Agent skill

Authentication Flow

by ThibautBaissac in ThibautBaissac/rails_ai_agents

Implements authentication using Rails 8 built-in generator. An agent skill from ThibautBaissac/rails_ai_agents.

MITAuto-check passedBackend & APIs

Install Authentication Flow

skills CLI
$ npx skills add ThibautBaissac/rails_ai_agents --skill authentication-flow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ThibautBaissac/rails_ai_agents authentication-flow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/authentication-flow .claude/skills/authentication-flow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authentication-flow
GitHub stars
665
Token cost
~1.9k tokens
SKILL.md length
101 words
Files
3 (incl. references)
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Implements authentication using Rails 8 built-in generator. An agent skill from ThibautBaissac/rails_ai_agents.

  • Setting up user authentication
  • SKILL.md covers Overview, Quick Start, Generated Structure and Core Components, plus 4 more sections
  • Calls rails
  • Session management

What it does

Authentication Flow is an agent skill from ThibautBaissac/rails_ai_agents. Implements authentication using Rails 8 built-in generator. Use when setting up user authentication, login/logout, session management, password reset flows, or securing controllers. WHEN NOT: Authorization and permissions (use Pundit policies), API token authentication, OAuth/SSO integration, or role-based access control.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/current.md` and `references/sessions.md`).

It sits in Backend & APIs, covering Authentication and Authorization and RBAC. It works with Ruby on Rails. The repository describes itself as: Specialized AI skills, agents, rules and hooks for modern Rails AI driven-development + Spec-Driven-Development kit + MCP. The licence is MIT.

When your agent uses it

  • Setting up user authentication
  • Session management
  • Password reset flows
  • Securing controllers

Example prompts

  • “Use the authentication-flow skill to implement authentication using Rails 8 built-in generator. An agent skill from ThibautBaissac/rails_ai_agents”
  • “/authentication-flow”

What it can do on your machine

Read from SKILL.md and the folder at commit 03622f2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rails

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authentication Flow loads about 1.9k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 86 tokens; SKILL.md has 101 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ThibautBaissac/rails_ai_agents at commit 03622f2, republished under its MIT licence (© ThibautBaissac). 101 words, ~1,943 tokens.

Download SKILL.mdSave it as .claude/skills/authentication-flow/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
authentication-flow
description
Implements authentication using Rails 8 built-in generator. Use when setting up user authentication, login/logout, session management, password reset flows, or securing controllers. WHEN NOT: Authorization and permissions (use Pundit policies), API token authentication, OAuth/SSO integration, or role-based access control.
paths
app/controllers/sessions_controller.rb, app/models/user.rb, app/models/session.rb

Rails 8 Authentication

Overview

Rails 8 includes a built-in authentication generator that creates a complete, secure authentication system without external gems.

Quick Start

bash
# Generate authentication
bin/rails generate authentication

# Run migrations
bin/rails db:migrate

This creates:

  • User model with has_secure_password
  • Session model for secure sessions
  • Current model for request-local storage
  • Authentication concern for controllers
  • Session and Password controllers
  • Login/logout views

Generated Structure

app/
├── models/
│   ├── user.rb              # User with has_secure_password
│   ├── session.rb           # Session tracking
│   └── current.rb           # Current.user accessor
├── controllers/
│   ├── sessions_controller.rb      # Login/logout
│   ├── passwords_controller.rb     # Password reset
│   └── concerns/
│       └── authentication.rb       # Auth helpers
└── views/
    ├── sessions/
    │   └── new.html.erb     # Login form
    └── passwords/
        ├── new.html.erb     # Forgot password
        └── edit.html.erb    # Reset password

Core Components

User Model
ruby
# app/models/user.rb
class User < ApplicationRecord
  has_secure_password
  has_many :sessions, dependent: :destroy

  normalizes :email_address, with: -> { _1.strip.downcase }

  validates :email_address, presence: true, uniqueness: true,
            format: { with: URI::MailTo::EMAIL_REGEXP }
end
Session Model
ruby
# app/models/session.rb
class Session < ApplicationRecord
  belongs_to :user

  before_create { self.token = SecureRandom.urlsafe_base64(32) }

  def self.find_by_token(token)
    find_by(token: token) if token.present?
  end
end
Current Model
ruby
# app/models/current.rb
class Current < ActiveSupport::CurrentAttributes
  attribute :session
  delegate :user, to: :session, allow_nil: true
end
Authentication Concern
ruby
# app/controllers/concerns/authentication.rb
module Authentication
  extend ActiveSupport::Concern

