express-oauth2-jwt-bearerUse when adding Auth0 token validation to Express or Node.js APIs - integrates express-oauth2-jwt-bearer SDK to protect Node.js API endpoints with JWT Bearer...
Install via ClawdBot CLI:
clawdbot install auth0/express-oauth2-jwt-bearerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/auth0/agent-skillsAudited May 10, 2026 · audit v1.0
Generated Aug 8, 2026
A SaaS provider needs to protect their multi-tenant API endpoints with JWT-based authentication to ensure only authorized customers can access their data. This skill integrates Auth0 middleware to validate tokens, handle expiry, and enforce scope-based access control.
A healthcare application requires strict access controls to comply with regulations like HIPAA. By using the skill's RBAC features, developers can enforce specific permissions (e.g., read:patient-data) on API endpoints, ensuring that only authorized healthcare providers can access sensitive information.
A fintech company needs to secure their transaction APIs to prevent unauthorized access and ensure compliance. The skill supports scope-based permissions and audience validation, which are crucial for financial services where data security is paramount.
An e-commerce platform wants to secure its order and inventory APIs to ensure only authenticated users can make purchases or manage products. The skill provides easy integration with Express middleware to validate JWT tokens, reducing setup time and complexity.
A government agency offers a public API for accessing public records but needs to ensure only authorized applications can consume it. The skill allows for audience and issuer validation, ensuring that only tokens from trusted sources are accepted, and can be integrated with Auth0's infrastructure.
The company provides a business-to-business software-as-a-service platform where customers subscribe to use the API. The skill ensures secure token-based authentication for each corporate account, enabling granular permission management via scopes.
The company offers a free tier with limited API access and premium tiers with advanced features. Using the skill's RBAC capabilities, they can manage token scopes to control access to premium endpoints, driving upgrades.
The company runs a developer platform where third-party apps access business APIs, charging per call or per user. The skill ensures secure authentication of developer tokens, enabling secure and flexible monetization of API usage.
💬 Integration Tip
Ensure your Auth0 Domain and Audience match exactly, and place the status middleware before auth() to avoid 401 on CORS preflight.
Scored Aug 8, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...