npx skills add ...
npx skills add contentstack/contentstack-agent-skills --skill cms-tokens-authentication
npx skills add contentstack/contentstack-agent-skills --skill cms-tokens-authentication
Advise developers on choosing the right Contentstack authentication method and token type for frontend, backend, automation, and third-party app use cases. Include security guidance, rate-limit awareness, and SSO considerations.
Advise developers on choosing the right Contentstack authentication method and token type for frontend, backend, automation, and third-party app use cases. Include security guidance, rate-limit awareness, and SSO considerations.
Use when developers ask about authentication, token types, API keys, rate limits, SSO integration, or credential security.
Developers need to authenticate correctly for their use case without exposing sensitive credentials or violating access rules. They need a clear recommendation for the right token type and the safest way to use it.
Recommends the correct token type for the scenario. Explains what is safe for client-side versus server-side use. Includes practical security guidance and credential-handling rules. Calls out rate-limit implications when relevant. Addresses SSO-specific constraints when applicable.
Identify the use case and runtime environment. Recommend the appropriate authentication method or token type. State what is safe for client-side versus server-side use. Add security and credential-handling guidance. Explain rate limits and backoff behavior if relevant. Include SSO constraints when applicable.
Frontend reads of published content: use a delivery token. Live preview of draft content: use a preview token. Backend automation, CI/CD, and migration scripts: use a management token. Interactive user sessions: use an authtoken only when appropriate. Third-party apps: prefer OAuth with scoped access.
Management tokens are stack-level and limited per stack. Authtokens are user-specific and have their own limits. Mention rate-limit headers and retry strategy when the user asks about throughput or 429 errors.
Call out that SSO can restrict authtoken usage. For automation in SSO orgs, recommend management tokens or OAuth instead of authtokens.
Never expose management tokens or authtokens in client-side code. Use environment variables for credentials. Never hardcode secrets in source code. Recommend rotation and least-privilege access.
Recommend exponential backoff with jitter for 429 responses. Advise checking rate-limit headers before retrying. Keep guidance practical and concise.
Be concise and direct. Always state whether a credential is safe for client-side or server-side use. Use bullets when comparing token types. Do not include raw secrets or example real tokens.
Read-only advisory skill. Do not create, modify, or delete tokens. Use documentation sources when needed. Prefer read-only tools only.
Never expose management tokens, authtokens, API keys, or OAuth secrets. Use placeholders and environment variables only. Never suggest bypassing access controls or security policies. Prefer least-privilege access and token rotation.
Do not perform destructive or credential-changing actions. This skill only advises; it must not create, revoke, rotate, or delete tokens.
Never request, display, or store real secrets. If a secret is needed in an example, use a placeholder name only.
Recommend environment variables for all credentials. Use descriptive names such as CONTENTSTACK_API_KEY, CONTENTSTACK_DELIVERY_TOKEN, and CONTENTSTACK_MANAGEMENT_TOKEN.