Agent skill

Convex Setup Auth

by waynesutton in waynesutton/markdown-site

Set up Convex authentication with proper user management, identity mapping, and access control patterns.

MITAuto-check passedBackend & APIs

Install Convex Setup Auth

skills CLI
$ npx skills add waynesutton/markdown-site --skill convex-setup-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install waynesutton/markdown-site convex-setup-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/waynesutton/markdown-site.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/convex-setup-auth .claude/skills/convex-setup-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
convex-setup-auth
GitHub stars
628
Token cost
~1.4k tokens
SKILL.md length
258 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Set up Convex authentication with proper user management, identity mapping, and access control patterns.

  • Works in 3 steps: Ask the user which auth solution they… → If the repo already uses a provider,… → If the user has not chosen and the repo…
  • Implementing auth flows
  • SKILL.md covers When to Use, First Step: Choose the Auth…, Schema Setup and Core Helper Functions, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Convex Setup Auth is an agent skill from waynesutton/markdown-site. Set up Convex authentication with proper user management, identity mapping, and access control patterns. Use when implementing auth flows, setting up OAuth providers, or adding role-based access control.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and Authentication. It works with Auth0 and WorkOS. The repository describes itself as: An open-source publishing framework built for AI agents and developers to ship websites, docs, or blogs. Write markdown, sync from the terminal. Your content is instantly… The licence is MIT.

When your agent uses it

  • Implementing auth flows
  • Setting up OAuth providers
  • Adding role-based access control

Example prompts

  • “/convex-setup-auth”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Ask the user which auth solution they want, unless the repository already makes it obvious
  2. If the repo already uses a provider, continue with that provider unless the user wants to switch
  3. If the user has not chosen and the repo does not make it obvious, ask before proceeding

What it can do on your machine

Read from SKILL.md and the folder at commit 3872c59. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.convex.dev
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Convex Setup Auth loads about 1.4k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 258 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from waynesutton/markdown-site at commit 3872c59, republished under its MIT licence (© waynesutton). 258 words, ~1,450 tokens.

Download SKILL.mdSave it as .claude/skills/convex-setup-auth/SKILL.md (or your agent's skills folder).
name
convex-setup-auth
description
Set up Convex authentication with proper user management, identity mapping, and access control patterns. Use when implementing auth flows, setting up OAuth providers, or adding role-based access control.

Convex Authentication Setup

Implement secure authentication in Convex with user management and access control.

When to Use

  • Setting up authentication for the first time
  • Implementing user management (users table, identity mapping)
  • Creating authentication helper functions
  • Setting up auth providers (Convex Auth, Clerk, WorkOS AuthKit, Auth0, custom JWT)

First Step: Choose the Auth Provider

Do not assume a provider. Before writing setup code:

  1. Ask the user which auth solution they want, unless the repository already makes it obvious
  2. If the repo already uses a provider, continue with that provider unless the user wants to switch
  3. If the user has not chosen and the repo does not make it obvious, ask before proceeding

Common options:

  • Convex Auth: good default when the user wants auth handled directly in Convex
  • Clerk: use when the app already uses Clerk
  • WorkOS AuthKit: use when the app already uses WorkOS
  • Auth0: use when the app already uses Auth0
  • Custom JWT provider: use when integrating an existing auth system

Look for signals in the repo before asking:

  • Dependencies such as @clerk/*, @workos-inc/*, @auth0/*
  • Existing files such as convex/auth.config.ts, auth middleware, provider wrappers
  • Environment variables that clearly point at a provider

Schema Setup

typescript
// convex/schema.ts
import { defineSchema, defineTable } from "convex/server";
import { v } from "convex/values";

export default defineSchema({
  users: defineTable({
    tokenIdentifier: v.string(),
    name: v.string(),
    email: v.string(),
    pictureUrl: v.optional(v.string()),
    role: v.union(v.literal("user"), v.literal("admin")),
    createdAt: v.number(),
    updatedAt: v.optional(v.number()),
  })
    .index("by_token", ["tokenIdentifier"])
    .index("by_email", ["email"]),
});

