Back to skills
SKILL.md
Auth Implementation Patterns
ASecurityUse when implementing authentication and authorization: sessions, JWT, OAuth2 and OpenID Connect, RBAC, SSO, multi-tenancy, or debugging auth issues. Covers AuthN vs AuthZ, token strategies and securing REST or GraphQL APIs.
- 21 stars
- 0 votes
- 0 copies
- 0 views
- Added September 22, 2026
Works with
Security analysis
100/100Pro scans all 3 files and shows the line behind each finding
npx -y skills add monoes/monomind --skill auth-implementation-patterns --agent claude-codeAre you the author of Auth Implementation Patterns?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/monoes-auth-implementation-patterns)---
name: auth-implementation-patterns
description: "Use when implementing authentication and authorization: sessions, JWT, OAuth2 and OpenID Connect, RBAC, SSO, multi-tenancy, or debugging auth issues. Covers AuthN vs AuthZ, token strategies and securing REST or GraphQL APIs."
tags: ["security","backend","api"]
tools: ["monograph_query","monograph_context"]
license: MIT
source: https://github.com/wshobson/agents
source_path: "plugins/developer-essentials/skills/auth-implementation-patterns"
source_commit: 4236bb91f8395b0435f1d8b8baf9e8e4c69a8620
---
# Authentication & Authorization Implementation Patterns
Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices.
## When to Use This Skill
- Implementing user authentication systems
- Securing REST or GraphQL APIs
- Adding OAuth2/social login
- Implementing role-based access control (RBAC)
- Designing session management
- Migrating authentication systems
- Debugging auth issues
- Implementing SSO or multi-tenancy
## Core Concepts
### 1. Authentication vs Authorization
**Authentication (AuthN)**: Who are you?
- Verifying identity (username/password, OAuth, biometrics)
- Issuing credentials (sessions, tokens)
- Managing login/logout
**Authorization (AuthZ)**: What can you do?
- Permission checking
- Role-based access control (RBAC)
- Resource ownership validation
- Policy enforcement
### 2. Authentication Strategies
**Session-Based:**
- Server stores session state
- Session ID in cookie
- Traditional, simple, stateful
**Token-Based (JWT):**
- Stateless, self-contained
- Scales horizontally
- Can store claims
**OAuth2/OpenID Connect:**
- Delegate authentication
- Social login (Google, GitHub)
- Enterprise SSO
## Detailed patterns and worked examples
Detailed pattern documentation lives in `references/details.md`. Read that file when the navigation tier above is insufficient.
## Best Practices
1. **Never Store Plain Passwords**: Always hash with bcrypt/argon2
2. **Use HTTPS**: Encrypt data in transit
3. **Short-Lived Access Tokens**: 15-30 minutes max
4. **Secure Cookies**: httpOnly, secure, sameSite flags
5. **Validate All Input**: Email format, password strength
6. **Rate Limit Auth Endpoints**: Prevent brute force attacks
7. **Implement CSRF Protection**: For session-based auth
8. **Rotate Secrets Regularly**: JWT secrets, session secrets
9. **Log Security Events**: Login attempts, failed auth
10. **Use MFA When Possible**: Extra security layer
## Common Pitfalls
- **Weak Passwords**: Enforce strong password policies
- **JWT in localStorage**: Vulnerable to XSS, use httpOnly cookies
- **No Token Expiration**: Tokens should expire
- **Client-Side Auth Checks Only**: Always validate server-side
- **Insecure Password Reset**: Use secure tokens with expiration
- **No Rate Limiting**: Vulnerable to brute force
- **Trusting Client Data**: Always validate on server
Files in this skill
- LICENSE.txt
- SKILL.md
- references/details.md
Attribution
Comments
Loading comments…