agentCLAWHUBUnverified

simplisafe-mcp

Query and control a SimpliSafe alarm system from the shell with curl — read system state, sensors, locks, events and settings, and arm/disarm or lock/unlock. Use when the user asks about their SimpliSafe alarm, house sensors, door locks, or whether the system is armed. Requires a one-time browser login to mint a refresh token.

OpenClaw

Rank

62

Safety

84

Downloads

1.4k

Updated

Oct 10, 2026

Version

1.3.1

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.4K downloadsadoption · observed Oct 10, 2026
Latest release
1.3.1release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:simplisafe-mcp
  1. Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:simplisafe-mcp` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/simplisafe-mcp before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/snapshot"

Documentation

CLAWHUB

146,649 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: simplisafe-api
description: Query and control a SimpliSafe alarm system from the shell with curl — read system state, sensors, locks, events and settings, and arm/disarm or lock/unlock. Use when the user asks about their SimpliSafe alarm, house sensors, door locks, or whether the system is armed. Requires a one-time browser login to mint a refresh token.
---

# SimpliSafe from the shell

SimpliSafe's API is reachable **server-side** — no browser bridge, no extension,
no signed-in tab. Auth is a bearer token minted from a long-lived OAuth refresh
token, so everything here is plain `curl` + `jq`.

Requires `curl` and `jq`.

## One-time setup

SimpliSafe issues no API keys. The credential is an OAuth refresh token, minted
by a browser login you do **once**:

```bash
node ~/git/simplisafe-mcp/scripts/bootstrap-auth.mjs           # prints an authorize URL
# sign in, then copy the com.simplisafe.mobile://... URL the browser fails to open
node ~/git/simplisafe-mcp/scripts/bootstrap-auth.mjs "<that URL>"
```

That writes `SIMPLISAFE_REFRESH_TOKEN` to `~/git/simplisafe-mcp/.env` (mode 0600).
SimpliSafe does **not** rotate refresh tokens, so this survives indefinitely —
until you sign out of all devices in the SimpliSafe app, which revokes it.

To capture the code from the browser: open DevTools → Network → tick **Preserve
log** *before* signing in, then find the failed navigation to
`com.simplisafe.mobile://…?code=…` and copy its link address. The code is
single-use and expires in ~2 minutes.

## Core pattern

```bash
source ~/git/simplisafe-mcp/skills/simplisafe-api/references/ss-helpers.sh

ss_api GET /api/authCheck | jq            # who am I
SID=$(ss_sid)                             # the single active system id
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=false" | jq
```

`ss_api <METHOD> <PATH> [JSON_BODY]` attaches auth, prints the body on stdout,
and on a non-2xx prints to **stderr** and returns 1 — so a failure never looks
like an empty result. Access tokens are cached in `$TMPDIR` (0600) and re-minted
only when stale; the helpers never write to the repo's `.env`.

## Resolve first

Almost every path needs a **system id (`sid`)**, and getting one takes two calls
(`authCheck` → `userId`, then the subscriptions route). `ss_sid` does both, and
**fails loudly if the account has more than one system** rather than guessing —
pass the sid explicitly in that case.

Note two routing traps:

- The system version that decides `ss3/` routing is at
  `location.system.version`, **not** the top-level `systemVersion` (a different
  number entirely).
- **Events and doorlock control are NOT under the `ss3/` prefix.** Everything
  else is.

## Reads

```bash
# Is it armed? -> OFF | HOME | AWAY | HOME_COUNT | AWAY_COUNT | ALARM
ss_api GET "/users/$(ss_api GET /api/authCheck | jq -r .userId)/subscriptions?activeOnly=true" \
  | jq -r '.subscriptions[0].location.system.alarmState'

# Anything wrong with a sensor?
ss_api GET "/ss3/subscriptions/$SID

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "simplisafe-mcp",
  "version": "1.3.1",
  "publishedAt": 1791588444696
}

references/recipes.md

# SimpliSafe curl + jq recipes

All examples assume:

```bash
source ~/git/simplisafe-mcp/skills/simplisafe-api/references/ss-helpers.sh
SID=$(ss_sid)
UID_=$(ss_api GET /api/authCheck | jq -r .userId)
```

Every recipe below was run against a live account.

## System

### Full system state

```bash
ss_api GET "/users/$UID_/subscriptions?activeOnly=true" \
  | jq '.subscriptions[] | {
      sid,
      name: .location.locationName,
      state: .location.system.alarmState,
      alarming: .location.system.isAlarming,
      offline: .location.system.isOffline,
      powerOutage: .location.system.powerOutage,
      conn: .location.system.connType,
      version: .location.system.version
    }'
```

### One-line "is the house armed?"

