Install and verify a server-side Runway Dev client without spending generation credits or exposing an organization key.

MITAuto-check passedBackend & APIs

Install Runway Install Auth

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill runway-install-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace runway-install-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/runway-install-auth .claude/skills/runway-install-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
runway-install-auth
GitHub stars
2.8k
Token cost
~1.4k tokens
SKILL.md length
630 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Install and verify a server-side Runway Dev client without spending generation credits or exposing an organization key.

  • Works in 6 steps: Discover the integration boundary → Resolve and pin the client → Provision the key safely → …
  • Rotating an integration
  • SKILL.md covers Overview, Prerequisites, Instructions and Authentication, plus 6 more sections
  • Reaches api.dev.runwayml.com; needs RUNWAYML_API_SECRET

What it does

Runway Install Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Install and verify a server-side Runway Dev client without spending generation credits or exposing an organization key. Use when bootstrapping or rotating an integration. Trigger with: "configure Runway API", "install Runway SDK", "verify Runway authentication".

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires server-side Runway Dev access, current first-party documentation, an approved credit budget, and controlled media storage.

It sits in Backend & APIs, covering Backend development and Authentication. It works with Runway. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Rotating an integration
  • With: configure Runway API
  • Install Runway SDK
  • Verify Runway authentication

Example prompts

  • “configure Runway API”
  • “install Runway SDK”
  • “verify Runway authentication”
  • “/runway-install-auth”

Requirements

  • Python 3
  • Node.js
  • A credential in RUNWAYML_API_SECRET
  • Compatibility (from SKILL.md): Requires server-side Runway Dev access, current first-party documentation, an approved credit budget, and controlled media storage.
  • Pre-approved tools (allowed-tools): Read, Grep, Write, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Discover the integration boundary
  2. Resolve and pin the client
  3. Provision the key safely
  4. Configure the protocol
  5. Run a read-only probe
  6. Exercise rotation and revocation

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.dev.runwayml.com

    Also links to:

    • docs.dev.runwayml.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • RUNWAYML_API_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires server-side Runway Dev access, current first-party documentation, an approved credit budget, and controlled media storage.

    From compatibility in the SKILL.md frontmatter.

Context cost

Runway Install Auth loads about 1.4k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 630 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 630 words, ~1,427 tokens.

Download SKILL.mdSave it as .claude/skills/runway-install-auth/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
runway-install-auth
description
Install and verify a server-side Runway Dev client without spending generation credits or exposing an organization key. Use when bootstrapping or rotating an integration. Trigger with: "configure Runway API", "install Runway SDK", "verify Runway authentication".
allowed-tools
Read, Grep, Write, Edit
compatibility
Requires server-side Runway Dev access, current first-party documentation, an approved credit budget, and controlled media storage.
version
2.0.0
argument-hint
[node|python|rest]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, runway, authentication, sdk, secrets

Secure Runway SDK and REST Bootstrap

Overview

Establish a reproducible client, explicit API-version contract, and non-billable authentication probe. Runway API keys are organization-scoped credentials, so a working client is not evidence that a user should retain access or that a billable generation is approved.

Prerequisites

  • Runway Dev organization and an operator authorized to manage API keys
  • Node.js 18+ or Python 3.8+, or an HTTP client for the REST path
  • A secret manager and a reviewed X-Runway-Version value

Instructions

Step 1: Discover the integration boundary

Use Read and Grep to locate runtime manifests, lockfiles, existing Runway clients, environment-variable names, and browser/server boundaries. Separate Runway Dev API access from the consumer Runway web application and from the OAuth-based Runway Dev MCP.

Step 2: Resolve and pin the client

Choose @runwayml/sdk, runwayml, or direct REST. Query the package registry and official SDK page at implementation time, review the changelog, and pin the selected compatible version in the project lockfile instead of copying a stale version from this skill.

Step 3: Provision the key safely

Create or rotate a key in the Developer Portal under the intended organization. Store it as RUNWAYML_API_SECRET in the deployment secret manager. Never place it in source, logs, screenshots, browser bundles, MCP configuration, or client-visible environment variables.

Step 4: Configure the protocol

The official SDKs read RUNWAYML_API_SECRET and supply the version header. For direct HTTP, send Authorization: Bearer <secret> and X-Runway-Version: 2024-11-06 to https://api.dev.runwayml.com; centralize both headers in one server-side client.

Step 5: Run a read-only probe

Use a documented organization or task read endpoint that the key is authorized to access. Record status, request ID, API version, and organization identity in redacted form. Do not create a generation merely to prove authentication.

Step 6: Exercise rotation and revocation

Install the replacement key, prove the read path, switch consumers, disable the old key explicitly, and prove the old key receives 401. Removing an organization member alone does not revoke an organization-scoped key.

