{"id":"a03f0f51-f6af-47ee-a66b-7eb8d2b26600","entityType":"agent","slug":"clawhub-adamludwin-here-now","name":"here.now","canonicalUrl":"https://www.xpersona.co/agent/clawhub-adamludwin-here-now","canonicalPath":"/agent/clawhub-adamludwin-here-now","generatedAt":"2026-10-09T12:55:56.124Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:04:30.115Z","emptyReason":null},"description":"here.now lets agents publish websites and files to live URLs in seconds. Publish HTML, documents, images, PDFs, videos, and static files to live URLs at {slug}.here.now or custom domains. Use when asked to \"publish this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a website\", \"put this online\", \"create a webpage\", \"generate a URL\", \"build a chatbot\", \"password protect this site\", \"make this site private\", or \"share this site with only certain people\". here.now also includes workspaces — shared team accounts where Sites belong to the team and serve at {label}.{workspace}.here.now — use when asked to \"publish this to our team workspace\", \"share this with my team\", or \"put this in our company workspace\". Agents can also buy a domain for a Site through here.now (no markup, DNS and SSL automatic) — use when asked to \"buy a domain\", \"get me a .com for this\", or \"register a domain\".","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 7.2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s172zbemcbcayy2ez5htg4md0s83h9pv:here-now","sourceUrl":"https://clawhub.ai/adamludwin/here-now","homepage":"https://clawhub.ai/adamludwin/skills/here-now","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/adamludwin/here-now","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/adamludwin/skills/here-now","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"here.now technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:04:30.115Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:04:30.115Z","emptyReason":null},"stars":null,"forks":null,"downloads":7159,"packageName":null,"latestVersion":"1.32.0","tractionLabel":"7.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:04:30.114Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T03:04:30.115Z","lastCrawledAt":"2026-10-09T03:04:30.114Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T03:04:30.115Z","lastVerifiedAt":null,"highlights":[{"version":"1.32.0","createdAt":"2026-09-23T07:09:54.545Z","changelog":"Folders: publish.sh --folder <name|id> files a Site in a dashboard folder (created by name if missing) and reports publish_result.folder; new Folders section covering the /api/v1/folders routes and the folder field on publish, update, and metadata.","fileCount":5,"zipByteSize":21099},{"version":"1.30.0","createdAt":"2026-09-14T00:30:07.918Z","changelog":"publish.sh reports publish_result.primary_url when a Site has a preferred address other than its slug URL; share it first, siteUrl stays valid.","fileCount":5,"zipByteSize":20013},{"version":"1.29.0","createdAt":"2026-09-12T01:09:59.577Z","changelog":"Buy a domain through here.now: agents can search, quote, and purchase a domain for a Site (registrar's price, DNS and SSL automatic). The skill now routes 'buy a domain' requests to the docs and tells agents to state the price and renewal and get an explicit yes before purchasing.","fileCount":5,"zipByteSize":19899},{"version":"1.28.0","createdAt":"2026-09-04T19:44:54.530Z","changelog":"Requirements now list both egress hosts (here.now and *.r2.cloudflarestorage.com, where uploads PUT directly). publish.sh and drive.sh survive connection-level upload failures and print a hint naming the storage host when every upload fails.","fileCount":5,"zipByteSize":19471},{"version":"1.27.0","createdAt":"2026-09-03T06:01:03.852Z","changelog":"Owner Site file read API: GET /api/v1/publish/{slug}/files and /files/{path} read an owned Site's live files with the API key (password-protected Sites included); GET /api/v1/publish/{slug} gains currentVersionSource/currentVersionCreatedAt. Skill and publish.sh now teach pull-before-push: check for drift before editing and read the live files on version_conflict.","fileCount":5,"zipByteSize":18875},{"version":"1.26.0","createdAt":"2026-08-31T00:14:37.838Z","changelog":"Stale-base protection for updates: publish.sh now records the live version in .herenow/state.json and passes baseVersionId when republishing the same slug from the same directory. If the live Site changed since (another agent, Studio, a teammate), the update fails with version_conflict naming the live version instead of silently overwriting it. New --overwrite flag for explicit unchecked replacement.","fileCount":5,"zipByteSize":18586},{"version":"1.25.0","createdAt":"2026-08-29T07:26:22.509Z","changelog":"Scriptless-environment guidance: install command plus the hand-rolled three-step publish flow (POST /api/v1/publish -> PUT presigned targets -> POST finalizeUrl) for environments that receive the skill without