Agent skill

Langfuse Enterprise Rbac

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Configure Langfuse enterprise organization management and access control.

MITAuto-check passedBackend & APIs

Install Langfuse Enterprise Rbac

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langfuse-enterprise-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace langfuse-enterprise-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/langfuse-enterprise-rbac .claude/skills/langfuse-enterprise-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
langfuse-enterprise-rbac
GitHub stars
2.8k
Token cost
~1.9k tokens
SKILL.md length
389 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Configure Langfuse enterprise organization management and access control.

  • Works in 5 steps: Organization and Project Structure → Scoped API Keys → Self-Hosted Access Control → …
  • Implementing team access controls
  • SKILL.md covers Overview, Prerequisites, Langfuse Built-In Roles and Instructions, plus 5 more sections
  • Needs ENCRYPTION_KEY and NEXTAUTH_SECRET

What it does

Langfuse Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure Langfuse enterprise organization management and access control. Use when implementing team access controls, configuring organization settings, or setting up role-based permissions for Langfuse projects. Trigger with phrases like "langfuse RBAC", "langfuse teams", "langfuse organization", "langfuse access control", "langfuse permissions".

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Authorization and RBAC and LLM observability. It works with Langfuse. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Implementing team access controls
  • Configuring organization settings
  • Setting up role-based permissions for Langfuse projects
  • With phrases like langfuse RBAC

Example prompts

  • “langfuse RBAC”
  • “langfuse teams”
  • “langfuse organization”
  • “/langfuse-enterprise-rbac”

Requirements

  • Docker
  • A credential in LANGFUSE_PUBLIC_KEY
  • A credential in ENCRYPTION_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Organization and Project Structure
  2. Scoped API Keys
  3. Self-Hosted Access Control
  4. SSO Integration
  5. Audit Logging

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • langfuse.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ENCRYPTION_KEY
    • NEXTAUTH_SECRET
    • LANGFUSE_PUBLIC_KEY
    • AUTH_CUSTOM_CLIENT_SECRET
    • SAML_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Langfuse Enterprise Rbac loads about 1.9k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 389 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 389 words, ~1,932 tokens.

Download SKILL.mdSave it as .claude/skills/langfuse-enterprise-rbac/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
langfuse-enterprise-rbac
description
Configure Langfuse enterprise organization management and access control. Use when implementing team access controls, configuring organization settings, or setting up role-based permissions for Langfuse projects. Trigger with phrases like "langfuse RBAC", "langfuse teams", "langfuse organization", "langfuse access control", "langfuse permissions".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
version
1.17.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, langfuse, rbac

Langfuse Enterprise RBAC

Overview

Configure enterprise access control for Langfuse: built-in roles and permissions, scoped API keys per service, SSO integration, project-level isolation, and audit logging for compliance.

Prerequisites

  • Langfuse Cloud (Team/Enterprise plan) or self-hosted instance
  • Organization admin access
  • SSO provider (optional, for SAML/OIDC integration)

Langfuse Built-In Roles

Langfuse provides these roles at the project level:

RoleView TracesCreate TracesManage PromptsManage MembersManage Billing
OwnerYesYesYesYesYes
AdminYesYesYesYesNo
MemberYesYesYesNoNo
ViewerYesNoNoNoNo

Instructions

Step 1: Organization and Project Structure
Organization: Acme Corp
├── Project: production-chatbot
│   ├── Owner: engineering-lead@acme.com
│   ├── Admin: senior-dev@acme.com
│   ├── Member: developer@acme.com
│   └── API Key: sk-lf-prod-chatbot-...
│
├── Project: staging-chatbot
│   ├── Admin: senior-dev@acme.com
│   ├── Member: developer@acme.com
│   └── API Key: sk-lf-staging-chatbot-...
│
└── Project: analytics-readonly
    ├── Admin: data-lead@acme.com
    ├── Viewer: analyst@acme.com
    └── API Key: sk-lf-analytics-...

Best practice: Separate projects for production, staging, and analytics. Never share API keys across environments.

Step 2: Scoped API Keys

Create API keys with specific purposes and rotate regularly:

typescript
// In Langfuse UI: Settings > API Keys > Create
// Each key pair (public + secret) is scoped to one project

// Service-specific keys
// Backend API:     pk-lf-prod-api-...  / sk-lf-prod-api-...
// CI/CD pipeline:  pk-lf-ci-...       / sk-lf-ci-...
// Analytics:       pk-lf-analytics-... / sk-lf-analytics-...

