Official agent skill

Use Link Identity

by stripe in stripe/link-cli

Use Link CLI's identity commands when a service requests a Link Agent Attestation Token (AAT) or signed user claims such as email.

OfficialMITAuto-check passedProductivity & Automation

Install Use Link Identity

skills CLI
$ npx skills add stripe/link-cli --skill use-link-identity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install stripe/link-cli use-link-identity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/stripe/link-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/use-link-identity .claude/skills/use-link-identity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
use-link-identity
GitHub stars
841
Token cost
~1.5k tokens
SKILL.md length
576 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Use Link CLI's identity commands when a service requests a Link Agent Attestation Token (AAT) or signed user claims such as email.

  • Tasks that involve Browser automation
  • SKILL.md covers Setup and handling, Attestations, Credentials and presentations and Send and recover
  • Calls npm; reaches api.link.com

What it does

Use Link Identity is an agent skill from stripe/link-cli, published by the product's own GitHub organization. Use Link CLI's identity commands when a service requests a Link Agent Attestation Token (AAT) or signed user claims such as email. Covers acquiring and managing attestations, obtaining identity credentials, and presenting selected claims to a verifier through an HTTP client or browser automation.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Browser automation. It works with Stripe. The repository describes itself as: Let your agents spend on your behalf. Your payment credentials are never exposed. You approve every purchase. The licence is MIT.

When your agent uses it

  • Tasks that involve Browser automation

Example prompts

  • “/use-link-identity”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash(link-cli:*), Bash(npx --yes @stripe/link-cli:*), Bash(npm install -g @stripe/link-cli:*)

What it can do on your machine

Read from SKILL.md and the folder at commit 0569cc0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(link-cli:*)
    • Bash(npx --yes @stripe/link-cli:*)
    • Bash(npm install -g @stripe/link-cli:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.link.com

    Also links to:

    • link.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Use Link Identity loads about 1.5k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 576 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from stripe/link-cli at commit 0569cc0, republished under its MIT licence (© stripe). 576 words, ~1,512 tokens.

Download SKILL.mdSave it as .claude/skills/use-link-identity/SKILL.md (or your agent's skills folder).
name
use-link-identity
description
Use Link CLI's identity commands when a service requests a Link Agent Attestation Token (AAT) or signed user claims such as email. Covers acquiring and managing attestations, obtaining identity credentials, and presenting selected claims to a verifier through an HTTP client or browser automation.
allowed-tools
Bash(link-cli:*), Bash(npx --yes @stripe/link-cli:*), Bash(npm install -g @stripe/link-cli:*)
license
Complete terms at https://github.com/stripe/link-cli/blob/main/LICENSE
metadata.author
stripe
metadata.url
link.com/agents

These commands are in beta and appear in link-cli identity --help without a preview flag. Use them when a service accepts Link attestations or signed user claims.

Service requestsCommandJSON field → HTTP header
A Link Agent Attestation Token (AAT), often via WWW-Authenticate: PrivateTokenidentity attestations popauthorization → Authorization
Signed claims, often via WWW-Authenticate: Identity-Presentationidentity credentials presentpresentation → Identity-Presentation

An AAT proves issuance by Link without disclosing user claims. A presentation discloses selected claims and proves possession of the credential's holder key for an audience and nonce. If the service requires both, send both headers.

Setup and handling

Use Link Agent Wallet v0.27.0 or later. Check link-cli --version; if older or missing, install or update with npm install -g @stripe/link-cli@latest. No LINK_IDENTITY_COMMANDS flag is needed. See wallet setup; reuse the create-payment-credential skill's authentication guidance.

  • Identity commands are available through the CLI, not its MCP tools.
  • Only request needs Link authentication. list, pop, and present use local files. Requests return paths and metadata; pop and present return proofs.
  • Capture stdout with --format json, parse it programmatically with a JSON parser or jq, and pass the exact proof to the HTTP client or browser automation. Never manually transcribe, reconstruct, or re-encode tokens or presentations. Keep proofs, private keys, and claim values out of transcripts and logs; use restrictive permissions for handoff files.
  • Cached identity files belong to the home directory. Changing --auth or logging in as another user does not switch the cached identity. Use separate home directories for different users.