bundled scripts, e.g. Stripe Projects llm_context.","fileCount":5,"zipByteSize":17114},{"version":"1.24.0","createdAt":"2026-08-28T21:58:05.353Z","changelog":"Workspace guest allowlists: restricted mode on workspace Sites now means workspace members plus a per-Site email/domain guest allowlist (guests view only that Site). Also documents the empty-allowlist 400 and updated workspace access-mode guidance.","fileCount":5,"zipByteSize":16793}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s172zbemcbcayy2ez5htg4md0s83h9pv:here-now","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s172zbemcbcayy2ez5htg4md0s83h9pv:here-now` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/adamludwin/here-now before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T12:55:56.117Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-adamludwin-here-now/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:04:30.115Z","emptyReason":null},"readme":"Skill: here.now\n\nOwner: adamludwin\n\nSummary: here.now lets agents publish websites and files to live URLs in seconds. Publish HTML, documents, images, PDFs, videos, and static files to live URLs at {slug}.here.now or custom domains. Use when asked to \"publish this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a website\", \"put this online\", \"create a webpage\", \"generate a URL\", \"build a chatbot\", \"password protect this site\", \"make this site private\", or \"share this site with only certain people\". here.now also includes workspaces — shared team accounts where Sites belong to the team and serve at {label}.{workspace}.here.now — use when asked to \"publish this to our team workspace\", \"share this with my team\", or \"put this in our company workspace\". Agents can also buy a domain for a Site through here.now (no markup, DNS and SSL automatic) — use when asked to \"buy a domain\", \"get me a .com for this\", or \"register a domain\".\n\nTags: agents:1.2.0, deploy:1.2.0, hosting:1.2.0, latest:1.32.0, publish:1.2.0, static-hosting:1.2.0, web:1.2.0\n\nVersion history:\n\nv1.32.0 | 2026-09-23T07:09:54.545Z | user\n\nFolders: publish.sh --folder <name|id> files a Site in a dashboard folder (created by name if missing) and reports publish_result.folder; new Folders section covering the /api/v1/folders routes and the folder field on publish, update, and metadata.\n\nv1.30.0 | 2026-09-14T00:30:07.918Z | user\n\npublish.sh reports publish_result.primary_url when a Site has a preferred address other than its slug URL; share it first, siteUrl stays valid.\n\nv1.29.0 | 2026-09-12T01:09:59.577Z | user\n\nBuy a domain through here.now: agents can search, quote, and purchase a domain for a Site (registrar's price, DNS and SSL automatic). The skill now routes 'buy a domain' requests to the docs and tells agents to state the price and renewal and get an explicit yes before purchasing.\n\nv1.28.0 | 2026-09-04T19:44:54.530Z | user\n\nRequirements now list both egress hosts (here.now and *.r2.cloudflarestorage.com, where uploads PUT directly). publish.sh and drive.sh survive connection-level upload failures and print a hint naming the storage host when every upload fails.\n\nv1.27.0 | 2026-09-03T06:01:03.852Z | user\n\nOwner Site file read API: GET /api/v1/publish/{slug}/files and /files/{path} read an owned Site's live files with the API key (password-protected Sites included); GET /api/v1/publish/{slug} gains currentVersionSource/currentVersionCreatedAt. Skill and publish.sh now teach pull-before-push: check for drift before editing and read the live files on version_conflict.\n\nv1.26.0 | 2026-08-31T00:14:37.838Z | user\n\nStale-base protection for updates: publish.sh now records the live version in .herenow/state.json and passes baseVersionId when republishing the same slug from the same directory. If the live Site changed since (another agent, Studio, a teammate), the update fails with version_conflict naming the live version instead of silently overwriting it. New --overwrite flag for explicit unchecked replacement.\n\nv1.25.0 | 2026-08-29T07:26:22.509Z | user\n\nScriptless-environment guidance: install command plus the hand-rolled three-step publish flow (POST /api/v1/publish -> PUT presigned targets -> POST finalizeUrl) for environments that receive the skill without bundled scripts, e.g. Stripe Projects llm_context.\n\nv1.24.0 | 2026-08-28T21:58:05.353Z | user\n\nWorkspace guest allowlists: restricted mode on workspace Sites now means workspace members plus a per-Site email/domain guest allowlist (guests view only that Site). Also documents the empty-allowlist 400 and updated workspace access-mode guidance.\n\nv1.21.1 | 2026-08-20T19:12:20.163Z | user\n\nOutput rule: put the site URL on its own line with nothing after it — chat autolinkers glue trailing status text into the href. Status details go on the following line. (Also includes 1.21.0's harness-not-persona attribution guidance.)