Agent skill

Sync Convex Auth

by udecode in udecode/kitcn

Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes.

Apache-2.0Auto-check passedBackend & APIs

Install Sync Convex Auth

skills CLI
$ npx skills add udecode/kitcn --skill sync-convex-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install udecode/kitcn sync-convex-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sync-convex-auth .claude/skills/sync-convex-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sync-convex-auth
GitHub stars
450
Token cost
~3.3k tokens
SKILL.md length
1,103 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes.

  • Works in 7 steps: Establish Fork, Upstream, And Refs → Sync The Fork → Read The Upstream Diff → …
  • Asked to run sync-convex-auth
  • SKILL.md covers Goal Template, Rules, 1. Establish Fork, Upstream,… and 2. Sync The Fork, plus 6 more sections
  • Calls git, gh and bun; reaches github.com

What it does

Sync Convex Auth is an agent skill from udecode/kitcn. Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes. Use when asked to run sync-convex-auth, compare the fork with upstream, fast-forward or PR the fork update when safe, audit commits the fork was behind on, classify relevance to kitcn auth integration, and delegate one implementation PR through task.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Better Auth. The repository describes itself as: Convex + Better Auth + tRPC + Drizzle + TanStack Query + shadcn. The licence is Apache-2.0.

When your agent uses it

  • Asked to run sync-convex-auth
  • Compare the fork with upstream
  • PR the fork update when safe
  • Audit commits the fork was behind on

Example prompts

  • “/sync-convex-auth”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Establish Fork, Upstream, And Refs
  2. Sync The Fork
  3. Read The Upstream Diff
  4. Search Kitcn For Affected Auth Surfaces
  5. Classify Every Upstream Change
  6. Choose One Implementation Slice
  7. Delegate Through task

What it can do on your machine

Read from SKILL.md and the folder at commit c6010f5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • bun
    • rg
    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sync Convex Auth loads about 3.3k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,103 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from udecode/kitcn at commit c6010f5, republished under its Apache-2.0 licence (© udecode). 1,103 words, ~3,260 tokens.

Download SKILL.mdSave it as .claude/skills/sync-convex-auth/SKILL.md (or your agent's skills folder).
name
sync-convex-auth
description
Sync `zbeyens/convex-better-auth` with upstream, then sync kitcn against upstream `convex-better-auth` changes. Use when asked to run `sync-convex-auth`, compare the fork with upstream, fast-forward or PR the fork update when safe, audit commits the fork was behind on, classify relevance to kitcn auth integration, and delegate one implementation PR through `task`.

Sync Convex Auth

Handle $ARGUMENTS.

Goal: compare https://github.com/zbeyens/convex-better-auth with its upstream fork, sync that fork to upstream when it can be done without losing fork-only work, extract every upstream change that matters to kitcn, then delegate one coherent implementation slice to $task so it opens the PR.

Goal Template

When this sync needs durable goal state, use the project-owned sync template instead of the generic task template:

bash
node .agents/skills/autogoal/scripts/create-goal-scratchpad.mjs \
  --template sync-convex-auth \
  --title "sync convex auth"

This plan owns the upstream audit, classification ledger, ambiguity decisions, fork-sync result, and delegated task prompt. The delegated implementation still uses task; do not duplicate implementation PR machinery inside the sync plan.

Rules

  • Use evidence, not vibes. Read commits, changed files, and patches.
  • Treat the fork being behind upstream as signal, not proof. Pull only relevant work into kitcn.
  • Syncing the fork is required. Snapshot the pre-sync range first, then update zbeyens/convex-better-auth by fast-forward push or fork PR. Never force push the fork.
  • Ignore genuinely irrelevant upstream changes when deciding KitCN work. Do not mirror upstream into KitCN just to feel caught up.
  • Pull all clearly relevant, non-conflicting fixes in the same slice when they share the same kitcn auth surface.
  • Stop and ask the user before importing optional additions where the tradeoff is unclear, especially slow e2e suites, broad fixture rewrites, examples, release plumbing, or dev-only test infrastructure.
  • Prefer deleting kitcn glue over adding more glue when upstream fixed the real problem.
  • If no actionable opportunity exists, stop with the evidence. Do not open a vanity PR.

1. Establish Fork, Upstream, And Refs

Use GitHub metadata to discover the upstream parent instead of guessing:

bash
gh repo view zbeyens/convex-better-auth \
  --json nameWithOwner,parent,defaultBranchRef \
  --jq '{fork: .nameWithOwner, parent: .parent.nameWithOwner, branch: .defaultBranchRef.name}'

If parent is missing or ambiguous, stop and ask for the upstream repo.

Before asking, try these fallbacks in order:

bash
npm view @convex-dev/better-auth repository homepage --json
test -d ../convex-better-auth/.git && git -C ../convex-better-auth remote -v
gh repo view get-convex/better-auth --json nameWithOwner,defaultBranchRef,url

If npm metadata or the local clone clearly point to one upstream repo, use that repo and continue instead of stopping.

