Start with an agent
The easiest path for vibe coders and agents—install the AnyOAuth skill, connect the CLI or MCP, and approve sign-in in your browser.
On this page
Install the AnyOAuth skill
Give your coding agent the AnyOAuth skill. It walks through installation, browser sign-in, project setup, and adding Google/GitHub login to your app. This is the easiest starting point if you’re building with an agent.
From your project directory, install it with the Skills CLI:
npx skills add AnyOAuth/anyoauth --skill anyoauthOr, once the AnyOAuth CLI is installed:
anyoauth skill install
# For Claude Code:
anyoauth skill install --dir .claude/skills/anyoauthThe default location is .agents/skills/anyoauth/SKILL.md. The installer preserves an
existing skill rather than overwriting it. You can also copy the
raw skill into your agent’s skill directory.
Then ask your agent:
Use the AnyOAuth skill to add Google and GitHub sign-in to this app. Create or reuse a project, register the correct callback, and keep the client secret on the backend.
Install the CLI
Use Node.js 22 or newer. The package includes both the CLI and local MCP server:
npm install --global @anyoauth/cli
anyoauth --helpInitial source installation: until @anyoauth/cli is published to npm, install from
the repository. Run the following npm commands inside the cloned checkout:
git clone https://github.com/AnyOAuth/anyoauth.git
# Open the anyoauth checkout in your terminal, then:
npm ci
npm run tooling:check
npm install --global ./packages/cliSign in through the website
anyoauth login
anyoauth meThe CLI opens AnyOAuth in your browser. Sign in with Google or GitHub, compare the displayed device code with your terminal, and approve the connection. Credentials are saved locally for both CLI and MCP; you don’t need to paste an API key.
For a remote terminal, use anyoauth login --no-browser and open the displayed URL
on your own computer. Agents that need to return control to you can use
anyoauth login --start, then anyoauth login --complete after you approve.
Approval requests last 10 minutes; management sessions last 30 days.
Connect the MCP server
After installing the package, add this to a host that supports mcpServers
(such as Claude Desktop):
{
"mcpServers": {
"anyoauth": {
"command": "anyoauth",
"args": ["mcp"]
}
}
}Use an absolute executable path if your host cannot find globally installed binaries.
Restart or reconnect the host. You can also use anyoauth-mcp as the command without
arguments. For Codex, configure the equivalent stdio server:
[mcp_servers.anyoauth]
command = "anyoauth"
args = ["mcp"]The agent calls anyoauth_login to open the website and show you a code, then
anyoauth_completeLogin after approval. If you already ran anyoauth login, the
MCP server uses that saved session automatically.
Create a project
anyoauth list-projects
anyoauth create-project --json '{"name":"My app","redirectUris":["http://localhost:3000/auth/callback"],"providers":["google","github"]}'In MCP, call anyoauth_listProjects and anyoauth_createProject with the same fields.
The result includes project.id and a one-time clientSecret. Save the secret in your
backend’s secret configuration before closing the result. AnyOAuth manages the provider
applications; you don’t need your own Google/GitHub app.
Use your actual port and exact callback path. For production, register an HTTPS URL. See projects and callback protection.
Discover commands and tools
anyoauth commands
anyoauth create-project --help
anyoauth providers
anyoauth list-project-users --id app_YOUR_PROJECT_IDCLI commands and MCP input schemas are generated from the same
sign-in JSON contract and
management JSON contract. Fields and validation match on both
surfaces. The CLI accepts generated field flags, inline --json, or --input file.json
(--input - reads stdin). API results are JSON; errors go to stderr with a nonzero exit.
Management tokens control your projects and identities. They are different from the 15-minute profile tokens used by application login. The skill guides your agent through the SDK integration, including browser-bound state/PKCE, backend code exchange, identity lookup, and your application’s own session.
Local development and sign-out
For a local AnyOAuth checkout, set ANYOAUTH_API_ORIGIN=http://localhost:8787 when running
the CLI or MCP. Credentials are scoped to that origin, so a development token isn’t used
against production. The shared credential directory defaults to ~/.config/anyoauth;
ANYOAUTH_CONFIG_DIR overrides it. Files use owner-only permissions on POSIX systems.
anyoauth logoutThis revokes the installation’s saved management token. Application user sessions are owned by your app; see sessions.