Better Auth Security Best Practices
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
Design frictionless signup experiences for developers including GitHub OAuth, API key generation, and onboarding personalization.
$ npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills developer-signup-flow --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/developer-signup-flow .claude/skills/developer-signup-flow && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "developer-signup-flow" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/developer-signup-flow into .claude/skills/developer-signup-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "developer-signup-flow", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/developer-signup-flowType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills developer-signup-flow --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/developer-signup-flow .agents/skills/developer-signup-flow && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "developer-signup-flow" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/developer-signup-flow into .agents/skills/developer-signup-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "developer-signup-flow", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills developer-signup-flow --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/developer-signup-flow .cursor/skills/developer-signup-flow && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "developer-signup-flow" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/developer-signup-flow into .cursor/skills/developer-signup-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "developer-signup-flow", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/developer-signup-flow--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills developer-signup-flow --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/developer-signup-flow .gemini/skills/developer-signup-flow && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "developer-signup-flow" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/developer-signup-flow into .gemini/skills/developer-signup-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "developer-signup-flow", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills developer-signup-flowInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/developer-signup-flow .github/skills/developer-signup-flow && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "developer-signup-flow" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/developer-signup-flow into .github/skills/developer-signup-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "developer-signup-flow", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills developer-signup-flow --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/developer-signup-flow .opencode/skills/developer-signup-flow && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "developer-signup-flow" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/developer-signup-flow into .opencode/skills/developer-signup-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "developer-signup-flow", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
developer-signup-flowDesign frictionless signup experiences for developers including GitHub OAuth, API key generation, and onboarding personalization.
Developer Signup Flow is an agent skill from sickn33/agentic-awesome-skills. Design frictionless signup experiences for developers including GitHub OAuth, API key generation, and onboarding personalization.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).
It sits in Backend & APIs, covering Conversion rate optimization and OAuth and OpenID Connect. It works with GitHub. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Developer Signup Flow loads about 3.1k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 1,381 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 1,381 words, ~3,121 tokens.
.claude/skills/developer-signup-flow/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill when you need design frictionless signup experiences for developers including GitHub OAuth, API key generation, and onboarding personalization. Trigger phrases: developer signup, dev registration, OAuth flow, API key onboarding, reduce signup friction, developer authentication, signup conversion,...
Create signup experiences that respect developers' time and get them to code as fast as possible.
Developer signup is your first chance to demonstrate that you understand developers. Every unnecessary form field, every extra click, every "verify your email before continuing" is a message that you don't value their time. The best developer signups feel like they barely exist—developers go from "I want to try this" to "I'm writing code" in under 60 seconds.
This skill covers OAuth integration, API key generation UX, progressive profiling, and measuring what actually matters in signup conversion.
Review the /devmarketing-skills/skills/developer-audience-context skill to understand your target developer segments. Signup optimization varies significantly based on whether you're targeting hobbyists exploring on weekends versus enterprise developers evaluating tools for their company.
For developer tools, GitHub OAuth should be your primary option. Here's why:
Good implementation (Vercel):
Bad implementation:
Prioritize based on your audience:
| Audience | Primary | Secondary | Avoid |
|---|---|---|---|
| Open source developers | GitHub | Google Workspace | |
| Startup developers | GitHub | Enterprise SSO | |
| Enterprise developers | SSO/SAML | Google Workspace | Social logins |
| Data scientists | GitHub | ||
| Mobile developers | GitHub |
Google OAuth works well when:
Google OAuth fails when:
Email+password signup should exist but not dominate. It serves:
If you support email signup:
The best signup has zero custom fields. Everything you need comes from OAuth:
If you genuinely need information, defer it:
Bad: Blocking signup
Create Account
- Email
- Password
- Company Name (required)
- Role (required)
- Team Size (required)
- How did you hear about us? (required)
[Create Account]Good: Progressive collection
Continue with GitHub
[Immediate dashboard access]
[Later, contextually in dashboard]
"To customize your experience, what are you building?"
[ ] API/Backend
[ ] Web app
[ ] Mobile app
[ ] Data pipeline
[Skip for now]For each field you want to add, answer:
Research suggests each additional required field reduces conversion by 5-10%.
Developers sign up to write code. Show them an API key immediately.
Good implementation (Stripe):
Bad implementation:
Your API Key
sk_test_xxxxxxxxxxxxxxxxxxxx [Copy]
[Show in cURL example] [Show in SDK example]Wait until developers need this. First-time signup should show one key.