  included do
    before_action :require_authentication
    helper_method :authenticated?
  end

  class_methods do
    def allow_unauthenticated_access(**options)
      skip_before_action :require_authentication, **options
    end
  end

  private

  def authenticated?
    Current.session.present?
  end

  def require_authentication
    resume_session || request_authentication
  end

  def resume_session
    if session_token = cookies.signed[:session_token]
      if session = Session.find_by_token(session_token)
        Current.session = session
      end
    end
  end

  def request_authentication
    redirect_to new_session_path
  end

  def start_new_session_for(user)
    session = user.sessions.create!
    cookies.signed.permanent[:session_token] = { value: session.token, httponly: true }
    Current.session = session
  end

  def terminate_session
    Current.session&.destroy
    cookies.delete(:session_token)
  end
end

Usage Patterns

Protecting Controllers
ruby
class ApplicationController < ActionController::Base
  include Authentication

  # All actions require authentication by default
end

class PostsController < ApplicationController
  # All actions protected
end

class HomeController < ApplicationController
  # Allow public access to specific actions
  allow_unauthenticated_access only: [:index, :about]
end
Accessing Current User
ruby
# In controllers
Current.user
Current.user.email_address

# In views
<%= Current.user.email_address %>

# In models (use sparingly)
Current.user
Login Flow
ruby
# app/controllers/sessions_controller.rb
class SessionsController < ApplicationController
  allow_unauthenticated_access only: [:new, :create]

  def new
  end

  def create
    if user = User.authenticate_by(email_address: params[:email_address],
                                    password: params[:password])
      start_new_session_for(user)
      redirect_to root_path, notice: "Signed in successfully"
    else
      flash.now[:alert] = "Invalid email or password"
      render :new, status: :unprocessable_entity
    end
  end

  def destroy
    terminate_session
    redirect_to root_path, notice: "Signed out"
  end
end

Testing Authentication

Request Specs
ruby
# spec/requests/sessions_spec.rb
RSpec.describe "Sessions", type: :request do
  let(:user) { create(:user, password: "password123") }

  describe "POST /session" do
    context "with valid credentials" do
      it "signs in the user" do
        post session_path, params: {
          email_address: user.email_address,
          password: "password123"
        }

        expect(response).to redirect_to(root_path)
        expect(cookies[:session_token]).to be_present
      end
    end

    context "with invalid credentials" do
      it "shows error" do
        post session_path, params: {
          email_address: user.email_address,
          password: "wrong"
        }

        expect(response).to have_http_status(:unprocessable_entity)
      end
    end
  end

  describe "DELETE /session" do
    it "signs out the user" do
      # First sign in
      post session_path, params: {
        email_address: user.email_address,
        password: "password123"
      }

      delete session_path

      expect(response).to redirect_to(root_path)
    end
  end
end
Test Helper
ruby
# spec/support/authentication_helpers.rb
module AuthenticationHelpers
  def sign_in(user)
    session = user.sessions.create!
    cookies[:session_token] = session.token
  end

  def sign_out
    cookies.delete(:session_token)
  end
end

RSpec.configure do |config|
  config.include AuthenticationHelpers, type: :request
  config.include AuthenticationHelpers, type: :system
end
Protected Route Specs
ruby
# spec/requests/posts_spec.rb
RSpec.describe "Posts", type: :request do
  let(:user) { create(:user) }

  describe "GET /posts" do
    context "when not authenticated" do
      it "redirects to login" do
        get posts_path
        expect(response).to redirect_to(new_session_path)
      end
    end

    context "when authenticated" do
      before { sign_in(user) }

      it "shows posts" do
        get posts_path
        expect(response).to have_http_status(:ok)
      end
    end
  end
end

References

Common Customizations

Remember Me
ruby
def start_new_session_for(user, remember: false)
  session = user.sessions.create!
  cookie_options = { value: session.token, httponly: true }
  cookie_options[:expires] = 2.weeks.from_now if remember
  cookies.signed.permanent[:session_token] = cookie_options
  Current.session = session
end
Multiple Sessions Tracking
ruby
# In User model
def active_sessions
  sessions.where('created_at > ?', 30.days.ago)
end

def terminate_all_sessions_except(current_session)
  sessions.where.not(id: current_session.id).destroy_all
end
Rate Limiting
ruby
# app/controllers/sessions_controller.rb
rate_limit to: 10, within: 3.minutes, only: :create,
           with: -> { redirect_to new_session_path, alert: "Too many attempts" }

© ThibautBaissac, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .agents/skills/authentication-flow of ThibautBaissac/rails_ai_agents.

