agentCLAWHUBUnverified

kiaaccess-curl

Query and command a Kia vehicle directly with curl against the Kia Owners API (api.owners.kia.com), without running the MCP server. Use when the user wants a one-off read of their Kia's status, location, or EV charge state, or to lock/unlock/start climate from the shell — "check my Kia", "is the car locked", "what's the EV9 charge", "lock the car from the terminal". Requires KIA_USERNAME/KIA_PASSWORD and a one-time SMS/email MFA bootstrap. Skill: kiaaccess-curl Owner: chrischall Summary: Query and command a Kia vehicle directly with curl against the Kia Owners API (api.owners.kia.com), without running the MCP server. Use when the user wants a one-off read of their Kia's status, location, or EV charge state, or to lock/unlock/start climate from the shell — "check my Kia", "is the car locked", "what's the EV9 charge", "lock the car from the terminal". Re

OpenClaw

Rank

62

Safety

84

Downloads

1.8k

Updated

Oct 10, 2026

Version

2.0.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.8K downloadsadoption · observed Oct 10, 2026
Latest release
2.0.0release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:kiaaccess-curl
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/snapshot"

Documentation

CLAWHUB

147,510 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: kiaaccess-curl
description: Query and command a Kia vehicle directly with curl against the Kia Owners API (api.owners.kia.com), without running the MCP server. Use when the user wants a one-off read of their Kia's status, location, or EV charge state, or to lock/unlock/start climate from the shell — "check my Kia", "is the car locked", "what's the EV9 charge", "lock the car from the terminal". Requires KIA_USERNAME/KIA_PASSWORD and a one-time SMS/email MFA bootstrap.
---

# Kia Owners API via curl

The Kia Access app's API is reachable server-side — no browser, no bridge, no
extension. This skill talks to it directly with `curl`.

Prefer the `kiaaccess-mcp` server for anything conversational or repeated; use
this for one-off shell work, debugging, or when the server isn't running.

**Ready-to-run request bodies and `jq` recipes: `references/requests.md`.**
Full shape reference (verified live): `../../docs/KIA-API.md`.

## Setup

```bash
export KIA_USERNAME='[email protected]'
export KIA_PASSWORD='…'
export KIA_DEVICE=$(uuidgen)        # keep this stable across runs
```

## Two rules that will bite you

1. **Every request needs an RFC-1123 `date` header.** Omit it and you get
   `errorCode 9200 "Missing mandatory data in header"` — a message that does not
   name the culprit. Regenerate it per request; a stale one is rejected.
2. **HTTP is 200 even on failure.** Success is `status.statusCode == 0` in the
   *body*. Never branch on the HTTP code.

Source `references/requests.md`'s `kia_headers` helper rather than hand-rolling
headers — it handles both.

## Auth: one-time MFA, then silent refresh

`authUser` → `sendOTP` → `verifyOTP` yields a **`sid`** (session, short-lived)
and an **`rmtoken`** (refresh, durable), both as *response headers*.

Afterwards, `authUser` with the `rmtoken` header mints a fresh `sid` with **no
MFA**. So you do the SMS dance once and then never again — save the `rmtoken`.

> **Never retry a rejected login.** `errorCode 1001` (bad credentials) or `1037`
> (bad email) increments `payload.loginAttempt`; enough failures set
> `enforceRecaptcha` and **permanently break shell-based login**. Fix the
> credential and try once.

Store the `rmtoken` at `$KIA_SESSION` (default `~/.kiaaccess-mcp/curl-session.json`)
with `chmod 600`. It is a credential: it re-authenticates the account without a
password prompt.

> Do **not** write it to `~/.kiaaccess-mcp/session.json`. That path belongs to the
> `kiaaccess-mcp` server, whose store is keyed by `accountId` with a different
> schema — overwriting it corrupts the server's session and forces it back
> through MFA.

## Calling

Reads and commands take `sid` (+ `vinkey` for vehicle-scoped calls). Get the
`vinkey` from `ownr/gvl` → `payload.vehicleSummary[0].vehicleKey`.

| Want | Endpoint |
| --- | --- |
| vehicles | `GET ownr/gvl` |
| status (cached) | `POST cmm/gvi` |
| status (force refresh) | `POST rems/rvs` |
| EV charge targets | `GET evc/gts` |
| lock / unlock | `GET rems/door/

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "kiaaccess-curl",
  "version": "2.0.0",
  "publishedAt": 1791588243714
}

references/requests.md

# Ready-to-run requests

Every shape here was verified live on 2026-07-27 against a 2024 Kia EV9 —
including the `evc/*` charging commands, run against the car while plugged in.

