Web Auth Integrator
Objective
Implement authentication and authorization end-to-end based on
project-config.json.
Required Workflow
- Read
project-config.jsonand determine auth provider. - For Clerk:
- install
@clerk/nextjsor@clerk/clerk-react - wrap app with
ClerkProvider - protect routes with auth middleware
- configure Clerk webhooks
- install
- For Auth.js / NextAuth:
- configure providers (Google, GitHub, credentials)
- choose JWT or DB sessions
- protect API routes and pages
- For Supabase Auth:
- use
supabase.auth - configure OAuth providers
- configure magic links
- use
- For custom JWT:
- scaffold
/auth/register,/auth/login,/auth/refresh - hash passwords with bcrypt
- sign/verify JWTs (
joseorjsonwebtoken) - implement refresh-token rotation
- scaffold
- Implement RBAC middleware.
- Add CSRF protection and secure cookie flags (
HttpOnly,SameSite=Strict,Secure). - Output auth integration artifacts and
auth-report.json.
Execution
python skills/web-auth-integrator/scripts/auth_integrator.py --input <workspace> --output <out.json> --format json
References
references/tools.md