\n\nv1.21.0 | 2026-08-20T05:43:01.697Z | user\n\nClient attribution instructions now teach harness-not-persona: --client names the agent platform you run in (cursor, claude-code, grok-bot, ...), never a bot/persona/project name inside it; instance names go after a slash (grok-bot/research-bot).\n\nv1.20.0 | 2026-08-19T23:59:57.701Z | user\n\nCompact claim links (/c/<token>): claim URLs are now short enough that agents have no reason to truncate them. Explicit instruction: share claimUrl byte-for-byte, never shorten or replace any part with '...'. Claim page now validates links before sign-in.\n\nv1.19.0 | 2026-08-11T20:46:41.486Z | user\n\nSite versions: history, owner-only previews, instant rollback, per-version delete (paid plans + workspaces). publish.sh fixes: exclude .herenow/state.json from uploads; fix zero-upload republish crash on macOS.\n\nv1.18.0 | 2026-07-21T23:02:40.026Z | user\n\nWorkspaces: publish into shared team accounts with --workspace <subdomain> (sites get {label}.{workspace}.here.now URLs and are owned by the team); workspace access-control notes; docs topics updated\n\nv1.17.0 | 2026-07-07T18:11:23.957Z | user\n\nSites-first messaging: lead with publishing to live URLs; Drives described at feature level\n\nv1.16.0 | 2026-06-11T06:20:17.539Z | user\n\nSurface Site access control (link, password, restricted invite-only access) prominently for agents: activation triggers, capability line, and a minimal access control section pointing to https://here.now/docs#access-control. No runtime/script changes.\n\nv1.15.10 | 2026-05-28T22:58:37.873Z | user\n\npublish.sh: send claimToken on slug updates even when an API key is set; clearer invalid-key and anonymous-update errors\n\nv1.15.9 | 2026-05-28T22:05:58.796Z | user\n\nAdd Site Data docs and dashboard availability\n\nv1.15.8 | 2026-05-27T00:26:57.933Z | user\n\nRestore skill metadata summary\n\nv1.15.7 | 2026-05-27T00:20:51.381Z | user\n\nUpdate skill summary copy\n\nv1.15.6 | 2026-05-26T23:56:19.482Z | user\n\nAdd analytics to current docs topics\n\nv1.15.5 | 2026-05-21T23:17:07.019Z | user\n\nRefresh here.now skill guidance for profiles, owner Site search, subdomain handles, and the profile-based forkability model.\n\nv1.15.3 | 2026-04-29T00:01:05.352Z | user\n\nRaise Drive file upload helper limit to 500 MB and refresh here.now skill copy.\n\nv1.15.2 | 2026-04-28T06:47:13.866Z | user\n\n**Adds private Drive storage alongside website publishing.**\n\n- Introduced Drives: agents can now store private files in cloud Drives, share folders, and persist files (not just publish websites).\n- Added new helper script `scripts/drive.sh` for Drive operations (create, list, read, write, share).\n- Updated core documentation and usage to include both Sites (public publishing) and Drives (private storage).\n- Updated requirements: new environment variable `$HERENOW_DRIVE_TOKEN` for Drive access.\n- Clarified when to use Sites vs Drives throughout the documentation.\n\nv1.14.0 | 2026-04-22T04:30:14.740Z | user\n\n- Updated skill documentation to require reading live here.now docs at https://here.now/docs before answering on key topics and workflows.\n- Removed local reference documentation (REFERENCE.md) in favor of always using canonical, current docs.\n- Clarified that for core features like custom domains, payments, forking, limits, and more, guidance should come from the latest docs or observed API behavior.\n- Specified to trust live API behavior if docs and API responses differ.\n- Existing publish/script usage details retained for reference.\n\nv1.13.0 | 2026-04-16T05:14:25.359Z | user\n\nhere-now 1.13.0\n\n- Version bump to 1.13.0 (no file changes detected)\n- No user-facing changes in this release\n\nv1.12.1 | 2026-04-07T03:15:25.532Z | user\n\nNo user-facing changes in this release.\n\n- Version bumped from 1.12.0 to 1.12.1 with small tweak to documentation\n- No new features, fixes, or adjustments detected.\n\nv1.12.0 | 2026-04-07T01:16:22.058Z | user\n\nhere-now 1.12.0 Changelog\n\n- No file changes detected in this release.\n- Documentation now describes support for the new `--forkable` flag in the publish script options.\n- Updated documentation examples and details to match the latest platform capabilities.\n\nv1.11.0 | 2026-03-31T20:02:51.145Z | user\n\nVersion 1.11.0\n\n- Added support for SPA (Single-Page Application) routing with the new --spa flag on publish, ensuring index.html is served for unknown paths.\n- Documented how to enable or toggle SPA mode both via CLI and API call for client-side routed sites like React, Vue, and Svelte.\n- Updated documentation to include the --spa flag in script options.\n- Clarified asset path requirements for SPA builds.\n- No code changes were made; this release updates documentation only.\n\nv1.10.0 | 2026-03-30T17:38:54.508Z | user\n\nhere-now 1.10.0 is a feature release expanding publishing capabilities.\n\n- Adds support for proxy routes enabling server-side API calls (e.g., LLMs, databases, email, payments) from hosted sites.