Ee Feature
rhesis-ai/rhesis
Add a new Enterprise Edition feature behind a feature gate, across backend and frontend.
CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit auth-web-cloudbase --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/config/source/skills/auth-web-cloudbase .claude/skills/auth-web-cloudbase && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auth-web-cloudbase" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/auth-web-cloudbase into .claude/skills/auth-web-cloudbase/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-web-cloudbase", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/auth-web-cloudbaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit auth-web-cloudbase --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/config/source/skills/auth-web-cloudbase .agents/skills/auth-web-cloudbase && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auth-web-cloudbase" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/auth-web-cloudbase into .agents/skills/auth-web-cloudbase/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-web-cloudbase", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit auth-web-cloudbase --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/config/source/skills/auth-web-cloudbase .cursor/skills/auth-web-cloudbase && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auth-web-cloudbase" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/auth-web-cloudbase into .cursor/skills/auth-web-cloudbase/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-web-cloudbase", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git --path config/source/skills/auth-web-cloudbase--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit auth-web-cloudbase --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/config/source/skills/auth-web-cloudbase .gemini/skills/auth-web-cloudbase && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auth-web-cloudbase" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/auth-web-cloudbase into .gemini/skills/auth-web-cloudbase/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-web-cloudbase", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit auth-web-cloudbaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/config/source/skills/auth-web-cloudbase .github/skills/auth-web-cloudbase && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auth-web-cloudbase" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/auth-web-cloudbase into .github/skills/auth-web-cloudbase/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-web-cloudbase", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit auth-web-cloudbase --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/config/source/skills/auth-web-cloudbase .opencode/skills/auth-web-cloudbase && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auth-web-cloudbase" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/auth-web-cloudbase into .opencode/skills/auth-web-cloudbase/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-web-cloudbase", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auth-web-cloudbaseCloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked.
Auth Web Cloudbase is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and practical Web authentication solutions with multiple login methods and complete user management.
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/extended-guide.md`).
It sits in Backend & APIs, covering Authentication. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.
Read from SKILL.md and the folder at commit ea2c202. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
tcb.cloud.tencent.comAlso links to:
docs.cloudbase.netFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
VITE_PUBLISHABLE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auth Web Cloudbase loads about 4.4k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 1,839 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
retrieval, write the publishable key to `.env.local` as `VITE_PUBLISHABLE_KEY` (create the file if missing) and read itAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit ea2c202, republished under its MIT licence (© TencentCloudBase). 1,839 words, ~4,390 tokens.
.claude/skills/auth-web-cloudbase/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Sibling CloudBase skills ship beside this skill. Use local relative paths such as ../auth-tool-cloudbase/SKILL.md.
If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do not HTTP-fetch remote skill or protocol markdown into the agent context.
@cloudbase/js-sdk and the auth provider setup has already been checked.auth-tool-cloudbase first to ensure providers are enabled, then return here for frontend integration.../auth-tool-cloudbase/SKILL.md for provider setup../web-development/SKILL.md for Web project structure and deploymentauth-tool-cloudbase before auth-web-cloudbase.Skipping publishable key and provider checks.
Replacing built-in Web auth with cloud function login logic.
Reusing this flow in Flutter, React Native, or native iOS/Android code.
Creating a detached helper file with auth.signUp / verifyOtp but never wiring it into the existing form handlers, so the actual button clicks still do nothing.
Using signInWithEmailAndPassword or signUpWithEmailAndPassword for username-style accounts such as admin and editor.
Keeping the login or register account input as type="email" when the task explicitly says the account identifier is a plain username string.
Starting implementation before calling queryAppAuth(action="getLoginConfig") and enabling usernamePassword when it is still off.
Writing auth.signInWithPassword(...) or auth.signUp(...) code without first confirming the provider is enabled via MCP. Before writing any sign-in or sign-up code in the browser, call queryAppAuth(action="listProviders") to verify the target provider (e.g. email, phone, usernamePassword) has On: "TRUE". For email-based sign-up (auth.signUp({ email, password })), additionally confirm SMTP is configured — otherwise the provider may throw "provider email not found" or similar errors. For username/password login, use auth.signInWithPassword({ username, password }); registration is best done through the management API (manageAppAuth(action="createUser")) or by confirming email provider readiness first.
Treating auth.getUser() or deprecated auth.getLoginState() as proof of real login. When the SDK is initialized with accessKey, the deprecated getLoginState() may still return an object with a valid uid even without any login — causing route guards that check !!loginState or !!uid to incorrectly pass. That misleading uid is not a gateway-authenticated session. Use auth.getSession() instead: it returns data.session === undefined when no real login has occurred. Only !!data.session from getSession() is a reliable authentication check.
