simplisafe-mcp
Query and control a SimpliSafe alarm system from the shell with curl — read system state, sensors, locks, events and settings, and arm/disarm or lock/unlock. Use when the user asks about their SimpliSafe alarm, house sensors, door locks, or whether the system is armed. Requires a one-time browser login to mint a refresh token.
Rank
62
Safety
84
Downloads
1.4k
Updated
Oct 10, 2026
Version
1.3.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.4K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.3.1release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:simplisafe-mcp- Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:simplisafe-mcp` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/simplisafe-mcp before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/snapshot"
Documentation
CLAWHUB
146,649 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
--- name: simplisafe-api description: Query and control a SimpliSafe alarm system from the shell with curl — read system state, sensors, locks, events and settings, and arm/disarm or lock/unlock. Use when the user asks about their SimpliSafe alarm, house sensors, door locks, or whether the system is armed. Requires a one-time browser login to mint a refresh token. --- # SimpliSafe from the shell SimpliSafe's API is reachable **server-side** — no browser bridge, no extension, no signed-in tab. Auth is a bearer token minted from a long-lived OAuth refresh token, so everything here is plain `curl` + `jq`. Requires `curl` and `jq`. ## One-time setup SimpliSafe issues no API keys. The credential is an OAuth refresh token, minted by a browser login you do **once**: ```bash node ~/git/simplisafe-mcp/scripts/bootstrap-auth.mjs # prints an authorize URL # sign in, then copy the com.simplisafe.mobile://... URL the browser fails to open node ~/git/simplisafe-mcp/scripts/bootstrap-auth.mjs "<that URL>" ``` That writes `SIMPLISAFE_REFRESH_TOKEN` to `~/git/simplisafe-mcp/.env` (mode 0600). SimpliSafe does **not** rotate refresh tokens, so this survives indefinitely — until you sign out of all devices in the SimpliSafe app, which revokes it. To capture the code from the browser: open DevTools → Network → tick **Preserve log** *before* signing in, then find the failed navigation to `com.simplisafe.mobile://…?code=…` and copy its link address. The code is single-use and expires in ~2 minutes. ## Core pattern ```bash source ~/git/simplisafe-mcp/skills/simplisafe-api/references/ss-helpers.sh ss_api GET /api/authCheck | jq # who am I SID=$(ss_sid) # the single active system id ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=false" | jq ``` `ss_api <METHOD> <PATH> [JSON_BODY]` attaches auth, prints the body on stdout, and on a non-2xx prints to **stderr** and returns 1 — so a failure never looks like an empty result. Access tokens are cached in `$TMPDIR` (0600) and re-minted only when stale; the helpers never write to the repo's `.env`. ## Resolve first Almost every path needs a **system id (`sid`)**, and getting one takes two calls (`authCheck` → `userId`, then the subscriptions route). `ss_sid` does both, and **fails loudly if the account has more than one system** rather than guessing — pass the sid explicitly in that case. Note two routing traps: - The system version that decides `ss3/` routing is at `location.system.version`, **not** the top-level `systemVersion` (a different number entirely). - **Events and doorlock control are NOT under the `ss3/` prefix.** Everything else is. ## Reads ```bash # Is it armed? -> OFF | HOME | AWAY | HOME_COUNT | AWAY_COUNT | ALARM ss_api GET "/users/$(ss_api GET /api/authCheck | jq -r .userId)/subscriptions?activeOnly=true" \ | jq -r '.subscriptions[0].location.system.alarmState' # Anything wrong with a sensor? ss_api GET "/ss3/subscriptions/$SID
_meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "simplisafe-mcp",
"version": "1.3.1",
"publishedAt": 1791588444696
}references/recipes.md
# SimpliSafe curl + jq recipes
All examples assume:
```bash
source ~/git/simplisafe-mcp/skills/simplisafe-api/references/ss-helpers.sh
SID=$(ss_sid)
UID_=$(ss_api GET /api/authCheck | jq -r .userId)
```
Every recipe below was run against a live account.
