Convex Setup Auth
waynesutton/markdown-site
Set up Convex authentication with proper user management, identity mapping, and access control patterns.
A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…
$ npx skills add usenotra/notra --skill workos -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install usenotra/notra workos --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/usenotra/notra.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/workos .claude/skills/workos && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "workos" agent skill from https://github.com/usenotra/notra/tree/main/.agents/skills/workos into .claude/skills/workos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workos", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/usenotra/notra/tree/main/.agents/skills/workosType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add usenotra/notra --skill workos -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install usenotra/notra workos --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usenotra/notra.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/workos .agents/skills/workos && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "workos" agent skill from https://github.com/usenotra/notra/tree/main/.agents/skills/workos into .agents/skills/workos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workos", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add usenotra/notra --skill workos -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install usenotra/notra workos --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usenotra/notra.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/workos .cursor/skills/workos && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "workos" agent skill from https://github.com/usenotra/notra/tree/main/.agents/skills/workos into .cursor/skills/workos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workos", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/usenotra/notra.git --path .agents/skills/workos--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add usenotra/notra --skill workos -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install usenotra/notra workos --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usenotra/notra.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/workos .gemini/skills/workos && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "workos" agent skill from https://github.com/usenotra/notra/tree/main/.agents/skills/workos into .gemini/skills/workos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workos", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install usenotra/notra workosInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add usenotra/notra --skill workos -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/usenotra/notra.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/workos .github/skills/workos && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "workos" agent skill from https://github.com/usenotra/notra/tree/main/.agents/skills/workos into .github/skills/workos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workos", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add usenotra/notra --skill workos -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install usenotra/notra workos --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usenotra/notra.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/workos .opencode/skills/workos && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "workos" agent skill from https://github.com/usenotra/notra/tree/main/.agents/skills/workos into .opencode/skills/workos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workos", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
workosA skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…
Workos is an agent skill from usenotra/notra. Use when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or migrating WorkOS — AuthKit, SSO/SAML, Directory Sync, RBAC, FGA, MFA, Vault, Audit Logs, Admin Portal, Pipes (Connected Apps), Feature Flags, Radar (bot/fraud detection), webhooks, Custom Domains, running the workos CLI in agent or sandbox sessions (WORKOSMODE, workos doctor), or migrating from Auth0, Clerk, Cognito, Firebase, Supabase…
Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 50 other files, including reference files (for example `evals/evals.json`, `references/workos-admin-portal.md` and `references/workos-api-authkit.md`).
It sits in Backend & APIs, covering Authentication, Authorization and RBAC and Webhooks. It works with WorkOS, Firebase, Supabase and Better Auth. The repository describes itself as: Notra is a modern GEO tool that asks ChatGPT, Claude and Gemini the questions your buyers ask. See if you show up, who shows up instead and how to fix it. The licence is AGPL-3.0.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e6483cd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
workos.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Workos loads about 6.2k tokens when it runs, and up to ~61k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 2,780 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from usenotra/notra at commit e6483cd, republished under its AGPL-3.0 licence (© usenotra). 2,780 words, ~6,242 tokens.
.claude/skills/workos/SKILL.md (or your agent's skills folder). This skill also uses 48 other files; get the full folder from GitHub.This file is a router, NOT the answer. Before responding to the user:
Exception: Widget requests use the workos-widgets skill via the Skill tool — it has its own multi-framework orchestration.
