PluginBench
Skill
Pass
Audit score 90

extension-email-verification

caffeinelabs/skills

Email verification via click-to-verify links for proving email ownership.

What is extension-email-verification?

This skill adds email address verification to Caffeine AI applications by sending users a click-to-verify link. Use it when you need to confirm that users actually own the email addresses they provide during registration or profile updates.

  • Sends verification emails with unique click-to-verify links to each recipient
  • Tracks verified email addresses in a dedicated state module
  • Provides a verification mixin that handles verification link callbacks automatically
  • Integrates with the extension-email skill for email delivery
  • Prevents duplicate email registration across users
  • Supports HTML email bodies with {{VERIFICATION_URL}} placeholder substitution

How to install extension-email-verification

npx skills add https://github.com/caffeinelabs/skills --skill extension-email-verification
Prerequisites
  • Caffeine AI subscription (Plus or Pro tier)
  • extension-email skill installed for email delivery
  • Motoko development environment configured
Claude Code
Cursor
Windsurf
Cline

How to use extension-email-verification

  1. 1.Import the VerifiedEmails module to track verified addresses in your actor state
  2. 2.Include the MixinEmailVerification mixin in your actor to handle verification callbacks
  3. 3.Call EmailClient.sendVerificationEmail() with recipients, subject, and HTML body containing {{VERIFICATION_URL}}
  4. 4.Use VerifiedEmails.contains() to check if an email is verified before granting access to features
  5. 5.Store user email addresses separately and map them to principals for uniqueness validation

Use cases

Good for
  • User registration workflows requiring email confirmation before account activation
  • Email change verification to ensure users control their new email address
  • Multi-step onboarding processes that gate features behind email verification
  • Preventing spam signups by validating email ownership
  • Building trust in user identity by confirming email deliverability
Who it's for
  • Backend developers building user registration systems
  • Application architects designing account verification flows
  • Teams building on Caffeine AI requiring email validation
  • Developers using Motoko for Internet Computer applications

extension-email-verification FAQ

What happens if a user clicks the verification link multiple times?

The verification link is idempotent—clicking it multiple times simply confirms the same email address is verified. No errors or duplicate entries occur.

Can I customize the verification email content?

Yes, you provide the subject and HTML body when calling sendVerificationEmail(). The only requirement is that the HTML body must contain the {{VERIFICATION_URL}} placeholder, which is automatically replaced with the unique verification link.

How long are verification links valid?

The SKILL.md does not specify an expiration time for verification links. Check the Caffeine AI documentation or contact support for link validity duration.

Should I store email verification status in my user profile?

No. The documentation explicitly states: 'Do NOT try to track the email verification status independently by storing it against the user profile.' Always use the VerifiedEmails.contains() function instead.

What email address should I use in the 'fromUsername' parameter?

The fromUsername is typically a service identifier like 'no-reply' or 'noreply'. The actual sending email address is configured in your Caffeine AI email settings.

Full instructions (SKILL.md)

Source of truth, from caffeinelabs/skills.


name: extension-email-verification description: Support for sending an email with a link the recipient can click to prove they own the email address. version: 0.1.8 compatibility: mops: caffeineai-email-verification: "~0.1.2" caffeineai-email: "~0.2.0" caffeineai-subscription: [plus, pro]

Email — Verification

Email verification extension for Caffeine AI.

Overview

This skill adds email address verification via a click-to-verify link. The MixinEmailVerification handles the verification callback; verifiedEmails tracks verified addresses.

Backend

This component is for sending an email to users with a verification link which the user can click to prove they own the email address.

To check if an email address has been verified

Use the prefabricated module mo:caffeineai-email-verification/verifiedEmails.mo which cannot be modified.

module {
  public type State = {
    var verifiedEmails : Set.Set<Text>;
  };

  public func new() : State {
    {
      var verifiedEmails = Set.empty<Text>();
    };
  };

  public func contains(state : State, email : Text) : Bool;

  public func iter(state : State) : Iter.Iter<Text>;

  public func size(state : State) : Nat;
};

To check whether an email is verified use the contains function. Do NOT try to track the email verification status independently by storing it against the user profile.

