Agent skill

Authentication Patterns

by zebbern in zebbern/claude-code-guide

Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes.

MITAuto-check passedBackend & APIs

Install Authentication Patterns

skills CLI
$ npx skills add zebbern/claude-code-guide --skill authentication-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zebbern/claude-code-guide authentication-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/authentication-patterns .claude/skills/authentication-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authentication-patterns
GitHub stars
4.6k
Token cost
~2k tokens
SKILL.md length
748 words
Files
1
Skills in repo
46
Repo updated
First seen
Licence
MIT

At a glance

Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes.

  • Implementing auth
  • SKILL.md covers WHEN_TO_USE, AUTH_APPROACHES, JWT_BEST_PRACTICES and PROVIDER_PATTERNS, plus 2 more sections
  • Needs GITHUB_CLIENT_SECRET
  • Reviewing auth flows

What it does

Authentication Patterns is an agent skill from zebbern/claude-code-guide. Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and Security review. It works with Supabase. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.

When your agent uses it

  • Implementing auth
  • Reviewing auth flows
  • Choosing auth providers

Example prompts

  • “/authentication-patterns”

Requirements

  • A credential in GITHUB_CLIENT_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 4698e3b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authentication Patterns loads about 2k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 748 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zebbern/claude-code-guide at commit 4698e3b, republished under its MIT licence (© zebbern). 748 words, ~2,013 tokens.

Download SKILL.mdSave it as .claude/skills/authentication-patterns/SKILL.md (or your agent's skills folder).
name
authentication-patterns
description
Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.

Authentication Patterns Skill

Reference for implementing secure, production-ready authentication.

WHEN_TO_USE

Apply this skill when implementing authentication in a project, reviewing existing auth flows for security issues, choosing between auth providers, or migrating between auth strategies. Use the security checklist before shipping any auth-related change.

AUTH_APPROACHES

ApproachHow It WorksBest ForDrawbacks
Session-basedServer stores session in DB/Redis, client holds session ID cookieTraditional server-rendered apps, apps needing instant revocationRequires server-side storage, harder to scale horizontally without shared store
JWT (stateless)Server signs token, client sends it on each requestAPI-first apps, microservices, mobile clientsCannot revoke without blocklist, token size grows with claims
OAuth 2.0 / OIDCDelegates auth to external provider (Google, GitHub, etc.)Social login, enterprise SSO, reducing auth responsibilityMore complex flow, depends on external provider availability
Passkeys / WebAuthnCryptographic key pair, no passwordsHigh-security apps, passwordless UXLimited browser support legacy, user education needed
Decision Guide
  • Server-rendered app with simple needs → Session-based
  • SPA or mobile app calling APIs → JWT with refresh token rotation
  • Want social login or SSO → OAuth 2.0 / OIDC
  • Greenfield with modern UX goals → Passkeys + OAuth fallback

JWT_BEST_PRACTICES

Token Lifecycle
Login → Access Token (short-lived) + Refresh Token (long-lived, rotated)
  │
  ├─ Access Token: 15 min expiry, sent via httpOnly cookie or Authorization header
  │
  └─ Refresh Token: 7-30 day expiry, stored in httpOnly secure cookie
       │
       └─ On use: issue new access + new refresh token, invalidate old refresh token
Rules
  • [P0-MUST] Set short expiry on access tokens (15 minutes or less).
  • [P0-MUST] Store tokens in httpOnly, Secure, SameSite=Lax cookies — never in localStorage or sessionStorage.
  • [P0-MUST] Implement refresh token rotation — each refresh token is single-use.
  • [P0-MUST] Maintain a server-side blocklist for revoked refresh tokens.
  • [P1-SHOULD] Include only essential claims in JWT payload (sub, iat, exp, role). Keep it small.
  • [P1-SHOULD] Use asymmetric signing (RS256 or ES256) for distributed systems; symmetric (HS256) for single-service only.
  • [P1-SHOULD] Validate iss, aud, and exp claims on every request.
  • [P2-MAY] Use JWE (encrypted JWT) when token payload contains sensitive data.
Token Storage Comparison
StorageXSS SafeCSRF SafeRecommendation
httpOnly cookieYesNo (needs CSRF token)Recommended
localStorageNoYesNever use for auth tokens
sessionStorageNoYesNever use for auth tokens
In-memory (JS variable)YesYesOK for SPAs, lost on refresh