Authentication

Runway REST authentication is a bearer API secret plus the required X-Runway-Version header. The SDKs obtain the secret from RUNWAYML_API_SECRET; browser code must call a protected server endpoint rather than receive the secret.

Show full SKILL.md (273 more words)Show less

Tool Discipline

Use Read and Grep to inspect application configuration, provider documentation, lockfiles, fixtures, schemas, tests, and redacted operational evidence before proposing a change. Use Write or Edit only for an approved implementation, configuration, test, runbook, or redacted receipt. Do not create, cancel, delete, retry, deploy, rotate, revoke, publish, or otherwise mutate production Runway resources without explicit operator approval.

Output

  • Pinned SDK or reviewed REST-client decision
  • Redacted authentication probe with organization and API-version evidence
  • Key rotation, revocation, and rollback record

Return the environment, organization alias, operation and task identifiers, API and SDK versions, model or router policy, source-contract fingerprint, task-state evidence, credit boundary, output disposition, unresolved risk, rollback state, and final decision without exposing API secrets, prompt or media contents, or temporary signed URLs.

Examples

A service replaces an exposed development key. The operator loads a new secret version, proves a read-only organization call, shifts one canary worker, disables the old key, and confirms that the disabled credential fails without issuing a paid generation.

Error Handling

FailureResponse
401 from the probeCheck the complete key, organization, disabled state, bearer header, and secret-manager mapping; do not retry blindly.
Version-header rejectionCompare the reviewed official version contract and the actual outgoing request; update one central client.
Key appears in a client bundle or logStop rollout, revoke it, purge accessible artifacts through the approved process, and issue a replacement.

Validation

Verify the resolved dependency, lockfile, server-only secret boundary, outgoing host and headers, a successful read-only probe, and a failed-old-key rotation test. Do not report success from environment-variable presence alone.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/runway-install-auth of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Runway Install Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Runway Install Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Runway Install Auth this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.4kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Laravel SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Socialite Developmenthexlet-volunteers/hexlet-sicp1145 repos~1.2kAutomated safety check: PassMIT
Passport Developmenttrypostit/trypost692—~1.9kAutomated safety check: PassMIT
Spa Auth Developmentgdarko/laravel-vue-starter145—~668Automated safety check: NotesMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    692 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Spa Auth Development

    gdarko/laravel-vue-starter

    Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

    145 GitHub stars~668 tokensUpdated 6 mo ago
    Backend & APIsAuto-check: notes
  • Developing With Fortify

    slimani-dev/muraqib

    Laravel Fortify headless authentication backend development.

    129 GitHub stars~1.3k tokensUpdated 12 days ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Runway Install Auth

What does Runway Install Auth do?

Install and verify a server-side Runway Dev client without spending generation credits or exposing an organization key. Runway Install Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Install and verify a server-side Runway Dev client without spending generation credits or exposing an organization key.

When should I use Runway Install Auth?

Runway Install Auth fits situations like: rotating an integration; with: configure Runway API; install Runway SDK; verify Runway authentication.

How do I install Runway Install Auth in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill runway-install-auth -a claude-code`. Or copy the skill folder (skills/.curated/runway-install-auth in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/runway-install-auth in your project. Claude Code loads it when a task matches its description.

How do I install Runway Install Auth in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill runway-install-auth -a codex`. Or copy the skill folder (skills/.curated/runway-install-auth in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/runway-install-auth in your project. Codex loads it when a task matches its description.

Can I use Runway Install Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill runway-install-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/runway-install-auth, .gemini/skills/runway-install-auth, .github/skills/runway-install-auth and .opencode/skills/runway-install-auth in your project.

What does Runway Install Auth need to run?

Going by SKILL.md and its folder, Runway Install Auth needs credentials named RUNWAYML_API_SECRET. Our summary lists: Python 3; Node.js; A credential in RUNWAYML_API_SECRET. Its frontmatter pre-approves these tools: Read, Grep, Write, Edit. Compatibility (from SKILL.md): Requires server-side Runway Dev access, current first-party documentation, an approved credit budget, and controlled media storage..

Does Runway Install Auth access the network?

SKILL.md names 2 domains. In commands or code: api.dev.runwayml.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.dev.runwayml.com. This is read from the text; nothing was executed.

Is Runway Install Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Runway Install Auth use?

Runway Install Auth is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Runway Install Auth use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 966 tokens, read only when the agent opens those files.

What are the alternatives to Runway Install Auth?

Skills that share tags, products or a category with Runway Install Auth: Fortify Development (coollabsio/coolify, 63k stars), Laravel Specialist (Jeffallan/claude-skills, 12k stars), Socialite Development (hexlet-volunteers/hexlet-sicp, 114 stars) and Passport Development (trypostit/trypost, 692 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Runway Install Auth?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.