Agent skill

Passport Development

by trypostit in trypostit/trypost

Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

MITAuto-check passedBackend & APIs

Install Passport Development

skills CLI
$ npx skills add trypostit/trypost --skill passport-development -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trypostit/trypost passport-development --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trypostit/trypost.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/passport-development .claude/skills/passport-development && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
passport-development
GitHub stars
676
Token cost
~1.9k tokens
SKILL.md length
601 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

  • Works in 3 steps: Install Passport → Configure the User model → Configure the auth guard
  • Mentions Passport
  • SKILL.md covers Documentation First, When to Apply, Passport vs. Sanctum and Installation, plus 9 more sections
  • Calls php

What it does

Passport Development is an agent skill from trypostit/trypost. Develops OAuth2 API authentication with Laravel Passport. Activates when installing or configuring Passport; setting up OAuth2 grants (authorization code, client credentials, personal access tokens, device authorization); managing OAuth clients; protecting API routes with token authentication; defining or checking token scopes; configuring SPA cookie authentication; handling token lifetimes and refresh tokens; or when the user mentions Passport, OAuth2, API tokens, bearer tokens, or API authentication. Make sure…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect, Backend development and Authentication. It works with Laravel, PHP, Vue.js and LinkedIn. The repository describes itself as: Open-source Social Media Scheduling. The licence is MIT.

When your agent uses it

  • Mentions Passport
  • API authentication
  • The user works with OAuth2
  • Third-party API access

Example prompts

  • “Use the passport-development skill to develop OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost”
  • “/passport-development”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Install Passport
  2. Configure the User model
  3. Configure the auth guard

What it can do on your machine

Read from SKILL.md and the folder at commit f9fc951. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • php

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Passport Development loads about 1.9k tokens when it runs. Until then it costs about 170 tokens; SKILL.md has 601 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~170
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trypostit/trypost at commit f9fc951, republished under its MIT licence (© trypostit). 601 words, ~1,860 tokens.

Download SKILL.mdSave it as .claude/skills/passport-development/SKILL.md (or your agent's skills folder).
name
passport-development
description
Develops OAuth2 API authentication with Laravel Passport. Activates when installing or configuring Passport; setting up OAuth2 grants (authorization code, client credentials, personal access tokens, device authorization); managing OAuth clients; protecting API routes with token authentication; defining or checking token scopes; configuring SPA cookie authentication; handling token lifetimes and refresh tokens; or when the user mentions Passport, OAuth2, API tokens, bearer tokens, or API authentication. Make sure to use this skill whenever the user works with OAuth2, API tokens, or third-party API access, even if they don't explicitly mention Passport.
license
MIT
metadata.author
laravel

Passport OAuth2 Authentication

Documentation First

Always use search-docs before writing Passport code. The documentation covers every grant type, configuration option, and edge case in detail. This skill teaches you how to navigate Passport — the docs have the implementation specifics.

search-docs(queries: ["Passport installation"], packages: ["laravel/framework@12.x"])

The Passport docs live under the laravel/framework package — not laravel/passport.

When to Apply

Activate this skill when:

  • Installing or configuring Passport
  • Setting up OAuth2 authorization grants
  • Creating or managing OAuth clients
  • Protecting API routes with token authentication
  • Defining or checking token scopes
  • Configuring SPA cookie-based authentication
  • Choosing between Passport and Sanctum

Passport vs. Sanctum

Passport is a full OAuth2 server — use it when third-party applications need to consume your API and when you need OAuth2 authorization code grants, client credentials for machine-to-machine auth, or device authorization flow.

Sanctum is simpler — use it when first-party SPAs, third parties, or mobile apps consume the API but you don't need the full OAuth2 grant flows.

Installation

Three steps are always required:

1. Install Passport
bash
php artisan install:api --passport

This publishes migrations, generates encryption keys, and registers routes.

