thunderid AGENTS.md

Project instructions for ThunderID, a lightweight open-source identity and access system with a Go backend and React frontend in one monorepo, meaning one repository containing multiple related projects.

In plain words
What is it for?
Use them when changing ThunderID code, reading architecture or build instructions, working on backend or frontend files, updating documentation, or choosing database and browser-testing guidance.
Why use it?
They show agents where to find the right rules and how to search, validate, and work across the backend, frontend, and documentation.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/thunder-id/thunderid/agents-md
Clone the repo
git clone --depth 1 https://github.com/thunder-id/thunderid

Made for: Codex, OpenCode.

Per session 1,195 This file is loaded in full into every session.
When invoked 1,195 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01195 $0.01195
Opus 5 $0.00598 $0.00598
Sonnet 5 $0.00239 $0.00239
Haiku 4.5 $0.00120 $0.00120

Measured 2d ago against content hash ad6e32568da3, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

thunderid AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 70 lines

How it starts

The opening of the file, as written. The whole thing — 70 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Project Overview

ThunderID is a lightweight, open-source IAM stack: a Go backend (backend/) and React frontend (frontend/) in a monorepo. It provides authentication and authorization via OAuth2/OIDC, flexible orchestration flows, and individual auth mechanisms (password, passwordless, social login).

Where to Look Next

Load only the guidance the task needs:

Working on… Read
Backend Go code backend/AGENTS.md
Frontend React code frontend/AGENTS.md
Documentation docs/AGENTS.md
Database schema, queries, or stores .agent/skills/db/SKILL.md
Browser automation / Console UI verification .agent/skills/console/SKILL.md

The .agent/skills/ entries above are internal guidance for developing ThunderID. Consumer-facing setup and framework-integration skills (setup-thunderid, integrate-*) live in the separate ThunderID Skills repository (installable via /plugin marketplace add thunder-id/skills) and are not used when working in this repo.

Search Hygiene

  • rg honors .gitignore, which already excludes build outputs, node_modules, .claude/, /coverage, tests/e2e/distribution/, .turbo, and generated API specs — don't search them.
  • Do not search mirror worktrees under .claude/worktrees/ (they duplicate the repo and double your results).

Validation Ladder

  • Inner loop: run the smallest relevant checks for the area you touched. The scoped AGENTS files say which tests to run.
  • Pre-PR gate: make pr_checks — the authoritative gate (verify_mocks → lint → format_check → unit/frontend/integration tests → builds).
  • Note: make test is backend-only (unit + integration), not full-repo validation.

Read the full file on GitHub · 70 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 70 lines · 1,195 tokens per session scan A ad6e32568da3

Subscribe to this mod's changes

thunderid AGENTS.md is an instructions file published in the GitHub repository thunder-id/thunderid (565 stars, last pushed 5d ago), licensed Apache-2.0. It adds 1,195 tokens to every session, about $0.0060 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.