agentCLAWHUBUnverified

alphaportal-mcp

Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the alphaportal-mcp server. Capture the signed-in web app's refresh token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint access tokens and curl the REST API directly. Use when you want AlphaPortal data without the MCP, in a script, or on a machine where the MCP isn't installed. Skill: alphaportal-mcp Owner: chrischall Summary: Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the alphaportal-mcp server. Capture the signed-in web app's refresh token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint access tokens and curl the REST API directly. Use when you want Al

OpenClaw

Rank

62

Safety

84

Downloads

1.1k

Updated

Oct 11, 2026

Version

1.2.3

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1.1K downloadsadoption · observed Oct 11, 2026
Latest release
1.2.3release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:alphaportal-mcp
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/snapshot"

Documentation

CLAWHUB

109,752 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: alphaportal-fpx
description: >-
  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus
  GPS location, arrival notifications — from a shell with curl instead of
  running the alphaportal-mcp server. Capture the signed-in web app's refresh
  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint
  access tokens and curl the REST API directly. Use when you want AlphaPortal
  data without the MCP, in a script, or on a machine where the MCP isn't
  installed.
---

# AlphaPortal via curl (no MCP, no runtime bridge)

AlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the
school district) has **no bot wall** on its API (`api.alpharoute.app`): once you
hold a token, plain `curl` does every call — no browser extension at runtime.
Login itself is reCAPTCHA-gated and can't be scripted, so the credential is the
**refresh token** the web app stores in your signed-in browser. It's an 8-day,
reusable JWT; from it you mint a 30-minute access token with one unauthenticated
POST (no reCAPTCHA, no MFA).

So the flow is: **capture the refresh token once → mint an access token → curl.**

## 1. Capture the refresh token (once; repeat when it expires after ~8 days)

**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,
open DevTools → Console and run:

```js
JSON.parse(localStorage.user).User.RefreshToken
```

Copy the value into your shell:

```sh
export ALPHAPORTAL_RT='<paste the refresh token>'
```

**Option B — fpx browser bridge** (needs the ContextMint Bridge extension — from
https://github.com/nullnet-app/contextmint-bridge/releases; Chrome: load the chrome
zip unpacked; Safari isn't available yet, so use Chrome for now — plus a signed-in
`*.alphaportal.app` tab). ContextMint Bridge is the fetchproxy extension renamed, same
maintainer; source is public at https://github.com/nullnet-app/contextmint-bridge — build
it yourself or verify a release zip with `shasum -a 256 -c contextmint-bridge-chrome-<version>.zip.sha256`:

```sh
npm install -g @fetchproxy/cli                              # provides `fpx`
fpx profile add alphaportal --domain alphaportal.app
fpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing
fpx local-storage user -p alphaportal                      # first call prints a pair code → approve in ContextMint Bridge
export ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')
```

## 2. Mint an access token (each session, or when the last one is >30 min old)

```sh
export ALPHAPORTAL_TOKEN=$(
  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \
    -H 'Content-Type: application/json' \
    -d "{\"refreshToken\":\"$ALPHAPORTAL_RT\"}" | jq -r '.data.token'
)
```

If `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —
re-capture it (step 1).

## 3. Core call pattern

Every read is a GET with the bearer token; the

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "alphaportal-mcp",
  "version": "1.2.3",
  "publishedAt": 1791588353518
}

references/endpoints.md

# AlphaPortal endpoint reference (curl)

Base: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`
(see `SKILL.md` for minting). Envelope: `{success, data, message}`.
`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).

All reads below are **live-verified** (2026-08-25). Define the helper once:

```sh
alpha() { curl -s "https://api.alpharoute.app/$1" -H "Authorization: Bearer $ALPHAPORTAL_TOKEN"; }
apost() { curl -s -X POST "https://api.alpharoute.app/$1" -H "Authorization: Bearer $ALPHAPORTAL_TOKEN" -H 'Content-Type: application/json' -d "$2"; }
```

## Students & transportation

```sh
# full student records
alpha AlphaPortal/v1/user-students/list | jq '.data.students'

# slim list (id + name only)
alpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'

# one student: school + morning/afternoon stops
alpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'

# a student's assigned stops (name, time, lat/lng, days)
alpha AlphaPortal/v1/user-students/stops/218652901 \
  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'

# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running
alpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'

# a one-time PDF report link
alpha "AlphaPortal/v1/user-students/reports-bulk?studentId=218652901" | jq '.data'

# the account groups (districts) you belong to
alpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'
```

## Notifications & requests

```sh
# arrival/departure notification feed (the real one)
alpha AlphaPortal/v1/notifications/list \
  | jq '.data.notifications[] | {title, personName, body, creationDate}'

# your submitted transportation requests (tracking numbers, status)
alpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'
```

## Account & district reference

```sh
apost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'
alpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone
alpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'
alpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags
alpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'
alpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'
alpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'
```

## Writes (real & permanent here — no dry-run)

Both require a `studentId`. Bodies are transcribed from the AlphaPortal web
client. Values for notification toggles are `0`/`1`.

```sh
# set walk-zone radius (meters) — affects eligibility
apost AlphaPortal/v1/user-students/radius-edit '{"studentId":218652901,"radius":800}' | jq

# set notification preferences (per category, push/email, AM/PM).
# Categories the district enables: stopRadiusEntry, studentScan, backupBus,
# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),
# <category>EmailAm/Pm (email).

skill-card.md

## Description:

Guides authorized users through accessing AlphaPortal student transportation data with shell commands instead of running the MCP server.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

Authorized parents, guardians, and developers use this skill to retrieve student stops, bus locations, and arrival notifications through the AlphaPortal API without an MCP server.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Copying a browser refresh token can expose account access.

Mitigation: Use only accounts you are authorized to access; treat tokens like passwords and keep them out of shared terminals, shell history, logs, and printed scripts.

Risk: Student locations and transportation details are sensitive.

Mitigation: Limit access to authorized students and avoid logging or sharing returned student data.

Risk: Write examples can change transportation settings without confirmation.

Mitigation: Run write commands only with explicit permission and an independent review step.

## Reference(s):

- [AlphaPortal endpoint recipes](references/endpoints.md)
- [ContextMint Bridge source](https://github.com/nullnet-app/contextmint-bridge)
- [AlphaPortal MCP skill release](https://clawhub.ai/chrischall/skills/alphaportal-mcp)

## Skill Output:

**Output Type(s):** [Shell commands, Configuration instructions, Guidance]

**Output Format:** [Markdown with shell and JavaScript examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Commands may expose account tokens or sensitive student transportation data.]

## Skill Version(s):

1.2.3 (source: ClawHub release evidence)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/alphaportal-mcp",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/alphaportal-mcp",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T11:24:33.567Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T11:24:33.567Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.1K downloads",
      "href": "https://clawhub.ai/chrischall/alphaportal-mcp",
      "sourceUrl": "https://clawhub.ai/chrischall/alphaportal-mcp",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T11:24:33.567Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.2.3",
      "href": "https://clawhub.ai/chrischall/alphaportal-mcp",
      "sourceUrl": "https://clawhub.ai/chrischall/alphaportal-mcp",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:25:53.518Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.2.3",
      "description": "- Removed the skill-card.md file. - No changes to functionality or documentation in SKILL.md. - Housekeeping update; no user-facing impact.",
      "href": "https://clawhub.ai/chrischall/alphaportal-mcp",
      "sourceUrl": "https://clawhub.ai/chrischall/alphaportal-mcp",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:25:53.518Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to alphaportal-mcp and adjacent AI workflows.