Add authentication to a web application using NextAuth.js (Auth.js), including OAuth providers, session management, and protected routes.

CC0-1.0Auto-check: notesBackend & APIs

Install Adding Auth

skills CLI
$ npx skills add spencerpauly/awesome-cursor-skills --skill adding-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spencerpauly/awesome-cursor-skills adding-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spencerpauly/awesome-cursor-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/adding-auth .claude/skills/adding-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
adding-auth
GitHub stars
842
Token cost
~557 tokens
SKILL.md length
160 words
Files
1
Skills in repo
57
Repo updated
First seen
Licence
CC0-1.0

At a glance

Add authentication to a web application using NextAuth.js (Auth.js), including OAuth providers, session management, and protected routes.

  • Works in 8 steps: Install dependencies → Generate an auth secret → Create the auth config — create auth.ts… → …
  • Tasks that involve Authentication
  • SKILL.md covers Steps and Notes
  • Calls npm and npx; needs AUTH_SECRET and AUTH_GITHUB_SECRET

What it does

Adding Auth is an agent skill from spencerpauly/awesome-cursor-skills. Add authentication to a web application using NextAuth.js (Auth.js), including OAuth providers, session management, and protected routes.

Its SKILL.md is about 560 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. The repository describes itself as: A curated list of awesome skills for Cursor. The licence is CC0-1.0.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/adding-auth”

Requirements

  • Node.js
  • A credential in AUTH_SECRET
  • A credential in AUTH_GITHUB_SECRET

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Install dependencies
  2. Generate an auth secret
  3. Create the auth config — create auth.ts in the project root
  4. Add the route handler — create app/api/auth/[...nextauth]/route.ts
  5. Add environment variables for each provider
  6. Add sign-in/sign-out UI — create components that call the signIn and signOut server actions, or use .
  7. Protect routes — use the auth() function in server components or middleware
  8. Add database adapter (optional) — if the user needs persistent sessions or user records, install a database adapter (e.g…

What it can do on your machine

Read from SKILL.md and the folder at commit 99cd265. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AUTH_SECRET
    • AUTH_GITHUB_SECRET
    • AUTH_GOOGLE_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Adding Auth loads about 557 tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 160 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~557

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:24
    This adds `AUTH_SECRET` to `.env.local`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spencerpauly/awesome-cursor-skills at commit 99cd265, republished under its CC0-1.0 licence (© spencerpauly). 160 words, ~557 tokens.

Download SKILL.mdSave it as .claude/skills/adding-auth/SKILL.md (or your agent's skills folder).
name
adding-auth
description
Add authentication to a web application using NextAuth.js (Auth.js), including OAuth providers, session management, and protected routes.

Add Authentication (Auth.js)

Use this skill when the user asks to add authentication, login, sign-up, OAuth, or session management.

Steps

  1. Install dependencies

    bash
    npm install next-auth@beta
  2. Generate an auth secret

    bash
    npx auth secret

    This adds AUTH_SECRET to .env.local.

  3. Create the auth config — create auth.ts in the project root:

    ts
    import NextAuth from "next-auth";
    import GitHub from "next-auth/providers/github";
    import Google from "next-auth/providers/google";
    
    export const { handlers, signIn, signOut, auth } = NextAuth({
      providers: [GitHub, Google],
    });
  4. Add the route handler — create app/api/auth/[...nextauth]/route.ts:

    ts
    import { handlers } from "@/auth";
    export const { GET, POST } = handlers;
  5. Add environment variables for each provider:

    AUTH_SECRET=...
    AUTH_GITHUB_ID=...
    AUTH_GITHUB_SECRET=...
    AUTH_GOOGLE_ID=...
    AUTH_GOOGLE_SECRET=...
  6. Add sign-in/sign-out UI — create components that call the signIn and signOut server actions, or use <Link href="/api/auth/signin">.

  7. Protect routes — use the auth() function in server components or middleware:

    ts
    import { auth } from "@/auth";
    
    export default async function ProtectedPage() {
      const session = await auth();
      if (!session) redirect("/api/auth/signin");
      return <div>Welcome {session.user?.name}</div>;
    }
  8. Add database adapter (optional) — if the user needs persistent sessions or user records, install a database adapter (e.g. @auth/drizzle-adapter, @auth/prisma-adapter) and configure it in the auth config.

Notes

  • Auth.js v5 works with Next.js App Router and Server Actions natively.
  • For Pages Router, use getServerSession in getServerSideProps and useSession on the client.
  • Add NEXTAUTH_URL for production deployments.
  • Store minimal user data in the session; fetch full profiles from the database when needed.

