Gemini Live API Dev
google-gemini/gemini-skills
A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.
Cloudflare Zero Trust Access authentication for Workers. An agent skill from secondsky/claude-skills.
$ npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install secondsky/claude-skills cloudflare-zero-trust-access --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access .claude/skills/cloudflare-zero-trust-access && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cloudflare-zero-trust-access" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access into .claude/skills/cloudflare-zero-trust-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust-access", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/secondsky/claude-skills/tree/main/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-accessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install secondsky/claude-skills cloudflare-zero-trust-access --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access .agents/skills/cloudflare-zero-trust-access && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cloudflare-zero-trust-access" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access into .agents/skills/cloudflare-zero-trust-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust-access", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install secondsky/claude-skills cloudflare-zero-trust-access --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access .cursor/skills/cloudflare-zero-trust-access && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cloudflare-zero-trust-access" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access into .cursor/skills/cloudflare-zero-trust-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust-access", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/secondsky/claude-skills.git --path plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install secondsky/claude-skills cloudflare-zero-trust-access --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access .gemini/skills/cloudflare-zero-trust-access && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cloudflare-zero-trust-access" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access into .gemini/skills/cloudflare-zero-trust-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust-access", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install secondsky/claude-skills cloudflare-zero-trust-accessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access .github/skills/cloudflare-zero-trust-access && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cloudflare-zero-trust-access" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access into .github/skills/cloudflare-zero-trust-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust-access", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install secondsky/claude-skills cloudflare-zero-trust-access --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access .opencode/skills/cloudflare-zero-trust-access && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cloudflare-zero-trust-access" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access into .opencode/skills/cloudflare-zero-trust-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust-access", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cloudflare-zero-trust-accessCloudflare Zero Trust Access authentication for Workers. An agent skill from secondsky/claude-skills.
Cloudflare Zero Trust Access is an agent skill from secondsky/claude-skills. Cloudflare Zero Trust Access authentication for Workers. Use for JWT validation, service tokens, CORS, or encountering preflight blocking, cache race conditions, missing JWT headers.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts and reference files (for example `references/access-policy-setup.md`, `references/common-errors.md` and `references/jwt-payload-structure.md`).
It sits in Backend & APIs, covering Authentication and Async programming. It works with Cloudflare and Hono. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.
Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBashFrom allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (TypeScript and Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
team.cloudflareaccess.comworker.workers.devAlso links to:
developers.cloudflare.comgithub.comhono.devone.dash.cloudflare.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cloudflare Zero Trust Access loads about 2.6k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 748 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Write, Edit, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 748 words, ~2,565 tokens.
.claude/skills/cloudflare-zero-trust-access/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.Integrate Cloudflare Zero Trust Access authentication with Cloudflare Workers applications using proven patterns and templates.
This skill provides complete integration patterns for Cloudflare Access, enabling application-level authentication for Workers without managing your own auth infrastructure.
What is Cloudflare Access? Cloudflare Access is Zero Trust authentication that sits in front of your application, validating users before they reach your Worker. After authentication, Access issues JWT tokens that your Worker validates.
Key Benefits:
Trigger this skill when tasks involve:
Keywords to Trigger: cloudflare access, zero trust, access authentication, JWT validation, service tokens, cloudflare auth, hono access, workers authentication, protect worker routes, admin authentication
📖 New to Cloudflare Access? Load references/quick-start.md for step-by-step setup instructions (15-20 minutes).
Use @hono/cloudflare-access for one-line Access integration.
When to Use:
Template: templates/hono-basic-setup.ts
Setup:
import { Hono } from 'hono'
import { cloudflareAccess } from '@hono/cloudflare-access'
const app = new Hono<{ Bindings: Env }>()
// Public routes
app.get('/', (c) => c.text('Public page'))
// Protected routes
app.use(
'/admin/*',
cloudflareAccess({
domain: (c) => c.env.ACCESS_TEAM_DOMAIN,
})
)
app.get('/admin/dashboard', (c) => {
const { email } = c.get('accessPayload')
return c.text(`Welcome, ${email}!`)
})Configuration (wrangler.jsonc):
{
"vars": {
"ACCESS_TEAM_DOMAIN": "your-team.cloudflareaccess.com",
"ACCESS_AUD": "your-app-aud-tag"
}
}Benefits:
When to Use: Not using Hono, need custom validation logic
Template: templates/jwt-validation-manual.ts (~100 lines, uses Web Crypto API)
When to Use: CI/CD pipelines, backend services, cron jobs (no interactive login)
Client: Send CF-Access-Client-Id + CF-Access-Client-Secret headers
Server: Same middleware handles both - detect via !payload.email && payload.common_name
📄 Full guide: references/service-tokens-guide.md
When to Use: SPA (React/Vue/Angular) calling protected API
⚠️ CRITICAL: CORS middleware MUST come BEFORE Access middleware!
