Home / orcaqubits / agentic-commerce-skills-plugins · medusa-commerce/skills/medusa-security/SKILL.md · GitHub

medusa-security skillA

medusa-security is agent-read markdown (skill) from orcaqubits/agentic-commerce-skills-plugins: Secure Medusa v2 applications — authentication strategies, API key types (publishable vs secret), CORS configuration, JWT and cookie secrets, admin vs store auth, and session management. Use when configuring security..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Medusa v2 Security

## Before writing code

**Fetch live docs**:
1. Web-search `site:docs.medusajs.com authentication` for auth strategies and API key setup
2. Web-search `site:docs.medusajs.com api key publishable secret` for API key types
3. Web-search `site:docs.medusajs.com CORS configuration` for cross-origin resource sharing
4. Fetch `https://docs.medusajs.com/learn/fundamentals/api-routes/middlewares` for middleware and auth config
5. Web-search `site:docs.medusajs.com medusa-config auth providers` for auth provider registration

## Authentication Architecture

### Admin vs Store Authentication

Medusa v2 separates admin and storefront authentication into distinct flows:

| Aspect | Admin Auth | Store Auth |
|--------|-----------|------------|
| **Actor type** | `user` | `customer` |
| **API scope** | `/admin/*` routes | `/store/*` routes |
| **Default provider** | `emailpass` | `emailpass` |
| **Session cookie** | Admin session cookie | Store session cookie |
| **API key support** | Secret API key (Bearer) | Publishable API key (header) |
| **JWT usage** | Admin JWT token | Customer JWT token |
…

Read the whole file at its exact version.

How to install

Latest version
mdr add orcaqubits/agentic-commerce-skills-plugins/medusa-security@git:20260326.769051f
Exact content
mdr add orcaqubits/agentic-commerce-skills-plugins/medusa-security@sha256:d7e5214e2baab44c

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_pb7ole5bljarcrph.svg)](https://markdownregistry.com/a/art_pb7ole5bljarcrph)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260326.769051f latest2026-03-26 769051f 7,067 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (7067 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

orcaqubits/agentic-commerce-skills-plugins · 39 stars · license MIT · pushed 2026-09-14 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_pb7ole5bljarcrph
GET https://markdownregistry.com/api/v1/resolve?ref=orcaqubits/agentic-commerce-skills-plugins/medusa-security
GET https://markdownregistry.com/api/v1/blob/d7e5214e2baab44c38c863eff6ddf7110e8a10839cec7bc4ab4064c56e1c1b33

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from orcaqubits/agentic-commerce-skills-plugins

a2a-agent-card skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-agent-card/SKILL.md · Create and configure A2A Agent Cards — the discovery document describing an agent's capabilities, skills…
git:20260309.786511c · audit A · 39 stars
a2a-authentication skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-authentication/SKILL.md · Implement A2A authentication — API keys, Bearer tokens, OAuth 2.0, OpenID Connect, and mutual TLS. Use when securing…
git:20260309.786511c · audit A · 39 stars
a2a-client skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-client/SKILL.md · Build an A2A client — the agent-side code that discovers other agents, sends tasks, handles responses, and manages…
git:20260309.786511c · audit A · 39 stars
a2a-dev-patterns skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-dev-patterns/SKILL.md · Apply A2A cross-cutting development patterns — orchestration topologies, idempotency, observability, agent registries…
git:20260309.786511c · audit A · 39 stars
a2a-error-handling skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-error-handling/SKILL.md · Implement A2A error handling — JSON-RPC errors, A2A-specific error codes, task failure states, retry strategies, and…
git:20260309.786511c · audit A · 39 stars
a2a-framework-integration skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-framework-integration/SKILL.md · Integrate A2A with agent frameworks — Google ADK, LangGraph, CrewAI, AutoGen, AWS Bedrock AgentCore, and Microsoft…
git:20260508.a724f54 · audit A · 39 stars
a2a-jsonrpc-transport skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-jsonrpc-transport/SKILL.md · Implement the A2A JSON-RPC 2.0 transport layer — request/response format, method routing, batch requests, and HTTP…
git:20260309.786511c · audit A · 39 stars
a2a-mcp-bridge skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-mcp-bridge/SKILL.md · Build bridges between A2A and MCP — wrap A2A agents as MCP tools, use MCP tools from A2A agents, and architect hybrid…
git:20260309.786511c · audit A · 39 stars
a2a-messages-parts skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-messages-parts/SKILL.md · Implement A2A messages and parts — TextPart, FilePart, DataPart, message roles, metadata, and content negotiation. Use…
git:20260309.786511c · audit A · 39 stars
a2a-multi-turn skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-multi-turn/SKILL.md · Implement A2A multi-turn conversations — input-required state handling, context preservation, iterative refinement, and…
git:20260309.786511c · audit A · 39 stars
a2a-push-notifications skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-push-notifications/SKILL.md · Implement A2A push notifications — callback URL registration, notification delivery, and management methods. Use when…
git:20260309.786511c · audit A · 39 stars
a2a-server skill
orcaqubits/agentic-commerce-skills-plugins · a2a-multi-agent/skills/a2a-server/SKILL.md · Build an A2A server — the agent-side endpoint that receives JSON-RPC requests, processes tasks, manages state, and…
git:20260309.786511c · audit A · 39 stars

Every file in orcaqubits/agentic-commerce-skills-plugins

Browse by kind, by grade A, or by owner.