Install
$ agentstack add skill-thunder-id-skills-integrate-express ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
ThunderID — Express Integration
Assumes ThunderID is running at https://localhost:8090. If not, run /setup-thunderid first.
Step 1 — Register an Application
Ask the developer to create an application in ThunderID and share the Client ID and Client Secret before continuing.
Guide them through these steps:
- Open
https://localhost:8090/consoleand sign in (default:admin/secret) - Navigate to Applications → New Application
- Fill in:
- Name: their app name (e.g.
my-express-app) - Type: Web Application
- Authorized Redirect URL:
http://localhost:3000/login
- Click Create and copy the Client ID and Client Secret shown on the next screen
Once they paste both values, use them in all subsequent steps. Do not use placeholders — wait for the real values.
Step 2 — Install
Detect the package manager from lockfiles: pnpm-lock.yaml → pnpm add, yarn.lock → yarn add, bun.lockb → bun add, else npm install.
npm install express cookie-parser @thunderid/express
Step 3 — Add Middleware and Routes
Create index.js:
const express = require('express');
const cookieParser = require('cookie-parser');
const { thunderID, handleSignIn, handleSignOut, protect } = require('@thunderid/express');
const app = express();
const port = 3000;
app.use(cookieParser());
app.use(express.json());
app.use(
thunderID({
baseUrl: 'https://localhost:8090',
clientId: '',
clientSecret: '',
afterSignInUrl: 'http://localhost:3000/login',
afterSignOutUrl: 'http://localhost:3000/logout',
}),
);
app.get('/', (_req, res) => {
res.send('Go to protected page');
});
app.get('/login', handleSignIn());
app.get('/logout', handleSignOut());
app.get(
'/protected',
protect((res) => res.redirect('/login')),
(_req, res) => {
res.send('You are signed in and can access this protected route.');
},
);
app.get('/me', protect(), async (req, res) => {
const user = await req.thunderIDAuth.getUserFromRequest(req);
res.json(user);
});
app.listen(port, () => {
console.log(`Server running on http://localhost:${port}`);
});
Step 4 — Run and Verify
node index.js
Visit http://localhost:3000/protected — you should be redirected to https://localhost:8090. After login, you'll return to the protected route. Visit http://localhost:3000/me to inspect the signed-in user profile.
Troubleshooting
Certificate error — Set NODE_TLS_REJECT_UNAUTHORIZED=0 in .env for local development (remove before deploying).
invalid_client — Double-check the Client ID and Client Secret.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: thunder-id
- Source: thunder-id/skills
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.