signupgenius-api
Access SignUpGenius (sign-ups, groups, RSVPs) from a shell with curl instead of running the signupgenius-mcp server — server-side email/password login to a JWT + cfid/cftoken cookies, then curl the v3 API and legacy /SUGboxAPI.cfm dispatcher directly. Use when you want SignUpGenius data without the MCP, in a script, or on a machine where the MCP isn't installed. Skill: signupgenius-api Owner: chrischall Summary: Access SignUpGenius (sign-ups, groups, RSVPs) from a shell with curl instead of running the signupgenius-mcp server — server-side email/password login to a JWT + cfid/cftoken cookies, then curl the v3 API and legacy /SUGboxAPI.cfm dispatcher directly. Use when you want SignUpGenius data without the MCP, in a script, or on a machine where the MCP isn't installed. Tags
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
2.1.9
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 2.1.9release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:signupgenius-api- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/snapshot"
Documentation
CLAWHUB
147,385 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
--- name: signupgenius-api description: "Access SignUpGenius (sign-ups, groups, RSVPs) from a shell with curl instead of running the signupgenius-mcp server — server-side email/password login to a JWT + cfid/cftoken cookies, then curl the v3 API and legacy /SUGboxAPI.cfm dispatcher directly. Use when you want SignUpGenius data without the MCP, in a script, or on a machine where the MCP isn't installed." --- # SignUpGenius via curl (no MCP) SignUpGenius's session mode is a classic ColdFusion login: POST email+password to the login form, get back a `accessToken` JWT cookie plus `cfid`/`cftoken` session cookies. No browser or extension needed — everything here is a plain `curl` call. This is the same auth path `signupgenius-mcp` uses in session mode (`src/auth-session-login.ts`); its fetchproxy path (lifting the same cookies out of a signed-in browser tab) is only a **fallback** for when you don't want to put a password in `.env` — this skill always logs in directly. ## One-time setup ```sh export SIGNUPGENIUS_EMAIL="[email protected]" export SIGNUPGENIUS_PASSWORD="..." # or: export SIGNUPGENIUS_PASSWORD="$(op read 'op://Private/SignUpGenius/password')" ``` SSO accounts (Google/Apple/Facebook/Microsoft) and 2FA-enabled accounts can't use this flow — same limitation as the MCP's session mode. ## Log in: get the JWT + cookies ```sh COOKIEJAR=$(mktemp) CSRF=$(curl -s -c "$COOKIEJAR" https://www.signupgenius.com/login \ | grep -oE 'name="csrfToken"[[:space:]]+value="[^"]+"' \ | sed -E 's/.*value="([^"]+)".*/\1/') curl -s -D /tmp/sug-login-headers.txt -o /dev/null \ -b "$COOKIEJAR" -c "$COOKIEJAR" \ -A 'Mozilla/5.0 (Macintosh; Intel Mac OS X 14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0 Safari/537.36' \ -X POST 'https://www.signupgenius.com/index.cfm?go=c.Login' \ --data-urlencode "csrfToken=$CSRF" \ --data-urlencode "loginemail=$SIGNUPGENIUS_EMAIL" \ --data-urlencode "pword=$SIGNUPGENIUS_PASSWORD" \ --data-urlencode "successpage=c.jump&jump=/index.cfm?go=c.MyAccount" \ --data-urlencode "failpage=c.Register" \ --data-urlencode "ScreenWidth=2000" \ --data-urlencode "ScreenHeight=1200" \ --data-urlencode "formaction=1" \ --data-urlencode "formName=loginform" \ --data-urlencode "refererUrl=" # Bad credentials 302 to c.Register instead of setting accessToken — check both: grep -q 'c.Register' /tmp/sug-login-headers.txt && echo "LOGIN FAILED (bad credentials)" >&2 ACCESS_TOKEN=$(awk -F'\t' '$6=="accessToken"{print $7}' "$COOKIEJAR") CFID=$(awk -F'\t' '$6=="cfid"{print $7}' "$COOKIEJAR") CFTOKEN=$(awk -F'\t' '$6=="cftoken"{print $7}' "$COOKIEJAR") [ -z "$ACCESS_TOKEN" ] && echo "LOGIN FAILED (no accessToken cookie set)" >&2 COOKIE_HEADER="accessToken=${ACCESS_TOKEN}; cfid=${CFID}; cftoken=${CFTOKEN}" ``` This mirrors `sessionLoginFlow` exactly: GET `/login` for the CSRF token + `cfid`/`cftoken`, POST the credentials with the exact same static form fields the wizard sends, and read the `accessToken` cookie bac
_meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "signupgenius-api",
"version": "2.1.9",
"publishedAt": 1791588447201
}references/sug-endpoints.md
# SignUpGenius session-mode endpoints for curl
All calls assume `$ACCESS_TOKEN` and `$COOKIE_HEADER` from the login step in
`../SKILL.md`. Every call sends both:
```
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER"
```
Paths under `api.signupgenius.com/v3` are the exact paths `signupgenius-mcp`'s
`client.ts` builds in session mode (it appends a trailing `/` to every v3
path — included below). Legacy calls POST JSON to
`https://www.signupgenius.com/SUGboxAPI.cfm?go=<action>` with
`Content-Type: application/json`.
