Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Flutter Authentication

ASecurity

Implement, repair, or review Flutter user authentication and session lifecycle, including OAuth or OIDC redirects, PKCE, token refresh, logout, account switching, passkeys, and device re-authentication. Use when sign-in identity or session behavior is the task; route broad threat audits to flutter-security and request transport to flutter-networking.

7 stars
0 votes
0 copies
1 views
Added 9/19/2026
developmentrustgoapibackendsecuritydocumentation

Works with

cliapi

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add thiennc-tesoglobal/flutter-skills --skill flutter-authentication --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Flutter Authentication?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Flutter Authentication
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thiennc-tesoglobal-flutter-authentication/badge)](https://www.skillsdirectory.com/skills/thiennc-tesoglobal-flutter-authentication)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: flutter-authentication
description: Implement, repair, or review Flutter user authentication and session lifecycle, including OAuth or OIDC redirects, PKCE, token refresh, logout, account switching, passkeys, and device re-authentication. Use when sign-in identity or session behavior is the task; route broad threat audits to flutter-security and request transport to flutter-networking.
---

# Flutter Authentication

Treat authentication as a protocol and account-state lifecycle spanning the identity provider, trusted backend, platform redirect surface, local session owner, and application UI. Preserve the project's provider, backend, SDK, router, storage, and state management unless migration is requested.

Installing this skill requires no Firebase, OAuth, OpenID, passkey, or other provider credential. Do not add an SDK, client registration, redirect association, secret placeholder, account, or backend merely because the skill is selected.

## Preflight

Read `pubspec.yaml`, SDK constraints, sign-in entrypoints, provider and backend contract, registered clients and redirects, deep-link handling, token and account storage, refresh coordination, navigation guards, logout behavior, flavors, platform associations, and tests. Distinguish authentication, session state, authorization, and device-local re-authentication.

Native and web Flutter clients are public clients and cannot keep a reusable client secret. For OAuth or OIDC, use the established authorization-code flow with PKCE and an external user-agent where the provider supports it. Validate redirect ownership and correlate the response using state and, for OIDC, nonce as applicable. Never trust a redirect merely because its scheme matches.

## Load references conditionally

- Read [OAuth, OIDC, and redirects](references/oauth-oidc-and-redirects.md) for browser authorization, PKCE, state, nonce, callback ownership, deep links, and provider errors.
- Read [sessions and account state](references/sessions-and-account-state.md) for token ownership, coordinated refresh, expiry, logout, revocation, account switching, startup restoration, and offline behavior.
- Read [passkeys and device re-authentication](references/passkeys-and-device-reauthentication.md) for relying-party challenges, platform associations, passkey lifecycle, biometrics, and local authorization gates.

## Boundaries

- `flutter-security` owns threat modeling and broad hardening; this skill implements correct identity and session behavior.
- `flutter-networking` owns HTTP mechanics, interceptors, and generic retry; this skill defines authentication refresh and account semantics.
- `flutter-navigation` owns route and back-stack correctness; this skill defines authenticated, unauthenticated, callback, and re-authentication states.
- `flutter-persistence` owns storage mechanics; this skill defines credential sensitivity, account isolation, expiry, and deletion lifecycle.
- `flutter-platform-integration` owns custom native credential APIs or redirect mechanics when an existing plugin cannot satisfy them.

## Verification

Use a fake identity adapter for deterministic state transitions and an authorized non-production provider for end-to-end proof. Cover success, cancellation, denial, malformed or replayed callback, state and nonce mismatch, expired access token, concurrent refresh, refresh failure, revoked session, offline startup, logout, account switch, process restart, and platform link ownership.

For passkeys or device credentials, exercise real supported devices and cancellation or lockout behavior. State which provider, client type, platform, account state, redirect, storage, and backend checks were actually observed. A successful login screen or locally decoded token does not prove callback integrity, server authorization, refresh safety, revocation, or logout cleanup.

## Sources

- [OAuth 2.0 for Native Apps](https://www.rfc-editor.org/rfc/rfc8252)
- [OpenID Connect Core](https://openid.net/specs/openid-connect-core-1_0.html)
- [Android passkeys](https://developer.android.com/identity/passkeys)
- [Apple Authentication Services](https://developer.apple.com/documentation/authenticationservices)

Attribution

thiennc-tesoglobalthiennc-tesoglobal
View sourceMore from thiennc-tesoglobal →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

284972 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2192 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10311 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →