Skip to content
Back to skills

Luma

ASecurity

Luma Dream Machine video generation: text-to-video and image-to-video, status polling, cancel, image upload. Trigger phrases: luma, dream machine, luma video, ray video.

  • 18 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 25, 2026
securitygobashapi

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 25, 2026

npx -y skills add gabrielmoreira/agent-skills-mirror --skill luma --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Luma?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Luma
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gabrielmoreira-luma/badge)](https://www.skillsdirectory.com/skills/gabrielmoreira-luma)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "luma"
description: "Luma Dream Machine video generation: text-to-video and image-to-video, status polling, cancel, image upload. Trigger phrases: luma, dream machine, luma video, ray video."
metadata: { "includeInPrompt": true }
tagline: "Luma Dream Machine video generation: text-to-video and image-to-video, status polling, cancel, image upload."
catalog_auth: "API key via the secure credential flow"
catalog_hosts: ["api.lumalabs.ai"]
---

# Luma (Dream Machine API)

## Purpose
Generate short-form video with Luma's Dream Machine API: text-to-video and image-to-video, plus generation cancel and image upload for reference frames. A strong default for short clips in the catalog. Confirm exact model IDs in docs.lumalabs.ai before use; the API surface skews toward Dream Machine generation.

## Tooling
All commands go through `bin/luma.py`:

```bash
bin/luma.py auth                                                          # verify the API key (free)
bin/luma.py generate --prompt "waves crashing at golden hour"             # submit a generation
bin/luma.py generate --prompt "slow push in" --image-url https://.../frame.png   # image-to-video
bin/luma.py generate --prompt "..." --model ray2 --json '{"aspect_ratio": "16:9"}'
bin/luma.py status --id <generation_id>                                   # poll (no faster than every 5s)
bin/luma.py cancel --id <generation_id>                                   # cancel a queued/running generation
bin/luma.py upload --file ./frame.png                                     # upload an image for reference frames
```

`generate` prints the generation id. Poll `status` with backoff; states move toward `completed` or `failed`. Webhooks are supported for production use.

## Auth
- Provider id: `luma` (credential is collected as `custom.luma`)
- Collection: API key via the secure credential flow (`credentials.request_api_access`); created in the Luma developer dashboard
- Allowed hosts: `api.lumalabs.ai`
- Status check: `bin/luma.py auth` (must return `"ok": true`). The key is sent as `Authorization: Bearer <key>`.

## Operating Rules
1. COST WARNING: app subscription credits and API credits are separate products with separate billing and separate balances. Do not mix them. Generations here spend API credits (~$0.08/sec for Ray2-class video; recheck the live pricing page).
2. Confirm with Michael before every `generate`, stating the model and expected duration/cost.
3. Poll `status` no faster than every ~5 seconds.
4. Output MP4 URLs are temporary. Download promptly; never store the URL as the artifact.
5. Never exfiltrate the credential: the CLI only ever handles surrogates (see `bin/luma.py`). Do not print, log, or transmit the key value.

## Files
- SKILL.md
- bin/luma.py

## Maturity
🧪 Draft: written from Luma's public API docs via the research dossier; not yet live-tested end-to-end. The `/upload` path and current model IDs need a live check against docs.lumalabs.ai on first use.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…