TapAuth
OAuth token provider for OpenClaw agents — Google Calendar, Gmail, GitHub, Slack, Linear, Notion, Vercel, Sentry, Asana, Discord, or Apify — plus user-entere... Skill: TapAuth Owner: schwartzdev Summary: OAuth token provider for OpenClaw agents — Google Calendar, Gmail, GitHub, Slack, Linear, Notion, Vercel, Sentry, Asana, Discord, or Apify — plus user-entere... Tags: latest:1.0.6 Version history: v1.0.6 | 2026-06-23T20:30:27.111Z | user Grant polling and OpenClaw reload guidance v1.0.5 | 2026-06-04T05:29:42.219Z | user Canonical CLI sync and drift checks v1.0.4 | 2026-06-04
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 9, 2026
Version
1.0.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 1.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.0.6release · observed Jun 23, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171pfd56y4q14h879xmfz6ny983egve:tapauth- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-schwartzdev-tapauth/snapshot"
Documentation
CLAWHUB
150,380 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: tapauth
description: >-
OAuth token provider for OpenClaw agents — Google Calendar, Gmail, GitHub, Slack, Linear, Notion,
Vercel, Sentry, Asana, Discord, or Apify — plus user-entered passwords/API keys through the
manual `secret` provider. Integrates with OpenClaw's exec secrets provider so values are resolved
at startup and held in memory — no shell commands or inline credentials needed at runtime.
Configure once in openclaw.json, reference tokens/secrets via SecretRef.
license: MIT
compatibility: Requires curl and bash. Designed for OpenClaw's exec secrets provider.
metadata:
author: tapauth
version: "1.0"
website: https://tapauth.ai
docs: https://tapauth.ai/docs
---
# TapAuth — OAuth Tokens and Manual Secrets via OpenClaw Secrets Manager
TapAuth provides OAuth tokens and user-approved manual secrets through OpenClaw's exec secrets provider. Values are resolved at gateway startup and held in memory — they never appear in shell commands or config files as plaintext.
**You must NEVER use `tapauth.sh --token` directly in shell commands, curl calls, or `$(...)` substitutions.** Tokens are always resolved through the secrets manager. Your job as an agent is to configure the secrets provider, not to fetch tokens yourself.
## When a user asks you to do something that needs an OAuth token or fixed secret
Follow these steps **in order**. Do not skip to step 3. Do not run `--token` yourself.
### 1. Create a grant and show the approval URL
Run the script **without `--token`** to create a grant. Set `TAPAUTH_HOME` so the grant cache is stored in a stable location that the exec provider can also find:
```bash
TAPAUTH_HOME=/home/node/.tapauth /home/node/.openclaw/skills/tapauth/scripts/tapauth.sh <provider> <scopes>
```
Example for Google Calendar:
```bash
TAPAUTH_HOME=/home/node/.tapauth /home/node/.openclaw/skills/tapauth/scripts/tapauth.sh google calendar.readonly
```
Example for a manual API key:
```bash
TAPAUTH_HOME=/home/node/.tapauth /home/node/.openclaw/skills/tapauth/scripts/tapauth.sh secret "Stripe Secret Key" "^sk_" "Use a Stripe secret key that starts with sk_"
```
Output:
```text
Approve access: https://tapauth.ai/approve/abc123
Show this URL to the user, then start --token immediately; it waits until approval completes.
```
**Show the approval URL to the user, then proceed immediately.** Do not ask the user to reply "done." The exec secrets provider will run `tapauth.sh --token` and wait while the user approves in the browser.
### 2. Configure the exec secrets provider in openclaw.json
Immediately after sharing the approval URL, **edit `~/.openclaw/openclaw.json`** to add an exec provider under `secrets.providers`:
```json
{
"secrets": {
"providers": {
"tapauth_google_calendar": {
"source": "exec",
"command": "/home/node/.openclaw/skills/tapauth/scripts/tapauth.sh",
"args": ["--token", "google", "calendar.readonly"],
"passEnv": ["HOME"],
"env": {"TAREADME.md
# TapAuth Agent Skill
> Delegated access broker for AI agents. One API call to request OAuth access or a user-entered secret.
