Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Pocketbase Auth

ASecurity

Authentication with PocketBase — email/password, OAuth2, and token management — use when implementing login and user sessions.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsgogitapifrontendsecurity

Works with

cliapi

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill pocketbase-auth --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Pocketbase Auth?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Pocketbase Auth
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-pocketbase-auth/badge)](https://www.skillsdirectory.com/skills/aicodedecode-pocketbase-auth)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: pocketbase-auth
description: Authentication with PocketBase — email/password, OAuth2, and token management — use when implementing login and user sessions.
category: pocketbase
---

## Overview

PocketBase's auth collections provide complete user management: email/password
with verification, OAuth2 providers, password resets, and token-based sessions
— all without a separate auth service. This skill covers implementing auth
flows correctly, managing tokens, and securing user data.

## When to use

- Setting up email/password auth with verification and password reset
- Adding OAuth2 providers (Google, GitHub, Apple, etc.)
- Managing auth tokens, refresh, and session persistence in clients
- Protecting user data with auth-aware API rules
- Handling multi-tenant or role-based access patterns

## Core concepts

**Auth collections are special.** They add `email`, `password`, `verified`,
and `tokenKey` fields plus auth endpoints (`auth-with-password`,
`auth-refresh`, `request-verification`, `request-password-reset`) to a base
collection. One project can have multiple auth collections (users, admins are
separate by default) — use this deliberately, not accidentally.

**Tokens, not sessions.** The SDK stores an auth token client-side and sends
it per request; `@request.auth.id` in API rules identifies the caller. Tokens
expire — the SDK's `authRefresh` keeps sessions alive. Treat tokens like
credentials: HTTPS only, secure storage on clients, never in URLs or logs.

**OAuth2 flow is handled for you.** Configure provider credentials in the
dashboard, redirect users to the provider, and PocketBase creates/links the
auth record on callback. Map provider profile data to collection fields on
first login; decide your account-linking policy (by email match? explicit
link only?) up front — it's a security decision.

**Verification and reset are email flows.** PocketBase sends the emails via
configured SMTP; customize templates, set token lifetimes sensibly, and make
sure the frontend handles the deep links. Unverified users can be restricted
via API rules (`@request.auth.verified = true`) for sensitive operations.

**API rules close the loop.** Auth without rules is decoration: every
user-data collection needs rules referencing `@request.auth.id`
(`owner = @request.auth.id` patterns). Test as anonymous, as user A, and as
user B — B must never see A's records.

## Practical workflow

1. **Configure the auth collection:** required fields, password requirements,
   unique email enforcement, and whether self-registration is allowed (disable
   it for invite-only products).
2. **Set up email:** SMTP settings, verify/reset templates with your branding,
   and test the full flow end-to-end (signup → email → verify → login).
3. **Add OAuth2 providers** needed; configure redirect URLs for each
   environment; implement the callback handling in your client per SDK docs.
4. **Write auth-aware API rules** for every collection holding user data;
   verify with three identities (anonymous, owner, non-owner).
5. **Implement the client:** login/logout UI, token persistence via the SDK's
   auth store, refresh handling, and route guards based on auth state.
6. **Harden:** rate-limit auth endpoints (reverse proxy / WAF), monitor for
   credential-stuffing patterns, enforce HTTPS, and define a session/token
   lifetime policy.

## Common pitfalls

- **Leaving self-registration open** unintentionally — anyone creates accounts;
  decide explicitly.
- **API rules that check authentication but not ownership** — logged-in user
  A reading user B's records; always scope to `@request.auth.id`.
- **Tokens in localStorage without considering XSS** — any XSS becomes
  account takeover; weigh storage options and invest in XSS prevention.
- **Untested email flows** — verification/reset emails broken in production
  (bad SMTP, wrong links) lock users out; test in a staging environment.
- **OAuth account-linking confusion** — auto-linking by email lets an attacker
  with a matching email hijack accounts; prefer explicit linking or verified-
  email matching with care.
- **No lockout or throttling on password auth** — brute-forceable login
  endpoints; add rate limiting at the proxy layer.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →