Groq Install AuthSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
npm install groq-sdk
pip install groq
npm install groq-sdk
pip install groq
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: groq-install-auth description: 'Install and configure Groq SDK authentication for TypeScript or Python. Use when setting up a new Groq integration, configuring API keys, or initializing the groq-sdk in your project. Trigger with phrases like "install groq", "setup groq", "groq auth", "configure groq API key". ' allowed-tools: Bash(npm:*), Bash(pip:*), Bash(export:*) version: 1.11.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - groq - api - authentication compatibility: Designed for Claude Code --- # Groq Install & Auth ## Overview Install the official Groq SDK and configure API key authentication. Groq provides ultra-fast LLM inference on custom LPU hardware through an OpenAI-compatible REST API at `api.groq.com/openai/v1/`. The workflow is four steps: install the SDK, mint an API key, export it as an environment variable, and verify the connection by listing models. Each step is summarized below; deep detail lives in [`references/`](references/). ## Prerequisites - Node.js 18+ or Python 3.8+ - Package manager (npm, pnpm, or pip) - Groq account at [console.groq.com](https://console.groq.com) - API key from GroqCloud console (Settings > API Keys) ## Instructions ### Step 1: Install the SDK ```bash set -euo pipefail # TypeScript / JavaScript npm install groq-sdk # Python pip install groq ``` ### Step 2: Get Your API Key 1. Go to [console.groq.com/keys](https://console.groq.com/keys) 2. Click "Create API Key" 3. Copy the key (starts with `gsk_`) 4. Store it securely -- you cannot view it again ### Step 3: Configure Environment Add the [`.gitignore` template](references/configuration.md#gitignore-template) **before** writing any `.env` file so a key can never be committed: ```bash # Set environment variable (recommended) export GROQ_API_KEY="gsk_your_key_here" # Or create .env file (add .env to .gitignore first) echo 'GROQ_API_KEY=gsk_your_key_here' >> .env ``` ### Step 4: Verify the Connection Run a short script that lists the models your key can access — a successful list proves authentication end-to-end. The essential TypeScript skeleton: ```typescript import Groq from "groq-sdk"; const groq = new Groq({ apiKey: process.env.GROQ_API_KEY }); const models = await groq.models.list(); console.log(models.data.map((m) => m.id)); ``` Full runnable TypeScript **and** Python verification scripts, with expected output: [verification walkthrough](references/verification.md). ## Output A successful setup produces: - `groq-sdk` (Node) or `groq` (Python) installed in the project. - `GROQ_API_KEY` available in the environment (or `.env`, with `.env` gitignored). - A verification run that prints the accessible models, for example: ``` Connected! Available models: llama-3.3-70b-versatile (owned by Meta) llama-3.1-8b-instant (owned by Meta) ``` If the verification run prints a `401` instead of a model list, authentication failed — see [Error Handling](#error-handling). ## SDK Defaults & Key Formats The SDK auto-reads `GROQ_API_KEY` from the environment when no `apiKey` is passed. Groq uses a single `gsk_` key type with full API access (no read/write scopes). Constructor options (`baseURL`, `maxRetries`, `timeout`), the OpenAI-SDK compatibility path, and the key-format table are in the [configuration reference](references/configuration.md). ## Error Handling | Error | Cause | Solution | |-------|-------|----------| | `401 Invalid API Key` | Key missing, revoked, or mistyped | Verify key at console.groq.com/keys | | `MODULE_NOT_FOUND groq-sdk` | SDK not installed | Run `npm install groq-sdk` | | `ModuleNotFoundError: No module named 'groq'` | Python SDK missing | Run `pip install groq` | | `ENOTFOUND api.groq.com` | Network/DNS issue | Check internet connectivity and firewall | Extended diagnostics (checking the exported variable, `.env` loading, key rotation): [troubleshooting reference](references/troubleshooting.md). ## Examples **Example 1 — Node project from scratch:** ```bash npm install groq-sdk export GROQ_API_KEY="gsk_your_key_here" node --env-file=.env verify.mjs # lists models → auth confirmed ``` **Example 2 — Python project:** ```bash pip install groq export GROQ_API_KEY="gsk_your_key_here" python verify.py # prints accessible models ``` **Example 3 — reuse an existing OpenAI codebase:** point the OpenAI SDK at Groq by overriding `baseURL` to `https://api.groq.com/openai/v1` and passing your `gsk_` key. See the [configuration reference](references/configuration.md#sdk-defaults). Complete, runnable versions of the verification scripts are in the [verification walkthrough](references/verification.md). ## Resources - [Groq Quickstart](https://console.groq.com/docs/quickstart) - [Groq API Reference](https://console.groq.com/docs/api-reference) - [groq-sdk on npm](https://www.npmjs.com/package/groq-sdk) - [groq-typescript on GitHub](https://github.com/groq/groq-typescript) ## Next Steps After successful auth, proceed to the `groq-hello-world` skill to run your first chat completion. For SDK tuning (retries, timeouts, custom base URL), read the [configuration reference](references/configuration.md).
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__groq-install-auth.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Groq Install Auth skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Groq Install Auth safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Groq Install Auth access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Groq Install Auth work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.