From fuse-tanstack-start
Use when: adding authentication/authorization to a TanStack Start app — protecting routes with beforeLoad + redirect, authorizing server functions, sessions/cookies (useSession, getRequest), CSRF, or wiring Auth.js. Do NOT use for: generic route guards unrelated to auth (react-tanstack-router) or non-Start Node auth.
How this skill is triggered — by the user, by Claude, or both
Slash command
/fuse-tanstack-start:start-authThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
**`beforeLoad` + `redirect()` protects the UI, NOT your data.**
beforeLoad + redirect() protects the UI, NOT your data.
Server functions and server routes are API endpoints reachable independently of whichever route renders the calling component. A beforeLoad guard keeps a user off a screen, but the underlying createServerFn handler can still be called directly (crafted request, replayed RPC). Authorization MUST be enforced inside the server-function handler or its middleware — that is the security boundary. beforeLoad is route UX only.
Route beforeLoad guard → UX: keep users out of screens they can't use
Server-fn middleware → SECURITY: the real data/API boundary — enforce auth HERE
→ data-boundary.md is mandatory reading before writing any auth code.
Before ANY implementation, spawn in parallel:
src/routes/_authed*, src/server/, existing session code/websites/tanstack_start_framework_reactuseSession, createMiddleware, getRequest signaturesAfter implementation, run fuse-ai-pilot:sniper, then consider fuse-security:auth-audit.
| Concern | Primitive |
|---|---|
| Route UX | beforeLoad + redirect({ to: '/login' }) in an _authed layout route |
| Data authorization | authMiddleware on every private createServerFn (the real boundary) |
| Sessions | useSession<T>() (sealed cookie) OR manual __Host- cookie via getRequest/setResponseHeader |
| CSRF | createCsrfMiddleware() (auto for server fns) + Origin check for sibling subdomains |
authMiddleware; never rely on beforeLoad.SameSite=Lax protects them.process.env.SECRET inside the handler, NEVER at module scope (leaks to bundle; undefined on edge).The official authentication guide lists Clerk, WorkOS, Better Auth, and Auth.js as supported options, plus fully DIY. This skill ships the DIY server-primitive templates (portable, no vendor lock-in), which the official guide documents in depth. For a managed library (Auth.js, Better Auth, Clerk, WorkOS), install it and follow ITS current docs / the better-auth skill — do NOT assume a Start adapter API without verifying it, and note there is no first-party start-authjs example in the TanStack repo (the real DIY examples are start-basic-auth and start-supabase-basic).
| Topic | Reference | Load when |
|---|---|---|
| Data boundary | data-boundary.md | ALWAYS first — where auth is actually enforced |
| Route protection | route-protection.md | Building the _authed layout + RBAC redirects |
| Sessions & cookies | sessions-cookies.md | Issuing/reading sessions, cookie flags |
| Hardening | hardening.md | CSRF, rate limiting, OAuth state/PKCE, timing |
| Template | When to Use |
|---|---|
| authed-middleware.md | _authed layout + authMiddleware + protected server fn |
| session-and-csrf.md | Cookie session helpers + global CSRF/origin middleware + login |
| oauth-pkce.md | OAuth authorization-code flow with state + PKCE |
authMiddleware so every handler gets a typed session__Host- prefixed, HttpOnly, Secure, SameSite=Lax cookiesOrigin on non-GET requests against your app originbeforeLoad as the security boundaryprocess.env at module top levelnpx claudepluginhub fusengine/agents --plugin fuse-tanstack-startGuides completion of development work by verifying tests, detecting environment, and presenting structured options for merge, PR, or cleanup.
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.
Dispatches multiple subagents concurrently for independent tasks without shared state. Use when facing 2+ unrelated failures or subsystems that can be investigated in parallel.