myhotlunchbox-mcp
Read and manage a My Hot Lunchbox school-lunch account from a shell with curl — sign in, list students, read the lunch calendar and cart, check orders, deliveries and payments. Use when you want My Hot Lunchbox data without running the MCP server, in a script, or on a machine where the MCP is not installed. Skill: myhotlunchbox-mcp Owner: chrischall Summary: Read and manage a My Hot Lunchbox school-lunch account from a shell with curl — sign in, list students, read the lunch calendar and cart, check orders, deliveries and payments. Use when you want My Hot Lunchbox data without running the MCP server, in a script, or on a machine where the MCP is not installed. Tags: latest:1.2.6 Version history: v1.2.6 | 2026-10-09T23:
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
1.2.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.2.6release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:myhotlunchbox-mcp- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-myhotlunchbox-mcp/snapshot"
Documentation
CLAWHUB
147,081 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
--- name: myhotlunchbox description: Read and manage a My Hot Lunchbox school-lunch account from a shell with curl — sign in, list students, read the lunch calendar and cart, check orders, deliveries and payments. Use when you want My Hot Lunchbox data without running the MCP server, in a script, or on a machine where the MCP is not installed. --- # My Hot Lunchbox from the shell `ordernow.myhotlunchbox.com` exposes a plain JSON API behind an OAuth2 password grant. It is reachable server-side — no browser, no extension, no bridge. Two `curl` calls get you data: one to sign in, one per read. ## Sign in once per shell Credentials come from the environment; never paste them into a command line (that puts them in shell history). ```sh export MHLB_USER='[email protected]' export MHLB_PASS='…' # e.g. read -rs MHLB_PASS export MHLB=https://ordernow.myhotlunchbox.com mhlb_login() { local resp resp=$(curl -sS -X POST "$MHLB/api/auth/login" \ -H 'Content-Type: application/x-www-form-urlencoded' \ -H 'Accept: application/json' \ --data-urlencode 'grant_type=password' \ --data-urlencode "username=$MHLB_USER" \ --data-urlencode "password=$MHLB_PASS" \ --data-urlencode 'scope=openid offline_access email profile roles') || return 1 MHLB_TOKEN=$(printf '%s' "$resp" | jq -r '.access_token // empty') if [ -z "$MHLB_TOKEN" ]; then printf '%s' "$resp" | jq -r '.error_description // .error // "login failed"' >&2 return 1 fi export MHLB_TOKEN } # Authenticated GET. usage: mhlb_get /parent/childrenInfo [curl args…] mhlb_get() { local endpoint=$1; shift # NOT `path`: zsh ties $path to $PATH curl -sS "$MHLB/api$endpoint" -H "Authorization: Bearer $MHLB_TOKEN" -H 'Accept: application/json' "$@" } mhlb_login && mhlb_get /auth/userinfo | jq '{name, email, students_count, pending_orders_count, parent_credit_value}' ``` **A failed sign-in must not be retried.** The server is OpenIddict and counts failed attempts; repeated failures can escalate to a CAPTCHA and remove server-side sign-in for that account entirely. If `invalid_grant` comes back, stop and check the credentials. The token lasts about an hour. Re-run `mhlb_login` when a call starts returning `401`. ## The three reads that answer most questions ```sh # Who the students are — the id feeds everything else mhlb_get /parent/childrenInfo | jq '.[] | {id, firstName, schoolName, gradeTeacher, isInactive}' # The lunch calendar for a date range (POST, despite being a read). # The fields are `start`/`end`. Using `startDate`/`endDate` returns 200 with an # EMPTY events array — a silent wrong answer, not an error. curl -sS -X POST "$MHLB/api/calendar/studentSchoolData" \ -H "Authorization: Bearer $MHLB_TOKEN" -H 'Content-Type: application/json' \ -d '{"start":"2026-09-01","end":"2026-09-30"}' | jq '.events[] | {studentId, id, start, className}' # What is in the cart but not yet paid for mhlb_get '/event/shoppingCart' | jq . ``` `references/endpoints.m
_meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "myhotlunchbox-mcp",
"version": "1.2.6",
"publishedAt": 1791588421483
}references/endpoints.md
# My Hot Lunchbox endpoints — ready-to-run
All paths are relative to `$MHLB/api`. All need `Authorization: Bearer $MHLB_TOKEN`.
Assumes the `mhlb_get` helper from `SKILL.md` is defined.
## Account
```sh
# Account claims: name, role, student count, credit balances, subscription state
mhlb_get /auth/userinfo | jq .
```
## Students
```sh
mhlb_get /parent/childrenInfo | jq '.[] | {id, firstName, schoolName, gradeTeacher, hasOrders, isInactive, isInvited}'
# Editable profile for one student (also the model that POST /parent/editChild takes back)
mhlb_get '/parent/editChild?childId=456' | jq .
# Blank profile + dropdown options for adding a student
mhlb_get /parent/createChild | jq .
