PO

posthog-security-basics

Secure your PostHog integration by properly managing project vs personal keys and auditing access control.

Install

mkdir -p .claude/skills/posthog-security-basics && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/6644" && unzip -o skill.zip -d .claude/skills/posthog-security-basics && rm skill.zip

Installs to .claude/skills/posthog-security-basics

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Secure PostHog integration: API key management, project key vs personal
71 charsno explicit “when” trigger
Intermediate

Key capabilities

  • Identify PostHog Project vs Personal API keys
  • Create scoped Personal API keys for specific services
  • Rotate compromised API keys
  • Implement Git pre-commit hooks for secret detection
  • Audit API key usage via activity logs

How it works

The skill enforces a security boundary by separating public Project keys from sensitive Personal keys, providing scripts for key rotation, scoping, and automated leak detection.

Inputs & outputs

You give it
API key configuration and environment variables
You get back
Securely scoped API keys and audit logs

When to use posthog-security-basics

  • Auditing PostHog security
  • Managing API key privileges
  • Rotating leaked secrets
  • Configuring environment security

About this skill

PostHog Security Basics

Overview

Secure PostHog API key management, least-privilege access, and secret rotation. PostHog has two key types with very different security profiles: the Project API Key (phc_...) is intentionally public and safe to include in frontend bundles, while the Personal API Key (phx_...) grants admin access and must never be exposed.

Prerequisites

  • PostHog account with admin access
  • Understanding of environment variable management
  • .gitignore configured

Instructions

Step 1: Understand Key Security Profiles

Key TypePrefixExposure RiskCapabilities
Project API Keyphc_Low (designed to be public)Capture events, evaluate flags, identify users
Personal API Keyphx_Critical (full admin access)CRUD flags, read persons, query insights, delete data
# .env (NEVER commit)
NEXT_PUBLIC_POSTHOG_KEY=phc_abc123   # Safe for frontend (NEXT_PUBLIC_ prefix)
POSTHOG_PERSONAL_API_KEY=phx_xyz789  # Server-only — NEVER in frontend code
POSTHOG_PROJECT_ID=12345

# .gitignore
.env
.env.local
.env.*.local

Step 2: Create Scoped Personal API Keys

set -euo pipefail
# Create a read-only key for BI dashboards
curl -X POST "https://app.posthog.com/api/personal_api_keys/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "label": "bi-dashboard-readonly",
    "scopes": ["insight:read", "dashboard:read", "query:read"]
  }'

# Create a key scoped to feature flags only
curl -X POST "https://app.posthog.com/api/personal_api_keys/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "label": "feature-flag-service",
    "scopes": ["feature_flag:read", "feature_flag:write"]
  }'

Step 3: Rotate Personal API Keys

set -euo pipefail
# 1. Create new key in PostHog Settings > Personal API Keys
# 2. Update secret in your deployment platform
# Vercel:
vercel env rm POSTHOG_PERSONAL_API_KEY production
vercel env add POSTHOG_PERSONAL_API_KEY production

# GitHub Actions:
gh secret set POSTHOG_PERSONAL_API_KEY --body "phx_new_key_here"

# 3. Verify new key works
curl -s "https://app.posthog.com/api/projects/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" | jq '.[0].name'

# 4. Delete old key in PostHog dashboard

Step 4: Prevent Key Leaks

# Git pre-commit hook to catch PostHog personal keys
# .git/hooks/pre-commit (or use husky)
#!/bin/bash
if git diff --cached --diff-filter=ACM | grep -qE 'phx_[a-zA-Z0-9]{20,}'; then
  echo "ERROR: PostHog personal API key (phx_) detected in staged files!"
  echo "Remove it and use environment variables instead."
  exit 1
fi
# .github/secret-scanning.yml (or use GitHub's built-in secret scanning)
patterns:
  - name: PostHog Personal API Key
    regex: 'phx_[a-zA-Z0-9]{20,}'
    severity: critical

