Agent skill

Session Management

by secondsky in secondsky/claude-skills

Implements secure session management with JWT tokens, Redis storage, refresh flows, and proper cookie configuration.

MITAuto-check passedBackend & APIs

Install Session Management

skills CLI
$ npx skills add secondsky/claude-skills --skill session-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/claude-skills session-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/session-management/skills/session-management .claude/skills/session-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
session-management
GitHub stars
227
Token cost
~651 tokens
SKILL.md length
68 words
Files
1
Skills in repo
169
Repo updated
First seen
Licence
MIT

At a glance

Implements secure session management with JWT tokens, Redis storage, refresh flows, and proper cookie configuration.

  • Building authentication systems
  • SKILL.md covers Token-Based Sessions, Redis Session Storage, Cookie Configuration and Token Refresh Flow, plus 2 more sections
  • Needs REFRESH_SECRET and JWT_SECRET
  • Managing user sessions

What it does

Session Management is an agent skill from secondsky/claude-skills. Implements secure session management with JWT tokens, Redis storage, refresh flows, and proper cookie configuration. Use when building authentication systems, managing user sessions, or implementing secure logout functionality.

Its SKILL.md is about 650 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with Redis. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • Building authentication systems
  • Managing user sessions
  • Implementing secure logout functionality

Example prompts

  • “Use the session-management skill to implement secure session management with JWT tokens, Redis storage, refresh flows, and proper cookie configuration”
  • “/session-management”

Requirements

  • A credential in JWT_SECRET
  • A credential in REFRESH_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • REFRESH_SECRET
    • JWT_SECRET
    • SESSION_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Session Management loads about 651 tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 68 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~651

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 68 words, ~651 tokens.

Download SKILL.mdSave it as .claude/skills/session-management/SKILL.md (or your agent's skills folder).
name
session-management
description
Implements secure session management with JWT tokens, Redis storage, refresh flows, and proper cookie configuration. Use when building authentication systems, managing user sessions, or implementing secure logout functionality.
license
MIT

Session Management

Implement secure session management with proper token handling and storage.

Token-Based Sessions

javascript
const jwt = require('jsonwebtoken');

function generateTokens(user) {
  const accessToken = jwt.sign(
    { userId: user.id, role: user.role, type: 'access' },
    process.env.JWT_SECRET,
    { expiresIn: '1h' }
  );

  const refreshToken = jwt.sign(
    { userId: user.id, type: 'refresh' },
    process.env.REFRESH_SECRET,
    { expiresIn: '7d' }
  );

  return { accessToken, refreshToken };
}

Redis Session Storage

javascript
const redis = require('redis');
const client = redis.createClient();

class SessionStore {
  async create(userId, sessionData) {
    const sessionId = crypto.randomUUID();
    await client.hSet(`sessions:${userId}`, sessionId, JSON.stringify({
      ...sessionData,
      createdAt: Date.now()
    }));
    await client.expire(`sessions:${userId}`, 86400 * 7);
    return sessionId;
  }

  async invalidateAll(userId) {
    await client.del(`sessions:${userId}`);
  }
}
javascript
app.use(session({
  name: 'session',
  secret: process.env.SESSION_SECRET,
  cookie: {
    httpOnly: true,
    secure: process.env.NODE_ENV === 'production',
    sameSite: 'strict',
    maxAge: 3600000, // 1 hour
    domain: '.example.com'
  },
  resave: false,
  saveUninitialized: false
}));

Token Refresh Flow

javascript
app.post('/auth/refresh', async (req, res) => {
  const { refreshToken } = req.cookies;

  try {
    const payload = jwt.verify(refreshToken, process.env.REFRESH_SECRET);
    if (payload.type !== 'refresh') throw new Error('Invalid token type');

    const user = await User.findById(payload.userId);
    const tokens = generateTokens(user);

    res.cookie('accessToken', tokens.accessToken, cookieOptions);
    res.json({ success: true });
  } catch (err) {
    res.status(401).json({ error: 'Invalid refresh token' });
  }
});

Security Requirements

  • Use HTTPS exclusively
  • Set httpOnly and sameSite on cookies
  • Implement proper token expiration
  • Use strong, unique secrets per environment
  • Validate signatures on every request

Never Do

  • Store sensitive data in tokens
  • Transmit tokens via URL parameters
  • Use weak or shared secrets
  • Skip signature validation

© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/session-management/skills/session-management of secondsky/claude-skills.

