dragoon0x/everything-design-taste

authentication-flow

Login, signup, password reset, SSO, MFA, and authentication UX patterns.

First seen Jul 18, 2026

Installation

$ npx skills add dragoon0x/everything-design-taste --skill authentication-flow

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from dragoon0x/everything-design-taste · top by installs.

npx skills add dragoon0x/everything-design-taste

Browse all from dragoon0x/everything-design-taste

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 11
License LICENSE
Default branch main
Open issues 0
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,655 B
  • docs SUMMARY.md 99 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 2 installs

SKILL.md

Authentication Flows

Sign Up

  • Minimum fields: Email and password (or just email for magic link)
  • Social sign-in options above the form (Google, GitHub, Apple)
  • Password requirements shown proactively, not after failed attempt
  • Email verification via link, not code (less friction)

Log In

  • Email + password as default
  • "Remember me" checkbox
  • "Forgot password?" link visible near password field
  • Show/hide password toggle
  • Rate limit failed attempts (show "try again in X seconds")

Password Reset

  1. Enter email → 2. Check email → 3. Set new password → 4. Confirmed
  • Don't confirm whether the email exists (security)
  • Reset links expire (1 hour typical)
  • Invalidate old passwords on reset

Multi-Factor Authentication

  • SMS codes are the minimum (but weakest)
  • Authenticator apps are better (TOTP)
  • Passkeys/WebAuthn are best (no codes needed)
  • Recovery codes: show once, make user save them
  • Don't force MFA setup during onboarding (ask after first valuable action)

Single Sign-On

  • Prominent SSO buttons with correct brand colors and logos
  • "Continue with Google" not "Sign in with Google" (works for both login and signup)
  • Handle account linking (same email, different auth method)

Session Management

  • Show active sessions in settings
  • Allow remote logout
  • Auto-logout after inactivity (configurable for sensitive apps)
  • Extend session silently on activity (no popup interruptions)