packages/cli/skills/pikku-auth-js/SKILL.md
Use when integrating Auth.js (NextAuth) with a Pikku app. Covers createAuthHandler, createAuthRoutes, and Auth.js configuration. TRIGGER when: code uses createAuthHandler, createAuthRoutes, user asks about Auth.js, NextAuth, OAuth providers, or @pikku/auth-js. DO NOT TRIGGER when: user asks about JWT middleware (use pikku-security) or custom session services (use pikku-services).
npx skillsauth add pikkujs/pikku pikku-auth-jsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill as an execution checklist, not reference material.
pikku-meta when available; otherwise run the relevant pikku meta ... --json command and inspect only the focused output you need..pikku, node_modules, vendored packages, or broad build artifacts.pikku-verify or pikku all when functions, wirings, schemas, or generated clients may have changed.@pikku/auth-js provides Auth.js integration for Pikku apps, handling OAuth providers, session management, and auth routes.
yarn add @pikku/auth-js @auth/core
createAuthHandler(config)Creates a Pikku function that handles all Auth.js routes (signin, signout, callback, etc.):
import { createAuthHandler } from '@pikku/auth-js'
const authHandler = createAuthHandler(
config: AuthConfig | ((services: CoreSingletonServices) => AuthConfig | Promise<AuthConfig>)
)
// Returns: { func: CorePikkuFunctionSessionless }
The config can be static or a factory function that receives singleton services (useful for dynamic provider configuration).
createAuthRoutes(config, basePath?)Creates HTTP route contracts for Auth.js endpoints:
import { createAuthRoutes } from '@pikku/auth-js'
const authRoutes = createAuthRoutes(
config: AuthConfig | ((services) => AuthConfig | Promise<AuthConfig>),
basePath?: string // default: '/auth'
)
// Returns: HTTPRouteContract<HTTPRouteMap>
import { createAuthHandler, createAuthRoutes } from '@pikku/auth-js'
import GitHub from '@auth/core/providers/github'
const authConfig = {
providers: [
GitHub({
clientId: process.env.GITHUB_CLIENT_ID,
clientSecret: process.env.GITHUB_CLIENT_SECRET,
}),
],
}
const authHandler = createAuthHandler(authConfig)
const authRoutes = createAuthRoutes(authConfig)
const authHandler = createAuthHandler(async (services) => {
const githubSecret = await services.secrets.getSecretJSON('github-oauth')
return {
providers: [
GitHub({
clientId: githubSecret.clientId,
clientSecret: githubSecret.clientSecret,
}),
],
}
})
import { wireHTTPRoute } from '@pikku/core/http'
// Auth routes are automatically wired when passed to your HTTP runner
const routes = [
...authRoutes,
// ...your other routes
]
documentation
Standard cleanup to run right after a Pikku template is cloned or scaffolded into a new project. TRIGGER when: a Pikku template was just cloned/scaffolded (via `pikku create`, `git clone <template>`, or the user says "I cloned the kanban template / starter / template"), or the working tree still looks like an untouched template (template README, placeholder `@project/*` name in package.json). DO NOT TRIGGER when: working in an established project mid-feature, or editing the template repo itself.
development
Make a Pikku frontend work in both English (LTR) and Arabic / right-to-left languages. Direction is derived from the active locale, applied once at the document root, and the layout mirrors itself — but only if styling is written flow-relative (margin-inline-start, text-align: start, Mantine ms/me) instead of left/right. TRIGGER when: adding Arabic (or Hebrew/Farsi/Urdu), asked to "support RTL / right-to-left / bidi / mirror the layout", or writing layout styles in an app that may run RTL. Builds on pikku-i18n (an RTL language is just another locale file). DO NOT TRIGGER for backend functions or for LTR-only copy changes.
development
Wire i18n into a Pikku frontend (Vite SPA, Vite SSR, or Next.js app-router) with react-i18next + i18next. English by default, every user-facing string goes through a `t()` token, and additional languages are served under `/de` `/es` URL prefixes. TRIGGER when: scaffolding or editing a frontend and writing user-facing text, adding a second language, or asked to "make this translatable / use tokens / add i18n". DO NOT TRIGGER for backend functions, error messages thrown from functions, or log output.
development
Use when translating an n8n Code node body into a real Pikku function body. Triggered when the user opens or points at a stub generated by @pikku/n8n-import (look for `STUB — generated from n8n Code node` in the file's JSDoc), or when the user says 'translate this n8n code', 'port this n8n code node', 'finish the codeStub__... function', etc. The stub file is a `pikkuSessionlessFunc` with a Zod input/output, a JSDoc preserving the original n8n JavaScript verbatim, and a `throw new Error('… — implement me')` body.