Skip to content

Repository files navigation

authentik LLM Marketplace

A collection of Agent Skills used by authentik idP.

Installing

These skills work with any agent that supports the Agent Skills standard, including Claude Code, OpenCode, OpenAI Codex, and Pi.

Claude Code

Install using the plugin marketplace:

/plugin marketplace add authentik-community/authentik-agent-marketplace
/plugin install ak-admin@authentik-marketplace
/plugin install ak-dev@authentik-marketplace

Pi

Install from the Pi Marketplace or add manually via Settings > Rules > Add Rule > Remote Rule (Github) with authentik-community/authentik-agent-marketplace.

npx skills

Install using the npx skills CLI:

npx skills add https://github.com/authentik-community/authentik-agent-marketplace

Clone / Copy

Clone this repo and copy the skill folders from the plugin you want (plugins/admin/skills/ or plugins/developer/skills/) into the appropriate directory for your agent:

Agent Skill Directory Docs
Claude Code ~/.claude/skills/ docs
Cursor ~/.cursor/skills/ docs
OpenCode ~/.config/opencode/skills/ docs
OpenAI Codex ~/.codex/skills/ docs
Pi ~/.pi/agent/skills/ docs

Commands

Commands are user-invocable slash commands that you explicitly call.

Command Description
/ak-docs-url Print the resolved authentik docs + integrations base URLs (ak-admin)

Plugins

The marketplace ships two plugins. Install whichever fits your role.

Plugin For
ak-admin Administering a running authentik instance
ak-dev Contributing to authentik's source code

Skills

Skills are contextual and auto-loaded based on your conversation. When a request matches a skill's triggers, the agent loads and applies the relevant skill to provide accurate, up-to-date guidance.

ak-admin

Skill Description
concepts Translate a plain-language goal into the right authentik objects; explains the object model
applications Connect a named app to authentik (SSO) end-to-end, and manage the Application object
providers Make an app trust authentik for login: OAuth2/OIDC, SAML, LDAP, RADIUS, proxy, outbound provisioning
sources Let users log in with Google/Microsoft/GitHub, or sync users in from Active Directory
flows-stages Change login/signup/recovery: enrollment, password reset, captcha, MFA placement
authenticators-mfa Turn on MFA: TOTP, WebAuthn/passkeys, Duo, SMS, and enforcing a second factor
policies-rbac Control who can use an app or reach a step; policies, bindings, and RBAC
users-directory Add or invite people, build groups, and issue service-account tokens
outposts Run the proxy/LDAP/RADIUS/RAC outpost and wire forward-auth
events-monitoring Alert on events (failed logins) and search the audit log
troubleshooting Diagnose from the symptom: can't log in, token rejected, redirect loop, email, forward-auth 401
operations Upgrade, recover a locked-out admin, rotate certs, brand the login page, back up and restore

ak-dev

Skill Description
dev-environment From a fresh clone to a running stack you can log into, or reset a broken one
backend Run the backend + worker, and take a model change to a committed migration
frontend Run the web UI with hot reload against your local backend, and build it
docs Preview a docs change with live reload, and build/check it before a PR
testing Run just your change, a single test, the e2e suite, or the web tests
linting Fix everything before you push, and reproduce a failing CI lint/type check
contributing Take a branch to a merge-ready PR: conventions, CI, and the (no-)CLA situation
community Send a question to the right venue (Issues / Discussions / Discord / security)
de-slop Removes AI-slop tells from human-facing text (issues, PRs, docs)

MCP servers

Some skills are backed by an MCP server, written in TypeScript and run directly — node …/lib/index.ts, with Node stripping the types (no build step, no bundle).

Server Backs plugin Tools
code-mode ak-admin (instance ops) search, execute, validate_blueprint, prepare_apply, docs

ak-dev inherits code-mode through its dependency on ak-admin, so the server lives only under ak-admin.

How it ships

  • ak-admin declares the server in plugins/admin/.mcp.json at ${CLAUDE_PLUGIN_ROOT}/mcp-servers/code-mode/lib/index.ts.
  • Its node_modules is not committed. A SessionStart hook (hooks/install-deps.sh) installs each server's runtime deps into the persistent ${CLAUDE_PLUGIN_DATA} (gated on a package.json diff, so it's a no-op unless deps changed) and symlinks them next to the server — ESM bare-specifier resolution needs a real node_modules, which NODE_PATH can't provide. Nothing for the user to run.
  • Local dev: the servers are npm workspaces, so one npm install at the repo root installs everything; the hook leaves an existing real node_modules untouched.

Configure the instance (the one per-deployment step)

The server reads AUTHENTIK_URL (default http://localhost:9000) and AUTHENTIK_TOKEN via the shared plugin env loader (plugins/admin/lib): it merges process.env, the .env in the directory Claude Code runs in (and the enclosing authentik checkout), and a .env co-located with the server (plugins/admin/mcp-servers/code-mode/.env, git-ignored — see .env.example; highest precedence). The token should be the scoped read-only identity from provision-agent-identity.py, never a superuser token:

uv run ak shell < .../mcp-servers/code-mode/scripts/provision-agent-identity.py   # prints AUTHENTIK_READ_TOKEN=...

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages