when
neither the dev server nor a build is in the loop (e.g. a one-off script, or CI
before a step that doesn't run payload build).// payload.config.ts
export default buildConfig({
typescript: {
outputFile: path.resolve(dirname, 'payload-types.ts'),
// autoGenerate defaults to true — types regenerate in dev automatically
},
})
// Usage
import type { Post, User } from '@/payload-types'overrideAccess respect access control by default — set it to true only for trusted server-side workreq in nested operations breaks transaction atomicityreq.context flagsdepth: 0 for IDs only_status field is auto-injected when drafts are enabledautoGenerate) and during payload build — avoid running generate:types manuallytransactionOptions: {}virtual: true cannot be used in admin.useAsTitle; use a stored top-level fieldversions: { drafts: true } by default on content collections; rely on the
auto-injected _status field rather than adding a custom status fieldslug field type for slugs instead of hand-rolling a unique text fieldadmin.useAsTitle; never use a computed
virtual: true field as the titleposition: 'sidebar' for short, at-a-glance fields (status, category,
author, date); keep long fields (description, rich text) in the main areaoverrideAccess: false whenever the call acts for a user, and pass that usersaveToJWT: true for roles to avoid database lookupsselect to limit returned fieldsmaxDepth on relationships to prevent over-fetchingreq.contextreq to nested operations in hooksbeforeValidate for data formattingbeforeChange for business logicautoGenerate) and payload build generate types; run generate:types manually only when neither is runningpayload-types.tsimport type { User } from '@/payload-types'CollectionConfig, Field, CollectionBeforeChangeHook, Access, Plugin, …) or use satisfies <Type>. Without an annotation, string properties like type: 'text' widen to string and discriminated unions (Field, CollectionConfig) fail to resolve. Inline literals get this for free via contextual typing; extracted constants do not.access/ directoryhooks/ directory© payloadcms, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files in packages/payload/skills/payload of payloadcms/payload.
Open the folder on GitHubat commit ed6a954
We found 27 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in payloadcms/payload, which our catalogue first saw on October 7, 2026.
Payload next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Payload this skillpayloadcms/payload | 45k | 5 repos | ~6.2k | Automated safety check: Pass | MIT | |
| Better Autheinverne/dotfiles | 121 | — | ~4k | Automated safety check: Notes | MIT | |
| Better Authsecondsky/claude-skills | 227 | — | ~7.5k | Automated safety check: Pass | MIT | |
| Shipany SaaS Boilerplate Referencelittleben/awesomeAgentskills | 188 | — | ~645 | Automated safety check: Pass | MIT | |
| Qstash JSupstash/qstash-js | 269 | 1 repos | ~746 | Automated safety check: Pass | MIT | |
| Stack Previewvicoa-ai/vicoa | 490 | — | ~1.8k | Automated safety check: Notes | AGPL-3.0 |
einverne/dotfiles
Guide for implementing Better Auth - a framework-agnostic authentication and authorization framework for TypeScript.
secondsky/claude-skills
Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks.
littleben/awesomeAgentskills
Shipany AI-powered SaaS boilerplate documentation. Use when working with Shipany framework, Next.js 15, TypeScript, Drizzle ORM, NextAuth, payment…
upstash/qstash-js
Work with the QStash JavaScript/TypeScript SDK for serverless messaging, scheduling.
vicoa-ai/vicoa
Run the whole Vicoa stack (Postgres, backend, realtime server, web dashboard) from the current checkout and publish it at one public tunnel URL, so a branch can be reviewed from another machine or…
lobehub/lobehub
Implementation patterns for Upstash Workflow and QStash handlers in the LobeHub codebase: dry runs, fan-out chunking and single-item execution.
payloadcms/payload
A skill your agent uses when a Payload pull request needs a concise visual walkthrough for reviewers.
payloadcms/payload
A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails
payloadcms/payload
A skill your agent uses when new translation keys are added to packages to generate new translations strings
payloadcms/payload
A skill your agent uses when CI tests fail on main branch after PR merge, when investigating flaky test failures, or when user provides a PR URL/number to aggregate all failing tests
payloadcms/payload
A skill your agent uses when UI changes are complete and e2e tests need updating.
payloadcms/payload
A skill your agent uses when changing or reviewing rendered Payload UI, interaction or focus behavior, semantic markup, accessibility tests, or WCAG/VPAT evidence.
Works with
Categories
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Payload is an agent skill from payloadcms/payload.ts, collections, fields, hooks, access control, Payload API).
Payload fits situations like: working with Payload projects (payload.config.ts; debugging validation errors; security issues; relationship queries.
Run `npx skills add payloadcms/payload --skill payload -a claude-code`. Or copy the skill folder (packages/payload/skills/payload in payloadcms/payload) into .claude/skills/payload in your project. Claude Code loads it when a task matches its description.
Run `npx skills add payloadcms/payload --skill payload -a codex`. Or copy the skill folder (packages/payload/skills/payload in payloadcms/payload) into .agents/skills/payload in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add payloadcms/payload --skill payload -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/payload, .gemini/skills/payload, .github/skills/payload and .opencode/skills/payload in your project.
Going by SKILL.md and its folder, Payload needs the command-line tools its instructions call (npx and pnpm) and credentials named PAYLOAD_SECRET. Our summary lists: Node.js; A credential in PAYLOAD_SECRET.
SKILL.md names 1 domain. As links in the text: payloadcms.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Payload is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Payload: Better Auth (einverne/dotfiles, 121 stars), Better Auth (secondsky/claude-skills, 227 stars), Shipany SaaS Boilerplate Reference (littleben/awesomeAgentskills, 188 stars) and Qstash JS (upstash/qstash-js, 269 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
payloadcms (a GitHub organization) maintains it in payloadcms/payload, which has 45,120 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: payloadcms/payload on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.