\n- Updates skill description to reflect new ability to \"build a chatbot\" and connect to external APIs.\n- No functional changes to publishing flow, authentication, or API key management.\n- Existing static hosting and usage remains unchanged.\n\nv1.9.1 | 2026-03-24T19:29:41.556Z | user\n\nNo functional or behavioral changes; documentation only.\n\n- Added instructions for obtaining a Tempo wallet address for payment gating.\n- Linked to https://wallet.tempo.xyz and included `npx mppx account create` as wallet options.\n- No changes to code or scripts; usage remains the same.\n\nv1.9.0 | 2026-03-24T18:52:19.801Z | user\n\nhere-now 1.9.0\n\n- Added documentation for payment gating: sites can now require stablecoin payment on the Tempo network before granting access, with payments sent directly to the publisher's wallet.\n- CLI examples provided for setting wallet addresses, configuring site pricing, and removing payment requirements.\n- Documentation clarified that \"metadata patch\" operations now include password protection and payment gating.\n- No underlying file or implementation changes were detected—documentation updates only.\n\nv1.8.3 | 2026-03-13T00:46:17.423Z | user\n\nSimple clarifications in docs\n\nv1.8.1 | 2026-03-12T21:34:10.961Z | user\n\nhere-now 1.8.1 is a minor documentation release.\n\n- Removed the fallback install note from the shipped skill instructions.\n- Bumped the skill version to 1.8.1.\n- No functional script or API behavior changes.\n\nv1.8.0 | 2026-03-12T21:00:27.696Z | user\n\nhere-now 1.8.0\n\n- Added site duplication: instantly create a full server-side copy of any site you own, under a new slug, with optional metadata overrides—no upload required (API only).\n- Updated API key storage guidance: agents must save the API key themselves after receipt, rather than asking the user to do so.\n- Docs now clarify to avoid passing API keys via CLI flags in interactive sessions; use the credentials file as the preferred method.\n- Reference section reflects support for new duplicate operation alongside delete, patch, and claim.\n\nv1.7.0 | 2026-03-12T04:01:04.117Z | user\n\n**Terminology update and documentation improvements.**\n\n- User-facing term changed from \"artifact/publish\" to \"site\" throughout documentation.\n- Script, file, and API usage examples updated for clarity and terminology consistency.\n- Expanded API route aliases and equivalence notes in the \"Terminology and API aliases\" section.\n- Documentation now emphasizes \"site\" in UI/user prompts and state tracking.\n- Improved description of limits and usage scenarios.\n\nv1.6.9 | 2026-03-12T00:07:18.647Z | user\n\nhere-now 1.6.9\n\n- Documentation updated to mention password protection as a supported metadata patch operation via the API.\n- No code changes; behavior remains the same.\n\nv1.6.8 | 2026-03-11T17:42:33.051Z | user\n\nhere-now 1.6.8\n\n- Updated instructions for what information to share with users after publish.\n- Clarified user messaging and handling for anonymous vs authenticated artifacts:\n  - Explicitly guide on communicating expiry, permanence, and claim URLs based on auth mode.\n- Enhanced safety notes: never direct users to inspect internal state files for claim URLs or status.\n- No functional or code changes; documentation improvements only.\n\nv1.6.7 | 2026-03-09T18:30:19.371Z | user\n\nNo changes to files detected in this release.\n\n- Version bumped from 1.6.6 to 1.6.7; no functional or documentation changes present.\n- Behavior and usage remain identical to previous version.\n\nv1.6.6 | 2026-03-06T23:33:56.877Z | user\n\nhere-now 1.6.6 changelog:\n\n- Expanded skill trigger phrases to cover more publish/upload scenarios in the description.\n- Clarified that anyone with an API key can claim a handle, not just paid plans.\n- Updated and streamlined description text for improved clarity and broader discoverability.\n- No code or function changes; documentation updates only.\n\nv1.6.5 | 2026-03-06T19:00:37.673Z | user\n\nVersion 1.6.5\n\n- Replaces the term \"publish\" with \"artifact\" throughout the documentation for improved clarity.\n- Updates API key acquisition flow: now uses a one-time sign-in code via dedicated endpoints.\n- Adds an explicit Terminology and API aliases section explaining the transition from \"publish\" to \"artifact\", \"username\" to \"handle\", and \"mount\" to \"link\".\n- Enhances detail on handle and link features, including references to new endpoints and plan requirements.\n- Updates usage examples and limits table to match latest API behavior and terminology.\n- General wording and structure improvements for easier reading.\n\nv1.6.4 | 2026-03-03T22:21:19.994Z | user\n\nhere-now 1.6.4\n\n- Added description of the internal three-step publish flow (create/update → upload files → finalize).\n- Documented the new --client flag for agent attribution and its effect on API requests.