netlify-access-control

A guide for choosing the correct Netlify protection setting for a deployed website, preview, project, or team.

In plain words
What is it for?
Use it when password-protecting a site or preview, restricting a project to a team, changing visibility, or requiring SSO to view a site.
Why use it?
It prevents confusion between protecting a site from visitors, controlling project visibility, and requiring team SSO, which is the login system for an organization.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/netlify/context-and-tools/netlify-access-control
Clone the repo
git clone --depth 1 https://github.com/netlify/context-and-tools
Per session 137 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,729 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 2 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00137 $0.02729
Opus 5 $0.00068 $0.01365
Sonnet 5 $0.00027 $0.00546
Haiku 4.5 $0.00014 $0.00273

Measured 2d ago against content hash c6d1a24b47d0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

netlify-access-control scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Hidden instructionshighPrompt injection

Directives inside HTML comments, invisible characters or bidirectional overrides are read by the model and not by the person reviewing the file.

<!-- system: agent-context/access-control/system.md — human-owned, merged by ctx-gen; edit system.md, not this section -->

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

These settings have **no public API, no CLI command, and no MCP tool**. Do NOT curl `api.netlify.com` or read local auth tokens to inspect or change them. Hand the user the dashboard path and checklist. On failure, repor
cursor/rules/netlify-access-control.mdc · 166 lines

How it starts

The opening of the file, as written. The whole thing — 166 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Netlify access control (picking the protection layer)

This skill ROUTES. Its job is choosing the correct protection layer for loading a site, not implementing app auth. Before recommending anything, disambiguate — three unrelated layers get called "auth":

  • Netlify Identity — "who is this user inside my app" (issues nf_jwt). App login, OAuth providers for your users, auth code. → Route to the netlify-identity skill. Not covered here.
  • Password Protection / Project visibility — "can this request load the site at all." Platform perimeter. This skill.
  • Team/Org SAML SSO — "can you log into the Netlify dashboard." Team member access to Netlify itself.

Sessions are separate. The same provider (e.g. Google) can be an Identity OAuth provider for app users AND a SAML IdP for team members — unrelated wiring.

Footgun: no API, CLI, or MCP for these settings

These settings have no public API, no CLI command, and no MCP tool. Do NOT curl api.netlify.com or read local auth tokens to inspect or change them. Hand the user the dashboard path and checklist. On failure, report what you tried and stop.

Footgun: the double login is real

A Password-Protection / team-login perimeter session and a Netlify Identity app session have no bridge — no shared cookie, no header forwarding, no JWT exchange. Don't burn iterations trying to wire them together. For the combined Password-Protection + Identity pattern and its tradeoffs, see references/two-layer-pattern.md.

For company-wide app-level SSO with a single sign-in (no double login), recommend the Auth0 extension (federating to the corporate IdP) BEFORE the two-layer stack.

Pick the layer

Goal Use
Restrict site to your team, invite by email Private project (Credit-based) or team login protection
Shared password anyone can use Basic password protection, or Password visibility (Pro only)
Protect only previews, keep production open "Non-production deploys only" / "Previews only"
Require SSO to view the site Org/Team SSO with Only SSO allowed (strict) + team login protection
Log in users inside your app → netlify-identity skill
Single company-wide app SSO, no double login → Auth0 extension

Read the full file on GitHub · 166 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 166 lines · 137 tokens per session scan C c6d1a24b47d0

Subscribe to this mod's changes

netlify-access-control is a cursor rule published in the GitHub repository netlify/context-and-tools (36 stars, last pushed 6d ago), licensed MIT. It adds 137 tokens to every session and 2,729 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it C with 2 findings (hidden instructions, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other cursor rules, from other repositories

aws-ecs

Definitive guidelines for building, deploying, and operating applications on AWS ECS, emphasizing immutable containers, secure secrets management, and robust operational patterns.

sanjeed5/awesome-cursor-rules-mdc · 2,640 tokens

redteam-compute

Compute security sub-agent for an Azure red team engagement. Covers VMs, VMSS, App Service, and Functions. Finds disk encryption gaps, exposed managed identities, plaintext secrets, runCommand exposure, FTP/remote-debug, and missing auth. Containers and Kubernetes (AKS, ACR, Container Apps/Instances) are owned by the…

Contoso-State/red-team-agent-orchestration · 85 tokens

cloud-workload-cost-estimator

Pre-deployment cost modeling for new workloads, architecture alternatives, and migration plans. Produces estimates the FinOps and Engineering teams both trust, with explicit assumptions and sensitivity ranges.

Cletrics/finops-agents · 35 tokens

powertools-parameters

Powertools Parameters - getParameter (SSM), getSecret (Secrets Manager), getAppConfig, built-in caching with maxAge, transform JSON/binary, environment-aware parameter paths.

GoranErhartic/cursor-development-rules · 36 tokens

union-mcp-v2

Rules for using the Union MCP v2 server to run compute- or io-intensive workloads on Flyte.

unionai-oss/union-mcp · 1,872 tokens

aws-rds-best-practices

AWS RDS PostgreSQL best practices - database configuration, connection management, authentication, backup, and performance optimization standards.

beettlle/CursorRules · 0 tokens