Attestations

bash
# Inspect inventory.
link-cli identity attestations list --format json

# Refill only when needed. Count is required: 1–100.
link-cli identity attestations request --count 10 --format json

# Pop a token when ready to use it.
link-cli identity attestations pop --format json

Check errors and attestations. Only entries with storage: "pool" are available to pop; total_token_count also includes exports. Requests append to ~/.link-cli/identity/attestations/pool.json.

Example pop output:

json
{
  "issuer": "https://api.link.com",
  "token_key_id": "<issuer-key-id>",
  "token": "<token>",
  "authorization": "PrivateToken token=\"<token-with-header-padding>\""
}

Use authorization verbatim, including its scheme and quoting. pop removes the token locally; server reuse rules belong to the service. Keep the same AAT for retries tied to an existing interaction, and use a fresh one for a new service. Do not return popped tokens to the pool.

For agent-managed allocation, export a batch instead:

bash
link-cli identity attestations request --count 10 --output-file ./aats.json --format json

Use a new file outside ~/.link-cli/identity/attestations. Read its tokens array and each entry's authorization programmatically. Exported tokens never enter the CLI pool; the caller owns allocation, concurrency, and cleanup.

Show full SKILL.md (215 more words)Show less

Credentials and presentations

bash
# Check errors, expired, expires_at, and claim_names.
link-cli identity credentials list --format json

# Request only if no usable credential exists for the intended user.
link-cli identity credentials request --format json

Issuance replaces ~/.link-cli/identity/credentials/current.json and creates or reuses ~/.link-cli/identity/holder-key.jwk. Keep both local. Choose claims with present:

bash
link-cli identity credentials present \
  --aud 'https://service.example' \
  --nonce '<nonce-from-challenge>' \
  --claim email \
  --format json

Use the service challenge's exact audience and nonce after checking that they belong to the intended service. All three options are required. Repeat --claim only for additional requested claims authorized by the user's task. Pass challenge values as individual process arguments or quote them safely in a shell.

Example output:

json
{"presentation":"<issuer-jwt>~<email-disclosure>~<key-binding-jwt>"}

present signs locally with the saved holder key and leaves the files unchanged. Send the presentation promptly. Reuse the underlying credential until expiry, but obtain a fresh challenge after a nonce is consumed or expires.

Send and recover

Set headers only for the intended endpoint. Preserve the challenged operation's method, body, session, interaction identifiers, and any required AAT. Avoid global browser headers or redirects that forward proofs to another origin. Report success only after the service accepts the request.

  • ATTESTATION_POOL_EMPTY: request a batch, then pop a token.
  • Errors in list: inspect the reported file/error instead of treating storage as empty.
  • Unavailable claim: check claim_names; do not disclose extra claims or the raw credential.
  • Missing or mismatched holder key: preserve the files and restore the correct key or explicitly obtain a new credential.
  • Audience or nonce rejection: check the intended service and its current challenge before presenting again.

© stripe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/use-link-identity of stripe/link-cli.

Open the folder on GitHubat commit 0569cc0

Compare with similar skills

Use Link Identity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Use Link Identity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Use Link Identity this skillstripe/link-cli841—~1.5kAutomated safety check: PassMIT
Agent Browserquran/quran.com-frontend-next1.9k40 repos~3.3kAutomated safety check: PassNone
Dev-Browser CLI AutomationSawyerHood/dev-browser6.7k1 repos~455Automated safety check: PassMIT
Browser Automationopenclaw/openclaw392k—~2.9kAutomated safety check: PassMIT
Camoufox CLIBin-Huang/camoufox-cli3501 repos~4.5kAutomated safety check: PassMIT
BrowserVibiumDev/vibium2.9k—~4.8kAutomated safety check: PassApache-2.0

Similar skills

  • Agent Browser

    quran/quran.com-frontend-next

    Automates browser interactions for web testing, form filling, screenshots, and data extraction.

    1.9k GitHub starsUsed in 40 repos~3.3k tokens
    Productivity & AutomationAuto-check passed
  • Dev-Browser CLI Automation

    SawyerHood/dev-browser

    Browser automation with persistent named pages via the dev-browser CLI. Use when users ask to navigate websites, fill forms, take screenshots, extract web…

    6.7k GitHub starsUsed in 1 repo~455 tokens
    Productivity & AutomationAuto-check passed
  • Browser Automation

    openclaw/openclaw

    A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.