Assuming publishable accessKey alone is enough for NoSQL CRUD. NoSQL app.database() get / add / update / watch requires a gateway-authenticated session: use a real login (password / OTP / OAuth). Anonymous login is a demo-only escape hatch for explicitly-public, non-user data — it is disabled by default, denied AI model permissions, and must never stand in for real auth in user-scoped apps. Skipping any login yields gateway 401. checkLogin() / getSession() alone do not create a usable write session.
Copying old CloudBase auth snippets from training data. Do not use auth.getLoginState(), auth.hasLoginState(), auth.getCurrentUser(), or auth.toDefaultLoginPage() as the default Web flow. Use the Web SDK v3 auth methods in this file and provider readiness from auth-tool-cloudbase.
Calling a standalone auth.verifyOtp({ token }) for OTP login. CloudBase Web SDK v3 returns verifyOtp as a callback on the signInWithOtp / signUp result: send the code first, keep the returned data, then call data.verifyOtp({ token }). A standalone auth.verifyOtp({ token }) without messageId fails with "messageId is required" — seeing that error means the callback form was skipped. See references/extended-guide.md for the full send → save callback → verify flow.
Note: anonymous login is disabled by default for new environments and inactive existing environments. Do not enable it to work around permission errors — enable via auth-tool-cloudbase only when the app explicitly serves public non-user data (e.g. NoSQL read-only demos). Always use auth.getSession() for auth guards.
Prerequisites: CloudBase environment ID (env)
Prerequisites: CloudBase environment Region (region)
Use Case: Web frontend projects using @cloudbase/js-sdk@latest for user authentication
Key Benefits: Supabase-compatible Auth API — all methods return { data, error }, supports phone, email, anonymous (disabled by default), username/password, OAuth, and third-party login methods
📌 Supabase API Compatibility: CloudBase Web SDK v3 auth module is designed with Supabase-like API ergonomics. If you are familiar with
supabase-jsauth patterns, the same mental model applies:
- All methods return
Promise<{ data, error }>— always checkerrorfirstsignInWithPassword,signInWithOtp,signUp,signOut,getSession,getUserfollow the same naming as SupabaseonAuthStateChange(callback)provides reactive auth state observation (events:INITIAL_SESSION,SIGNED_IN,SIGNED_OUT,TOKEN_REFRESHED,USER_UPDATED,PASSWORD_RECOVERY,BIND_IDENTITY)- Session management via
getSession()/refreshSession()/setSession()mirrors Supabase patternsKey differences from Supabase:
- OTP verification: Supabase uses a standalone
auth.verifyOtp({ phone, token, type })call; CloudBase returnsverifyOtpas a callback ondata— calldata.verifyOtp({ token })from thesignInWithOtp/signUpresultaccessKeyreplaces Supabase'sanonKey; environment usesenv+regioninstead of Supabase'surlsignInWithIdTokenfor direct third-party token login (similar to Supabase's same-named method)
Use npm installation for modern Web projects. In React, Vue, Vite, and other bundler-based apps, install and import @cloudbase/js-sdk from the project dependencies instead of using a CDN script.
auth-tool-cloudbase to check app-side auth readiness via queryAppAuth / manageAppAuth, then get the publishable key and configure login methods.queryAppAuth(action="getPublishableKey"). If it is empty, call manageAppAuth(action="ensurePublishableKey") first — new environments may not have one provisioned, and skipping this step leaves the frontend without a data-plane credential, surfacing later as gateway auth failures instead of an obvious missing-key error..env.local as VITE_PUBLISHABLE_KEY (create the file if missing) and read it in client code via import.meta.env.VITE_PUBLISHABLE_KEY. Never hardcode the key into source files, and never ask the user to fetch it from the console — fall back to the console link below only if both MCP calls fail.auth-tool-cloudbase failed, let user go to https://tcb.cloud.tencent.com/dev?envId={env}#/env/apikey to get publishable key and https://tcb.cloud.tencent.com/dev?envId={env}#/identity/login-manage to set up login methodsloginMethods.usernamePassword === true from queryAppAuth(action="getLoginConfig"). If it is false, enable it with manageAppAuth(action="patchLoginStrategy", patch={ usernamePassword: true }) before wiring frontend auth code.queryEnv(action="list", alias=..., aliasExact=true) first and use the returned canonical full EnvId for SDK init, console links, and generated config. Do not pass alias-like short forms directly into cloudbase.init({ env }).supabase-js auth example is valid unchanged”queryAppAuth / manageAppAuth returns sdkStyle: "supabase-like" and sdkHints, follow those method and parameter hints firstauth.signInWithOtp({ phone }) and auth.signUp({ phone }) use the phone number in a phone field, not phone_numberauth.signInWithOtp({ email }) and auth.signUp({ email }) use emailauth.signInWithPassword({ username, password }) is the canonical Web login path for username/password accountsauth.signUp({ username, password }) as conditional. Verify sdkHints and the installed SDK first; some versions only support signUp for OTP/provider-token flows and will not create username/password users.admin, editor, or another plain string without @, treat it as a username-style identifier rather