MI

middleware-protection

Implement declarative security and route protection in Next.js applications.

Install

mkdir -p .claude/skills/middleware-protection && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4274" && unzip -o skill.zip -d .claude/skills/middleware-protection && rm skill.zip

Installs to .claude/skills/middleware-protection

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Protect routes with Next.js middleware. Check authentication once, protect routes declaratively. Supports public routes, protected routes, and role-based access.
161 charsno explicit “when” trigger
Intermediate

Key capabilities

  • →Centralize authentication checks for multiple routes
  • →Implement role-based access control
  • →Refresh user sessions during SSR
  • →Inject user ID into request headers
  • →Handle API-specific error responses

How it works

The middleware intercepts all requests to verify session validity via Supabase, then either redirects unauthenticated users or injects the user ID into headers for downstream routes.

Inputs & outputs

You give it
Incoming HTTP request
You get back
Redirect response or modified request with user headers

When to use middleware-protection

  • →Protect private routes
  • →Implement role-based access
  • →Verify auth tokens on requests

About middleware-protection

Manages route-level security logic within Next.js middleware. Allows for centralized enforcement of public vs. protected routes and user roles.

Protect routes with Next.js middleware. Check authentication once, protect routes declaratively. Supports public routes, protected routes, and role-based access.

When not to use it

  • →When using client-side only routing without server-side middleware
  • →When authentication is handled entirely by a third-party service provider without custom route logic

Prerequisites

Next.jsSupabase accountEnvironment variables for Supabase URL and key

Limitations

  • →Must explicitly skip static files and internal Next.js paths
  • →Requires careful configuration to avoid redirect loops

How it compares

This approach centralizes security logic in one file rather than repeating authentication checks across every individual route handler.

Compared to similar skills

middleware-protection side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
middleware-protection (this skill)17moReviewIntermediate
auth-patterns79moReviewIntermediate
reviewing-nextjs-16-patterns1110moReviewIntermediate
better-auth510moReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

auth-patterns

davepoon

This skill should be used when the user asks about "authentication in Next.js", "NextAuth", "Auth.js", "middleware auth", "protected routes", "session management", "JWT", "login flow", or needs guidance on implementing authentication and authorization in Next.js applications.

720

reviewing-nextjs-16-patterns

djankies

Review code for Next.js 16 compliance - security patterns, caching, breaking changes. Use when reviewing Next.js code, preparing for migration, or auditing for violations.

11106

better-auth

mrgoonie

Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.

527

route-handlers

davepoon

This skill should be used when the user asks to "create an API route", "add an endpoint", "build a REST API", "handle POST requests", "create route handlers", "stream responses", or needs guidance on Next.js API development in the App Router.

14

nextjs-server-side-error-debugging

blader

Debug getServerSideProps and getStaticProps errors in Next.js. Use when: (1) Page shows generic error but browser console is empty, (2) API routes return 500 with no details, (3) Server-side code fails silently, (4) Error only occurs on refresh not client navigation. Check terminal/server logs instead of browser for actual error messages.

11

azure-keyvault-keys-ts

microsoft

Manage cryptographic keys using Azure Key Vault Keys SDK for JavaScript (@azure/keyvault-keys). Use when creating, encrypting/decrypting, signing, or rotating keys.

10

Search skills

Search the agent skills registry