better-auth agent-auth
COMMUNITYLABSCO SUMMARY
agent-auth-cli drives the whole flow — discovering providers, connecting an agent, managing its granted capabilities, and executing operations — through the auth-agent CLI binary; agent-auth-mcp does the identical job through MCP tools instead, for a client that talks MCP rather than shelling out. agent-auth-connectors sits on top of either one: a workflow skill for using specific connector capabilities, Gmail named as the example, once an agent is already registered and approved.
This is for a team building the server side of the protocol itself: the plugin lives in @better-auth/agent-auth for a Better Auth server, alongside a separate client SDK (@auth/agent) and CLI (@auth/agent-cli). It is not Better Auth's mainline authentication library — that ships its own separate repository and skill set — so anyone who came here expecting ordinary login-flow skills should look there instead.
READ THE FULL ANALYSIS
The protocol is not this repository's own design. The canonical specification lives at nicepkg/agent-auth-protocol on GitHub; this repository is Better Auth's implementation of it, demonstrated in Next.js reference apps under examples/ (paired with Drizzle), two of which add WebAuthn/passkey sign-in on top of the baseline email/password flow.
Two of the three skills are the same job through two different doors. A reader picks agent-auth-cli or agent-auth-mcp depending on whether their own client shells out to a CLI or speaks MCP, then reaches for agent-auth-connectors only once that choice is working.
Checked 19 September 2026 from the repository README and its three currently live skills.
WHAT'S INSIDE
3 showing · 3 totalagent-auth-cli
An agent cannot be trusted with your password, so it gets its own named, approved permissions instead — and this does all of that from the terminal.
agent-auth-connectors
The manners and the pitfalls of letting an agent into someone's email account — connect once, grant only what the job needs, and warn the person before you do.
agent-auth-mcp
Inside Cursor or Claude Desktop, the assistant asks for permission itself — it requests only the actions a task needs, waits for you to approve, and then runs them.
HOW TO GET IT
npx skills add better-auth/agent-authnpx skills add better-auth/agent-auth --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.