Agent skill

Groq Enterprise Rbac

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

A skill your agent uses when you run Groq inference for multiple teams and need per-team model allow-lists, spending caps, rate limits, and key rotation — because Groq API keys have no built-in…

MITAuto-check passedBackend & APIs

Install Groq Enterprise Rbac

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill groq-enterprise-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace groq-enterprise-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/groq-enterprise-rbac .claude/skills/groq-enterprise-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
groq-enterprise-rbac
GitHub stars
2.8k
Token cost
~1.4k tokens
SKILL.md length
525 words
Files
3 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when you run Groq inference for multiple teams and need per-team model allow-lists, spending caps, rate limits, and key rotation — because Groq API keys have no built-in…

  • Works in 5 steps: API key strategy — one Groq Project (and… → Model access control — define a per-team… → API gateway — groqGateway(team,… → …
  • You run Groq inference for multiple teams and need per-team model allow-lists
  • SKILL.md covers Overview, Groq Access Model, Prerequisites and Instructions, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Groq Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use when you run Groq inference for multiple teams and need per-team model allow-lists, spending caps, rate limits, and key rotation — because Groq API keys have no built-in scopes, so access control must live in your gateway. Configure Groq organization management, API key scoping, spending controls, and team access patterns. Trigger with phrases like "groq organization", "groq RBAC", "groq enterprise", "groq team access", "groq spending limits", "groq multi-team".

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Authorization and RBAC and Rate limiting. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • You run Groq inference for multiple teams and need per-team model allow-lists
  • Key rotation — because Groq API keys have no built-in scopes
  • So access control must live in your gateway
  • With phrases like groq organization

Example prompts

  • “groq organization”
  • “groq RBAC”
  • “groq enterprise”
  • “/groq-enterprise-rbac”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. API key strategy — one Groq Project (and key) per team/environment, named {team}-{environment}-{purpose}. Register keys in a lookup
  2. Model access control — define a per-team config (allowedModels, maxTokensPerRequest, monthlyBudgetUsd, rateLimitRPM) and a…
  3. API gateway — groqGateway(team, messages, model, maxTokens) validates permissions, checks the monthly budget, rate-limits per team via…
  4. Spending controls — set an org-level cap + alerts in the Groq Console (50/80/95%, auto-pause), and track application-level per-team spend…
  5. Key rotation — zero-downtime rotation: create a new key in the same Project, deploy alongside the old key, update the secret manager…

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • console.groq.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Groq Enterprise Rbac loads about 1.4k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 123 tokens; SKILL.md has 525 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 525 words, ~1,395 tokens.

Download SKILL.mdSave it as .claude/skills/groq-enterprise-rbac/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
groq-enterprise-rbac
description
Use when you run Groq inference for multiple teams and need per-team model allow-lists, spending caps, rate limits, and key rotation — because Groq API keys have no built-in scopes, so access control must live in your gateway. Configure Groq organization management, API key scoping, spending controls, and team access patterns. Trigger with phrases like "groq organization", "groq RBAC", "groq enterprise", "groq team access", "groq spending limits", "groq multi-team".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
version
1.11.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, groq, rbac

Groq Enterprise Access Management

Overview

Manage team access to Groq's inference API through API key strategy, model-level routing controls, spending limits, and usage monitoring. Groq uses flat API keys (gsk_ prefix) with no built-in scoping -- access control is implemented at the application layer, in a gateway that sits between your teams and Groq.

Groq Access Model

  • API keys are per-organization, not per-user
  • No built-in scopes -- every key has full API access
  • Rate limits are per-organization, shared across all keys
  • Spending limits are configurable in the Groq Console
  • Projects allow creating isolated API keys with separate limits

Prerequisites

  • A Groq organization with Console access (console.groq.com) and billing configured.
  • Permission to create Groq Projects — one per team/service, each yielding its own gsk_ key.
  • A secret manager (AWS Secrets Manager, GCP Secret Manager, Vault, etc.) to store per-team keys.
  • A gateway/service layer (Node/TypeScript in these examples) that every team's traffic passes through — Groq enforces nothing per-team, so your gateway is the control point.
  • groq-sdk and p-queue installed if you use the reference gateway.

Instructions

Access control is enforced in your own gateway. The full, copy-paste implementation for every step lives in references/implementation.md; the high-level flow:

  1. API key strategy — one Groq Project (and key) per team/environment, named {team}-{environment}-{purpose}. Register keys in a lookup:

    typescript
    // Key naming convention: {team}-{environment}-{purpose}
    const KEY_REGISTRY = {
      "chatbot-prod":    "gsk_...",  // Project: chatbot-production
      "chatbot-staging": "gsk_...",  // Project: chatbot-staging
      "analytics-prod":  "gsk_...",  // Project: analytics-production
    } as const;
  2. Model access control — define a per-team config (allowedModels, maxTokensPerRequest, monthlyBudgetUsd, rateLimitRPM) and a validateRequest(team, model, maxTokens) guard that throws before any unauthorized model or oversized request reaches Groq.

