A collection of Agent Skills used by authentik idP.
These skills work with any agent that supports the Agent Skills standard, including Claude Code, OpenCode, OpenAI Codex, and Pi.
Install using the plugin marketplace:
/plugin marketplace add authentik-community/authentik-agent-marketplace
/plugin install ak-admin@authentik-marketplace
/plugin install ak-dev@authentik-marketplace
Install from the Pi Marketplace or add manually via Settings > Rules > Add Rule > Remote Rule (Github) with authentik-community/authentik-agent-marketplace.
Install using the npx skills CLI:
npx skills add https://github.com/authentik-community/authentik-agent-marketplace
Clone this repo and copy the skill folders from the plugin you want
(plugins/admin/skills/ or plugins/developer/skills/) into the appropriate
directory for your agent:
| Agent | Skill Directory | Docs |
|---|---|---|
| Claude Code | ~/.claude/skills/ |
docs |
| Cursor | ~/.cursor/skills/ |
docs |
| OpenCode | ~/.config/opencode/skills/ |
docs |
| OpenAI Codex | ~/.codex/skills/ |
docs |
| Pi | ~/.pi/agent/skills/ |
docs |
Commands are user-invocable slash commands that you explicitly call.
| Command | Description |
|---|---|
/ak-docs-url |
Print the resolved authentik docs + integrations base URLs (ak-admin) |
The marketplace ships two plugins. Install whichever fits your role.
| Plugin | For |
|---|---|
ak-admin |
Administering a running authentik instance |
ak-dev |
Contributing to authentik's source code |
Skills are contextual and auto-loaded based on your conversation. When a request matches a skill's triggers, the agent loads and applies the relevant skill to provide accurate, up-to-date guidance.
| Skill | Description |
|---|---|
concepts |
Translate a plain-language goal into the right authentik objects; explains the object model |
applications |
Connect a named app to authentik (SSO) end-to-end, and manage the Application object |
providers |
Make an app trust authentik for login: OAuth2/OIDC, SAML, LDAP, RADIUS, proxy, outbound provisioning |
sources |
Let users log in with Google/Microsoft/GitHub, or sync users in from Active Directory |
flows-stages |
Change login/signup/recovery: enrollment, password reset, captcha, MFA placement |
authenticators-mfa |
Turn on MFA: TOTP, WebAuthn/passkeys, Duo, SMS, and enforcing a second factor |
policies-rbac |
Control who can use an app or reach a step; policies, bindings, and RBAC |
users-directory |
Add or invite people, build groups, and issue service-account tokens |
outposts |
Run the proxy/LDAP/RADIUS/RAC outpost and wire forward-auth |
events-monitoring |
Alert on events (failed logins) and search the audit log |
troubleshooting |
Diagnose from the symptom: can't log in, token rejected, redirect loop, email, forward-auth 401 |
operations |
Upgrade, recover a locked-out admin, rotate certs, brand the login page, back up and restore |
| Skill | Description |
|---|---|
dev-environment |
From a fresh clone to a running stack you can log into, or reset a broken one |
backend |
Run the backend + worker, and take a model change to a committed migration |
frontend |
Run the web UI with hot reload against your local backend, and build it |
docs |
Preview a docs change with live reload, and build/check it before a PR |
testing |
Run just your change, a single test, the e2e suite, or the web tests |
linting |
Fix everything before you push, and reproduce a failing CI lint/type check |
contributing |
Take a branch to a merge-ready PR: conventions, CI, and the (no-)CLA situation |
community |
Send a question to the right venue (Issues / Discussions / Discord / security) |
de-slop |
Removes AI-slop tells from human-facing text (issues, PRs, docs) |
Some skills are backed by an MCP server, written in TypeScript and run directly — node …/lib/index.ts, with Node stripping the types (no build step, no bundle).
| Server | Backs plugin | Tools |
|---|---|---|
code-mode |
ak-admin (instance ops) |
search, execute, validate_blueprint, prepare_apply, docs |
ak-dev inherits code-mode through its dependency on ak-admin, so the server lives only under ak-admin.
ak-admindeclares the server inplugins/admin/.mcp.jsonat${CLAUDE_PLUGIN_ROOT}/mcp-servers/code-mode/lib/index.ts.- Its
node_modulesis not committed. ASessionStarthook (hooks/install-deps.sh) installs each server's runtime deps into the persistent${CLAUDE_PLUGIN_DATA}(gated on apackage.jsondiff, so it's a no-op unless deps changed) and symlinks them next to the server — ESM bare-specifier resolution needs a realnode_modules, whichNODE_PATHcan't provide. Nothing for the user to run. - Local dev: the servers are npm workspaces, so one
npm installat the repo root installs everything; the hook leaves an existing realnode_modulesuntouched.
The server reads AUTHENTIK_URL (default http://localhost:9000) and AUTHENTIK_TOKEN via the shared plugin env loader (plugins/admin/lib): it merges process.env, the .env in the directory Claude Code runs in (and the enclosing authentik checkout), and a .env co-located with the server (plugins/admin/mcp-servers/code-mode/.env, git-ignored — see .env.example; highest precedence). The token should be the scoped read-only identity from provision-agent-identity.py, never a superuser token:
uv run ak shell < .../mcp-servers/code-mode/scripts/provision-agent-identity.py # prints AUTHENTIK_READ_TOKEN=...