Billing SDK
hashgraph-online/awesome-codex-plugins
BillingSDK, the open-source React and shadcn component library for Dodo Payments billing UI.
Wire Supabase Auth into this Next.js 16 app with @supabase/ssr — browser/server clients, the proxy.ts session refresh (Next 16 renamed middleware), getClaims vs getSession, protected routes and…
$ npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install textura-agency/next16-claude-starter supabase-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/textura-agency/next16-claude-starter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/supabase-auth .claude/skills/supabase-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "supabase-auth" agent skill from https://github.com/textura-agency/next16-claude-starter/tree/main/.claude/skills/supabase-auth into .claude/skills/supabase-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/textura-agency/next16-claude-starter/tree/main/.claude/skills/supabase-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install textura-agency/next16-claude-starter supabase-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/textura-agency/next16-claude-starter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/supabase-auth .agents/skills/supabase-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "supabase-auth" agent skill from https://github.com/textura-agency/next16-claude-starter/tree/main/.claude/skills/supabase-auth into .agents/skills/supabase-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install textura-agency/next16-claude-starter supabase-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/textura-agency/next16-claude-starter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/supabase-auth .cursor/skills/supabase-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "supabase-auth" agent skill from https://github.com/textura-agency/next16-claude-starter/tree/main/.claude/skills/supabase-auth into .cursor/skills/supabase-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/textura-agency/next16-claude-starter.git --path .claude/skills/supabase-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install textura-agency/next16-claude-starter supabase-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/textura-agency/next16-claude-starter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/supabase-auth .gemini/skills/supabase-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "supabase-auth" agent skill from https://github.com/textura-agency/next16-claude-starter/tree/main/.claude/skills/supabase-auth into .gemini/skills/supabase-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install textura-agency/next16-claude-starter supabase-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/textura-agency/next16-claude-starter.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/supabase-auth .github/skills/supabase-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "supabase-auth" agent skill from https://github.com/textura-agency/next16-claude-starter/tree/main/.claude/skills/supabase-auth into .github/skills/supabase-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install textura-agency/next16-claude-starter supabase-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/textura-agency/next16-claude-starter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/supabase-auth .opencode/skills/supabase-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "supabase-auth" agent skill from https://github.com/textura-agency/next16-claude-starter/tree/main/.claude/skills/supabase-auth into .opencode/skills/supabase-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
supabase-authWire Supabase Auth into this Next.js 16 app with @supabase/ssr — browser/server clients, the proxy.ts session refresh (Next 16 renamed middleware), getClaims vs getSession, protected routes and…
Supabase Auth is an agent skill from textura-agency/next16-claude-starter. Wire Supabase Auth into this Next.js 16 app with @supabase/ssr — browser/server clients, the proxy.ts session refresh (Next 16 renamed middleware), getClaims vs getSession, protected routes and sign-in flows. Use when the user asks for login, accounts, a client portal, gated content, or "add auth". Not needed for a plain marketing site.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Frontend & Design, covering Landing pages. It works with Supabase and Next.js. The repository describes itself as: AI-first Next.js 16 starter for animation-heavy sites, wired with an Obsidian vault & Claude Code hooks. The licence is Unlicense.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6c6edf9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
yarnFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use yarn, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Supabase Auth loads about 1.4k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 311 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from textura-agency/next16-claude-starter at commit 6c6edf9, republished under its Unlicense licence (© textura-agency). 311 words, ~1,366 tokens.
.claude/skills/supabase-auth/SKILL.md (or your agent's skills folder).Only reach for this if the project genuinely needs user accounts. A marketing site backed by Payload does not — Payload has its own admin auth, and adding Supabase Auth on top is pure complexity.
Verified 2026-08 against @supabase/ssr 0.12.4.
middleware.ts no longer exists — it is proxy.ts, exporting a function
named proxy, running on Node (the Edge runtime is gone and cannot be
configured). Next's guidance is the "thin proxy" pattern: cheap cookie checks and
redirects only. Session refresh is fine there; heavy authorisation is not.
yarn add @supabase/supabase-js @supabase/ssrEnv: NEXT_PUBLIC_SUPABASE_URL, NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY
(both zod-validated in src/env.ts).
src/lib/supabase/client.ts — browser:
import { createBrowserClient } from '@supabase/ssr'
export function createClient() {
return createBrowserClient(
process.env.NEXT_PUBLIC_SUPABASE_URL!,
process.env.NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY!
)
}src/lib/supabase/server.ts — Server Components, Route Handlers, Actions:
import { createServerClient } from '@supabase/ssr'
import { cookies } from 'next/headers'
export async function createClient() {
const cookieStore = await cookies()
return createServerClient(
process.env.NEXT_PUBLIC_SUPABASE_URL!,
process.env.NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY!,
{
cookies: {
getAll() {
return cookieStore.getAll()
},
setAll(cookiesToSet, _headers) {
try {
cookiesToSet.forEach(({ name, value, options }) =>
cookieStore.set(name, value, options)
)
} catch {
// Called from a Server Component — safe to ignore when the proxy
// is refreshing sessions.
}
},
},
}
)
}src/lib/supabase/proxy.ts — the session refresher:
import { createServerClient } from '@supabase/ssr'
import { NextResponse, type NextRequest } from 'next/server'
export async function updateSession(request: NextRequest) {
let supabaseResponse = NextResponse.next({ request })
// With Fluid compute, never hoist this client into a module-level variable.
const supabase = createServerClient(
process.env.NEXT_PUBLIC_SUPABASE_URL!,
process.env.NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY!,
{
cookies: {
getAll() {
return request.cookies.getAll()
},
setAll(cookiesToSet, headers) {
cookiesToSet.forEach(({ name, value }) => request.cookies.set(name, value))
supabaseResponse = NextResponse.next({ request })
cookiesToSet.forEach(({ name, value, options }) =>
supabaseResponse.cookies.set(name, value, options)
)
Object.entries(headers).forEach(([key, value]) =>
supabaseResponse.headers.set(key, value)
)
},
},
}
)
// Do not run code between createServerClient and getClaims().
const { data } = await supabase.auth.getClaims()
const user = data?.claims
if (!user && !request.nextUrl.pathname.startsWith('/login')) {
const url = request.nextUrl.clone()
url.pathname = '/login'
return NextResponse.redirect(url)
}
return supabaseResponse
}src/proxy.ts — the entry point:
import { type NextRequest } from 'next/server'
import { updateSession } from '@/lib/supabase/proxy'
export async function proxy(request: NextRequest) {
return await updateSession(request)
}
export const config = {
matcher: ['/((?!_next/static|_next/image|favicon.ico|.*\\.(?:svg|png|jpg|jpeg|gif|webp)$).*)'],
}getSession() in server code. It reads the cookie without
revalidating. Use getClaims() (verifies the JWT signature against the
project's published keys) or getUser() (round-trips to Supabase).createServerClient and getClaims() in the proxy.
It desynchronises cookie refresh and logs users out at random.supabaseResponse unmodified. If you must build a new response,
pass { request } and copy every cookie across, or the refreshed session is
dropped.The proxy redirect is UX, not security — it only checks a cookie. Real access
control is RLS (see the supabase-db skill). Assume every client-side query
is attacker-controlled and let Postgres decide.
obsidian/backend/api-architecture.md).proxy.ts means every matched route runs Node before serving — keep the
matcher tight so static marketing pages are not dragged through it.© textura-agency, Unlicense. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/supabase-auth of textura-agency/next16-claude-starter.
Open the folder on GitHubat commit 6c6edf9
Supabase Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Supabase Auth this skilltextura-agency/next16-claude-starter | 133 | — | ~1.4k | Automated safety check: Pass | Unlicense | |
| Billing SDKhashgraph-online/awesome-codex-plugins | 1.3k | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| UI UX Pro Maxsaoudi-h/solar-icons | 190 | 18 repos | ~11k | Automated safety check: Notes | Custom licence | |
| UI/UX Design System AdvisorGalaxy-Dawn/claude-scholar | 5.7k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Design StyleCastor6/tactus | 376 | 1 repos | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Gridgeistohmiler/gridgeist | 115 | — | ~2.6k | Automated safety check: Pass | MIT |
hashgraph-online/awesome-codex-plugins
BillingSDK, the open-source React and shadcn component library for Dodo Payments billing UI.
saoudi-h/solar-icons
UI/UX design intelligence for web and mobile. An agent skill from saoudi-h/solar-icons.
Galaxy-Dawn/claude-scholar
Turns a vague UI request into a concrete design system with style, palette, typography and layout guidance from a search script, plus stack-specific implementation advice.
Castor6/tactus
A skill your agent uses whenever the user asks to build, create, design, develop, improve, or style any frontend interface or visual element.
ohmiler/gridgeist
A skill your agent uses when creating, redesigning, or reviewing web interfaces that need product-specific structure, clear hierarchy, responsive composition, accessible interaction, or relief from…
bear2u/my-skills
Comprehensive guide for creating effective landing pages using Next.js or React.
textura-agency/next16-claude-starter
Make a site behave on real phones — the defects no Lighthouse run or headless scroll test sees, learned from site owners reviewing production sites on an iPhone.
textura-agency/next16-claude-starter
Get a page into Lighthouse's green zone on desktop and mobile, for people AND for the robot form crawlers get — build it, audit all four categories (Performance, Accessibility, Best Practices, SEO)…
textura-agency/next16-claude-starter
Make a page in this starter actually smooth — build it, scroll it in real Chrome on PC and on an emulated phone, fix what the measurement blames, re-measure to prove it.
textura-agency/next16-claude-starter
Make a Payload admin feel like part of the site and explain itself — the skin re-tinted from the site's own tokens (calm, light, no added motion), the site's wordmark and favicon, a dashboard…
textura-agency/next16-claude-starter
Put a Payload CMS admin on a site built from this starter — every visible string and content photo editable, derived from the site's own content objects with the code's copy as the fallback, a…
textura-agency/next16-claude-starter
Answer Engine Optimisation — make the site citable by ChatGPT, Claude, Perplexity, Gemini and AI Overviews.
Categories
Wire Supabase Auth into this Next.js 16 app with @supabase/ssr — browser/server clients, the proxy.ts session refresh (Next 16 renamed middleware), getClaims vs getSession, protected routes and…. Supabase Auth is an agent skill from textura-agency/next16-claude-starter.ts session refresh (Next 16 renamed middleware), getClaims vs getSession, protected routes and sign-in flows.
Supabase Auth fits situations like: the user asks for login; A client portal.
Run `npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a claude-code`. Or copy the skill folder (.claude/skills/supabase-auth in textura-agency/next16-claude-starter) into .claude/skills/supabase-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a codex`. Or copy the skill folder (.claude/skills/supabase-auth in textura-agency/next16-claude-starter) into .agents/skills/supabase-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add textura-agency/next16-claude-starter --skill supabase-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-auth, .gemini/skills/supabase-auth, .github/skills/supabase-auth and .opencode/skills/supabase-auth in your project.
Going by SKILL.md and its folder, Supabase Auth needs the command-line tools its instructions call (yarn) and credentials named NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY. Our summary lists: A credential in NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Supabase Auth is published under the Unlicense licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Supabase Auth: Billing SDK (hashgraph-online/awesome-codex-plugins, 1.3k stars), UI UX Pro Max (saoudi-h/solar-icons, 190 stars), UI/UX Design System Advisor (Galaxy-Dawn/claude-scholar, 5.7k stars) and Design Style (Castor6/tactus, 376 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
textura-agency (a GitHub organization) maintains it in textura-agency/next16-claude-starter, which has 133 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 7, 2026.
Source: textura-agency/next16-claude-starter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.