Use a local clone for navigation, creating it only if missing. Identify the remote that points at the fork and the remote that points at upstream by URL; do not assume origin is the fork:

bash
test -d ../convex-better-auth/.git || \
  gh repo clone zbeyens/convex-better-auth ../convex-better-auth
git -C ../convex-better-auth remote -v
git -C ../convex-better-auth remote get-url <upstream-remote> >/dev/null 2>&1 || \
  git -C ../convex-better-auth remote add <upstream-remote> https://github.com/<upstream-owner>/<repo-name>.git
git -C ../convex-better-auth fetch <fork-remote> --tags
git -C ../convex-better-auth fetch <upstream-remote> --tags

Record:

  • fork owner/name and default branch
  • upstream owner/name and default branch
  • fork remote name and upstream remote name
  • fork ref and upstream ref being compared
  • behind count
  • ahead count, if any
  • exact commit range

Commands:

bash
git -C ../convex-better-auth rev-list --count <fork-remote>/<fork-branch>..<upstream-remote>/<upstream-branch>
git -C ../convex-better-auth rev-list --count <upstream-remote>/<upstream-branch>..<fork-remote>/<fork-branch>
git -C ../convex-better-auth log --oneline --decorate <fork-remote>/<fork-branch>..<upstream-remote>/<upstream-branch>

If $ARGUMENTS names a base or target ref, use it as the bound after proving it exists.

2. Sync The Fork

The sync audit must update zbeyens/convex-better-auth itself, not only KitCN. Do this after recording the pre-sync range above, so the KitCN audit still knows which upstream commits were imported.

If the fork is already at the upstream ref, record fork sync: already synced.

If the fork is behind and not ahead, fast-forward the fork default branch to the upstream ref and push:

bash
git -C ../convex-better-auth merge-base --is-ancestor \
  <fork-remote>/<fork-branch> <upstream-remote>/<upstream-branch>
git -C ../convex-better-auth push <fork-remote> \
  refs/remotes/<upstream-remote>/<upstream-branch>:refs/heads/<fork-branch>
git -C ../convex-better-auth fetch <fork-remote> --tags
git -C ../convex-better-auth rev-parse <fork-remote>/<fork-branch>

If the fast-forward push is rejected because the fork default branch is protected or direct push is not allowed, open a PR in the fork instead:

bash
git -C ../convex-better-auth switch -C sync-upstream-<date> \
  <upstream-remote>/<upstream-branch>
git -C ../convex-better-auth push <fork-remote> \
  HEAD:refs/heads/sync-upstream-<date>
gh pr create \
  --repo zbeyens/convex-better-auth \
  --base <fork-branch> \
  --head zbeyens:sync-upstream-<date> \
  --title "Sync upstream convex-better-auth" \
  --body "Fast-forward fork to <upstream-owner>/<repo-name>@<upstream-ref>."

If the fork is ahead of upstream or has diverged, stop and ask before merging, rebasing, or overwriting anything. Do not force push. Record:

  • fork sync status: already synced, fast-forward pushed, fork PR opened, blocked: diverged, or blocked: push rejected
  • post-sync fork ref or PR URL
  • whether KitCN audit continues from the pre-sync range

3. Read The Upstream Diff

Start with a file summary:

bash
git -C ../convex-better-auth diff --name-status \
  <pre-sync-fork-ref>..<pre-sync-upstream-ref>

Then read patches for relevant-looking files:

bash
git -C ../convex-better-auth diff \
  <pre-sync-fork-ref>..<pre-sync-upstream-ref> -- \
  src package.json bun.lock tsconfig.json '*.md' \
  ':!**/dist/**' ':!**/build/**' ':!**/node_modules/**'

Use gh compare when it gives cleaner commit/file metadata:

bash
gh api \
  repos/<upstream-owner>/<repo-name>/compare/<fork-owner>:<fork-branch>...<upstream-branch> \
  --jq '.commits[] | {sha: .sha, message: .commit.message}'

gh api \
  repos/<upstream-owner>/<repo-name>/compare/<fork-owner>:<fork-branch>...<upstream-branch> \
  --jq '.files[] | {filename,status,patch}'

If the compare is too large, group by subsystem first, then inspect the patches for likely auth-runtime impact.