// Validate key scope at startup
function validateApiKeyScope(expectedProject: string) {
  const pk = process.env.LANGFUSE_PUBLIC_KEY || "";

  if (!pk.includes(expectedProject)) {
    console.warn(
      `WARNING: API key may not match expected project: ${expectedProject}`
    );
  }
}

// Key rotation script
async function rotateApiKeys() {
  // 1. Create new key pair in Langfuse UI
  // 2. Deploy new keys to secret manager
  // 3. Wait for all instances to pick up new keys
  // 4. Revoke old key pair in Langfuse UI

  console.log("Key rotation checklist:");
  console.log("1. [ ] New key pair created in Langfuse");
  console.log("2. [ ] New keys deployed to secret manager");
  console.log("3. [ ] All services restarted with new keys");
  console.log("4. [ ] Old key pair revoked in Langfuse");
  console.log("5. [ ] Verified traces flowing with new keys");
}
Step 3: Self-Hosted Access Control
yaml
# docker-compose.yml -- enterprise hardening
services:
  langfuse:
    image: langfuse/langfuse:latest
    environment:
      # Disable public registration
      - AUTH_DISABLE_SIGNUP=true

      # SSO enforcement for your domain
      - AUTH_DOMAINS_WITH_SSO_ENFORCEMENT=acme.com

      # Default role for new project members
      - LANGFUSE_DEFAULT_PROJECT_ROLE=VIEWER

      # Encrypt data at rest
      - ENCRYPTION_KEY=${ENCRYPTION_KEY}

      # Session security
      - NEXTAUTH_SECRET=${NEXTAUTH_SECRET}
Step 4: SSO Integration

SAML Setup (Okta, Azure AD, OneLogin):

  1. In your IdP, create a new SAML application for Langfuse
  2. Configure the SSO callback URL: https://langfuse.your-domain.com/api/auth/callback/saml
  3. Set the entity ID: https://langfuse.your-domain.com
  4. Map IdP groups to Langfuse roles:
yaml
# Self-hosted SSO configuration
services:
  langfuse:
    environment:
      - AUTH_CUSTOM_CLIENT_ID=${SAML_CLIENT_ID}
      - AUTH_CUSTOM_CLIENT_SECRET=${SAML_CLIENT_SECRET}
      - AUTH_CUSTOM_ISSUER=https://your-idp.com/saml
      - AUTH_DOMAINS_WITH_SSO_ENFORCEMENT=acme.com
Step 5: Audit Logging

Track access and permission changes for compliance:

typescript
// Application-level audit logging for Langfuse operations
import { LangfuseClient } from "@langfuse/client";

interface AuditEvent {
  timestamp: string;
  actor: string;
  action: string;
  resource: string;
  details: Record<string, any>;
}

const auditLog: AuditEvent[] = [];

function logAuditEvent(event: Omit<AuditEvent, "timestamp">) {
  const entry: AuditEvent = {
    ...event,
    timestamp: new Date().toISOString(),
  };
  auditLog.push(entry);
  console.log(`[AUDIT] ${entry.action}: ${entry.resource} by ${entry.actor}`);

  // In production: send to your SIEM or audit log service
  // await sendToSIEM(entry);
}

// Audit Langfuse API key usage
function auditedLangfuseClient(actor: string): LangfuseClient {
  const client = new LangfuseClient();

  // Log score creation
  const originalScoreCreate = client.score.create.bind(client.score);
  client.score.create = async (params) => {
    logAuditEvent({
      actor,
      action: "score.create",
      resource: `trace:${params.traceId}`,
      details: { scoreName: params.name },
    });
    return originalScoreCreate(params);
  };

  return client;
}

Access Control Checklist

CategoryRequirementImplementation
AuthenticationSSO enforced for org domainAUTH_DOMAINS_WITH_SSO_ENFORCEMENT
RegistrationPublic signup disabledAUTH_DISABLE_SIGNUP=true
Default roleLeast privilegeLANGFUSE_DEFAULT_PROJECT_ROLE=VIEWER
API keysPer-service, per-environmentSeparate keys in secret manager
Key rotationQuarterly or on compromiseDocumented rotation procedure
Data encryptionAt-rest encryptionENCRYPTION_KEY configured
Audit trailAll access loggedApplication-level audit logging
Show full SKILL.md (150 more words)Show less

Error Handling

IssueCauseSolution
Permission deniedInsufficient roleRequest role upgrade from project owner
SSO login failsWrong callback URLVerify SAML callback URL matches
API key rejectedWrong project or revokedCreate new key pair for correct project
New user gets no accessNot added to projectAdmin must invite to specific project

Output

Produce an access-control record identifying the project, role mapping, SSO enforcement state, and audit-log destination. Include a least-privilege verification result for a viewer, member, and administrator; never include client secrets, API keys, or IdP assertions.

