auth0-cli CLAUDE.md

An AI-agent guide for auth0-cli, a command-line program for managing and testing Auth0 integrations from a terminal. It explains the Go codebase, its tools, project structure, and security requirements.

In plain words
What is it for?
Working on Auth0 CLI commands, Go dependencies, API integrations, secret storage, Terraform export, documentation, and tests.
Why use it?
It gives coding agents the context needed to make changes safely in a tool that handles tenant credentials and generates command documentation.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/auth0/auth0-cli/claude-md
Clone the repo
git clone --depth 1 https://github.com/auth0/auth0-cli
Per session 2,023 This file is loaded in full into every session.
When invoked 2,023 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02023 $0.02023
Opus 5 $0.01012 $0.01012
Sonnet 5 $0.00405 $0.00405
Haiku 4.5 $0.00202 $0.00202

Measured 2d ago against content hash 59a0c81a7988, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

auth0-cli CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 140 lines

How it starts

The opening of the file, as written. The whole thing — 140 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AI Agent Guidelines for auth0-cli

This document provides context and guidelines for AI coding assistants working with the auth0-cli codebase.

Your Role

You are a Go CLI engineer maintaining the Auth0 CLI — a Cobra-based tool (internal/cli over the go-auth0 Management API) where, because it stores tenant secrets on users' machines and generates its command docs, secure credential handling and doc regeneration are first-class concerns on every change.


Project Overview

auth0-cli is the official command-line interface for Auth0, used to build, manage, and test Auth0 integrations from the terminal.

  • Language: Go 1.25.8
  • Package Manager: Go modules (vendored). Run go mod tidy && go mod vendor after dependency changes.
  • Command Framework: Cobra (spf13/cobra) with pflag
  • Auth0 APIs: go-auth0 Management SDK (v1 and v3)
  • Secret Storage: zalando/go-keyring
  • Crash Reporting: Sentry (sentry-go)
  • Terraform: terraform-exec for Terraform export functionality
  • Markdown Rendering: charmbracelet/glamour
  • Testing: Go testing, stretchr/testify, and gomock

Project Structure

auth0-cli/
├── cmd/
│   ├── auth0/            # Main entrypoint — calls cli.Execute()
│   └── doc-gen/          # Generates docs/*.md from Cobra commands
├── internal/
│   ├── cli/              # All CLI commands (Cobra) — the bulk of the code
│   ├── auth/             # Device-code authentication flow against Auth0
│   ├── auth0/            # go-auth0 Management API wrappers + generated mocks
│   ├── keyring/          # System keyring storage for tokens & client secrets
│   ├── analytics/        # Segment usage tracking (opt-out via env var)
│   ├── instrumentation/  # Sentry crash reporting
│   ├── config/           # On-disk CLI config (tenants, default tenant)
│   ├── display/          # Output rendering (tables, JSON, colors)
│   ├── prompt/           # Interactive prompts (survey/promptui)
│   └── iostream/         # TTY / pipe detection
├── docs/                 # GENERATED command reference (make docs) — do not hand-edit
├── test/integration/     # YAML-driven integration tests (commander)
└── Makefile              # Canonical build/test/lint/docs targets

Read the full file on GitHub · 140 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 140 lines · 2,023 tokens per session scan A 59a0c81a7988

Subscribe to this mod's changes

auth0-cli CLAUDE.md is an instructions file published in the GitHub repository auth0/auth0-cli (339 stars, last pushed 4d ago), licensed MIT. It adds 2,023 tokens to every session, about $0.0101 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.