Agent skill

Authentication Sessions

by WrongStack in WrongStack/WrongStack

Implement application sign-in, sessions and identity integration with explicit account/tenant authorization.

MITAuto-check passedBackend & APIs

Install Authentication Sessions

skills CLI
$ npx skills add WrongStack/WrongStack --skill authentication-sessions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack authentication-sessions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/authentication-sessions .claude/skills/authentication-sessions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authentication-sessions
GitHub stars
371
Token cost
~830 tokens
SKILL.md length
301 words
Files
1
Skills in repo
100
Repo updated
First seen
Licence
MIT

At a glance

Implement application sign-in, sessions and identity integration with explicit account/tenant authorization.

  • Works in 6 steps: Define trusted identity issuer, account… → Validate callback state/redirect and… → Keep server authorization on each… → …
  • Building OAuth/OIDC
  • SKILL.md covers Selection card, Overview, Rules and Workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Authentication Sessions is an agent skill from WrongStack/WrongStack. Implement application sign-in, sessions and identity integration with explicit account/tenant authorization. Use when building OAuth/OIDC, passkeys, password login or session renewal; use security-scanner for a requested defensive review.

Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect, Authentication and Vulnerability scanning. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Building OAuth/OIDC
  • Session renewal
  • Use security-scanner for a requested defensive review

Example prompts

  • “/authentication-sessions”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Define trusted identity issuer, account linkage, tenant scope and session ownership.
  2. Validate callback state/redirect and token issuer/audience/expiry using the supported library; access and identity tokens serve different…
  3. Keep server authorization on each operation/object; sign-in success or a client role claim alone cannot grant access.
  4. Choose cookie/token storage and CSRF protection for the actual browser/mobile architecture.
  5. Model refresh, concurrent requests, revocation, logout and account switch; stale renewal must not resurrect a logged-out session.
  6. Keep credentials/keys outside source/logs and use sandbox/local fixtures for auth integration checks.

What it can do on your machine

Read from SKILL.md and the folder at commit a744bdc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • rfc-editor.org
    • better-auth.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authentication Sessions loads about 830 tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 301 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~830

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit a744bdc, republished under its MIT licence (© WrongStack). 301 words, ~830 tokens.

Download SKILL.mdSave it as .claude/skills/authentication-sessions/SKILL.md (or your agent's skills folder).
name
authentication-sessions
description
Implement application sign-in, sessions and identity integration with explicit account/tenant authorization. Use when building OAuth/OIDC, passkeys, password login or session renewal; use security-scanner for a requested defensive review.
trigger
Implement application sign-in, sessions and identity integration with explicit account/tenant authorization. Use when building OAuth/OIDC, passkeys, password…
version
1.0.1
required-capabilities
filesystem.read
optional-capabilities
filesystem.write, execution.shell, verification.run, web.research
metadata.routing-group
backend
metadata.domain
product

Authentication Sessions

Selection card

  • Task: Build login, session rotation and revocation. / TR: Giriş, oturum yenileme ve iptal kur.
  • Start: Locate the endpoint, schema, authentication boundary and caller.
  • Finish: apply the acceptance checks below; report observed results and unresolved constraints.

Overview

Implement application sign-in, sessions and identity integration with explicit account/tenant authorization.

Checked 2026-10-09: Better Auth 1.7.7 and jose 6.2.12. Use current provider/library contracts and OAuth security guidance; an OAuth draft is not automatically a stable replacement for the deployed protocol.

Rules

  1. Define trusted identity issuer, account linkage, tenant scope and session ownership.
  2. Validate callback state/redirect and token issuer/audience/expiry using the supported library; access and identity tokens serve different roles.
  3. Keep server authorization on each operation/object; sign-in success or a client role claim alone cannot grant access.
  4. Choose cookie/token storage and CSRF protection for the actual browser/mobile architecture.
  5. Model refresh, concurrent requests, revocation, logout and account switch; stale renewal must not resurrect a logged-out session.
  6. Keep credentials/keys outside source/logs and use sandbox/local fixtures for auth integration checks.