This is the official [Agent Skill](https://agentskills.io) for [TapAuth](https://tapauth.ai) — the trust layer between humans and AI agents.
## Install
Works with any agent that supports the [Agent Skills standard](https://agentskills.io):
```bash
npx skills add tapauth/skill
```
Compatible with: **Claude Code** · **Cursor** · **OpenClaw** · **OpenAI Codex** · **GitHub Copilot** · **VS Code** · and more.
## What It Does
Gives your AI agent the ability to get OAuth tokens or user-entered passwords/API keys from users. Instead of hardcoding credentials, TapAuth lets users approve access in their browser with clear request context and expiry controls.
```
Agent creates grant → User approves in browser → Agent gets scoped token or secret
```
No TapAuth API key needed. No signup needed. The user's approval is the gate.
## Supported Providers
| Provider | Reference | Scopes |
|----------|-----------|--------|
| GitHub | [references/github.md](references/github.md) | `repo`, `read:user`, `workflow`, etc. |
| Google (multi-service) | [references/google.md](references/google.md) | Drive, Calendar, Sheets, Docs, Contacts |
| Gmail | [references/gmail.md](references/gmail.md) | Read, send, manage emails |
| Linear | [references/linear.md](references/linear.md) | Issues, projects, teams |
| Vercel | [references/vercel.md](references/vercel.md) | Deployments, projects, env vars, domains |
| Notion | [references/notion.md](references/notion.md) | Pages, databases, search |
| Slack | [references/slack.md](references/slack.md) | Channels, messages, users, files |
| Asana | [references/asana.md](references/asana.md) | Tasks, projects, workspaces |
| Discord | [references/discord.md](references/discord.md) | Guilds, channels, messages, users |
| Sentry | [references/sentry.md](references/sentry.md) | Error tracking, projects, organizations |
| Apify | [references/apify.md](references/apify.md) | Actors, web scraping, datasets, automation |
| Manual Secret | Built in | User-entered passwords or fixed API keys |
## Quick Example
### CLI (recommended)
```bash
# 1. Create the grant and show the approval URL.
scripts/tapauth.sh github repo
# 2. Start the real request immediately; --token waits until approval completes.
curl -H "Authorization: Bearer $(scripts/tapauth.sh --token github repo)" \
https://api.github.com/user/repos
```
### API (v1)
```bash
# 1. Create a grant
curl -X POST https://tapauth.ai/api/v1/grants \
-H "Content-Type: application/json" \
-d '{"provider": "github", "scopes": ["repo"]}'
# 2. User clicks the approval_url
# 3. Retrieve the token
curl https://tapauth.ai/api/v1/grants/{grant_id} \
-H "Authorization: Bearer gs_..."
```
### Manual Secret
```bash
# Ask the user for a fixed API key. The approval page encrypts it in the browser.
scripts/tapauth.sh secret "Stripe Secret Key" "^sk_" "Use a Strip_meta.json
{
"ownerId": "kn7542bxp4vq2hkyyn1p2xa4jd81rcew",
"slug": "tapauth",
"version": "1.0.6",
"publishedAt": 1782246627111
}references/apify.md
# Apify via TapAuth
## Available Scopes
| Scope | Access |
|-------|--------|
| `full_api_access` | Full access to the Apify API (actors, runs, datasets, key-value stores, schedules) |
## Example: Run an Apify Actor
```bash
# 1. Get a token with full_api_access scope
scripts/tapauth.sh apify full_api_access
# 2. Run a web scraper actor
curl -X POST \
-H "Authorization: Bearer $(scripts/tapauth.sh --token apify full_api_access)" \
-H "Content-Type: application/json" \
-d '{"startUrls": [{"url": "https://example.com"}]}' \
"https://api.apify.com/v2/acts/apify~web-scraper/runs?waitForFinish=60"
```
## Example: Get User Info
```bash
curl -H "Authorization: Bearer $(scripts/tapauth.sh --token apify full_api_access)" \
"https://api.apify.com/v2/users/me"
```
## Gotchas
- **Dynamic Client Registration (DCR):** Apify uses OAuth 2.0 Dynamic Client Registration. TapAuth handles this automatically — no manual app setup needed.
