kiaaccess-curl
Query and command a Kia vehicle directly with curl against the Kia Owners API (api.owners.kia.com), without running the MCP server. Use when the user wants a one-off read of their Kia's status, location, or EV charge state, or to lock/unlock/start climate from the shell — "check my Kia", "is the car locked", "what's the EV9 charge", "lock the car from the terminal". Requires KIA_USERNAME/KIA_PASSWORD and a one-time SMS/email MFA bootstrap. Skill: kiaaccess-curl Owner: chrischall Summary: Query and command a Kia vehicle directly with curl against the Kia Owners API (api.owners.kia.com), without running the MCP server. Use when the user wants a one-off read of their Kia's status, location, or EV charge state, or to lock/unlock/start climate from the shell — "check my Kia", "is the car locked", "what's the EV9 charge", "lock the car from the terminal". Re
Rank
62
Safety
84
Downloads
1.8k
Updated
Oct 10, 2026
Version
2.0.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.8K downloadsadoption · observed Oct 10, 2026
- Latest release
- 2.0.0release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:kiaaccess-curl- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/snapshot"
Documentation
CLAWHUB
147,510 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
--- name: kiaaccess-curl description: Query and command a Kia vehicle directly with curl against the Kia Owners API (api.owners.kia.com), without running the MCP server. Use when the user wants a one-off read of their Kia's status, location, or EV charge state, or to lock/unlock/start climate from the shell — "check my Kia", "is the car locked", "what's the EV9 charge", "lock the car from the terminal". Requires KIA_USERNAME/KIA_PASSWORD and a one-time SMS/email MFA bootstrap. --- # Kia Owners API via curl The Kia Access app's API is reachable server-side — no browser, no bridge, no extension. This skill talks to it directly with `curl`. Prefer the `kiaaccess-mcp` server for anything conversational or repeated; use this for one-off shell work, debugging, or when the server isn't running. **Ready-to-run request bodies and `jq` recipes: `references/requests.md`.** Full shape reference (verified live): `../../docs/KIA-API.md`. ## Setup ```bash export KIA_USERNAME='[email protected]' export KIA_PASSWORD='…' export KIA_DEVICE=$(uuidgen) # keep this stable across runs ``` ## Two rules that will bite you 1. **Every request needs an RFC-1123 `date` header.** Omit it and you get `errorCode 9200 "Missing mandatory data in header"` — a message that does not name the culprit. Regenerate it per request; a stale one is rejected. 2. **HTTP is 200 even on failure.** Success is `status.statusCode == 0` in the *body*. Never branch on the HTTP code. Source `references/requests.md`'s `kia_headers` helper rather than hand-rolling headers — it handles both. ## Auth: one-time MFA, then silent refresh `authUser` → `sendOTP` → `verifyOTP` yields a **`sid`** (session, short-lived) and an **`rmtoken`** (refresh, durable), both as *response headers*. Afterwards, `authUser` with the `rmtoken` header mints a fresh `sid` with **no MFA**. So you do the SMS dance once and then never again — save the `rmtoken`. > **Never retry a rejected login.** `errorCode 1001` (bad credentials) or `1037` > (bad email) increments `payload.loginAttempt`; enough failures set > `enforceRecaptcha` and **permanently break shell-based login**. Fix the > credential and try once. Store the `rmtoken` at `$KIA_SESSION` (default `~/.kiaaccess-mcp/curl-session.json`) with `chmod 600`. It is a credential: it re-authenticates the account without a password prompt. > Do **not** write it to `~/.kiaaccess-mcp/session.json`. That path belongs to the > `kiaaccess-mcp` server, whose store is keyed by `accountId` with a different > schema — overwriting it corrupts the server's session and forces it back > through MFA. ## Calling Reads and commands take `sid` (+ `vinkey` for vehicle-scoped calls). Get the `vinkey` from `ownr/gvl` → `payload.vehicleSummary[0].vehicleKey`. | Want | Endpoint | | --- | --- | | vehicles | `GET ownr/gvl` | | status (cached) | `POST cmm/gvi` | | status (force refresh) | `POST rems/rvs` | | EV charge targets | `GET evc/gts` | | lock / unlock | `GET rems/door/
_meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "kiaaccess-curl",
"version": "2.0.0",
"publishedAt": 1791588243714
}references/requests.md
# Ready-to-run requests
Every shape here was verified live on 2026-07-27 against a 2024 Kia EV9 —
including the `evc/*` charging commands, run against the car while plugged in.
## Header helper
Source this first. It regenerates the mandatory `date` per call and keeps the
device id stable.