// ✅ CORRECT ORDER
app.use('*', cors({ origin: 'https://app.example.com', credentials: true }))
app.use('/api/*', cloudflareAccess({ domain: (c) => c.env.ACCESS_TEAM_DOMAIN }))Why: OPTIONS preflight has no auth headers → Access blocks with 401
📄 Full pattern: templates/cors-access.ts
When to Use: SaaS with per-org authentication, white-label apps
Architecture: Tenant config in D1/KV → Dynamic middleware per request
📄 Full pattern: templates/multi-tenant.ts and references/use-cases.md
This skill prevents 8 documented errors. Full details: references/common-errors.md
Problem: OPTIONS requests return 401, breaking CORS
Solution: CORS middleware BEFORE Access middleware
// ✅ Correct
app.use('*', cors())
app.use('/api/*', cloudflareAccess({ domain: '...' }))Problem: Request not going through Access, no JWT header
Solution: Access Worker through Access URL, not direct *.workers.dev
✅ https://team.cloudflareaccess.com/...
❌ https://worker.workers.devProblem: Hardcoded or wrong team name causes "Invalid issuer"
Solution: Use environment variables
// ✅ Correct
cloudflareAccess({ domain: (c) => c.env.ACCESS_TEAM_DOMAIN })
// ❌ Wrong
cloudflareAccess({ domain: 'my-team.cloudflareaccess.com' })| # | Error | Solution |
|---|---|---|
| 4 | Key cache race | Use @hono/cloudflare-access (auto-caches) |
| 5 | Wrong service token headers | Use CF-Access-Client-Id/Secret (not Authorization) |
| 6 | Token expiration (401 after 1 hr) | Handle gracefully, redirect to login |
| 7 | Overlapping policies | Use most specific paths |
| 8 | Dev/prod mismatch | Use environment-specific configs |
📄 Full error details: references/common-errors.md (~2.5 hours saved per implementation)
| Template | Purpose |
|---|---|
hono-basic-setup.ts | Standard Hono + Access integration |
jwt-validation-manual.ts | Manual JWT verification with Web Crypto |
service-token-auth.ts | Service token patterns |
cors-access.ts | CORS + Access (correct ordering) |
multi-tenant.ts | Multi-tenant architecture |
wrangler.jsonc | Complete Wrangler configuration |
.env.example | Environment variable template |
types.ts | TypeScript definitions |
| Script | Usage |
|---|---|
test-access-jwt.sh | ./test-access-jwt.sh <jwt-token> - Decode and validate JWT |
create-service-token.sh | ./create-service-token.sh [name] - Service token setup guide |
| Use Case | Template | Key Point |
|---|---|---|
| Admin Dashboard | hono-basic-setup.ts | Email domain policy |
| API Authentication | hono-basic-setup.ts | Mixed user/service policy |
| SPA + API | cors-access.ts | CORS before Access! |
| CI/CD Pipeline | service-token-auth.ts | Service token in secrets |
| Multi-Tenant SaaS | multi-tenant.ts | D1 tenant config |
📄 Detailed use cases: references/use-cases.md
| Reference File | Load When... |
|---|---|
references/quick-start.md | Step-by-step setup for new users, first-time integration |
references/common-errors.md | Debugging auth issues, prevention patterns (includes all 8 errors) |
references/jwt-payload-structure.md | Accessing JWT claims, user vs service token |
references/service-tokens-guide.md | Setting up machine-to-machine auth |
references/access-policy-setup.md | Dashboard configuration, policy creation |
references/use-cases.md | Detailed implementation for specific scenarios |
references/value-proposition.md | Token efficiency metrics, workflow guidance, production validation |
| Package | Version |
|---|---|
| @hono/cloudflare-access | 0.3.1 |
| hono | 4.12.12 |
| @cloudflare/workers-types | 4.20260408.0 |
Verified: 2025-12-14 | Token Savings: ~58% | Production Tested: ✅
This skill is for Cloudflare Workers with Cloudflare Access. Do not use for:
@cloudflare/pages-plugin-cloudflare-access instead)For those, use appropriate skills or libraries.