These apply regardless of which routing rule fires. They exist because the most common failure mode of past WorkOS agent interactions has been plausibly-shaped fabrication of CLI commands and Dashboard paths.
whoami, list_operations, query, and mutate — tool names may carry a client-specific prefix), prefer those tools for reading and changing workspace resources: they already run as the signed-in dashboard user, with no CLI install and no API key. The CLI remains the right surface for bootstrap, seeding, local project config, and diagnostics. The full decision guide is the "Choosing a surface" section of references/workos-management.md.references/workos-mcp.md first: identify the MCP client and requested configuration scope, and do not modify user-global agent configuration without explicit intent. Authentication that depends on a browser, credential store, or host certificates must be completed in the user's normal host shell. If no MCP server is configured and the user hasn't asked for one, do not divert the request into MCP setup — the CLI path in references/workos-management.md fully supports it.workos CLI commands. If the user asks about CLI support or you're about to suggest a command, verify the command tree first. The authoritative source is WORKOS_MODE=agent workos --help --json — it emits the complete registered command tree. Do not assume a create subcommand exists because list/get/delete do. See references/workos-management.md.WORKOS_MODE=agent when invoking the workos CLI from a coding-agent session. The CLI auto-detects most agent environments (CLAUDECODE, CLAUDE_CODE, CURSOR_AGENT, CODEX_SANDBOX, non-TTY), but the explicit env var is more reliable across sandbox configurations. See the WorkOS CLI in Coding-Agent Sessions section below.dashboard.workos.com/some/specific/path should not appear unless you have verified them against a docs page you just fetched. The Dashboard UI reorganizes; docs pages are stable. Cite the docs URL and describe the destination conceptually ("the Authorization page", "the directory's settings") instead of committing to a click-path.references/workos-management.md.The CLI resolves two independent axes: interaction mode (human/agent/ci) and output mode (human/json). The CLI auto-detects agent environments via known env vars (CLAUDECODE, CLAUDE_CODE, CURSOR_AGENT, CODEX_SANDBOX, CURSOR_TRACE_ID) and non-TTY detection, but explicit settings are more reliable across sandbox configurations.
Recommended preflight for any setup or debugging task:
WORKOS_MODE=agent workos doctor --json --skip-ai--skip-ai disables the doctor's AI-powered diagnosis pass, which requires an API key and network round-trip — neither is guaranteed in a sandbox. If --skip-ai errors as an unknown flag, the CLI is outdated — see references/workos-cli-upgrade.md. The structured JSON output is sufficient for programmatic triage.
This returns a structured JSON report with interactionMode ({ mode, source }) and hostExecution ({ ok, failures[] }) fields. Read the JSON before suggesting fixes.
Rules:
--json when parsing command output. It controls formatting only — it does not change CLI behavior.WORKOS_MODE=agent even when relaying human-readable messages. It controls prompts, browser launch, and host trust.HOST_EXECUTION_UNTRUSTED issue as a hard trust boundary. If the doctor report contains this issue (or hostExecution.ok is false), the current shell may be sandboxed. Auth, config, keychain, and API failures from this shell are not authoritative. Ask the user to re-run host-sensitive commands (workos auth login, workos doctor, workos env add) on their host shell before drawing conclusions.workos auth login) works in a sandbox. If auth is required, surface the manual URL/code fallback that the CLI prints, or ask the user to run workos auth login on their host shell.confirmation_required error. Known flags: --yes for workos api (mutating methods), --force for workos connection delete, workos directory delete, and workos debug reset. If unsure which flag a command expects, run workos <cmd> --help --json to check.error.recovery.hints array, where each hint has description, optional command, and optional hostShellRequired. Prefer those hints over guessing the next step.Legacy compatibility you may encounter:
WORKOS_NO_PROMPT=1 is a legacy alias that sets both agent interaction behavior AND JSON output. To migrate, set WORKOS_MODE=agent and pass --json to the command to preserve both behaviors. Using WORKOS_MODE=agent alone drops the implicit JSON formatting.WORKOS_FORCE_TTY=1 only affects output formatting; it does not change interaction mode.Terminology lookups — "what is X", "docs URL for X" — are handled by Rule 0 below, not this topic map. They route to
references/workos-terms.md.