  3. API gateway — groqGateway(team, messages, model, maxTokens) validates permissions, checks the monthly budget, rate-limits per team via p-queue, calls Groq with the team's key, and records usage.

  4. Spending controls — set an org-level cap + alerts in the Groq Console (50/80/95%, auto-pause), and track application-level per-team spend with recordTeamUsage, which logs threshold alerts.

  5. Key rotation — zero-downtime rotation: create a new key in the same Project, deploy alongside the old key, update the secret manager, restart, monitor 24h, then delete the old key.

See references/implementation.md for the complete code for each step.

Show full SKILL.md (195 more words)Show less

Output

Applying this skill produces a working per-team access layer in front of Groq:

  • A key registry mapping each team/environment to its own Groq Project key.
  • A TEAM_CONFIGS policy object — the source of truth for which models, token ceilings, budgets, and rate limits each team gets.
  • A gateway function that rejects unauthorized model/token/budget requests before they reach Groq and rate-limits per team.
  • Per-team spend tracking with 80%/95% threshold alerts, plus a weekly cost/token report table.
  • A documented key-rotation runbook for zero-downtime credential changes.

Error Handling

IssueCauseSolution
429 rate_limit_exceededOrg-level RPM/TPM hitTeams share org limits; reduce aggregate volume
401 invalid_api_keyKey deleted or rotatedUpdate secret manager, restart services
Budget exhaustedMonthly cap reachedIncrease cap or wait for billing cycle reset
Wrong model usedNo server-side enforcementValidate model against team config before calling Groq

Examples

Two worked examples — a weekly per-team usage dashboard and a request that gets blocked by the model allow-list — are in references/examples.md.

The gateway rejects an out-of-scope model before it ever bills Groq:

typescript
// analytics is scoped to llama-3.1-8b-instant only
await groqGateway("analytics", messages, "llama-3.3-70b-versatile", 512);
// throws: "Team analytics not authorized for model llama-3.3-70b-versatile"

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/.curated/groq-enterprise-rbac of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/examples.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Groq Enterprise Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Groq Enterprise Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Groq Enterprise Rbac this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.4kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Auth Architecturemajiayu000/litellm-rs118—~1.9kAutomated safety check: PassMIT
Springboot Securityaffaan-m/ECC277k5 repos~2kAutomated safety check: PassMIT
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Migrate Application Operationsimstudioai/sim30k—~6.3kAutomated safety check: PassApache-2.0

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Auth Architecture

    majiayu000/litellm-rs

    LiteLLM-RS Authentication Architecture. An agent skill from majiayu000/litellm-rs.

    118 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

    277k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check passed
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Create or migrate a protected Sim resource operation in the shared Principal and application-use-case architecture across internal APIs, public or versioned APIs, Copilot, and other trusted tool…

    30k GitHub stars~6.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Laravel Security

    affaan-m/ECC

    Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.

    277k GitHub starsUsed in 3 repos~2k tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Groq Enterprise Rbac

What does Groq Enterprise Rbac do?

A skill your agent uses when you run Groq inference for multiple teams and need per-team model allow-lists, spending caps, rate limits, and key rotation — because Groq API keys have no built-in…. Groq Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use when you run Groq inference for multiple teams and need per-team model allow-lists, spending caps, rate limits, and key rotation — because Groq API keys have no built-in scopes, so access control must live in your gateway.

When should I use Groq Enterprise Rbac?

Groq Enterprise Rbac fits situations like: you run Groq inference for multiple teams and need per-team model allow-lists; key rotation — because Groq API keys have no built-in scopes; so access control must live in your gateway; with phrases like groq organization.

How do I install Groq Enterprise Rbac in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill groq-enterprise-rbac -a claude-code`. Or copy the skill folder (skills/.curated/groq-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/groq-enterprise-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Groq Enterprise Rbac in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill groq-enterprise-rbac -a codex`. Or copy the skill folder (skills/.curated/groq-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/groq-enterprise-rbac in your project. Codex loads it when a task matches its description.

Can I use Groq Enterprise Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill groq-enterprise-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/groq-enterprise-rbac, .gemini/skills/groq-enterprise-rbac, .github/skills/groq-enterprise-rbac and .opencode/skills/groq-enterprise-rbac in your project.

What does Groq Enterprise Rbac need to run?

SKILL.md names no scripts, command-line tools or credentials: Groq Enterprise Rbac is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Groq Enterprise Rbac access the network?

SKILL.md names 1 domain. As links in the text: console.groq.com. This is read from the text; nothing was executed.

Is Groq Enterprise Rbac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Groq Enterprise Rbac use?

Groq Enterprise Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Groq Enterprise Rbac use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Groq Enterprise Rbac?

Skills that share tags, products or a category with Groq Enterprise Rbac: API Audit (briiirussell/cybersecurity-skills, 413 stars), Auth Architecture (majiayu000/litellm-rs, 118 stars), Springboot Security (affaan-m/ECC, 277k stars) and API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Groq Enterprise Rbac?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.