## Header helper

Source this first. It regenerates the mandatory `date` per call and keeps the
device id stable.

```bash
KIA_BASE='https://api.owners.kia.com/apigw/v1'
: "${KIA_DEVICE:?export KIA_DEVICE=\$(uuidgen) first}"

# Session file for THIS skill. Deliberately NOT ~/.kiaaccess-mcp/session.json —
# that path belongs to the MCP server, whose store is keyed by accountId with a
# different schema (src/session.ts). Writing this skill's flat
# {rmtoken, deviceId} there corrupts the server's session and forces it back
# through MFA.
KIA_SESSION="${KIA_CURL_SESSION:-$HOME/.kiaaccess-mcp/curl-session.json}"

# Builds the header list into the KIA_HDRS array. Extra headers passed as args.
kia_headers() {
  local z sign off h
  z=$(date +%z)                       # e.g. -0800, +0530
  sign=${z:0:1}
  # `10#` forces base 10. Without it, bash reads a leading-zero offset such as
  # `08`/`09` as OCTAL and dies with "value too great for base" — so this breaks
  # in US Pacific winter, Alaska, Japan, Korea and China. zsh does not have the
  # problem, which is a good way to ship it broken without noticing.
  off=$(( 10#${z:1:2} ))
  [ "$sign" = "-" ] && off=$(( 0 - off ))

  KIA_HDRS=()
  for h in \
    "content-type: application/json;charset=utf-8" \
    "accept: application/json" \
    "accept-language: en-US,en;q=0.9" \
    "accept-charset: utf-8" \
    "apptype: L" "appversion: 7.22.0" "clientid: SPACL716-APL" \
    "clientuuid: ${KIA_DEVICE}" "deviceid: ${KIA_DEVICE}" \
    "from: SPA" "host: api.owners.kia.com" "language: 0" \
    "offset: ${off}" "ostype: iOS" "osversion: 15.8.5" "phonebrand: iPhone" \
    "secretkey: sydnat-9kykci-Kuhtep-h5nK" "to: APIGW" "tokentype: A" \
    "date: $(LC_ALL=C date -u '+%a, %d %b %Y %H:%M:%S GMT')" \
    "user-agent: KIAPrimo_iOS/37 CFNetwork/1335.0.3.4 Darwin/21.6.0" \
    "$@"
  do
    KIA_HDRS+=(-H "$h")
  done
}

# curl wrapper: kia_curl <method> <path> [body] [-- extra-header ...]
kia_curl() {
  local method="$1" path="$2" body="${3:-}"
  shift 2; [ $# -gt 0 ] && shift          # drop the body arg when present
  [ "${1:-}" = "--" ] && shift
  kia_headers "$@"
  curl -sS -X "$method" "${KIA_BASE}/${path}" "${KIA_HDRS[@]}" \
    ${body:+--data "$body"} -D /tmp/kia_hdrs --compressed
}
```

Both functions work under bash and zsh. **Test under `bash` if you change them** —
the octal trap above bites only bash, so zsh-only testing hides it. An array is
used rather than piping headers through `sed`, which avoids depending on GNU
sed's `\n`-in-replacement behaviour.

`secretkey` is a **static app constant**, not a user secret — it is the same for
every install.

## 1. Login (one-time MFA)

```bash
# Step 1 — authenticate. Captures otpKey (body) and xid (RESPONSE HEADER).
kia_curl POST prof/authUser "$(jq -nc \
  --arg u "$KIA_USERNAME" --ar

skill-card.md

## Description:

Guides one-off Kia vehicle status checks and remote commands through shell requests to the Kia Owners API.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

Kia owners and their authorized assistants use the skill to inspect vehicle status, location, and charging information or request door, climate, and charging actions from the shell.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The skill can access sensitive account and vehicle location data and issue real vehicle commands.

Mitigation: Run only on a private machine and require explicit confirmation before unlock, climate, or charging actions.

Risk: Durable session credentials and temporary response files can expose account or vehicle data.

Mitigation: Protect the saved session file, restrict access to temporary files, and delete them when finished.

## Reference(s):

- [ClawHub skill release](https://clawhub.ai/chrischall/skills/kiaaccess-curl)
- [Ready-to-run requests](references/requests.md)

## Skill Output:

**Output Type(s):** [Guidance, Shell commands]

**Output Format:** [Markdown with bash examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Requires account credentials and one-time MFA setup; command acceptance does not prove a vehicle state change.]

## Skill Version(s):

2.0.0 (source: ClawHub release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 13h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/kiaaccess-curl",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/kiaaccess-curl",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:51:24.503Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:51:24.503Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.8K downloads",
      "href": "https://clawhub.ai/chrischall/kiaaccess-curl",
      "sourceUrl": "https://clawhub.ai/chrischall/kiaaccess-curl",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:51:24.503Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.0.0",
      "href": "https://clawhub.ai/chrischall/kiaaccess-curl",
      "sourceUrl": "https://clawhub.ai/chrischall/kiaaccess-curl",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:24:03.714Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess-curl/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.0.0",
      "description": "kiaaccess-curl 2.0.0 - Removed the sample file skill-card.md. - No changes to functionality or documentation content.",
      "href": "https://clawhub.ai/chrischall/kiaaccess-curl",
      "sourceUrl": "https://clawhub.ai/chrischall/kiaaccess-curl",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:24:03.714Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to kiaaccess-curl and adjacent AI workflows.