---
## 1. Profile
```sh
curl -s 'https://api.signupgenius.com/v3/member/profile/' \
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" | jq '.data'
```
## 2. Groups
List groups (`sort` is optional, `asc`/`desc`):
```sh
curl -s 'https://api.signupgenius.com/v3/groups/all/?sort=asc' \
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" \
| jq -r '.data[] | "\(.groupid)\t\(.title)"'
```
List a group's members (`GROUP_ID` from above):
```sh
curl -s "https://api.signupgenius.com/v3/groups/${GROUP_ID}/members/" \
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" \
| jq -r '.data[] | "\(.communitymemberid)\t\(.emailaddress)"'
```
Get one member's detail (address/phone — only present if they supplied it on
a sign-up):
```sh
curl -s "https://api.signupgenius.com/v3/groups/${GROUP_ID}/members/${MEMBER_ID}/details/" \
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" | jq '.data'
```
Add a member (**write** — confirm with the user first; `firstname`/`lastname`
are optional):
```sh
curl -s -X POST "https://api.signupgenius.com/v3/groups/${GROUP_ID}/members/create/" \
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" \
-H 'Content-Type: application/json' \
-d '{"emailaddress":"[email protected]","firstname":"Jane","lastname":"Doe"}' \
| jq '.success, .message'
```
## 3. Sign-up listings
In session mode `created`/`invited`/`signedupfor` each have **one** v3 path
each (unlike key mode's separate `/active`/`/expired`/`/all` paths) — filter
on `enddate` client-side if you only want active ones:
```sh
# everything the account created (active + expired together)
curl -s 'https://api.signupgenius.com/v3/signups/created/' \
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" \
| jq -r '.data[] | "\(.signupid)\t\(.enddate)\t\(.title)"'
# sign-ups invited to
curl -s 'https://api.signupgenius.com/v3/signups/invited/' \
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" | jq '.data'
# sign-ups personally signed up for
curl -s 'https://api.signupgenius.com/v3/signups/signedupfor/' \
-H "Authorization: Bearer $ACCESS_TOKEN" -H "Cookie: $COOKIE_HEADER" | jq '.data'
```
Legacy dispatcher equivalent — sometimes returns fuller data than v3
(note the **upper-case** envelope):
```sh
curl -s -X POST 'https://www.signupgenius.com/SUGboxAPI.cfm?go=t.getMySignups' \
-H "Authskill-card.md
## Description: Guides agents in accessing SignUpGenius sign-ups, groups, and RSVPs with shell commands using account-based authentication instead of an MCP server. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: Developers and other SignUpGenius users use this skill to retrieve sign-ups and group information or manage RSVPs and slot claims from a shell without an MCP server. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Account passwords, bearer tokens, and session cookies may be exposed through shell history, logs, or temporary files. Mitigation: Use a private machine and secure secret handling; do not log or paste authorization headers or cookies, and delete cookie jars and temporary header files after use. Risk: Public participant lookups can expose personal information. Mitigation: Only retrieve participant details for an authorized purpose and limit sharing of personal data. Risk: RSVP, slot-claim, release, and group-member actions can change account or participant records. Mitigation: Confirm the intended action and account details with the user before making changes. ## Reference(s): - [SignUpGenius API skill release](https://clawhub.ai/chrischall/skills/signupgenius-api) - [SignUpGenius session-mode endpoint reference](references/sug-endpoints.md) ## Skill Output: **Output Type(s):** [Shell commands, Guidance] **Output Format:** [Markdown with shell code blocks] **Output Parameters:** [1D] **Other Properties Related to Output:** [None] ## Skill Version(s): 2.1.9 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/signupgenius-api",
"sourceUrl": "https://clawhub.ai/chrischall/skills/signupgenius-api",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T06:14:21.077Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T06:14:21.077Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/chrischall/signupgenius-api",
"sourceUrl": "https://clawhub.ai/chrischall/signupgenius-api",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T06:14:21.077Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.1.9",
"href": "https://clawhub.ai/chrischall/signupgenius-api",
"sourceUrl": "https://clawhub.ai/chrischall/signupgenius-api",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:27:27.201Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-signupgenius-api/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.1.9",
"description": "- Clarified that RSVPs and slot claims should default to the signed-in user's name and email, as the entry is tied to the authenticated account. - Updated SKILL.md for more accurate instructions on RSVP and slot claim data. - Removed legacy skill-card.md file.",
"href": "https://clawhub.ai/chrischall/signupgenius-api",
"sourceUrl": "https://clawhub.ai/chrischall/signupgenius-api",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:27:27.201Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