Step 5: Server-Side Key Isolation

// lib/posthog-server.ts — Personal key never leaves the server
import { PostHog } from 'posthog-node';

const posthog = new PostHog(process.env.NEXT_PUBLIC_POSTHOG_KEY!, {
  host: 'https://us.i.posthog.com',
  // personalApiKey ONLY used server-side for local flag evaluation
  personalApiKey: process.env.POSTHOG_PERSONAL_API_KEY,
});

// API routes that proxy admin operations
// Never expose the personal key to the client
export async function getFeatureFlagsForUser(userId: string) {
  return posthog.getAllFlags(userId);
}

Step 6: Audit API Key Usage

set -euo pipefail
# Check activity log for API key operations
curl "https://app.posthog.com/api/projects/$POSTHOG_PROJECT_ID/activity_log/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" | \
  jq '[.results[] | select(.scope == "PersonalAPIKey") | {
    user: .user.email,
    activity: .activity,
    created_at
  }]'

Security Checklist

  • Project key (phc_) used for all frontend/capture code
  • Personal key (phx_) only on server, never in frontend bundles
  • .env files in .gitignore
  • Separate keys per environment (dev/staging/prod)
  • Scoped personal keys (not full admin for every service)
  • Git pre-commit hook scanning for phx_ keys
  • Key rotation documented and scheduled (quarterly)

Error Handling

IssueDetectionFix
Personal key in git historyGitHub secret scanning alertRotate key immediately, revoke old one
Wrong key type401 on admin APIUse phx_ for admin, phc_ for capture
Overprivileged keyAudit log shows unexpected operationsCreate scoped key, revoke broad one
Key exposed in logsLog scrubbing finds phx_Redact logs, rotate key

Output

  • Environment-specific API key configuration
  • Scoped personal API keys for least privilege
  • Key rotation procedure
  • Git pre-commit hook for leak prevention
  • Audit log queries for key usage monitoring

Resources

Next Steps

For production deployment, see posthog-prod-checklist.

When not to use it

  • Using Personal API keys in frontend bundles
  • Committing unencrypted secrets to version control

Prerequisites

PostHog account with admin accessEnvironment variable management.gitignore configuration

Limitations

  • Personal keys must never be exposed in frontend code
  • Requires manual rotation of keys after exposure

How it compares

Unlike manual key management, this provides specific shell scripts and configuration patterns to automate the enforcement of least-privilege access and leak prevention.

Compared to similar skills

posthog-security-basics side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
posthog-security-basics (this skill)126dCautionIntermediate
api-security-best-practices156moReviewIntermediate
api-security-testing17moReviewAdvanced
scanning-api-security226dReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

api-security-best-practices

davila7

Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

1554

api-security-testing

Ed1s0nZ

API安全测试的专业技能和方法论

18

scanning-api-security

jeremylongshore

Detect API security vulnerabilities including injection, broken auth, and data exposure. Use when scanning APIs for security vulnerabilities. Trigger with phrases like "scan API security", "check for vulnerabilities", or "audit API security".

26

openrouter-data-privacy

jeremylongshore

Implement data privacy controls for OpenRouter requests. Use when handling PII or meeting compliance requirements. Trigger with phrases like 'openrouter privacy', 'openrouter pii', 'openrouter gdpr', 'openrouter data protection'.

05

apollo-security-basics

jeremylongshore

Apply Apollo.io API security best practices. Use when securing Apollo integrations, managing API keys, or implementing secure data handling. Trigger with phrases like "apollo security", "secure apollo api", "apollo api key security", "apollo data protection".

13

perplexity-enterprise-rbac

jeremylongshore

Configure Perplexity enterprise SSO, role-based access control, and organization management. Use when implementing SSO integration, configuring role-based permissions, or setting up organization-level controls for Perplexity. Trigger with phrases like "perplexity SSO", "perplexity RBAC", "perplexity enterprise", "perplexity roles", "perplexity permissions", "perplexity SAML".

04

Search skills

Search the agent skills registry