```bash
KIA_BASE='https://api.owners.kia.com/apigw/v1'
: "${KIA_DEVICE:?export KIA_DEVICE=\$(uuidgen) first}"
# Session file for THIS skill. Deliberately NOT ~/.kiaaccess-mcp/session.json —
# that path belongs to the MCP server, whose store is keyed by accountId with a
# different schema (src/session.ts). Writing this skill's flat
# {rmtoken, deviceId} there corrupts the server's session and forces it back
# through MFA.
KIA_SESSION="${KIA_CURL_SESSION:-$HOME/.kiaaccess-mcp/curl-session.json}"
# Builds the header list into the KIA_HDRS array. Extra headers passed as args.
kia_headers() {
local z sign off h
z=$(date +%z) # e.g. -0800, +0530
sign=${z:0:1}
# `10#` forces base 10. Without it, bash reads a leading-zero offset such as
# `08`/`09` as OCTAL and dies with "value too great for base" — so this breaks
# in US Pacific winter, Alaska, Japan, Korea and China. zsh does not have the
# problem, which is a good way to ship it broken without noticing.
off=$(( 10#${z:1:2} ))
[ "$sign" = "-" ] && off=$(( 0 - off ))
KIA_HDRS=()
for h in \
"content-type: application/json;charset=utf-8" \
"accept: application/json" \
"accept-language: en-US,en;q=0.9" \
"accept-charset: utf-8" \
"apptype: L" "appversion: 7.22.0" "clientid: SPACL716-APL" \
"clientuuid: ${KIA_DEVICE}" "deviceid: ${KIA_DEVICE}" \
"from: SPA" "host: api.owners.kia.com" "language: 0" \
"offset: ${off}" "ostype: iOS" "osversion: 15.8.5" "phonebrand: iPhone" \
"secretkey: sydnat-9kykci-Kuhtep-h5nK" "to: APIGW" "tokentype: A" \
"date: $(LC_ALL=C date -u '+%a, %d %b %Y %H:%M:%S GMT')" \
"user-agent: KIAPrimo_iOS/37 CFNetwork/1335.0.3.4 Darwin/21.6.0" \
"$@"
do
KIA_HDRS+=(-H "$h")
done
}
# curl wrapper: kia_curl <method> <path> [body] [-- extra-header ...]
kia_curl() {
local method="$1" path="$2" body="${3:-}"
shift 2; [ $# -gt 0 ] && shift # drop the body arg when present
[ "${1:-}" = "--" ] && shift
kia_headers "$@"
curl -sS -X "$method" "${KIA_BASE}/${path}" "${KIA_HDRS[@]}" \
${body:+--data "$body"} -D /tmp/kia_hdrs --compressed
}
```
Both functions work under bash and zsh. **Test under `bash` if you change them** —
the octal trap above bites only bash, so zsh-only testing hides it. An array is
used rather than piping headers through `sed`, which avoids depending on GNU
sed's `\n`-in-replacement behaviour.
`secretkey` is a **static app constant**, not a user secret — it is the same for
every install.
## 1. Login (one-time MFA)
```bash
# Step 1 — authenticate. Captures otpKey (body) and xid (RESPONSE HEADER).
kia_curl POST prof/authUser "$(jq -nc \
--arg u "$KIA_USERNAME" --arskill-card.md
## Description: Guides one-off Kia vehicle status checks and remote commands through shell requests to the Kia Owners API. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: Kia owners and their authorized assistants use the skill to inspect vehicle status, location, and charging information or request door, climate, and charging actions from the shell. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill can access sensitive account and vehicle location data and issue real vehicle commands. Mitigation: Run only on a private machine and require explicit confirmation before unlock, climate, or charging actions. Risk: Durable session credentials and temporary response files can expose account or vehicle data. Mitigation: Protect the saved session file, restrict access to temporary files, and delete them when finished. ## Reference(s): - [ClawHub skill release](https://clawhub.ai/chrischall/skills/kiaaccess-curl) - [Ready-to-run requests](references/requests.md) ## Skill Output: **Output Type(s):** [Guidance, Shell commands] **Output Format:** [Markdown with bash examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Requires account credentials and one-time MFA setup; command acceptance does not prove a vehicle state change.] ## Skill Version(s): 2.0.0 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/kiaaccess-curl",
"sourceUrl": "https://clawhub.ai/chrischall/skills/kiaaccess-curl",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T02:51:24.503Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T02:51:24.503Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.8K downloads",
"href": "https://clawhub.ai/chrischall/kiaaccess-curl",
"sourceUrl": "https://clawhub.ai/chrischall/kiaaccess-curl",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T02:51:24.503Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.0.0",
"href": "https://clawhub.ai/chrischall/kiaaccess-curl",
"sourceUrl": "https://clawhub.ai/chrischall/kiaaccess-curl",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:24:03.714Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.0.0",
"description": "kiaaccess-curl 2.0.0 - Removed the sample file skill-card.md. - No changes to functionality or documentation content.",
"href": "https://clawhub.ai/chrischall/kiaaccess-curl",
"sourceUrl": "https://clawhub.ai/chrischall/kiaaccess-curl",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:24:03.714Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
