agentCLAWHUBUnverified

honeybook-fpx

Read HoneyBook client-portal data (contracts, invoices, proposals, payment methods, workspace status) from a shell with the fpx CLI (@fetchproxy/cli) instead of running the honeybook-mcp server — capture a vendor session once via the signed-in browser tab, then curl api.honeybook.com directly. Use when you want HoneyBook data without the MCP, in a script, or on a machine where the MCP isn't installed.

OpenClaw

Rank

62

Safety

84

Downloads

1.3k

Updated

Oct 10, 2026

Version

1.2.6

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.3K downloadsadoption · observed Oct 10, 2026
Latest release
1.2.6release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:honeybook-fpx
  1. Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:honeybook-fpx` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/honeybook-fpx before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-honeybook-fpx/snapshot"

Documentation

CLAWHUB

148,572 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: honeybook-fpx
description: >-
  Read HoneyBook client-portal data (contracts, invoices, proposals, payment
  methods, workspace status) from a shell with the fpx CLI (@fetchproxy/cli)
  instead of running the honeybook-mcp server — capture a vendor session once
  via the signed-in browser tab, then curl api.honeybook.com directly. Use
  when you want HoneyBook data without the MCP, in a script, or on a machine
  where the MCP isn't installed.
---

# HoneyBook via fpx + curl (no MCP)

HoneyBook has **no server-side login** a script can drive — a client never
gets a password, only a magic-link email per vendor. The credential is
whatever the signed-in `*.hbportal.co` portal tab already holds: a bearer
token + user id in `localStorage["HONEYBOOK_REACT_CURR_USER"]`. (HoneyBook
used to keep these in the AngularJS `localStorage["jStorage"]` blob as
`HB_AUTH_TOKEN`/`HB_AUTH_USER_ID`; that blob is now down to
`HB_TRUSTED_DEVICE`, `SESSION_COMPANY_ID` and routing state.)
There's no bot wall on the API itself once you have those — `honeybook-mcp`'s
own `client.ts` proves plain Node `fetch` works fine against
`api.honeybook.com`. So this skill is **hybrid**: `fpx` captures the session
**once** (per vendor), then plain `curl` does every read from then on.

This mirrors `src/auth.ts` (`captureSessionViaFetchproxy`) and `src/client.ts`
(`HoneyBookClient.request`) in `honeybook-mcp` — same headers, same base URL,
same retry rules.

## Multi-domain scope

Two apexes are declared on one profile:
- `hbportal.co` — the vendor's branded portal (e.g. `acme.hbportal.co`),
  where the stored session lives.
- `honeybook.com` — the main app, where the same session is also valid.

## One-time setup

```sh
npm install -g @fetchproxy/cli   # provides `fpx`
fpx profile add honeybook --domain honeybook.com --domain hbportal.co
fpx profile declare honeybook \
  --local-storage HONEYBOOK_REACT_CURR_USER \
  --local-storage jStorage
fpx pair -p honeybook            # prints a pair code → approve in ContextMint Bridge
```

Requirements: the **ContextMint Bridge** browser extension installed
([releases](https://github.com/nullnet-app/contextmint-bridge/releases):
Chrome loads the chrome zip unpacked; Safari isn't available yet, so use
Chrome for now), its Chrome **Site access** allowing both `honeybook.com` and
`hbportal.co`, and a vendor magic-link URL already open (signed in) in that
browser. Pairing persists — after the first approval every later `fpx` call
reuses it.

ContextMint Bridge is the fetchproxy extension renamed, same maintainer (see [fetchproxy#extension](https://github.com/chrischall/fetchproxy#extension)); source at [nullnet-app/contextmint-bridge](https://github.com/nullnet-app/contextmint-bridge) — build it yourself or verify a release zip with `shasum -a 256 -c contextmint-bridge-chrome-<version>.zip.sha256`.

## Capture a vendor session (once per vendor, and again when it expires)

1. Click the vendor's HoneyBook magic-link email in the browser with

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "honeybook-fpx",
  "version": "1.2.6",
  "publishedAt": 1791588414915
}

references/requests.md

# HoneyBook requests for fpx + curl

Ready-to-run commands for the four live read endpoints `honeybook-mcp`
actually calls (from `src/tools/*.ts` + `src/client.ts`). All are
`GET api.honeybook.com/api/v2/*`, carrying the same headers built in
`HoneyBookClient.request` — see `../SKILL.md` for how to capture
`$AUTH_TOKEN`/`$USER_ID`/`$API_VERSION` first. `$TRUSTED_DEVICE` is
optional and `hb-api-fingerprint` is not required at all.

```sh
hb_get() {   # $1 = path (e.g. /api/v2/users/$USER_ID/workspace_files)
  curl -s "https://api.honeybook.com$1" \
    -H 'accept: application/json, text/plain, */*' \
    -H "hb-api-auth-token: $AUTH_TOKEN" \
    -H "hb-api-user-id: $USER_ID" \
    ${TRUSTED_DEVICE:+-H "hb-trusted-device: $TRUSTED_DEVICE"} \
    -H "hb-api-client-version: $API_VERSION" \
    -H "hb-api-duplicate-calls-prevention-uuid: $(uuidgen)" \
    -H 'hb-admin-login: false'
}
```

`sign_contract`/`pay_invoice` are **not** included below — the MCP itself
doesn't call a signing/payment API; it returns a deep link
(`$PORTAL_ORIGIN/app/workspace_file/<file_id>/agreement` or `/invoice`) for
the user to open in their browser. There's no request shape to transcribe.

