All skills
catalystbyzoho avatar

/catalyst-authentication

@4a64353

Catalyst Authentication — user login/signup, ZAID, Web SDK auth flows, OAuth token management via Connections, third-party authentication (Okta, Auth0, Duo, custom IdP), social logins (Google, Facebook, LinkedIn, Microsoft), generateCustomToken, signinWithJwt. Trigger on 'authentication', 'login', 'signup', 'getCurrentUser', 'ZAID', 'isUserAuthenticated', 'signOut', 'Connections', 'getAccessToken', 'third-party auth', 'social login', 'Google login', 'signinWithJwt', or 'generateCustomToken'. You MUST load this skill whenever implementing user login or protecting data — ZAID differs between Development and Production and is the #1 cause of auth failures after environment promotion. For Security Rules (function invocation control), route to catalyst-functions.

Use this Skill: https://skilld.dev/gh/catalystbyzoho/agent-skills/catalyst-authentication

This session only. Nothing lands on disk.

referencesconnections.md

≈633 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Overview

Connections manages OAuth2 tokens (and other auth types) for third-party service integrations. It auto-handles token refresh, so you never write refresh logic.

Built-in Default Services (25+ pre-configured):

  • Zoho services: All Zoho products (CRM, Desk, Books, Projects, etc.)
  • Third-party services: Google, MailChimp, Dropbox, DocuSign, Adobe Sign, GoToMeeting

Custom Service (manual setup required):

  • Any OAuth2, API Key, or Basic Auth provider not in the default list (e.g., GitHub, Slack, HubSpot, Salesforce, Stripe)
  • You provide: Client ID/Secret, Authorization URL, Token URL, scopes

Using a Connection in a Function

const connection = catalystApp.connection();

// Get a connector by name (configured in Console → Connections)
const connector = connection.getConnector('ZohoCRM');

// Get a valid access token (auto-refreshes if expired)
const tokenData = await connector.getAccessToken();
const accessToken = tokenData.access_token;

// Use the token to call the external API
const response = await fetch('https://www.zohoapis.com/crm/v3/Deals', {
  headers: {
    'Authorization': `Zoho-oauthtoken ${accessToken}`,
    'Content-Type': 'application/json'
  }
});
const data = await response.json();

Setup in Console

  1. Console → Connections → Create Connection
  2. Select service type (Zoho, Google, or Custom OAuth2)
  3. Provide Client ID / Client Secret
  4. Authorize the connection (OAuth consent flow)
  5. Set connection name (used as string arg to getConnector())

Custom OAuth2 Providers

For services not in the built-in list:

  1. Choose "Custom OAuth2" connection type
  2. Provide Authorization URL, Token URL, Scope
  3. Complete the OAuth consent flow

Pricing

Connections is a free feature — no additional cost per token fetch.

Common Errors

Error Cause Fix
Connection not found Connection ID wrong or not yet authorized by user Confirm the connection name in the Connections console and verify the user has completed the OAuth grant
Token refresh failed OAuth app credentials rotated or revoked by third-party Re-authenticate the connection from the Connections console
Scope not authorized Required OAuth scope was not included during connection setup Delete and recreate the connection with the correct scopes
Connection is inactive Connection was manually disabled or expired Re-enable or reconnect from Catalyst Console → Connections

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides comprehensive documentation and code samples for implementing Zoho Catalyst authentication flows, including native, social, and third-party login strategies. It correctly identifies security considerations such as environment-specific configuration (ZAID), cross-domain session handling, and secure cookie forwarding. All external resources (SDKs, APIs) originate from the vendor's own infrastructure (Zoho/Catalyst domains). No malicious patterns were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 4a64353. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 3 weeks ago
metadata
{
  "version": "2.1.2"
}

README badge

README badge for catalystbyzoho/agent-skills/catalyst-authentication