4. Search Kitcn For Affected Auth Surfaces

Search local kitcn integration points:

bash
rg -n "@convex-dev/better-auth|convexBetterAuth|getToken|convexClient|convex\\(|BetterAuth|better-auth|auth" \
  packages www .agents docs tooling fixtures example

Search institutional notes before proposing work:

bash
rg -i --files-with-matches \
  "convex-better-auth|@convex-dev/better-auth|better-auth|auth|react-start|nextjs|jwt|jwks|session|cookie|schema|plugin|getToken" \
  docs/solutions docs/plans

Read relevant hits, especially notes about:

  • @convex-dev/better-auth reexports and wrappers
  • kitcn/auth, kitcn/auth-client, kitcn/auth-nextjs, and kitcn/auth-start
  • Better Auth and Convex version compatibility
  • token, JWT, JWKS, cookie, and session handling
  • schema generation, plugin reconciliation, and generated auth contracts
  • React, Solid, Next.js, and TanStack Start provider behavior
  • scaffold templates, docs, and packages/kitcn/skills/kitcn/**
  • local hacks that might be obsolete after upstream changes
Show full SKILL.md (448 more words)Show less

5. Classify Every Upstream Change

Classify each commit or file group:

  • compatibility: required work to keep kitcn working with upstream auth, Better Auth, Convex, framework, or package changes.
  • security: auth correctness or security hardening kitcn should not miss.
  • bugfix: upstream fix that maps to a kitcn runtime, provider, token, schema, routing, or scaffold issue.
  • feature: new upstream API, helper, framework support, or auth capability kitcn can expose cleanly.
  • cleanup: upstream change that lets kitcn delete a workaround, wrapper, fallback, doc warning, copied logic, or special-case patch.
  • docs: upstream change that only affects user-facing docs, setup guidance, or skills.
  • tests: upstream test coverage or harness changes.
  • no-op: interesting upstream change with no kitcn action.

For every non-no-op, include:

  • commit evidence
  • diff evidence
  • local kitcn files affected
  • expected implementation surface
  • verification command(s)
  • confidence

Use this relevance filter:

  • Relevant: runtime auth behavior, package exports kitcn imports or reexports, helpers kitcn wraps, version compatibility, security, framework integration, schema/plugin behavior, generated code contracts, docs/skills users rely on, and cleanup of known kitcn workarounds.
  • Usually irrelevant: upstream release config, repository-only CI, maintainer docs, benchmark harnesses, examples that do not map to kitcn scaffolds, and tests for behavior kitcn neither exposes nor depends on.
  • Ambiguous optional: added test suites, e2e harnesses, examples, fixtures, benchmark tooling, and dev-only utilities. Stop and ask before pulling these in unless they are the direct verification path for a selected required fix.

6. Choose One Implementation Slice

Pick the highest-leverage slice using this order:

  1. security fix
  2. compatibility breakage
  3. bugfix that affects kitcn users
  4. delete dirty hack made obsolete upstream
  5. agentic or DX improvement for deterministic setup, CLI, or generated output
  6. feature kitcn can expose cleanly
  7. docs or skill-only update
  8. optional tests or examples only after user approval

If several relevant upstream fixes touch the same auth surface and do not conflict, delegate them together. If they touch separate surfaces, pick the highest-risk slice first.

If the winning slice touches published package code, the delegated task must update the active changeset and run bun --cwd packages/kitcn build.

If it touches scaffold templates, the delegated task must run bun run fixtures:sync and bun run fixtures:check.

If it touches auth runtime, client, provider, or query invalidation surfaces, the delegated task must follow the repo's auth verification lane. Do not import a slow upstream e2e suite unless the user explicitly approves it.

7. Delegate Through task

Load $task with a prompt in this exact shape:

md
Implement this convex-better-auth sync opportunity.

Fork: zbeyens/convex-better-auth
Upstream: <upstream-owner>/<repo-name>
Range: <fork-ref>..<upstream-ref>
Behind: <count> commits
Fork sync: <already synced | fast-forward pushed | fork PR URL | blocked reason>

Opportunity: <one-sentence selected slice>
Class: <security | compatibility | bugfix | cleanup | agentic | feature | docs | tests>

Evidence:

- Upstream commits: <short commit list or summary>
- Upstream diff: <refs and files>
- Kitcn evidence: <local files and docs/solutions notes>

Implementation:

- <specific files or surfaces to inspect first>
- <expected code/doc/test shape>
- <anything explicitly ignored as irrelevant>

Acceptance:

- <focused tests/checks>
- <package build if packages/kitcn changes>
- <fixtures commands if scaffold output changes>
- open the PR after verification

Do not preserve obsolete auth workarounds if the upstream change removes the
need for them. Hard cut the hack.
Do not add optional slow e2e suites, broad examples, or dev-only upstream test
infrastructure unless the user approved that scope.

Then follow task until the PR exists or a real blocker is proven.

