agentCLAWHUBUnverified

workday-fpx

Read Workday HR data (org chart, worker profiles, tasks, pay, benefits, compensation, your app menu) from a shell with the fpx CLI (@fetchproxy/cli) instead of running the workday-mcp server — fetch any *.htmld data endpoint through your own signed-in *.myworkday.com tab (SSO/Ping/Okta/Entra already cleared). Use when you want Workday data without the MCP, in a script, or on a machine where the MCP isn't installed.

OpenClaw

Rank

62

Safety

84

Downloads

1.4k

Updated

Oct 10, 2026

Version

1.1.8

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.4K downloadsadoption · observed Oct 10, 2026
Latest release
1.1.8release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:workday-fpx
  1. Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:workday-fpx` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/workday-fpx before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/snapshot"

Documentation

CLAWHUB

147,446 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: workday-fpx
description: >-
  Read Workday HR data (org chart, worker profiles, tasks, pay, benefits,
  compensation, your app menu) from a shell with the fpx CLI (@fetchproxy/cli)
  instead of running the workday-mcp server — fetch any *.htmld data endpoint through your own
  signed-in *.myworkday.com tab (SSO/Ping/Okta/Entra already cleared). Use
  when you want Workday data without the MCP, in a script, or on a machine
  where the MCP isn't installed.
---

# Workday via fpx (no MCP)

Workday employees have no personal API — the official REST/SOAP surface
needs a tenant-admin-registered OAuth client. The only usable surface is the
employee's own signed-in web session behind corporate SSO (Ping/Okta/Entra +
MFA). `fpx` routes the request through the user's already-authenticated
`*.myworkday.com` browser tab (the ContextMint Bridge extension), so a `*.htmld`
data endpoint that would otherwise bounce to the IdP returns clean JSON.

This is the same access the `workday_*` MCP tools use (a widget-tree JSON
response, parsed here with `jq` instead of `workday-mcp`'s TypeScript
parser), reached with one CLI call instead of a running server.

## One-time setup

```sh
npm install -g @fetchproxy/cli                # provides `fpx`
fpx profile add workday --domain myworkday.com # apex domain (per-tenant subdomain e.g. wd5)
fpx pair -p workday                            # prints a pair code → approve in ContextMint Bridge
```

Requirements: the **ContextMint Bridge** extension installed (from
https://github.com/nullnet-app/contextmint-bridge/releases — Chrome: load the
chrome zip unpacked, after checking it against the `.sha256` beside it; Safari is
not available yet (it will ship inside the ContextMint app, which has no public
download link), so use Chrome for now — it is the fetchproxy browser extension
renamed, source public at https://github.com/nullnet-app/contextmint-bridge), an
open tab at `https://<host>/<tenant>` (e.g. `https://wd5.myworkday.com/acme`) with SSO
already completed, and the extension's Chrome **Site access** allowing
`myworkday.com`. Pairing persists — after the first approval every later
`fpx` call reuses it.

## Core call

Every read is a `GET` of a tenant-scoped `*.htmld` data endpoint. Send it raw
so stdout is the JSON body, ready for `jq`:

```sh
fpx get 'https://wd5.myworkday.com/acme/quickaccess/fetch.htmld?shouldFetchUpcApps=true' -p workday \
  | jq '[.. | objects | select(.widget=="configuredAppsItem") | {label, taskId: .taskIid}] | unique_by(.label)'
```

Ready-to-run endpoint paths (apps list, task/data-card read, worker profile +
its ~40-task drill-in catalog, org chart, grid tables, healthcheck probe) with
`jq` projection recipes are in `references/endpoints.md`. The
full widget-tree schema and gotchas are captured in the repo at
`docs/WORKDAY-API.md` — the operations here are the same live-verified
shapes `src/client.ts` / `src/tools/*.ts` use.

## Path rules (mirror `WorkdayClient.resolvePath`)

- **SPA route

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "workday-fpx",
  "version": "1.1.8",
  "publishedAt": 1791588512334
}

references/endpoints.md

# Workday `*.htmld` endpoints for fpx

Ready-to-run paths for `fpx get '<url>' -p workday`. All shapes are
live-verified in the repo (`src/client.ts`, `src/tools/*.ts`,
`docs/WORKDAY-API.md`) against a production tenant on `wd5.myworkday.com`
(cards 2026-06, the manager surfaces 2026-08). Replace
`wd5.myworkday.com`/`acme` with your own `$HOST`/`$TENANT`.

