Agent skill

Provision Model Keys

by swyxio in swyxio/skills

Provision app-specific Claude, OpenAI, OpenRouter, ElevenLabs or fal.ai API keys, install secrets, rotate keys or adjust their budgets using saved authorization.

MITAuto-check passedAI & LLM Engineering

Install Provision Model Keys

skills CLI
$ npx skills add swyxio/skills --skill provision-model-keys -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install swyxio/skills provision-model-keys --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/swyxio/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/provision-model-keys .claude/skills/provision-model-keys && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
provision-model-keys
GitHub stars
175
Token cost
~1.3k tokens
SKILL.md length
667 words
Files
10 (incl. scripts, references)
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Provision app-specific Claude, OpenAI, OpenRouter, ElevenLabs or fal.ai API keys, install secrets, rotate keys or adjust their budgets using saved authorization.

  • Credential setup and lifecycle requests
  • SKILL.md covers Saved authority, Names, permissions and storage and Setup and limits
  • Runs Python scripts from its folder; needs ANTHROPIC_API_KEY and OPENAI_API_KEY
  • Not ordinary model/API implementation

What it does

Provision Model Keys is an agent skill from swyxio/skills. Provision app-specific Claude, OpenAI, OpenRouter, ElevenLabs or fal.ai API keys, install secrets, rotate keys or adjust their budgets using saved authorization. Use for credential setup and lifecycle requests, not ordinary model/API implementation.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/anthropic.md` and `references/authorization.md`).

It sits in AI & LLM Engineering, covering Model routing and gateways, Text to speech and voice and Authorization and RBAC. It works with OpenAI, ElevenLabs, OpenRouter and fal. The repository describes itself as: Agent skills for Claude Code and other AI agents. The licence is MIT.

When your agent uses it

  • Credential setup and lifecycle requests
  • Not ordinary model/API implementation

Example prompts

  • “/provision-model-keys”

Requirements

  • Python 3
  • A credential in ANTHROPIC_API_KEY
  • A credential in OPENAI_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 038ef34. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTHROPIC_API_KEY
    • OPENAI_API_KEY
    • OPENROUTER_API_KEY
    • ELEVENLABS_API_KEY
    • FAL_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Provision Model Keys loads about 1.3k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 667 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from swyxio/skills at commit 038ef34, republished under its MIT licence (© swyxio). 667 words, ~1,335 tokens.

Download SKILL.mdSave it as .claude/skills/provision-model-keys/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
provision-model-keys
description
Provision app-specific Claude, OpenAI, OpenRouter, ElevenLabs or fal.ai API keys, install secrets, rotate keys or adjust their budgets using saved authorization. Use for credential setup and lifecycle requests, not ordinary model/API implementation.

Provision model keys

Make the requested app work using its own named key and the approved starter allowance.

Saved authority

Read authorization.md. A matching active grant permits complete setup without further approval: provider project/workspace, key, secret installation, app permissions, a small synthetic paid test, budget warnings and runtime enablement. Rotation/repair stays within the same scope and allowance. Future apps qualify only when the user requests them under the approved repository owner, provider accounts and destination templates.

Default proposal: USD 5 per app per month, USD 50 aggregate per month. Once granted, renewal and small spending within that allowance require no new authorization. Budget raises, credit purchases and auto-recharge require explicit approval. Trust the user-approved private grant record; revisit its source only if provenance or scope is unclear. Current user restrictions override it.

Names, permissions and storage

Use <app>-<env>-<provider>, e.g. notes-dev-openai. Add purpose when it distinguishes multiple keys; add owner when identity would otherwise be ambiguous. Keep repository, provider account, project/workspace and key IDs in metadata; names do not enforce scope.

Give runtime keys the endpoints/models needed for the app's intended features, including necessary writes. Expand within those approved features without another permission ceremony. Keep administration, billing and unrelated resources outside the runtime key. Prefer dedicated app/environment scope over shared keys.

Install into the deployment secret store and, when needed, a private Git-ignored local file (0600); Keychain is optional. Preserve the app's existing server secret name, otherwise use ANTHROPIC_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, ELEVENLABS_API_KEY or FAL_KEY. Keep admin/management credentials in a separate secret store. Capture one-time secrets directly; never print raw creation responses or put keys in source, frontend variables, chat or command arguments.

