get-convex/templates-template-tanstack-start-authkit-convex-setup-auth
Sets up Convex auth, identity mapping, and access control. Use for login, auth providers, users tables, protected functions, or roles in a Convex app.
This is a copy. The original lives at get-convex/templates-convex-setup-auth.
npx skills add https://github.com/get-convex/templates --skill convex-setup-auth
Implement secure authentication in Convex with user management and access
control.
JWT)
one-line fix
Convex supports multiple authentication approaches. Do not assume a provider.
Before writing setup code:
makes it obvious
user wants to switch
ask before proceeding
Common options:
the user wants auth handled directly in Convex
Clerk or the user wants Clerk's hosted auth features
already uses WorkOS or the user wants AuthKit specifically
Auth0
above
Look for signals in the repo before asking:
@clerk/*, @workos-inc/*, @auth0/*, or Convex Authpackages
convex/auth.config.ts, auth middleware, providerwrappers, or login components
Read the provider's official guide and the matching local reference file:
references/convex-auth.md
references/clerk.md
references/workos-authkit.md
references/auth0.md
The local reference files contain the concrete workflow, expected files and env
vars, gotchas, and validation checks.
Use those sources for:
convex/auth.config.ts setupFor shared auth behavior, use the official Convex docs as the source of truth:
ctx.auth.getUserIdentity()
for optional app-level user storage
authorization guidance
provider is Convex Auth
Prefer official docs over recalled steps, because provider CLIs and Convex Auth
internals change between versions. Inventing setup from memory risks outdated
patterns. For third-party providers, only add app-level user storage if the app
actually needs user documents in Convex. Not every app needs a users table.
For Convex Auth, follow the Convex Auth docs and built-in auth tables rather
than adding a parallel users table plus storeUser flow, because Convex Auth
already manages user records internally. After running provider initialization
commands, verify generated files and complete the post-init wiring steps the
provider reference calls out. Initialization commands rarely finish the entire
integration.
The most common auth task is checking identity in Convex functions.
// Bad: trusting a client-provided userId
export const getMyProfile = query({
args: { userId: v.id("users") },
handler: async (ctx, args) => {
return await ctx.db.get(args.userId);
},
});
// Good: verifying identity server-side
export const getMyProfile = query({
args: {},
handler: async (ctx) => {
const identity = await ctx.auth.getUserIdentity();
if (!identity) throw new Error("Not authenticated");
return await ctx.db
.query("users")
.withIndex("by_tokenIdentifier", (q) =>
q.eq("tokenIdentifier", identity.tokenIdentifier),
)
.unique();
},
});
storage, and authorization patterns
app needs them
configuration if requested
If the flow blocks on interactive provider or deployment setup, ask the user
explicitly for the exact human step needed, then continue after they complete
it. For UI-facing auth flows, offer to validate the real sign-up or sign-in flow
after setup is done. If the environment has browser automation tools, you can
use them. If it does not, give the user a short manual validation checklist
instead.
references/convex-auth.mdreferences/clerk.mdreferences/workos-authkit.mdreferences/auth0.mdpatterns
users table or storeUser flow forConvex Auth
Take get-convex/templates-template-tanstack-start-authkit-convex-setup-auth from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.