PROVIDER_PATTERNS

Comparison
ProviderTypeBest ForPricingKey Features
NextAuth / Auth.jsOSS libraryNext.js apps wanting full controlFree80+ providers, DB adapters, self-hosted
ClerkManaged serviceFast launch, pre-built UI, user managementFree tier, then per-MAUDrop-in components, user dashboard, org support
Supabase AuthManaged (part of Supabase)Apps already using Supabase for DB/storageFree tier, then per-MAURow-level security integration, magic links, SSO
LuciaOSS libraryFull control, minimal abstractionFreeSession-based, framework-agnostic, type-safe
When to Use Each
  • NextAuth / Auth.js: You want provider flexibility, self-hosting, and database session control. Best when you need custom flows.
  • Clerk: You want auth done fast with pre-built UI components. Best for MVPs and teams that don't want to build auth UI.
  • Supabase Auth: You're already using Supabase. Auth integrates with RLS policies for row-level security.
  • Lucia: You want a minimal, type-safe session library without framework lock-in.
Show full SKILL.md (278 more words)Show less
NextAuth.js Setup Pattern
typescript
// app/api/auth/[...nextauth]/route.ts
import NextAuth from "next-auth";
import GitHub from "next-auth/providers/github";
import { PrismaAdapter } from "@auth/prisma-adapter";
import { prisma } from "@/lib/prisma";

export const { handlers, auth, signIn, signOut } = NextAuth({
  adapter: PrismaAdapter(prisma),
  providers: [
    GitHub({
      clientId: process.env.GITHUB_CLIENT_ID!,
      clientSecret: process.env.GITHUB_CLIENT_SECRET!,
    }),
  ],
  callbacks: {
    session({ session, user }) {
      session.user.id = user.id;
      return session;
    },
  },
});

SECURITY_CHECKLIST

Before Shipping Auth
  • Rate limiting: Login endpoint limited to 5-10 attempts per minute per IP.
  • CSRF protection: Anti-CSRF tokens on all state-changing requests (or use SameSite=Lax cookies).
  • Password hashing: Using bcrypt (cost 12+) or argon2id — never MD5, SHA-1, or plain SHA-256.
  • HTTPS only: All auth endpoints served over TLS. Cookies have Secure flag.
  • Input validation: Email format, password length (min 8, max 128), no SQL/NoSQL injection vectors.
  • Account enumeration: Login and registration return the same response whether account exists or not.
  • Session invalidation: Logout invalidates server-side session/refresh token, not just client cookie.
  • MFA support: TOTP (authenticator app) or WebAuthn as second factor for sensitive accounts.
  • Password reset: Time-limited tokens (1 hour), single-use, sent over secure channel.
  • Audit logging: Log auth events (login, logout, failed attempts, password changes) with timestamp and IP.
Password Hashing
typescript
// Using bcrypt
import bcrypt from "bcrypt";

const SALT_ROUNDS = 12;

async function hashPassword(password: string): Promise<string> {
  return bcrypt.hash(password, SALT_ROUNDS);
}

async function verifyPassword(password: string, hash: string): Promise<boolean> {
  return bcrypt.compare(password, hash);
}
typescript
// Using argon2 (preferred for new projects)
import argon2 from "argon2";

async function hashPassword(password: string): Promise<string> {
  return argon2.hash(password, { type: argon2.argon2id });
}

async function verifyPassword(hash: string, password: string): Promise<boolean> {
  return argon2.verify(hash, password);
}