© spencerpauly, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in resources/adding-auth of spencerpauly/awesome-cursor-skills.

Open the folder on GitHubat commit 99cd265

Compare with similar skills

Adding Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Adding Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Adding Auth this skillspencerpauly/awesome-cursor-skills842—~557Automated safety check: NotesCC0-1.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
OAuth Account Setupspinabot/brigade11k—~878Automated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61710 repos~4.4kAutomated safety check: PassNone

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • OAuth Account Setup

    spinabot/brigade

    Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.

    11k GitHub stars~878 tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from spencerpauly/awesome-cursor-skills

All 57 skills in this repo
  • Babysitting PR

    spencerpauly/awesome-cursor-skills

    Monitor a pull request for CI failures, review comments, and merge conflicts — then fix them automatically.

    842 GitHub stars~930 tokensUpdated 2 mo ago
    Auto-check passed
  • Best Of N Solving

    spencerpauly/awesome-cursor-skills

    Solve a hard problem by trying multiple approaches in parallel using isolated git worktrees.

    842 GitHub stars~698 tokensUpdated 2 mo ago
    Auto-check passed
  • Grinding Until Pass

    spencerpauly/awesome-cursor-skills

    Keep iterating on code changes until the tests pass, the build succeeds, or linting is clean.

    842 GitHub stars~796 tokensUpdated 2 mo ago
    Auto-check passed
  • Parallel CI Triage

    spencerpauly/awesome-cursor-skills

    When GitHub Actions fails, fetch failing job logs and assign each failing job to a separate subagent that fixes its slice of the problem in parallel.

    842 GitHub stars~793 tokensUpdated 2 mo ago
    Auto-check passed
  • Parallel Exploring

    spencerpauly/awesome-cursor-skills

    Explore a large codebase in parallel by launching multiple explore subagents that each investigate a different area simultaneously.

    842 GitHub stars~787 tokensUpdated 2 mo ago
    Auto-check: notes
  • Profiling Performance

    spencerpauly/awesome-cursor-skills

    Profile a running web application's CPU performance using Cursor's built-in browser profiler.

    842 GitHub stars~686 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Adding Auth

What does Adding Auth do?

Add authentication to a web application using NextAuth.js (Auth.js), including OAuth providers, session management, and protected routes. Adding Auth is an agent skill from spencerpauly/awesome-cursor-skills.js), including OAuth providers, session management, and protected routes.

When should I use Adding Auth?

Adding Auth fits situations like: tasks that involve Authentication; tasks that involve OAuth and OpenID Connect.

How do I install Adding Auth in Claude Code?

Run `npx skills add spencerpauly/awesome-cursor-skills --skill adding-auth -a claude-code`. Or copy the skill folder (resources/adding-auth in spencerpauly/awesome-cursor-skills) into .claude/skills/adding-auth in your project. Claude Code loads it when a task matches its description.

How do I install Adding Auth in Codex?

Run `npx skills add spencerpauly/awesome-cursor-skills --skill adding-auth -a codex`. Or copy the skill folder (resources/adding-auth in spencerpauly/awesome-cursor-skills) into .agents/skills/adding-auth in your project. Codex loads it when a task matches its description.

Can I use Adding Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spencerpauly/awesome-cursor-skills --skill adding-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/adding-auth, .gemini/skills/adding-auth, .github/skills/adding-auth and .opencode/skills/adding-auth in your project.

What does Adding Auth need to run?

Going by SKILL.md and its folder, Adding Auth needs the command-line tools its instructions call (npm and npx) and credentials named AUTH_SECRET, AUTH_GITHUB_SECRET and AUTH_GOOGLE_SECRET. Our summary lists: Node.js; A credential in AUTH_SECRET; A credential in AUTH_GITHUB_SECRET.

Does Adding Auth access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Adding Auth safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Adding Auth use?

Adding Auth is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Adding Auth use?

About 557 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Adding Auth?

Skills that share tags, products or a category with Adding Auth: Fortify Development (coollabsio/coolify, 63k stars), Security Review (doorkeeper-gem/doorkeeper, 5.5k stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars) and OAuth Account Setup (spinabot/brigade, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Adding Auth?

spencerpauly (a GitHub user) maintains it in spencerpauly/awesome-cursor-skills, which has 842 GitHub stars. The repository holds 57 skills in this directory. The repository was last updated on August 2, 2026.

Source: spencerpauly/awesome-cursor-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.