aceternity-ui
100+ animated React components (Aceternity UI) for Next.js with Tailwind. Use for hero sections, parallax, 3D effects, or encountering animation, shadcn CLI…
Cloudflare Zero Trust Access authentication for Workers. Use for JWT validation, service tokens, CORS, or encountering preflight blocking, cache race conditions, missing JWT headers.
$ npx -y skills add secondsky/claude-skills --skill cloudflare-zero-trust-access --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cloudflare-zero-trust-accessContext preview
The summary Claude sees to decide when to auto-load this skill.
Cloudflare Zero Trust Access authentication for Workers. Use for JWT validation, service tokens, CORS, or encountering preflight blocking, cache race conditions, missing JWT headers.
name: cloudflare-zero-trust-access
description: "Cloudflare Zero Trust Access authentication for Workers. Use for JWT validation, service tokens, CORS, or encountering preflight blocking, cache race conditions, missing JWT headers."
license: MIT
allowed-tools:
- Read
- Write
- Edit
- Bash
metadata:
version: "1.0.0"
category: authentication
framework: hono
platform: cloudflare-workers
package_versions:
"@hono/cloudflare-access": "0.3.1"
"hono": "4.12.12"
"@cloudflare/workers-types": "4.20260408.0"
errors_prevented: 8
token_savings: "58%"
time_savings: "2.5 hours"
production_tested: true
last_verified: "2025-10-28"
keywords:
- Cloudflare Access
- Zero Trust
- Cloudflare Zero Trust Access
- Access authentication
- JWT validation
- access jwt
- service tokens
- hono cloudflare access
- hono-cloudflare-access middleware
- workers authentication
- protect worker routes
- admin authentication
- access policy
- identity providers
- azure ad access
- google workspace access
- okta access
- github access
- rbac cloudflare
- geographic restrictions
- multi-tenant access
- cors access
- CORS preflight blocked
- JWT header missing
- access key cache
- team mismatch
- access claimsIntegrate Cloudflare Zero Trust Access authentication with Cloudflare Workers applications using proven patterns and templates.
---
This skill provides complete integration patterns for Cloudflare Access, enabling application-level authentication for Workers without managing your own auth infrastructure.
**What is Cloudflare Access?** Cloudflare Access is Zero Trust authentication that sits in front of your application, validating users before they reach your Worker. After authentication, Access issues JWT tokens that your Worker validates.
**Key Benefits**:
---
Trigger this skill when tasks involve:
**Keywords to Trigger**: cloudflare access, zero trust, access authentication, JWT validation, service tokens, cloudflare auth, hono access, workers authentication, protect worker routes, admin authentication
---
📖 **New to Cloudflare Access?** Load `references/quick-start.md` for step-by-step setup instructions (15-20 minutes).
Use `@hono/cloudflare-access` for one-line Access integration.
**When to Use**:
**Template**: `templates/hono-basic-setup.ts`
**Setup**:
import { Hono } from 'hono'
import { cloudflareAccess } from '@hono/cloudflare-access'
const app = new Hono<{ Bindings: Env }>()
// Public routes
app.get('/', (c) => c.text('Public page'))
// Protected routes
app.use(
'/admin/*',
cloudflareAccess({
domain: (c) => c.env.ACCESS_TEAM_DOMAIN,
})
)
app.get('/admin/dashboard', (c) => {
const { email } = c.get('accessPayload')
return c.text(`Welcome, ${email}!`)
})**Configuration** (`wrangler.jsonc`):
{
"vars": {
"ACCESS_TEAM_DOMAIN": "your-team.cloudflareaccess.com",
"ACCESS_AUD": "your-app-aud-tag"
}
}**Benefits**:
---
**When to Use**: Not using Hono, need custom validation logic
**Template**: `templates/jwt-validation-manual.ts` (~100 lines, uses Web Crypto API)
---
**When to Use**: CI/CD pipelines, backend services, cron jobs (no interactive login)
**Client**: Send `CF-Access-Client-Id` + `CF-Access-Client-Secret` headers
**Server**: Same middleware handles both - detect via `!payload.email && payload.common_name`
📄 **Full guide**: `references/service-tokens-guide.md`
---
**When to Use**: SPA (React/Vue/Angular) calling protected API
**⚠️ CRITICAL**: CORS middleware MUST come BEFORE Access middleware!
// ✅ CORRECT ORDER
app.use('*', cors({ origin: 'https://app.example.com', credentials: true }))
app.use('/api/*', cloudflareAccess({ domain: (c) => c.env.ACCESS_TEAM_DOMAIN }))**Why**: OPTIONS preflight has no auth headers → Access blocks with 401
📄 **Full pattern**: `templates/cors-access.ts`
---
**When to Use**: SaaS with per-org authentication, white-label apps
**Architecture**: Tenant config in D1/KV → Dynamic middleware per request
📄 **Full pattern**: `templates/multi-tenant.ts` and `references/use-cases.md`
---
This skill prevents 8 documented errors. Full details: `references/common-errors.md`
**Problem**: OPTIONS requests return 401, breaking CORS
**Solution**: CORS middleware BEFORE Access middleware
// ✅ Correct
app.use('*', cors())
app.use('/api/*', cloudflareAccess({ domain: '...' }))---
**Problem**: Request not going through Access, no JWT header
**Solution**: Access Worker through Access URL, not direct `*.workers.dev`
✅ https://team.clou
145 production-ready skills for Claude Code CLI 🔌 Platform / Harness Support These plugins ship as Claude Code marketplace plugins (.claude-plugin/ manifests) and Codex CLI plugins (.codex-plugin/ manifests).
Repo: secondsky/claude-skills
100+ animated React components (Aceternity UI) for Next.js with Tailwind. Use for hero sections, parallax, 3D effects, or encountering animation, shadcn CLI…
Secure API authentication with JWT, OAuth 2.0, API keys. Use for authentication systems, third-party integrations, service-to-service communication, or…
Creates comprehensive API changelogs documenting breaking changes, deprecations, and migration strategies for API consumers. Use when managing API versions,…
Verifies API contracts between services using consumer-driven contracts, schema validation, and tools like Pact. Use when testing microservices communication,…
Master REST and GraphQL API design principles to build intuitive, scalable, and maintainable APIs that delight developers. Use when designing new APIs,…
Implements standardized API error responses with proper status codes, logging, and user-friendly messages. Use when building production APIs, implementing…