Execute mcloud authentication and context commands: login, logout, whoami, use, version, and signup. Use when setting up the CLI, switching accounts, verifying auth state, setting the active org/project/environment context, or checking the CLI version.
npx skills add https://github.com/medusajs/medusa-agent-skills --skill mcloud-auth
Execute authentication and context commands for the Medusa Cloud CLI.
mcloud login, mcloud signup, and mcloud use (without flags) require a TTY — they fail in CI, Docker, or piped input. Use MCLOUD_TOKEN or pass flags explicitly instead.MCLOUD_TOKEN is set, file-based credentials are ignored and mcloud login is rejected. Unset it to switch accounts.mcloud whoami --json | jq -e '.auth.kind != "none"'Show authenticated user, auth method, and active context (organization, project, environment).
mcloud whoami --json
Options:
--json — Output as JSONUse to verify auth and scope:
mcloud whoami --json | jq -e '.auth.kind != "none" and .organization.id != null'
Exit code 0 = authenticated and scoped. Non-zero = stop and prompt the user.
Set the active organization, project, and/or environment so subsequent commands skip those flags.
mcloud use \
--organization <org-id> \
--project <project-id-or-handle> \
--environment <environment-handle>
CRITICAL: mcloud use without flags is interactive and fails in CI/Docker/piped input. Always pass flags explicitly.
Options:
-o/--organization <id> — Set active organization-p/--project <id-or-handle> — Set active project-e/--environment <handle> — Set active environment--clear — Clear all active context--json — Output as JSONClear context:
mcloud use --clear
Print CLI version and platform metadata.
mcloud version --json
Options:
--json — Output as JSONAuthenticate with Medusa Cloud. Opens a browser to complete auth.
> TTY required. Cannot be run in CI, Docker, or non-interactive environments. Use MCLOUD_TOKEN instead for non-interactive auth.
mcloud login
Non-interactive alternative:
export MCLOUD_TOKEN=<access-key>
Options:
-t/--token <token> — Authenticate using an access key without browser (non-interactive)--json — Output as JSONRemove stored credentials.
mcloud logout --json
Options:
--json — Output as JSONCreate a new Medusa Cloud account. Opens a browser.
> TTY required. Cannot be run in non-interactive environments.
mcloud signup
| Method | When to use |
|--------|-------------|
| mcloud login (browser) | Interactive setup; requires TTY |
| mcloud login --token <key> | Non-interactive login with access key |
| MCLOUD_TOKEN=<key> env var | CI/CD, Docker, scripted environments |
# Check authentication and active context
mcloud whoami --json
# Verify auth before running commands
mcloud whoami --json | jq -e '.auth.kind != "none" and .organization.id != null'
# Set full context (org + project + environment)
mcloud use \
--organization org_123 \
--project my-store \
--environment production
# Set context by resolving names
ORGANIZATION_ID=$(mcloud organizations list --json | jq -r '.[] | select(.name == "My Org") | .id')
PROJECT_HANDLE=$(mcloud projects list --organization "$ORGANIZATION_ID" --json | jq -r '.[] | select(.name == "My Store") | .handle')
ENVIRONMENT_HANDLE=$(mcloud environments list --organization "$ORGANIZATION_ID" --project "$PROJECT_HANDLE" --json | jq -r '.[] | select(.name == "Production") | .handle')
mcloud use \
--organization "$ORGANIZATION_ID" \
--project "$PROJECT_HANDLE" \
--environment "$ENVIRONMENT_HANDLE"
# Clear context
mcloud use --clear
# Check CLI version
mcloud version --json
# Non-interactive login with token
mcloud login --token <access-key>
# Logout
mcloud logout
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
Package entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with customizable include/exclude patterns, generate multiple output formats (XML, Markdown, plain text), preserve file structure and context, optimize for AI consumption with token counting, filter by file types and directories, add custom headers and summaries. Use when packaging codebases for AI analysis, creating repository snapshots for LLM context, analyzing third-party libraries, preparing for security audits, generating documentation context, or evaluating unfamiliar codebases.
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects. Covers Node.js and Python SDKs.
Perform language and framework specific security best-practice reviews and suggest improvements. Use when the user explicitly requests security best practices guidance, a security review or report, or secure-by-default coding help. Supports Python, JavaScript/TypeScript, and Go. Do NOT use for general code review, debugging, threat modeling (use security-threat-model), or non-security tasks.
Configures API gateways for routing, authentication, rate limiting, and request transformation in microservice architectures. Use when setting up Kong, Nginx, AWS API Gateway, or Traefik for centralized API management.
Take medusajs/mcloud-auth from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.