Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
better-auth avatar

Agent Auth Cli

  • 85 installs
  • 56 repo stars
  • Updated July 9, 2026
  • better-auth/agent-auth

Agent Auth CLI is a skill for using the auth-agent command-line tool to authenticate agents, manage capabilities, and execute provider operations securely.

About

Agent Auth CLI is a skill for driving the auth-agent (@auth/agent-cli) command-line tool to authenticate AI agents against Agent Auth providers. It walks through discovering providers, connecting agents with scoped capabilities and constraints, checking approval status, executing capabilities, and lifecycle actions like revoke and key rotation. A developer uses it to give an agent secure, constrained access to provider operations from the terminal.

  • Drives the auth-agent CLI to authenticate agents to Agent Auth providers
  • Discover, connect, describe, execute, and revoke agent capabilities
  • Supports constraints, CIBA approval, key rotation, and JWT signing

Agent Auth Cli by the numbers

  • 85 all-time installs (skills.sh)
  • Ranked #1,073 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

agent-auth-cli capabilities & compatibility

Free; runs the auth-agent CLI, provider approval may be required.

Capabilities
agent auth · authentication · capability management
Use cases
security audit · orchestration
Platforms
macOS · Linux
Pricing
Free
From the docs

What agent-auth-cli says it does

Use the Agent Auth CLI (auth-agent) to discover providers, connect agents, manage capabilities, and execute operations.
SKILL.md
npx skills add https://github.com/better-auth/agent-auth --skill agent-auth-cli

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs85
repo stars56
Last updatedJuly 9, 2026
Repositorybetter-auth/agent-auth

What it does

Authenticate and authorize an AI agent to a provider from the terminal using the auth-agent CLI with scoped, constrained capabilities.

Who is it for?

Authenticating agents and executing scoped, constrained provider capabilities from the terminal.

Skip if: End-user login flows or auth systems unrelated to Agent Auth providers.

When should I use this skill?

You need to authenticate an agent or execute Agent Auth provider capabilities from the CLI.

By the numbers

  • 9-step CLI workflow
  • 24-character reset token entropy referenced in Agent Auth

Files

SKILL.mdMarkdownGitHub ↗

Agent Auth CLI

You have access to the auth-agent CLI for interacting with Agent Auth providers. Always prefer using the CLI for any agent authentication operations rather than making raw HTTP requests or writing custom code.

Binary

The CLI binary is auth-agent (package: @auth/agent-cli). If not installed globally, run via npx @auth/agent-cli.

Workflow

Follow this order when working with a provider:

1. Discover or find a provider

# If you have the provider URL
auth-agent discover https://api.example.com

# If you need to search by intent
auth-agent search "deploy web apps"

# List already-known providers
auth-agent providers
  • discover fetches the /.well-known/agent-configuration document and caches the provider.
  • search queries the directory and returns matching providers.
  • Always discover or search first before connecting.

2. Explore capabilities

# List all capabilities for a provider
auth-agent capabilities --provider https://api.example.com

# Filter by query
auth-agent capabilities --provider https://api.example.com --query "transfer"

# Get full definition with input schema
auth-agent describe transfer_money --provider https://api.example.com
  • Always run describe before executing a capability to understand the required input schema and constraints.
  • If connected, pass --agent-id <id> to see which capabilities are granted.

3. Connect an agent

# Basic connection with specific capabilities
auth-agent connect --provider https://api.example.com \
  --capabilities read_data transfer_money \
  --name my-agent

# With constraints on capability arguments
auth-agent connect --provider https://api.example.com \
  --capabilities read_data transfer_money \
  --constraints '{"transfer_money":{"amount":{"max":1000}}}' \
  --name constrained-agent

# Autonomous mode (no user association)
auth-agent connect --provider https://api.example.com \
  --capabilities read_data \
  --mode autonomous

# With CIBA approval (backchannel, sends notification to user)
auth-agent connect --provider https://api.example.com \
  --capabilities read_data \
  --preferred-method ciba \
  --login-hint user@example.com
  • Save the returned agent_id — you need it for all subsequent operations.
  • If approval is required, the CLI opens the browser or prints the approval URL. Pass --no-browser to suppress browser opening.
  • Use --force-new to create a new connection even if one exists.

4. Check status

auth-agent status <agent-id>
  • Shows agent status (pending_approval, active, expired, revoked), granted capabilities, and constraints.
  • Run this after connecting to confirm the agent was approved.

5. Execute capabilities

auth-agent execute <agent-id> transfer_money \
  --args '{"amount": 50, "to": "alice"}'
  • The --args flag takes a JSON string matching the capability's input schema.
  • Always describe the capability first to know the required arguments.

6. Request additional capabilities

auth-agent request <agent-id> \
  --capabilities admin_panel \
  --constraints '{"admin_panel":{"scope":{"in":["read","write"]}}}' \
  --reason "Need admin access for deployment"

7. Lifecycle management

# Disconnect (revoke) an agent
auth-agent disconnect <agent-id>

# Reactivate an expired agent
auth-agent reactivate <agent-id>

# View stored connection details
auth-agent connection <agent-id>

# List all connections for a provider
auth-agent connections <issuer-url>

8. Key rotation

# Rotate an agent's keypair
auth-agent rotate-agent-key <agent-id>

# Rotate the host keypair for a provider
auth-agent rotate-host-key <issuer-url>

9. Host enrollment

auth-agent enroll-host --provider https://api.example.com --token <enrollment-token> --name "My Device"

10. Sign JWTs manually

# Sign an agent JWT (for use with external HTTP calls)
auth-agent sign <agent-id>

# Scope to specific capabilities
auth-agent sign <agent-id> --capabilities transfer_money read_data

Global Flags

FlagEnv varDescription
--storage-dir <path>AGENT_AUTH_STORAGE_DIRStorage directory (default: ~/.agent-auth)
--directory-url <url>AGENT_AUTH_DIRECTORY_URLDirectory URL for provider search
--host-name <name>AGENT_AUTH_HOST_NAMEHost name for identification
--no-browserAGENT_AUTH_NO_BROWSER=1Suppress browser opening for approval URLs
--url <urls...>AGENT_AUTH_URLSProvider URLs to auto-discover at startup

Important Rules

  • Never make raw HTTP requests to Agent Auth endpoints. Always use the CLI.
  • Always discover before connecting. The CLI needs the provider's configuration cached locally.
  • Always describe before executing. Check the input schema so you pass correct arguments.
  • Check status after connecting. The agent may require user approval before it becomes active.
  • Store agent IDs. You need them for execute, status, request, disconnect, and all other operations.
  • Use constraints when connecting to limit what the agent can do — this is a security best practice.
  • Set `AGENT_AUTH_ENCRYPTION_KEY` in production to encrypt private keys stored in ~/.agent-auth/.

Storage

Connections, keys, and provider configs are stored in ~/.agent-auth/ by default:

  • host.json — host identity and keypair
  • agents/<agent-id>.json — agent connections
  • providers/<encoded-issuer>.json — cached provider configurations

Related skills

FAQ

How do I limit what an agent can do?

Pass --constraints when connecting to limit capability arguments, e.g. a max transfer amount; the skill calls this a security best practice.

Where are agent keys stored?

Connections, keys, and provider configs are stored in ~/.agent-auth/ by default; set AGENT_AUTH_ENCRYPTION_KEY in production to encrypt private keys.

Securityappsecsecrets

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.