convex-auth
Implement Convex authentication and authorization patterns with OIDC providers or Convex Auth. Use for auth provider setup, ctx.auth usage, user identity handling, and auth-aware schema patterns. Use proactively when users mention auth, JWT, Clerk/Auth0/WorkOS, or Convex Auth. Examples: - user: "Add auth to Convex" → choose provider and outline setup - user: "Get current user" → use ctx.auth.getUserIdentity and checks - user: "Service-to-service access" → use shared secret pattern
How do I install this agent skill?
npx skills add https://github.com/igorwarzocha/opencode-workflows --skill convex-authIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill provides instructions for implementing authentication in Convex applications. It follows security best practices by explicitly prohibiting hardcoded secrets, requiring signature verification for webhooks, and mandating row-level authorization in server functions.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
- Runlayerpass
1/1 file flagged
What does this agent skill do?
Auth Operations
- In functions:
ctx.auth.getUserIdentity()returnstokenIdentifier,subject,issuerplus provider claims. - Custom JWT auth MAY expose claims at
identity["properties.email"]style paths. - User storage patterns:
- Client mutation to store user from JWT, or webhook from provider to upsert users.
- Index lookups SHOULD use
by_token/byExternalId.
- Webhooks: You MUST implement via HTTP actions and verify signatures with provider SDK; signing secrets MUST be stored in env vars.
Convex Auth (Beta) Specifics
- Supported Methods:
- Magic Links & OTPs: Email-based links or codes.
- OAuth: GitHub, Google, Apple, etc.
- Passwords: Supports reset flows and optional email verification.
- Components: Does not provide UI components; You MUST build them in React using library hooks.
- Next.js: SSR/Middleware support is experimental/beta.
Server Function Patterns
- You MUST read identity via
ctx.auth.getUserIdentity(). - You MUST enforce row-level authorization in every public function.
- You SHOULD NOT expose sensitive logic via public functions; prefer internal ones.
Service-to-service Access
- If no user JWT is available, You SHOULD use a shared secret pattern.
- You MUST store secrets in deployment env vars; MUST NOT hardcode.
Client Guidance
- You MUST follow provider quickstarts; MUST NOT invent flows.
- You SHOULD NOT rely on auth data in client-only code without server verification.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/igorwarzocha/opencode-workflows/convex-auth">View convex-auth on skillZs</a>