$npx -y skills add butterbase-ai/butterbase-skills --skill journey-authUse as the auth build stage of the Butterbase journey, after journey-schema (and rls if separate). Implements the Auth section of 02-plan.md by delegating to auth-setup. Calls manage_oauth (configure) for providers and optionally manage_auth_config (configure_auth_hook, update_jw
| 1 | # Journey: Auth |
| 2 | |
| 3 | Stage 3c of the guided journey. Configure OAuth providers and (optionally) auth hooks. |
| 4 | |
| 5 | ## When to use |
| 6 | |
| 7 | - Dispatched by `journey` when `current_stage: auth`. |
| 8 | - Directly via `/butterbase-skills:journey-auth`. |
| 9 | - Skipped (annotated `(n/a)` in `00-state.md`) if the plan has no end-user auth. |
| 10 | |
| 11 | ## Preflight |
| 12 | |
| 13 | If `docs/butterbase/03-preflight.md` is missing, older than 24 hours, or `00-state.md` has `app_id: null`, invoke `butterbase-skills:journey-preflight` first. Wait for it to return successfully before proceeding. |
| 14 | |
| 15 | ## Inputs |
| 16 | |
| 17 | - `docs/butterbase/02-plan.md` — the Auth section. |
| 18 | - `docs/butterbase/00-state.md` — for `app_id`. |
| 19 | |
| 20 | ## Procedure |
| 21 | |
| 22 | 0. **Refresh docs.** Call `butterbase_docs` with `topic: "auth"`. For provider-specific setup (Google/GitHub/Apple), also WebFetch `https://docs.butterbase.ai/auth`. Skip if cache is fresh. |
| 23 | |
| 24 | 1. Read the Auth section of `02-plan.md`. Print it back: `"About to configure auth: providers=<list>, demo_user=<yes/no>. Proceed?"`. Wait for `yes`. |
| 25 | 2. Invoke `butterbase-skills:auth-setup` via the Skill tool, passing the Auth plan and `app_id`. The wrapped skill will prompt for each provider's client ID/secret and call `manage_oauth action: configure`. If a demo user is requested, it seeds one via `insert_row` on the users table. |
| 26 | 3. After it returns, run `manage_oauth action: get` to confirm and print the redirect URLs the user must register with each provider. |
| 27 | 4. Append one line to `docs/butterbase/04-build-log.md`: |
| 28 | `<ISO timestamp> auth manage_oauth ok` |
| 29 | 5. Tick `- [x] auth` in `00-state.md`, set `current_stage:` to the next unchecked stage. |
| 30 | 6. Return to `journey` orchestrator (or ask `"Continue to the next stage? (yes/no)"`). |
| 31 | |
| 32 | ## Outputs |
| 33 | |
| 34 | - Configured OAuth providers. |
| 35 | - Optional seed user. |
| 36 | - One line in `04-build-log.md`. |
| 37 | |
| 38 | ## Anti-patterns |
| 39 | |
| 40 | - ❌ Echoing OAuth client secrets back to the user. |
| 41 | - ❌ Forgetting to give the user the provider-side redirect URL — auth will silently fail without it. |