schoolpass-curl
Read a SchoolPass parent account directly with curl against the regional SchoolPass REST API (a busapi shard on school-pass.net), without running the MCP server. Use for a one-off shell read of your students, arrival/dismissal calendar, pending pickup changes, drivers, dismissal locations, or school info — "check SchoolPass from the terminal", "list my kids in SchoolPass", "any dismissal changes today". Requires SCHOOLPASS_EMAIL / SCHOOLPASS_PASSWORD / SCHOOLPASS_SCHOOL_CODE.
Rank
62
Safety
84
Downloads
1.1k
Updated
Oct 11, 2026
Version
1.0.9
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.0.9release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:schoolpass-curl- Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:schoolpass-curl` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/schoolpass-curl before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/snapshot"
Documentation
CLAWHUB
126,765 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
--- name: schoolpass-curl description: Read a SchoolPass parent account directly with curl against the regional SchoolPass REST API (a busapi shard on school-pass.net), without running the MCP server. Use for a one-off shell read of your students, arrival/dismissal calendar, pending pickup changes, drivers, dismissal locations, or school info — "check SchoolPass from the terminal", "list my kids in SchoolPass", "any dismissal changes today". Requires SCHOOLPASS_EMAIL / SCHOOLPASS_PASSWORD / SCHOOLPASS_SCHOOL_CODE. --- # SchoolPass API via curl The SchoolPass JSON API is reachable server-side — no browser, no bridge, no extension. This skill talks to it directly with `curl`. Prefer the `schoolpass-mcp` server for anything conversational or repeated; use this for one-off shell work, scripts, or when the server isn't running. **Ready-to-run request bodies and `jq` recipes: `references/requests.md`.** Full shape reference: `../../docs/SCHOOLPASS-API.md`. ## Setup ```bash export SCHOOLPASS_EMAIL='[email protected]' export SCHOOLPASS_PASSWORD='…' export SCHOOLPASS_SCHOOL_CODE=1183 # your school id (the AppCode) export SCHOOLPASS_API_HOST=busapi-east16-ss.school-pass.net # your region's shard ``` Find your school id and region host by signing into your school's `<school>.school-pass.net` portal, opening the new SchoolPass app, and reading `appCode` (the id) and `apiUrl` (the host) from its `localStorage`. ## Two rules 1. **Every request needs an `AppCode: <schoolCode>` header.** It selects your school. Omit it (or send the wrong one) and you get `401`. It is not a secret. `references/requests.md`'s `sp_curl` helper adds it for you. 2. **HTTP status codes are real.** `401` = the token or AppCode was rejected, `403` = a parent account cannot reach that route (it is admin-only), `2xx` = success. Branch on the HTTP code. ## Auth: email/password → bearer 1. `POST Auth/users` with `{schoolCode,email,password,authType:"Credentials"}` → the identities your email owns. Take the one whose `userType` is `3` (Parent). 2. `POST Auth/token` with `{schoolCode,userId,userType,password,authType:"Credentials"}` → `{ access_token, refresh_token, … }`. Send `access_token` as `Authorization: Bearer …` on every subsequent call. `references/requests.md`'s `sp_login` does both and caches the token. > **Never retry a rejected login.** SchoolPass fronts its login with reCAPTCHA; > repeated wrong passwords can get the account challenged and break shell login. > Fix the credential and try once. ## Reads All are `GET` with the `AppCode` header + `Authorization: Bearer`. Most parent endpoints take an optional `memberId` (your own parent id, from `Auth/users`). | Want | Endpoint | | --- | --- | | your students | `GET parent/getstudents` | | parent profile | `GET parent/profile` | | authorized drivers | `GET parent/parentdrivers?includeCarpool=true` | | student calendar | `GET Student/StudentCalendar?schoolCode=&studentId=&startDate=&en
_meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "schoolpass-curl",
"version": "1.0.9",
"publishedAt": 1791588422839
}references/requests.md
# Ready-to-run requests
Shapes come from the SchoolPass Swagger spec and `docs/SCHOOLPASS-API.md`. Run
the live check (`node --env-file=.env scripts/live-check.mjs`) once to confirm
the auth-response fields on your account before trusting the `jq` recipes below.