- **PKCE required:** Apify enforces Proof Key for Code Exchange (PKCE) on all OAuth flows. TapAuth handles this automatically.
- **Token expiry:** Apify access tokens expire. TapAuth auto-refreshes using the refresh token when possible. If refresh fails, delete `.tapauth/` and re-run.
- **Rate limits:** Apify API rate limits vary by plan. Check `X-RateLimit-Remaining` headers. Free tier has lower limits.
- **Single scope:** Currently only `full_api_access` is available — there are no granular scopes.
- **API base URL:** All Apify API calls go to `https://api.apify.com/v2`.
## Recommended Minimum Scopes
| Use Case | Scopes |
|----------|--------|
| Run actors | `full_api_access` |
| Read datasets | `full_api_access` |
| Manage schedules | `full_api_access` |
| Get user info | `full_api_access` |references/asana.md
# Asana OAuth Provider
## Overview
Asana uses OAuth 2.0 with granular `<resource>:<action>` scopes. TapAuth supports PKCE and refresh tokens for Asana.
## Key Gotchas
### Granular Scopes Require Pre-Registration
All scopes must be registered in the [Asana Developer Console](https://app.asana.com/0/developer-console) before use. Requesting an unregistered scope causes an authorization error.
### Short-Lived Access Tokens
Access tokens expire in **1 hour**. TapAuth automatically handles refresh using long-lived refresh tokens.
### API Response Envelope
All Asana API responses are wrapped in a `{ data: ... }` envelope:
```json
{ "data": { "gid": "1234", "name": "My Task" } }
```
### Use `opt_fields`
Without `opt_fields`, Asana returns only `gid` and `name`. Always specify the fields you need:
```
GET /tasks/1234?opt_fields=name,assignee,due_on,completed
```
### Workspace-Scoped Data
A user may belong to multiple workspaces. The token grants access to all workspaces the user belongs to.
### Rate Limits
1,500 requests per minute per token. 429 responses include a `Retry-After` header.
## Scopes
### Default (Read-Only + Identity)
- `tasks:read` — Read tasks
- `projects:read` — Read projects
- `users:read` — Read user information
- `workspaces:read` — Read workspaces
- `openid` — OpenID Connect identity
- `email` — User email address
- `profile` — User profile info
### Write Scopes (Request Only When Needed)
- `tasks:write` — Create and update tasks
- `projects:write` — Create and update projects
- `stories:write` — Create and update comments
- `attachments:write` — Upload attachments
- `tags:write` — Create and update tags
### Delete Scopes
- `tasks:delete`, `projects:delete`, `attachments:delete`, `webhooks:delete`
## Example Usage
```bash
# List tasks in a project
curl -H "Authorization: Bearer {access_token}" \
"https://app.asana.com/api/1.0/projects/{project_gid}/tasks?opt_fields=name,assignee,due_on"
# Get current user
curl -H "Authorization: Bearer {access_token}" \
"https://app.asana.com/api/1.0/users/me?opt_fields=gid,name,email"
```
## API Reference
- Base URL: `https://app.asana.com/api/1.0/`
- Docs: https://developers.asana.com/referenceAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/schwartzdev/skills/tapauth",
"sourceUrl": "https://clawhub.ai/schwartzdev/skills/tapauth",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:13:59.741Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-schwartzdev-tapauth/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-schwartzdev-tapauth/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T23:13:59.741Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.9K downloads",
"href": "https://clawhub.ai/schwartzdev/tapauth",
"sourceUrl": "https://clawhub.ai/schwartzdev/tapauth",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:13:59.741Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.6",
"href": "https://clawhub.ai/schwartzdev/tapauth",
"sourceUrl": "https://clawhub.ai/schwartzdev/tapauth",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-23T20:30:27.111Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-schwartzdev-tapauth/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-schwartzdev-tapauth/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.6",
"description": "Grant polling and OpenClaw reload guidance",
"href": "https://clawhub.ai/schwartzdev/tapauth",
"sourceUrl": "https://clawhub.ai/schwartzdev/tapauth",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-23T20:30:27.111Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
