Store authentication tokens securely

SkillFiles & storage

token-storage-security is a skill for reviewing how authentication tokens are stored in a web application. It helps you find places where tokens could be stolen through cross-site scripting, and it supports setting up a new auth system with safer storage choices. Use it when you are auditing an existing login flow or deciding where to keep tokens in a new one.

Use Store authentication tokens securely in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Store authentication tokens securely and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Store authentication tokens securely skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Have the authentication code or design for the application you want to review.

Store authentication tokens securelyStart free

What your AI can do with it

  • Review an authentication implementation for token storage risks
  • Identify storage choices that expose tokens to XSS-based theft
  • Evaluate a new auth system's token storage approach
  • Flag token handling patterns that increase theft risk

Getting started

  1. Have the authentication code or design for the application you want to review.
  2. Add the token-storage-security skill to your agent's available skills.
  3. Point the agent at the relevant auth files or describe the current token storage approach.
  4. Ask the agent to review the implementation for XSS-based token theft risks.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/token-storage-security/SKILL.md and read by ahel’s review.

localStorage is accessible to any JavaScript running on the page. A single XSS vulnerability — including one in a third-party script — can exfiltrate all tokens silently. httpOnly cookies are completely invisible to JavaScript; even if an attacker executes arbitrary code on the page, they cannot read the cookie. This single architectural choice eliminates the most common token theft vector.

Quick Reference

  • Store session tokens and JWTs in httpOnly cookies — not localStorage
  • localStorage is readable by any JavaScript on the page, including injected XSS code
  • Combine httpOnly with Secure and SameSite=Strict (or Lax) cookie flags
  • Use short-lived access tokens and rotate refresh tokens on each use
  • Protect every state-changing request with CSRF defenses, not cookie flags alone

Check

Check whether authentication tokens are stored in httpOnly cookies or in JavaScript-accessible storage like localStorage. Verify that POST, PUT, PATCH, and DELETE requests also require a CSRF token or an equivalent anti-forgery control.

Fix

Move token storage from localStorage/sessionStorage to httpOnly cookies set by the server, and ensure the cookies have Secure and SameSite flags. Add CSRF protection to every state-changing route that relies on browser-sent credentials.

Explain

Explain why localStorage is vulnerable to XSS token theft and how httpOnly cookies mitigate this attack vector.

Code Review

Review authentication flows, token storage calls, and API client code. Flag any use of localStorage.setItem, sessionStorage.setItem, or document.cookie for storing access tokens, JWTs, or session identifiers. Also flag credentialed mutations that lack a CSRF token, Origin check, or same-site enforcement.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/security/token-storage-security

Signals

GitHub stars
74k
Forks
7k
Last commit
Oct 2026

Questions

When should I use this skill?
Use it when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based token theft.
What does it check for?
It checks how authentication tokens are stored and whether that storage exposes them to theft through cross-site scripting.
Does it fix the issues it finds?
The skill reviews and identifies risks. It does not state that it changes code or applies fixes.
Can it review a new auth system before any code is written?
Yes. The skill is meant for setting up a new auth system, so it can evaluate a planned token storage approach.
Advanced
Item type
skill
Key
token-storage-security
Source
github.com/thedaviddias/front-end-checklist