Better Auth Best Practices
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes.
$ npx skills add udecode/kitcn --skill sync-convex-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install udecode/kitcn sync-convex-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sync-convex-auth .claude/skills/sync-convex-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sync-convex-auth" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/sync-convex-auth into .claude/skills/sync-convex-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-convex-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/udecode/kitcn/tree/main/.agents/skills/sync-convex-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add udecode/kitcn --skill sync-convex-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install udecode/kitcn sync-convex-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/sync-convex-auth .agents/skills/sync-convex-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sync-convex-auth" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/sync-convex-auth into .agents/skills/sync-convex-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-convex-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add udecode/kitcn --skill sync-convex-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install udecode/kitcn sync-convex-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/sync-convex-auth .cursor/skills/sync-convex-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sync-convex-auth" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/sync-convex-auth into .cursor/skills/sync-convex-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-convex-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/udecode/kitcn.git --path .agents/skills/sync-convex-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add udecode/kitcn --skill sync-convex-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install udecode/kitcn sync-convex-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/sync-convex-auth .gemini/skills/sync-convex-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sync-convex-auth" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/sync-convex-auth into .gemini/skills/sync-convex-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-convex-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install udecode/kitcn sync-convex-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add udecode/kitcn --skill sync-convex-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/sync-convex-auth .github/skills/sync-convex-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sync-convex-auth" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/sync-convex-auth into .github/skills/sync-convex-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-convex-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add udecode/kitcn --skill sync-convex-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install udecode/kitcn sync-convex-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/sync-convex-auth .opencode/skills/sync-convex-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sync-convex-auth" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/sync-convex-auth into .opencode/skills/sync-convex-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-convex-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sync-convex-authSync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes.
Sync Convex Auth is an agent skill from udecode/kitcn. Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes. Use when asked to run sync-convex-auth, compare the fork with upstream, fast-forward or PR the fork update when safe, audit commits the fork was behind on, classify relevance to kitcn auth integration, and delegate one implementation PR through task.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs. It works with Better Auth. The repository describes itself as: Convex + Better Auth + tRPC + Drizzle + TanStack Query + shadcn. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c6010f5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghbunrgnodenpmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sync Convex Auth loads about 3.3k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,103 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from udecode/kitcn at commit c6010f5, republished under its Apache-2.0 licence (© udecode). 1,103 words, ~3,260 tokens.
.claude/skills/sync-convex-auth/SKILL.md (or your agent's skills folder).Handle $ARGUMENTS.
Goal: compare https://github.com/zbeyens/convex-better-auth with its
upstream fork, sync that fork to upstream when it can be done without losing
fork-only work, extract every upstream change that matters to kitcn, then
delegate one coherent implementation slice to
$task so it
opens the PR.
When this sync needs durable goal state, use the project-owned sync template instead of the generic task template:
node .agents/skills/autogoal/scripts/create-goal-scratchpad.mjs \
--template sync-convex-auth \
--title "sync convex auth"This plan owns the upstream audit, classification ledger, ambiguity decisions,
fork-sync result, and delegated task prompt. The delegated implementation still
uses task; do not duplicate implementation PR machinery inside the sync plan.
zbeyens/convex-better-auth by fast-forward push or fork PR. Never force
push the fork.Use GitHub metadata to discover the upstream parent instead of guessing:
gh repo view zbeyens/convex-better-auth \
--json nameWithOwner,parent,defaultBranchRef \
--jq '{fork: .nameWithOwner, parent: .parent.nameWithOwner, branch: .defaultBranchRef.name}'If parent is missing or ambiguous, stop and ask for the upstream repo.
Before asking, try these fallbacks in order:
npm view @convex-dev/better-auth repository homepage --json
test -d ../convex-better-auth/.git && git -C ../convex-better-auth remote -v
gh repo view get-convex/better-auth --json nameWithOwner,defaultBranchRef,urlIf npm metadata or the local clone clearly point to one upstream repo, use that repo and continue instead of stopping.
Use a local clone for navigation, creating it only if missing. Identify the
remote that points at the fork and the remote that points at upstream by URL;
do not assume origin is the fork:
test -d ../convex-better-auth/.git || \
gh repo clone zbeyens/convex-better-auth ../convex-better-auth
git -C ../convex-better-auth remote -v
git -C ../convex-better-auth remote get-url <upstream-remote> >/dev/null 2>&1 || \
git -C ../convex-better-auth remote add <upstream-remote> https://github.com/<upstream-owner>/<repo-name>.git
git -C ../convex-better-auth fetch <fork-remote> --tags
git -C ../convex-better-auth fetch <upstream-remote> --tagsRecord:
Commands:
git -C ../convex-better-auth rev-list --count <fork-remote>/<fork-branch>..<upstream-remote>/<upstream-branch>
git -C ../convex-better-auth rev-list --count <upstream-remote>/<upstream-branch>..<fork-remote>/<fork-branch>
git -C ../convex-better-auth log --oneline --decorate <fork-remote>/<fork-branch>..<upstream-remote>/<upstream-branch>If $ARGUMENTS names a base or target ref, use it as the bound after proving it exists.
