zola-api
Query or update Zola wedding-planning data (vendors, budget, guests, seating, events/RSVPs, registry, gift tracker, inquiries, wedding website) straight from a shell with curl against mobile-api.zola.com, instead of running the zola-mcp server. Use when you want Zola data without the MCP, in a script, or on a machine where the MCP isn't installed. Triggers on "check Zola", "Zola vendors/budget/guests/RSVP/seating/registry", or any Zola wedding data request that should hit the API directly.
Rank
62
Safety
84
Downloads
1.3k
Updated
Oct 10, 2026
Version
2.1.10
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.3K downloadsadoption · observed Oct 10, 2026
- Latest release
- 2.1.10release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:zola-api- Install using `clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:zola-api` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/chrischall/zola-api before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/snapshot"
Documentation
CLAWHUB
146,719 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: zola-api
description: >-
Query or update Zola wedding-planning data (vendors, budget, guests, seating,
events/RSVPs, registry, gift tracker, inquiries, wedding website) straight
from a shell with curl against mobile-api.zola.com, instead of running the
zola-mcp server. Use when you want Zola data without the MCP, in a script,
or on a machine where the MCP isn't installed. Triggers on "check Zola",
"Zola vendors/budget/guests/RSVP/seating/registry", or any Zola wedding
data request that should hit the API directly.
---
# Zola mobile API via curl (no MCP)
Zola's mobile API (`mobile-api.zola.com` — the same surface the iOS/iPad app
and `zola-mcp` use) is a plain Bearer-JWT REST API reachable directly from a
server or shell — no browser bridge needed. This skill shells out to `curl`
with the JWT in an `Authorization: Bearer` header, exactly as
`zola-mcp`'s `src/client.ts` does.
## One-time setup: get the refresh token
You need Zola's long-lived (~1 year) refresh JWT — the `usr` cookie from a
signed-in `zola.com` session. Same credential `zola-mcp` uses:
```sh
# Prefer the env var zola-mcp itself reads (check its .env first):
grep -h ZOLA_REFRESH_TOKEN ~/git/zola-mcp/.env 2>/dev/null
export ZOLA_REFRESH_TOKEN='eyJhbGciOi...' # or export directly if you have it
```
If you don't have it yet: sign into zola.com, open DevTools → Application →
Cookies → `https://www.zola.com`, copy the `usr` value. (`zola-mcp` also has a
fetchproxy fallback that reads this cookie from a signed-in browser tab — see
its README — but that's the MCP's path, not this skill's; this skill assumes
you already have the token in hand.)
## Core call pattern
Every mobile-api call needs a short-lived (30 min) **session token**, minted
from the refresh token, plus a fixed set of headers (CloudFront WAF requires
`x-zola-session-id` on every request — omit it and you get a 403).
```sh
BASE=https://mobile-api.zola.com
DEVICE_SESSION_ID=$(uuidgen | tr 'a-z' 'A-Z') # one per "session"; reuse across calls
UA='Zola/42.5.0 (iPad; iOS 26.4; Scale/2.0)'
# 1. Mint a 30-min session token from the refresh token
SESSION_TOKEN=$(curl -sS -X POST "$BASE/v3/sessions/refresh" \
-H 'content-type: application/json' -H 'accept: application/json' \
-H "x-zola-platform-type: iphone_app" -H "x-zola-session-id: $DEVICE_SESSION_ID" \
-H "user-agent: $UA" \
-d "{\"token\":\"$ZOLA_REFRESH_TOKEN\"}" | jq -r '.data.session_token')
# 2. Every subsequent call reuses $SESSION_TOKEN until it expires (~30 min),
# then re-run step 1. All calls carry the same 4 headers:
curl -sS -X GET "$BASE/v3/users/me/context" \
-H "authorization: Bearer $SESSION_TOKEN" \
-H "x-zola-platform-type: iphone_app" -H "x-zola-session-id: $DEVICE_SESSION_ID" \
-H "user-agent: $UA" | jq '.data'
```
Wrap this in a shell function or export the 4 headers once — every recipe in
`references/mobile-api-endpoints.md` reuses `$BASE`, `$SESSION_TOKEN`,
`$DEVICE_SESSION_ID`, `$UA`. POST/PUT bodies _meta.json
{
"ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
"slug": "zola-api",
"version": "2.1.10",
"publishedAt": 1791588409449
}references/mobile-api-endpoints.md
# Zola mobile-api endpoints (curl + jq)
All paths are relative to `$BASE=https://mobile-api.zola.com`. Every call
carries `authorization: Bearer $SESSION_TOKEN`, `x-zola-platform-type:
iphone_app`, `x-zola-session-id: $DEVICE_SESSION_ID`, `user-agent: $UA` (see
`SKILL.md`); POST/PUT/DELETE-with-body also need `-H 'content-type:
application/json'`. `$ACCT` = `wedding_account_id`, `$REG` = `registry_id`,
`$WEDDING_ID` = `wedding_id`, all three from `GET /v3/users/me/context` (see
`SKILL.md`'s "resolve context first" section). Response envelope is `{"data": ...}`
unless noted. Paths/bodies below are transcribed from `src/tools/*.ts` —
each section names its source file.
