Picks the right Netlify site-protection layer and disambiguates the three unrelated "auth" concepts users conflate — app-user login (Netlify Identity), site-load gating (Password Protection / project visibility), and dashboard SAML SSO. Use it when asked to password-protect a site or Deploy Preview, make a project private/public, restrict a site to your team, require SSO to view a site, set up company-wide app SSO, or invite users to a private project. Also use it for SSO-session symptoms on protected sites: "logged out mid-session", 401s after about an hour, or token expiry/refresh questions. Not for wiring auth code — route app-login setup to netlify-identity.
72
87%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
This skill routes you to the correct protection layer. It does not teach each one. These settings have no public API, CLI command, or MCP tool. Never curl api.netlify.com or read local auth tokens to inspect or change them — give the user the dashboard path and checklist. On failure, report what you tried and stop.
Users constantly conflate these. Identify which one is meant before recommending anything.
nf_jwt. → route to the netlify-identity skill; not covered here.Sessions are separate. The same provider (e.g. Google) can appear twice unrelated — Identity OAuth for app users vs. SAML IdP for team members.
Double-login footgun: a Password-Protection/team-login perimeter session and an Identity app session have no bridge — no shared cookie, no header forwarding, no JWT exchange. Don't try to wire them together. For the combined layered pattern and its tradeoffs, see references/two-layer-pattern.md.
Want company-wide app SSO with a single sign-in (no double login)? Recommend the Auth0 extension federating to the corporate IdP before the two-layer stack.
If a user reports being "logged out mid-session" or 401s on an SSO-protected site: SSO auth tokens expire after 1 hour, after which requests return 401. Sites with SSO protection return the header Netlify-Site-Protection-Expires-In — seconds until the request's token expires. Refresh proactively:
// Client-side. Checks the Netlify SSO protection header and reloads before expiry.
const res = await fetch(window.location.href, { method: "HEAD" });
const secondsLeft = Number(res.headers.get("Netlify-Site-Protection-Expires-In"));
// Tokens last 1 hour (3600s). Reload a bit early to avoid a 401.
if (!Number.isNaN(secondsLeft) && secondsLeft < 60) {
window.location.reload();
}Credit-based plans (Free, Personal, Pro) — project-level "Password Protection" is replaced by Project visibility:
https://app.netlify.com/projects/{site_name}/configuration/general/#project-visibility. Edit visibility → (Customize if a team default exists) → Public / Password (Pro only) / Private → set Preview access (Production and previews / Previews only) → Save.https://app.netlify.com/teams/{team_name}/settings/general#default-project-visibility. Options: Private for new projects / Private for all projects / Public for new projects.Enterprise / Open Source / legacy (non-Credit-based) — use Password Protection UI:
https://app.netlify.com/projects/{site_name}/configuration/general#visitor-access. Configure → Basic or Team login → scope (All deploys / Non-production deploys only) → Save.https://app.netlify.com/teams/{team_name}/settings/access#default-site-protection-settings. Applies to all sites without their own settings.Legacy → Credit-based mapping: No protection→Public · Basic protection→Password · Team protection→Private · All deploys→Production and previews · Non-production deploys only→Previews only.
Reference: https://docs.netlify.com/manage/security/secure-access-to-sites/overview/ · https://docs.netlify.com/manage/security/secure-access-to-sites/password-protection/ · https://docs.netlify.com/manage/security/secure-access-to-sites/project-visibility/
These are org conventions, not docs facts — merged into the rendered skill by ctx-gen and never generated. Owned by the skills maintainer.
references/two-layer-pattern.md.nf_jwt),
Password Protection / project visibility ("can this request load the site
at all"), and Team/Org SAML SSO ("can you log in to the Netlify
dashboard"). Sessions are separate; the same provider (Google) can appear
in two unrelated places — Identity OAuth for app users, SAML IdP for team
members. Disambiguate before recommending anything.references/two-layer-pattern.md.api.netlify.com or read local auth tokens to inspect or change them —
hand the user the dashboard path and checklist; on failure, report what
you tried and stop.Netlify-Site-Protection-Expires-In guidance is unreachable if the
skill never triggers on the symptom.0830047
Also appears in
since Sep 26, 2026
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.