Open the folder on GitHubat commit 8837836

Compare with similar skills

Session Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Session Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Session Management this skillsecondsky/claude-skills227—~651Automated safety check: PassMIT
Cb Realtime APIBlkLeg/CircuitBreaker201—~1.7kAutomated safety check: PassMIT
Auth Flowsgjovanovicst/golang-auth-api129—~2.2kAutomated safety check: PassMIT
Project Mapgjovanovicst/golang-auth-api129—~2.6kAutomated safety check: PassMIT
Frontmcp Configagentfront/frontmcp146—~7kAutomated safety check: PassApache-2.0
Centrifugopedronauck/skills633—~3.1kAutomated safety check: PassNone

Similar skills

  • Cb Realtime API

    BlkLeg/CircuitBreaker

    How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…

    201 GitHub stars~1.7k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Auth Flows

    gjovanovicst/golang-auth-api

    Detailed documentation of the 4 authentication systems, token lifecycle, middleware pipeline, session management, and RBAC authorization.

    129 GitHub stars~2.2k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Project Map

    gjovanovicst/golang-auth-api

    Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.

    129 GitHub stars~2.6k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Frontmcp Config

    agentfront/frontmcp

    A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

    146 GitHub stars~7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Centrifugo

    pedronauck/skills

    Centrifugo real-time messaging server expert for WebSocket PUB/SUB, channel management, JWT authentication, event proxying, and horizontal scaling with Redis/NATS.

    633 GitHub stars~3.1k tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed

More from secondsky/claude-skills

All 169 skills in this repo
  • Tanstack AI

    secondsky/claude-skills

    TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.

    227 GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check: notes
  • Auto Animate

    secondsky/claude-skills

    AutoAnimate (@formkit/auto-animate) zero-config animations for React.

    227 GitHub stars~2.9k tokensUpdated 9 days ago
    Auto-check passed
  • Base UI React

    secondsky/claude-skills

    MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Cloudflare Images

    secondsky/claude-skills

    This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…

    227 GitHub stars~3.6k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Nextjs

    secondsky/claude-skills

    Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).

    227 GitHub stars~5.3k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 9 days ago
    Auto-check passed

Works with

Categories

Questions about Session Management

What does Session Management do?

Implements secure session management with JWT tokens, Redis storage, refresh flows, and proper cookie configuration. Session Management is an agent skill from secondsky/claude-skills. Implements secure session management with JWT tokens, Redis storage, refresh flows, and proper cookie configuration.

When should I use Session Management?

Session Management fits situations like: building authentication systems; managing user sessions; implementing secure logout functionality.

How do I install Session Management in Claude Code?

Run `npx skills add secondsky/claude-skills --skill session-management -a claude-code`. Or copy the skill folder (plugins/session-management/skills/session-management in secondsky/claude-skills) into .claude/skills/session-management in your project. Claude Code loads it when a task matches its description.

How do I install Session Management in Codex?

Run `npx skills add secondsky/claude-skills --skill session-management -a codex`. Or copy the skill folder (plugins/session-management/skills/session-management in secondsky/claude-skills) into .agents/skills/session-management in your project. Codex loads it when a task matches its description.

Can I use Session Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill session-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/session-management, .gemini/skills/session-management, .github/skills/session-management and .opencode/skills/session-management in your project.

What does Session Management need to run?

Going by SKILL.md and its folder, Session Management needs credentials named REFRESH_SECRET, JWT_SECRET and SESSION_SECRET. Our summary lists: A credential in JWT_SECRET; A credential in REFRESH_SECRET.

Does Session Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Session Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Session Management use?

Session Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Session Management use?

About 651 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Session Management?

Skills that share tags, products or a category with Session Management: Cb Realtime API (BlkLeg/CircuitBreaker, 201 stars), Auth Flows (gjovanovicst/golang-auth-api, 129 stars), Project Map (gjovanovicst/golang-auth-api, 129 stars) and Frontmcp Config (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Session Management?

secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.

Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.