2. Configure the User model

The User model needs both the HasApiTokens trait AND the OAuthenticatable interface. Missing the interface is the most common Passport setup mistake — it causes runtime errors that can be confusing to debug.

php
use Laravel\Passport\Contracts\OAuthenticatable;
use Laravel\Passport\HasApiTokens;

class User extends Authenticatable implements OAuthenticatable
{
    use HasApiTokens;
}
3. Configure the auth guard

The api guard must use the passport driver in config/auth.php. Using token or sanctum here silently breaks Passport authentication.

php
'guards' => [
    'api' => [
        'driver' => 'passport',
        'provider' => 'users',
    ],
],

Choosing a Grant Type

Matching the right grant to the use case is the most important Passport decision. Use search-docs for implementation details of any grant.

Use CaseGrant TypeClient Flag
Third-party app accessing user dataAuthorization Code(default)
Mobile/SPA without client secretAuthorization Code + PKCE--public
Machine-to-machine, no user contextClient Credentials--client
User-generated API keysPersonal Access Tokens--personal
Smart TV, CLI, IoT devicesDevice Authorization--device

Legacy grants (Password, Implicit) are disabled by default and not recommended. They must be explicitly enabled with Passport::enablePasswordGrant() or Passport::enableImplicitGrant().

Client Management

Create clients with the appropriate flag for the grant type:

bash
php artisan passport:client              # Authorization code

php artisan passport:client --public     # PKCE (no secret)

php artisan passport:client --client     # Client credentials

php artisan passport:client --personal   # Personal access tokens

php artisan passport:client --device     # Device authorization

Additional flags: --name=, --redirect_uri=, --provider=.

Client secrets are hashed by default — the plain-text secret is only shown at creation time and cannot be retrieved later.

Show full SKILL.md (244 more words)Show less

Protecting Routes

Apply auth:api middleware. Clients send tokens via the Authorization: Bearer <token> header.

php
Route::get('/user', function (Request $request) {
    return $request->user();
})->middleware('auth:api');
Scope Enforcement

Scope middleware must come alongside auth:api:

  • CheckToken::using('scope1', 'scope2') — requires ALL listed scopes
  • CheckTokenForAnyScope::using('scope1', 'scope2') — requires ANY listed scope
  • EnsureClientIsResourceOwner::using('scope1') — restricts to client credential tokens
php
use Laravel\Passport\Http\Middleware\CheckToken;

Route::get('/orders', function () {
    // ...
})->middleware(['auth:api', CheckToken::using('orders:read')]);
Programmatic scope checking
php
if ($request->user()->tokenCan('place-orders')) {
    // ...
}

Use search-docs for full scope middleware registration and usage patterns.

Key Configuration

Configure in AppServiceProvider::boot(). Use search-docs for the full list of options.

php
// Token lifetimes (each is independent)
Passport::tokensExpireIn(now()->addDays(15));
Passport::refreshTokensExpireIn(now()->addDays(30));
Passport::personalAccessTokensExpireIn(now()->addMonths(6));

// Define scopes
Passport::tokensCan([
    'place-orders' => 'Place orders',
    'check-status' => 'Check order status',
]);

For first-party SPAs, the CreateFreshApiToken middleware issues a laravel_token cookie containing an encrypted JWT. The SPA must include CSRF tokens — missing the X-CSRF-TOKEN or X-XSRF-TOKEN header causes 419 errors.

Use search-docs for setup details — this feature has specific CSRF and cookie configuration requirements.

Testing

Passport provides helpers to bypass full OAuth flows in tests:

php
Passport::actingAs($user, ['scope1', 'scope2']);
Passport::actingAsClient($client, ['scope1']);

Token Maintenance

bash
php artisan passport:purge              # Purge revoked & expired

php artisan passport:purge --revoked    # Only revoked

php artisan passport:purge --expired    # Only expired

Schedule passport:purge for regular expired token clean-up.

