Back to skills
SKILL.md
Authentication
ASecuritySecure token storage (HttpOnly Cookies) and Middleware patterns.
- 8 stars
- 0 votes
- 0 copies
- 3 views
- Added September 8, 2026
Works with
Security analysis
100/100Pro scans all 2 files and shows the line behind each finding
npx -y skills add ngxtm/devkit --skill authentication --agent claude-codeAre you the author of Authentication?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/ngxtm-authentication)---
name: Next.js Authentication
description: Secure token storage (HttpOnly Cookies) and Middleware patterns.
metadata:
labels: [nextjs, auth, security, cookies]
triggers:
files: ['middleware.ts', '**/auth.ts', '**/login/page.tsx']
keywords: [cookie, jwt, session, localstorage, auth]
---
# Authentication & Token Management
## **Priority: P0 (CRITICAL)**
Use **HttpOnly Cookies** for token storage. **Never** use LocalStorage.
## Key Rules
1. **Storage**: Use `cookies().set()` with `httpOnly: true`, `secure: true`, `sameSite: 'lax'`.
- _Reference_: [Auth Implementation](references/auth-implementation.md) (See "Setting Tokens").
2. **Access**: Read tokens in Server Components via `cookies().get()`.
- _Reference_: [Auth Implementation](references/auth-implementation.md) (See "Reading Tokens").
3. **Protection**: Guard routes in `middleware.ts` before rendering.
- _Reference_: [Auth Implementation](references/auth-implementation.md) (See "Middleware Protection").
## Anti-Pattern: LocalStorage
- **Security Risk**: Vulnerable to XSS.
- **Performance Hit**: Incompatible with Server Components (RSC). Forces client hydration and causes layout shift.
Files in this skill
- SKILL.md
- references/auth-implementation.md
Attribution
Comments
Loading comments…