Authentication & Session Security Patterns

.cursor/skills/auth-patterns

NextAuth, Supabase, Lucia, OAuth 2.0, and multi-tenant RBAC.

Where it installs

# .claude/skills/auth-patterns/SKILL.md
---
name: auth-patterns
description: ...
---
# identical content, skills are the same file in both editors

What it does

Authentication & Session Security Patterns is a Cursor skill: a SKILL.md playbook that AgenticKit installs at .cursor/skills/auth-patterns. Cursor's agent loads it when the task matches the skill description, instead of stuffing the same rules into every chat.

Authentication and session management architecture ensuring secure token storage, CSRF protection, OAuth 2.0 PKCE, and role-based access control.

NextAuth, Supabase, Lucia, OAuth 2.0, and multi-tenant RBAC. The file is domain knowledge, not a slash macro. You do not type it. The agent reads it when the job is auth patterns.

Why it exists

Default Cursor has no memory of how your team ships code, schema, and tests. Founders paste the same conventions into chat, then watch the model drift on the next turn. This skill exists so those conventions live on disk and load only when relevant.

It ships in the Engineering Kit. It is wired to App Security Auditor (security-auditor), API Integration Specialist (api-engineer), and Senior Backend Architect (backend-architect). It is wired to the /auth-system: Authentication & Role-Based Access System and /audit: Codebase Quality & Security Auditor commands. That graph is the point: the skill is the standard, the agent is the role, the command is the trigger.

When to use it

  • Use Authentication & Session Security Patterns when the work is specifically about nextauth, supabase, lucia, oauth 2.0, and multi-tenant rbac.
  • Load it before a long session that will touch this surface more than once. A one-line edit does not need the full playbook.
  • Use it on production SaaS work (multi-tenant apps, paid features, anything that will be reviewed) rather than a throwaway prototype.

When not to use it

  • Do not treat the skill as a replacement for a slash command. Skills teach. Commands run a pipeline.
  • Do not paste the whole SKILL.md into chat. If Cursor is not loading it, fix the description or invoke the matching command.
  • Do not use it as a generic 'write better code' rule. Scope is this domain only.

Example workflow

  1. Install the Engineering Kit so .cursor/skills/auth-patterns lands in the repo.
  2. Open a new Cursor agent chat pointed at the files this skill governs.
  3. Ask the App Security Auditor (security-auditor) to read the skill, or run /auth-system: Authentication & Role-Based Access System.
  4. Review the first artifact against the practices below. If it violates one, stop and correct the file. Do not prompt 'just finish it'.
  5. Commit the skill-guided files with the rest of the slice so the next session inherits the same standard.

Example usage

Example prompt: "Read .cursor/skills/auth-patterns and apply it to this change. Do not invent extra conventions."

Or trigger the pipeline: /auth-system: Authentication & Role-Based Access System. That command is written to load this skill.

Check the output against: Store session tokens in httpOnly, secure, sameSite=lax cookies

Example output

  • The skill itself does not write a single output file. It changes what the agent is allowed to produce in code, schema, and tests.
  • When you run /auth-system: Authentication & Role-Based Access System, expect repo files plus notes under docs/, not a chat-only answer.

Best practices

  • Store session tokens in httpOnly, secure, sameSite=lax cookies
  • Enforce tenant-level authorization checks on every single database query
  • Implement rate limiting on login, registration, and password reset routes
  • Protect against CSRF using state parameter validation in OAuth handshakes

Common mistakes

  • Ignoring "Store session tokens in httpOnly, secure, sameSite=lax cookies" and hoping a later prompt will clean it up.
  • Copying the skill into .cursor/rules as always-on. That burns context and fights Cursor's load-on-match design.
  • Running two overlapping skills that contradict each other in the same turn.
  • Letting the agent skip tests or types because 'the skill is about architecture'.

Frequently asked questions

  • What is the Authentication & Session Security Patterns Cursor skill?
    Authentication and session management architecture ensuring secure token storage, CSRF protection, OAuth 2.0 PKCE, and role-based access control. It lives at .cursor/skills/auth-patterns after you install the Engineering Kit.
  • When should I use auth-patterns instead of a Cursor rule?
    Use a rule for always-on or glob-scoped constraints. Use this skill for the full playbook that should load only when the task matches.
  • Which agents read auth-patterns?
    App Security Auditor (security-auditor); API Integration Specialist (api-engineer); Senior Backend Architect (backend-architect). Those roles are told to open this file before they edit.
  • Which commands use auth-patterns?
    /auth-system: Authentication & Role-Based Access System; /audit: Codebase Quality & Security Auditor.
  • Does this skill work outside AgenticKit?
    Yes. A SKILL.md in .cursor/skills/auth-patterns is a normal Cursor skill. AgenticKit is the packaged version plus the agent and command graph.

Add auth-patterns and the other 48 Cursor skills

AgenticKit installs 61 skills, 46 agents, and 47 slash commands into .cursor/. One license, lifetime updates.