Official agent skill

Adding Project Secret API Key Auth

by PostHog in PostHog/posthog

How to gate a PostHog API endpoint with project secret API key (PSAK) auth — a project-scoped, user-less service credential.

OfficialCustom licenceAuto-check passedBackend & APIs

Install Adding Project Secret API Key Auth

skills CLI
$ npx skills add PostHog/posthog --skill adding-project-secret-api-key-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PostHog/posthog adding-project-secret-api-key-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PostHog/posthog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/adding-project-secret-api-key-auth .claude/skills/adding-project-secret-api-key-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
adding-project-secret-api-key-auth
GitHub stars
40k
Token cost
~1.6k tokens
SKILL.md length
603 words
Files
1
Skills in repo
252
Repo updated
First seen
Licence
Custom licence

At a glance

How to gate a PostHog API endpoint with project secret API key (PSAK) auth — a project-scoped, user-less service credential.

  • Works in 4 steps: Whitelist the scope/action pair → Add the authenticator and opt in actions → Use PSAK-aware throttles → …
  • Adding PSAK support to a viewset action
  • SKILL.md covers What a PSAK is, Wiring a viewset action — the…, What you get for free and Calling a PSAK-gated endpoint, plus 1 more section
  • Calls curl; reaches us.posthog.com; needs PROJECT_SECRET_API_KEY

What it does

Adding Project Secret API Key Auth is an agent skill from PostHog/posthog, published by the product's own GitHub organization. How to gate a PostHog API endpoint with project secret API key (PSAK) auth — a project-scoped, user-less service credential. Use when adding PSAK support to a viewset action, allowing a new scope for PSAKs, handling synthetic users (ProjectSecretAPIKeyUser), or choosing PSAK-aware rate throttles. Trigger terms: PSAK, ProjectSecretAPIKey, project secret API key, phs token, service auth, programmatic endpoint auth.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs. It works with PostHog. The repository describes itself as: :hedgehog: PostHog is the leading platform for building self-driving products. Our developer tools – AI observability, analytics, session replay, flags, experiments, error…

When your agent uses it

  • Adding PSAK support to a viewset action
  • Allowing a new scope for PSAKs
  • Handling synthetic users (ProjectSecretAPIKeyUser)
  • Choosing PSAK-aware rate throttles

Example prompts

  • “/adding-project-secret-api-key-auth”

Requirements

  • Python 3
  • A credential in PROJECT_SECRET_API_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Whitelist the scope/action pair
  2. Add the authenticator and opt in actions
  3. Use PSAK-aware throttles
  4. Handle the synthetic user

What it can do on your machine

Read from SKILL.md and the folder at commit 10f9ad7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • us.posthog.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PROJECT_SECRET_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Adding Project Secret API Key Auth loads about 1.6k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 603 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 603 words (~1,578 tokens).

“A ProjectSecretAPIKey is a project-scoped, user-less service credential (posthog/models/project_secret_api_key.py). It behaves like a personal API key but survives users leaving the project, carries its own scopes, and authenticates as a synthetic user — not a real User row.”

— opening of SKILL.md by PostHog, Custom licence
name
adding-project-secret-api-key-auth

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/adding-project-secret-api-key-auth of PostHog/posthog.

Open the folder on GitHubat commit 10f9ad7

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in PostHog/posthog, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Adding Project Secret API Key Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Adding Project Secret API Key Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Adding Project Secret API Key Auth this skillPostHog/posthog40k—~1.6kAutomated safety check: PassCustom licence
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Paperclippaperclipai/paperclip99k—~9.6kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works15818 repos~4kAutomated safety check: PassAGPL-3.0
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT

Similar skills

  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Paperclip

    paperclipai/paperclip

    Interact with the Paperclip control plane API for task coordination and governance.

    99k GitHub stars~9.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Covers the RuView `wifi-densepose` command line binary, its Axum REST API and the WebAssembly builds for browsers and ESP32, for embedding or scripting RuView.

    97k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes

More from PostHog/posthog

All 252 skills in this repo
  • Authoring Log Alerts

    PostHog/posthog

    Official

    Author useful, low-noise log alerts on services in a PostHog project.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Official

    Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…

    40k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    40k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Exploring Apm Traces

    PostHog/posthog

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    40k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Exploring LLM Traces

    PostHog/posthog

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    40k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Investigate Metric

    PostHog/posthog

    Official

    Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.

    40k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Adding Project Secret API Key Auth

What does Adding Project Secret API Key Auth do?

How to gate a PostHog API endpoint with project secret API key (PSAK) auth — a project-scoped, user-less service credential. Adding Project Secret API Key Auth is an agent skill from PostHog/posthog, published by the product's own GitHub organization. How to gate a PostHog API endpoint with project secret API key (PSAK) auth — a project-scoped, user-less service credential.

When should I use Adding Project Secret API Key Auth?

Adding Project Secret API Key Auth fits situations like: adding PSAK support to a viewset action; allowing a new scope for PSAKs; handling synthetic users (ProjectSecretAPIKeyUser); choosing PSAK-aware rate throttles.

How do I install Adding Project Secret API Key Auth in Claude Code?

Run `npx skills add PostHog/posthog --skill adding-project-secret-api-key-auth -a claude-code`. Or copy the skill folder (.agents/skills/adding-project-secret-api-key-auth in PostHog/posthog) into .claude/skills/adding-project-secret-api-key-auth in your project. Claude Code loads it when a task matches its description.

How do I install Adding Project Secret API Key Auth in Codex?

Run `npx skills add PostHog/posthog --skill adding-project-secret-api-key-auth -a codex`. Or copy the skill folder (.agents/skills/adding-project-secret-api-key-auth in PostHog/posthog) into .agents/skills/adding-project-secret-api-key-auth in your project. Codex loads it when a task matches its description.

Can I use Adding Project Secret API Key Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog --skill adding-project-secret-api-key-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/adding-project-secret-api-key-auth, .gemini/skills/adding-project-secret-api-key-auth, .github/skills/adding-project-secret-api-key-auth and .opencode/skills/adding-project-secret-api-key-auth in your project.

What does Adding Project Secret API Key Auth need to run?

Going by SKILL.md and its folder, Adding Project Secret API Key Auth needs the command-line tools its instructions call (curl) and credentials named PROJECT_SECRET_API_KEY. Our summary lists: Python 3; A credential in PROJECT_SECRET_API_KEY.

Does Adding Project Secret API Key Auth access the network?

SKILL.md names 1 domain. In commands or code: us.posthog.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Adding Project Secret API Key Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Adding Project Secret API Key Auth use?

Adding Project Secret API Key Auth has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Adding Project Secret API Key Auth use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Adding Project Secret API Key Auth?

Skills that share tags, products or a category with Adding Project Secret API Key Auth: API Designer (Jeffallan/claude-skills, 12k stars), Paperclip (paperclipai/paperclip, 99k stars), Nodejs Backend Patterns (ever-works/ever-works, 158 stars) and OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Adding Project Secret API Key Auth?

PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog, which has 40,182 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 8, 2026.

Source: PostHog/posthog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.