agentCLAWHUBUnverified

signupgenius-api

Access SignUpGenius (sign-ups, groups, RSVPs) from a shell with curl instead of running the signupgenius-mcp server — server-side email/password login to a JWT + cfid/cftoken cookies, then curl the v3 API and legacy /SUGboxAPI.cfm dispatcher directly. Use when you want SignUpGenius data without the MCP, in a script, or on a machine where the MCP isn't installed. Skill: signupgenius-api Owner: chrischall Summary: Access SignUpGenius (sign-ups, groups, RSVPs) from a shell with curl instead of running the signupgenius-mcp server — server-side email/password login to a JWT + cfid/cftoken cookies, then curl the v3 API and legacy /SUGboxAPI.cfm dispatcher directly. Use when you want SignUpGenius data without the MCP, in a script, or on a machine where the MCP isn't installed. Tags

OpenClaw

Rank

62

Safety

84

Downloads

1.6k

Updated

Oct 10, 2026

Version

2.1.9

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.6K downloadsadoption · observed Oct 10, 2026
Latest release
2.1.9release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:signupgenius-api
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/snapshot"

Documentation

CLAWHUB

147,385 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: signupgenius-api
description: "Access SignUpGenius (sign-ups, groups, RSVPs) from a shell with curl instead of running the signupgenius-mcp server — server-side email/password login to a JWT + cfid/cftoken cookies, then curl the v3 API and legacy /SUGboxAPI.cfm dispatcher directly. Use when you want SignUpGenius data without the MCP, in a script, or on a machine where the MCP isn't installed."
---

# SignUpGenius via curl (no MCP)

SignUpGenius's session mode is a classic ColdFusion login: POST email+password
to the login form, get back a `accessToken` JWT cookie plus `cfid`/`cftoken`
session cookies. No browser or extension needed — everything here is a plain
`curl` call. This is the same auth path `signupgenius-mcp` uses in session
mode (`src/auth-session-login.ts`); its fetchproxy path (lifting the same
cookies out of a signed-in browser tab) is only a **fallback** for when you
don't want to put a password in `.env` — this skill always logs in directly.

## One-time setup

```sh
export SIGNUPGENIUS_EMAIL="[email protected]"
export SIGNUPGENIUS_PASSWORD="..."
# or: export SIGNUPGENIUS_PASSWORD="$(op read 'op://Private/SignUpGenius/password')"
```

SSO accounts (Google/Apple/Facebook/Microsoft) and 2FA-enabled accounts can't
use this flow — same limitation as the MCP's session mode.

## Log in: get the JWT + cookies

```sh
COOKIEJAR=$(mktemp)

CSRF=$(curl -s -c "$COOKIEJAR" https://www.signupgenius.com/login \
  | grep -oE 'name="csrfToken"[[:space:]]+value="[^"]+"' \
  | sed -E 's/.*value="([^"]+)".*/\1/')

curl -s -D /tmp/sug-login-headers.txt -o /dev/null \
  -b "$COOKIEJAR" -c "$COOKIEJAR" \
  -A 'Mozilla/5.0 (Macintosh; Intel Mac OS X 14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0 Safari/537.36' \
  -X POST 'https://www.signupgenius.com/index.cfm?go=c.Login' \
  --data-urlencode "csrfToken=$CSRF" \
  --data-urlencode "loginemail=$SIGNUPGENIUS_EMAIL" \
  --data-urlencode "pword=$SIGNUPGENIUS_PASSWORD" \
  --data-urlencode "successpage=c.jump&jump=/index.cfm?go=c.MyAccount" \
  --data-urlencode "failpage=c.Register" \
  --data-urlencode "ScreenWidth=2000" \
  --data-urlencode "ScreenHeight=1200" \
  --data-urlencode "formaction=1" \
  --data-urlencode "formName=loginform" \
  --data-urlencode "refererUrl="

# Bad credentials 302 to c.Register instead of setting accessToken — check both:
grep -q 'c.Register' /tmp/sug-login-headers.txt && echo "LOGIN FAILED (bad credentials)" >&2

ACCESS_TOKEN=$(awk -F'\t' '$6=="accessToken"{print $7}' "$COOKIEJAR")
CFID=$(awk -F'\t' '$6=="cfid"{print $7}' "$COOKIEJAR")
CFTOKEN=$(awk -F'\t' '$6=="cftoken"{print $7}' "$COOKIEJAR")
[ -z "$ACCESS_TOKEN" ] && echo "LOGIN FAILED (no accessToken cookie set)" >&2
COOKIE_HEADER="accessToken=${ACCESS_TOKEN}; cfid=${CFID}; cftoken=${CFTOKEN}"
```

This mirrors `sessionLoginFlow` exactly: GET `/login` for the CSRF token +
`cfid`/`cftoken`, POST the credentials with the exact same static form fields
the wizard sends, and read the `accessToken` cookie bac

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "signupgenius-api",
  "version": "2.1.9",
  "publishedAt": 1791588447201
}

references/sug-endpoints.md

# SignUpGenius session-mode endpoints for curl

All calls assume `$ACCESS_TOKEN` and `$COOKIE_HEADER` from the login step in
`../SKILL.md`. Every call sends both:

```
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER"
```

Paths under `api.signupgenius.com/v3` are the exact paths `signupgenius-mcp`'s
`client.ts` builds in session mode (it appends a trailing `/` to every v3
path — included below). Legacy calls POST JSON to
`https://www.signupgenius.com/SUGboxAPI.cfm?go=<action>` with
`Content-Type: application/json`.

