Official agent skill

Authenticating To Clickhouse

by PostHog in PostHog/posthog

Authenticate a new or changed service to ClickHouse with the rotating ch-podauth ServiceAccount token instead of a static password.

OfficialCustom licenceAuto-check passedDatabases

Install Authenticating To Clickhouse

skills CLI
$ npx skills add PostHog/posthog --skill authenticating-to-clickhouse -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PostHog/posthog authenticating-to-clickhouse --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PostHog/posthog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/authenticating-to-clickhouse .claude/skills/authenticating-to-clickhouse && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authenticating-to-clickhouse
GitHub stars
40k
Token cost
~585 tokens
SKILL.md length
235 words
Files
1
Skills in repo
254
Repo updated
First seen
Licence
Custom licence

At a glance

Authenticate a new or changed service to ClickHouse with the rotating ch-podauth ServiceAccount token instead of a static password.

  • Adding a service
  • SKILL.md covers Do and Do not
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Container that reads

What it does

Authenticating To Clickhouse is an agent skill from PostHog/posthog, published by the product's own GitHub organization. Authenticate a new or changed service to ClickHouse with the rotating ch-podauth ServiceAccount token instead of a static password. Use when adding a service, sidecar, or container that reads or writes ClickHouse, adding a new ClickHouseUser, or hand-building a ClickHouse pool or client for a custom timeout or setting. Covers the token-aware default path (syncexecute, getclient), the rule that a custom pool must pass credentialprovider or it silently stays on the static password, wiring the username so the user…

Its SKILL.md is about 590 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Data warehousing. It works with ClickHouse and PostHog. The repository describes itself as: :hedgehog: PostHog is the leading platform for building self-driving products. Our developer tools – AI observability, analytics, session replay, flags, experiments, error…

When your agent uses it

  • Adding a service
  • Container that reads
  • Writes ClickHouse
  • Adding a new ClickHouseUser

Example prompts

  • “/authenticating-to-clickhouse”

What it can do on your machine

Read from SKILL.md and the folder at commit c012c8d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authenticating To Clickhouse loads about 585 tokens when it runs. Until then it costs about 176 tokens; SKILL.md has 235 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~176
When it runs · the whole SKILL.md, loaded when a task matches
~585

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 235 words (~585 tokens).

“A service authenticates to ClickHouse with a short-lived ServiceAccount token, validated by the ch-podauth bridge, not a static password. The token rotates, so the client reads it on each use. Read posthog/clickhouse/client/AGENTS.md for the full recipe and the traps. This…”

— opening of SKILL.md by PostHog, Custom licence
name
authenticating-to-clickhouse

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/authenticating-to-clickhouse of PostHog/posthog.

Open the folder on GitHubat commit c012c8d

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in PostHog/posthog, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Authenticating To Clickhouse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authenticating To Clickhouse compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authenticating To Clickhouse this skillPostHog/posthog40k—~585Automated safety check: PassCustom licence
Keeper Stress AnalysisClickHouse/ClickHouse50k—~4.7kAutomated safety check: PassApache-2.0
Perf ComparisonClickHouse/ClickHouse50k—~3.9kAutomated safety check: NotesApache-2.0
Patch Release CheckClickHouse/ClickHouse50k—~4kAutomated safety check: NotesApache-2.0
Clickhouse Architecture Advisorvemetric/vemetric3952 repos~791Automated safety check: PassApache-2.0
Decompress BinaryClickHouse/ClickHouse50k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Keeper Stress Analysis

    ClickHouse/ClickHouse

    Analyze ClickHouse Keeper stress-test results from play.clickhouse.com / keeperstresstests data warehouse.

    50k GitHub stars~4.7k tokensUpdated today
    DatabasesAuto-check passed
  • Perf Comparison

    ClickHouse/ClickHouse

    Evaluate ClickHouse performance test results from existing CI/dashboard data or local perf.py runs.

