Borrowing it
Nothing to install: this file belongs to Cratis/VerticalSlices. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Cratis/VerticalSlices/main/.ai/skills/auth-and-identity/SKILL.mdgit clone --depth 1 https://github.com/Cratis/VerticalSlicesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cratis/verticalslices/auth-and-identity)<a href="https://agentmods.dev/skills/cratis/verticalslices/auth-and-identity"><img src="https://agentmods.dev/badge/skills/cratis/verticalslices/auth-and-identity.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00088 | $0.01999 |
| Opus 5 | $0.00044 | $0.01000 |
| Sonnet 5 | $0.00018 | $0.00400 |
| Haiku 4.5 | $0.00009 | $0.00200 |
Grade A, and why
auth-and-identity scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to auth-and-identity — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 162 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Auth & Identity in Cratis Arc
This skill covers the full auth and identity stack in a Cratis Arc application. Read the relevant reference files below for detailed API usage.
Read the relevant instruction files first. This skill references concepts from the core copilot instructions in
.github/copilot-instructions.md. If you need details on vertical slices, commands, queries, or proxy generation, consult those instructions.
Architecture Overview
Identity and auth in Arc follow a cookie-first, convention-based pattern:
Frontend (React) Backend (ASP.NET Core)
───────────────── ──────────────────────
<IdentityProvider> app.MapIdentityProvider()
└── useIdentity() hook └── GET /.cratis/me
│ │
├─ 1. Read .cratis-identity cookie │
└─ 2. If no cookie → fetch /.cratis/me │
▼
AuthenticationMiddleware
└── IAuthenticationHandler[]
│ sets HttpContext.User
▼
IIdentityProvider.Get()
└── IProvideIdentityDetails.Provide()
│
▼
IdentityProviderResult
→ JSON response
→ .cratis-identity cookie (base64)
Authorization:
[Authorize] / [Roles("Admin")] / [AllowAnonymous]
└── AuthorizationEvaluator checks per command/query
Key design decisions:
- The
.cratis-identitycookie isHttpOnly=falseso the frontend JavaScript can read it directly — no extra HTTP call needed on page load. - Identity details are base64-encoded JSON in the cookie, automatically decoded by the frontend
IdentityProvider. - Only one
IProvideIdentityDetailsimplementation is allowed per application (auto-discovered). If none exists, a default provider grants access to everyone. - Cratis has its own
[Authorize],[AllowAnonymous], and[Roles]attributes inCratis.Arc.Authorization— these are distinct from ASP.NET Core's and are evaluated byAuthorizationEvaluatorin the command and query pipeline.
What ships with it
5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 162 lines · 88 tokens per session scan A 91511bb9085e
auth-and-identity is a skill published in the GitHub repository Cratis/VerticalSlices (2 stars, last pushed 5d ago), licensed MIT. It adds 88 tokens to every session and 1,999 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to auth-and-identity, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
cratis-chronicle-client-dotnet
Talk to a Chronicle server from a standalone .NET application with the Cratis.Chronicle client - connection strings, ChronicleClient construction outside any host, AddCratisChronicle for a worker or ASP.NET host, [EventType] records, IEventSequence.Append, reactors and reducers found by assembly scanning, the…
cratis-chronicle-client-kotlin
Talk to a Chronicle server from a Kotlin or Java application with the io.cratis:chronicle client - connection strings, ChronicleClient and the Spring Boot starter, @EventType classes, suspending append, reactors and reducers dispatched by first-parameter type, model-bound read models, classpath artifact discovery, and…
cratis-chronicle-client-elixir
Talk to a Chronicle server from an Elixir application with the cratischronicle Hex package - putting Chronicle.Client in a supervision tree, connection strings, use Chronicle.Events.EventType structs, Chronicle.append returning ok or error tuples, reactors with the @handles attribute and a handle/2 callback…
cratis-chronicle-client-typescript
Talk to a Chronicle server from a Node.js or TypeScript application with @cratis/chronicle - reflect-metadata and decorator compiler settings, ChronicleClient and connection strings, @eventType classes, eventLog.append, reactors and reducers dispatched by camelCase method name, model-bound and declarative projections…
cratis-command
Step-by-step guidance for creating a Cratis Arc command — [Command] record, Handle() method, CommandValidator, proxy generation, and React .use() hook with CommandDialog. Use when adding or creating a command, wiring up a form or button to the backend, working with IEventLog, CommandResult, CommandValidator…
cratis-arc-command
Define a Cratis Arc command — the [Command] record, its Handle() method and return shape, the optional Provide() step, and the generated TypeScript proxy. Use when adding a command, choosing what Handle() should return, deciding which values may reach the causation chain, or wiring a form or button to an Arc backend.…