references/{name}.md)| User wants to... | Read file |
|---|---|
| Install AuthKit in Next.js | references/workos-authkit-nextjs.md |
| Install AuthKit in React SPA | references/workos-authkit-react.md |
| Install AuthKit with React Router | references/workos-authkit-react-router.md |
| Install AuthKit with TanStack Start | references/workos-authkit-tanstack-start.md |
| Install AuthKit with SvelteKit | references/workos-authkit-sveltekit.md |
| Install AuthKit in vanilla JS | references/workos-authkit-vanilla-js.md |
| AuthKit architecture reference | references/workos-authkit-base.md |
| Add WorkOS Widgets | Load workos-widgets skill via Skill tool |
references/{name}.md)| User wants to... | Read file |
|---|---|
| Install AuthKit in Node.js backend | references/workos-node.md |
| Install AuthKit in Python | references/workos-python.md |
| Install AuthKit in .NET | references/workos-dotnet.md |
| Install AuthKit in Go | references/workos-go.md |
| Install AuthKit in Ruby | references/workos-ruby.md |
| Install AuthKit in PHP | references/workos-php.md |
| Install AuthKit in PHP Laravel | references/workos-php-laravel.md |
| Install AuthKit in Kotlin | references/workos-kotlin.md |
| Install AuthKit in Elixir | references/workos-elixir.md |
references/{name}.md)| User wants to... | Read file |
|---|---|
| Configure Single Sign-On | references/workos-sso.md |
| Set up Directory Sync | references/workos-directory-sync.md |
| Implement RBAC / roles | references/workos-rbac.md |
| Encrypt data with Vault | references/workos-vault.md |
| Handle WorkOS Events / webhooks | references/workos-events.md |
| Set up Audit Logs | references/workos-audit-logs.md |
| Enable Admin Portal | references/workos-admin-portal.md |
| Add Multi-Factor Auth | references/workos-mfa.md |
| Configure email delivery | references/workos-email.md |
| Set up Custom Domains | references/workos-custom-domains.md |
| Set up IdP integration | references/workos-integrations.md |
| Implement FGA / fine-grained authz | references/workos-fga.md |
| Set up Pipes / Connected Apps | references/workos-pipes.md |
| Configure Feature Flags | references/workos-feature-flags.md |
| Set up Radar / fraud detection | references/workos-radar.md |
references/{name}.md)Feature topic files above include endpoint tables for their respective APIs. Use these API-only references when no feature topic exists:
| User wants to... | Read file |
|---|---|
| AuthKit API Reference | references/workos-api-authkit.md |
| Organization API Reference | references/workos-api-organization.md |
references/{name}.md)| User wants to... | Read file |
|---|---|
| Migrate from Auth0 | references/workos-migrate-auth0.md |
| Migrate from AWS Cognito | references/workos-migrate-aws-cognito.md |
| Migrate from Better Auth | references/workos-migrate-better-auth.md |
| Migrate from Clerk | references/workos-migrate-clerk.md |
| Migrate from Descope | references/workos-migrate-descope.md |
| Migrate from Firebase | references/workos-migrate-firebase.md |
| Migrate from Stytch | references/workos-migrate-stytch.md |
| Migrate from Supabase Auth | references/workos-migrate-supabase-auth.md |
| Migrate from the standalone SSO API | references/workos-migrate-the-standalone-sso-api.md |
| Migrate from other services | references/workos-migrate-other-services.md |
references/{name}.md)| User wants to... | Read file |
|---|---|
| Set up or recover the WorkOS MCP server | references/workos-mcp.md |
| Manage WorkOS resources (MCP server or CLI) | references/workos-management.md |
Upgrade the workos CLI to a newer version | references/workos-cli-upgrade.md |
Apply these rules in order. First match wins.
Triggers: Lookup-shaped phrasing — "what is X", "what does X mean", "docs URL for X", "where's the docs on X", "canonical link for X", "where do I configure X in the dashboard" — where X is a WorkOS-specific config field, endpoint, env var, or term. Examples: initiate_login_uri, "Sign-in endpoint", "Redirect URI", dashboard field names, WORKOS_* environment variables.
Do NOT fire Rule 0 for setup-shaped phrasing like "set up Vault", "enable Admin Portal", "configure MFA" — those route to Rule 3 (Feature-Specific).