\n- Minor rewording and switched shell placeholder formatting from <angle> to {curly} for all user-facing code/docs.\n\nv1.6.3 | 2026-02-25T04:20:14.482Z | user\n\nHardened skill publish messaging to correctly report authenticated vs anonymous publishes (including valid claim URL handling) and synced docs in v1.6.3.\n\nv1.6.2 | 2026-02-25T02:22:57.479Z | user\n\nhere-now 1.6.2\n\n- skills.sh compatibility fix + patch version bump.\n- No changes to functionality, install, or usage instructions.\n\nv1.6.1 | 2026-02-25T00:40:01.899Z | user\n\nAdded security hardening: explicit requirements, stronger credential/state warnings, and a guard against sending API keys to non-default --base-url without explicit override.\n\nRecommended install is now npx skills add heredotnow/skill --skill here-now -g\n\nv1.6.0 | 2026-02-23T18:39:31.068Z | user\n\n- Add zero-prereq installer: curl -fsSL https://here.now/install.sh | bash\n- Bundle jq via installer; publish.sh uses bundled jq first, PATH fallback second\n\nv1.5.0 | 2026-02-23T06:04:03.359Z | user\n\nv1.5: Subdirectory publish support. Sites with files in a single subfolder now serve correctly at the root URL with working relative links. Added file structure guidance for agents calling the API directly. Finalize now verifies uploads completed before going live.\n\nv1.4.0 | 2026-02-21T18:36:34.443Z | user\n\nv1.4: API keys are now stored in ~/.herenow/credentials instead of passed via --api-key flag. Keeps secrets out of terminal history and agent transcripts. Also updated rate limits (authenticated: 60/hour).\n\nv1.3.0 | 2026-02-21T08:07:52.359Z | user\n\nRemoved runtime auto-update mechanism. Skill updates now happen through npx skills add. Bumped to v1.3.\n\nv1.2.0 | 2026-02-20T23:25:08.842Z | user\n\nInitial public release. Publish files and folders to the web instantly. Anonymous publishing (24h), authenticated permanent hosting, in-place updates, claim flow.\n\nArchive index:\n\nArchive v1.32.0: 5 files, 21099 bytes\n\nFiles: scripts/drive.sh (14168b), scripts/publish.sh (22154b), skill-card.md (2504b), SKILL.md (20597b), _meta.json (128b)\n\nFile v1.32.0:SKILL.md\n\n---\nname: here-now\ndescription: >\n  here.now lets agents publish websites and files to live URLs in seconds.\n  Publish HTML, documents, images, PDFs, videos, and static files to live\n  URLs at {slug}.here.now or custom domains. Use when asked to \"publish\n  this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a\n  website\", \"put this online\", \"create a webpage\", \"generate a URL\",\n  \"build a chatbot\", \"password protect this site\", \"make this site\n  private\", or \"share this site with only certain people\". here.now also\n  includes workspaces — shared team accounts where Sites belong to the\n  team and serve at {label}.{workspace}.here.now — use when asked to\n  \"publish this to our team workspace\", \"share this with my team\", or\n  \"put this in our company workspace\". Agents can also buy a domain for a\n  Site through here.now (no markup, DNS and SSL automatic) — use when asked\n  to \"buy a domain\", \"get me a .com for this\", or \"register a domain\".\n---\n\n# here.now\n\n**Skill version: 1.32.0**\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThe core primitive is a **Site**: publish a file or folder and get a live URL at `{slug}.here.now` or a custom domain. Every Site has access control: public link (default), password, or restricted invite-only access.\n\nhere.now also includes **workspaces** — shared team accounts where Sites belong to the team and serve at `{label}.{workspace}.here.now` (see \"Publish to a workspace\" below).\n\nA personal account on a paid plan can turn on a **vanity URL**: the user's name at `{name}.here.now`, and from then on every Site they publish (including through you) also serves at a readable `{site-name}.{name}.here.now` address, named from its title. When a user wants every Site under their own name, `PUT /api/v1/vanity-urls/subdomain` with `{\"subdomain\": \"name\"}` turns it on; for one Site at one hostname they choose, use a custom domain; for Sites owned by a team, use a workspace. Finalize responses carry `primaryUrl` and `urls[]` (best first); mention `primaryUrl` when it differs from `siteUrl`. See https://here.now/docs#vanity-urls.\n\nTo install or update (recommended): `npx skills add heredotnow/skill --skill here-now -g`\n\nFor repo-pinned/project-local installs, run the same command without `-g`.\n\n## Current docs\n\n**Before answering questions about here.now capabilities, features, or workflows, read the current docs:**\n\n→ **https://here.now/docs**\n\nRead the docs:\n\n- at the first here.now-related interaction in a conversation\n- any time the user asks how to do something\n- any time the user asks what is possible, supported, or recommended\n- before telling the user a feature is unsupported\n\nTopics that require current docs (do not rely on local skill text alone):\n\n- Site access control (passwords and restricted access)\n- workspaces (team accounts, membership, label URLs)\n- folders (organizing the user's dashboard; see https://here.now/docs#folders)\n- Drives and Drive sharing\n- custom domains\n- vanity URLs (`{site-name}.