Output

Before delegation, keep the audit terse:

md
Fork: zbeyens/convex-better-auth
Upstream: <upstream-owner>/<repo-name>
Range: <fork-ref>..<upstream-ref>
Behind: <count>
Fork sync: <status and post-sync ref or PR URL>

| Class  | Opportunity | Evidence | Decision |
| ------ | ----------- | -------- | -------- |
| bugfix | ...         | ...      | selected |

Delegating to task: <selected slice>

If the right choice is ambiguous, stop and ask one pointed question. Example:

md
Upstream added a Playwright e2e suite that does not fix a current kitcn bug.
Do you want that pulled in, or should I ignore it and keep this sync to runtime
fixes only?

After task finishes, use its final handoff format.

© udecode, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/sync-convex-auth of udecode/kitcn.

Open the folder on GitHubat commit c6010f5

Compare with similar skills

Sync Convex Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sync Convex Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sync Convex Auth this skilludecode/kitcn450—~3.3kAutomated safety check: PassApache-2.0
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
Email And Password Best Practicesever-works/ever-works1583 repos~1.5kAutomated safety check: PassAGPL-3.0
Better Auth Security Best Practicesagutinbaigo28/financial-agent-api128—~2.7kAutomated safety check: PassNone
Organization Best Practicesever-works/ever-works1582 repos~2.6kAutomated safety check: PassAGPL-3.0

Similar skills

  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Backend & APIsAuto-check passed
  • Configure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication.

    158 GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Better Auth Security Best Practices

    agutinbaigo28/financial-agent-api

    Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…

    128 GitHub stars~2.7k tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Organization Best Practices

    ever-works/ever-works

    Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin.

    158 GitHub starsUsed in 2 repos~2.6k tokens
    Backend & APIsAuto-check passed
  • Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.

    158 GitHub starsUsed in 2 repos~1.8k tokens
    Backend & APIsAuto-check passed

More from udecode/kitcn

All 33 skills in this repo
  • Walkthrough

    udecode/kitcn

    Create a short annotated visual walkthrough from real final-state screenshots or rendered artifacts.

    450 GitHub stars~1.6k tokensUpdated 6 days ago
    Auto-check passed
  • Avoid Feature Creep

    udecode/kitcn

    Prevent feature creep when building software, apps, and AI-powered products.

    450 GitHub stars~2.7k tokensUpdated 6 days ago
    Auto-check passed
  • Changeset Resolve

    udecode/kitcn

    Repair an unreleased .changeset/.md file so it matches the real branch delta against main.

    450 GitHub stars~922 tokensUpdated 6 days ago
    Auto-check passed
  • Audit newer Convex npm releases against kitcn. An agent skill from udecode/kitcn.

    450 GitHub stars~1.8k tokensUpdated 6 days ago
    Auto-check passed
  • Jotai X

    udecode/kitcn

    A skill your agent uses when working with Jotai X stores (createAtomStore), accessing state in components or callbacks, persisting state to cookies or localStorage

    450 GitHub stars~3.7k tokensUpdated 6 days ago
    Auto-check passed
  • Linear Backlog

    udecode/kitcn

    Run a scoped Linear backlog autonomously as a sequence of maximal safe parallel batches by composing orchestrator, autogoal, and task.

    450 GitHub stars~3.1k tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Sync Convex Auth

What does Sync Convex Auth do?

Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes. Sync Convex Auth is an agent skill from udecode/kitcn. Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes.

When should I use Sync Convex Auth?

Sync Convex Auth fits situations like: asked to run sync-convex-auth; compare the fork with upstream; PR the fork update when safe; audit commits the fork was behind on.

How do I install Sync Convex Auth in Claude Code?

Run `npx skills add udecode/kitcn --skill sync-convex-auth -a claude-code`. Or copy the skill folder (.agents/skills/sync-convex-auth in udecode/kitcn) into .claude/skills/sync-convex-auth in your project. Claude Code loads it when a task matches its description.

How do I install Sync Convex Auth in Codex?

Run `npx skills add udecode/kitcn --skill sync-convex-auth -a codex`. Or copy the skill folder (.agents/skills/sync-convex-auth in udecode/kitcn) into .agents/skills/sync-convex-auth in your project. Codex loads it when a task matches its description.

Can I use Sync Convex Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add udecode/kitcn --skill sync-convex-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sync-convex-auth, .gemini/skills/sync-convex-auth, .github/skills/sync-convex-auth and .opencode/skills/sync-convex-auth in your project.

What does Sync Convex Auth need to run?

Going by SKILL.md and its folder, Sync Convex Auth needs the command-line tools its instructions call (git, gh, bun, rg, node and npm).

Does Sync Convex Auth access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sync Convex Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sync Convex Auth use?

Sync Convex Auth is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sync Convex Auth use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sync Convex Auth?

Skills that share tags, products or a category with Sync Convex Auth: Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), Email And Password Best Practices (ever-works/ever-works, 158 stars) and Better Auth Security Best Practices (agutinbaigo28/financial-agent-api, 128 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sync Convex Auth?

udecode (a GitHub organization) maintains it in udecode/kitcn, which has 450 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: udecode/kitcn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.