{"id":8253,"plugin_id":"plugin_asdk_app_6a183f5bead08191b494b99bc881e8c0","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T22:52:20.432Z","digest":"ea4ceab3fba34543c1936376c97876453b1302a857716bf716613fb4eb8d41be","against":null,"payload":{"name":"descope-auth","description":"Integrate Descope authentication into applications. Use when implementing login, signup, passwordless auth (OTP, Magic Link, Passkeys), OAuth, SSO, or MFA. Detects framework and provides targeted guidance.","included_files":[{"relative_path":"references/backend.md","size_in_bytes":1329},{"relative_path":"references/nextjs.md","size_in_bytes":2294},{"relative_path":"references/react.md","size_in_bytes":2526}],"skill_md_contents":"---\nname: descope-auth\ndescription: Integrate Descope authentication into applications. Use when implementing login, signup, passwordless auth (OTP, Magic Link, Passkeys), OAuth, SSO, or MFA. Detects framework and provides targeted guidance.\n---\n\n# Descope Authentication\n\nIntegrate secure, passwordless authentication using Descope Flows and SDKs.\n\n## Framework Detection\n\nDetect the user's framework and use the appropriate reference:\n\n| If project has... | Use reference |\n|-------------------|---------------|\n| `next` in package.json | `references/nextjs.md` |\n| `react` (no Next.js) | `references/react.md` |\n| Python/Node.js backend only | `references/backend.md` |\n\n## Quick Start (all frameworks)\n\n1. Get Project ID from https://app.descope.com/settings/project\n2. Set environment variable: `NEXT_PUBLIC_DESCOPE_PROJECT_ID=<your-id>`\n3. Follow framework-specific reference\n4. **Verify**: After setup, confirm the `<Descope>` component renders the login form. Check the browser console — a missing or invalid Project ID produces a clear `Could not load flows` error.\n\n### Minimal Inline Example (Next.js)\n\n```tsx\n// src/app/login/page.tsx\nimport { Descope } from '@descope/nextjs-sdk';\n\nexport default function LoginPage() {\n  return (\n    <Descope\n      flowId=\"sign-up-or-in\"\n      onSuccess={(e) => console.log('Authenticated:', e.detail.user)}\n      onError={(e) => console.error('Auth failed:', e.detail)}\n    />\n  );\n}\n```\n\nFor React SPA or backend-only setups, see the framework-specific references below.\n\n## Valid Flow IDs (CRITICAL - do not invent others)\n\n| Flow ID | Purpose |\n|---------|---------|\n| `sign-up-or-in` | Combined signup/login (RECOMMENDED) |\n| `sign-up` | Registration only |\n| `sign-in` | Login only |\n| `step-up` | MFA step-up authentication |\n| `update-user` | Profile updates, add auth methods |\n\n## Authentication Methods\n\n| Method | When to use |\n|--------|-------------|\n| OTP (Email/SMS) | Quick verification codes |\n| Magic Link | Passwordless email links |\n| Passkeys | Biometric/WebAuthn (most secure) |\n| OAuth | Social login (Google, GitHub, etc.) |\n| SSO | Enterprise SAML/OIDC |\n| Passwords | Traditional auth (not recommended) |\n\n## DO NOT (Security Guardrails)\n\n- DO NOT parse JWTs manually - always use SDK's `validateSession()`\n- DO NOT store tokens in localStorage - SDK handles this securely\n- DO NOT invent flow IDs - only use IDs from the table above\n- DO NOT skip server-side validation - always validate on backend\n- DO NOT expose DESCOPE_MANAGEMENT_KEY in client code\n\n## References\n\n- `references/nextjs.md` - Next.js App Router integration\n- `references/react.md` - React SPA integration  \n- `references/backend.md` - Backend session validation\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}