
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
@runapi.ai/luma-mcp
Advanced tools
RunAPI Luma MCP server for video generation: create tasks, poll results, and check pricing across 1 model from Claude Code, Codex, Cursor, and VS Code.
Luma API access for AI agents: run video generation operations, poll asynchronous results, and check pricing through one focused MCP server.
Works with Claude Code, Codex, Cursor, Windsurf, VS Code, Roo Code, and any MCP-compatible host.
Install | Tools | Models | Agent Prompts | Configuration | Links
@runapi.ai/luma-mcp is a focused Model Context Protocol server for the Luma model line on RunAPI.
It gives MCP-compatible assistants direct access to 1 endpoint and 1 model variant without loading the full RunAPI catalog.
Use this per-model server when an agent should stay scoped to Luma. Use @runapi.ai/mcp when one assistant should discover every RunAPI model line.
Add it to Claude Code:
claude mcp add luma -s user -- npx -y @runapi.ai/luma-mcp
Use project scope when the server should be shared with a repository:
claude mcp add luma -s project -- npx -y @runapi.ai/luma-mcp
Codex, Cursor, Windsurf, VS Code, Roo Code, and other MCP hosts can use the same stdio command:
{
"mcpServers": {
"luma": {
"command": "npx",
"args": ["-y", "@runapi.ai/luma-mcp"]
}
}
}
check_pricing works before sign-in. For task creation and status polling, ask your assistant to call the login tool. It opens a browser login and saves credentials to ~/.config/runapi/config.json, the same file used by runapi login.
Headless and CI hosts can still set RUNAPI_API_KEY before starting the MCP host.
Ready-made examples are in examples/ for Claude, Cursor, Windsurf, VS Code, and Roo Code.
| Tool | Auth | Purpose |
|---|---|---|
modify_video | Yes | Create a Luma modify video task and optionally wait for a terminal status. Returns the task id, status, and output URLs. |
get_task | Yes | Fetch the current status and latest payload for an existing task. |
check_pricing | No | Look up current pricing for a Luma model and endpoint. |
Luma covers 1 model variant across 1 endpoint. Each tool accepts the models listed for it:
| Tool | Models |
|---|---|
modify_video | luma-modify-video |
Model availability can change between releases. Use check_pricing or the Luma model page for the current catalog view.
Ask your assistant in natural language; it can inspect pricing, create the task, and return the task id plus output URLs.
Run a Luma modify video task with RunAPI.
The assistant can call check_pricing, then modify_video, and return the task id, status, and output URLs.
Create the task but don't wait for it to finish.
The assistant calls the create tool with wait: false and returns the task id. Check on it later with get_task.
Check current Luma pricing, then create the task if it matches my request.
The assistant calls check_pricing and can link to the Luma model page for the canonical catalog entry.
The server resolves auth in this order:
RUNAPI_API_KEY environment variable, useful for headless and CI hosts~/.config/runapi/config.json, created by the MCP login tool or runapi logincheck_pricingThe config file is normally managed by login. A pre-provisioned headless config can use:
{
"apiKey": "your_runapi_key"
}
Do not commit real API keys.
| Resource | URL |
|---|---|
| Luma model page | https://runapi.ai/models/luma |
| npm package | @runapi.ai/luma-mcp |
| GitHub repository | runapi-ai/luma-mcp |
| RunAPI MCP overview | runapi.ai/mcp |
| RunAPI docs | runapi.ai/docs |
Licensed under the Apache License, Version 2.0.
FAQs
RunAPI Luma MCP server for video generation: create tasks, poll results, and check pricing across 1 model from Claude Code, Codex, Cursor, and VS Code.
The npm package @runapi.ai/luma-mcp receives a total of 30 weekly downloads. As such, @runapi.ai/luma-mcp popularity was classified as not popular.
We found that @runapi.ai/luma-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.