Backend · inspect by default

/backend-auth

Build or audit authentication and session behavior

Use for identity/session lifecycle; backend-permissions handles what an identity may do.

Make it your own.

In Claude Code, use the slash command and add your context. In Codex, select backend-auth from the just-vibe skill picker, then send the same brief.

Version 0.11.0 also supports /jv backend-auth, /just-vibe backend-auth and /jv:backend-auth in Claude. See shortcut setup and context examples.

Example · inspect
/just-vibe:backend-auth Audit session refresh, logout, and expired-token behavior.
edge · apply
/just-vibe:backend-auth Repair refresh behavior across concurrent browser tabs and expired sessions.
blocked · inspect
/just-vibe:backend-auth Review auth configuration without credentials or live login attempts.

What the agent does

  1. Identify the provider, session owner, trust boundaries and the actual request: audit or implementation. Trace login, refresh, logout and recovery across browser and server.
  2. Read only the matching cookie-session, OAuth callback, refresh-race or recovery scenario. Use the supported provider mechanism, implement the requested boundary and verify the relevant transitions.

Inputs

  • identity provider, session model, and recovery/logout requirements.

Optional context: scope, references, constraints, successCriteria, environment, mode, budget.

Scope

Reads
Authentication and session lifecycle; resource authorization is separately checked by `backend-permissions`.
Writes
Inspect/plan: inspect or propose; save requested artifacts only. Apply: edit the requested local implementation and perform relevant bounded checks while preserving unrelated work. Live data changes, remote actions and paid jobs require their resolved target and existing session authorization.
Mode
Inspect for audits; apply for a specified implementation. Requires identity provider, session model, and recovery/logout requirements.
Prerequisites
Service source, data/interface contracts, framework/runtime versions, and test environment. Default apply operations target local code and isolated tests; live infrastructure/data mutations require their own requested scope.

Expected output

  • Authentication findings or implementation with the auth lifecycle, trust assumptions and expired/revoked/invalid-credential checks.

How the work is checked

  • Logout/revocation invalidates the intended session; untrusted or expired tokens fail closed.

When to stop or clarify

  • Do not invent cryptography, log credentials, or mistake authentication for permission to access every resource.

Handling missing context

Infer
Trace service callers, request contracts, authorization, transactions, retries and existing test infrastructure.
Assume
Use the existing persistence and framework; isolate local tests from live services.
Ask
Resolve ambiguous durability, duplication or consistency requirements before encoding them; absent production access does not prevent local implementation.

Technical guidance

Evidence
Resolve provider/version, session storage, cookie topology and token refresh/revocation semantics.
Method
Load the matching authentication scenario and identity security guide; trace browser binding, token verification, rotation, recovery and account linking.
Pitfall
Decoding a JWT is not signature/issuer/audience validation; accepting an access token as identity can cross protocol boundaries.
Check
Test invalid/expired credentials, wrong flow state, session fixation, concurrent refresh and logout followed by a late refresh result.

Situational decisions

When browser cookie sessions carry authentication: Resolve cookie scope, proxy/HTTPS behavior, CSRF protection, session rotation and logout semantics.

When OAuth/OIDC callbacks establish a session: Bind the flow to the initiating browser, enforce the supported state/PKCE/nonce contract, and validate identity through the provider client.

When refresh and logout can overlap across tabs or workers: Choose the session owner and stale-result rule; test rotation/reuse, expired credentials and late refresh after logout.

When recovery or account linking changes access: Verify single-use/expiry, ownership proof, abuse controls and the intended existing-session invalidation.

The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.

Keep exploring