Skip to main content
If an AI assistant writes your auth code, give it the real docs and the real API. theAuth ships three things for that: an agent skill, a stdio MCP server in the CLI, and llms.txt files.

One command setup

Run this in your project root:
terminal
It writes, for each assistant: Options:
  • --target claude,cursor,vscode limits the set. The default is all three.
  • --dry-run prints what would be written and writes nothing.
  • --force replaces files and theauth MCP entries that already exist.
Existing files are left alone. Other servers in your MCP config are kept. A config file that is not plain JSON (for example one with comments) is skipped and reported, so add the entry by hand:
.mcp.json
VS Code uses servers with "type": "stdio" instead of mcpServers.

The MCP server

theauth mcp starts a stdio MCP server. It speaks newline-delimited JSON-RPC on stdout and writes nothing else there. All tools are read-only. inspect reads source files as text and never runs them. It reports env var names from .env files, never their values, and never echoes string literals from your config.

The skill

The skill lives in the repository at skills/theauth/SKILL.md and covers install, adapter choice, plugins, agent identity, delegation and MCP auth. Any tool that reads the SKILL.md format can use it directly. init --agent copies it into your project.

llms.txt

For assistants that fetch context from URLs: Maintainers regenerate both from docs/*.mdx and docs/docs.json with node scripts/generate-llms.mjs. Add --check to fail when they are stale. The Go docs are not included.
Last modified on October 9, 2026