Skip to main content

embed-and-auth

The host-owned-identity auth model for an app embedded in a platform's back-office surface, and how to authenticate every request. Use when adding or changing an authenticated API route, a client-side data fetch, the token handshake, the embed entry route, iframe/CSP headers, or when debugging 401s, a blank embed, or "token" problems. Explains why the app is a token-gated client SPA (no cookies, no SSR data fetching, library-owned verification) and how to reach the platform server-side WITHOUT a user token — install/tenant-scoped from a persisted install id — for public pages, webhooks, and cron. Triggers on "add an API route", "authenticate a request", "iframe won't load", "401 in the embed", "call the platform from a public page", "call the platform without a user token", "background/cron access".

インストールへ移動

ソース情報

リポジトリ
peek-travel/app-cli
ソースの最終更新活動
2026年8月18日 20:05
検出された SKILL.md の言語
英語
スター
0
フォーク
0

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。