npx skills add ...
npx skills add adobe/skills --skill da-auth
Use this when another step needs to call the admin.da.live API, for example before pushing HTML content, listing documents, or triggering a DA preview, and you do not already have a valid DA_TOKEN in scope from an earlier step in the same session. Covers obtaining a valid Adobe IMS access token for the DA (Document Authoring) API.
npx skills add adobe/skills --skill da-auth
Gets a valid Adobe IMS access token and stores it in DA_TOKEN for use in subsequent admin.da.live API calls.
Use this skill whenever you need to call the DA Admin API (admin.da.live) and do not already have a valid token in scope. Common cases:
Do NOT use this skill when:
DA_TOKEN earlier in the same session and it has not expired (tokens are valid for ~1 hour with a 60-second buffer)ims-na1.adobelogin.com$DA_TOKEN is set when snowflake PUTs the converted page to DA$DA_TOKEN once you have it (Source API, preview/publish)Before triggering a browser login, check whether a valid token is already cached.
If DA_TOKEN is non-empty, skip to Step 3.
Choose the option that fits the environment:
Option A (preferred) — da-auth-helper CLI:
The da-auth-helper tool handles the full IMS OAuth 2.0 implicit flow, caches the token at ~/.aem/da-token.json, and prints the token to stdout.
If npx is unavailable or slow, install globally first:
This opens a browser window. Instruct the user:
Please complete the Adobe IMS login in the browser window that just opened. The token will be captured automatically once you log in.
Success: DA_TOKEN is a non-empty JWT string starting with eyJ.
Option B — DA MCP server:
If a DA MCP server is configured in the session, use its authentication tool to start the OAuth flow and retrieve the token from the response.
Option C — Manual paste (last resort):
I need an Adobe IMS access token to push content to DA. You can copy one from your browser:
- Open da.live and log in
- Open DevTools → Network tab → find any request to
admin.da.live- Copy the
Authorization: Bearer <token>value (without theBearerprefix)- Paste it here
Confirm the token is accepted by the DA API before proceeding:
Success: HTTP 200. The token is valid — DA_TOKEN is ready for use by the calling skill.
| Symptom | Likely cause | Fix |
|---|---|---|
DA_TOKEN is empty after Step 1 | No cached token or token expired | Proceed to Step 2 |
| Browser window does not open | npx / da-auth-helper blocked or headless environment | Use Option B (MCP) or Option C (manual paste) |
npx github:adobe-rnd/da-auth-helper fails | Network restrictions on GitHub package registry | Use Option B (DA MCP server) or Option C (manual token paste) |
Step 3 returns 401 | Token expired between steps | Re-run Step 2 to refresh |
Step 3 returns 403 | Authenticated user lacks access to {{ORG}}/{{REPO}} | Ask the user to verify their DA permissions for that org/repo |
~/.aem/da-token.json