Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.
Restart Claude Code after copying so it picks up the new skill.
Use it in TypingMind
Enable Authentication Patterns in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.
SkillsLoad skill"authentication-patterns"
GPT-6 Astra
The model loads Authentication Patterns on its own as soon as a request matches it.
Works with any AI model
AI skills are plain Markdown instructions rather than provider-specific code, so Authentication Patterns is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.
Loaded only when it is needed
The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.
Switch models mid-chat
Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.
Skill instructions
This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.
Authentication Patterns Skill
Reference for implementing secure, production-ready authentication.
WHEN_TO_USE
Apply this skill when implementing authentication in a project, reviewing existing auth flows for security issues, choosing between auth providers, or migrating between auth strategies. Use the security checklist before shipping any auth-related change.
AUTH_APPROACHES
Approach
How It Works
Best For
Drawbacks
Session-based
Server stores session in DB/Redis, client holds session ID cookie
Traditional server-rendered apps, apps needing instant revocation
Requires server-side storage, harder to scale horizontally without shared store
JWT (stateless)
Server signs token, client sends it on each request
API-first apps, microservices, mobile clients
Cannot revoke without blocklist, token size grows with claims
OAuth 2.0 / OIDC
Delegates auth to external provider (Google, GitHub, etc.)
Social login, enterprise SSO, reducing auth responsibility
More complex flow, depends on external provider availability
Passkeys / WebAuthn
Cryptographic key pair, no passwords
High-security apps, passwordless UX
Limited browser support legacy, user education needed
Decision Guide
Server-rendered app with simple needs → Session-based
SPA or mobile app calling APIs → JWT with refresh token rotation
Want social login or SSO → OAuth 2.0 / OIDC
Greenfield with modern UX goals → Passkeys + OAuth fallback
JWT_BEST_PRACTICES
Token Lifecycle
Login → Access Token (short-lived) + Refresh Token (long-lived, rotated)
│
├─ Access Token: 15 min expiry, sent via httpOnly cookie or Authorization header
│
└─ Refresh Token: 7-30 day expiry, stored in httpOnly secure cookie
│
└─ On use: issue new access + new refresh token, invalidate old refresh token
Rules
[P0-MUST] Set short expiry on access tokens (15 minutes or less).
[P0-MUST] Store tokens in httpOnly, Secure, SameSite=Lax cookies — never in localStorage or sessionStorage.
[P0-MUST] Implement refresh token rotation — each refresh token is single-use.
[P0-MUST] Maintain a server-side blocklist for revoked refresh tokens.
[P1-SHOULD] Include only essential claims in JWT payload (sub, iat, exp, role). Keep it small.
[P1-SHOULD] Use asymmetric signing (RS256 or ES256) for distributed systems; symmetric (HS256) for single-service only.
[P1-SHOULD] Validate iss, aud, and exp claims on every request.
[P2-MAY] Use JWE (encrypted JWT) when token payload contains sensitive data.
Token Storage Comparison
Storage
XSS Safe
CSRF Safe
Recommendation
httpOnly cookie
Yes
No (needs CSRF token)
Recommended
localStorage
No
Yes
Never use for auth tokens
sessionStorage
No
Yes
Never use for auth tokens
In-memory (JS variable)
Yes
Yes
OK for SPAs, lost on refresh
PROVIDER_PATTERNS
Comparison
Provider
Type
Best For
Pricing
Key Features
NextAuth / Auth.js
OSS library
Next.js apps wanting full control
Free
80+ providers, DB adapters, self-hosted
Clerk
Managed service
Fast launch, pre-built UI, user management
Free tier, then per-MAU
Drop-in components, user dashboard, org support
Supabase Auth
Managed (part of Supabase)
Apps already using Supabase for DB/storage
Free tier, then per-MAU
Row-level security integration, magic links, SSO
Lucia
OSS library
Full control, minimal abstraction
Free
Session-based, framework-agnostic, type-safe
When to Use Each
NextAuth / Auth.js: You want provider flexibility, self-hosting, and database session control. Best when you need custom flows.
Clerk: You want auth done fast with pre-built UI components. Best for MVPs and teams that don't want to build auth UI.
Supabase Auth: You're already using Supabase. Auth integrates with RLS policies for row-level security.
Lucia: You want a minimal, type-safe session library without framework lock-in.
Rate limiting: Login endpoint limited to 5-10 attempts per minute per IP.
CSRF protection: Anti-CSRF tokens on all state-changing requests (or use SameSite=Lax cookies).
Password hashing: Using bcrypt (cost 12+) or argon2id — never MD5, SHA-1, or plain SHA-256.
HTTPS only: All auth endpoints served over TLS. Cookies have Secure flag.
Input validation: Email format, password length (min 8, max 128), no SQL/NoSQL injection vectors.
Account enumeration: Login and registration return the same response whether account exists or not.
Session invalidation: Logout invalidates server-side session/refresh token, not just client cookie.
MFA support: TOTP (authenticator app) or WebAuthn as second factor for sensitive accounts.
Password reset: Time-limited tokens (1 hour), single-use, sent over secure channel.
Audit logging: Log auth events (login, logout, failed attempts, password changes) with timestamp and IP.
Password Hashing
typescript
// Using bcryptimportbcryptfrom"bcrypt";constSALT_ROUNDS=12;asyncfunctionhashPassword(password:string):Promise<string>{return bcrypt.hash(password,SALT_ROUNDS);}asyncfunctionverifyPassword(password:string, hash:string):Promise<boolean>{return bcrypt.compare(password, hash);}
typescript
// Using argon2 (preferred for new projects)importargon2from"argon2";asyncfunctionhashPassword(password:string):Promise<string>{return argon2.hash(password,{ type: argon2.argon2id});}asyncfunctionverifyPassword(hash:string, password:string):Promise<boolean>{return argon2.verify(hash, password);}
COMMON_MISTAKES
Mistake
Risk
Fix
Storing JWT in localStorage
XSS can steal tokens
Use httpOnly cookies
Long-lived JWTs (days/weeks)
Stolen token is valid for extended period
15 min access token + refresh rotation
Missing CSRF protection
Attackers can forge requests from other sites
SameSite=Lax cookies + CSRF token
Weak password requirements
Brute force and credential stuffing
Min 8 chars, check against breached password lists
Exposing user existence on login
Account enumeration
Generic "Invalid credentials" message
Not rotating refresh tokens
Stolen refresh token grants indefinite access
Single-use refresh tokens with rotation
Hardcoding secrets in source
Credential leak via git history
Use environment variables, never commit secrets
Missing rate limiting on login
Brute force attacks
5-10 attempts/min per IP, exponential backoff
Rolling your own crypto
Subtle vulnerabilities
Use established libraries (bcrypt, argon2, jose)
Not validating JWT claims
Token misuse across services
Always verify iss, aud, exp
Frequently asked questions
What does the Authentication Patterns AI skill do?
Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.
Why use Authentication Patterns on TypingMind?
Because you install it once and use it with any model. Authentication Patterns is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.
How do I install Authentication Patterns in TypingMind?
Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/zebbern/claude-code-guide/tree/main/skills/authentication-patterns. TypingMind reads its SKILL.md and installs it as a skill you can enable per chat.
Which AI models can use Authentication Patterns?
Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.
How many AI models can I use with Authentication Patterns?
As many as you like. As long as a model supports skills, you can use Authentication Patterns with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.
Is the Authentication Patterns AI skill free?
Yes. It is published on GitHub by zebbern under the MIT license. You only pay your own AI provider for the tokens you use.
What are AI skills?
An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.
How are AI skills different from plugins or MCP servers?
A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.