← Cursor Slash Commands · ENGINEERING
/auth-system
Authentication & Role-Based Access System
OAuth 2.0, session cookies, multi-tenant RBAC, and middleware protection.
/auth-system Add Google OAuth and RBAC middleware for admin workspace routesWhere it installs
# .cursor/commands/auth-system.md
# no frontmatter, the file opens with its H1 title# .claude/commands/auth-system.md
---
description: ...
argument-hint: [auth provider or flow, e.g. Clerk with orgs]
allowed-tools: Read, Grep, Glob, Skill, TodoWrite, Task, ...
---What it does
/auth-system is a Cursor slash command. Type it in chat to run a saved workflow: Authentication & Role-Based Access System.
Implements secure authentication and authorization: OAuth logins (Google/GitHub), session management, password hashing, and role-based route middleware.
OAuth 2.0, session cookies, multi-tenant RBAC, and middleware protection. Unlike a skill, a command is something you invoke on purpose. The agent does not decide to run /auth-system for you.
Why it exists
Founders retype the same multi-step prompt until it rots. /auth-system exists so the pipeline, all 4 steps of it, is a file in .cursor/commands, versioned with the repo.
It ships in the Engineering Kit. It is wired to App Security Auditor (security-auditor), API Integration Specialist (api-engineer), and Senior Backend Architect (backend-architect). Required skills: Authentication & Session Security Patterns; OAuth 2.0 & Third-Party API Integrations; Web Security Fundamentals & OWASP Defense.
When to use it
- Use when setting up login systems, multi-tenant workspace permissions, or protected routes.
- Use /auth-system when you want that pipeline, not a freeform chat. If you only need one step, use a narrower command or a single agent.
- Start a new chat. Do not run this command in a thread that just wrote marketing copy.
When not to use it
- Do not run /auth-system as a substitute for reading the diff. The command produces files; you still gate them.
- Do not chain it into a 40-turn chat. Fresh context is part of the design.
- Do not run it if you have not filled CURSOR.md. The pipeline will invent a stack.
Example workflow
- Configure authentication provider and session token cookies
- Set up user credentials and OAuth account database tables
- Write Next.js edge middleware protecting authenticated routes
- Add workspace membership roles (Owner, Admin, Member) and permission guards
Example usage
Type this in Cursor chat: /auth-system Add Google OAuth and RBAC middleware for admin workspace routes
The command file tells the session which agents to adopt and which skills to read. You should see phase headers, not a single dump of code.
If a phase fails its gate, stop. Do not add 'just continue'.
Example output
- Expected artifact: src/middleware.ts
- Expected artifact: src/lib/auth.ts
- Expected artifact: src/app/api/auth/...
Best practices
- Keep the prompt specific. /auth-system Add Google OAuth and RBAC middleware for admin workspace routes is the shape: object, constraint, and outcome.
- Let the listed agents work in order: security-auditor → api-engineer → backend-architect.
- Save outputs in the repo. Chat-only answers evaporate.
- Engineering commands should leave tests or an audit note, not only implementation files.
Common mistakes
- Typing /auth-system with no object ('do the thing'). The pipeline will guess.
- Re-running the command in the same chat after a failed gate instead of fixing the failing file.
- Editing the command file to skip review so it 'goes faster'.
- Skipping the Authentication & Session Security Patterns skill that the command depends on.
Frequently asked questions
What does /auth-system do in Cursor?
Implements secure authentication and authorization: OAuth logins (Google/GitHub), session management, password hashing, and role-based route middleware.When should I run /auth-system?
Use when setting up login systems, multi-tenant workspace permissions, or protected routes.What is an example /auth-system prompt?
/auth-system Add Google OAuth and RBAC middleware for admin workspace routesWhich skills does /auth-system load?
Authentication & Session Security Patterns; OAuth 2.0 & Third-Party API Integrations; Web Security Fundamentals & OWASP DefenseIs /auth-system a Cursor skill?
No. /auth-system is a slash command you type. Skills are playbooks the agent may load. Use both: the command runs the workflow, the skills constrain how it writes.
Run /auth-system from your own repo
AgenticKit installs 47 slash commands, 46 agents, and 61 skills. One command installation.