Agent skill

Spring Security JWT

by rrezartprebreza in rrezartprebreza/spring-boot-skills

A skill your agent uses when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security.

MITAuto-check passedBackend & APIs

Install Spring Security JWT

skills CLI
$ npx skills add rrezartprebreza/spring-boot-skills --skill spring-security-jwt -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rrezartprebreza/spring-boot-skills spring-security-jwt --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rrezartprebreza/spring-boot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spring-boot-3/spring-security-jwt .claude/skills/spring-security-jwt && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spring-security-jwt
GitHub stars
298
Token cost
~1.7k tokens
SKILL.md length
540 words
Files
7
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security.

  • An application issues and validates its own first-party JWT access and refresh tokens
  • SKILL.md covers Dependencies, Security configuration, JWT implementation and JSON 401/403, plus 4 more sections
  • Runs Java scripts from its folder; needs JWT_SECRET
  • Including authentication filters

What it does

Spring Security JWT is an agent skill from rrezartprebreza/spring-boot-skills. Use when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security. For JWTs issued by Keycloak, Auth0, Okta, Cognito, or another authorization server, use oauth2-resource-server.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering Authentication and Authorization and RBAC. It works with Auth0, Okta, Spring Boot and Java. The repository describes itself as: Production-grade Claude Code and Codex skills for Spring Boot developers. The licence is MIT.

When your agent uses it

  • An application issues and validates its own first-party JWT access and refresh tokens
  • Including authentication filters
  • Password encoding
  • Method security

Example prompts

  • “/spring-security-jwt”

Requirements

  • A credential in JWT_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit f0c06a0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Java), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spring Security JWT loads about 1.7k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 540 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rrezartprebreza/spring-boot-skills at commit f0c06a0, republished under its MIT licence (© rrezartprebreza). 540 words, ~1,670 tokens.

Download SKILL.mdSave it as .claude/skills/spring-security-jwt/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
spring-security-jwt
description
Use when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security. For JWTs issued by Keycloak, Auth0, Okta, Cognito, or another authorization server, use oauth2-resource-server.

Spring Security — JWT

Dependencies

xml
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-api</artifactId>
    <version>0.12.6</version>
</dependency>
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-impl</artifactId>
    <version>0.12.6</version>
    <scope>runtime</scope>
</dependency>
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-jackson</artifactId>
    <version>0.12.6</version>
    <scope>runtime</scope>
</dependency>

Security configuration

Use the compiled SecurityConfig with the filter and service below. It uses the lambda DSL, stateless bearer authentication, role rules, JSON 401/403 handlers and disabled servlet registration for the security-chain filter. Bean method injection avoids constructor cycles between the configuration and its own AuthenticationProvider bean. Adapt the routes and roles to the project. CSRF disabling applies to header-only bearer APIs; keep CSRF protection when browsers send authentication cookies automatically.

JWT implementation

Use the tested JwtService and JwtAuthenticationFilter templates together. The configuration keys are app.jwt.secret, app.jwt.access-token-expiration, and app.jwt.refresh-token-expiration (durations in milliseconds).

The filter rejects expired, malformed, tampered, missing-expiration and refresh tokens with 401 and a Bearer challenge. It checks the current user's enabled, locked, account-expired and credentials-expired flags before authentication. Deleted users also receive 401. Database outages and downstream application failures must remain server failures, not be masked as invalid credentials. Invalid supplied tokens are rejected even on public endpoints.

The filter's example error body uses Problem Details. For an existing legacy API, adapt this response and the entry point below to the established error contract. Never log bearer tokens. Register a filter bean only in the security chain: disable servlet-container registration with a FilterRegistrationBean<JwtAuthenticationFilter> whose enabled flag is false.

These templates illustrate a single-service first-party token contract. Before sharing signing keys or accepting tokens across services, define and validate issuer and audience, key rotation, and revocation. Spring Security's resource-server support can also validate custom JWTs; preserve it when it already fits the application. Token generation is not a complete refresh flow: retain the rotation/reuse-detection requirements below.

JSON 401/403

The configuration and filter templates use Problem Details for authentication and authorization errors. Adapt both together for a legacy error contract. Missing credentials on a protected route return 401; an authenticated caller without the required role returns 403. An invalid supplied token returns 401 even when the route permits anonymous access. Controller advice cannot handle exceptions thrown before the dispatcher servlet.