Action:
references/workos-terms.md — a curated table mapping WorkOS terms to canonical docs URLs.For terminology lookups, do NOT WebFetch llms.txt or guess workos.com/docs/... URLs before reading the terms file. (Rules 8 and 9 use llms.txt for different purposes — this prohibition is scoped to Rule 0 only.)
Why this wins: Terminology lookups happen independent of feature/framework/migration context. They need to short-circuit routing, not fall through to "Vague or General" (Rule 8).
Triggers: User mentions migrating FROM another provider (Auth0, Clerk, Cognito, Firebase, Supabase, Stytch, Descope, Better Auth, standalone SSO API).
Action: Read references/workos-migrate-[provider].md where [provider] matches the source system. If provider is not in the table, read references/workos-migrate-other-services.md.
Why this wins: Migration context overrides feature-specific routing because users need provider-specific data export and transformation steps.
Triggers: User explicitly asks about "API endpoints", "request format", "response schema", "API reference", or mentions inspecting HTTP details.
Action: For features with topic files (SSO, Directory Sync, RBAC, Vault, Events, Audit Logs, Admin Portal), read the feature topic file — it includes an endpoint table. For AuthKit or Organization APIs, read references/workos-api-[domain].md.
Why this wins: API references are low-level; feature topics are high-level but include endpoint tables for quick reference.
Triggers: User mentions a specific WorkOS feature by name (SSO, MFA, Directory Sync, Audit Logs, Vault, RBAC, FGA, Admin Portal, Custom Domains, Events, Integrations, Email, Pipes, Feature Flags, Radar).
Action: Read references/workos-[feature].md where [feature] is the lowercase slug (sso, mfa, directory-sync, audit-logs, vault, rbac, fga, admin-portal, custom-domains, events, integrations, email, pipes, feature-flags, radar).
Exception: Widget requests load the workos-widgets skill via the Skill tool — it has its own orchestration.
Disambiguation: If user mentions BOTH a feature and "API", route to the feature topic file (it includes endpoints). If they mention MULTIPLE features, route to the MOST SPECIFIC one first (e.g., "SSO with MFA" → route to SSO; user can request MFA separately). If user mentions "FGA" or "fine-grained authorization", route to workos-fga — NOT workos-rbac. RBAC is org-level roles; FGA is resource-scoped roles on top of RBAC.
Special case — IdP group → role mapping: If the user asks about mapping Entra / Azure AD / Okta / Google Workspace / SCIM / directory / SSO groups to WorkOS roles (regardless of exact phrasing), read BOTH workos-rbac.md AND the source-specific reference:
workos-directory-sync.mdworkos-sso.mdBoth files now have a canonical recipe. Do not answer from memory or paraphrase dashboard menu paths — the docs don't commit to exact click-paths, so neither should you. This mapping is not a WorkOS CLI operation; if asked for a CLI command, state that it's not in the CLI and link the docs.
Triggers: User mentions authentication setup, login flow, sign-up, session management, or explicitly says "AuthKit" WITHOUT mentioning a specific feature like SSO or MFA.
Action: Detect framework and language using the priority-ordered checks below. Read the corresponding reference file.