Events

All in Laravel\Passport\Events: AccessTokenCreated, AccessTokenRevoked, RefreshTokenCreated.

Common Pitfalls

  • Missing OAuthenticatable interface — both the HasApiTokens trait and the OAuthenticatable interface are required on the User model. Missing the interface causes runtime errors.
  • Wrong guard driver — the api guard must use passport, not token or sanctum. This fails silently.
  • Token lifetime confusion — access token, refresh token, and personal access token lifetimes are all independent settings.
  • Missing CSRF for SPA cookie auth — CreateFreshApiToken requires CSRF tokens. Use Passport::ignoreCsrfToken() only if you understand the security implications.
  • Client secrets are hashed — the plain-text secret is only available at creation time.
  • Legacy grants are disabled — Password and Implicit grants must be explicitly enabled and are not recommended.

© trypostit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/passport-development of trypostit/trypost.

Open the folder on GitHubat commit f9fc951

Compare with similar skills

Passport Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Passport Development compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Passport Development this skilltrypostit/trypost676—~1.9kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Socialite Developmenthexlet-volunteers/hexlet-sicp1145 repos~1.2kAutomated safety check: PassMIT
Spa Auth Developmentgdarko/laravel-vue-starter145—~668Automated safety check: NotesMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Livewire Developmentcoollabsio/coolify63k—~964Automated safety check: PassMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Spa Auth Development

    gdarko/laravel-vue-starter

    Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

    145 GitHub stars~668 tokensUpdated 6 mo ago
    Backend & APIsAuto-check: notes
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Livewire Development

    coollabsio/coolify

    A skill your agent uses for any task or question involving Livewire.

    63k GitHub stars~964 tokensUpdated today
    Backend & APIsAuto-check passed
  • Livewire Development

    yungifez/skuul

    A skill your agent uses for any task or question involving Livewire.

    409 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed

More from trypostit/trypost

  • AI SDK Development

    trypostit/trypost

    TRIGGER when working with ai-sdk which is Laravel official first-party AI SDK.

    676 GitHub starsUsed in 2 repos~3.5k tokens
    Auto-check passed
  • Configure Nightwatch

    trypostit/trypost

    Configures Laravel Nightwatch data collection, sampling rates, filtering rules, and redaction policies.

    676 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Passport Development

What does Passport Development do?

Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost. Passport Development is an agent skill from trypostit/trypost. Develops OAuth2 API authentication with Laravel Passport.

When should I use Passport Development?

Passport Development fits situations like: mentions Passport; API authentication; the user works with OAuth2; third-party API access.

How do I install Passport Development in Claude Code?

Run `npx skills add trypostit/trypost --skill passport-development -a claude-code`. Or copy the skill folder (.agents/skills/passport-development in trypostit/trypost) into .claude/skills/passport-development in your project. Claude Code loads it when a task matches its description.

How do I install Passport Development in Codex?

Run `npx skills add trypostit/trypost --skill passport-development -a codex`. Or copy the skill folder (.agents/skills/passport-development in trypostit/trypost) into .agents/skills/passport-development in your project. Codex loads it when a task matches its description.

Can I use Passport Development in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trypostit/trypost --skill passport-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/passport-development, .gemini/skills/passport-development, .github/skills/passport-development and .opencode/skills/passport-development in your project.

What does Passport Development need to run?

Going by SKILL.md and its folder, Passport Development needs the command-line tools its instructions call (php).

Does Passport Development access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Passport Development safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Passport Development use?

Passport Development is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Passport Development use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Passport Development?

Skills that share tags, products or a category with Passport Development: Fortify Development (coollabsio/coolify, 63k stars), Socialite Development (hexlet-volunteers/hexlet-sicp, 114 stars), Spa Auth Development (gdarko/laravel-vue-starter, 145 stars) and Configuring Horizon (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Passport Development?

trypostit (a GitHub organization) maintains it in trypostit/trypost, which has 676 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: trypostit/trypost on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.