Show full SKILL.md (215 more words)Show less

Auth Controller

java
@RestController
@RequestMapping("/api/v1/auth")
@RequiredArgsConstructor
public class AuthController {

    private final AuthService authService;

    @PostMapping("/login")
    public ApiResponse<AuthResponse> login(@Valid @RequestBody LoginRequest request) {
        return ApiResponse.ok(authService.login(request));
    }

    @PostMapping("/refresh")
    public ApiResponse<AuthResponse> refresh(@Valid @RequestBody RefreshRequest request) {
        return ApiResponse.ok(authService.refresh(request.refreshToken()));
    }

    @PostMapping("/register")
    public ResponseEntity<ApiResponse<AuthResponse>> register(@Valid @RequestBody RegisterRequest request) {
        return ResponseEntity.status(201).body(ApiResponse.ok(authService.register(request)));
    }
}

public record AuthResponse(String accessToken, String refreshToken, long expiresIn) {}

Method-Level Security

java
// On service methods
@PreAuthorize("hasRole('ADMIN')")
public void deleteUser(UUID userId) { ... }

@PreAuthorize("hasRole('ADMIN') or #userId == authentication.principal.id")
public UserProfile getProfile(UUID userId) { ... }

@PostAuthorize("returnObject.email == authentication.name")
public User findById(UUID id) { ... }

application.yml

yaml
app:
  jwt:
    secret: ${JWT_SECRET} # min 256-bit base64 encoded key
    access-token-expiration: 900000   # 15 minutes
    refresh-token-expiration: 604800000 # 7 days

The example creates refresh tokens but does not implement a refresh endpoint. A production refresh flow must accept only type=refresh, rotate the refresh token on every use, and revoke the previous token (for example, with a hashed token-family record in a database or Redis).

Gotchas

  • Agent catches AuthenticationException broadly around user lookup - preserve AuthenticationServiceException as a server failure.
  • Agent logs in disabled or locked users from valid JWTs - validate current account status as well as claims.
  • Agent uses HttpSecurity.csrf().disable() old API — use AbstractHttpConfigurer::disable
  • Agent lets ExpiredJwtException escape the filter — expired token becomes a 500 instead of 401; catch in filter
  • Agent skips exceptionHandling() — clients get empty 401/403 bodies (or a login-page redirect); @RestControllerAdvice can't catch filter-level exceptions
  • Agent stores JWT secret in code — always ${JWT_SECRET} from environment (HS256 needs a ≥256-bit key or Keys.hmacShaKeyFor throws WeakKeyException)
  • Agent uses SessionCreationPolicy.IF_REQUIRED — must be STATELESS for JWT
  • Agent validates only signature and expiry — the bearer filter must accept type=access tokens only; refresh tokens belong to a separate refresh endpoint
  • Agent forgets @EnableMethodSecurity for @PreAuthorize to work
  • Agent uses BCrypt strength < 10 — use 12 for production
  • Agent puts token validation logic in controller — belongs in filter
  • Agent puts refresh tokens in localStorage examples — recommend httpOnly cookies or secure storage; refresh tokens are long-lived credentials

© rrezartprebreza, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in skills/spring-boot-3/spring-security-jwt of rrezartprebreza/spring-boot-skills.

  • SKILL.md
  • agents/openai.yaml
  • examples/bad-security-config.java
  • examples/good-security-config.java
  • templates/JwtAuthenticationFilter.java
  • templates/JwtService.java
  • templates/SecurityConfig.java

Open the folder on GitHubat commit f0c06a0

Compare with similar skills

Spring Security JWT next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spring Security JWT compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spring Security JWT this skillrrezartprebreza/spring-boot-skills298—~1.7kAutomated safety check: PassMIT
Springboot Securityaffaan-m/ECC276k5 repos~2kAutomated safety check: PassMIT
Frontmcp Authoritiesagentfront/frontmcp146—~7.1kAutomated safety check: PassApache-2.0
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Cometchat Securitycometchat/cometchat-skills131—~1.9kAutomated safety check: PassMIT
Spring Boot Security JWTgiuseppe-trisciuoglio/developer-kit356—~3.9kAutomated safety check: NotesMIT

Similar skills

  • Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

    276k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check passed
  • Frontmcp Authorities

    agentfront/frontmcp

    A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.