Disambiguation:
workos-sso (#3) — feature wins over framework.Check in this exact order. First match wins:
1. `@tanstack/start` in package.json dependencies
→ Read: references/workos-authkit-tanstack-start.md
2. `@sveltejs/kit` in package.json dependencies
→ Read: references/workos-authkit-sveltekit.md
3. `react-router` or `react-router-dom` in package.json dependencies
→ Read: references/workos-authkit-react-router.md
4. `next.config.js` OR `next.config.mjs` OR `next.config.ts` exists in project root
→ Read: references/workos-authkit-nextjs.md
5. (`vite.config.js` OR `vite.config.ts` exists) AND `react` in package.json dependencies
→ Read: references/workos-authkit-react.md
6. NONE of the above detected
→ Read: references/workos-authkit-vanilla-js.mdIf the project is NOT a JavaScript/TypeScript frontend framework, check:
1. `pyproject.toml` OR `requirements.txt` OR `setup.py` exists
→ Read: references/workos-python.md
2. `go.mod` exists
→ Read: references/workos-go.md
3. `Gemfile` exists OR `config/routes.rb` exists
→ Read: references/workos-ruby.md
4. `composer.json` exists AND `laravel/framework` in dependencies
→ Read: references/workos-php-laravel.md
5. `composer.json` exists (without Laravel)
→ Read: references/workos-php.md
6. `*.csproj` OR `*.sln` exists
→ Read: references/workos-dotnet.md
7. `build.gradle.kts` OR `build.gradle` exists
→ Read: references/workos-kotlin.md
8. `mix.exs` exists
→ Read: references/workos-elixir.md
9. `package.json` exists with `express` / `fastify` / `hono` / `koa` (backend JS)
→ Read: references/workos-node.mdWhy this order: TanStack, SvelteKit, and React Router are MORE specific than Next.js/Vite+React. A project can have both Next.js AND React Router; in that case, React Router wins because it's more specific. Vanilla JS is the fallback when no framework is detected. Backend languages are checked when no frontend framework is found.
Edge case — multiple frameworks detected: If you detect conflicting signals (e.g., both next.config.js and @tanstack/start), ASK the user which one they want to use. Do NOT guess.
Edge case — framework unclear from context: If the user says "add login" but you cannot scan files (remote repo, no access), ASK: "Which framework/language are you using?" Do NOT default without confirmation.
Triggers: User mentions connecting to external IdPs, configuring third-party integrations, or asks "how do I integrate with [provider]".
Action: Read references/workos-integrations.md.
Why separate from SSO: SSO covers the authentication flow; Integrations covers IdP configuration and connection setup. If user mentions BOTH ("set up Google SSO"), route to SSO (#3) — it will reference Integrations where needed.
Triggers: User asks to install or configure the WorkOS MCP server, choose a configuration scope, or reports that WorkOS MCP tools are missing, unauthenticated, unavailable, or interrupted during startup.
Action: Read references/workos-mcp.md. It routes setup and recovery through the canonical WorkOS MCP documentation, protects configuration scope and OAuth credentials, and identifies authentication steps that must run in the user's normal host shell.
Why this wins: MCP setup happens before MCP tools are callable. It requires configuration-scope and host-trust checks that ordinary workspace-management guidance does not cover.
Triggers: User mentions managing WorkOS resources (organizations, users, roles, permissions), seeding data, or CLI management commands.
Action: Read references/workos-management.md. It opens with a surface-choice guide: prefer connected WorkOS MCP tools for workspace reads/writes, and the CLI for bootstrap, seeding, local config, CI, and diagnostics. Read it even when MCP tools are present — it maps which operations live on which surface.
Sub-case — CLI upgrade: If the user reports an outdated workos CLI (workos --version shows an old release, unknown command errors after following recent docs, or asks "how do I update the workos CLI?"), read references/workos-cli-upgrade.md instead. Do NOT guess the latest version — that file tells you to instruct the user to run npm view workos version.
Triggers: User says "help with WorkOS", "WorkOS setup", "what can WorkOS do", or provides no feature-specific context.
Action:
Do NOT guess a feature — force disambiguation by showing options.
Triggers: None of the above rules match, OR the request is genuinely ambiguous.
Action:
Route to the MOST SPECIFIC reference first. Example: "SSO with MFA and directory sync" → route to workos-sso first. After completing SSO setup, the user can request MFA and Directory Sync separately.
Route to the feature topic file — it includes an endpoint table. Example: "SSO API endpoints" → workos-sso.md.
Route to the feature reference (#3), not back to AuthKit installation. Example: "I'm using AuthKit in Next.js and want to add SSO" → workos-sso.md.
Route to Integrations (#5). Example: "How do I connect Okta?" → workos-integrations.md.
