Skip to main content

embed-and-auth

The host-owned-identity auth model for an app embedded in a platform's back-office surface, and how to authenticate every request. Use when adding or changing an authenticated API route, a client-side data fetch, the token handshake, the embed entry route, iframe/CSP headers, or when debugging 401s, a blank embed, or "token" problems. Explains why the app is a token-gated client SPA (no cookies, no SSR data fetching, library-owned verification) and how to reach the platform server-side WITHOUT a user token — install/tenant-scoped from a persisted install id — for public pages, webhooks, and cron. Triggers on "add an API route", "authenticate a request", "iframe won't load", "401 in the embed", "call the platform from a public page", "call the platform without a user token", "background/cron access".

Zur Installation springen

Quellinformationen

Repository
peek-travel/app-cli
Letzte Quellaktivität
18. August 2026 um 20:05
Erkannte Sprache von SKILL.md
Englisch
Sterne
0
Forks
0

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.