---

## 1. List a vendor's shared files

`list_workspace_files` (`src/tools/workspace_files.ts`):

```sh
hb_get "/api/v2/users/$USER_ID/workspace_files" > /tmp/hb-files.json
```

Response envelope (`HBListEnvelope<T>`, `src/types.ts`):
`{ data: [...], cur_page, last_page, last_id?, total_count? }`.
If `last_page` is `false`, more results exist on later pages. The MCP
requests `?page=2`, `?page=3`, … (the parameter `/api/v2/client/events`
takes) until `last_page` is true, and reports `complete: false` if a page
brings nothing new; do the same here if you need every file.

```sh
# Filter to a file_type client-side (agreement | invoice | brochure | proposal)
jq '[.data[] | select(.file_type == "agreement")]' /tmp/hb-files.json

# Compact listing: id, type, title, accepted/paid flags
jq -r '.data[] | [.["_id"], .file_type, .file_title, (.is_file_accepted|tostring), (.has_pending_payment|tostring)] | @tsv' /tmp/hb-files.json
```

## 2. Get one file's detail

`get_workspace_file` (`src/tools/workspace_files.ts`):

```sh
hb_get "/api/v2/workspace_files/$FILE_ID" > /tmp/hb-file.json
```

The raw response is large on proposal-class files (a real one hit ~1.3 MB,
mostly vendor-internal fields the MCP prunes off `company`:
`vendor_emails`, `workflow_automation_infos`, `brochure_templates`,
`questionnaires`, `lead_sources`, `proposals`, `agreements`, `invoices`,
`vendor_packages`, `contact_forms`, `stripe_persons`,
`user_pipeline_stages`, `project_types`, `company_assets`). Project what you
need instead of dumping the whole body:

```sh
# Summary-equivalent: identity, status, vendor, event, pricing totals, payments
jq '{
  id: .["_id"], title: .file_title, type: .file_type,
  status: .status_name, accepted: .is_file_accepted,
  vendor: .company.company_name,
  event: (.event | {date: .event_date, ty

skill-card.md

## Description:

Guides agents in reading HoneyBook client-portal contracts, invoices, proposals, payment methods, and workspace status using a captured browser session and shell commands without the HoneyBook MCP server.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and agents use this skill to inspect HoneyBook client-portal files, project status, and saved payment methods from a shell without running the MCP server.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Captured HoneyBook sessions expose credentials and private portal data to shell-level access.

Mitigation: Use only in a trusted environment; restrict session captures to private, owner-only temporary storage and delete them promptly.

Risk: Full API responses can contain sensitive client and vendor information.

Mitigation: Select only the fields needed and avoid storing raw responses in shared temporary directories.

Risk: The included message-sending workflow emails a real vendor despite the skill's read-oriented purpose.

Mitigation: Do not send messages unless explicitly authorized; preview the content before sending.

## Reference(s):

- [HoneyBook FPX on ClawHub](https://clawhub.ai/chrischall/skills/honeybook-fpx)
- [Request examples](references/requests.md)
- [ContextMint Bridge source](https://github.com/nullnet-app/contextmint-bridge)
- [ContextMint Bridge releases](https://github.com/nullnet-app/contextmint-bridge/releases)

## Skill Output:

**Output Type(s):** [Shell commands, Configuration, Guidance]

**Output Format:** [Markdown with shell examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Read responses can contain sensitive client and vendor data.]

## Skill Version(s):

1.2.6 (source: ClawHub release)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/honeybook-fpx",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/honeybook-fpx",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T16:13:40.927Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-honeybook-fpx/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-honeybook-fpx/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T16:13:40.927Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.3K downloads",
      "href": "https://clawhub.ai/chrischall/honeybook-fpx",
      "sourceUrl": "https://clawhub.ai/chrischall/honeybook-fpx",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T16:13:40.927Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.2.6",
      "href": "https://clawhub.ai/chrischall/honeybook-fpx",
      "sourceUrl": "https://clawhub.ai/chrischall/honeybook-fpx",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:26:54.915Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-honeybook-fpx/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-honeybook-fpx/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.2.6",
      "description": "- Removed obsolete skill-card.md file for better clarity and maintenance. - Updated documentation in references/requests.md with clarified or revised instructions. - No changes to core logic or functionality; documentation only.",
      "href": "https://clawhub.ai/chrischall/honeybook-fpx",
      "sourceUrl": "https://clawhub.ai/chrischall/honeybook-fpx",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:26:54.915Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to honeybook-fpx and adjacent AI workflows.