dirctl-auth

An authentication guide for dirctl, a command-line tool used to sign in to an AGNTCY Directory service.

In plain words
What is it for?
It explains how to log in, obtain or refresh a token, locate the approved dirctl binary, and troubleshoot authentication errors.
Why use it?
It prevents failed logins caused by using the wrong executable or authentication setup.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/agntcy/dir-mcp/dirctl-auth
Clone the repo
git clone --depth 1 https://github.com/agntcy/dir-mcp
Per session 28 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 200 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00028 $0.00200
Opus 5 $0.00014 $0.00100
Sonnet 5 $0.00006 $0.00040
Haiku 4.5 $0.00003 $0.00020

Measured yesterday against content hash 76f00dd965b4, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

dirctl-auth scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

dir-mcp-plugins/cursor/rules/dirctl-auth.mdc · 20 lines

What it actually says

dirctl Authentication

When the user asks to log in to the Directory, authenticate with dirctl, get a token, run dirctl auth login, or fix auth errors from the MCP tools, follow the dirctl-auth skill.

Binary lookup

Never run which dirctl or scan PATH. The binary must come from DIRECTORY_DIRCTL_PATH in the config or the bundled binary set by the npm wrapper. If neither is available, instruct the user to set DIRECTORY_DIRCTL_PATH in the config.

When to trigger

  • "log in to the Directory"
  • "authenticate with dirctl"
  • "dirctl auth login"
  • "get a token" / "refresh my token"
  • MCP tools return auth or permission errors and the auth mode is oidc
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 20 lines · 28 tokens per session scan A 76f00dd965b4

Subscribe to this mod's changes

dirctl-auth is a cursor rule published in the GitHub repository agntcy/dir-mcp (2 stars, last pushed 2d ago), licensed Apache-2.0. It adds 28 tokens to every session and 200 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.