Core Helper Functions

Get Current User
typescript
// convex/lib/auth.ts
import { QueryCtx, MutationCtx } from "./_generated/server";
import { Doc } from "./_generated/dataModel";

export async function getCurrentUser(
  ctx: QueryCtx | MutationCtx
): Promise<Doc<"users">> {
  const identity = await ctx.auth.getUserIdentity();
  if (!identity) throw new Error("Not authenticated");

  const user = await ctx.db
    .query("users")
    .withIndex("by_token", q =>
      q.eq("tokenIdentifier", identity.tokenIdentifier)
    )
    .unique();

  if (!user) throw new Error("User not found");
  return user;
}

export async function getCurrentUserOrNull(
  ctx: QueryCtx | MutationCtx
): Promise<Doc<"users"> | null> {
  const identity = await ctx.auth.getUserIdentity();
  if (!identity) return null;

  return await ctx.db
    .query("users")
    .withIndex("by_token", q =>
      q.eq("tokenIdentifier", identity.tokenIdentifier)
    )
    .unique();
}

export async function requireAdmin(
  ctx: QueryCtx | MutationCtx
): Promise<Doc<"users">> {
  const user = await getCurrentUser(ctx);
  if (user.role !== "admin") throw new Error("Admin access required");
  return user;
}

User Creation/Upsert

typescript
// convex/users.ts
import { mutation } from "./_generated/server";
import { v } from "convex/values";

export const storeUser = mutation({
  args: {},
  handler: async (ctx) => {
    const identity = await ctx.auth.getUserIdentity();
    if (!identity) throw new Error("Not authenticated");

    const existingUser = await ctx.db
      .query("users")
      .withIndex("by_token", q =>
        q.eq("tokenIdentifier", identity.tokenIdentifier)
      )
      .unique();

    if (existingUser) {
      await ctx.db.patch(existingUser._id, { updatedAt: Date.now() });
      return existingUser._id;
    }

    return await ctx.db.insert("users", {
      tokenIdentifier: identity.tokenIdentifier,
      name: identity.name ?? "Anonymous",
      email: identity.email ?? "",
      pictureUrl: identity.pictureUrl,
      role: "user",
      createdAt: Date.now(),
    });
  },
});

Access Control Patterns

Resource Ownership
typescript
export const deleteTask = mutation({
  args: { taskId: v.id("tasks") },
  handler: async (ctx, args) => {
    const user = await getCurrentUser(ctx);
    const task = await ctx.db.get(args.taskId);
    if (!task) throw new Error("Task not found");
    if (task.userId !== user._id) throw new Error("You can only delete your own tasks");
    await ctx.db.delete(args.taskId);
  },
});
Team-Based Access
typescript
async function requireTeamAccess(
  ctx: MutationCtx,
  teamId: Id<"teams">
): Promise<{ user: Doc<"users">, membership: Doc<"teamMembers"> }> {
  const user = await getCurrentUser(ctx);
  const membership = await ctx.db
    .query("teamMembers")
    .withIndex("by_team_and_user", q =>
      q.eq("teamId", teamId).eq("userId", user._id)
    )
    .unique();

  if (!membership) throw new Error("You don't have access to this team");
  return { user, membership };
}

Checklist

  • Chosen the correct auth provider before writing setup code
  • Users table with tokenIdentifier index
  • getCurrentUser helper function
  • storeUser mutation for first sign-in
  • Authentication check in all protected functions
  • Authorization check for resource access
  • Clear error messages ("Not authenticated", "Unauthorized")
  • Client auth provider configured

Source: https://github.com/get-convex/agent-skills

© waynesutton, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/convex-setup-auth of waynesutton/markdown-site.

Open the folder on GitHubat commit 3872c59

Compare with similar skills

Convex Setup Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Convex Setup Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Convex Setup Auth this skillwaynesutton/markdown-site628—~1.4kAutomated safety check: PassMIT
Workosusenotra/notra255—~6.2kAutomated safety check: PassAGPL-3.0
Convex Setup Authvvedantb/eva101—~1.5kAutomated safety check: PassMIT
Convex AuthIgorWarzocha/Opencode-Workflows122—~744Automated safety check: PassNone
Convex Setup Authspokvulcan/poker-planning1148 repos~1.8kAutomated safety check: PassMIT
Frontmcp Authoritiesagentfront/frontmcp146—~7.1kAutomated safety check: PassApache-2.0

Similar skills

  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    255 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    vvedantb/eva

    Set up Convex authentication with proper user management, identity mapping, and access control patterns.