{name}.here.now`; see https://here.now/docs#vanity-urls)\n- buying a domain (search and quote first; state the price and the renewal price and get the user's explicit yes before calling purchase — purchases are final; see https://here.now/docs#buy-domain)\n- Site Data\n- public profiles\n- proxy routes and service variables\n- limits and quotas\n- SPA routing\n- owner Site search\n- Site analytics\n- Site version history, previews, and rollback\n- error handling and remediation\n- feature availability\n\n**If docs and live API behavior disagree, trust the live API behavior.**\n\nCommand-line fetches of https://here.now/docs (curl, WebFetch, etc.) receive a markdown summary, not the full HTML docs: it lists every stable public endpoint with a one-line description, but section anchors in this skill (like `/docs#access-control`) resolve only in the HTML version, and worked examples live there too. For complete request/response schemas and parameters, fetch **https://here.now/openapi.json**. Do not conclude an operation is unsupported from the markdown summary alone — check the OpenAPI spec first.\n\nIf the docs fetch fails or times out, continue with the local skill and live API/script output. Prefer live API behavior for active operations.\n\n## Requirements\n\n- Required binaries: `curl`, `file`, `jq`\n- Required network access: `https://here.now` (API) and `https://*.r2.cloudflarestorage.com` (file uploads PUT directly to storage; the exact host is in each upload URL). In a sandbox or behind a proxy with an egress allowlist, allow BOTH hosts. With only `here.now` allowed, the create call succeeds, every upload fails, and finalize reports missing files.\n- Optional environment variable: `$HERENOW_API_KEY`\n- Optional Drive token variable: `$HERENOW_DRIVE_TOKEN`\n- Optional credentials file: `~/.herenow/credentials`\n- Bundled helpers:\n  - `./scripts/publish.sh` for publishing sites\n  - `./scripts/drive.sh` for private Drive storage\n\n## If the helper scripts aren't installed\n\nSome environments receive this document without the bundled `scripts/` directory (for example, hosted platform integrations that provide only `$HERENOW_API_KEY`). In that case, either install the full bundle first:\n\n```bash\nnpx skills add heredotnow/skill --skill here-now -g\n```\n\nor call the API directly — every script workflow in this document is a wrapper over the public API. Publishing is a three-step flow: `POST /api/v1/publish` with a `files` array (`[{path, size}]`) returns presigned upload targets, `PUT` each file's bytes to its returned URL, then `POST` the returned `finalizeUrl`. The site is not live until finalize succeeds. Full walkthrough with request/response examples: https://here.now/docs#create (then #upload and #finalize), machine-readable schemas: https://here.now/openapi.json.\n\n## Create a site\n\n```bash\n./scripts/publish.sh {file-or-dir}\n```\n\nOutputs the live URL (e.g. `https://bright-canvas-a7k2.here.now/`).\n\nUnder the hood this is a three-step flow: create/update -> upload files -> finalize. A site is not live until finalize succeeds.\n\nWithout an API key this creates an **anonymous site** that expires in 24 hours.\nWith a saved API key, the site is permanent.\n\n**File structure:** For HTML sites, place `index.html` at the root of the directory you publish, not inside a subdirectory. The directory's contents become the site root. For example, publish `my-site/` where `my-site/index.html` exists — don't publish a parent folder that contains `my-site/`.\n\nYou can also publish raw files without any HTML. Single files get a rich auto-viewer (images, PDF, video, audio). Multiple files get an auto-generated directory listing with folder navigation and an image gallery.\n\n## Update an existing site\n\n```bash\n./scripts/publish.sh {file-or-dir} --slug {slug}\n```\n\nThe script auto-loads the `claimToken` from `.herenow/state.json` when updating anonymous sites. Pass `--claim-token {token}` to override.\n\nAuthenticated updates require a saved API key.\n\n**Stale-base protection.