convex-create-componen…
Create reusable Convex components with clear boundaries and a small app-facing API.
Implement secure authentication in Convex with user management and access control.
$ npx -y skills add get-convex/convex-backend --skill convex-setup-auth --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/convex-setup-authContext preview
The summary Claude sees to decide when to auto-load this skill.
Implement secure authentication in Convex with user management and access control.
name: convex-setup-auth description: Sets up Convex authentication with user management, identity mapping, and access control. Use this skill when adding login or signup to a Convex app, configuring Convex Auth, Clerk, WorkOS AuthKit, Auth0, or custom JWT providers, wiring auth.config.ts, protecting queries and mutations with ctx.auth.getUserIdentity(), creating a users table with identity mapping, or setting up role-based access control, even if the user just says "add auth" or "make it require login."
Implement secure authentication in Convex with user management and access control.
JWT)
one-line fix
Convex supports multiple authentication approaches. Do not assume a provider.
Before writing setup code:
1. Ask the user which auth solution they want, unless the repository already makes it obvious 2. If the repo already uses a provider, continue with that provider unless the user wants to switch 3. If the user has not chosen a provider and the repo does not make it obvious, ask before proceeding
Common options:
the user wants auth handled directly in Convex
Clerk or the user wants Clerk's hosted auth features
already uses WorkOS or the user wants AuthKit specifically
Auth0
above
Look for signals in the repo before asking:
packages
wrappers, or login components
Read the provider's official guide and the matching local reference file:
`references/convex-auth.md`
`references/clerk.md`
`references/workos-authkit.md`
`references/auth0.md`
The local reference files contain the concrete workflow, expected files and env vars, gotchas, and validation checks.
Use those sources for:
For shared auth behavior, use the official Convex docs as the source of truth:
`ctx.auth.getUserIdentity()`
for optional app-level user storage
authorization guidance
provider is Convex Auth
Prefer official docs over recalled steps, because provider CLIs and Convex Auth internals change between versions. Inventing setup from memory risks outdated patterns. For third-party providers, only add app-level user storage if the app actually needs user documents in Convex. Not every app needs a `users` table. For Convex Auth, follow the Convex Auth docs and built-in auth tables rather than adding a parallel `users` table plus `storeUser` flow, because Convex Auth already manages user records internally. After running provider initialization commands, verify generated files and complete the post-init wiring steps the provider reference calls out. Initialization commands rarely finish the entire integration.
The most common auth task is checking identity in Convex functions.
// Bad: trusting a client-provided userId
export const getMyProfile = query({
args: { userId: v.id("users") },
handler: async (ctx, args) => {
return await ctx.db.get(args.userId);
},
});// Good: verifying identity server-side
export const getMyProfile = query({
args: {},
handler: async (ctx) => {
const identity = await ctx.auth.getUserIdentity();
if (!identity) throw new Error("Not authenticated");
return await ctx.db
.query("users")
.withIndex("by_tokenIdentifier", (q) =>
q.eq("tokenIdentifier", identity.tokenIdentifier),
)
.unique();
},
});1. Determine the provider, either by asking the user or inferring from the repo 2. Ask whether the user wants local-only setup or production-ready setup now 3. Read the matching provider reference file 4. Follow the official provider docs for current setup details 5. Follow the official Convex docs for shared backend auth behavior, user storage, and authorization patterns 6. Only add app-level user storage if the docs and app requirements call for it 7. Add authorization checks for ownership, roles, or team access only where the app needs them 8. Verify login state, protected queries, environment variables, and production configurati
Repo: get-convex/convex-backend
Create reusable Convex components with clear boundaries and a small app-facing API.
Safely migrate Convex schemas and data when making breaking changes.
Diagnose and fix performance problems in Convex applications, one problem class at a time.