  • SKILL.md
  • references/current.md
  • references/sessions.md

Open the folder on GitHubat commit 03622f2

Compare with similar skills

Authentication Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authentication Flow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authentication Flow this skillThibautBaissac/rails_ai_agents665—~1.9kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61710 repos~4.4kAutomated safety check: PassNone
Auth Setupdilolabs/nosia2131 repos~2.9kAutomated safety check: PassMIT
Configuration Cryptogreenpau/caddy-security2.3k—~3.5kAutomated safety check: PassApache-2.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0

Similar skills

  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Auth Setup

    dilolabs/nosia

    Implements custom passwordless authentication without Devise.

    213 GitHub starsUsed in 1 repo~2.9k tokens
    Backend & APIsAuto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Bkend Auth

    ww-w-ai/bkit-claude-code

    bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.

    601 GitHub stars~937 tokensUpdated 11 days ago
    Backend & APIsAuto-check: notes

More from ThibautBaissac/rails_ai_agents

All 19 skills in this repo
  • Accessibility Review

    ThibautBaissac/rails_ai_agents

    Audits Rails application accessibility against WCAG 2.2 Level AA, detects violations with axe-core / Lighthouse / Pa11y, and reports remediation guidance for ERB views, ViewComponents, Stimulus…

    665 GitHub stars~2.9k tokensUpdated 4 mo ago
    Auto-check: notes
  • Action Cable Patterns

    ThibautBaissac/rails_ai_agents

    Implements real-time features with Action Cable and WebSockets.

    665 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Active Storage Setup

    ThibautBaissac/rails_ai_agents

    Configures Active Storage for file uploads with variants and direct uploads.

    665 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Caching Strategies

    ThibautBaissac/rails_ai_agents

    Implements Rails caching patterns for performance optimization.

    665 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • I18n Patterns

    ThibautBaissac/rails_ai_agents

    Implements internationalization with Rails I18n for multi-language support.

    665 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Performance Optimization

    ThibautBaissac/rails_ai_agents

    Identifies and fixes Rails performance issues including N+1 queries, slow queries, and memory problems.

    665 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Authentication Flow

What does Authentication Flow do?

Implements authentication using Rails 8 built-in generator. An agent skill from ThibautBaissac/rails_ai_agents. Authentication Flow is an agent skill from ThibautBaissac/rails_ai_agents. Implements authentication using Rails 8 built-in generator.

When should I use Authentication Flow?

Authentication Flow fits situations like: setting up user authentication; session management; password reset flows; securing controllers.

How do I install Authentication Flow in Claude Code?

Run `npx skills add ThibautBaissac/rails_ai_agents --skill authentication-flow -a claude-code`. Or copy the skill folder (.agents/skills/authentication-flow in ThibautBaissac/rails_ai_agents) into .claude/skills/authentication-flow in your project. Claude Code loads it when a task matches its description.

How do I install Authentication Flow in Codex?

Run `npx skills add ThibautBaissac/rails_ai_agents --skill authentication-flow -a codex`. Or copy the skill folder (.agents/skills/authentication-flow in ThibautBaissac/rails_ai_agents) into .agents/skills/authentication-flow in your project. Codex loads it when a task matches its description.

Can I use Authentication Flow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ThibautBaissac/rails_ai_agents --skill authentication-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authentication-flow, .gemini/skills/authentication-flow, .github/skills/authentication-flow and .opencode/skills/authentication-flow in your project.

What does Authentication Flow need to run?

Going by SKILL.md and its folder, Authentication Flow needs the command-line tools its instructions call (rails).

Does Authentication Flow access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Authentication Flow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authentication Flow use?

Authentication Flow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authentication Flow use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Authentication Flow?

Skills that share tags, products or a category with Authentication Flow: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars), Auth Setup (dilolabs/nosia, 213 stars) and Configuration Crypto (greenpau/caddy-security, 2.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authentication Flow?

ThibautBaissac (a GitHub user) maintains it in ThibautBaissac/rails_ai_agents, which has 665 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on June 1, 2026.

Source: ThibautBaissac/rails_ai_agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.