Keep Skill credentials in XMEMO_KEY or the supported device-login flow, never in public output.
Two credential paths
The Skill authenticates with XMEMO_KEY from the environment, or through the supported device-login flow. Credentials never belong in Skill output or in a file the agent can echo back.
- XMEMO_KEY in the environment or a supported secret store.
- Device login for interactive setup without pasting a token.
- Never print the token value in agent output.
Environment credential
export XMEMO_KEY='<your-xmemo-token>'
Sign in without pasting tokens
The first run can start device-code login. The user approves in the browser, and the browser page never displays the bearer token. The Skill stores a user-scoped credential file, and logout self-revokes the active token.
node skills/xmemo/scripts/xmemo-skill.mjs login
node skills/xmemo/scripts/xmemo-skill.mjs auth-status --verify
node skills/xmemo/scripts/xmemo-skill.mjs logout
Device login endpoints
These are the four endpoints the login and logout commands call. A client never needs to call them directly, but they are what the flow is built from.
POST /v1/auth/device/start # initiate device authorization code flow
POST /v1/auth/device/token # exchange device code for a session token
POST /v1/auth/token/validate # validate current token authenticity
POST /v1/auth/token/revoke-self # revoke current token and sign out
Credential handling rules
- No token exposure: discovery responses and local runtime execution never print active tokens.
- No commits: cached credentials must be kept out of version control and public repositories.
- Fail-closed: bad credentials fail the doctor check instead of silently allowing anonymous operations.
- Separate surfaces: MCP configuration is optional and isolated from the standalone Skill runtime.