better-auth

1.8k
mrgooniemrgoonie

Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.

193 days ago

auth-patterns

241
MadAppGangMadAppGang

Use when implementing authentication (JWT, sessions, OAuth), authorization (RBAC, ABAC), password hashing, MFA, or security best practices for backend services.

193 days ago

Authentication Testing Patterns

71
PramodDuttaPramodDutta

Comprehensive authentication testing including login flows, password policies, MFA, session management, account lockout, and SSO integration.

authenticationloginmfa+2
193 days ago

user-investigation

48
SCStelzSCStelz

Use this skill when asked to investigate a user account for security issues, suspicious activity, or compliance review. Triggers on keywords like "investigate user", "security investigation", "user investigation", "check user activity", "analyze sign-ins", or when a UPN/email is mentioned with investigation context. This skill provides comprehensive Entra ID user security analysis including sign-in anomalies, MFA status, device compliance, audit logs, security incidents, Identity Protection risk, and automated reports (HTML, markdown file, or inline chat).

193 days ago

authentication-tracing

48
SCStelzSCStelz

Use this skill when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins. Triggers on keywords like "trace authentication", "trace back to interactive MFA", "SessionId analysis", "token reuse", "geographic anomaly", "impossible travel", or when investigating suspicious sign-in locations. This skill provides forensic analysis of Entra ID authentication chains to distinguish legitimate activity from credential/token theft.

193 days ago

modern-auth-2026

43
curiositechcuriositech

Modern authentication implementation for 2026 - passkeys (WebAuthn), OAuth (Google, Apple), magic links, and cross-device sync. Use for passwordless-first authentication, social login setup, Supabase Auth, Next.js auth flows, and multi-factor authentication. Activate on "passkeys", "WebAuthn", "Google Sign-In", "Apple Sign-In", "magic link", "passwordless", "authentication", "login", "OAuth", "social login". NOT for session management without auth (use standard JWT docs), authorization/RBAC (use security-auditor), or API key management (use api-architect).

authenticationpasskeyswebauthn+5
193 days ago

standard-security-auth

41
salavendersalavender

Security & Authentication Specialist - Expert in JWT, cookie-based auth, MFA, and generic security patterns

193 days ago

authentication-patterns

31
melodic-softwaremelodic-software

Comprehensive authentication implementation guidance including JWT best practices, OAuth 2.0/OIDC flows, Passkeys/FIDO2/WebAuthn, MFA patterns, and secure session management. Use when implementing login systems, token-based auth, SSO, passwordless authentication, or reviewing authentication security.

193 days ago

authentication-oauth

29
omer-metinomer-metin

Expert guidance on authentication implementation including OAuth 2.0/OIDC, JWT tokens, session management, and secure password handling. Covers both implementing auth from scratch and integrating auth providers. Use when "implement authentication, oauth login, jwt tokens, session management, social login, password reset, multi-factor auth, refresh tokens, Working with Auth0, Clerk, NextAuth, Passport.js, authentication, oauth, jwt, session, security, login, password, mfa, oidc" mentioned.

193 days ago

auth-specialist

29
omer-metinomer-metin

Authentication and authorization expert for OAuth, sessions, JWT, MFA, and identity security. Use when "authentication flow, login system, oauth integration, jwt tokens, session management, password hashing, mfa setup, refresh tokens, social login, role-based access, authentication, authorization, oauth, oidc, jwt, sessions, mfa, passkeys, nextauth, supabase-auth, clerk" are mentioned.

193 days ago

auth

27
cosmixcosmix

Authentication and authorization patterns including OAuth2, JWT, RBAC/ABAC, session management, API keys, password hashing, and MFA. USE WHEN: Implementing login flows, access control, identity management, tokens, permissions, session handling, API key authentication, or MFA. DO NOT USE: For security vulnerability scanning (use /security-scan), for security audits (use /security-audit), for threat modeling (use /threat-model). TRIGGERS: login, logout, signin, signup, authentication, authorization, password, credential, token, JWT, OAuth, OAuth2, OIDC, SSO, SAML, session, cookie, RBAC, ABAC, permissions, roles, MFA, 2FA, TOTP, API key, PKCE.

