Backend · inspect by default
/backend-auth
Build or audit authentication and session behavior
Use for identity/session lifecycle; backend-permissions handles what an identity may do.
Make it your own.
In Claude Code, use the slash command and add your context. In Codex, select backend-auth from the just-vibe skill picker, then send the same brief.
Version 0.11.0 also supports /jv backend-auth, /just-vibe backend-auth and /jv:backend-auth in Claude. See shortcut setup and context examples.
/just-vibe:backend-auth Audit session refresh, logout, and expired-token behavior./just-vibe:backend-auth Repair refresh behavior across concurrent browser tabs and expired sessions./just-vibe:backend-auth Review auth configuration without credentials or live login attempts.What the agent does
- Identify the provider, session owner, trust boundaries and the actual request: audit or implementation. Trace login, refresh, logout and recovery across browser and server.
- Read only the matching cookie-session, OAuth callback, refresh-race or recovery scenario. Use the supported provider mechanism, implement the requested boundary and verify the relevant transitions.
Inputs
- identity provider, session model, and recovery/logout requirements.
Optional context: scope, references, constraints, successCriteria, environment, mode, budget.
Scope
- Reads
- Authentication and session lifecycle; resource authorization is separately checked by `backend-permissions`.
- Writes
- Inspect/plan: inspect or propose; save requested artifacts only. Apply: edit the requested local implementation and perform relevant bounded checks while preserving unrelated work. Live data changes, remote actions and paid jobs require their resolved target and existing session authorization.
- Mode
- Inspect for audits; apply for a specified implementation. Requires identity provider, session model, and recovery/logout requirements.
- Prerequisites
- Service source, data/interface contracts, framework/runtime versions, and test environment. Default apply operations target local code and isolated tests; live infrastructure/data mutations require their own requested scope.
Expected output
- Authentication findings or implementation with the auth lifecycle, trust assumptions and expired/revoked/invalid-credential checks.
How the work is checked
- Logout/revocation invalidates the intended session; untrusted or expired tokens fail closed.
When to stop or clarify
- Do not invent cryptography, log credentials, or mistake authentication for permission to access every resource.
Handling missing context
- Infer
- Trace service callers, request contracts, authorization, transactions, retries and existing test infrastructure.
- Assume
- Use the existing persistence and framework; isolate local tests from live services.
- Ask
- Resolve ambiguous durability, duplication or consistency requirements before encoding them; absent production access does not prevent local implementation.
Technical guidance
- Evidence
- Resolve provider/version, session storage, cookie topology and token refresh/revocation semantics.
- Method
- Load the matching authentication scenario and identity security guide; trace browser binding, token verification, rotation, recovery and account linking.
- Pitfall
- Decoding a JWT is not signature/issuer/audience validation; accepting an access token as identity can cross protocol boundaries.
- Check
- Test invalid/expired credentials, wrong flow state, session fixation, concurrent refresh and logout followed by a late refresh result.
Situational decisions
When browser cookie sessions carry authentication: Resolve cookie scope, proxy/HTTPS behavior, CSRF protection, session rotation and logout semantics.
When OAuth/OIDC callbacks establish a session: Bind the flow to the initiating browser, enforce the supported state/PKCE/nonce contract, and validate identity through the provider client.
When refresh and logout can overlap across tabs or workers: Choose the session owner and stale-result rule; test rotation/reuse, expired credentials and late refresh after logout.
When recovery or account linking changes access: Verify single-use/expiry, ownership proof, abuse controls and the intended existing-session invalidation.
The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.