Redact credential headers and secret fields from logs, traces and errors; disable shell tracing during secret handling and remove temporary secret files afterward. Send credentials only to verified provider HTTPS endpoints, never in URLs or forwarded across origins.

Before enabling paid traffic, verify caller authorization and bounded request size/concurrency in the app's server paths; intentionally public features need abuse limits. Keep upstream endpoints/models server-controlled so the app cannot become an unrestricted paid proxy.

Show full SKILL.md (323 more words)Show less

Setup and limits

Read the selected provider reference: OpenAI, OpenRouter, Claude, ElevenLabs or fal.ai. Verify the exact provider account and runtime target. Reconcile existing inventory before creating; inspect inventory after an ambiguous timeout instead of blindly creating twice.

Reserve the app's recurring allocation with scripts/authorization.py reserve. These commitments persist across months; provider usage resets, allocation capacity does not. Divide the app allowance across its keys/environments so they cannot each obtain a fresh USD 5 budget.

Choose budget controls in order: provider hard limit → alerts/monitoring → runtime gate. The user accepts an honestly labeled soft-budget fallback. Use an existing gate where available; implement one only if needed for this app when provider controls and warnings are insufficient. Configure warnings near 80% and at 100% where supported, otherwise show them in the app's existing budget/error flow. Distinguish budget exhaustion from rate limiting. Ask concisely before a raise: current spend, current cap and proposed new cap. Never silently raise a cap or buy credits.

Read back installed scope, permissions and budget settings; run one small synthetic test within the allowance. Stop once the app works and the selected control/warning path is verified. Save a compact secret-free receipt with grant, repo, provider IDs, destination, monthly allocation, enforcement type and result. Keep partial receipts for reconciliation; deactivate only newly created unusable keys when setup fails.

Rotation preserves current-month usage and the recurring allocation. For an approved raise from USD 5 to USD 20/month, reserve USD 15/month additional capacity and apply a new USD 20 cap. Do not clear usage on rotation, retry or deployment. Grant revocation stops future provisioning; disabling an existing key is a separate exact-target action.

For a known exposed/compromised key covered by an active rotation grant, revoke that exact key immediately, then replace it; this overrides the routine replacement-before-revocation order in provider references. Confirm revocation and record the incident without the secret; if authority does not cover that key, report exposure and request exact-key revocation approval.

© swyxio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in provision-model-keys of swyxio/skills.

  • SKILL.md
  • agents/openai.yaml
  • references/anthropic.md
  • references/authorization.md
  • references/elevenlabs.md
  • references/fal.md
  • references/openai.md
  • references/openrouter.md
  • scripts/authorization.py
  • scripts/test_authorization.py

Open the folder on GitHubat commit 038ef34

Compare with similar skills

Provision Model Keys next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Provision Model Keys compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Provision Model Keys this skillswyxio/skills175—~1.3kAutomated safety check: PassMIT
Agentstadaspetra/loop2961 repos~2.5kAutomated safety check: PassMIT
Agentselevenlabs/skills482—~6.5kAutomated safety check: PassMIT
Quota Axikunchenguid/quota-axi146—~547Automated safety check: PassMIT
Embeddings via 9Routerdecolua/9router30k—~604Automated safety check: PassMIT
Using Ccproxy Inspectorstarbaser/ccproxy350—~2.7kAutomated safety check: PassCustom licence

Similar skills

  • Agents

    tadaspetra/loop

    Build voice AI agents with ElevenLabs. An agent skill from tadaspetra/loop.

    296 GitHub starsUsed in 1 repo~2.5k tokens
    AI & LLM EngineeringAuto-check passed
  • Agents

    elevenlabs/skills

    Build voice AI agents with ElevenLabs. An agent skill from elevenlabs/skills.

    482 GitHub stars~6.5k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Quota Axi

    kunchenguid/quota-axi

    Report local Claude, Codex, Cursor, GitHub Copilot, Grok, Kimi, Z.AI, Alibaba, OpenCode Go, Antigravity, Command Code, MiniMax, MiMo, DeepSeek, OpenRouter, ElevenLabs, Devin, Muse, and Higgsfield…

    146 GitHub stars~547 tokensUpdated today
    Backend & APIsAuto-check passed
  • Embeddings via 9Router

    decolua/9router

    Generates vector embeddings through the 9Router /v1/embeddings endpoint, using models from providers such as OpenAI, Gemini, Mistral and Voyage for RAG and semantic search.

