workday-fpx
Read Workday HR data (org chart, worker profiles, tasks, pay, benefits, compensation, your app menu) from a shell with the fpx CLI (@fetchproxy/cli) instead of running the workday-mcp server — fetch any *.htmld data endpoint through your own signed-in *.myworkday.com tab (SSO/Ping/Okta/Entra already cleared). Use when you want Workday data without the MCP, in a script, or on a machine where the MCP isn't installed.
Rank
62
Safety
84
Downloads
1.4k
Updated
Oct 10, 2026
Version
1.1.8
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.4K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.1.8release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:workday-fpx- Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:workday-fpx` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/workday-fpx before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/snapshot"
Documentation
CLAWHUB
147,446 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: workday-fpx
description: >-
Read Workday HR data (org chart, worker profiles, tasks, pay, benefits,
compensation, your app menu) from a shell with the fpx CLI (@fetchproxy/cli)
instead of running the workday-mcp server — fetch any *.htmld data endpoint through your own
signed-in *.myworkday.com tab (SSO/Ping/Okta/Entra already cleared). Use
when you want Workday data without the MCP, in a script, or on a machine
where the MCP isn't installed.
---
# Workday via fpx (no MCP)
Workday employees have no personal API — the official REST/SOAP surface
needs a tenant-admin-registered OAuth client. The only usable surface is the
employee's own signed-in web session behind corporate SSO (Ping/Okta/Entra +
MFA). `fpx` routes the request through the user's already-authenticated
`*.myworkday.com` browser tab (the ContextMint Bridge extension), so a `*.htmld`
data endpoint that would otherwise bounce to the IdP returns clean JSON.
This is the same access the `workday_*` MCP tools use (a widget-tree JSON
response, parsed here with `jq` instead of `workday-mcp`'s TypeScript
parser), reached with one CLI call instead of a running server.
## One-time setup
```sh
npm install -g @fetchproxy/cli # provides `fpx`
fpx profile add workday --domain myworkday.com # apex domain (per-tenant subdomain e.g. wd5)
fpx pair -p workday # prints a pair code → approve in ContextMint Bridge
```
Requirements: the **ContextMint Bridge** extension installed (from
https://github.com/nullnet-app/contextmint-bridge/releases — Chrome: load the
chrome zip unpacked, after checking it against the `.sha256` beside it; Safari is
not available yet (it will ship inside the ContextMint app, which has no public
download link), so use Chrome for now — it is the fetchproxy browser extension
renamed, source public at https://github.com/nullnet-app/contextmint-bridge), an
open tab at `https://<host>/<tenant>` (e.g. `https://wd5.myworkday.com/acme`) with SSO
already completed, and the extension's Chrome **Site access** allowing
`myworkday.com`. Pairing persists — after the first approval every later
`fpx` call reuses it.
## Core call
Every read is a `GET` of a tenant-scoped `*.htmld` data endpoint. Send it raw
so stdout is the JSON body, ready for `jq`:
```sh
fpx get 'https://wd5.myworkday.com/acme/quickaccess/fetch.htmld?shouldFetchUpcApps=true' -p workday \
| jq '[.. | objects | select(.widget=="configuredAppsItem") | {label, taskId: .taskIid}] | unique_by(.label)'
```
Ready-to-run endpoint paths (apps list, task/data-card read, worker profile +
its ~40-task drill-in catalog, org chart, grid tables, healthcheck probe) with
`jq` projection recipes are in `references/endpoints.md`. The
full widget-tree schema and gotchas are captured in the repo at
`docs/WORKDAY-API.md` — the operations here are the same live-verified
shapes `src/client.ts` / `src/tools/*.ts` use.
## Path rules (mirror `WorkdayClient.resolvePath`)
- **SPA route_meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "workday-fpx",
"version": "1.1.8",
"publishedAt": 1791588512334
}references/endpoints.md
# Workday `*.htmld` endpoints for fpx
Ready-to-run paths for `fpx get '<url>' -p workday`. All shapes are
live-verified in the repo (`src/client.ts`, `src/tools/*.ts`,
`docs/WORKDAY-API.md`) against a production tenant on `wd5.myworkday.com`
(cards 2026-06, the manager surfaces 2026-08). Replace
`wd5.myworkday.com`/`acme` with your own `$HOST`/`$TENANT`.