Introduce key management when:
Ask one question, then customize the experience:
Question (shown post-signup, skippable): "What are you building?"
Path customization:
| Selection | Dashboard emphasis | First CTA | Docs default |
|---|---|---|---|
| Integrate existing | SDKs and integrations | "Install SDK" | Integration guides |
| Build new | Quickstart tutorial | "Start tutorial" | Getting started |
| Evaluate for team | Pricing and features | "Book demo" | Use cases |
| Just exploring | Interactive playground | "Try playground" | API reference |
If GitHub OAuth is used, check public repos for language patterns:
Primary language: Python (45% of repos)
Also uses: JavaScript (30%), Go (15%)
→ Show Python SDK first in docs
→ Default code examples to Python
→ Suggest Python quickstartAfter signup, track and adapt:
| Behavior | Adaptation |
|---|---|
| Copies HTTP request | Prefer HTTP examples over SDK-only flow |
| Views pricing page early | Surface free tier limits in dashboard |
| Creates multiple projects | Suggest team features |
| Frequent docs visits | Add "Stuck?" help widget |
Signup (OAuth only):
First session (optional, in-context):
After first API call:
After hitting free tier limits:
After upgrade:
Bad: Random popup
[Popup after 3 days]
Help us serve you better!
Company: ___
Role: ___
Team size: ___
How did you hear about us: ___Good: Contextual ask
[When developer invites first team member]
To set up your team workspace, what should we call it?
Company/Team name: ___
[When developer hits rate limit]
To increase your rate limit, we need to verify your account:
Phone: ___Signup start rate
Signup completion rate
Time to signup
API key copy rate
First API call rate
Time to first API call
Track the complete funnel:
Landing page visitors: 10,000
├── Clicked signup: 1,000 (10%)
├── Completed signup: 800 (80% of clicks)
├── Copied API key: 600 (75% of signups)
├── First API call: 300 (50% of key copies)
└── Second day return: 150 (50% of first call)Identify where developers drop off and why:
Test in this order (highest impact first):
/devmarketing-skills/skills/developer-onboarding - What happens after signup/devmarketing-skills/skills/developer-audience-context - Understanding who's signing up/devmarketing-skills/skills/free-tier-strategy - What they're signing up for© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/developer-signup-flow of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit 1e53ce2
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Developer Signup Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Developer Signup Flow this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| GitHub OAuth Nango IntegrationAgentWorkforce/relay | 865 | 1 repos | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| EmulateUsefulSoftwareCo/executor | 4.1k | — | ~2.2k | Automated safety check: Notes | MIT | |
| Nuget Trusted Publishingrodri-oliveira-dev/Dapper-FluentMap | 453 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Auth Setupbutterbase-ai/butterbase-skills | 534 | — | ~2.2k | Automated safety check: Pass | MIT |
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
AgentWorkforce/relay
A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling
UsefulSoftwareCo/executor
Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…
rodri-oliveira-dev/Dapper-FluentMap
Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.
butterbase-ai/butterbase-skills
A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys
rome-os/rome
Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Works with
Categories
Design frictionless signup experiences for developers including GitHub OAuth, API key generation, and onboarding personalization. Developer Signup Flow is an agent skill from sickn33/agentic-awesome-skills. Design frictionless signup experiences for developers including GitHub OAuth, API key generation, and onboarding personalization.
Developer Signup Flow fits situations like: tasks that involve Conversion rate optimization; tasks that involve OAuth and OpenID Connect.
Run `npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a claude-code`. Or copy the skill folder (skills/developer-signup-flow in sickn33/agentic-awesome-skills) into .claude/skills/developer-signup-flow in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a codex`. Or copy the skill folder (skills/developer-signup-flow in sickn33/agentic-awesome-skills) into .agents/skills/developer-signup-flow in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill developer-signup-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/developer-signup-flow, .gemini/skills/developer-signup-flow, .github/skills/developer-signup-flow and .opencode/skills/developer-signup-flow in your project.
SKILL.md names no scripts, command-line tools or credentials: Developer Signup Flow is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Developer Signup Flow is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Developer Signup Flow: Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 865 stars), Emulate (UsefulSoftwareCo/executor, 4.1k stars) and Nuget Trusted Publishing (rodri-oliveira-dev/Dapper-FluentMap, 453 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.