## Helper — source this first
```bash
: "${SCHOOLPASS_SCHOOL_CODE:?export SCHOOLPASS_SCHOOL_CODE first}"
: "${SCHOOLPASS_EMAIL:?}"; : "${SCHOOLPASS_PASSWORD:?}"
SP_HOST="${SCHOOLPASS_API_HOST:-busapi-east16-ss.school-pass.net}"
SP_BASE="https://${SP_HOST}/api"
# Token cache for this skill (NOT the MCP server's store — the server keeps none
# on disk, but keep this skill's state self-contained regardless).
SP_SESSION="${SCHOOLPASS_CURL_SESSION:-$HOME/.schoolpass-mcp/curl-token.json}"
# sp_curl <method> <path> [body-json] [-- extra-curl-args...]
# Adds the AppCode header, Authorization (if $SP_TOKEN set), and JSON accept.
sp_curl() {
local method="$1" path="$2" body="${3:-}"
shift 2; [ $# -gt 0 ] && shift
[ "${1:-}" = "--" ] && shift
curl -sS -X "$method" "${SP_BASE}/${path}" \
-H "AppCode: ${SCHOOLPASS_SCHOOL_CODE}" \
-H "accept: application/json" \
-H "content-type: application/json" \
${SP_TOKEN:+-H "Authorization: Bearer ${SP_TOKEN}"} \
${body:+--data "$body"} "$@"
}
# sp_login: Auth/users -> pick Parent identity -> Auth/token -> export SP_TOKEN.
# Verify the response field names against your account once (live-check) — the
# access-token field is `access_token`; adjust the jq path if yours differs.
sp_login() {
local users uid utype token
users=$(sp_curl POST Auth/users "$(jq -nc \
--argjson sc "$SCHOOLPASS_SCHOOL_CODE" --arg em "$SCHOOLPASS_EMAIL" --arg pw "$SCHOOLPASS_PASSWORD" \
'{schoolCode:$sc,email:$em,password:$pw,ssoToken:null,authType:"Credentials"}')") || return 1
# Pick the Parent identity (userType 3), else the sole identity. Field names
# vary (userId|id, userType|type) — normalize.
uid=$(echo "$users" | jq -r '(if type=="array" then . else (.users // .data // [.]) end)
| map({id:(.userId // .id), t:(.userType // .type)})
| (map(select(.t==3))[0] // .[0]) | .id')
utype=$(echo "$users" | jq -r '(if type=="array" then . else (.users // .data // [.]) end)
| map({id:(.userId // .id), t:(.userType // .type)})
| (map(select(.t==3))[0] // .[0]) | .t')
token=$(sp_curl POST Auth/token "$(jq -nc \
--argjson sc "$SCHOOLPASS_SCHOOL_CODE" --argjson uid "$uid" --argjson ut "$utype" --arg pw "$SCHOOLPASS_PASSWORD" \
'{schoolCode:$sc,userId:$uid,userType:$ut,password:$pw,ssoToken:null,authType:"Credentials"}')" \
| jq -r '.access_token // .payload.access_token // .accessToken')
[ -n "$token" ] && [ "$token" != "null" ] || { echo "login failed" >&2; return 1; }
export SP_TOKEN="$token" SP_MEMBER_ID="$uid"
mkdir -p "$(dirname "$SP_SESSION")" && chmod 700 "$(dirname "$SP_SESSION")"
printf '{"memberId":%s}\n' "$uid" > "$SP_SESSION" # never write the token to disk
}
```
## Reachability (no autskill-card.md
## Description: Provides curl and jq guidance for reading a SchoolPass parent account, with separate examples for changing arrival or dismissal records. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: Parents and authorized helpers use this skill for one-off terminal checks of students, calendars, pickup changes, drivers, dismissal locations, and school information in their SchoolPass account. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The reference guide includes live commands that can create or delete student arrival or dismissal changes despite the skill's read-focused description. Mitigation: Avoid the POST and DELETE examples unless you explicitly intend to change live records; re-read the calendar to confirm any intended change. Risk: SchoolPass passwords, bearer tokens, and student information can be exposed when commands or responses are shared. Mitigation: Keep credentials and tokens out of shared transcripts, and copy only appCode and apiUrl when checking browser localStorage. ## Reference(s): - [SchoolPass Curl release](https://clawhub.ai/chrischall/skills/schoolpass-curl) - [Ready-to-run requests](references/requests.md) ## Skill Output: **Output Type(s):** [Shell commands, Guidance] **Output Format:** [Markdown with bash and jq examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Requires a SchoolPass parent account, school code, and regional API host.] ## Skill Version(s): 1.0.9 (source: server-resolved release) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/schoolpass-curl",
"sourceUrl": "https://clawhub.ai/chrischall/skills/schoolpass-curl",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T09:44:13.912Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T09:44:13.912Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.1K downloads",
"href": "https://clawhub.ai/chrischall/schoolpass-curl",
"sourceUrl": "https://clawhub.ai/chrischall/schoolpass-curl",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T09:44:13.912Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.9",
"href": "https://clawhub.ai/chrischall/schoolpass-curl",
"sourceUrl": "https://clawhub.ai/chrischall/schoolpass-curl",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:27:02.839Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.9",
"description": "- Removed the file skill-card.md. - No user-facing or functional changes to the skill's logic or documentation.",
"href": "https://clawhub.ai/chrischall/schoolpass-curl",
"sourceUrl": "https://clawhub.ai/chrischall/schoolpass-curl",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:27:02.839Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
