fireflies-webhooks-events
Securely process Fireflies.ai transcript webhooks with HMAC-SHA256 signature verification.
Install
mkdir -p .claude/skills/fireflies-webhooks-events && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8766" && unzip -o skill.zip -d .claude/skills/fireflies-webhooks-events && rm skill.zipInstalls to .claude/skills/fireflies-webhooks-events
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Implement Fireflies.ai webhook receiver with HMAC signature verificationKey capabilities
- →Handle Fireflies.ai webhook events for real-time transcript notifications
- →Verify HMAC-SHA256 signature of incoming webhooks
- →Process transcription completed events
- →Fetch and process the full transcript after notification
- →Extract action items and route them to downstream systems
- →Support per-upload webhooks for specific audio files
How it works
This skill sets up an HTTPS endpoint to receive Fireflies.ai webhook events, verifies the HMAC-SHA256 signature, and then processes the event payload to fetch and analyze the meeting transcript.
Inputs & outputs
When to use fireflies-webhooks-events
- →Setting up Fireflies webhook endpoints
- →Implementing HMAC signature verification
- →Building meeting transcript data pipelines
- →Handling transcription-ready notifications
About this skill
Fireflies Webhooks V2 Consumer
Overview
Implement a current Fireflies Webhooks V2 consumer with raw-body HMAC verification, event allowlisting, idempotency, ordering tolerance, and fast acknowledgement.
Prerequisites
- The target repository or integration path and the requested operator outcome.
- The Fireflies principal, team, environment, and data classification for the work.
- Current Fireflies documentation, credentials only when needed, and an accountable approver.
Current Contract
V2 payloads contain event, timestamp, meeting_id, and optional client_reference_id. Documented events include meeting.transcribed and meeting.summarized. X-Hub-Signature is sha256=<hex HMAC> over the raw body; valid deliveries need a 2xx response within 10 seconds.
Authentication
For authenticated operations, inject FIREFLIES_API_KEY from an approved secret manager and send it only as Authorization: Bearer REDACTED_KEY to https://api.fireflies.ai/graphql. Never print, commit, place in a URL, forward to a browser, or include the key in evidence. Webhook signing secrets are separate credentials and must not be reused as API keys.
Instructions
- Subscribe only to approved V2 event types at an HTTPS endpoint.
- Capture raw bytes and validate the signature format and timing-safe HMAC before JSON parsing.
- Validate event, timestamp, meeting_id, and optional client reference against a strict schema.
- Reject unknown events or route them to a quarantined metadata-only lane.
- Deduplicate using delivery metadata plus event and meeting identity, and tolerate summarized arriving after transcribed.
- Acknowledge quickly, then fetch authorized data asynchronously if needed.
- Record signature result, event type, latency, dedupe outcome, and job ID without payload content.
Tool Discipline
Use Read, Glob, and Grep to inspect code, configuration, tests, and evidence. Use Write/Edit only for approved implementation or documentation changes. Do not query Fireflies, retrieve meeting content, create an AskFred thread, upload media, change account state, replay an event, or deploy merely because this skill was invoked.
Approval Boundaries
Require approval before subscribing to team-wide events, fetching transcript content after an event, replaying a delivery, or retaining payloads.
Output
Return the exact operation or event surface, environment, authorization class, selected field groups, validation results, content-free metrics, decisions, and a concise pass/fail receipt. Keep secrets and meeting-derived content out of general output.
Validation
Before reporting success, rerun the smallest relevant deterministic check, compare actual state with the requested outcome and current contract, verify no secret or meeting-derived content entered logs or artifacts, and record unresolved uncertainty explicitly.
Error Handling
- Missing signature when verification is configured: return 401.
- Duplicate delivery: acknowledge without repeating side effects.
- Unknown event: quarantine metadata and do not infer a schema.
Examples
- "Review fireflies webhooks v2 consumer" produces a bounded plan and redacted receipt.
- A request that widens access or mutates production is paused at the approval boundary.
Resources
Read official Fireflies.ai evidence before relying on a field, filter, event, permission, plan limit, mutation, or processing state.
When not to use it
- →When webhooks are not for meetings you own
- →When `clientReferenceId` is needed for bot-recorded meetings
Prerequisites
Limitations
- →Webhooks fire only for meetings the user owns
- →Super Admin webhooks (Enterprise only) fire for all team-owned meetings
- →clientReferenceId is null if the meeting was bot-recorded
How it compares
This skill automates the secure reception and processing of Fireflies.ai transcript notifications, unlike manually checking for transcript availability or processing unverified data.
Compared to similar skills
fireflies-webhooks-events side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| fireflies-webhooks-events (this skill) | 0 | 2mo | Caution | Intermediate |
| apify-ultimate-scraper | 0 | 5mo | Review | Intermediate |
| telegram-bot-builder | 106 | 8mo | Review | Intermediate |
| chrome-devtools | 41 | 8mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
apify-ultimate-scraper
Anhvu1107
ALWAYS use this when the request matches Apify Ultimate Scraper: AI-driven data extraction from 55+ Actors across all major platforms.
telegram-bot-builder
davila7
Expert in building Telegram bots that solve real problems - from simple automation to complex AI-powered bots. Covers bot architecture, the Telegram Bot API, user experience, monetization strategies, and scaling bots to thousands of users. Use when: telegram bot, bot api, telegram automation, chat bot telegram, tg bot.
chrome-devtools
mrgoonie
Browser automation, debugging, and performance analysis using Puppeteer CLI scripts. Use for automating browsers, taking screenshots, analyzing performance, monitoring network traffic, web scraping, form automation, and JavaScript debugging.
playwright-browser-automation
lackeyjb
Complete browser automation with Playwright. Auto-detects dev servers, writes clean test scripts to /tmp. Test pages, fill forms, take screenshots, check responsive design, validate UX, test login flows, check links, automate any browser task. Use when user wants to test websites, automate browser interactions, validate web functionality, or perform any browser-based testing.
workflow-orchestration-patterns
wshobson
Design durable workflows with Temporal for distributed systems. Covers workflow vs activity separation, saga patterns, state management, and determinism constraints. Use when building long-running processes, distributed transactions, or microservice orchestration.
codex-skill
feiskyer
Use when user asks to leverage codex, gpt-5, or gpt-5.1 to implement something (usually implement a plan or feature designed by Claude). Provides non-interactive automation mode for hands-off task execution without approval prompts.