Skip to main content

acme-embed-and-auth

The concrete ACME embed + auth wiring — how a starter-kit app embeds inside the ACME iframe and authenticates every request with the brand-agnostic peek-auth JWT. Use when adding or changing an authenticated ACME API route, the token handshake, the embed entry route, or when debugging 401s / a blank iframe. Covers the shared POST → redirect → SPA → postMessage-token → Bearer-API pipeline, withAppAuthentication and the platform-claim branch that picks the ACME accessor, createAcmeService (no gatewayKey/mode), and calling ACME server-side with no user token. Triggers on "acme auth", "acme embed", "authenticate an acme request", "withAppAuthentication", "createAcmeService", "auth.user.platform", "401 in the acme embed", "call acme without a user token".

Jump to install

Source facts

Repository
peek-travel/app-cli
Last source activity
August 20, 2026 at 01:29
Detected SKILL.md language
English
Stars
0
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.