Examples

Map an IdP engineering group to the minimum project role, sign in with a test user, and confirm it cannot perform administrator actions. For a key-rotation event, revoke the old project key, create a replacement in the secret manager, update the owning service, and confirm its audit event is recorded.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/langfuse-enterprise-rbac of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Langfuse Enterprise Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Langfuse Enterprise Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Langfuse Enterprise Rbac this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: PassMIT
Security Reviewlangfuse/langfuse36k—~1.4kAutomated safety check: PassCustom licence
Backend Dev Guidelineslangfuse/langfuse36k—~1.9kAutomated safety check: PassCustom licence
Phoenix Authorization Patternsj-morgan6/elixir-phoenix-guide167—~2.1kAutomated safety check: PassMIT
Phx Planoliver-kriska/claude-elixir-phoenix565—~1.5kAutomated safety check: PassMIT
Planoliver-kriska/claude-elixir-phoenix565—~1.6kAutomated safety check: PassMIT

Similar skills

  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    36k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Backend Dev Guidelines

    langfuse/langfuse

    Build or review Langfuse backend code. An agent skill from langfuse/langfuse.

    36k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Phoenix Authorization Patterns

    j-morgan6/elixir-phoenix-guide

    A skill your agent uses when deciding who may do what — ownership checks, policy modules, scoped queries, role-based access in LiveViews and controllers.

    167 GitHub stars~2.1k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Phx Plan

    oliver-kriska/claude-elixir-phoenix

    Plan features spanning multiple domains: billing (Stripe), auth (RBAC), real-time (Presence), webhooks, jobs (Oban).

    565 GitHub stars~1.5k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Plan

    oliver-kriska/claude-elixir-phoenix

    Plan features spanning multiple domains: billing (Stripe), auth (RBAC), real-time (Presence), webhooks, jobs (Oban).

    565 GitHub stars~1.6k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Security

    oliver-kriska/claude-elixir-phoenix

    Build and harden Phoenix auth and security — OAuth login, password hashing, sessions, RBAC, rate limiting, CSRF, XSS, SQL injection, secrets.

    565 GitHub stars~1k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Langfuse Enterprise Rbac

What does Langfuse Enterprise Rbac do?

Configure Langfuse enterprise organization management and access control. Langfuse Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure Langfuse enterprise organization management and access control.

When should I use Langfuse Enterprise Rbac?

Langfuse Enterprise Rbac fits situations like: implementing team access controls; configuring organization settings; setting up role-based permissions for Langfuse projects; with phrases like langfuse RBAC.

How do I install Langfuse Enterprise Rbac in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langfuse-enterprise-rbac -a claude-code`. Or copy the skill folder (skills/.curated/langfuse-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/langfuse-enterprise-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Langfuse Enterprise Rbac in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langfuse-enterprise-rbac -a codex`. Or copy the skill folder (skills/.curated/langfuse-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/langfuse-enterprise-rbac in your project. Codex loads it when a task matches its description.

Can I use Langfuse Enterprise Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langfuse-enterprise-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/langfuse-enterprise-rbac, .gemini/skills/langfuse-enterprise-rbac, .github/skills/langfuse-enterprise-rbac and .opencode/skills/langfuse-enterprise-rbac in your project.

What does Langfuse Enterprise Rbac need to run?

Going by SKILL.md and its folder, Langfuse Enterprise Rbac needs credentials named ENCRYPTION_KEY, NEXTAUTH_SECRET, LANGFUSE_PUBLIC_KEY and AUTH_CUSTOM_CLIENT_SECRET. Our summary lists: Docker; A credential in LANGFUSE_PUBLIC_KEY; A credential in ENCRYPTION_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Langfuse Enterprise Rbac access the network?

SKILL.md names 1 domain. As links in the text: langfuse.com. This is read from the text; nothing was executed.

Is Langfuse Enterprise Rbac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Langfuse Enterprise Rbac use?

Langfuse Enterprise Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Langfuse Enterprise Rbac use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Langfuse Enterprise Rbac?

Skills that share tags, products or a category with Langfuse Enterprise Rbac: Security Review (langfuse/langfuse, 36k stars), Backend Dev Guidelines (langfuse/langfuse, 36k stars), Phoenix Authorization Patterns (j-morgan6/elixir-phoenix-guide, 167 stars) and Phx Plan (oliver-kriska/claude-elixir-phoenix, 565 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Langfuse Enterprise Rbac?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.