resy-fpx
Query and act on Resy (resy.com restaurant reservations) from a shell without running the resy-mcp server — search venues, check slot availability, book/cancel reservations, and manage favorites/Priority Notify with curl against api.resy.com, using the fpx CLI (@fetchproxy/cli) only for the one-time token bootstrap when you have no RESY_EMAIL/RESY_PASSWORD. Use when you want Resy data or actions without the MCP, in a script, or on a machine where the MCP isn't installed. Skill: resy-fpx Owner: chrischall Summary: Query and act on Resy (resy.com restaurant reservations) from a shell without running the resy-mcp server — search venues, check slot availability, book/cancel reservations, and manage favorites/Priority Notify with curl against api.resy.com, using the fpx CLI (@fetchproxy/cli) only for the one-time token bootstrap when you have no RESY_EMAIL/RESY_PASSWORD. Use when you want
Rank
62
Safety
84
Downloads
1.4k
Updated
Oct 10, 2026
Version
1.3.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.4K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.3.3release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:resy-fpx- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-resy-fpx/snapshot"
Documentation
CLAWHUB
148,263 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: resy-fpx
description: >-
Query and act on Resy (resy.com restaurant reservations) from a shell
without running the resy-mcp server — search venues, check slot
availability, book/cancel reservations, and manage favorites/Priority
Notify with curl against api.resy.com, using the fpx CLI
(@fetchproxy/cli) only for the one-time token bootstrap when you have no
RESY_EMAIL/RESY_PASSWORD. Use when you want Resy data or actions without
the MCP, in a script, or on a machine where the MCP isn't installed.
---
# Resy via curl (+ one-time fpx bootstrap)
Resy has no public API — resy-mcp calls the same `api.resy.com` endpoints
the resy.com web app calls, all of which are reachable with **plain
curl**; nothing here needs a bot-wall bypass. The browser bridge (`fpx`)
is only needed to mint an auth token when you have no email/password on
hand — after that, every actual call (search, slots, book, cancel,
favorites, notify, profile) is a direct curl with the token in a header.
This mirrors resy-mcp's own "Pattern B": bridge the one auth call, then
go direct for the hot path (see `src/client.ts` / `src/auth-fetchproxy.ts`
in the resy-mcp repo).
## Step 1 — get a token (pick ONE path)
**Path A — you have Resy credentials (preferred, no browser needed):**
```sh
curl -s 'https://api.resy.com/3/auth/password' \
-H 'Authorization: ResyAPI api_key="VbWk7s3L4KiK5fzlO7JD3Q5EYolJI7n5"' \
-H 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode "email=$RESY_EMAIL" \
--data-urlencode "password=$RESY_PASSWORD" \
| jq -r '.token // .id.token // .auth_token'
```
The api key above is Resy's public web-app key (baked into resy.com's own
JS, not a secret — see `src/client.ts`). Save the returned token as
`$RESY_TOKEN`.
**Path B — no credentials, only a signed-in resy.com browser tab:**
One-time setup:
```sh
npm install -g @fetchproxy/cli # provides `fpx`
fpx profile add resy --domain resy.com
fpx pair -p resy # prints a pair code → approve in ContextMint Bridge
```
Then bootstrap the token through the tab (this replicates the one call
resy.com's own JS makes to refresh its in-memory token — the HttpOnly
session cookies authenticate it):
```sh
fpx post-json 'https://api.resy.com/3/auth/refresh' '{}' -p resy \
| jq -r '.token'
```
Save it as `$RESY_TOKEN`. `fpx` is not used again after this — every
call below is curl.
## Step 2 — call the API directly with the token
Every authenticated request needs this header set (see `SPOOF_HEADERS` +
`buildHeaders` in `src/client.ts`):
```sh
RESY_API_KEY='VbWk7s3L4KiK5fzlO7JD3Q5EYolJI7n5' # override if Resy rotates it
curl -s '<url>' \
-H "Authorization: ResyAPI api_key=\"$RESY_API_KEY\"" \
-H "x-resy-auth-token: $RESY_TOKEN" \
-H "x-resy-universal-auth: $RESY_TOKEN" \
-H 'Origin: https://resy.com' \
-H 'Referer: https://resy.com/' \
-H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko_meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "resy-fpx",
"version": "1.3.3",
"publishedAt": 1791588418360
}references/resy-api.md
# Resy API — ready-to-run requests
Base URL: `https://api.resy.com`. All requests below assume you've already
exported:
```sh
RESY_API_KEY='VbWk7s3L4KiK5fzlO7JD3Q5EYolJI7n5' # public web-app key, see SKILL.md
RESY_TOKEN='...' # from Step 1 in SKILL.md
```
and define this helper so every call below is one line:
```sh
resy() {
local method=$1 path=$2; shift 2
curl -s -X "$method" "https://api.resy.com${path}" \
-H "Authorization: ResyAPI api_key=\"$RESY_API_KEY\"" \
-H "x-resy-auth-token: $RESY_TOKEN" \
-H "x-resy-universal-auth: $RESY_TOKEN" \
-H 'Origin: https://resy.com' \
-H 'Referer: https://resy.com/' \
-H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36' \
-H 'Accept: application/json, text/plain, */*' \
"$@"
}
```
Any remaining args are forwarded straight to curl — use one `--data-urlencode "key=value"`
per form field for POST bodies (curl sets `Content-Type: application/x-www-form-urlencoded`
automatically once any `--data*` flag is present). `--data-urlencode` percent-encodes each
value the same way `src/client.ts`'s `URLSearchParams` does on the wire, so tokens like
`book_token`/`resy_token` (which can contain `rr://`, `:`, `&`, `=`) survive intact instead of
corrupting the body when interpolated raw into a single `--data` string.
