# Convex Auth > Añade autenticación (passkeys/OAuth) a la app Convex actual, incluyendo la configuración de auth.config.ts. Fuente: https://skillsagentes.com/skills/get-convex/agent-skills/convex-auth Markdown: https://skillsagentes.com/skills/get-convex/agent-skills/convex-auth.md Repositorio: https://github.com/get-convex/agent-skills Autor: get-convex Licencia: Apache-2.0 Actualizado: el mes pasado Coste de contexto: 25 tok instalada, 749 tok al activarse, 749 tok con todos los archivos del bundle Bundle: 1 archivo, 3 KB Permisos que pide: ninguno declarado ## Instalación Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina. ```bash # Claude Code npx -y skills add get-convex/agent-skills --skill convex-auth --agent claude-code # Cursor npx -y skills add get-convex/agent-skills --skill convex-auth --agent cursor # Codex npx -y skills add get-convex/agent-skills --skill convex-auth --agent codex # Gemini CLI npx -y skills add get-convex/agent-skills --skill convex-auth --agent gemini # Windsurf npx -y skills add get-convex/agent-skills --skill convex-auth --agent windsurf # Cline npx -y skills add get-convex/agent-skills --skill convex-auth --agent cline ``` ## Qué hace - Instala y configura @convex-dev/auth en la app Convex actual - Añade el proveedor en convex/auth.ts (Passkey por defecto, o Password/OAuth si se pide) - Genera JWT_PRIVATE_KEY y JWKS headlessly con jose y los define como variables de entorno - Escribe convex/auth.config.ts para evitar el bug de sign-out silencioso - Conecta el cliente con ConvexAuthProvider, el componente de sign-in y los route guards ## Cuándo usarla - Cuando hay que añadir autenticación (passkeys/OAuth) a la app Convex actual - Cuando se necesita configurar correctamente auth.config.ts para evitar el fallo de estar siempre desconectado ## Qué la activa - "Añade autenticación con passkeys a mi app Convex" - "Configura login con Google usando @convex-dev/auth" - "Necesito sign-in por password en mi proyecto Convex" ## Antes de instalar - Requiere @convex-dev/auth y el paquete jose (con pnpm hay que añadirlo aparte); si se usan primitivas shadcn/ui, deben instalarse antes con `npx shadcn@latest add `. ## Archivos - SKILL.md — 3 KB ## SKILL.md Reproducido tal cual desde get-convex/agent-skills bajo Apache-2.0. Esta sección es el documento original y está en inglés. # Add sign-in to the app Install and wire @convex-dev/auth for the current app: a provider (passkeys by default, or OAuth/password), the server config, the client hooks, and a sign-in UI — correctly, including the auth.config.ts that's the #1 real-world auth footgun. ## Workflow 1. Install @convex-dev/auth (pinned build) and add it to convex.config.ts. With pnpm, also `pnpm add jose` (it won't hoist otherwise); you need it for step 3. 2. Add the provider in convex/auth.ts (Passkey by default; Password or OAuth like Google on request). 3. Generate the auth keys HEADLESSLY. Do NOT run the interactive `npx @convex-dev/auth` wizard: it needs a login/TTY and hangs in non-interactive, anonymous, or CI runs (the #1 auth time-sink). Generate JWT_PRIVATE_KEY + JWKS deterministically with `jose`: node -e 'import("jose").then(async({generateKeyPair,exportPKCS8,exportJWK})=>{const k=await generateKeyPair("RS256",{extractable:true});const priv=await exportPKCS8(k.privateKey);const pub=await exportJWK(k.publicKey);process.stdout.write(JSON.stringify({JWT_PRIVATE_KEY:priv.trimEnd().replace(/\n/g," "),JWKS:JSON.stringify({keys:[{use:"sig",...pub}]})}))})' > .auth-keys.json Then set JWT_PRIVATE_KEY and JWKS (from .auth-keys.json) plus SITE_URL on the deployment. Prefer the Convex MCP `envSet` tool, one call per var, to avoid shell-quoting the multi-line key. CLI fallback: use the NAME=VALUE form (`npx convex env set "JWT_PRIVATE_KEY=$JWT"`), NEVER `env set JWT_PRIVATE_KEY "$JWT"` (the value starts with `-----BEGIN` and the CLI parses the leading `-` as an unknown flag). SITE_URL is the dev URL (e.g. http://localhost:3000). Delete .auth-keys.json after. 4. Write convex/auth.config.ts (the silently-always-signed-out bug lives here if it's wrong). 5. Wire the client: ConvexAuthProvider, the sign-in component, and route guards. If you import shadcn/ui primitives (button, input, textarea, label, and so on), add them first with `npx shadcn@latest add `; a missing @/components/ui/* is a hard build error. 6. Verify a sign-in round-trips before declaring done. ## Rules - Generate JWT_PRIVATE_KEY/JWKS with `jose` (extractable RS256; PKCS8 newlines to spaces; JWKS = {keys:[{use:"sig", ...publicJwk}]}). Do NOT run the interactive `npx @convex-dev/auth` wizard: it hangs headless/anonymous. Set the vars via the MCP `envSet` tool or the NAME=VALUE CLI form. - Always write auth.config.ts: a missing/incorrect one makes the app silently always-signed-out with no error. - Passkeys by default; only switch to password/OAuth on explicit request. - Install any shadcn/ui primitive you import up front (`npx shadcn@latest add ...`); a missing @/components/ui/* is a hard build failure. - Verify a real sign-in works before finishing. ## Dónde encaja - Categoría: [Desarrollo de APIs](https://skillsagentes.com/categorias/desarrollo-apis.md) — Diseña, prueba y documenta APIs HTTP y GraphQL. - Creador: [get-convex](https://skillsagentes.com/creators/get-convex.md) — 33 skills en el directorio - [Todas las skills](https://skillsagentes.com/skills.md) - [Ranking de instalaciones](https://skillsagentes.com/ranking.md) --- Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)