    50k GitHub stars~3.9k tokensUpdated today
    DatabasesAuto-check: notes
  • Patch Release Check

    ClickHouse/ClickHouse

    Check whether ClickHouse's supported versions (last 3 majors + latest LTS) have recent stable patch releases, diagnose why the scheduled AutoReleases pipeline failed, and identify which releases…

    50k GitHub stars~4k tokensUpdated today
    DatabasesAuto-check: notes
  • MUST USE when designing ClickHouse architectures, selecting between ingestion or modeling patterns, or translating best practices into workload-specific system designs.

    395 GitHub starsUsed in 2 repos~791 tokens
    DatabasesAuto-check passed
  • Decompress Binary

    ClickHouse/ClickHouse

    Extract the inner ELF from a ClickHouse self-extracting clickhouse binary, including when its architecture differs from the host (e.g.

    50k GitHub stars~1.1k tokensUpdated today
    DatabasesAuto-check passed
  • Good PRs

    ClickHouse/ClickHouse

    Show a report of open ClickHouse PRs whose only non-green CI check is "CH Inc sync" (or that are fully green) — i.e.

    50k GitHub stars~1.8k tokensUpdated today
    DatabasesAuto-check passed

More from PostHog/posthog

All 254 skills in this repo
  • Authoring Log Alerts

    PostHog/posthog

    Official

    Author useful, low-noise log alerts on services in a PostHog project.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Official

    Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…

    40k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    40k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Exploring Apm Traces

    PostHog/posthog

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    40k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Exploring LLM Traces

    PostHog/posthog

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    40k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Investigate Metric

    PostHog/posthog

    Official

    Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.

    40k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Authenticating To Clickhouse

What does Authenticating To Clickhouse do?

Authenticate a new or changed service to ClickHouse with the rotating ch-podauth ServiceAccount token instead of a static password. Authenticating To Clickhouse is an agent skill from PostHog/posthog, published by the product's own GitHub organization. Authenticate a new or changed service to ClickHouse with the rotating ch-podauth ServiceAccount token instead of a static password.

When should I use Authenticating To Clickhouse?

Authenticating To Clickhouse fits situations like: adding a service; container that reads; writes ClickHouse; adding a new ClickHouseUser.

How do I install Authenticating To Clickhouse in Claude Code?

Run `npx skills add PostHog/posthog --skill authenticating-to-clickhouse -a claude-code`. Or copy the skill folder (.agents/skills/authenticating-to-clickhouse in PostHog/posthog) into .claude/skills/authenticating-to-clickhouse in your project. Claude Code loads it when a task matches its description.

How do I install Authenticating To Clickhouse in Codex?

Run `npx skills add PostHog/posthog --skill authenticating-to-clickhouse -a codex`. Or copy the skill folder (.agents/skills/authenticating-to-clickhouse in PostHog/posthog) into .agents/skills/authenticating-to-clickhouse in your project. Codex loads it when a task matches its description.

Can I use Authenticating To Clickhouse in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog --skill authenticating-to-clickhouse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authenticating-to-clickhouse, .gemini/skills/authenticating-to-clickhouse, .github/skills/authenticating-to-clickhouse and .opencode/skills/authenticating-to-clickhouse in your project.

What does Authenticating To Clickhouse need to run?

SKILL.md names no scripts, command-line tools or credentials: Authenticating To Clickhouse is instructions for the agent only.

Does Authenticating To Clickhouse access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Authenticating To Clickhouse safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authenticating To Clickhouse use?

Authenticating To Clickhouse has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Authenticating To Clickhouse use?

About 585 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authenticating To Clickhouse?

Skills that share tags, products or a category with Authenticating To Clickhouse: Keeper Stress Analysis (ClickHouse/ClickHouse, 50k stars), Perf Comparison (ClickHouse/ClickHouse, 50k stars), Patch Release Check (ClickHouse/ClickHouse, 50k stars) and Clickhouse Architecture Advisor (vemetric/vemetric, 395 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authenticating To Clickhouse?

PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog, which has 40,209 GitHub stars. The repository holds 254 skills in this directory. The repository was last updated on October 10, 2026.

Source: PostHog/posthog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.