Workflow

  1. Inspect existing auth/provider/session storage and route consumers.
  2. Resolve current stable library/provider compatibility and define the state transitions.
  3. Implement callback/session flows and server authorization with explicit errors.
  4. Test expiry, rejection, retry, stale refresh, logout and two-user/tenant isolation.
  5. Exercise the actual login/logout journey and report provider/device gaps.

Before returning

Issuer/session/account contracts explicit; server authorization and logout/refresh races checked; real flow and test boundaries recorded.

Sources

Versioned facts checked 2026-10-09; refresh authoritative sources before new installs/upgrades. OAuth current practice, Better Auth.

Skills in scope

  • api-design — api design contracts and verification.
  • react-native-expo — build and upgrade React Native or Expo applications with navigation, native modules and verified platform integration.
  • database-development — implement database access, models and queries with explicit consistency, transactions and bounded results.
  • testing — testing contracts and verification.

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/core/skills/authentication-sessions of WrongStack/WrongStack.

Open the folder on GitHubat commit a744bdc

Compare with similar skills

Authentication Sessions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authentication Sessions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authentication Sessions this skillWrongStack/WrongStack371—~830Automated safety check: PassMIT
Quarkus Securityaffaan-m/ECC276k1 repos~3.1kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61810 repos~4.4kAutomated safety check: PassNone
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Authenticationcodewithmukesh/dotnet-claude-kit7561 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Quarkus Security

    affaan-m/ECC

    Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…

    276k GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    618 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    756 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes

More from WrongStack/WrongStack

All 100 skills in this repo
  • Tech Stack

    WrongStack/WrongStack

    Validate and upgrade dependencies against live registries and official migration guides in any ecosystem.

    371 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Skill Creator

    WrongStack/WrongStack

    Create, improve and validate WrongStack SKILL.md bundles with precise discovery, progressive resources and current runtime contracts.

    371 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Bug Hunter

    WrongStack/WrongStack

    A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

    371 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    371 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    371 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    371 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Authentication Sessions

What does Authentication Sessions do?

Implement application sign-in, sessions and identity integration with explicit account/tenant authorization. Authentication Sessions is an agent skill from WrongStack/WrongStack. Implement application sign-in, sessions and identity integration with explicit account/tenant authorization.

When should I use Authentication Sessions?

Authentication Sessions fits situations like: building OAuth/OIDC; session renewal; use security-scanner for a requested defensive review.

How do I install Authentication Sessions in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill authentication-sessions -a claude-code`. Or copy the skill folder (packages/core/skills/authentication-sessions in WrongStack/WrongStack) into .claude/skills/authentication-sessions in your project. Claude Code loads it when a task matches its description.

How do I install Authentication Sessions in Codex?

Run `npx skills add WrongStack/WrongStack --skill authentication-sessions -a codex`. Or copy the skill folder (packages/core/skills/authentication-sessions in WrongStack/WrongStack) into .agents/skills/authentication-sessions in your project. Codex loads it when a task matches its description.

Can I use Authentication Sessions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill authentication-sessions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authentication-sessions, .gemini/skills/authentication-sessions, .github/skills/authentication-sessions and .opencode/skills/authentication-sessions in your project.

What does Authentication Sessions need to run?

SKILL.md names no scripts, command-line tools or credentials: Authentication Sessions is instructions for the agent only.

Does Authentication Sessions access the network?

SKILL.md names 2 domains. As links in the text: rfc-editor.org and better-auth.com. This is read from the text; nothing was executed.

Is Authentication Sessions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authentication Sessions use?

Authentication Sessions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authentication Sessions use?

About 830 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authentication Sessions?

Skills that share tags, products or a category with Authentication Sessions: Quarkus Security (affaan-m/ECC, 276k stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 618 stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authentication Sessions?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 371 GitHub stars. The repository holds 100 skills in this directory. The repository was last updated on October 10, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.