agentCLAWHUBUnverified

schoolpass-curl

Read a SchoolPass parent account directly with curl against the regional SchoolPass REST API (a busapi shard on school-pass.net), without running the MCP server. Use for a one-off shell read of your students, arrival/dismissal calendar, pending pickup changes, drivers, dismissal locations, or school info — "check SchoolPass from the terminal", "list my kids in SchoolPass", "any dismissal changes today". Requires SCHOOLPASS_EMAIL / SCHOOLPASS_PASSWORD / SCHOOLPASS_SCHOOL_CODE.

OpenClaw

Rank

62

Safety

84

Downloads

1.1k

Updated

Oct 11, 2026

Version

1.0.9

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1.1K downloadsadoption · observed Oct 11, 2026
Latest release
1.0.9release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:schoolpass-curl
  1. Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:schoolpass-curl` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/schoolpass-curl before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/snapshot"

Documentation

CLAWHUB

126,765 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: schoolpass-curl
description: Read a SchoolPass parent account directly with curl against the regional SchoolPass REST API (a busapi shard on school-pass.net), without running the MCP server. Use for a one-off shell read of your students, arrival/dismissal calendar, pending pickup changes, drivers, dismissal locations, or school info — "check SchoolPass from the terminal", "list my kids in SchoolPass", "any dismissal changes today". Requires SCHOOLPASS_EMAIL / SCHOOLPASS_PASSWORD / SCHOOLPASS_SCHOOL_CODE.
---

# SchoolPass API via curl

The SchoolPass JSON API is reachable server-side — no browser, no bridge, no
extension. This skill talks to it directly with `curl`.

Prefer the `schoolpass-mcp` server for anything conversational or repeated; use
this for one-off shell work, scripts, or when the server isn't running.

**Ready-to-run request bodies and `jq` recipes: `references/requests.md`.**
Full shape reference: `../../docs/SCHOOLPASS-API.md`.

## Setup

```bash
export SCHOOLPASS_EMAIL='[email protected]'
export SCHOOLPASS_PASSWORD='…'
export SCHOOLPASS_SCHOOL_CODE=1183          # your school id (the AppCode)
export SCHOOLPASS_API_HOST=busapi-east16-ss.school-pass.net   # your region's shard
```

Find your school id and region host by signing into your school's
`<school>.school-pass.net` portal, opening the new SchoolPass app, and reading
`appCode` (the id) and `apiUrl` (the host) from its `localStorage`.

## Two rules

1. **Every request needs an `AppCode: <schoolCode>` header.** It selects your
   school. Omit it (or send the wrong one) and you get `401`. It is not a
   secret. `references/requests.md`'s `sp_curl` helper adds it for you.
2. **HTTP status codes are real.** `401` = the token or AppCode was rejected,
   `403` = a parent account cannot reach that route (it is admin-only), `2xx` =
   success. Branch on the HTTP code.

## Auth: email/password → bearer

1. `POST Auth/users` with `{schoolCode,email,password,authType:"Credentials"}`
   → the identities your email owns. Take the one whose `userType` is `3`
   (Parent).
2. `POST Auth/token` with `{schoolCode,userId,userType,password,authType:"Credentials"}`
   → `{ access_token, refresh_token, … }`. Send `access_token` as
   `Authorization: Bearer …` on every subsequent call.

`references/requests.md`'s `sp_login` does both and caches the token.

> **Never retry a rejected login.** SchoolPass fronts its login with reCAPTCHA;
> repeated wrong passwords can get the account challenged and break shell login.
> Fix the credential and try once.

## Reads

All are `GET` with the `AppCode` header + `Authorization: Bearer`. Most parent
endpoints take an optional `memberId` (your own parent id, from `Auth/users`).

| Want | Endpoint |
| --- | --- |
| your students | `GET parent/getstudents` |
| parent profile | `GET parent/profile` |
| authorized drivers | `GET parent/parentdrivers?includeCarpool=true` |
| student calendar | `GET Student/StudentCalendar?schoolCode=&studentId=&startDate=&en

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "schoolpass-curl",
  "version": "1.0.9",
  "publishedAt": 1791588422839
}

references/requests.md

# Ready-to-run requests

Shapes come from the SchoolPass Swagger spec and `docs/SCHOOLPASS-API.md`. Run
the live check (`node --env-file=.env scripts/live-check.mjs`) once to confirm
the auth-response fields on your account before trusting the `jq` recipes below.

