# Web Auth Integrator

> Integrate authentication and authorization flows with provider-specific setup and RBAC safeguards.

- **Type:** Skill
- **Install:** `agentstack add skill-0x-professor-agent-skills-hub-web-auth-integrator`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [0x-Professor](https://agentstack.voostack.com/s/0x-professor)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [0x-Professor](https://github.com/0x-Professor)
- **Source:** https://github.com/0x-Professor/Agent-Skills-Hub/tree/main/skills/web-auth-integrator

## Install

```sh
agentstack add skill-0x-professor-agent-skills-hub-web-auth-integrator
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Web Auth Integrator

## Objective

Implement authentication and authorization end-to-end based on
`project-config.json`.

## Required Workflow

1. Read `project-config.json` and determine auth provider.
2. For Clerk:
   - install `@clerk/nextjs` or `@clerk/clerk-react`
   - wrap app with `ClerkProvider`
   - protect routes with auth middleware
   - configure Clerk webhooks
3. For Auth.js / NextAuth:
   - configure providers (Google, GitHub, credentials)
   - choose JWT or DB sessions
   - protect API routes and pages
4. For Supabase Auth:
   - use `supabase.auth`
   - configure OAuth providers
   - configure magic links
5. For custom JWT:
   - scaffold `/auth/register`, `/auth/login`, `/auth/refresh`
   - hash passwords with bcrypt
   - sign/verify JWTs (`jose` or `jsonwebtoken`)
   - implement refresh-token rotation
6. Implement RBAC middleware.
7. Add CSRF protection and secure cookie flags (`HttpOnly`, `SameSite=Strict`, `Secure`).
8. Output auth integration artifacts and `auth-report.json`.

## Execution

```bash
python skills/web-auth-integrator/scripts/auth_integrator.py --input  --output  --format json
```

## References

- `references/tools.md`

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [0x-Professor](https://github.com/0x-Professor)
- **Source:** [0x-Professor/Agent-Skills-Hub](https://github.com/0x-Professor/Agent-Skills-Hub)
- **License:** Apache-2.0

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-0x-professor-agent-skills-hub-web-auth-integrator
- Seller: https://agentstack.voostack.com/s/0x-professor
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
