CtrlK
BlogDocsLog inGet started
Tessl Logo

adding-project-secret-api-key-auth

How to gate a PostHog API endpoint with project secret API key (PSAK) auth — a project-scoped, user-less service credential. Use when adding PSAK support to a viewset action, allowing a new scope for PSAKs, handling synthetic users (ProjectSecretAPIKeyUser), or choosing PSAK-aware rate throttles. Trigger terms: PSAK, ProjectSecretAPIKey, project secret API key, phs_ token, service auth, programmatic endpoint auth.

74

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

—

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, highly actionable wiring checklist with concrete code and file paths throughout, plus a dedicated testing validation section. It is lean and codebase-specific, with only minor conciseness and inline-organization room for improvement.

Suggestions

Tighten framing prose such as "The machinery is shipped but nothing is wired to it yet — the first planned consumer is the endpoints (the product) run action" to the essential fact, improving conciseness.

Add an inline validation checkpoint after the four wiring steps (e.g. "Run the test cases below before considering the action live") to give the workflow an explicit validate-then-proceed gate.

Consider moving the throttle-pair details and the synthetic-user caveats into a short reference file so the main checklist stays a lean overview, improving progressive disclosure.

DimensionReasoningScore

Conciseness

The body is dense and codebase-specific, assuming Django/DRF competence and explaining only PSAK machinery Claude would not know (synthetic-user behavior, default-deny, throttle buckets); a few framing phrases like "The machinery is shipped but nothing is wired to it yet" could be trimmed but earn their place.

4 / 5

Actionability

Provides copy-paste-ready code at every step — the scope tuple, the viewset with authentication_classes and psak_allowed_actions, named throttle classes, the isinstance/bypass snippet, a curl call, and exact file paths — covering the common wiring cases fully.

5 / 5

Workflow Clarity

The four required steps are explicitly numbered and sequenced ("Four things, all required"), and the Testing section lists required validation cases, but there is no inline validate-then-proceed gate or error-recovery feedback loop within the steps themselves.

4 / 5

Progressive Disclosure

Well-organized into clear sections (What a PSAK is, Wiring checklist, What you get for free, Calling, Testing) with no nested references; slightly over the simple-skill line count, and some inline detail (e.g. throttle specifics) could be externalized, but structure is solid.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, complete, and well-targeted: it states concrete capabilities, gives an explicit Use-when clause with natural trigger terms, and carves out a distinct niche. It uses appropriate third-person voice with no padding or over-claims.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "gate a PostHog API endpoint," "adding PSAK support to a viewset action," "allowing a new scope," "handling synthetic users," "choosing PSAK-aware rate throttles" — giving comprehensive coverage of the capability rather than vague language.

5 / 5

Completeness

Clearly answers "what" (gate an endpoint with PSAK auth, a project-scoped user-less credential) and "when" ("Use when adding PSAK support... allowing a new scope... handling synthetic users..."), with concrete trigger phrases.

5 / 5

Trigger Term Quality

Explicit "Trigger terms" list covers natural synonyms and the token format a developer would actually say: "PSAK, ProjectSecretAPIKey, project secret API key, phs_ token, service auth, programmatic endpoint auth."

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (PSAK auth in PostHog) with distinct triggers like "phs_ token" and "ProjectSecretAPIKeyUser," making accidental triggering for an unrelated skill very unlikely.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
PostHog/posthog
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.