๐Ÿ”
AI EngineeringPython

Auth Security

by majiayu000

Auth Security is an AI Engineering skill for Claude Code, published by majiayu000 in spellbook.

265 stars26 forkson majiayu000/spellbookAdded 2026/09/02+1% in starsRepository updated 2026/08/31
agent-skillsai-agent-skillsai-agentsai-coding-assistantautomationclaudeclaude-codeclaude-code-skillscode-reviewcodexcodex-skillscross-runtimedeveloper-toolsmulti-agentproductivityprompt-engineeringskill-librarysoftware-developmentspellbookworkflows
Install in seconds
Install Auth Security
Copy Auth Security into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/majiayu000/spellbook/tree/main/skills/auth-security ~/.claude/skills/auth-security

Requires Node.js. Downloads this skill only โ€” not the rest of the repository โ€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/majiayu000/spellbook.git

Clones the whole repository, then copy the skillโ€™s own directory into your skills folder yourself.

In this catalog

Source file
skills/auth-security/SKILL.md in majiayu000/spellbook
Installs to
~/.claude/skills/auth-security
Collection
One of 25 skills cataloged from this repository
Category
AI Engineering โ€” 2631 skills

What Auth Security does

Auth Security covers OAuth 2.1 and JWT best practices for implementing login, API authorization, and token handling. Use it for PKCE flows, token rotation, secure storage, and JWT verification.

Auth Security is cataloged under AI Engineering on DirSkills. Auth Security comes from a repository tagged agent-skills, ai-agent-skills, ai-agents, ai-coding-assistant and automation.

Documentation

README

Auth Security

Core Principles

  • OAuth 2.1 โ€” Follow RFC 9700 (January 2025)
  • PKCE Required โ€” All clients must use PKCE
  • Short-lived Tokens โ€” Access tokens expire in 5-15 minutes
  • Token Rotation โ€” Refresh tokens are single-use
  • HttpOnly Storage โ€” Browser tokens in HttpOnly cookies
  • Explicit Algorithm โ€” Never trust JWT header algorithm
  • No backwards compatibility โ€” Delete deprecated auth flows

OAuth 2.1 Key Changes

Deprecated Flows (DO NOT USE)

Flow Status Replacement
Implicit Grant Removed Authorization Code + PKCE
Password Grant Removed Authorization Code + PKCE
Auth Code without PKCE Removed Must use PKCE

Required: Authorization Code + PKCE

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Auth Security

  • What else does majiayu000 publish alongside Auth Security?

    Auth Security is one of 25 skills that DirSkills catalogs from majiayu000/spellbook, the repository it ships in. Its siblings there include AGENTS.md Scaffold, API Design and Agents Md Optimize. Each one is a separate skill with its own page in this directory, installs the same way Auth Security does, and is maintained by majiayu000 in that same repository. The rest of the collection is listed on the majiayu000/spellbook page.

  • How does Auth Security compare to other AI Engineering skills?

    Auth Security ranks #2230 by stars among the 2631 AI Engineering skills in this catalog. The most-starred ones next to it are Architecture Decision Records, AI-First Engineering and Agentic OS. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Auth Security against them. Open each page to compare what they document and how they install.

More from majiayu000/spellbook

Auth Security is one of 25 skills cataloged on DirSkills from majiayu000/spellbook.

See all 25 skills โ†’
๐Ÿงญ
1h ago

AGENTS.md Scaffold

AGENTS.md Scaffold generates or updates repository-specific AGENTS.md files from repo evidence. It is used when a repo needs scoped agent instructions, validation commands, or directory-specific rules.
Automation
26526
๐Ÿ”Œ
1h ago

API Design

API Design covers REST, GraphQL, and gRPC best practices for defining contracts, versioning, pagination, errors, and idempotency. Use it when designing public or internal APIs and their schemas.
AI Engineering
26526
๐Ÿ› ๏ธ
1h ago

Agents Md Optimize

Agents Md Optimize audits a CLAUDE.md or AGENTS.md file, scores common instruction patterns, and applies approved fixes in place. Use it when you want to improve an agent instruction file, not just review it.
AI Engineering
26526
๐Ÿงช
1h ago

App User Story QA

App User Story QA turns a broad request to test an app into a tracked loop of feature inventory, code-backed expected behavior, and user-story tests. Use it to audit every surface, classify failures, and retest documented defects after fixes.
Quality
26526
๐Ÿ—๏ธ
1h ago

Architecture Foundation

Architecture Foundation turns architecture discussions into explicit boundaries, contracts, validation gates, and a small execution plan. Use it when designing or refactoring system structure, choosing module or service boundaries, or writing a spec before coding.
AI Engineering
26526
๐Ÿ—๏ธ
1h ago

Architecture Research

Architecture Research helps analyze real systems from source, docs, and runtime evidence before choosing a technical direction. Use it for architecture studies, system archaeology, build-vs-buy decisions, and reassessing earlier choices.
AI Engineering
26526