Cloudflare Documentation:
Packages:
Dashboard:
Skill Version: 1.0.0 Last Updated: 2025-10-28 Errors Prevented: 8 Token Savings: 58% Time Savings: 2.5 hours Production Tested: ✅
© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 17 other files (scripts, references) in plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access of secondsky/claude-skills.
Open the folder on GitHubat commit 8837836
Cloudflare Zero Trust Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cloudflare Zero Trust Access this skillsecondsky/claude-skills | 227 | — | ~2.6k | Automated safety check: Notes | MIT | |
| Gemini Live API Devgoogle-gemini/gemini-skills | 4.3k | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Apikerhodgef/apiker | 127 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Cloudflare WorkersEpicenterHQ/epicenter | 4.8k | — | ~576 | Automated safety check: Pass | Custom licence | |
| HonoEpicenterHQ/epicenter | 4.8k | — | ~513 | Automated safety check: Pass | Custom licence | |
| Better Autheinverne/dotfiles | 121 | — | ~4k | Automated safety check: Notes | MIT |
google-gemini/gemini-skills
A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.
hodgef/apiker
Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.
EpicenterHQ/epicenter
Cloudflare Workers patterns for Worker runtime APIs, Durable Objects, KV, R2, D1, Queues, WebSockets, streaming responses, bindings, wrangler configuration, and deployment limits.
EpicenterHQ/epicenter
Hono patterns for TypeScript API routes, middleware, request and response typing, streaming, WebSockets, and Cloudflare Workers deployment.
einverne/dotfiles
Guide for implementing Better Auth - a framework-agnostic authentication and authorization framework for TypeScript.
hashgraph-online/awesome-codex-plugins
A skill your agent uses when a val needs to require login with a Val Town account — gating routes behind authentication, identifying the current user, building user-specific dashboards.
secondsky/claude-skills
TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.
secondsky/claude-skills
AutoAnimate (@formkit/auto-animate) zero-config animations for React.
secondsky/claude-skills
MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.
secondsky/claude-skills
This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…
secondsky/claude-skills
Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).
secondsky/claude-skills
Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.
Works with
Categories
Cloudflare Zero Trust Access authentication for Workers. An agent skill from secondsky/claude-skills. Cloudflare Zero Trust Access is an agent skill from secondsky/claude-skills. Cloudflare Zero Trust Access authentication for Workers.
Cloudflare Zero Trust Access fits situations like: encountering preflight blocking; cache race conditions; missing JWT headers.
Run `npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a claude-code`. Or copy the skill folder (plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access in secondsky/claude-skills) into .claude/skills/cloudflare-zero-trust-access in your project. Claude Code loads it when a task matches its description.
Run `npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a codex`. Or copy the skill folder (plugins/cloudflare-zero-trust-access/skills/cloudflare-zero-trust-access in secondsky/claude-skills) into .agents/skills/cloudflare-zero-trust-access in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill cloudflare-zero-trust-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-zero-trust-access, .gemini/skills/cloudflare-zero-trust-access, .github/skills/cloudflare-zero-trust-access and .opencode/skills/cloudflare-zero-trust-access in your project.
Going by SKILL.md and its folder, Cloudflare Zero Trust Access needs TypeScript and a shell for the scripts in its folder. Our summary lists: Node.js; A Bash shell. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash.
SKILL.md names 6 domains. In commands or code: team.cloudflareaccess.com and worker.workers.dev; the agent is likely to contact these when it follows the instructions. As links in the text: developers.cloudflare.com, github.com, hono.dev and one.dash.cloudflare.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Cloudflare Zero Trust Access is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Cloudflare Zero Trust Access: Gemini Live API Dev (google-gemini/gemini-skills, 4.3k stars), Apiker (hodgef/apiker, 127 stars), Cloudflare Workers (EpicenterHQ/epicenter, 4.8k stars) and Hono (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.
Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.