    392k GitHub stars~2.9k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Camoufox CLI

    Bin-Huang/camoufox-cli

    Anti-detect browser automation CLI & Skills for AI agents. An agent skill from Bin-Huang/camoufox-cli.

    350 GitHub starsUsed in 1 repo~4.5k tokens
    Productivity & AutomationAuto-check passed
  • Browser

    VibiumDev/vibium

    Automate browsers with the Vibium CLI. An agent skill from VibiumDev/vibium.

    2.9k GitHub stars~4.8k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Test AIRI display-model imports with agent-browser across stage-tamagotchi Electron, stage-web, and stage-pocket mobile web layouts.

    50k GitHub stars~1.1k tokensUpdated today
    Productivity & AutomationAuto-check passed

More from stripe/link-cli

  • Financial Insights

    stripe/link-cli

    Official

    Reads a user's Link financial data — transactions, balances, and wallet sources — so agents can answer questions about spending and available source capabilities.

    841 GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Official

    Creates and manages Link spend requests and retrieves approved one-time-use payment credentials.

    841 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Official

    Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users.

    841 GitHub starsUsed in 1 repo~8.9k tokens
    Auto-check passed
  • Financial Insights

    stripe/link-cli

    Official

    Reads a user's Link transactions, balances, financial sources, and precomputed insights to answer questions about spending, available funds, connected accounts, and account activity.

    841 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Check Link Wallet

    stripe/link-cli

    Official

    Reads the connected Link account, the cards and bank accounts saved in its wallet, its saved shipping addresses, and the status of existing spend requests.

    841 GitHub stars~683 tokensUpdated today
    Auto-check passed
  • Complete Link Purchase

    stripe/link-cli

    Official

    Buys something on a merchant site with a Link wallet by asking the user to authorize a one-time virtual card, then retrieving the credential and entering it at checkout.

    841 GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Use Link Identity

What does Use Link Identity do?

Use Link CLI's identity commands when a service requests a Link Agent Attestation Token (AAT) or signed user claims such as email. Use Link Identity is an agent skill from stripe/link-cli, published by the product's own GitHub organization. Use Link CLI's identity commands when a service requests a Link Agent Attestation Token (AAT) or signed user claims such as email.

When should I use Use Link Identity?

Use Link Identity fits situations like: tasks that involve Browser automation.

How do I install Use Link Identity in Claude Code?

Run `npx skills add stripe/link-cli --skill use-link-identity -a claude-code`. Or copy the skill folder (skills/use-link-identity in stripe/link-cli) into .claude/skills/use-link-identity in your project. Claude Code loads it when a task matches its description.

How do I install Use Link Identity in Codex?

Run `npx skills add stripe/link-cli --skill use-link-identity -a codex`. Or copy the skill folder (skills/use-link-identity in stripe/link-cli) into .agents/skills/use-link-identity in your project. Codex loads it when a task matches its description.

Can I use Use Link Identity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add stripe/link-cli --skill use-link-identity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/use-link-identity, .gemini/skills/use-link-identity, .github/skills/use-link-identity and .opencode/skills/use-link-identity in your project.

What does Use Link Identity need to run?

Going by SKILL.md and its folder, Use Link Identity needs the command-line tools its instructions call (npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(link-cli:*), Bash(npx --yes @stripe/link-cli:*), Bash(npm install -g @stripe/link-cli:*).

Does Use Link Identity access the network?

SKILL.md names 2 domains. In commands or code: api.link.com; the agent is likely to contact it when it follows the instructions. As links in the text: link.com. This is read from the text; nothing was executed.

Is Use Link Identity safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Use Link Identity use?

Use Link Identity is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Use Link Identity use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Use Link Identity?

Skills that share tags, products or a category with Use Link Identity: Agent Browser (quran/quran.com-frontend-next, 1.9k stars), Dev-Browser CLI Automation (SawyerHood/dev-browser, 6.7k stars), Browser Automation (openclaw/openclaw, 392k stars) and Camoufox CLI (Bin-Huang/camoufox-cli, 350 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Use Link Identity?

stripe (a GitHub organization, an official publisher) maintains it in stripe/link-cli, which has 841 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 10, 2026.

Source: stripe/link-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.