## System
### Full system state
```bash
ss_api GET "/users/$UID_/subscriptions?activeOnly=true" \
| jq '.subscriptions[] | {
sid,
name: .location.locationName,
state: .location.system.alarmState,
alarming: .location.system.isAlarming,
offline: .location.system.isOffline,
powerOutage: .location.system.powerOutage,
conn: .location.system.connType,
version: .location.system.version
}'
```
### One-line "is the house armed?"
```bash
ss_api GET "/users/$UID_/subscriptions?activeOnly=true" \
| jq -r '.subscriptions[0].location.system | "\(.alarmState)\(if .isAlarming then " ** ALARMING **" else "" end)"'
```
### Base-station messages (firmware notices, faults)
```bash
ss_api GET "/users/$UID_/subscriptions?activeOnly=true" \
| jq -r '.subscriptions[0].location.system.messages[] | "\(.timestamp|todate) \(.text)"'
```
## Sensors
### All devices, compact
```bash
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=false" \
| jq -r '.sensors[] | "\(.type)\t\(.name)\tlowBat=\(.flags.lowBattery)\toffline=\(.flags.offline)"' \
| column -t
```
### Only devices needing attention
```bash
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=false" \
| jq '[.sensors[]
| select(.flags.offline or .flags.lowBattery or (.status.triggered // false))
| {name, type, offline: .flags.offline, lowBattery: .flags.lowBattery, triggered: .status.triggered}]'
```
### Currently-open entry sensors (type 5)
```bash
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=true" \
| jq -r '.sensors[] | select(.type==5 and .status.triggered==true) | .name'
```
`forceUpdate=true` is warranted here — an open/closed reading is only meaningful
if it is fresh.
### Device type ids
| id | device | | id | device |
| --- | --- | --- | --- | --- |
| 0 | remote | | 13 | siren |
| 1 | keypad | | 14 | smoke + CO |
| 2 | keychain | | 15 | doorbell |
| 3 | panic button | | 16 | **lock** |
| 4 | motion | | 17 | outdoor camera |
| 5 | **entry** | | 20 | motion v2 |
| 6 | glass break | | 22 | outdoor bell box |
| 7 | carbon monoxide | | 253 | lock keypad |
| 8 | smoke | | | |
| 9 | leak | | 21, 23, 24 | seen live, **not in any public enum** |
| 10 | temperature | | | |
| 12 | camera | | | |
Type 24 carries `smokeTriggered` / `coTriggered` / `tamper` / `endOfLife`.
## Locks
### Lock roster with decoded state
`lockState` **1 = locked, 2 = unlocked**; `lockJamState` overrides both.
```bash
ss_api GET "/ss3/subscriptions/$SID/sensors?forceUpdate=false" \
| jq -r '.sensors[] | select(.type==16) |
"\(.name)\t\(if .status.lockJamState==1 then "JAMMED"
elif .status.lockState==1 then "locked"
else "unloskill-card.md
## Description: Helps agents check SimpliSafe alarm, sensor, lock, and event status and issue alarm or lock commands through the shell. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: SimpliSafe account holders and their agents can inspect home security status and, with explicit authorization, arm or disarm the alarm and control door locks. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Authenticated commands can disarm the alarm or unlock doors without an enforced confirmation step. Mitigation: Require explicit human confirmation before every arm, disarm, lock, or unlock action; prefer a version that enforces write confirmation and restricts allowed actions. Risk: A long-lived refresh token can grant ongoing account access if exposed in logs, shell history, or shared files. Mitigation: Keep the token private and avoid exposing credentials in logs, shell history, or shared files. Risk: The settings response can contain cleartext alarm PINs, and lock status can be stale after a write. Mitigation: Request PINs only with explicit consent; exclude them from routine settings output and refresh lock status before reporting a change as complete. ## Reference(s): - [ClawHub skill release](https://clawhub.ai/chrischall/skills/simplisafe-mcp) - [SimpliSafe command recipes](references/recipes.md) - [SimpliSafe shell helpers](references/ss-helpers.sh) ## Skill Output: **Output Type(s):** [Shell commands, Guidance, Configuration instructions] **Output Format:** [Markdown with shell commands and JSON-query examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Requires an authenticated SimpliSafe account, curl, and jq.] ## Skill Version(s): 1.3.1 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/simplisafe-mcp",
"sourceUrl": "https://clawhub.ai/chrischall/skills/simplisafe-mcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T12:03:05.666Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T12:03:05.666Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.4K downloads",
"href": "https://clawhub.ai/chrischall/simplisafe-mcp",
"sourceUrl": "https://clawhub.ai/chrischall/simplisafe-mcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T12:03:05.666Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.3.1",
"href": "https://clawhub.ai/chrischall/simplisafe-mcp",
"sourceUrl": "https://clawhub.ai/chrischall/simplisafe-mcp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:27:24.696Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-simplisafe-mcp/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.3.1",
"description": "- Removed the file skill-card.md. - No changes were made to core functionality or usage documentation. - This update affects only project documentation.",
"href": "https://clawhub.ai/chrischall/simplisafe-mcp",
"sourceUrl": "https://clawhub.ai/chrischall/simplisafe-mcp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:27:24.696Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
