simplepractice-fpx
Read a SimplePractice Client Portal (`<practice>.clientsecure.me`) from a shell — appointments, invoices/statements/superbills/receipts, documents to sign, announcements, practice and clinician info — with plain `curl` against its JSON:API, instead of running the simplepractice-mcp server. Sign in headlessly with an emailed magic link, or capture the session cookie from an already-signed-in browser tab with `fpx`. Use when you want Client Portal data without the MCP, in a script, or on a machine where the MCP isn't installed.
Rank
62
Safety
84
Downloads
1.1k
Updated
Oct 11, 2026
Version
1.2.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.2.6release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:simplepractice-fpx- Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:simplepractice-fpx` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/simplepractice-fpx before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplepractice-fpx/snapshot"
Documentation
CLAWHUB
146,842 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: simplepractice-fpx
description: >-
Read a SimplePractice Client Portal (`<practice>.clientsecure.me`) from a
shell — appointments, invoices/statements/superbills/receipts, documents to
sign, announcements, practice and clinician info — with plain `curl` against
its JSON:API, instead of running the simplepractice-mcp server. Sign in
headlessly with an emailed magic link, or capture the session cookie from an
already-signed-in browser tab with `fpx`. Use when you want Client Portal
data without the MCP, in a script, or on a machine where the MCP isn't
installed.
---
# SimplePractice Client Portal via curl (+ optional fpx)
The Client Portal is an Ember app whose backend is a plain **JSON:API** at
`https://<practice>.clientsecure.me/client-portal-api`. It has **no bot wall**
— every endpoint below answers ordinary server-side `curl` once you hold a
session cookie. So this skill is curl-first; `fpx` appears only as an optional
one-time way to lift the cookie out of a browser you're already signed into.
There is **no password**. Sign-in is passwordless: SimplePractice emails you
either a magic link or a 6-digit PIN, and you trade that for a session cookie.
That flow carries **no captcha** (reCAPTCHA guards only the new-client request,
waitlist and contact forms), so §1 below works headlessly with nothing but
`curl` and access to your inbox.
> This is protected health information — your own therapy/medical record.
> Treat the cookie jar as a credential: it is a full-access bearer token for
> the portal. Keep it `chmod 600`, out of git, and off shared machines.
## Your practice subdomain
Every URL is scoped to one practice. Take the host from the portal link your
provider sent you and export it once:
```sh
export SP_HOST='achievebalancetherapy.clientsecure.me' # <-- yours
export SP_API="https://$SP_HOST/client-portal-api"
export SP_JAR="$HOME/.simplepractice-cookies"
# curl creates a cookie jar world-readable (644). This one holds a live
# session for a medical record, so create it 0600 BEFORE curl ever writes it.
[ -e "$SP_JAR" ] || ( umask 077; : > "$SP_JAR" )
chmod 600 "$SP_JAR"
```
## The four headers — all of them, on every call
```sh
sp() { curl -s -b "$SP_JAR" -c "$SP_JAR" \
-H 'Api-Version: 2026-05-25' \
-H 'Application-Build-Version: 0.0.0' \
-H 'Application-Platform: web' \
-H 'Accept: application/vnd.api+json' "$@"; }
```
Omit `Application-Build-Version` and the API rejects the call with
`400 {"errors":[{"title":"Application build version is missing"}]}` — verified.
`Api-Version` is the API's own dated contract version, unrelated to any package
version; send it as-is.
## 1. Sign in with a magic link (no browser)
**a. Request the link.** One call, to your own portal address:
```sh
sp -X POST "$SP_API/sign-in-tokens" \
-H 'Content-Type: application/vnd.api+json' \
--data '{"data":{"type":"sign-in-tokens","attributes":{"email":"[email protected]","expiresIn":"15 minutes"}}}'
```
`202 Accepted` _meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "simplepractice-fpx",
"version": "1.2.6",
"publishedAt": 1791588642026
}references/requests.md
# SimplePractice Client Portal — request reference
Base: `https://<practice>.clientsecure.me/client-portal-api`
Every shape below was taken from the portal app's own published sourcemaps
(`widget-cdn.simplepractice.com/assets/*.map`, which ship full
`sourcesContent`) and then confirmed against a live signed-in portal. Nothing
here is guessed. Where a field could not be exercised on the account used for
verification, it says so.
Assumes the `sp()` helper and `$SP_API` from `SKILL.md`.