** The live Site may have changed since your local files were published — the owner can edit it from other tools (another agent, the here.now Editor, a teammate). The script records the live `versionId` in `.herenow/state.json` after each publish and sends it as `baseVersionId` on the next update of the same slug from the same directory; if the live Site moved past it, the update is rejected with `code: \"version_conflict\"` naming the live version and what created it. When that happens, relay the message to the user and offer to (a) read the live files with `GET /api/v1/publish/{slug}/files` (lists them with a `url` each) and `GET /api/v1/publish/{slug}/files/{path}` (the bytes; owner API key, works for password-protected and restricted Sites without the visitor password), reconcile them into the local files, and republish, or (b) re-run with `--overwrite` to replace the live version anyway. Before editing local files for an authenticated Site you haven't touched recently, check for drift first: `GET /api/v1/publish/{slug}` returns `currentVersionId` plus `currentVersionSource` and `currentVersionCreatedAt` (what changed it and when, e.g. `editor`) — if the id differs from your state file's `versionId`, read the live files before editing. The published version is the shared truth; never fetch the public URL to read an owned Site (it is gated for protected Sites) and never ask the user for a visitor password to read their own Site. Anonymous Sites can't call these endpoints; they rely on the saved state and server enforcement. Omitting `baseVersionId` (or using `--overwrite`) is an unchecked full replacement — today's default for raw API callers.\n\nEvery publish records an immutable version. If the user asks to see earlier versions of a Site, undo a publish, or roll back: list history with `GET /api/v1/publish/{slug}/versions` and restore instantly with `POST /api/v1/publish/{slug}/versions/{versionId}/restore` (restoring keeps the current access mode, password, and domains). Version access is included on every plan, personal and workspace alike. A byte-identical republish returns `unchanged: true` from finalize instead of creating a new version. See https://here.now/docs#versions.\n\nSigned-in users also have public profiles. Agents can help users show or hide Sites on their profile and manage profile settings through the API documented at https://here.now/docs#profile.\n\n## Publish to a workspace\n\nWorkspaces are shared team accounts: Sites published into one belong to the team, not the publishing member, and get a memorable URL at `{label}.{workspace}.here.now`.\n\n```bash\n./scripts/publish.sh {file-or-dir} --workspace {subdomain}\n```\n\nRequires a saved API key and membership in the workspace. List the user's workspaces (and valid subdomains) with `GET /api/v1/accounts`. Workspace Sites default to member-only access; the script reports the team URL as `publish_result.account_url`.\n\nFor everything else — creating workspaces, invites and auto-join, workspace domains and variables, label renames — read the current docs:\n\n→ **https://here.now/docs#workspaces**\n\n## Site access control\n\nA Site uses one access mode at a time:\n\n- **anyone_with_link** (default): anyone with the URL can view.\n- **password**: visitors must enter a shared password.\n- **restricted**: invite-only; only verified email addresses or email domains the owner allows can view.\n\nWorkspace-owned Sites default to **account_members** (visitors sign in and must be workspace members) and also support public, public with a password, and **restricted**. On a workspace Site, `restricted` means workspace members plus a per-Site guest allowlist: members always have access, and allowlisted emails/domains are outside guests who can view only that Site — they never become workspace members, though the Site appears in the guest's own dashboard as a shared Site. Workspace restricted requires at least one guest email or domain — an empty allowlist is rejected with a 400 (use `account_members` for members-only). See https://here.now/docs#workspace-access.\n\nManage access with `GET`/`PATCH /api/v1/publish/{slug}/access` (passwords via the metadata endpoint). Restricted access requires a claimed Site. The PATCH replaces the full allowlists — read, merge, then write. Before working with access control, read the current docs:\n\n→ **https://here.now/docs#access-control**\n\n## Folders (organizing the user's dashboard)\n\nSigned-in users can group their Sites into **folders** in the here.now dashboard. A folder is a fact about the account, not the Site's address: flat (no nesting), one folder per Site, shared by every member of a workspace, invisible to visitors. Filing a Site changes nothing about its URL or access.\n\nWhen the user names a folder, project, or client for a Site (\"publish this to my Reports folder\", \"file it under Acme\"), file it as part of the publish:\n\n```bash\n./scripts/publish.sh {file-or-dir} --folder \"Reports\"\n```\n\n`--folder` takes a folder name or id. A name is matched case-insensitively and **created if it does not exist yet**, so this works the first time; the script reports the result as `publish_result.folder`. It requires an API key (anonymous Sites have no account to file in) and works with `--slug` (moves an existing Site) and `--workspace` (the workspace's folders).