    101 GitHub stars~1.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Convex Auth

    IgorWarzocha/Opencode-Workflows

    Implement Convex authentication and authorization patterns with OIDC providers or Convex Auth.

    122 GitHub stars~744 tokensUpdated 8 mo ago
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    spokvulcan/poker-planning

    Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.

    114 GitHub starsUsed in 8 repos~1.8k tokens
    Backend & APIsAuto-check passed
  • Frontmcp Authorities

    agentfront/frontmcp

    A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.

    146 GitHub stars~7.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Securing Authentication

    ancoleman/ai-design-components

    Authentication, authorization, and API security implementation.

    526 GitHub stars~3.4k tokensUpdated 10 mo ago
    Backend & APIsAuto-check passed

More from waynesutton/markdown-site

All 17 skills in this repo
  • Convex Self Hosting

    waynesutton/markdown-site

    Integrate Convex static self hosting into existing apps using the latest upstream instructions from get-convex/self-hosting every time.

    628 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Robel Auth

    waynesutton/markdown-site

    Integrate and maintain Robelest Convex Auth in apps by always checking upstream before implementation.

    628 GitHub stars~4.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Migration Helper

    waynesutton/markdown-site

    Plan and execute Convex schema migrations safely, including adding fields, creating tables, and data transformations.

    628 GitHub starsUsed in 1 repo~958 tokens
    Auto-check passed
  • Convex Return Validators

    waynesutton/markdown-site

    Guide for when to use and when not to use return validators in Convex functions.

    628 GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Convex Doctor

    waynesutton/markdown-site

    Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories.

    628 GitHub stars~1.9k tokensUpdated 4 mo ago
    Auto-check passed
  • Convex Quickstart

    waynesutton/markdown-site

    Initialize a new Convex project from scratch or add Convex to an existing app.

    628 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Convex Setup Auth

What does Convex Setup Auth do?

Set up Convex authentication with proper user management, identity mapping, and access control patterns. Convex Setup Auth is an agent skill from waynesutton/markdown-site. Set up Convex authentication with proper user management, identity mapping, and access control patterns.

When should I use Convex Setup Auth?

Convex Setup Auth fits situations like: implementing auth flows; setting up OAuth providers; adding role-based access control.

How do I install Convex Setup Auth in Claude Code?

Run `npx skills add waynesutton/markdown-site --skill convex-setup-auth -a claude-code`. Or copy the skill folder (.claude/convex-setup-auth in waynesutton/markdown-site) into .claude/skills/convex-setup-auth in your project. Claude Code loads it when a task matches its description.

How do I install Convex Setup Auth in Codex?

Run `npx skills add waynesutton/markdown-site --skill convex-setup-auth -a codex`. Or copy the skill folder (.claude/convex-setup-auth in waynesutton/markdown-site) into .agents/skills/convex-setup-auth in your project. Codex loads it when a task matches its description.

Can I use Convex Setup Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waynesutton/markdown-site --skill convex-setup-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/convex-setup-auth, .gemini/skills/convex-setup-auth, .github/skills/convex-setup-auth and .opencode/skills/convex-setup-auth in your project.

What does Convex Setup Auth need to run?

SKILL.md names no scripts, command-line tools or credentials: Convex Setup Auth is instructions for the agent only.

Does Convex Setup Auth access the network?

SKILL.md names 2 domains. As links in the text: docs.convex.dev and github.com. This is read from the text; nothing was executed.

Is Convex Setup Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Convex Setup Auth use?

Convex Setup Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Convex Setup Auth use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Convex Setup Auth?

Skills that share tags, products or a category with Convex Setup Auth: Workos (usenotra/notra, 255 stars), Convex Setup Auth (vvedantb/eva, 101 stars), Convex Auth (IgorWarzocha/Opencode-Workflows, 122 stars) and Convex Setup Auth (spokvulcan/poker-planning, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Convex Setup Auth?

waynesutton (a GitHub user) maintains it in waynesutton/markdown-site, which has 628 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on May 20, 2026.

Source: waynesutton/markdown-site on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.