    146 GitHub stars~7.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Cometchat Security

    cometchat/cometchat-skills

    Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group…

    131 GitHub stars~1.9k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    356 GitHub stars~3.9k tokensUpdated 29 days ago
    Backend & APIsAuto-check: notes
  • Convex Setup Auth

    waynesutton/markdown-site

    Set up Convex authentication with proper user management, identity mapping, and access control patterns.

    628 GitHub stars~1.4k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed

More from rrezartprebreza/spring-boot-skills

All 51 skills in this repo
  • AI Observability

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when adding Spring AI-specific model observations, token usage, latency, externally configured cost attribution, advisor telemetry, or protected prompt and completion logging.

    298 GitHub stars~1.6k tokensUpdated 18 days ago
    Auto-check passed
  • API Versioning

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when versioning Spring MVC or WebFlux APIs in Spring Boot 3 / Spring Framework 6.

    298 GitHub stars~516 tokensUpdated 18 days ago
    Auto-check passed
  • API Versioning

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when versioning Spring MVC or WebFlux APIs in Spring Boot 4 / Spring Framework 7.

    298 GitHub stars~643 tokensUpdated 18 days ago
    Auto-check passed
  • Container Native Deployment

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when packaging a Spring Boot 3 application as an OCI image or GraalVM native executable.

    298 GitHub stars~781 tokensUpdated 18 days ago
    Auto-check passed
  • Container Native Deployment

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when packaging Spring Boot 4 as an OCI image, JVM container, AOT application, or GraalVM native executable.

    298 GitHub stars~706 tokensUpdated 18 days ago
    Auto-check passed
  • Domain Driven Design

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when evolving aggregate invariants, value objects or domain events in an existing DDD-style Spring Boot 3 application, or when DDD is explicitly requested.

    298 GitHub stars~2.1k tokensUpdated 18 days ago
    Auto-check passed

Categories

Questions about Spring Security JWT

What does Spring Security JWT do?

A skill your agent uses when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security. Spring Security JWT is an agent skill from rrezartprebreza/spring-boot-skills. Use when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security.

When should I use Spring Security JWT?

Spring Security JWT fits situations like: an application issues and validates its own first-party JWT access and refresh tokens; including authentication filters; password encoding; method security.

How do I install Spring Security JWT in Claude Code?

Run `npx skills add rrezartprebreza/spring-boot-skills --skill spring-security-jwt -a claude-code`. Or copy the skill folder (skills/spring-boot-3/spring-security-jwt in rrezartprebreza/spring-boot-skills) into .claude/skills/spring-security-jwt in your project. Claude Code loads it when a task matches its description.

How do I install Spring Security JWT in Codex?

Run `npx skills add rrezartprebreza/spring-boot-skills --skill spring-security-jwt -a codex`. Or copy the skill folder (skills/spring-boot-3/spring-security-jwt in rrezartprebreza/spring-boot-skills) into .agents/skills/spring-security-jwt in your project. Codex loads it when a task matches its description.

Can I use Spring Security JWT in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rrezartprebreza/spring-boot-skills --skill spring-security-jwt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spring-security-jwt, .gemini/skills/spring-security-jwt, .github/skills/spring-security-jwt and .opencode/skills/spring-security-jwt in your project.

What does Spring Security JWT need to run?

Going by SKILL.md and its folder, Spring Security JWT needs Java for the scripts in its folder and credentials named JWT_SECRET. Our summary lists: A credential in JWT_SECRET.

Does Spring Security JWT access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spring Security JWT safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Spring Security JWT use?

Spring Security JWT is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spring Security JWT use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spring Security JWT?

Skills that share tags, products or a category with Spring Security JWT: Springboot Security (affaan-m/ECC, 276k stars), Frontmcp Authorities (agentfront/frontmcp, 146 stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars) and Cometchat Security (cometchat/cometchat-skills, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spring Security JWT?

rrezartprebreza (a GitHub user) maintains it in rrezartprebreza/spring-boot-skills, which has 298 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on September 21, 2026.

Source: rrezartprebreza/spring-boot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.