Every response is a `root` envelope: page chrome (`title`, `taskId`,
`tenant`, `currentUser`, `accountTasks`, `header` export links,
**`sessionSecureToken` — SECRET, never project this**) plus a `body`.
**`body` is NOT always `cardContentSections`** — Workday serves seven page
families (data card, `grid`, form/`fieldSet`, `compositeView` worker profile,
`hierarchyNavigator` org chart, `landingPage` hub, and report prompt forms),
so a page that looks empty under a `cardContentSections` filter usually is
not. **Always pipe through one of the filters below — never bare `jq '.'`.**
---
## 1. List your apps (the discovery entry point)
```
GET https://$HOST/$TENANT/quickaccess/fetch.htmld?shouldFetchUpcApps=true
```
```sh
fpx get "https://$HOST/$TENANT/quickaccess/fetch.htmld?shouldFetchUpcApps=true" -p workday \
| jq '[.. | objects | select(.widget=="configuredAppsItem") | {label, taskId: .taskIid}] | unique_by(.label)'
```
A `widget/children` tree; leaf `configuredAppsItem` nodes carry `label` +
`taskIid`. Some apps share a generic launcher id (e.g. `2997$2151`) and open
to a near-empty page — for those, open the app in your browser and use its
page URL with endpoint 3 instead.
## 2. Task by id (constructable — no page-context token needed)
```
GET https://$HOST/$TENANT/task/<taskId>.htmld
```
`<taskId>` looks like `2998$43525` (from endpoint 1, or a prior response's
references). Returns clean JSON for any task id, but **container/launcher
tasks return a near-empty shell** (no `cardContentSections`) — rich data
needs endpoints 3+4 below.
```sh
fpx get "https://$HOST/$TENANT/task/2998\$43525.htmld" -p workday | jq '{
title: (if (.title|type)=="object" then .title.text else .title end),
fields: [.. | objects | select(.widget=="text") | {label, value}],
refs: [.. | objects | select(.widget=="moniker") | {text, instanceId}],
relatedTasks: (.accountTasks // [])
}'
```
(Escape the literal `$` in a task id before the shell expands it, as shown.)
## 3. Task hub → data card crawl (rich data)
Container tasks (Benefits and Pay, etc.) delegate to child cards through two
opaque, page-context-bound tokens you can only get by loading the parent:
```
GET https://$HOST/$TENANT/inst/<pageCtx>/cacheable-task/<taskId>.htmld # the hub
GET https://$HOST/$TENANT/card/all/<cardId>/<pageCtx>.htmld # a child card (the real content)
```
`<pageCtx>` is NOT constructable — read it off the hub response's own
references/uris (or copy the child card's URL from your open browser tab).
The `cacheable-task` token is comparatively stable across loads; the
`card/all` child token rotates. Projecskill-card.md
## Description: Guides employees in reading Workday HR data through their signed-in browser session using the fpx CLI, without a separate MCP server. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: Authorized employees and developers use this skill to retrieve Workday org charts, worker profiles, tasks, pay, benefits, compensation, and app listings through their existing signed-in session. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Access through a signed-in browser session can expose confidential HR, pay, benefits, compensation, and worker-profile data. Mitigation: Use only with organizational authorization, treat results as confidential, and redact personal and compensation fields by default. Risk: Raw Workday responses may expose a session security token and sensitive employee data. Mitigation: Project only required fields, avoid raw response logging, and never print the session security token. Risk: A paired browser bridge may retain access to the signed-in Workday session. Mitigation: Restrict extension site access and remove or unpair the bridge when it is no longer needed. ## Reference(s): - [ClawHub skill listing](https://clawhub.ai/chrischall/skills/workday-fpx) - [Workday endpoint reference](references/endpoints.md) - [ContextMint Bridge source](https://github.com/nullnet-app/contextmint-bridge) - [ContextMint Bridge releases](https://github.com/nullnet-app/contextmint-bridge/releases) ## Skill Output: **Output Type(s):** [Shell commands, Guidance] **Output Format:** [Markdown with shell and jq examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Read-only examples project selected fields from JSON responses.] ## Skill Version(s): 1.1.8 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/workday-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/skills/workday-fpx",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T12:07:06.332Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T12:07:06.332Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.4K downloads",
"href": "https://clawhub.ai/chrischall/workday-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/workday-fpx",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T12:07:06.332Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.1.8",
"href": "https://clawhub.ai/chrischall/workday-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/workday-fpx",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:28:32.334Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-workday-fpx/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.1.8",
"description": "- Removed the sample file skill-card.md. - No changes to functionality or SKILL.md documentation.",
"href": "https://clawhub.ai/chrischall/workday-fpx",
"sourceUrl": "https://clawhub.ai/chrischall/workday-fpx",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:28:32.334Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
