agentCLAWHUBUnverified

zola-api

Query or update Zola wedding-planning data (vendors, budget, guests, seating, events/RSVPs, registry, gift tracker, inquiries, wedding website) straight from a shell with curl against mobile-api.zola.com, instead of running the zola-mcp server. Use when you want Zola data without the MCP, in a script, or on a machine where the MCP isn't installed. Triggers on "check Zola", "Zola vendors/budget/guests/RSVP/seating/registry", or any Zola wedding data request that should hit the API directly.

OpenClaw

Rank

62

Safety

84

Downloads

1.3k

Updated

Oct 10, 2026

Version

2.1.10

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.3K downloadsadoption · observed Oct 10, 2026
Latest release
2.1.10release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:zola-api
  1. Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:zola-api` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/zola-api before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/snapshot"

Documentation

CLAWHUB

146,719 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: zola-api
description: >-
  Query or update Zola wedding-planning data (vendors, budget, guests, seating,
  events/RSVPs, registry, gift tracker, inquiries, wedding website) straight
  from a shell with curl against mobile-api.zola.com, instead of running the
  zola-mcp server. Use when you want Zola data without the MCP, in a script,
  or on a machine where the MCP isn't installed. Triggers on "check Zola",
  "Zola vendors/budget/guests/RSVP/seating/registry", or any Zola wedding
  data request that should hit the API directly.
---

# Zola mobile API via curl (no MCP)

Zola's mobile API (`mobile-api.zola.com` — the same surface the iOS/iPad app
and `zola-mcp` use) is a plain Bearer-JWT REST API reachable directly from a
server or shell — no browser bridge needed. This skill shells out to `curl`
with the JWT in an `Authorization: Bearer` header, exactly as
`zola-mcp`'s `src/client.ts` does.

## One-time setup: get the refresh token

You need Zola's long-lived (~1 year) refresh JWT — the `usr` cookie from a
signed-in `zola.com` session. Same credential `zola-mcp` uses:

```sh
# Prefer the env var zola-mcp itself reads (check its .env first):
grep -h ZOLA_REFRESH_TOKEN ~/git/zola-mcp/.env 2>/dev/null
export ZOLA_REFRESH_TOKEN='eyJhbGciOi...'   # or export directly if you have it
```

If you don't have it yet: sign into zola.com, open DevTools → Application →
Cookies → `https://www.zola.com`, copy the `usr` value. (`zola-mcp` also has a
fetchproxy fallback that reads this cookie from a signed-in browser tab — see
its README — but that's the MCP's path, not this skill's; this skill assumes
you already have the token in hand.)

## Core call pattern

Every mobile-api call needs a short-lived (30 min) **session token**, minted
from the refresh token, plus a fixed set of headers (CloudFront WAF requires
`x-zola-session-id` on every request — omit it and you get a 403).

```sh
BASE=https://mobile-api.zola.com
DEVICE_SESSION_ID=$(uuidgen | tr 'a-z' 'A-Z')   # one per "session"; reuse across calls
UA='Zola/42.5.0 (iPad; iOS 26.4; Scale/2.0)'

# 1. Mint a 30-min session token from the refresh token
SESSION_TOKEN=$(curl -sS -X POST "$BASE/v3/sessions/refresh" \
  -H 'content-type: application/json' -H 'accept: application/json' \
  -H "x-zola-platform-type: iphone_app" -H "x-zola-session-id: $DEVICE_SESSION_ID" \
  -H "user-agent: $UA" \
  -d "{\"token\":\"$ZOLA_REFRESH_TOKEN\"}" | jq -r '.data.session_token')

# 2. Every subsequent call reuses $SESSION_TOKEN until it expires (~30 min),
#    then re-run step 1. All calls carry the same 4 headers:
curl -sS -X GET "$BASE/v3/users/me/context" \
  -H "authorization: Bearer $SESSION_TOKEN" \
  -H "x-zola-platform-type: iphone_app" -H "x-zola-session-id: $DEVICE_SESSION_ID" \
  -H "user-agent: $UA" | jq '.data'
```

Wrap this in a shell function or export the 4 headers once — every recipe in
`references/mobile-api-endpoints.md` reuses `$BASE`, `$SESSION_TOKEN`,
`$DEVICE_SESSION_ID`, `$UA`. POST/PUT bodies 

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "zola-api",
  "version": "2.1.10",
  "publishedAt": 1791588409449
}

references/mobile-api-endpoints.md

# Zola mobile-api endpoints (curl + jq)

All paths are relative to `$BASE=https://mobile-api.zola.com`. Every call
carries `authorization: Bearer $SESSION_TOKEN`, `x-zola-platform-type:
iphone_app`, `x-zola-session-id: $DEVICE_SESSION_ID`, `user-agent: $UA` (see
`SKILL.md`); POST/PUT/DELETE-with-body also need `-H 'content-type:
application/json'`. `$ACCT` = `wedding_account_id`, `$REG` = `registry_id`,
`$WEDDING_ID` = `wedding_id`, all three from `GET /v3/users/me/context` (see
`SKILL.md`'s "resolve context first" section). Response envelope is `{"data": ...}`
unless noted. Paths/bodies below are transcribed from `src/tools/*.ts` —
each section names its source file.