## Helper — source this first

```bash
: "${SCHOOLPASS_SCHOOL_CODE:?export SCHOOLPASS_SCHOOL_CODE first}"
: "${SCHOOLPASS_EMAIL:?}"; : "${SCHOOLPASS_PASSWORD:?}"
SP_HOST="${SCHOOLPASS_API_HOST:-busapi-east16-ss.school-pass.net}"
SP_BASE="https://${SP_HOST}/api"
# Token cache for this skill (NOT the MCP server's store — the server keeps none
# on disk, but keep this skill's state self-contained regardless).
SP_SESSION="${SCHOOLPASS_CURL_SESSION:-$HOME/.schoolpass-mcp/curl-token.json}"

# sp_curl <method> <path> [body-json] [-- extra-curl-args...]
# Adds the AppCode header, Authorization (if $SP_TOKEN set), and JSON accept.
sp_curl() {
  local method="$1" path="$2" body="${3:-}"
  shift 2; [ $# -gt 0 ] && shift
  [ "${1:-}" = "--" ] && shift
  curl -sS -X "$method" "${SP_BASE}/${path}" \
    -H "AppCode: ${SCHOOLPASS_SCHOOL_CODE}" \
    -H "accept: application/json" \
    -H "content-type: application/json" \
    ${SP_TOKEN:+-H "Authorization: Bearer ${SP_TOKEN}"} \
    ${body:+--data "$body"} "$@"
}

# sp_login: Auth/users -> pick Parent identity -> Auth/token -> export SP_TOKEN.
# Verify the response field names against your account once (live-check) — the
# access-token field is `access_token`; adjust the jq path if yours differs.
sp_login() {
  local users uid utype token
  users=$(sp_curl POST Auth/users "$(jq -nc \
    --argjson sc "$SCHOOLPASS_SCHOOL_CODE" --arg em "$SCHOOLPASS_EMAIL" --arg pw "$SCHOOLPASS_PASSWORD" \
    '{schoolCode:$sc,email:$em,password:$pw,ssoToken:null,authType:"Credentials"}')") || return 1
  # Pick the Parent identity (userType 3), else the sole identity. Field names
  # vary (userId|id, userType|type) — normalize.
  uid=$(echo "$users" | jq -r '(if type=="array" then . else (.users // .data // [.]) end)
      | map({id:(.userId // .id), t:(.userType // .type)})
      | (map(select(.t==3))[0] // .[0]) | .id')
  utype=$(echo "$users" | jq -r '(if type=="array" then . else (.users // .data // [.]) end)
      | map({id:(.userId // .id), t:(.userType // .type)})
      | (map(select(.t==3))[0] // .[0]) | .t')
  token=$(sp_curl POST Auth/token "$(jq -nc \
    --argjson sc "$SCHOOLPASS_SCHOOL_CODE" --argjson uid "$uid" --argjson ut "$utype" --arg pw "$SCHOOLPASS_PASSWORD" \
    '{schoolCode:$sc,userId:$uid,userType:$ut,password:$pw,ssoToken:null,authType:"Credentials"}')" \
    | jq -r '.access_token // .payload.access_token // .accessToken')
  [ -n "$token" ] && [ "$token" != "null" ] || { echo "login failed" >&2; return 1; }
  export SP_TOKEN="$token" SP_MEMBER_ID="$uid"
  mkdir -p "$(dirname "$SP_SESSION")" && chmod 700 "$(dirname "$SP_SESSION")"
  printf '{"memberId":%s}\n' "$uid" > "$SP_SESSION"   # never write the token to disk
}
```

## Reachability (no aut

skill-card.md

## Description:

Provides curl and jq guidance for reading a SchoolPass parent account, with separate examples for changing arrival or dismissal records.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

Parents and authorized helpers use this skill for one-off terminal checks of students, calendars, pickup changes, drivers, dismissal locations, and school information in their SchoolPass account.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The reference guide includes live commands that can create or delete student arrival or dismissal changes despite the skill's read-focused description.

Mitigation: Avoid the POST and DELETE examples unless you explicitly intend to change live records; re-read the calendar to confirm any intended change.

Risk: SchoolPass passwords, bearer tokens, and student information can be exposed when commands or responses are shared.

Mitigation: Keep credentials and tokens out of shared transcripts, and copy only appCode and apiUrl when checking browser localStorage.

## Reference(s):

- [SchoolPass Curl release](https://clawhub.ai/chrischall/skills/schoolpass-curl)
- [Ready-to-run requests](references/requests.md)

## Skill Output:

**Output Type(s):** [Shell commands, Guidance]

**Output Format:** [Markdown with bash and jq examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Requires a SchoolPass parent account, school code, and regional API host.]

## Skill Version(s):

1.0.9 (source: server-resolved release)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/schoolpass-curl",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/schoolpass-curl",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T09:44:13.912Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T09:44:13.912Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.1K downloads",
      "href": "https://clawhub.ai/chrischall/schoolpass-curl",
      "sourceUrl": "https://clawhub.ai/chrischall/schoolpass-curl",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T09:44:13.912Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.0.9",
      "href": "https://clawhub.ai/chrischall/schoolpass-curl",
      "sourceUrl": "https://clawhub.ai/chrischall/schoolpass-curl",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:27:02.839Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-schoolpass-curl/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.0.9",
      "description": "- Removed the file skill-card.md. - No user-facing or functional changes to the skill's logic or documentation.",
      "href": "https://clawhub.ai/chrischall/schoolpass-curl",
      "sourceUrl": "https://clawhub.ai/chrischall/schoolpass-curl",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:27:02.839Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to schoolpass-curl and adjacent AI workflows.