Endpoints match the tool set in `src/tools/*.ts` of the resy-mcp repo
1:1 (14 tools total). Source line references are to that repo.
## Auth (Step 1 — see SKILL.md, not covered by the `resy()` helper)
- `POST /3/auth/password` — form body `email`, `password` → `{ token }`
(or `{ id: { token } }` / `{ auth_token }` on some responses).
`src/client.ts` `loginWithPassword()`.
- `POST /3/auth/refresh` (via `fpx post-json`, not curl — HttpOnly cookies
authenticate it) → `{ token }`. `src/auth-fetchproxy.ts`.
## User / profile — `resy_get_profile`, `resy_list_payment_methods`
```sh
resy GET /2/user | jq '{
first_name, last_name, email: .em_address, phone: .mobile_number,
num_bookings, member_since: .date_created, is_resy_select: .resy_select
}'
resy GET /2/user | jq '.payment_methods[] | {
id, brand, last_four: (.last_four // .last4 // .display_number),
exp_month, exp_year, is_default
}'
```
`payment_methods[].id` is the `payment_method_id` accepted by the book
call below.
## Venue search — `resy_search_venues`
```sh
STRUCT=$(jq -nc --arg q "ramen" --arg day "2026-08-01" \
'{availability:true, page:1, per_page:20, slot_filter:{day:$day, party_size:2},
types:["venue"], order_by:"availability",
geo:{latitude:40.7128, longitude:-73.9876, radius:16100}, query:$q}')
resy POST /3/venuesearch/search --data-urlencode "struct_data=$STRUCT" \
| jq '.search.hits[] | {venue_id: .id.resy, name, cuisine, price_range, rating, url_slug}'
```
`src/tools/venues.ts` `registerVenueTools` / `resy_search_venues`. NYC geo
(`40.7128,-73.9876`) is theskill-card.md
## Description: Helps agents search Resy restaurants, check availability, and manage reservations, favorites, and Priority Notify using shell commands. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: Resy account holders and developers can use this skill to find restaurants and available tables, book or cancel reservations, and manage favorites and Priority Notify without an MCP server. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Booking, cancellation, favorite, and notify requests change a live Resy account without an enforced confirmation step. Mitigation: Before each write, show and confirm the venue, date, time, party size, reservation or notify identifier, and payment method as applicable; check the account afterward. Risk: Resy credentials and account tokens may be exposed through shared scripts or logs. Mitigation: Treat RESY_PASSWORD and RESY_TOKEN as secrets; avoid including their values in shared logs or scripts. ## Reference(s): - [Resy API request examples](references/resy-api.md) - [resy-fpx on ClawHub](https://clawhub.ai/chrischall/skills/resy-fpx) ## Skill Output: **Output Type(s):** [Shell commands, Guidance] **Output Format:** [Markdown with shell command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Includes read-only lookups and commands that change a live Resy account.] ## Skill Version(s): 1.3.3 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/resy-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/skills/resy-fpx",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T14:11:22.577Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-resy-fpx/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-resy-fpx/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T14:11:22.577Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.4K downloads",
"href": "https://clawhub.ai/chrischall/resy-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/resy-fpx",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T14:11:22.577Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.3.3",
"href": "https://clawhub.ai/chrischall/resy-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/resy-fpx",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:26:58.360Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-resy-fpx/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-resy-fpx/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.3.3",
"description": "- Removed the redundant skill-card.md file. - No user-facing functionality or documentation changes. - Internal cleanup for improved file organization.",
"href": "https://clawhub.ai/chrischall/resy-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/resy-fpx",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:26:58.360Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
