Agent skill

Bkend Auth

by ww-w-ai in ww-w-ai/bkit-claude-code

bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.

Apache-2.0Auto-check: notesBackend & APIs

Install Bkend Auth

skills CLI
$ npx skills add ww-w-ai/bkit-claude-code --skill bkend-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ww-w-ai/bkit-claude-code bkend-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bkend-auth .claude/skills/bkend-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bkend-auth
GitHub stars
601
Token cost
~937 tokens
SKILL.md length
284 words
Files
1
Skills in repo
44
Repo updated
First seen
Licence
Apache-2.0

At a glance

bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.

  • Works in 3 steps: Search docs: search_docs with query… → Get examples: search_docs with query… → Generate code: AI generates REST API…
  • Tasks that involve Authentication
  • SKILL.md covers Auth Methods, JWT Token Structure, Password Policy and MCP Auth Workflow, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bkend Auth is an agent skill from ww-w-ai/bkit-claude-code. bkend.ai authentication — email/social login, JWT tokens, RBAC, session management. Triggers: bkend auth, bkend login, bkend signup, bkend JWT, bkend RBAC

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and Authorization and RBAC. The repository describes itself as: bkit Vibecoding Kit - PDCA methodology + Claude Code mastery for AI-native development. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve Authorization and RBAC

Example prompts

  • “/bkend-auth”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Glob, Grep, Bash, mcp__bkend__*

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Search docs: search_docs with query "email signup" or "social login"
  2. Get examples: search_docs with query "auth code examples"
  3. Generate code: AI generates REST API code based on search results

What it can do on your machine

Read from SKILL.md and the folder at commit 85b4913. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Bash
    • mcp__bkend__*

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bkend Auth loads about 937 tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 284 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~937

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Glob, Grep, Bash, mcp__bkend__*

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ww-w-ai/bkit-claude-code at commit 85b4913, republished under its Apache-2.0 licence (© ww-w-ai). 284 words, ~937 tokens.

Download SKILL.mdSave it as .claude/skills/bkend-auth/SKILL.md (or your agent's skills folder).
name
bkend-auth
description
bkend.ai authentication — email/social login, JWT tokens, RBAC, session management. Triggers: bkend auth, bkend login, bkend signup, bkend JWT, bkend RBAC
allowed-tools
Read, Write, Edit, Glob, Grep, Bash, mcp__bkend__*
classification
capability
classification-reason
Pattern guidance may overlap with model's built-in knowledge as it improves
deprecation-risk
medium
effort
medium
user-invocable
false
agent
bkit:bkend-expert
imports
${PLUGIN_ROOT}/templates/shared/bkend-patterns.md

bkend.ai Authentication & Security Guide

Auth Methods

MethodDescription
Email + PasswordEmail/password signup and login
Social (Google)OAuth 2.0 social login
Social (GitHub)OAuth 2.0 social login
Magic LinkEmail link login (no password)

JWT Token Structure

  • Access Token: 1 hour validity
  • Refresh Token: 7 days validity
  • Auto-refresh: POST /v1/auth/refresh

Password Policy

8+ characters, uppercase + lowercase + numbers + special characters

MCP Auth Workflow

bkend MCP does NOT have dedicated auth tools. Use this workflow:

  1. Search docs: search_docs with query "email signup" or "social login"
  2. Get examples: search_docs with query "auth code examples"
  3. Generate code: AI generates REST API code based on search results
Searchable Auth Docs
Doc IDContent
3_howto_implement_authSignup, login, token management guide
6_code_examples_authEmail, social, magic link code examples
Key Pattern
User: "Add social login"
  → search_docs(query: "social login implementation")
  → Returns auth guide with REST API patterns
  → AI generates social login code

REST Auth API (Core Endpoints)

For the complete endpoint list, use search_docs or check Live Reference.

MethodEndpointDescription
POST/v1/auth/email/signupSign up
POST/v1/auth/email/signinSign in
GET/v1/auth/meCurrent user
POST/v1/auth/refreshRefresh token
POST/v1/auth/signoutSign out
GET/POST/v1/auth/:provider/callbackSocial login callback
POST/v1/auth/password/reset/requestPassword reset
POST/v1/auth/password/reset/confirmConfirm reset
POST/v1/auth/password/changeChange password
GET/v1/auth/sessionsList sessions
DELETE/v1/auth/sessions/:sessionIdRemove session
DELETE/v1/auth/withdrawDelete account

Additional endpoints (MFA, invitations, user management): use search_docs or Live Reference.