193 days ago

kanidm-expert

25
Martinholovsky Claude Skills Generator Kanidm ExpertMartinholovsky Claude Skills Generator Kanidm Expert

Expert in the Kanidm modern identity management system specializing in user and group management, OAuth2/OIDC, LDAP, RADIUS, SSH key management, WebAuthn, and MFA. Deep expertise in secure authentication flows, credential policies, access control, and platform integrations. Use when implementing identity management, SSO, authentication systems, or securing access to infrastructure.

193 days ago

authentication-patterns

16
travisjneumantravisjneuman

OAuth 2.0, JWT, SSO, MFA, NextAuth/Clerk/Supabase Auth implementation patterns

193 days ago

authentication-security

13
williamzujkowskiwilliamzujkowski

Authentication security standards covering OAuth2 flows (authorization code, PKCE), JWT best practices (RS256, expiration), MFA (TOTP, WebAuthn), session management, and NIST 800-63B compliance for production systems

securityauthenticationoauth2+4
193 days ago

openvpn

9
TerminalSkillsTerminalSkills

Deploy and manage OpenVPN servers and clients. Use when a user asks to set up a VPN server, create client certificates, configure site-to-site tunnels, set up split tunneling, manage PKI with EasyRSA, harden OpenVPN security, automate client provisioning, configure routing and NAT, set up MFA for VPN, monitor connected clients, or troubleshoot VPN connectivity. Covers server deployment, PKI management, client configuration, and production hardening.

193 days ago

auth0-mfa

8
auth0auth0

Use when adding multi-factor authentication (MFA/2FA) or requiring additional verification for sensitive operations - covers step-up auth, adaptive MFA, and risk-based authentication with Auth0

193 days ago

better-auth

7
samhvw8samhvw8

TypeScript authentication framework (framework-agnostic). Features: email/password, OAuth (Google, GitHub, Discord), 2FA (TOTP, SMS), passkeys/WebAuthn, session management, RBAC, rate limiting, database adapters. Actions: implement, configure, secure authentication systems. Keywords: Better Auth, authentication, authorization, OAuth, email/password, 2FA, MFA, TOTP, passkeys, WebAuthn, session management, RBAC, rate limiting, database adapter, TypeScript auth, social login, Google auth, GitHub auth, Discord auth, email verification, password reset. Use when: implementing TypeScript auth, adding OAuth providers, setting up 2FA/MFA, managing sessions, configuring RBAC, building secure auth systems.

193 days ago

account-security

4
SylphxAISylphxAI

Account security - MFA, sessions, recovery. Use when protecting user accounts.

193 days ago

better-auth

4
hoadhhoadh

Add authentication with Better Auth (TypeScript). Use for email/password, OAuth providers (Google, GitHub), 2FA/MFA, passkeys/WebAuthn, sessions, RBAC, rate limiting.

193 days ago

better-auth

4
ngxtmngxtm

Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.

193 days ago

mfa-development-cooperation-aid

3
taivoptaivop

Retrieve Ministry of Foreign Affairs development cooperation and humanitarian aid strategy/report records from official page documents.

193 days ago

better-auth

3
zircotezircote

Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.

193 days ago

mfa-sanctions

3
taivoptaivop

Retrieve MFA sanctions implementation records from official sanctions pages and the linked sanctions search backend endpoint.