Shorthand used below:

```sh
H=(-H "authorization: Bearer $SESSION_TOKEN" -H "x-zola-platform-type: iphone_app" \
   -H "x-zola-session-id: $DEVICE_SESSION_ID" -H "user-agent: $UA")
HJ=("${H[@]}" -H 'content-type: application/json')
```

---

## Context (`src/client.ts`)

```sh
curl -sS "${H[@]}" "$BASE/v3/users/me/context" | jq '.data'
# .data.user.id, .data.wedding_account.wedding_account_id,
# .data.wedding.{wedding_id,wedding_date,slug}, .data.registry.id
```

---

## Vendors (`src/tools/vendors.ts`)

**List booked vendors** — `POST /v3/account-vendors/booked-list` body `{}`:

```sh
curl -sS "${HJ[@]}" -X POST "$BASE/v3/account-vendors/booked-list" -d '{}' \
  | jq '.data.booked_vendors'
```

**Search vendors (typeahead)** — `POST /v3/reference-vendors/typeahead-taxonomy`:

```sh
curl -sS "${HJ[@]}" -X POST "$BASE/v3/reference-vendors/typeahead-taxonomy" \
  -d '{"query":"Acme Photography","taxonomy_key":"wedding-photographers"}' | jq '.data'
# taxonomy_key default: wedding-venues. Other keys: wedding-planners, wedding-bands-djs, ...
```

**Book a vendor** — find an unbooked slot from `booked-list` for the
`vendor_type`, then `PUT /v5/account-vendors/vendor` (note: **v5**, not v3):

```sh
curl -sS "${HJ[@]}" -X PUT "$BASE/v5/account-vendors/vendor" -d '{
  "uuid": "<slot-uuid-from-booked-list>", "id": 0, "vendor_type": "PHOTOGRAPHER",
  "booked": true, "booking_source": "BOOKED_VENDORS",
  "price_cents": 350000, "event_date": null,
  "sync_with_budget_tool_enabled": true, "facet_keys": [],
  "reference_vendor_request": {
    "id": null, "name": "Acme Photography", "email": null, "phone": null,
    "address": {"city": "Charlotte", "state_province_region": "NC"}
  }
}' | jq '.data'
```

**Update a booked vendor** — same `PUT /v5/account-vendors/vendor`, but
read-modify-write: GET `booked-list`, find by `uuid`, keep `id`/`vendor_type`,
only patch the fields you're changing (name/city/state/email/price/date
default to the current value).

**Unbook a vendor** — `POST /v3/account-vendors/vendor/unbook`:

```sh
curl -sS "${HJ[@]}" -X POST "$BASE/v3/account-vendors/vendor/unbook" \
  -d '{"uuid":"<vendor-uuid>"}'
```

---

## Budget (`src/tools/budget.ts`)

**Get budget** — `GET /v3/budgets`:

```sh
curl -sS "${H[@]}" "$BASE/v3/budgets" | jq '{
  budgeted_cents: .data.budgeted_cents, c

skill-card.md

## Description:

Guides agents in querying and updating Zola wedding-planning data directly from a shell using authenticated API requests, without the MCP server.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

Zola account holders and developers use this skill to inspect or manage wedding-planning records, including guests, budgets, events, RSVPs, registries, and websites, from a shell without an MCP server.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The long-lived Zola refresh token effectively grants account access and can leak through chats, logs, or shared terminals.

Mitigation: Keep tokens out of chats, logs, and committed files; handle them temporarily and rotate any exposed token.

Risk: Write and delete examples can change live wedding data, and incomplete update bodies can erase unrelated fields.

Mitigation: Back up or export data, confirm each production change, and read the current record before sending a complete update body.

## Reference(s):

- [Zola API endpoint recipes](references/mobile-api-endpoints.md)
- [ClawHub skill page](https://clawhub.ai/chrischall/skills/zola-api)

## Skill Output:

**Output Type(s):** [Shell commands, Guidance]

**Output Format:** [Markdown with shell command examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [API responses may contain private wedding-planning information.]

## Skill Version(s):

2.1.10 (source: ClawHub release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/zola-api",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/zola-api",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T18:15:17.713Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T18:15:17.713Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.3K downloads",
      "href": "https://clawhub.ai/chrischall/zola-api",
      "sourceUrl": "https://clawhub.ai/chrischall/zola-api",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T18:15:17.713Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.1.10",
      "href": "https://clawhub.ai/chrischall/zola-api",
      "sourceUrl": "https://clawhub.ai/chrischall/zola-api",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:26:49.449Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.1.10",
      "description": "- Removed the file skill-card.md. - No feature, functionality, or documentation changes in this release.",
      "href": "https://clawhub.ai/chrischall/zola-api",
      "sourceUrl": "https://clawhub.ai/chrischall/zola-api",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:26:49.449Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to zola-api and adjacent AI workflows.