Skip to content
Next.js Authentication logo

Next.js Authentication

Secure token storage (HttpOnly Cookies) and Middleware patterns.

ngxtm/devkit0installs8starsSecurity

SKILL.md

Full skill instructions

Authentication & Token Management

Priority: P0 (CRITICAL)

Use HttpOnly Cookies for token storage. Never use LocalStorage.

Key Rules

  1. Storage: Use cookies().set() with httpOnly: true, secure: true, sameSite: 'lax'.
  2. Access: Read tokens in Server Components via cookies().get().
  3. Protection: Guard routes in middleware.ts before rendering.

Anti-Pattern: LocalStorage

  • Security Risk: Vulnerable to XSS.
  • Performance Hit: Incompatible with Server Components (RSC). Forces client hydration and causes layout shift.