RBAC (Role-Based Access Control)

GroupDescriptionScope
adminFull CRUDAll data
userAuthenticated userFull read, own write
selfOwner onlycreatedBy-based
guestUnauthenticatedRead only (usually)

RLS (Row Level Security)

  • Per-table row-level access control
  • 4-level policies: admin/user/self/guest
  • Auto-filtering based on createdBy field

Session Management

  • Per-device session tracking
  • GET /v1/auth/sessions - List sessions
  • DELETE /v1/auth/sessions/:sessionId - Remove session

Official Documentation (Live Reference)

For the latest authentication documentation, use WebFetch:

© ww-w-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/bkend-auth of ww-w-ai/bkit-claude-code.

Open the folder on GitHubat commit 85b4913

Compare with similar skills

Bkend Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bkend Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bkend Auth this skillww-w-ai/bkit-claude-code601—~937Automated safety check: NotesApache-2.0
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61810 repos~4.4kAutomated safety check: PassNone
Configuration Cryptogreenpau/caddy-security2.3k—~3.5kAutomated safety check: PassApache-2.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Authenticationcodewithmukesh/dotnet-claude-kit7561 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    618 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    756 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes

More from ww-w-ai/bkit-claude-code

All 44 skills in this repo
  • Audit

    ww-w-ai/bkit-claude-code

    View audit logs, decision traces, and session history for AI transparency.

    601 GitHub stars~1.6k tokensUpdated 13 days ago
    Auto-check: notes
  • Bkend Cookbook

    ww-w-ai/bkit-claude-code

    bkend.ai project tutorials (todo to SaaS) and common error troubleshooting.

    601 GitHub stars~891 tokensUpdated 13 days ago
    Auto-check: notes
  • Bkend Quickstart

    ww-w-ai/bkit-claude-code

    bkend.ai onboarding — MCP setup, resource hierarchy, tenant/user model, first project.

    601 GitHub stars~1.2k tokensUpdated 13 days ago
    Auto-check passed
  • Bkend Storage

    ww-w-ai/bkit-claude-code

    bkend.ai file storage — upload (presigned URL), download (CDN), visibility levels, buckets.

    601 GitHub stars~901 tokensUpdated 13 days ago
    Auto-check: notes
  • Bkit

    ww-w-ai/bkit-claude-code

    bkit plugin help - list available functions including /pdca (9-phase feature cycle), /sprint (8-phase feature container, v2.1.13), /control (Trust L0-L4 + SPRINTAUTORUNSCOPE), /bkit-explore, and 40+…

    601 GitHub stars~1.4k tokensUpdated 13 days ago
    Auto-check passed
  • Bkit Evals

    ww-w-ai/bkit-claude-code

    Run skill evals via evals/runner.js — wrapper validates skill names, captures stdout/stderr, persists JSON results.

    601 GitHub stars~1k tokensUpdated 13 days ago
    Auto-check: notes

Categories

Questions about Bkend Auth

What does Bkend Auth do?

bkend.ai authentication — email/social login, JWT tokens, RBAC, session management. Bkend Auth is an agent skill from ww-w-ai/bkit-claude-code.ai authentication — email/social login, JWT tokens, RBAC, session management.

When should I use Bkend Auth?

Bkend Auth fits situations like: tasks that involve Authentication; tasks that involve Authorization and RBAC.

How do I install Bkend Auth in Claude Code?

Run `npx skills add ww-w-ai/bkit-claude-code --skill bkend-auth -a claude-code`. Or copy the skill folder (skills/bkend-auth in ww-w-ai/bkit-claude-code) into .claude/skills/bkend-auth in your project. Claude Code loads it when a task matches its description.

How do I install Bkend Auth in Codex?

Run `npx skills add ww-w-ai/bkit-claude-code --skill bkend-auth -a codex`. Or copy the skill folder (skills/bkend-auth in ww-w-ai/bkit-claude-code) into .agents/skills/bkend-auth in your project. Codex loads it when a task matches its description.

Can I use Bkend Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ww-w-ai/bkit-claude-code --skill bkend-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bkend-auth, .gemini/skills/bkend-auth, .github/skills/bkend-auth and .opencode/skills/bkend-auth in your project.

What does Bkend Auth need to run?

SKILL.md names no scripts, command-line tools or credentials: Bkend Auth is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep, Bash, mcp__bkend__*.

Does Bkend Auth access the network?

SKILL.md names 1 domain. As links in the text: raw.githubusercontent.com. This is read from the text; nothing was executed.

Is Bkend Auth safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Bkend Auth use?

Bkend Auth is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bkend Auth use?

About 937 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bkend Auth?

Skills that share tags, products or a category with Bkend Auth: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 618 stars), Configuration Crypto (greenpau/caddy-security, 2.3k stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bkend Auth?

ww-w-ai (a GitHub organization) maintains it in ww-w-ai/bkit-claude-code, which has 601 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on September 27, 2026.

Source: ww-w-ai/bkit-claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.