---

## 1. Profile

```sh
curl -s 'https://api.signupgenius.com/v3/member/profile/' \
  -H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" | jq '.data'
```

## 2. Groups

List groups (`sort` is optional, `asc`/`desc`):

```sh
curl -s 'https://api.signupgenius.com/v3/groups/all/?sort=asc' \
  -H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" \
  | jq -r '.data[] | "\(.groupid)\t\(.title)"'
```

List a group's members (`GROUP_ID` from above):

```sh
curl -s "https://api.signupgenius.com/v3/groups/${GROUP_ID}/members/" \
  -H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" \
  | jq -r '.data[] | "\(.communitymemberid)\t\(.emailaddress)"'
```

Get one member's detail (address/phone — only present if they supplied it on
a sign-up):

```sh
curl -s "https://api.signupgenius.com/v3/groups/${GROUP_ID}/members/${MEMBER_ID}/details/" \
  -H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" | jq '.data'
```

Add a member (**write** — confirm with the user first; `firstname`/`lastname`
are optional):

```sh
curl -s -X POST "https://api.signupgenius.com/v3/groups/${GROUP_ID}/members/create/" \
  -H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" \
  -H 'Content-Type: application/json' \
  -d '{"emailaddress":"[email protected]","firstname":"Jane","lastname":"Doe"}' \
  | jq '.success, .message'
```

## 3. Sign-up listings

In session mode `created`/`invited`/`signedupfor` each have **one** v3 path
each (unlike key mode's separate `/active`/`/expired`/`/all` paths) — filter
on `enddate` client-side if you only want active ones:

```sh
# everything the account created (active + expired together)
curl -s 'https://api.signupgenius.com/v3/signups/created/' \
  -H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" \
  | jq -r '.data[] | "\(.signupid)\t\(.enddate)\t\(.title)"'

# sign-ups invited to
curl -s 'https://api.signupgenius.com/v3/signups/invited/' \
  -H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" | jq '.data'

# sign-ups personally signed up for
curl -s 'https://api.signupgenius.com/v3/signups/signedupfor/' \
  -H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" | jq '.data'
```

Legacy dispatcher equivalent — sometimes returns fuller data than v3
(note the **upper-case** envelope):

```sh
curl -s -X POST 'https://www.signupgenius.com/SUGboxAPI.cfm?go=t.getMySignups' \
  -H "Auth

skill-card.md

## Description:

Guides agents in accessing SignUpGenius sign-ups, groups, and RSVPs with shell commands using account-based authentication instead of an MCP server.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and other SignUpGenius users use this skill to retrieve sign-ups and group information or manage RSVPs and slot claims from a shell without an MCP server.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Account passwords, bearer tokens, and session cookies may be exposed through shell history, logs, or temporary files.

Mitigation: Use a private machine and secure secret handling; do not log or paste authorization headers or cookies, and delete cookie jars and temporary header files after use.

Risk: Public participant lookups can expose personal information.

Mitigation: Only retrieve participant details for an authorized purpose and limit sharing of personal data.

Risk: RSVP, slot-claim, release, and group-member actions can change account or participant records.

Mitigation: Confirm the intended action and account details with the user before making changes.

## Reference(s):

- [SignUpGenius API skill release](https://clawhub.ai/chrischall/skills/signupgenius-api)
- [SignUpGenius session-mode endpoint reference](references/sug-endpoints.md)

## Skill Output:

**Output Type(s):** [Shell commands, Guidance]

**Output Format:** [Markdown with shell code blocks]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [None]

## Skill Version(s):

2.1.9 (source: ClawHub release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 15h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/signupgenius-api",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/signupgenius-api",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T06:14:21.077Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T06:14:21.077Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.6K downloads",
      "href": "https://clawhub.ai/chrischall/signupgenius-api",
      "sourceUrl": "https://clawhub.ai/chrischall/signupgenius-api",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T06:14:21.077Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.1.9",
      "href": "https://clawhub.ai/chrischall/signupgenius-api",
      "sourceUrl": "https://clawhub.ai/chrischall/signupgenius-api",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:27:27.201Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.1.9",
      "description": "- Clarified that RSVPs and slot claims should default to the signed-in user's name and email, as the entry is tied to the authenticated account. - Updated SKILL.md for more accurate instructions on RSVP and slot claim data. - Removed legacy skill-card.md file.",
      "href": "https://clawhub.ai/chrischall/signupgenius-api",
      "sourceUrl": "https://clawhub.ai/chrischall/signupgenius-api",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:27:27.201Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to signupgenius-api and adjacent AI workflows.