Setting the skill. One moment.
Skills
Skill 4 of 33
Add authentication (passkeys/OAuth) to the current Convex app, including the auth.config.ts wiring.
2 minutes · 430 words · 3 sections
Install
npx skills add get-convex/agent-skills --skill convex-authnpx skills add get-convex/agent-skillsThe first command installs just this skill, by the name in its SKILL.md; the second installs the whole repository.
Install and wire @convex-dev/auth for the current app: a provider (passkeys by default, or OAuth/password), the server config, the client hooks, and a sign-in UI — correctly, including the auth.config.ts that’s the #1 real-world auth footgun.
pnpm add jose (it won’t hoist otherwise); you need it for step 3.npx @convex-dev/auth wizard: it needs a login/TTY and hangs in non-interactive, anonymous, or CI runs (the #1 auth time-sink). Generate JWT_PRIVATE_KEY + JWKS deterministically with jose:
node -e ‘import(“jose”).then(async({generateKeyPair,exportPKCS8,exportJWK})=>{const k=await generateKeyPair(“RS256”,{extractable:true});const priv=await exportPKCS8(k.privateKey);const pub=await exportJWK(k.publicKey);process.stdout.write(JSON.stringify({JWT_PRIVATE_KEY:priv.trimEnd().replace(/\n/g,” “),JWKS:JSON.stringify({keys:[{use:”sig”,…pub}]})}))})’ > .auth-keys.json
Then set JWT_PRIVATE_KEY and JWKS (from .auth-keys.json) plus SITE_URL on the deployment. Prefer the Convex MCP envSet tool, one call per var, to avoid shell-quoting the multi-line key. CLI fallback: use the NAME=VALUE form (npx convex env set "JWT_PRIVATE_KEY=$JWT"), NEVER env set JWT_PRIVATE_KEY "$JWT" (the value starts with -----BEGIN and the CLI parses the leading - as an unknown flag). SITE_URL is the dev URL (e.g. http://localhost:3000 (opens in a new tab)). Delete .auth-keys.json after.npx shadcn@latest add <name>; a missing @/components/ui/* is a hard build error.jose (extractable RS256; PKCS8 newlines to spaces; JWKS = {keys:[{use:”sig”, …publicJwk}]}). Do NOT run the interactive npx @convex-dev/auth wizard: it hangs headless/anonymous. Set the vars via the MCP envSet tool or the NAME=VALUE CLI form.npx shadcn@latest add ...); a missing @/components/ui/* is a hard build failure.main, last pushed 9 September 2026.SKILL.md, not by matching a directory convention. One layout observed: skills/*/SKILL.md.h1 and no skipped levels:/get-convex/agent-skills.md, and each skill at its own .md URL.