skillsConfig.enabled), FrontMCP supports four authentication modes to protect skill endpoints.
Auth Modes
With
inherit, a request to /skills, /llm.txt or /llm_full.txt must pass the same check as the MCP endpoint (a static key, a transparent token, a FrontMCP-issued token…); only a public-mode server lets everyone in. Skills with authorities are listed only for a caller whose verified claims satisfy them. In the other modes no claims are available, so those skills are never served over HTTP.
Configuration
Public Mode
Disable authentication on skill endpoints regardless of the parent server’s auth.API Key Mode
API key comparison uses timing-safe equality to prevent timing attacks. All configured keys are checked even after a match is found to maintain constant-time behavior.
JWT Bearer Mode
{issuer}/.well-known/jwks.json). A token must carry exp: one without it would never expire, so it is refused (401).
Validation Result
The validator returns a structured result:Authorizing a Request
UseauthorizeSkillHttpRequest() to apply skillsConfig.auth to a request. It covers every mode, including inherit (the default), for which it runs the server’s session:verify flow, and it returns the verified caller that skill authorities are evaluated against:
Header-Only Validator (api-key, bearer)
createSkillHttpAuthValidator() builds a validator that checks the request headers for an explicit auth: 'api-key' or auth: 'bearer'. It returns null only for auth: 'public'. It can’t run the server’s auth, so for inherit or an unset auth it refuses every request (500); use authorizeSkillHttpRequest() there.