Shorthand used below:
```sh
H=(-H "authorization: Bearer $SESSION_TOKEN" -H "x-zola-platform-type: iphone_app" \
-H "x-zola-session-id: $DEVICE_SESSION_ID" -H "user-agent: $UA")
HJ=("${H[@]}" -H 'content-type: application/json')
```
---
## Context (`src/client.ts`)
```sh
curl -sS "${H[@]}" "$BASE/v3/users/me/context" | jq '.data'
# .data.user.id, .data.wedding_account.wedding_account_id,
# .data.wedding.{wedding_id,wedding_date,slug}, .data.registry.id
```
---
## Vendors (`src/tools/vendors.ts`)
**List booked vendors** — `POST /v3/account-vendors/booked-list` body `{}`:
```sh
curl -sS "${HJ[@]}" -X POST "$BASE/v3/account-vendors/booked-list" -d '{}' \
| jq '.data.booked_vendors'
```
**Search vendors (typeahead)** — `POST /v3/reference-vendors/typeahead-taxonomy`:
```sh
curl -sS "${HJ[@]}" -X POST "$BASE/v3/reference-vendors/typeahead-taxonomy" \
-d '{"query":"Acme Photography","taxonomy_key":"wedding-photographers"}' | jq '.data'
# taxonomy_key default: wedding-venues. Other keys: wedding-planners, wedding-bands-djs, ...
```
**Book a vendor** — find an unbooked slot from `booked-list` for the
`vendor_type`, then `PUT /v5/account-vendors/vendor` (note: **v5**, not v3):
```sh
curl -sS "${HJ[@]}" -X PUT "$BASE/v5/account-vendors/vendor" -d '{
"uuid": "<slot-uuid-from-booked-list>", "id": 0, "vendor_type": "PHOTOGRAPHER",
"booked": true, "booking_source": "BOOKED_VENDORS",
"price_cents": 350000, "event_date": null,
"sync_with_budget_tool_enabled": true, "facet_keys": [],
"reference_vendor_request": {
"id": null, "name": "Acme Photography", "email": null, "phone": null,
"address": {"city": "Charlotte", "state_province_region": "NC"}
}
}' | jq '.data'
```
**Update a booked vendor** — same `PUT /v5/account-vendors/vendor`, but
read-modify-write: GET `booked-list`, find by `uuid`, keep `id`/`vendor_type`,
only patch the fields you're changing (name/city/state/email/price/date
default to the current value).
**Unbook a vendor** — `POST /v3/account-vendors/vendor/unbook`:
```sh
curl -sS "${HJ[@]}" -X POST "$BASE/v3/account-vendors/vendor/unbook" \
-d '{"uuid":"<vendor-uuid>"}'
```
---
## Budget (`src/tools/budget.ts`)
**Get budget** — `GET /v3/budgets`:
```sh
curl -sS "${H[@]}" "$BASE/v3/budgets" | jq '{
budgeted_cents: .data.budgeted_cents, cskill-card.md
## Description: Guides agents in querying and updating Zola wedding-planning data directly from a shell using authenticated API requests, without the MCP server. This skill is ready for commercial/non-commercial use. ## Publisher: [chrischall](https://clawhub.ai/user/chrischall) ### License/Terms of Use: MIT-0 ## Use Case: Zola account holders and developers use this skill to inspect or manage wedding-planning records, including guests, budgets, events, RSVPs, registries, and websites, from a shell without an MCP server. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The long-lived Zola refresh token effectively grants account access and can leak through chats, logs, or shared terminals. Mitigation: Keep tokens out of chats, logs, and committed files; handle them temporarily and rotate any exposed token. Risk: Write and delete examples can change live wedding data, and incomplete update bodies can erase unrelated fields. Mitigation: Back up or export data, confirm each production change, and read the current record before sending a complete update body. ## Reference(s): - [Zola API endpoint recipes](references/mobile-api-endpoints.md) - [ClawHub skill page](https://clawhub.ai/chrischall/skills/zola-api) ## Skill Output: **Output Type(s):** [Shell commands, Guidance] **Output Format:** [Markdown with shell command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [API responses may contain private wedding-planning information.] ## Skill Version(s): 2.1.10 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chrischall/skills/zola-api",
"sourceUrl": "https://clawhub.ai/chrischall/skills/zola-api",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T18:15:17.713Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T18:15:17.713Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/chrischall/zola-api",
"sourceUrl": "https://clawhub.ai/chrischall/zola-api",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T18:15:17.713Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.1.10",
"href": "https://clawhub.ai/chrischall/zola-api",
"sourceUrl": "https://clawhub.ai/chrischall/zola-api",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:26:49.449Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-zola-api/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.1.10",
"description": "- Removed the file skill-card.md. - No feature, functionality, or documentation changes in this release.",
"href": "https://clawhub.ai/chrischall/zola-api",
"sourceUrl": "https://clawhub.ai/chrischall/zola-api",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T23:26:49.449Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