    30k GitHub stars~604 tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Using Ccproxy Inspector

    starbaser/ccproxy

    Operates the ccproxy inspector MITM system for intercepting, inspecting, and transforming LLM API traffic.

    350 GitHub stars~2.7k tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed
  • Interviews you about provider, cost, openness and image needs, then designs the models section of a mecatl settings file with aliases, slots and router categories.

    250 GitHub stars~2.7k tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from swyxio/skills

All 89 skills in this repo
  • Programmatic Agents

    swyxio/skills

    Run a selected coding-agent CLI programmatically, with latency, error, usage, cost, and trace logging.

    175 GitHub stars~2.2k tokensUpdated 5 days ago
    Auto-check passed
  • Design, implement, audit, or refresh protected username and handle namespaces for public products.

    175 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • New Mac Setup

    swyxio/skills

    Fully automated new Mac setup for fullstack web developers and AI engineers.

    175 GitHub stars~4.3k tokensUpdated 5 days ago
    Auto-check passed
  • Youtube API

    swyxio/skills

    Manage YouTube videos programmatically via the YouTube Data API v3 — upload video files, upload custom thumbnails, update video metadata (titles, descriptions, tags), and query video/channel info…

    175 GitHub stars~2.2k tokensUpdated 5 days ago
    Auto-check passed
  • Batch YouTube Studio upload workflow for videos sourced from Airtable, Google Drive, Loom, YouTube, or local files.

    175 GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check: warnings
  • Reconstruct and visually analyze paired agent, game, or policy trajectories to determine whether changed actions produced their intended effects.

    175 GitHub stars~1.8k tokensUpdated 5 days ago
    Auto-check passed

Questions about Provision Model Keys

What does Provision Model Keys do?

Provision app-specific Claude, OpenAI, OpenRouter, ElevenLabs or fal.ai API keys, install secrets, rotate keys or adjust their budgets using saved authorization. Provision Model Keys is an agent skill from swyxio/skills.ai API keys, install secrets, rotate keys or adjust their budgets using saved authorization.

When should I use Provision Model Keys?

Provision Model Keys fits situations like: credential setup and lifecycle requests; not ordinary model/API implementation.

How do I install Provision Model Keys in Claude Code?

Run `npx skills add swyxio/skills --skill provision-model-keys -a claude-code`. Or copy the skill folder (provision-model-keys in swyxio/skills) into .claude/skills/provision-model-keys in your project. Claude Code loads it when a task matches its description.

How do I install Provision Model Keys in Codex?

Run `npx skills add swyxio/skills --skill provision-model-keys -a codex`. Or copy the skill folder (provision-model-keys in swyxio/skills) into .agents/skills/provision-model-keys in your project. Codex loads it when a task matches its description.

Can I use Provision Model Keys in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add swyxio/skills --skill provision-model-keys -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/provision-model-keys, .gemini/skills/provision-model-keys, .github/skills/provision-model-keys and .opencode/skills/provision-model-keys in your project.

What does Provision Model Keys need to run?

Going by SKILL.md and its folder, Provision Model Keys needs Python for the scripts in its folder and credentials named ANTHROPIC_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY and ELEVENLABS_API_KEY. Our summary lists: Python 3; A credential in ANTHROPIC_API_KEY; A credential in OPENAI_API_KEY.

Does Provision Model Keys access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Provision Model Keys safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Provision Model Keys use?

Provision Model Keys is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Provision Model Keys use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Provision Model Keys?

Skills that share tags, products or a category with Provision Model Keys: Agents (tadaspetra/loop, 296 stars), Agents (elevenlabs/skills, 482 stars), Quota Axi (kunchenguid/quota-axi, 146 stars) and Embeddings via 9Router (decolua/9router, 30k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Provision Model Keys?

swyxio (a GitHub user) maintains it in swyxio/skills, which has 175 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 5, 2026.

Source: swyxio/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.