fireflies-prod-checklist
A checklist for deploying Fireflies.ai integrations to production, covering security and health monitoring.
Install
mkdir -p .claude/skills/fireflies-prod-checklist && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8783" && unzip -o skill.zip -d .claude/skills/fireflies-prod-checklist && rm skill.zipInstalls to .claude/skills/fireflies-prod-checklist
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Execute Fireflies.ai production deployment checklist with health checksKey capabilities
- →Validate production API key configuration
- →Implement HMAC-SHA256 webhook signature verification
- →Deploy health check endpoints for monitoring
- →Configure alerting for API errors and rate limits
- →Execute rollback procedures
How it works
The checklist ensures production readiness by verifying API keys, securing webhooks with signature checks, and implementing health check endpoints that monitor connectivity to the Fireflies API.
Inputs & outputs
When to use fireflies-prod-checklist
- →Securing production API keys in environment managers
- →Implementing webhook signature verification
- →Verifying integration health in staging environments
- →Setting up rate limiting and exponential backoff
About this skill
Fireflies Production Readiness Gate
Overview
Run a fail-closed readiness review for a Fireflies integration covering identity, schema contracts, privacy, quotas, webhooks, observability, rollback, and ownership.
Prerequisites
- The target repository or integration path and the requested operator outcome.
- The Fireflies principal, team, environment, and data classification for the work.
- Current Fireflies documentation, credentials only when needed, and an accountable approver.
Current Contract
Readiness is evidence, not a successful demo. The release must prove its exact operations, selected fields, permission model, quotas, webhook behavior, failure modes, rollback, and retention controls against the current public contract.
Authentication
For authenticated operations, inject FIREFLIES_API_KEY from an approved secret manager and send it only as Authorization: Bearer REDACTED_KEY to https://api.fireflies.ai/graphql. Never print, commit, place in a URL, forward to a browser, or include the key in evidence. Webhook signing secrets are separate credentials and must not be reused as API keys.
Instructions
- Pin the release revision and enumerate GraphQL operations and Webhooks V2 events.
- Verify secret ownership, rotation, redaction, and environment isolation.
- Review every selected field and derived output against classification and retention.
- Exercise success, GraphQL error, timeout, throttling, null/processing, invalid signature, and duplicate webhook paths.
- Confirm operation-specific budgets, queue limits, alerts, dashboards, and runbooks.
- Test rollback or feature disablement without deleting source records.
- Obtain accountable approvals and archive a content-free launch receipt.
Tool Discipline
Use Read, Glob, and Grep to inspect code, configuration, tests, and evidence. Use Write/Edit only for approved implementation or documentation changes. Do not query Fireflies, retrieve meeting content, create an AskFred thread, upload media, change account state, replay an event, or deploy merely because this skill was invoked.
Approval Boundaries
Require approval before production enablement, elevated roles, broad meeting access, destructive mutations, or accepting an untested rollback.
Output
Return the exact operation or event surface, environment, authorization class, selected field groups, validation results, content-free metrics, decisions, and a concise pass/fail receipt. Keep secrets and meeting-derived content out of general output.
Validation
Before reporting success, rerun the smallest relevant deterministic check, compare actual state with the requested outcome and current contract, verify no secret or meeting-derived content entered logs or artifacts, and record unresolved uncertainty explicitly.
Error Handling
- Any required evidence absent: fail the gate.
- Schema or docs changed after review: rerun affected checks.
- Rollback cannot stop writes or webhook processing: do not launch.
Examples
- "Review fireflies production readiness gate" produces a bounded plan and redacted receipt.
- A request that widens access or mutates production is paused at the approval boundary.
Resources
Read official Fireflies.ai evidence before relying on a field, filter, event, permission, plan limit, mutation, or processing state.
When not to use it
- →Development environments without production-grade security
- →Systems lacking monitoring infrastructure
Prerequisites
Limitations
- →Requires HTTPS for webhook endpoints
- →Webhook handler must process events asynchronously
How it compares
This process provides a structured verification path for production deployment, including specific health checks and rollback steps, rather than relying on manual testing.
Compared to similar skills
fireflies-prod-checklist side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| fireflies-prod-checklist (this skill) | 0 | 2mo | Caution | Advanced |
| django-verification | 5 | 6mo | Review | Intermediate |
| deployment-validation-config-validate | 1 | 5mo | Review | Advanced |
| documenso-prod-checklist | 1 | 2mo | Caution | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
django-verification
affaan-m
Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
deployment-validation-config-validate
sickn33
You are a configuration management expert specializing in validating, testing, and ensuring the correctness of application configurations. Create comprehensive validation schemas, implement configurat
documenso-prod-checklist
jeremylongshore
Execute Documenso production deployment checklist and rollback procedures. Use when deploying Documenso integrations to production, preparing for launch, or implementing go-live procedures. Trigger with phrases like "documenso production", "deploy documenso", "documenso go-live", "documenso launch checklist".
gh-actions-validator
jeremylongshore
Validate use when validating GitHub Actions workflows for Google Cloud and Vertex AI deployments. Trigger with phrases like "validate github actions", "setup workload identity federation", "github actions security", "deploy agent with ci/cd", or "automate vertex ai deployment". Enforces Workload Identity Federation (WIF), validates OIDC permissions, ensures least privilege IAM, and implements security best practices.
ideogram-multi-env-setup
jeremylongshore
Configure Ideogram across development, staging, and production environments. Use when setting up multi-environment deployments, configuring per-environment secrets, or implementing environment-specific Ideogram configurations. Trigger with phrases like "ideogram environments", "ideogram staging", "ideogram dev prod", "ideogram environment setup", "ideogram config by env".
perplexity-prod-checklist
jeremylongshore
Execute Perplexity production deployment checklist and rollback procedures. Use when deploying Perplexity integrations to production, preparing for launch, or implementing go-live procedures. Trigger with phrases like "perplexity production", "deploy perplexity", "perplexity go-live", "perplexity launch checklist".