To handle the verification link

Use the prefabricated module mo:caffeineai-email-verification/verificationMixin.mo which cannot be modified.

The MixinEmailVerification handles calls to the verification link to verify an email address.

import MixinEmailVerification "mo:caffeineai-email-verification/verificationMixin";

For sending users a verification email

  • This extension depends on the extension-email for sending emails.
  • Use the sendVerificationEmail function.
  • It returns a SendResult which is #ok if the email is sent successfully otherwise #err(error) with the error text.
  • Each recipient receives an individual email with a specific verification link for them
  • The htmlBody MUST contain the placeholder text {{VERIFICATION_URL}}
module {
  public type SendResult = {
    #ok;
    #err : Text;
  };

  public func sendVerificationEmail(
    fromUsername : Text,
    recipients : [Text],
    subject : Text,
    htmlBody : Text,
  ) : async SendResult;
};

Example usage with endpoints for registering a user and for checking whether a user is verified.

import Map "mo:core/Map";
import Runtime "mo:core/Runtime";
import Principal "mo:core/Principal";
import Text "mo:core/Text";
import EmailClient "mo:caffeineai-email/emailClient";
import MixinEmailVerification "mo:caffeineai-email-verification/verificationMixin";
import VerifiedEmails "mo:caffeineai-email-verification/verifiedEmails";

actor {
  // Stores which emails are verified
  let verifiedEmails : VerifiedEmails.State;

  // User profiles storage
  let users : Map.Map<Principal, User>;

  // Email to principal mapping for uniqueness check
  let emailToPrincipal : Map.Map<Text, Principal>;

  // Handles the verification link and updates the verifiedEmails store
  include MixinEmailVerification(verifiedEmails);

  type User = {
    name : Text;
    email : Text;
  };

  public shared ({ caller }) func registerUser(email : Text, name : Text) : async () {
    if (users.containsKey(caller)) {
      Runtime.trap("User already registered");
    };
    if (emailToPrincipal.containsKey(email)) {
      Runtime.trap("Email already registered");
    };

    let user : User = {
      name;
      email;
    };
    users.add(caller, user);
    emailToPrincipal.add(email, caller);
    let result = await EmailClient.sendVerificationEmail(
      "no-reply",
      [email],
      "Welcome to Our Service",
      "Hello " # name # ",<br><br>Thank you for registering with our service. Please <a href=\"{{VERIFICATION_URL}}\">click here</a> to verify your email address<br><br>Best regards,<br>The Team",
    );

    switch (result) {
      case (#ok) {};
      case (#err(error)) {
        Runtime.trap("Couldn't send verification email: " # error);
      };
    };
  };

  public shared ({ caller }) func isEmailVerified() : async Bool {
    let user = users.get(caller) ?? Runtime.trap("User not registered");
    VerifiedEmails.contains(verifiedEmails, user.email);
  };
};

The migration chain head:

import Map "mo:core/Map";
import VerifiedEmails "mo:caffeineai-email-verification/verifiedEmails";

module {
  type User = {
    name : Text;
    email : Text;
  };

  type NewActor = {
    verifiedEmails : VerifiedEmails.State;
    users : Map.Map<Principal, User>;
    emailToPrincipal : Map.Map<Text, Principal>;
  };

  public func migration(_old : {}) : NewActor {
    {
      verifiedEmails = VerifiedEmails.new();
      users = Map.empty<Principal, User>();
      emailToPrincipal = Map.empty<Text, Principal>();
    };
  };
};

Frontend

If there is a UI for the admin to enter the content of a verification email then indicate that the placeholder text {{VERIFICATION_URL}} must be present in the email body.