Establish a least-privilege Fireflies API identity, protect its bearer key, and prove the authenticated GraphQL boundary without exposing meeting data. Use when bootstrapping or repairing an integration. Trigger with "configure Fireflies API", "Fireflies auth failed", or "rotate Fireflies key".
Create an auditable identity boundary before any transcript query or mutation. A successful request proves only that the key is accepted; it does not grant permission to enumerate or export meeting content.
Fireflies uses POST requests to https://api.fireflies.ai/graphql with Content-Type application/json and Authorization: Bearer . Obtain the key from the Fireflies Integrations page, keep it server-side, and use the smallest identity query needed to confirm the principal and team context.
For authenticated operations, inject FIREFLIES_API_KEY from an approved secret manager and send it only as Authorization: Bearer REDACTED_KEY to https://api.fireflies.ai/graphql. Never print, commit, place in a URL, forward to a browser, or include the key in evidence. Webhook signing secrets are separate credentials and must not be reused as API keys.
Use Read, Glob, and Grep to inspect code, configuration, tests, and evidence. Use Write/Edit only for approved implementation or documentation changes. Do not query Fireflies, retrieve meeting content, create an AskFred thread, upload media, change account state, replay an event, or deploy merely because this skill was invoked.
Require approval before creating, rotating, revoking, or broadening a production key, changing its owning account, or querying any real meeting record.
Return the exact operation or event surface, environment, authorization class, selected field groups, validation results, content-free metrics, decisions, and a concise pass/fail receipt. Keep secrets and meeting-derived content out of general output.
Before reporting success, rerun the smallest relevant deterministic check, compare actual state with the requested outcome and current contract, verify no secret or meeting-derived content entered logs or artifacts, and record unresolved uncertainty explicitly.
Read official Fireflies.ai evidence before relying on a field, filter, event, permission, plan limit, mutation, or processing state.
88dcf65
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.