Route to the feature reference (#3). Example: "Set up Okta SSO" → workos-sso.md (it will reference Integrations for Okta setup).
If you cannot detect framework and the user hasn't specified, ASK: "Which framework/language are you using?" Do NOT default without confirmation.
If detection finds conflicting signals (e.g., both Next.js and TanStack Start configs), ASK: "I see both [framework A] and [framework B]. Which one do you want to use for AuthKit?"
Follow step #8 (Vague or General Request): fetch llms.txt, show options, and force disambiguation.
© usenotra, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 48 other files (references) in .agents/skills/workos of usenotra/notra.
Open the folder on GitHubat commit e6483cd
Workos next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Workos this skillusenotra/notra | 256 | — | ~6.2k | Automated safety check: Pass | AGPL-3.0 | |
| Convex Setup Authwaynesutton/markdown-site | 628 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Frontmcp Authoritiesagentfront/frontmcp | 146 | — | ~7.1k | Automated safety check: Pass | Apache-2.0 | |
| Convex Setup Authvvedantb/eva | 101 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Convex AuthIgorWarzocha/Opencode-Workflows | 122 | — | ~744 | Automated safety check: Pass | None | |
| Insforge Integrationsaiskillstore/marketplace | 430 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 |
waynesutton/markdown-site
Set up Convex authentication with proper user management, identity mapping, and access control patterns.
agentfront/frontmcp
A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.
vvedantb/eva
Set up Convex authentication with proper user management, identity mapping, and access control patterns.
IgorWarzocha/Opencode-Workflows
Implement Convex authentication and authorization patterns with OIDC providers or Convex Auth.
aiskillstore/marketplace
A skill your agent uses when wiring an external auth provider (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) into InsForge for JWT-based RLS, or when adding the OKX x402 payment facilitator for…
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
usenotra/notra
Quick-reference card for all ponytail modes, skills, and commands.
usenotra/notra
Guides and best practices for working with Lakebase Postgres, the database behind Neon.
usenotra/notra
Expert guidance for Satori, the library that converts JSX/HTML and CSS into SVG (the engine behind dynamic Open Graph images and social cards).
usenotra/notra
A skill your agent uses when the user is implementing, embedding, or debugging a WorkOS Widget — specifically the User Management, User Profile, Admin Portal SSO Connection, or Admin Portal Domain…
usenotra/notra
Modeling a user's pricing into an Autumn catalog — deciding the structure (plans, variants, add-ons, licenses, credit systems, pooled balances) before writing config, then filling in the numbers.
usenotra/notra
Repo file-organization convention for TypeScript projects. An agent skill from usenotra/notra.
Categories
A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…. Workos is an agent skill from usenotra/notra.
Workos fits situations like: the user asks for a WorkOS docs URL; dashboard field (Sign-in endpoint; initiateloginuri; WORKOS env vars).
Run `npx skills add usenotra/notra --skill workos -a claude-code`. Or copy the skill folder (.agents/skills/workos in usenotra/notra) into .claude/skills/workos in your project. Claude Code loads it when a task matches its description.
Run `npx skills add usenotra/notra --skill workos -a codex`. Or copy the skill folder (.agents/skills/workos in usenotra/notra) into .agents/skills/workos in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add usenotra/notra --skill workos -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workos, .gemini/skills/workos, .github/skills/workos and .opencode/skills/workos in your project.
Going by SKILL.md and its folder, Workos needs the command-line tools its instructions call (npm). Our summary lists: Python 3; Node.js.
SKILL.md names 1 domain. As links in the text: workos.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Workos is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 55k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Workos: Convex Setup Auth (waynesutton/markdown-site, 628 stars), Frontmcp Authorities (agentfront/frontmcp, 146 stars), Convex Setup Auth (vvedantb/eva, 101 stars) and Convex Auth (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
usenotra (a GitHub organization) maintains it in usenotra/notra, which has 256 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.
Source: usenotra/notra on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.