---
## 0. Two naming systems — the trap
URLs are **dashed and plural**. JSON:API `type` values are **camelCase and
plural**. They are not the same string, and one endpoint uses both:
| URL path | `.data[].type` |
|---|---|
| `/sign-in-tokens` | `signInTokens` |
| `/document-requests` | `documentRequestQuestionnaires`, `documentRequestConsentDocuments`, … |
| `/billing-items` | `invoices`, `statements`, `superbills`, `receipts`, `payments` |
| `/client-billing-overviews` | `clientBillingOverviews` |
| `/environment` (singular!) | `environments` |
So never build a `jq` filter by pluralising the path. Match on the `type`
string the response actually carries, or select positionally.
`/environment` is the one singular path in the API.
---
## 1. Auth
### 1.1 Request a magic link — `POST /sign-in-tokens`
```sh
sp -X POST "$SP_API/sign-in-tokens" \
-H 'Content-Type: application/vnd.api+json' \
--data '{"data":{"type":"sign-in-tokens","attributes":{"email":"[email protected]","expiresIn":"15 minutes"}}}'
```
`202 Accepted`:
```json
{"data":{"id":"…","type":"signInTokens","attributes":{"email":"[email protected]","expiresIn":"24 hours"}}}
```
- `expiresIn` in the **response** is the real lifetime (24 hours) whatever you
request. The portal app deliberately shows the same "24 hours" wording for an
address with no account, so that the response cannot be used to test whether
an email is registered. A `202` is therefore not proof the address exists.
- Optional `redirect` attribute: a portal-relative path to land on after
verifying (the app uses it for `payment-link/<id>`).
- **Errors.** `429` with title `Email request limit reached` or
`IP request limit reached`; `422` for a malformed address. Do not retry
either — this is the only auth path the portal has.
### 1.2 Exchange the token — `POST /sessions/token`
The emailed link is
**`https://<practice>.clientsecure.me/sign-in/token#<TOKEN>`** — `/sign-in/token`,
*not* the `sign-in/token/verify` the app's route tree implies. A second variant,
sent for the mobile app, points at the bare apex under the API namespace:
`https://clientsecure.me/client-portal-api/sign-in/token#<TOKEN>`. Either works —
take the fragment, ignore the path.
The token is the **fragment** (303–317 characters observed). A browser never
sends a fragment to the server; the app reads `location.hash` and posts it.
Fetching the link with `curl` accomplishes nothing — copy the part after `#`.
Both emails are quoted-printable, so the URL iskill-card.md
## Description: Guides an agent in reading a signed-in SimplePractice Client Portal from the shell to retrieve appointments, billing records, documents, and practice information. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: Portal users and their authorized agents use this skill to retrieve their SimplePractice appointment, billing, document, and practice information without installing a separate portal server. It covers reading data, not making payments or changing appointments. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: A live portal session cookie can grant access to sensitive health and billing records. Mitigation: Use a trusted personal machine, restrict the cookie jar to the account owner, keep it out of git and logs, and delete it when finished. Risk: Portal responses may expose protected health information in shared output or saved files. Mitigation: Avoid printing or saving health and billing responses in shared locations; review any agent output before sharing. ## Reference(s): - [SimplePractice FPX release](https://clawhub.ai/chrischall/skills/simplepractice-fpx) - [SimplePractice Client Portal request reference](references/requests.md) ## Skill Output: **Output Type(s):** [Guidance, Shell commands, Text] **Output Format:** [Markdown with shell examples and portal response summaries] **Output Parameters:** [1D] **Other Properties Related to Output:** [Read-only portal guidance; results may contain sensitive health and billing information.] ## Skill Version(s): 1.2.6 (source: server-resolved release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/simplepractice-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/skills/simplepractice-fpx",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T08:11:14.751Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplepractice-fpx/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplepractice-fpx/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T08:11:14.751Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.1K downloads",
"href": "https://clawhub.ai/chrischall/simplepractice-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/simplepractice-fpx",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T08:11:14.751Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.2.6",
"href": "https://clawhub.ai/chrischall/simplepractice-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/simplepractice-fpx",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:30:42.026Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplepractice-fpx/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplepractice-fpx/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.2.6",
"description": "- Removed the file skill-card.md. - No changes to functionality or user-facing documentation apart from removing an internal documentation file.",
"href": "https://clawhub.ai/chrischall/simplepractice-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/simplepractice-fpx",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:30:42.026Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