193 days ago

None

2
mukul975mukul975

Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust

iamidentityaccess-control+4
193 days ago

performing-adversary-in-the-middle-phishing-detection

2
mukul975mukul975

Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens.

aitmevilproxyevilginx+5
193 days ago

implementing-conduit-security-for-ot-remote-access

2
mukul975mukul975

Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control systems without exposing OT networks directly.

ot-securityicsremote-access+5
193 days ago

implementing-nerc-cip-compliance-controls

2
mukul975mukul975

This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance controls for Bulk Electric System (BES) cyber systems. It addresses asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007), configuration management (CIP-010), supply chain risk management (CIP-013), and the 2025 updates including mandatory MFA for remote access and expanded low-impact asset requirements.

ot-securityicsscada+5
193 days ago

implementing-google-workspace-admin-security

2
mukul975mukul975

Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and external sharing restrictions. Activates for requests involving Google Workspace hardening, G Suite security configuration, or cloud office security administration.

Google-Workspaceadmin-securityMFA+4
193 days ago

securing-remote-access-to-ot-environment

2
mukul975mukul975

This skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors while preventing unauthorized access that could compromise industrial operations. It addresses jump server architecture, multi-factor authentication, session recording, privileged access management, vendor remote access controls, and compliance with IEC 62443 and NERC CIP-005 remote access requirements.

ot-securityicsscada+5
193 days ago

managing-cloud-identity-with-okta

2
mukul975mukul975

This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and deprovisioning, and enforcing adaptive access policies based on device posture and risk signals.

oktacloud-identitysingle-sign-on+2
193 days ago

performing-initial-access-with-evilginx3

2
mukul975mukul975

Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.

red-teaminitial-accessphishing+4
193 days ago

implementing-passwordless-auth-with-microsoft-entra

2
mukul975mukul975

Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies.

passwordlessFIDO2passkeys+3
193 days ago

better-auth

1
hoadhhoadh

Add authentication with Better Auth (TypeScript). Use for email/password, OAuth providers (Google, GitHub), 2FA/MFA, passkeys/WebAuthn, sessions, RBAC, rate limiting.

193 days ago

better-auth

mfarzanansarimfarzanansari

Framework-agnostic Better Auth implementation and troubleshooting skill for TypeScript applications. Use when setting up Better Auth, migrating from Auth.js/Auth0/Clerk/Supabase/WorkOS, configuring adapters/providers/plugins, hardening security settings, or diagnosing Better Auth runtime/auth/session errors.

193 days ago

mfa

engineers-hub-ltd-in-house-projectengineers-hub-ltd-in-house-project

多要素認証(MFA)の設計・実装パターン。TOTP(Time-based One-Time Password、 Google Authenticator 互換)、WebAuthn/パスキー、リカバリーコード、 バックアップ手段の実装を含む。パスワード認証に加えて第二要素を要求することで アカウント乗っ取りリスクを低減する場面で使用する。

193 days ago

gcp-auth-failures

hminooeihminooei

Use this skill when users need to audit, detect, or remediate Identification and Authentication Failures (OWASP A07:2021) on Google Cloud Platform. This includes auditing Identity-Aware Proxy (IAP) configuration, enforcing multi-factor authentication (MFA), detecting brute force attack vectors, configuring Cloud Armor rate limiting, reviewing API key rotation and session management, checking Identity Platform and reCAPTCHA Enterprise enablement, and monitoring authentication-related Security Command Center findings. Activate for GCP authentication hardening, brute force protection, MFA enforcement, rate limiting configuration, or OWASP A07 compliance.

193 days ago

better-auth

miethemiethe

TypeScript authentication framework (framework-agnostic). Features: email/password, OAuth (Google, GitHub, Discord), 2FA (TOTP, SMS), passkeys/WebAuthn, session management, RBAC, rate limiting, database adapters. Actions: implement, configure, secure authentication systems. Keywords: Better Auth, authentication, authorization, OAuth, email/password, 2FA, MFA, TOTP, passkeys, WebAuthn, session management, RBAC, rate limiting, database adapter, TypeScript auth, social login, Google auth, GitHub auth, Discord auth, email verification, password reset. Use when: implementing TypeScript auth, adding OAuth providers, setting up 2FA/MFA, managing sessions, configuring RBAC, building secure auth systems.

193 days ago