than an email addressdata.verifyOtp({ token }) — the verifyOtp callback on the signInWithOtp / signUp result data — expects the SMS or email code in token; do not invent a standalone auth.verifyOtp({ token }) call, which additionally requires messageIdaccessKey is the publishable key from queryAppAuth / manageAppAuth via auth-tool-cloudbase, not a secret keyaccessKey alone does not create a gateway-authenticated session. Publishable accessKey initializes the SDK; it does not replace a login for NoSQL CRUD. Any app.database() get / add / update / watch needs a session — prefer a real login (password / OTP / OAuth); signInAnonymously() only for explicitly-public demo data (disabled by default, denied AI model permissions). Otherwise the gateway returns 401. Separately: the deprecated auth.getLoginState() may still return a misleading uid without login; use auth.getSession() for route guards (data.session === undefined when not logged in). checkLogin() / getSession() alone do not create a usable write session.accessKey to envId, a username, or any placeholder string. If you do not have a real Publishable Key yet, do not fabricate one.auth-tool-cloudbase before writing frontend codeSDK init reference: docs.cloudbase.net/api-reference/webv3/initialization.md(URL 加 .md 可取 raw markdown 原文)
// npm install @cloudbase/js-sdk
import cloudbase from '@cloudbase/js-sdk'
const app = cloudbase.init({
env: 'your-full-env-id', // Canonical full CloudBase environment ID resolved from queryEnv or the console, not an alias or shorthand
region: 'ap-shanghai', // CloudBase environment Region, default 'ap-shanghai'
accessKey: 'publishable key', // required, get from auth-tool-cloudbase
// ⚠️ accessKey alone ≠ a login session. NoSQL CRUD needs a session —
// real login preferred; signInAnonymously() only for public demo data.
// Use auth.getSession() for route guards; deprecated getLoginState()
// may return a misleading uid without a real session.
auth: { detectSessionInUrl: true }, // required
})
const auth = app.auth
// NoSQL app.database() CRUD requires a session (js-sdk 3.x + publishable key).
// Real login (see cookbook). Anonymous, only for public non-user demos:
// const { error } = await auth.signInAnonymously()
// if (error) throw errorIf the current task has not retrieved a real Publishable Key, omit accessKey instead of inventing one. A wrong accessKey can break auth-state checks and protected-route behavior.
Every method returns the unified shape { data, error } — branch on error first and surface error.message. The auth API is identical in traditional and PG environments. Source: official auth docs(raw markdown, cross-check snippets there when in doubt).
Default auth UI contract: when the user asks for 登录/注册/账号体系/user system without restricting the method, the login page must make ALL of these reachable (tabs or separate forms): password sign-in, OTP sign-in, verified sign-up (code + password), and forgot-password (whenever password sign-in exists). Never ship OTP-only or password-only UI unless explicitly asked. Never reveal whether an identifier is already registered in user-facing copy — route existing users to login with neutral wording.
Password sign-in (username-style or email identifiers both go here):
const { data, error } = await auth.signInWithPassword({ username, password })
// email accounts: auth.signInWithPassword({ email, password })
if (error) { /* show error.message */ } else { /* data.user */ }Anonymous sign-in — demo-only, not a default. NoSQL app.database() CRUD needs some session (PG anon reads work with accessKey alone). Prefer a real login; reach for anonymous ONLY when the app explicitly serves public non-user data and the user accepts the trade-off — it is disabled by default, denied AI model permissions, and its uid must never own user-scoped rows:
const { error } = await auth.signInAnonymously()Registration — verification code is MANDATORY. There is no password-only signup: signUp itself sends a code, and data.verifyOtp must complete it. Smart flow: existing identifier → plain login; new identifier → register + auto-login. Phone/SMS is 上海地域 only — prefer email:
const { data, error } = await auth.signUp({ email, password }) // or { phone, password }
if (error) throw error
// user types the code from their inbox...
const { data: login, error: verifyErr } = await data.verifyOtp({ token: code })
// login.user / login.session — signed in on both pathsOTP sign-in (no password) — same shape as signUp, auto-creates the user by default (shouldCreateUser: false to refuse unknown users). Requires 邮箱/短信验证码登录 enabled in console → 身份认证/登录方式:
const { data, error } = await auth.signInWithOtp({ email }) // or { phone }
const { data: login, error: verifyErr } = await data.verifyOtp({ token: code })Forgot password — email code → set new password → auto sign-in (emits PASSWORD_RECOVERY):
const { data, error } = await auth.resetPasswordForEmail(email)
if (error) throw error
const { data: login, error: resetErr } = await data.updateUser({ nonce: code, password: newPassword })OTP closure vs standalone verifyOtp — do not mix. The data.verifyOtp returned by signUp / signInWithOtp / resetPasswordForEmail has the message ID bound (pass only { token }). The standalone auth.verifyOtp(...) requires messageId and only logs in — it never registers. Always use the returned closure.
