Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
secondsky avatar

Api Authentication

  • 421 installs
  • 202 repo stars
  • Updated August 4, 2026
  • secondsky/claude-skills

api-authentication is an agent skill that implements JWT, OAuth 2.0, API key, and session authentication with secure token handling for developers securing REST API endpoints.

About

api-authentication in secondsky/claude-skills helps developers implement secure authentication mechanisms for REST APIs using modern standards. The skill documents four primary methods in a comparison table: JWT for stateless auth and SPAs, OAuth 2.0 for third-party integration, API keys for service-to-service calls, and session-based auth for traditional web applications. Guidance includes JWT implementation patterns in Node.js with jsonwebtoken, token issuance and verification flows, and best practices for protecting endpoints without exposing secrets. Developers reach for api-authentication when adding login flows, securing new API routes, or choosing between stateless and session-based strategies. Agents produce concrete authentication middleware, token validation logic, and configuration aligned with each method's security level rather than generic security checklists.

  • api-authentication

Api Authentication by the numbers

  • 421 all-time installs (skills.sh)
  • +16 installs in the week ending Aug 5, 2026 (Skillselion tracking)
  • Ranked #1,047 of 4,347 Backend & APIs skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/secondsky/claude-skills --skill api-authentication

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs421
repo stars202
Last updatedAugust 4, 2026
Repositorysecondsky/claude-skills

How do you implement JWT and OAuth API authentication?

Use api-authentication for development tasks

Who is it for?

Backend developers adding or hardening authentication on REST APIs who need concrete JWT, OAuth 2.0, API key, or session implementation patterns.

Skip if: Teams that only need API route testing without implementing auth or frontends that require no server-side token logic.

When should I use this skill?

User asks to secure API endpoints, implement JWT or OAuth 2.0, manage API keys, or add login and session authentication flows.

What you get

Authentication middleware, token issuance and verification code, and endpoint protection patterns for JWT, OAuth 2.0, API keys, or sessions.

  • Authentication middleware code
  • Token issuance and verification logic

By the numbers

  • Documents 4 authentication methods: JWT, OAuth 2.0, API keys, and sessions
  • Listed at 370 installs on skills.sh

Files

SKILL.mdMarkdownGitHub ↗

API Authentication

Implement secure authentication mechanisms for APIs using modern standards and best practices.

Authentication Methods

MethodUse CaseSecurity Level
JWTStateless auth, SPAsHigh
OAuth 2.0Third-party integrationHigh
API KeysService-to-serviceMedium
SessionTraditional web appsHigh

JWT Implementation (Node.js)

const jwt = require('jsonwebtoken');

const generateTokens = (user) => ({
  accessToken: jwt.sign(
    { userId: user.id, role: user.role },
    process.env.JWT_SECRET,
    { expiresIn: '15m' }
  ),
  refreshToken: jwt.sign(
    { userId: user.id, type: 'refresh' },
    process.env.REFRESH_SECRET,
    { expiresIn: '7d' }
  )
});

const authMiddleware = (req, res, next) => {
  const authHeader = req.headers.authorization;

  // Validate authorization header format
  if (!authHeader || !authHeader.startsWith('Bearer ')) {
    return res.status(401).json({ error: 'Malformed authorization header' });
  }

  const parts = authHeader.split(' ');
  if (parts.length !== 2) {
    return res.status(401).json({ error: 'Malformed authorization header' });
  }

  const token = parts[1];
  if (!token) {
    return res.status(401).json({ error: 'No token provided' });
  }

  try {
    req.user = jwt.verify(token, process.env.JWT_SECRET);
    next();
  } catch (err) {
    res.status(401).json({ error: 'Invalid token' });
  }
};

Security Requirements

  • Always use HTTPS
  • Store tokens in HttpOnly cookies (not localStorage)
  • Hash passwords with bcrypt (cost factor 12+)
  • Implement rate limiting on auth endpoints
  • Rotate secrets regularly
  • Never transmit tokens in URLs

Security Headers

app.use((req, res, next) => {
  res.setHeader('X-Content-Type-Options', 'nosniff');
  res.setHeader('X-Frame-Options', 'DENY');
  res.setHeader('Strict-Transport-Security', 'max-age=31536000');
  next();
});

Additional Implementations

See references/python-flask.md for:

  • Flask JWT with role-based access control decorators
  • OAuth 2.0 Google integration with Authlib
  • API key authentication with secure hashing

Common Mistakes to Avoid

  • Storing plain-text passwords
  • Using weak JWT secrets
  • Ignoring token expiration
  • Disabling HTTPS in production
  • Logging sensitive tokens

Related skills

How it compares

Pick api-authentication to implement auth flows; pick api-testing from the same collection when validating secured endpoints with Supertest or httpx.

FAQ

Which authentication methods does api-authentication cover?

api-authentication documents JWT for stateless SPAs, OAuth 2.0 for third-party integration, API keys for service-to-service calls, and session auth for traditional web apps, each with implementation guidance.

Does api-authentication include JWT code examples?

api-authentication provides JWT implementation patterns in Node.js using jsonwebtoken, covering token creation, verification, and secure endpoint protection practices for REST APIs.

Backend & APIsbackendintegrations

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.