Every response is a `root` envelope: page chrome (`title`, `taskId`,
`tenant`, `currentUser`, `accountTasks`, `header` export links,
**`sessionSecureToken` — SECRET, never project this**) plus a `body`.
**`body` is NOT always `cardContentSections`** — Workday serves seven page
families (data card, `grid`, form/`fieldSet`, `compositeView` worker profile,
`hierarchyNavigator` org chart, `landingPage` hub, and report prompt forms),
so a page that looks empty under a `cardContentSections` filter usually is
not. **Always pipe through one of the filters below — never bare `jq '.'`.**

---

## 1. List your apps (the discovery entry point)

```
GET https://$HOST/$TENANT/quickaccess/fetch.htmld?shouldFetchUpcApps=true
```

```sh
fpx get "https://$HOST/$TENANT/quickaccess/fetch.htmld?shouldFetchUpcApps=true" -p workday \
  | jq '[.. | objects | select(.widget=="configuredAppsItem") | {label, taskId: .taskIid}] | unique_by(.label)'
```

A `widget/children` tree; leaf `configuredAppsItem` nodes carry `label` +
`taskIid`. Some apps share a generic launcher id (e.g. `2997$2151`) and open
to a near-empty page — for those, open the app in your browser and use its
page URL with endpoint 3 instead.

## 2. Task by id (constructable — no page-context token needed)

```
GET https://$HOST/$TENANT/task/<taskId>.htmld
```

`<taskId>` looks like `2998$43525` (from endpoint 1, or a prior response's
references). Returns clean JSON for any task id, but **container/launcher
tasks return a near-empty shell** (no `cardContentSections`) — rich data
needs endpoints 3+4 below.

```sh
fpx get "https://$HOST/$TENANT/task/2998\$43525.htmld" -p workday | jq '{
  title: (if (.title|type)=="object" then .title.text else .title end),
  fields: [.. | objects | select(.widget=="text") | {label, value}],
  refs:   [.. | objects | select(.widget=="moniker") | {text, instanceId}],
  relatedTasks: (.accountTasks // [])
}'
```

(Escape the literal `$` in a task id before the shell expands it, as shown.)

## 3. Task hub → data card crawl (rich data)

Container tasks (Benefits and Pay, etc.) delegate to child cards through two
opaque, page-context-bound tokens you can only get by loading the parent:

```
GET https://$HOST/$TENANT/inst/<pageCtx>/cacheable-task/<taskId>.htmld   # the hub
GET https://$HOST/$TENANT/card/all/<cardId>/<pageCtx>.htmld              # a child card (the real content)
```

`<pageCtx>` is NOT constructable — read it off the hub response's own
references/uris (or copy the child card's URL from your open browser tab).
The `cacheable-task` token is comparatively stable across loads; the
`card/all` child token rotates. Projec

skill-card.md

## Description:

Guides employees in reading Workday HR data through their signed-in browser session using the fpx CLI, without a separate MCP server.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

Authorized employees and developers use this skill to retrieve Workday org charts, worker profiles, tasks, pay, benefits, compensation, and app listings through their existing signed-in session.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Access through a signed-in browser session can expose confidential HR, pay, benefits, compensation, and worker-profile data.

Mitigation: Use only with organizational authorization, treat results as confidential, and redact personal and compensation fields by default.

Risk: Raw Workday responses may expose a session security token and sensitive employee data.

Mitigation: Project only required fields, avoid raw response logging, and never print the session security token.

Risk: A paired browser bridge may retain access to the signed-in Workday session.

Mitigation: Restrict extension site access and remove or unpair the bridge when it is no longer needed.

## Reference(s):

- [ClawHub skill listing](https://clawhub.ai/chrischall/skills/workday-fpx)
- [Workday endpoint reference](references/endpoints.md)
- [ContextMint Bridge source](https://github.com/nullnet-app/contextmint-bridge)
- [ContextMint Bridge releases](https://github.com/nullnet-app/contextmint-bridge/releases)

## Skill Output:

**Output Type(s):** [Shell commands, Guidance]

**Output Format:** [Markdown with shell and jq examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Read-only examples project selected fields from JSON responses.]

## Skill Version(s):

1.1.8 (source: ClawHub release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 19h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/workday-fpx",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/workday-fpx",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T12:07:06.332Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T12:07:06.332Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.4K downloads",
      "href": "https://clawhub.ai/chrischall/workday-fpx",
      "sourceUrl": "https://clawhub.ai/chrischall/workday-fpx",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T12:07:06.332Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.1.8",
      "href": "https://clawhub.ai/chrischall/workday-fpx",
      "sourceUrl": "https://clawhub.ai/chrischall/workday-fpx",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:28:32.334Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.1.8",
      "description": "- Removed the sample file skill-card.md. - No changes to functionality or SKILL.md documentation.",
      "href": "https://clawhub.ai/chrischall/workday-fpx",
      "sourceUrl": "https://clawhub.ai/chrischall/workday-fpx",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:28:32.334Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to workday-fpx and adjacent AI workflows.