Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Set up ClickUp API v2 authentication with personal tokens or OAuth 2.0. Use when configuring a new ClickUp integration, setting up API access, or initializing OAuth flows for multi-user apps. Trigger: "install clickup", "setup clickup auth", "clickup API token", "clickup OAuth", "configure clickup credentials".
.claude/skills/jeremylongshore-clickup-install-auth/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 13% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 34% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 18% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 57% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 5% | 0% |
Choose the authentication mode by tenancy and ownership, then prove the authorized Workspace boundary without exposing credentials.
Use Read, Glob, and Grep to inspect the repository, adapters, configuration names, tests, and evidence. Use WebFetch only for current official ClickUp documentation. Use Write or Edit after confirming the target file, Workspace boundary, and requested mode.
pk_, are intended for individual/testing use, and do not expire unless regenerated or revoked.https://app.clickup.com/api and exchange at https://api.clickup.com/api/v2/oauth/token.Authorization; authorized Workspaces are verified through the teams endpoint.Use a personal token only for accountable individual/testing work or OAuth Authorization Code for a user-facing integration. Inject the token server-side through a governed secret reference, send it in Authorization, verify authorized Workspace IDs, and never print the token, OAuth client secret, or webhook secret.
GET /api/v2/user and GET /api/v2/team with bounded timeouts.Do not print tokens, put a client secret in frontend code, accept unvalidated state, silently expand Workspace authorization, or regenerate a shared token without owner approval.
Return auth mode, secret-reference name, redirect/state result, authorized Workspace IDs in redacted form, verification status, and rotation owner.
| Condition | Response | |---|---| | State mismatch | Reject the callback and start a new authorization attempt. | | Redirect mismatch | Correct the registered exact URI; do not relax validation. | | Workspace not authorized | Stop and require explicit user reauthorization. | | Credential leaked | Revoke/regenerate, scrub artifacts, and record the incident. |
The example below is a redacted operator receipt; it contains no task text, member data, credential, or webhook secret.
textmode=oauth; redirect=exact; state=valid; token=stored-by-reference; workspace-match=yes; writes=0
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-04 | pass→pass | 6,077 | 2,160 | -64% | 1 | 1 | 0% | 1,100 | 1,729 | +57% | 0 | 0 | — |
case-01 | fail→pass | 15,968 | 10,501 | -34% | 1 | 1 | 0% | 3,330 | 3,774 | +13% | 0 | 0 | — |
case-02 | pass→pass | 15,630 | 9,250 | -41% | 1 | 1 | 0% | 3,171 | 3,324 | +5% | 0 | 0 | — |
case-03 | pass→pass | 5,773 | 5,296 | -8% | 1 | 1 | 0% | 1,060 | 2,235 | +111% | 0 | 0 | — |
case-05 | pass→pass | 4,289 | 2,243 | -48% | 1 | 1 | 0% | 761 | 1,683 | +121% | 0 | 0 | — |
case-06 | pass→pass | 3,258 | 3,056 | -6% | 1 | 1 | 0% | 594 | 1,884 | +217% | 0 | 0 | — |
case-07 | pass→pass | 11,763 | 11,801 | +0% | 1 | 1 | 0% | 1,881 | 3,594 | +91% | 0 | 0 | — |
case-08 | pass→pass | 9,322 | 4,668 | -50% | 1 | 1 | 0% | 1,734 | 2,117 | +22% | 0 | 0 | — |
case-09 | fail→pass | 9,199 | 5,460 | -41% | 1 | 1 | 0% | 1,743 | 2,338 | +34% | 0 | 0 | — |
case-10 | fail→pass | 9,180 | 3,407 | -63% | 1 | 1 | 0% | 1,625 | 1,922 | +18% | 0 | 0 | — |
case-11 | pass→pass | 7,355 | 3,214 | -56% | 1 | 1 | 0% | 1,250 | 1,849 | +48% | 0 | 0 | — |
case-12 | pass→pass | 5,618 | 3,192 | -43% | 1 | 1 | 0% | 1,082 | 1,906 | +76% | 0 | 0 | — |
case-13 | pass→pass | 3,774 | 2,570 | -32% | 1 | 1 | 0% | 718 | 1,792 | +150% | 0 | 0 | — |
case-14 | pass→pass | 2,430 | 1,574 | -35% | 1 | 1 | 0% | 359 | 1,548 | +331% | 0 | 0 | — |
case-15 | pass→pass | 3,325 | 2,186 | -34% | 1 | 1 | 0% | 455 | 1,668 | +267% | 0 | 0 | — |
case-16 | pass→pass | 7,158 | 2,973 | -58% | 1 | 1 | 0% | 1,284 | 1,868 | +45% | 0 | 0 | — |
case-17 | pass→pass | 9,135 | 4,597 | -50% | 1 | 1 | 0% | 1,552 | 2,218 | +43% | 0 | 0 | — |
case-18 | pass→pass | 6,282 | 2,762 | -56% | 1 | 1 | 0% | 1,146 | 1,830 | +60% | 0 | 0 | — |
case-19 | pass→pass | 6,206 | 3,542 | -43% | 1 | 1 | 0% | 1,020 | 1,866 | +83% | 0 | 0 | — |
case-20 | pass→pass | 13,069 | 10,302 | -21% | 1 | 1 | 0% | 2,792 | 3,645 | +31% | 0 | 0 | — |
case-21 | pass→pass | 8,807 | 7,056 | -20% | 1 | 1 | 0% | 1,930 | 2,600 | +35% | 0 | 0 | — |
case-22 | pass→pass | 10,273 | 10,838 | +5% | 1 | 1 | 0% | 1,929 | 3,514 | +82% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.