COMMON_MISTAKES

MistakeRiskFix
Storing JWT in localStorageXSS can steal tokensUse httpOnly cookies
Long-lived JWTs (days/weeks)Stolen token is valid for extended period15 min access token + refresh rotation
Missing CSRF protectionAttackers can forge requests from other sitesSameSite=Lax cookies + CSRF token
Weak password requirementsBrute force and credential stuffingMin 8 chars, check against breached password lists
Exposing user existence on loginAccount enumerationGeneric "Invalid credentials" message
Not rotating refresh tokensStolen refresh token grants indefinite accessSingle-use refresh tokens with rotation
Hardcoding secrets in sourceCredential leak via git historyUse environment variables, never commit secrets
Missing rate limiting on loginBrute force attacks5-10 attempts/min per IP, exponential backoff
Rolling your own cryptoSubtle vulnerabilitiesUse established libraries (bcrypt, argon2, jose)
Not validating JWT claimsToken misuse across servicesAlways verify iss, aud, exp

© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/authentication-patterns of zebbern/claude-code-guide.

Open the folder on GitHubat commit 4698e3b

Compare with similar skills

Authentication Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authentication Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authentication Patterns this skillzebbern/claude-code-guide4.6k—~2kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Supabasecurvenote/curvenote1695 repos~2.2kAutomated safety check: PassCustom licence
Security Reviewjewbetcha/opentrace11617 repos~3.1kAutomated safety check: NotesMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.5kAutomated safety check: NotesMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.4kAutomated safety check: NotesMIT

Similar skills

  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    169 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 17 repos~3.1k tokens
    SecurityAuto-check: notes
  • Security Review

    xu-xiang/everything-claude-code-zh

    当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。

    2k GitHub stars~2.5k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Review

    xu-xiang/everything-claude-code-zh

    在添加身份验证、处理用户输入、操作机密信息、创建 API 接口或实现支付/敏感功能时使用此技能。提供全面的安全自查清单和模式。

    2k GitHub stars~2.4k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check passed

More from zebbern/claude-code-guide

All 46 skills in this repo
  • Localization Toolkit

    zebbern/claude-code-guide

    This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…

    4.6k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Audit Flow

    zebbern/claude-code-guide

    Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

    4.6k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Chart Image

    zebbern/claude-code-guide

    Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.

    4.6k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Code To Diagram

    zebbern/claude-code-guide

    Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.

    4.6k GitHub stars~972 tokensUpdated today
    Auto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.6k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Data Viz Renderer

    zebbern/claude-code-guide

    Generate self-contained HTML/SVG infographics from JSON data, including stat cards, bar charts, flow diagrams, and mixed dashboards.

    4.6k GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Authentication Patterns

What does Authentication Patterns do?

Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Authentication Patterns is an agent skill from zebbern/claude-code-guide. Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes.

When should I use Authentication Patterns?

Authentication Patterns fits situations like: implementing auth; reviewing auth flows; choosing auth providers.

How do I install Authentication Patterns in Claude Code?

Run `npx skills add zebbern/claude-code-guide --skill authentication-patterns -a claude-code`. Or copy the skill folder (skills/authentication-patterns in zebbern/claude-code-guide) into .claude/skills/authentication-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Authentication Patterns in Codex?

Run `npx skills add zebbern/claude-code-guide --skill authentication-patterns -a codex`. Or copy the skill folder (skills/authentication-patterns in zebbern/claude-code-guide) into .agents/skills/authentication-patterns in your project. Codex loads it when a task matches its description.

Can I use Authentication Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill authentication-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authentication-patterns, .gemini/skills/authentication-patterns, .github/skills/authentication-patterns and .opencode/skills/authentication-patterns in your project.

What does Authentication Patterns need to run?

Going by SKILL.md and its folder, Authentication Patterns needs credentials named GITHUB_CLIENT_SECRET. Our summary lists: A credential in GITHUB_CLIENT_SECRET.

Does Authentication Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Authentication Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authentication Patterns use?

Authentication Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authentication Patterns use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authentication Patterns?

Skills that share tags, products or a category with Authentication Patterns: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Supabase (curvenote/curvenote, 169 stars), Security Review (jewbetcha/opentrace, 116 stars) and Security Review (xu-xiang/everything-claude-code-zh, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authentication Patterns?

zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,648 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 7, 2026.

Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.