This skill should be used when the user asks to "add authentication", "protect an endpoint", "implement OAuth", "set up OIDC", "handle JWT tokens", "implement RBAC", "add permissions", "secure API routes", "implement 2FA", "add role-based access", or needs guidance on authentication flows, token management, or authorization patterns.
This skill should be used when the user asks to "add authentication", "protect an endpoint", "implement OAuth", "set up OIDC", "handle JWT tokens", "implement RBAC", "add permissions", "secure API routes", "implement 2FA", "add role-based access", or needs guidance on authentication flows, token management, or authorization patterns.
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Claude CodeNot declared
CursorNot declared
CodexNot declared
GitHub CopilotNot declared
WindsurfNot declared
Gemini CLINot declared
ClineNot declared
OpenCodeNot declared
Skill metadata
Parsed from SKILL.md frontmatter.
Version1.0.0
Package contents
Files included with this skill beyond the listing page.
skill mdSKILL.md5,471 B
docsSUMMARY.md356 B
History
First recorded snapshot · 0 installs
SKILL.md
Authentication & Authorization Patterns
Secure authentication flows, token management, and role-based access control.
Core Concepts
Concept
Description
Authentication
Verify identity (who you are)
Authorization
Verify permissions (what you can do)
OAuth 2.0
Delegated authorization framework
OIDC
Identity layer on top of OAuth 2.0
JWT
Stateless token format for claims
RBAC
Role-Based Access Control
Authentication Patterns
JWT Authentication Flow
1. User submits credentials
2. Server validates credentials
3. Server generates JWT (access + refresh tokens)
4. Store tokens in HttpOnly cookies (preferred) or secure storage
5. Client sends token with each request
6. Server validates token and extracts claims