The sync audit must update zbeyens/convex-better-auth itself, not only KitCN.
Do this after recording the pre-sync range above, so the KitCN audit still knows
which upstream commits were imported.
If the fork is already at the upstream ref, record fork sync: already synced.
If the fork is behind and not ahead, fast-forward the fork default branch to the upstream ref and push:
git -C ../convex-better-auth merge-base --is-ancestor \
<fork-remote>/<fork-branch> <upstream-remote>/<upstream-branch>
git -C ../convex-better-auth push <fork-remote> \
refs/remotes/<upstream-remote>/<upstream-branch>:refs/heads/<fork-branch>
git -C ../convex-better-auth fetch <fork-remote> --tags
git -C ../convex-better-auth rev-parse <fork-remote>/<fork-branch>If the fast-forward push is rejected because the fork default branch is protected or direct push is not allowed, open a PR in the fork instead:
git -C ../convex-better-auth switch -C sync-upstream-<date> \
<upstream-remote>/<upstream-branch>
git -C ../convex-better-auth push <fork-remote> \
HEAD:refs/heads/sync-upstream-<date>
gh pr create \
--repo zbeyens/convex-better-auth \
--base <fork-branch> \
--head zbeyens:sync-upstream-<date> \
--title "Sync upstream convex-better-auth" \
--body "Fast-forward fork to <upstream-owner>/<repo-name>@<upstream-ref>."If the fork is ahead of upstream or has diverged, stop and ask before merging, rebasing, or overwriting anything. Do not force push. Record:
already synced, fast-forward pushed,
fork PR opened, blocked: diverged, or blocked: push rejectedStart with a file summary:
git -C ../convex-better-auth diff --name-status \
<pre-sync-fork-ref>..<pre-sync-upstream-ref>Then read patches for relevant-looking files:
git -C ../convex-better-auth diff \
<pre-sync-fork-ref>..<pre-sync-upstream-ref> -- \
src package.json bun.lock tsconfig.json '*.md' \
':!**/dist/**' ':!**/build/**' ':!**/node_modules/**'Use gh compare when it gives cleaner commit/file metadata:
gh api \
repos/<upstream-owner>/<repo-name>/compare/<fork-owner>:<fork-branch>...<upstream-branch> \
--jq '.commits[] | {sha: .sha, message: .commit.message}'
gh api \
repos/<upstream-owner>/<repo-name>/compare/<fork-owner>:<fork-branch>...<upstream-branch> \
--jq '.files[] | {filename,status,patch}'If the compare is too large, group by subsystem first, then inspect the patches for likely auth-runtime impact.
Search local kitcn integration points:
rg -n "@convex-dev/better-auth|convexBetterAuth|getToken|convexClient|convex\\(|BetterAuth|better-auth|auth" \
packages www .agents docs tooling fixtures exampleSearch institutional notes before proposing work:
rg -i --files-with-matches \
"convex-better-auth|@convex-dev/better-auth|better-auth|auth|react-start|nextjs|jwt|jwks|session|cookie|schema|plugin|getToken" \
docs/solutions docs/plansRead relevant hits, especially notes about:
@convex-dev/better-auth reexports and wrapperskitcn/auth, kitcn/auth-client, kitcn/auth-nextjs, and
kitcn/auth-startpackages/kitcn/skills/kitcn/**Classify each commit or file group:
compatibility: required work to keep kitcn working with upstream auth,
Better Auth, Convex, framework, or package changes.security: auth correctness or security hardening kitcn should not miss.bugfix: upstream fix that maps to a kitcn runtime, provider, token, schema,
routing, or scaffold issue.feature: new upstream API, helper, framework support, or auth capability
kitcn can expose cleanly.cleanup: upstream change that lets kitcn delete a workaround, wrapper,
fallback, doc warning, copied logic, or special-case patch.docs: upstream change that only affects user-facing docs, setup guidance, or
skills.tests: upstream test coverage or harness changes.no-op: interesting upstream change with no kitcn action.For every non-no-op, include:
Use this relevance filter:
Pick the highest-leverage slice using this order:
If several relevant upstream fixes touch the same auth surface and do not conflict, delegate them together. If they touch separate surfaces, pick the highest-risk slice first.
If the winning slice touches published package code, the delegated task must
update the active changeset and run bun --cwd packages/kitcn build.
If it touches scaffold templates, the delegated task must run
bun run fixtures:sync and bun run fixtures:check.
If it touches auth runtime, client, provider, or query invalidation surfaces, the delegated task must follow the repo's auth verification lane. Do not import a slow upstream e2e suite unless the user explicitly approves it.
taskLoad $task with a prompt in this exact shape:
Implement this convex-better-auth sync opportunity.
