api-gateway
Smart proxy for external API calls with retry, caching, rate limiting, and fallback providers. Key management with masked display. Zero external dependencies.
Rank
62
Safety
84
Downloads
1.4k
Updated
Oct 10, 2026
Version
1.1.12
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.4K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.1.12release · observed Sep 13, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s175p518b8g47fx6r9zyvs95ks876t4t:api-proxy- Install using `clawhub skill install s175p518b8g47fx6r9zyvs95ks876t4t:api-proxy` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/jlacroix82/api-proxy before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-api-proxy/snapshot"
Documentation
CLAWHUB
148,162 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: api-gateway version: 1.1.12 description: Smart proxy for external API calls with retry, caching, rate limiting, and fallback providers. PERSISTS: API keys (chmod 0600 plaintext in keys.json), request/response cache metadata, and request logs. Network: outbound HTTPS only, with a strict provider-domain allowlist. Caches metadata by default; full response bodies are opt-in per provider. Cache and rate-limit keys are SHA-256 digests, so request bodies and endpoint URLs are never written to disk in plaintext. --- # API Gateway ⚡ > **Read this first.** This skill makes outbound HTTPS calls and writes plaintext API keys to disk. By installing or running it, you accept responsibility for the security of the keys you provide and the endpoints you target. **Stop duplicating API logic. Start routing through one smart gateway.** ## What This Skill Does API Gateway is a local Node.js HTTP client wrapper that gives one call: - **Retry with exponential backoff** (3 attempts, 1s/2s/4s) - **Response caching** (default 5 min TTL, metadata-only) - **Rate-limit handling** (parses `x-ratelimit-remaining`, auto-fallback) - **Circuit breaker** (5-failure open, 30s cooldown, auto-recover) - **API key management** (masked display, chmod 0600 storage, env-var override) - **Fallback providers** (configurable per-provider chain) ## ⚠️ Important Warnings ### Outbound HTTPS Requests to Whitelisted Provider Domains `--call <provider> <endpoint>` sends HTTPS requests and, for configured providers, attaches a `Authorization: Bearer <key>` header. **The provider allowlist is strict: it is a domain-match check, not a `string.includes()` check.** A URL like `https://attacker.com/api?provider=openai` will NOT receive the key because the hostname must match the provider's registered allowlist entry. Review the allowlist in `--keys` output before adding sensitive keys. ### API Keys Stored in Plaintext on Disk API keys saved via `--keys add` are written to `memory/api-gateway/keys.json` in plaintext, with file permissions set to `0600` (owner read/write only). The key is NEVER echoed back. Anyone with shell access to the workspace as the same user can still read it. For higher assurance, prefer environment variables: `OPENAI_API_KEY=sk-...` — API Gateway auto-detects any `PROVIDER_API_KEY` variable (e.g. `OPENAI_API_KEY`, `ANTHROPIC_API_KEY`) and uses it without disk storage. It does NOT read arbitrary `env:NAME` references — only the `PROVIDER_API_KEY` pattern — so unrelated secrets are never pulled in. ### Persistent Data Files (Disclosed Up Front) The following files persist in `memory/api-gateway/` after any operation: - `keys.json` — API key storage, chmod 0600 - `cache.json` — **Metadata-only by default** (status code, timestamp, response headers, response body *length*). The full response **body** is NOT stored unless you explicitly enable it per provider via `--cache-full <provider>`. **Cache keys are provider name + a SHA-256 digest of the endpoint path an
README.md
# API Gateway
Smart proxy for external API calls with retry logic, caching, circuit breaker, and rate limiting.
> ⚠️ **DATA LEAVES TO A THIRD PARTY:** every `--call` sends your request (URL, headers, body, prompts) to the provider endpoint *you* specify — a separate external service. Responses come back from that provider and may be retained by them per their own policy. This skill is NOT a transparent pass-through; it centralizes collection, storage, and forwarding of potentially sensitive data. Only call endpoints you trust. By default only request **metadata** (provider, status class, timestamp) and cache **metadata** are written to disk; the full response body is written only if you enable `--cache-full <provider>`. Cache and rate-limit entries are keyed by a SHA-256 digest of the endpoint path and request body, so neither your endpoints nor your payloads are stored on disk in readable form.
## Features
- **HTTP Proxy** — Make API calls with automatic retry and timeout handling
- **Circuit Breaker** — Automatic failure detection and cooldown (opens after 5 failures)
- **Response Caching** — Cache API responses to reduce repeated calls
- **Rate Limiting** — Per-provider rate limit tracking
- **Fallback Providers** — Configure fallback providers for redundancy
- **API Key Management** — Store, list, and remove API keys with masked output
- **Request Logging** — Track request history for debugging
## Installation
```bash
# The skill is auto-loaded by OpenClaw via the skill registry.
# For standalone use:
const AG = require('./api-gateway.js');
```
## Commands
```
--call <provider> <endpoint> [body] Make API call with retry/caching
--call --dry-run <provider> <endpoint> Preview call without executing
--keys List configured API keys (masked)
--keys add <provider> <key> Add API key
--keys remove <provider> Remove API key
--cache Show cache status
--cache --clear Clear cache
--rate <provider> Check rate limit status
--fallback <provider> <fallback> Set fallback provider
--status Gateway status overview
```
## API
### `makeRequest(url, method, headers, body, timeout)`
Make an HTTP request with automatic retry and timeout.
