Store authentication tokens securely
SkillFiles & storagetoken-storage-security is a skill for reviewing how authentication tokens are stored in a web application. It helps you find places where tokens could be stolen through cross-site scripting, and it supports setting up a new auth system with safer storage choices. Use it when you are auditing an existing login flow or deciding where to keep tokens in a new one.
Use Store authentication tokens securely in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Store authentication tokens securely and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Store authentication tokens securely skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Have the authentication code or design for the application you want to review.
What your AI can do with it
- Review an authentication implementation for token storage risks
- Identify storage choices that expose tokens to XSS-based theft
- Evaluate a new auth system's token storage approach
- Flag token handling patterns that increase theft risk
Getting started
- Have the authentication code or design for the application you want to review.
- Add the token-storage-security skill to your agent's available skills.
- Point the agent at the relevant auth files or describe the current token storage approach.
- Ask the agent to review the implementation for XSS-based token theft risks.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/token-storage-security/SKILL.md and read by ahel’s review.
localStorage is accessible to any JavaScript running on the page. A single XSS vulnerability — including one in a third-party script — can exfiltrate all tokens silently. httpOnly cookies are completely invisible to JavaScript; even if an attacker executes arbitrary code on the page, they cannot read the cookie. This single architectural choice eliminates the most common token theft vector.
Quick Reference
- Store session tokens and JWTs in httpOnly cookies — not localStorage
- localStorage is readable by any JavaScript on the page, including injected XSS code
- Combine httpOnly with Secure and SameSite=Strict (or Lax) cookie flags
- Use short-lived access tokens and rotate refresh tokens on each use
- Protect every state-changing request with CSRF defenses, not cookie flags alone
Check
Check whether authentication tokens are stored in httpOnly cookies or in JavaScript-accessible storage like localStorage. Verify that POST, PUT, PATCH, and DELETE requests also require a CSRF token or an equivalent anti-forgery control.
Fix
Move token storage from localStorage/sessionStorage to httpOnly cookies set by the server, and ensure the cookies have Secure and SameSite flags. Add CSRF protection to every state-changing route that relies on browser-sent credentials.
Explain
Explain why localStorage is vulnerable to XSS token theft and how httpOnly cookies mitigate this attack vector.
Code Review
Review authentication flows, token storage calls, and API client code. Flag any use of localStorage.setItem, sessionStorage.setItem, or document.cookie for storing access tokens, JWTs, or session identifiers. Also flag credentialed mutations that lack a CSRF token, Origin check, or same-site enforcement.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/token-storage-security
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Oct 2026
Questions
- When should I use this skill?
- Use it when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based token theft.
- What does it check for?
- It checks how authentication tokens are stored and whether that storage exposes them to theft through cross-site scripting.
- Does it fix the issues it finds?
- The skill reviews and identifies risks. It does not state that it changes code or applies fixes.
- Can it review a new auth system before any code is written?
- Yes. The skill is meant for setting up a new auth system, so it can evaluate a planned token storage approach.
Advanced
- Item type
- skill
- Key
token-storage-security- Source
- github.com/thedaviddias/front-end-checklist
github.com/thedaviddias/front-end-checklist
Related picks
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretsowasp-security
Skill · davila7
The pick for Web (OWASP)security-and-hardening
Skill · addyosmani
The pick for Web (OWASP)pptx
Skill · anthropics
More in Files & storagedocx
Skill · anthropics
More in Files & storage