```bash
ss_api GET "/users/$UID_/subscriptions?activeOnly=true" \
  | jq -r '.subscriptions[0].location.system | "\(.alarmState)\(if .isAlarming then "  ** ALARMING **" else "" end)"'
```

### Base-station messages (firmware notices, faults)

```bash
ss_api GET "/users/$UID_/subscriptions?activeOnly=true" \
  | jq -r '.subscriptions[0].location.system.messages[] | "\(.timestamp|todate)  \(.text)"'
```

## Sensors

### All devices, compact

```bash
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=false" \
  | jq -r '.sensors[] | "\(.type)\t\(.name)\tlowBat=\(.flags.lowBattery)\toffline=\(.flags.offline)"' \
  | column -t
```

### Only devices needing attention

```bash
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=false" \
  | jq '[.sensors[]
         | select(.flags.offline or .flags.lowBattery or (.status.triggered // false))
         | {name, type, offline: .flags.offline, lowBattery: .flags.lowBattery, triggered: .status.triggered}]'
```

### Currently-open entry sensors (type 5)

```bash
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=true" \
  | jq -r '.sensors[] | select(.type==5 and .status.triggered==true) | .name'
```

`forceUpdate=true` is warranted here — an open/closed reading is only meaningful
if it is fresh.

### Device type ids

| id | device | | id | device |
| --- | --- | --- | --- | --- |
| 0 | remote | | 13 | siren |
| 1 | keypad | | 14 | smoke + CO |
| 2 | keychain | | 15 | doorbell |
| 3 | panic button | | 16 | **lock** |
| 4 | motion | | 17 | outdoor camera |
| 5 | **entry** | | 20 | motion v2 |
| 6 | glass break | | 22 | outdoor bell box |
| 7 | carbon monoxide | | 253 | lock keypad |
| 8 | smoke | | | |
| 9 | leak | | 21, 23, 24 | seen live, **not in any public enum** |
| 10 | temperature | | | |
| 12 | camera | | | |

Type 24 carries `smokeTriggered` / `coTriggered` / `tamper` / `endOfLife`.

## Locks

### Lock roster with decoded state

`lockState` **1 = locked, 2 = unlocked**; `lockJamState` overrides both.

```bash
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=false" \
  | jq -r '.sensors[] | select(.type==16) |
      "\(.name)\t\(if .status.lockJamState==1 then "JAMMED"
                   elif .status.lockState==1 then "locked"
                   else "unlo

skill-card.md

## Description:

Helps agents check SimpliSafe alarm, sensor, lock, and event status and issue alarm or lock commands through the shell.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

SimpliSafe account holders and their agents can inspect home security status and, with explicit authorization, arm or disarm the alarm and control door locks.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Authenticated commands can disarm the alarm or unlock doors without an enforced confirmation step.

Mitigation: Require explicit human confirmation before every arm, disarm, lock, or unlock action; prefer a version that enforces write confirmation and restricts allowed actions.

Risk: A long-lived refresh token can grant ongoing account access if exposed in logs, shell history, or shared files.

Mitigation: Keep the token private and avoid exposing credentials in logs, shell history, or shared files.

Risk: The settings response can contain cleartext alarm PINs, and lock status can be stale after a write.

Mitigation: Request PINs only with explicit consent; exclude them from routine settings output and refresh lock status before reporting a change as complete.

## Reference(s):

- [ClawHub skill release](https://clawhub.ai/chrischall/skills/simplisafe-mcp)
- [SimpliSafe command recipes](references/recipes.md)
- [SimpliSafe shell helpers](references/ss-helpers.sh)

## Skill Output:

**Output Type(s):** [Shell commands, Guidance, Configuration instructions]

**Output Format:** [Markdown with shell commands and JSON-query examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Requires an authenticated SimpliSafe account, curl, and jq.]

## Skill Version(s):

1.3.1 (source: ClawHub release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 19h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/simplisafe-mcp",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/simplisafe-mcp",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T12:03:05.666Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T12:03:05.666Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.4K downloads",
      "href": "https://clawhub.ai/chrischall/simplisafe-mcp",
      "sourceUrl": "https://clawhub.ai/chrischall/simplisafe-mcp",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T12:03:05.666Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.3.1",
      "href": "https://clawhub.ai/chrischall/simplisafe-mcp",
      "sourceUrl": "https://clawhub.ai/chrischall/simplisafe-mcp",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:27:24.696Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.3.1",
      "description": "- Removed the file skill-card.md. - No changes were made to core functionality or usage documentation. - This update affects only project documentation.",
      "href": "https://clawhub.ai/chrischall/simplisafe-mcp",
      "sourceUrl": "https://clawhub.ai/chrischall/simplisafe-mcp",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:27:24.696Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to simplisafe-mcp and adjacent AI workflows.