```javascript
const result = await AG.makeRequest('https://api.openai.com/v1/models', 'GET', {}, null, 30000);
```
### `maskKey(key)`
Mask a sensitive key for display (`sk-a****fgh`).
### Circuit Breaker
```javascript
AG.getCircuitState('openai'); // Current state (CLOSED/OPEN/HALF-OPEN)
AG.recordFailure('openai'); // Record a failure
AG.recordSuccess('openai'); // Record a success (resets counter)
AG.getCircuitStatus(); // All circuit states
AG.resetCircuit('openai'); // Reset circuit breaker
```
### Key Management
```javascript
AG.addKey('openai', 'sk-...'); // Add API key
AG.r_meta.json
{
"ownerId": "kn7b6eyf5vc7khg5fr63pjm8xd82qvw5",
"slug": "api-proxy",
"version": "1.1.12",
"publishedAt": 1789302891177
}skill-card.md
## Description: API Gateway is a local Node.js proxy for outbound API calls with retries, metadata-only caching by default, rate-limit handling, circuit breaking, fallback providers, and API key management. This skill is ready for commercial/non-commercial use. ## Publisher: [jlacroix82](https://clawhub.ai/user/jlacroix82) ### License/Terms of Use: MIT-0 ## Use Case: Developers and agents use this skill to centralize outbound HTTP API calls through a reusable gateway with retry, fallback, rate-limit, cache, request-log, and API-key handling controls. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The gateway handles provider credentials and can store API keys as plaintext in the local workspace. Mitigation: Prefer PROVIDER_API_KEY environment variables or a secrets manager, use tightly scoped allowlisted stored keys only when needed, and remove local keys after sensitive work. Risk: Requests, prompts, headers, bodies, and responses are transmitted to the third-party provider endpoint selected by the caller. Mitigation: Send requests only to trusted endpoints, review provider retention policies, and avoid routing sensitive or regulated data through untrusted providers. Risk: Full-body caching can persist complete responses that may contain secrets, personal data, or proprietary content. Mitigation: Keep the default metadata-only cache, avoid --cache-full for sensitive providers, and clear cache and log files after sensitive sessions. Risk: Plain HTTP can expose traffic when API_GATEWAY_ALLOW_HTTP=1 is enabled. Mitigation: Use HTTPS endpoints and never enable API_GATEWAY_ALLOW_HTTP=1 when credentials or sensitive payloads may be attached. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/jlacroix82/skills/api-proxy) - [README](README.md) - [Vetting report](VET-REPORT.md) ## Skill Output: **Output Type(s):** [text, shell commands, configuration, guidance] **Output Format:** [CLI text, JSON API responses, and Markdown guidance] **Output Parameters:** [1D] **Other Properties Related to Output:** [May perform outbound HTTP API calls and write local gateway state, including keys, cache metadata, request logs, rate-limit state, circuit state, and fallback mappings.] ## Skill Version(s): 1.1.12 (source: frontmatter and server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
VET-REPORT.md
# Vetting Report: api-proxy **Date:** 2026-09-13 08:11 EDT **Vetter:** JARVIS (skill-vetter skill) **Source:** local (/home/jarvis/.openclaw/workspace) **Verdict:** PASS **Risk score:** 8/100 ## Findings ### Critical - (none) ### Warnings - 2 network URLs - No description in frontmatter ### Notes - (none) ## Permission footprint - Tools requested: exec process read write ## Network footprint https://api.openai.com/v1/chat/completion https://attacker.com/api?provider=openai` will NOT receive the key becau ## Side effects - Reads: SKILL.md - Writes: VET-REPORT.md (this file) - Network: 2 distinct hosts ## Verdict rationale Score 8/100 with 0 critical findings and 2 warnings.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/jlacroix82/skills/api-proxy",
"sourceUrl": "https://clawhub.ai/jlacroix82/skills/api-proxy",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T12:24:36.329Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-api-proxy/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-api-proxy/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T12:24:36.329Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.4K downloads",
"href": "https://clawhub.ai/jlacroix82/api-proxy",
"sourceUrl": "https://clawhub.ai/jlacroix82/api-proxy",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T12:24:36.329Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.1.12",
"href": "https://clawhub.ai/jlacroix82/api-proxy",
"sourceUrl": "https://clawhub.ai/jlacroix82/api-proxy",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-13T12:34:51.177Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-api-proxy/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-api-proxy/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.1.12",
"description": "**api-proxy 1.1.12** - Cache and rate-limit keys are now SHA-256 digests; endpoint URLs and request bodies are no longer stored in plaintext. - Documentation updated to reflect improved on-disk privacy for cache and rate-limit files (see SKILL.md). - Minor refinements to external dependency listing and internal documentation for clarity. - Added VET-REPORT.md for enhanced visibility. - Removed obsolete skill-card.md.",
"href": "https://clawhub.ai/jlacroix82/api-proxy",
"sourceUrl": "https://clawhub.ai/jlacroix82/api-proxy",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-13T12:34:51.177Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
