groq-enterprise-rbac
Implements API key scoping and organizational access control for Groq. Prevents credential misuse across multiple teams.
Install
mkdir -p .claude/skills/groq-enterprise-rbac && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7121" && unzip -o skill.zip -d .claude/skills/groq-enterprise-rbac && rm skill.zipInstalls to .claude/skills/groq-enterprise-rbac
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Use when you run Groq inference for multiple teams and need per-team model allow-lists, spending caps, rate limits, and key rotation — because Groq API keys have no built-in scopes, so access control must live in your gateway. Configure Groq organization management, API key scoping, spending controls, and team access patterns. Trigger with phrases like "groq organization", "groq RBAC", "groq enterprise", "groq team access", "groq spending limits", "groq multi-team".Key capabilities
- →Implement per-team model allow-lists
- →Configure spending caps and budget alerts
- →Rotate Groq API keys with zero downtime
- →Create isolated Groq Projects for teams
How it works
Access control is implemented at the application layer using a gateway that validates requests against team-specific configurations before forwarding them to Groq.
Inputs & outputs
When to use groq-enterprise-rbac
- →Implement team-based model access
- →Configure spending limits per organization
- →Rotate Groq API keys securely
- →Set up per-team API key isolation
About this skill
Groq Enterprise Access Management
Overview
Manage team access to Groq's inference API through API key strategy, model-level routing controls, spending limits, and usage monitoring. Groq uses flat API keys (gsk_ prefix) with no built-in scoping -- access control is implemented at the application layer, in a gateway that sits between your teams and Groq.
Groq Access Model
- API keys are per-organization, not per-user
- No built-in scopes -- every key has full API access
- Rate limits are per-organization, shared across all keys
- Spending limits are configurable in the Groq Console
- Projects allow creating isolated API keys with separate limits
Prerequisites
- A Groq organization with Console access (console.groq.com) and billing configured.
- Permission to create Groq Projects — one per team/service, each yielding its own
gsk_key. - A secret manager (AWS Secrets Manager, GCP Secret Manager, Vault, etc.) to store per-team keys.
- A gateway/service layer (Node/TypeScript in these examples) that every team's traffic passes through — Groq enforces nothing per-team, so your gateway is the control point.
groq-sdkandp-queueinstalled if you use the reference gateway.
Instructions
Access control is enforced in your own gateway. The full, copy-paste implementation for every step lives in references/implementation.md; the high-level flow:
-
API key strategy — one Groq Project (and key) per team/environment, named
{team}-{environment}-{purpose}. Register keys in a lookup:// Key naming convention: {team}-{environment}-{purpose} const KEY_REGISTRY = { "chatbot-prod": "gsk_...", // Project: chatbot-production "chatbot-staging": "gsk_...", // Project: chatbot-staging "analytics-prod": "gsk_...", // Project: analytics-production } as const; -
Model access control — define a per-team config (
allowedModels,maxTokensPerRequest,monthlyBudgetUsd,rateLimitRPM) and avalidateRequest(team, model, maxTokens)guard that throws before any unauthorized model or oversized request reaches Groq. -
API gateway —
groqGateway(team, messages, model, maxTokens)validates permissions, checks the monthly budget, rate-limits per team viap-queue, calls Groq with the team's key, and records usage. -
Spending controls — set an org-level cap + alerts in the Groq Console (50/80/95%, auto-pause), and track application-level per-team spend with
recordTeamUsage, which logs threshold alerts. -
Key rotation — zero-downtime rotation: create a new key in the same Project, deploy alongside the old key, update the secret manager, restart, monitor 24h, then delete the old key.
See references/implementation.md for the complete code for each step.
Output
Applying this skill produces a working per-team access layer in front of Groq:
- A key registry mapping each team/environment to its own Groq Project key.
- A
TEAM_CONFIGSpolicy object — the source of truth for which models, token ceilings, budgets, and rate limits each team gets. - A gateway function that rejects unauthorized model/token/budget requests before they reach Groq and rate-limits per team.
- Per-team spend tracking with 80%/95% threshold alerts, plus a weekly cost/token report table.
- A documented key-rotation runbook for zero-downtime credential changes.
Error Handling
| Issue | Cause | Solution |
|---|---|---|
429 rate_limit_exceeded | Org-level RPM/TPM hit | Teams share org limits; reduce aggregate volume |
401 invalid_api_key | Key deleted or rotated | Update secret manager, restart services |
| Budget exhausted | Monthly cap reached | Increase cap or wait for billing cycle reset |
| Wrong model used | No server-side enforcement | Validate model against team config before calling Groq |
Examples
Two worked examples — a weekly per-team usage dashboard and a request that gets blocked by the model allow-list — are in references/examples.md.
The gateway rejects an out-of-scope model before it ever bills Groq:
// analytics is scoped to llama-3.1-8b-instant only
await groqGateway("analytics", messages, "llama-3.3-70b-versatile", 512);
// throws: "Team analytics not authorized for model llama-3.3-70b-versatile"
Resources
- Groq Projects
- Groq Spend Limits
- Groq Rate Limits
- Groq API Keys
- Full implementation walkthrough
- Worked examples
- For migration strategies, see the
groq-migration-deep-diveskill.
When not to use it
- →Relying on built-in API key scoping as Groq keys have no native scopes
Prerequisites
Limitations
- →Groq API keys have no built-in scopes
- →Rate limits are shared across all keys in an organization
- →Gateway must be maintained to enforce model allow-lists
How it compares
This approach enforces security at the gateway level to compensate for Groq's flat, unscoped API key structure.
Compared to similar skills
groq-enterprise-rbac side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| groq-enterprise-rbac (this skill) | 1 | 27d | No flags | Advanced |
| fix-dependabot-alerts | 18 | 6mo | Review | Intermediate |
| security-best-practices | 7 | 6mo | No flags | Intermediate |
| security-scan | 1 | 6mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
fix-dependabot-alerts
microsoft
Fix Dependabot security alerts by updating vulnerable npm dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", or wants to update packages with security issues.
security-best-practices
openai
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
security-scan
redpanda-data
Resolve npm dependency vulnerabilities detected by security scans.
azure-keyvault-keys-ts
microsoft
Manage cryptographic keys using Azure Key Vault Keys SDK for JavaScript (@azure/keyvault-keys). Use when creating, encrypting/decrypting, signing, or rotating keys.
azure-keyvault-secrets-ts
microsoft
Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyvault-secrets). Use when storing and retrieving application secrets or configuration values.
juicebox-security-basics
jeremylongshore
Apply Juicebox security best practices. Use when securing API keys, implementing access controls, or auditing Juicebox integration security. Trigger with phrases like "juicebox security", "secure juicebox", "juicebox API key security", "juicebox access control".