```
## Calendar and deliveries
```sh
# Lunch calendar for a range — a POST that reads
mhlb_post() {
local endpoint=$1; shift # NOT `path`: zsh ties $path to $PATH
curl -sS -X POST "$MHLB/api$endpoint" -H "Authorization: Bearer $MHLB_TOKEN" \
-H 'Content-Type: application/json' -d "${1:-{\}}"
}
# Fields are `start`/`end` — `startDate`/`endDate` silently returns zero events.
mhlb_post /calendar/studentSchoolData '{"start":"2026-09-01","end":"2026-09-30"}' | jq .
# Events carry the ids the ordering endpoints need:
mhlb_post /calendar/studentSchoolData '{"start":"2026-09-01","end":"2026-09-30"}' \
| jq '.events[] | {studentId, eventId: .id, orderId, date: .start[0:10], className}'
# What one student has on one day
mhlb_get '/calendar/studentOrderItems?studentId=456&date=2026-09-14' | jq .
```
`/deliveryInfo/*` and `/calendar/viewMatchedVendors` look parent-facing in the
site's compiled client but return **403** for a parent account — they belong to
the school and vendor dashboards. Verified live; don't reach for them.
## Cart and menu
```sh
# Valid filter values first — periods (semesters) and status tabs
mhlb_get /event/ShoppingCartBaseData | jq '{periods: [.periods[] | {text, value, selected}]}'
# The cart itself; every filter is optional
mhlb_get '/event/shoppingCart' | jq .
mhlb_get '/event/shoppingCart?selectedStudentId=456' | jq .
# The orderable menu for a student on a date — vendor, items, sizes, prices, cutoff
mhlb_get '/event/orderBaseData?studentId=456&eventDate=2026-09-14' | jq .
```
## Transactions and subscriptions
```sh
mhlb_get /event/transactionsList | jq .
mhlb_get '/event/transactionDetails?id=999' | jq . # id comes from transactionsList
mhlb_get /event/subscription | jq .
mhlb_get '/event/upcomingSubscriptions' | jq .
```
## Gift cards and coupons
```sh
mhlb_get /parent/giftCardDataTables | jq .
mhlb_get /parent/coupon | jq .
```
## Printable reports
These stream a **binary PDF**, not JSON — pipe to a file, never to `jq`. Their
payloads are not date ranges.
```sh
mhlb_pdf() { # usage: mhlb_pdf <endpoint> <json> <out.pdf>
curl -sS -X POST "$MHLB/api$1" -H "Authorization: Bearer $MHLB_TOKEN" \
-H 'Content-Type: application/json' -d "$2" -o "$3" && file "$3"
}
# Calenskill-card.md
## Description: Helps agents access and manage a My Hot Lunchbox school-lunch account using shell commands when the MCP server is unavailable. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: Parents and their authorized assistants can check students, lunch calendars, carts, orders, deliveries, and payments, or prepare account changes from a shell without the MCP server. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Account credentials and access tokens are handled by an agent or shell script. Mitigation: Use a trusted environment, keep credentials out of command history, and avoid exposing tokens or account data. Risk: Raw account-changing commands may alter or clear existing orders; write request bodies have not been verified against a live account. Mitigation: Inspect the complete payload before sending it, confirm each mutation, and read the resource again afterward; prefer the MCP wrapper when available. Risk: Checkout and subscription actions can cause real charges or account changes. Mitigation: Check prices and totals manually, obtain explicit approval, and never call checkout speculatively. ## Reference(s): - [ClawHub skill release](https://clawhub.ai/chrischall/skills/myhotlunchbox-mcp) - [My Hot Lunchbox endpoint reference](artifact/references/endpoints.md) ## Skill Output: **Output Type(s):** [Shell commands, Guidance] **Output Format:** [Markdown with shell command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Commands can retrieve JSON account data or save PDF reports.] ## Skill Version(s): 1.2.6 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/myhotlunchbox-mcp",
"sourceUrl": "https://clawhub.ai/chrischall/skills/myhotlunchbox-mcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T00:50:03.445Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-myhotlunchbox-mcp/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-myhotlunchbox-mcp/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T00:50:03.445Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/chrischall/myhotlunchbox-mcp",
"sourceUrl": "https://clawhub.ai/chrischall/myhotlunchbox-mcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T00:50:03.445Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.2.6",
"href": "https://clawhub.ai/chrischall/myhotlunchbox-mcp",
"sourceUrl": "https://clawhub.ai/chrischall/myhotlunchbox-mcp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:27:01.483Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-myhotlunchbox-mcp/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-myhotlunchbox-mcp/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.2.6",
"description": "- Update documentation in SKILL.md to clarify MCP confirmation behavior and mention the `MCP_CONFIRM_ELICITATION=off` environment variable. - Remove redundant skill-card.md file. - No changes to actual skill logic; update is documentation-only.",
"href": "https://clawhub.ai/chrischall/myhotlunchbox-mcp",
"sourceUrl": "https://clawhub.ai/chrischall/myhotlunchbox-mcp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:27:01.483Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