Session check / route guard — always getSession(), never the deprecated getLoginState():
const { data } = await auth.getSession()
const session = data?.session // undefined === not logged inAuth state listener (wire this once at app bootstrap):
auth.onAuthStateChange((event, session) => {
// event: INITIAL_SESSION | SIGNED_IN | SIGNED_OUT | PASSWORD_RECOVERY
// | TOKEN_REFRESHED | USER_UPDATED | BIND_IDENTITY
})Sign out:
const { error } = await auth.signOut()Mandatory auth gate before user-scoped data. Before reading/writing user-owned PG rows or Storage objects, check the session and show login when absent — never "fix" data errors by silently calling signInAnonymously:
const { data } = await auth.getSession()
if (!data?.session) { navigate('/login'); return }Completion Bar — before calling the auth task done, the generated source must have ALL of:
signInWithPassword (when password login is part of the UI)signUp + data.verifyOtp and/or signInWithOtponAuthStateChange wired at bootstrap (route guard reacts to SIGNED_OUT)error.message, no invented error textsignInAnonymously as a fallback for permission errors, no mock/localStorage sessionsFor detailed scenarios, examples, and patterns, read extended-guide.md.
All packaged reference files (required for skill lint reachability):
© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in config/source/skills/auth-web-cloudbase of TencentCloudBase/CloudBase-AI-Toolkit.
Open the folder on GitHubat commit ea2c202
We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in TencentCloudBase/CloudBase-AI-Toolkit, which our catalogue first saw on October 7, 2026.
Auth Web Cloudbase next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auth Web Cloudbase this skillTencentCloudBase/CloudBase-AI-Toolkit | 1.1k | 2 repos | ~4.4k | Automated safety check: Notes | MIT | |
| Ee Featurerhesis-ai/rhesis | 396 | — | ~398 | Automated safety check: Pass | Custom licence | |
| Configuration Authentication Cross Devicegreenpau/caddy-security | 2.3k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Loginthedaviddias/ux-patterns-for-developers | 258 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Auth Web CloudbaseLeoYeAI/openclaw-master-skills | 2.2k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Gating Sensitive ActionsPostHog/posthog-foss | 721 | — | ~2.3k | Automated safety check: Notes | MIT |
rhesis-ai/rhesis
Add a new Enterprise Edition feature behind a feature gate, across backend and frontend.
greenpau/caddy-security
Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy.
thedaviddias/ux-patterns-for-developers
A skill your agent uses when implementing user authentication and sign-in forms.
LeoYeAI/openclaw-master-skills
CloudBase Web Authentication Quick Guide - Provides concise and practical Web frontend authentication solutions with multiple login methods and complete user management.
PostHog/posthog-foss
A skill your agent uses when deciding whether an endpoint, settings section, or UI flow should require recent authentication (re-auth), when adding TimeSensitiveActionPermission or its exemptions…
gdarko/laravel-vue-starter
Activate when creating or modifying Vue 3 components, pages, layouts, stores, or services in the frontend.
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.
TencentCloudBase/CloudBase-AI-Toolkit
CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.
TencentCloudBase/CloudBase-AI-Toolkit
Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).
TencentCloudBase/CloudBase-AI-Toolkit
Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.
TencentCloudBase/CloudBase-AI-Toolkit
Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…
Categories
CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Auth Web Cloudbase is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked.
Auth Web Cloudbase fits situations like: tasks that involve Authentication.
Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a claude-code`. Or copy the skill folder (config/source/skills/auth-web-cloudbase in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/auth-web-cloudbase in your project. Claude Code loads it when a task matches its description.
Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a codex`. Or copy the skill folder (config/source/skills/auth-web-cloudbase in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/auth-web-cloudbase in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill auth-web-cloudbase -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth-web-cloudbase, .gemini/skills/auth-web-cloudbase, .github/skills/auth-web-cloudbase and .opencode/skills/auth-web-cloudbase in your project.
Going by SKILL.md and its folder, Auth Web Cloudbase needs credentials named VITE_PUBLISHABLE_KEY. Our summary lists: Node.js; A credential in VITE_PUBLISHABLE_KEY.
SKILL.md names 2 domains. In commands or code: tcb.cloud.tencent.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.cloudbase.net. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Auth Web Cloudbase is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Auth Web Cloudbase: Ee Feature (rhesis-ai/rhesis, 396 stars), Configuration Authentication Cross Device (greenpau/caddy-security, 2.3k stars), Login (thedaviddias/ux-patterns-for-developers, 258 stars) and Auth Web Cloudbase (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,132 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 6, 2026.
Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.