Fork: zbeyens/convex-better-auth
Upstream: <upstream-owner>/<repo-name>
Range: <fork-ref>..<upstream-ref>
Behind: <count> commits
Fork sync: <already synced | fast-forward pushed | fork PR URL | blocked reason>
Opportunity: <one-sentence selected slice>
Class: <security | compatibility | bugfix | cleanup | agentic | feature | docs | tests>
Evidence:
- Upstream commits: <short commit list or summary>
- Upstream diff: <refs and files>
- Kitcn evidence: <local files and docs/solutions notes>
Implementation:
- <specific files or surfaces to inspect first>
- <expected code/doc/test shape>
- <anything explicitly ignored as irrelevant>
Acceptance:
- <focused tests/checks>
- <package build if packages/kitcn changes>
- <fixtures commands if scaffold output changes>
- open the PR after verification
Do not preserve obsolete auth workarounds if the upstream change removes the
need for them. Hard cut the hack.
Do not add optional slow e2e suites, broad examples, or dev-only upstream test
infrastructure unless the user approved that scope.Then follow task until the PR exists or a real blocker is proven.
Before delegation, keep the audit terse:
Fork: zbeyens/convex-better-auth
Upstream: <upstream-owner>/<repo-name>
Range: <fork-ref>..<upstream-ref>
Behind: <count>
Fork sync: <status and post-sync ref or PR URL>
| Class | Opportunity | Evidence | Decision |
| ------ | ----------- | -------- | -------- |
| bugfix | ... | ... | selected |
Delegating to task: <selected slice>If the right choice is ambiguous, stop and ask one pointed question. Example:
Upstream added a Playwright e2e suite that does not fix a current kitcn bug.
Do you want that pulled in, or should I ignore it and keep this sync to runtime
fixes only?After task finishes, use its final handoff format.
© udecode, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/sync-convex-auth of udecode/kitcn.
Open the folder on GitHubat commit c6010f5
Sync Convex Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sync Convex Auth this skilludecode/kitcn | 450 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| Email And Password Best Practicesever-works/ever-works | 158 | 3 repos | ~1.5k | Automated safety check: Pass | AGPL-3.0 | |
| Better Auth Security Best Practicesagutinbaigo28/financial-agent-api | 128 | — | ~2.7k | Automated safety check: Pass | None | |
| Organization Best Practicesever-works/ever-works | 158 | 2 repos | ~2.6k | Automated safety check: Pass | AGPL-3.0 |
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
ever-works/ever-works
Configure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication.
agutinbaigo28/financial-agent-api
Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…
ever-works/ever-works
Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin.
ever-works/ever-works
Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.
udecode/kitcn
Create a short annotated visual walkthrough from real final-state screenshots or rendered artifacts.
udecode/kitcn
Prevent feature creep when building software, apps, and AI-powered products.
udecode/kitcn
Repair an unreleased .changeset/.md file so it matches the real branch delta against main.
udecode/kitcn
Audit newer Convex npm releases against kitcn. An agent skill from udecode/kitcn.
udecode/kitcn
A skill your agent uses when working with Jotai X stores (createAtomStore), accessing state in components or callbacks, persisting state to cookies or localStorage
udecode/kitcn
Run a scoped Linear backlog autonomously as a sequence of maximal safe parallel batches by composing orchestrator, autogoal, and task.
Works with
Categories
Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes. Sync Convex Auth is an agent skill from udecode/kitcn. Sync zbeyens/convex-better-auth with upstream, then sync kitcn against upstream convex-better-auth changes.
Sync Convex Auth fits situations like: asked to run sync-convex-auth; compare the fork with upstream; PR the fork update when safe; audit commits the fork was behind on.
Run `npx skills add udecode/kitcn --skill sync-convex-auth -a claude-code`. Or copy the skill folder (.agents/skills/sync-convex-auth in udecode/kitcn) into .claude/skills/sync-convex-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add udecode/kitcn --skill sync-convex-auth -a codex`. Or copy the skill folder (.agents/skills/sync-convex-auth in udecode/kitcn) into .agents/skills/sync-convex-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add udecode/kitcn --skill sync-convex-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sync-convex-auth, .gemini/skills/sync-convex-auth, .github/skills/sync-convex-auth and .opencode/skills/sync-convex-auth in your project.
Going by SKILL.md and its folder, Sync Convex Auth needs the command-line tools its instructions call (git, gh, bun, rg, node and npm).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sync Convex Auth is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sync Convex Auth: Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), Email And Password Best Practices (ever-works/ever-works, 158 stars) and Better Auth Security Best Practices (agutinbaigo28/financial-agent-api, 128 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
udecode (a GitHub organization) maintains it in udecode/kitcn, which has 450 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.
Source: udecode/kitcn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.