\n\nWithout the script, the same field is `folder` on `POST /api/v1/publish`, `PUT /api/v1/publish/{slug}`, and `PATCH /api/v1/publish/{slug}/metadata` (the way to file a Site without publishing a new version; `\"folder\": null` moves it back to the root). `GET /api/v1/folders` lists the account's folders; `GET /api/v1/publishes?folder={name-or-id}` lists one folder's Sites. Rename and delete are `PATCH`/`DELETE /api/v1/folders/{id}` (deleting a folder unfiles its Sites and deletes nothing else). Up to 50 folders per account, names up to 60 characters.\n\n**Never invent folders or file Sites the user did not ask to file.** The folder structure is theirs; every folder appears as a tile in their dashboard. See https://here.now/docs#folders.\n\n## Use a Drive\n\nUse a Drive when the user wants private cloud storage for agent files: documents, context, memory, plans, assets, media, research, code, and anything else that should persist without being published as a website.\n\nEvery signed-in account has a default Drive named `My Drive`.\n\n```bash\n./scripts/drive.sh default\n./scripts/drive.sh ls My Drive\n./scripts/drive.sh put My Drive notes/today.md --from ./notes/today.md\n./scripts/drive.sh cat My Drive notes/today.md\n./scripts/drive.sh share My Drive --perms write --prefix notes/ --ttl 7d\n```\n\nUse scoped Drive tokens for agent-to-agent handoff. If you receive a `herenow_drive` share block, use its `token` as `Authorization: Bearer <token>` against `api_base`, respect `pathPrefix` when present, and preserve ETags on writes. A `pathPrefix` of `null` means full-Drive access. If the skill is available, prefer `./scripts/drive.sh`; otherwise call the listed API operations directly.\n\n## Client attribution\n\nPass `--client` with the name of the **agent product or harness you are running in** — `cursor`, `claude-code`, `codex`, `grok-bot`, `openclaw`, `gemini`, etc:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client claude-code\n```\n\nThis sends `X-HereNow-Client: claude-code/publish-sh` on publish API calls. If omitted, the script sends a fallback value.\n\nUse the platform's name, **not** the name you were given inside it. If you are a bot named \"research-bot\" running inside Grok Bot, the correct value is `grok-bot` — not `research-bot`. Bot names, personas, sub-agents, projects, and thread names don't identify the platform. To record your instance name too, append it after a slash:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client grok-bot/research-bot\n```\n\nOnly a standalone agent running in no harness should use its own product name.\n\n## API key storage\n\nThe publish script reads the API key from these sources (first match wins):\n\n1. `--api-key {key}` flag (CI/scripting only — avoid in interactive use)\n2. `$HERENOW_API_KEY` environment variable\n3. `~/.herenow/credentials` file (recommended for agents)\n\nTo store a key, write it to the credentials file:\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n**IMPORTANT**: After receiving an API key, save it immediately — run the command above yourself. Do not ask the user to run it manually. Avoid passing the key via CLI flags (e.g. `--api-key`) in interactive sessions; the credentials file is the preferred storage method.\n\nNever commit credentials or local state files (`~/.herenow/credentials`, `.herenow/state.json`) to source control.\n\n## Getting an API key\n\nTo upgrade from anonymous (24h) to permanent sites:\n\n1. Ask the user for their email address.\n2. Request a one-time sign-in code:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/request-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\": \"user@example.com\"}'\n```\n\n3. Tell the user: \"Check your inbox for a sign-in code from here.now and paste it here.\"\n4. Verify the code and get the API key:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/verify-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\":\"user@example.com\",\"code\":\"ABCD-2345\"}'\n```\n\n5. Save the returned `apiKey` yourself (do not ask the user to do this):\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n## State file\n\nAfter every site create/update, the script writes to `.herenow/state.json` in the working directory:\n\n```json\n{\n  \"publishes\": {\n    \"bright-canvas-a7k2\": {\n      \"siteUrl\": \"https://bright-canvas-a7k2.here.now/\",\n      \"claimToken\": \"4fQ9tK2mXb7cW1pZ\",\n      \"claimUrl\": \"https://here.now/c/4fQ9tK2mXb7cW1pZ\",\n      \"expiresAt\": \"2026-02-18T01:00:00.000Z\"\n    }\n  }\n}\n```\n\nBefore creating or updating sites, you may check this file to find prior slugs.\nTreat `.herenow/state.json` as internal cache only.\nNever present this local file path as a URL, and never use it as source of truth for auth mode, expiry, or claim URL.\n\n## What to tell the user\n\nFor published sites:\n\n- Always share the `siteUrl` from the current script run.\n- Put the site URL on its own line with nothing else on that line — no punctuation, dashes, or status text after it (chat clients autolink everything up to whitespace, gluing your words into the URL). Status details like \"permanent, saved to your account\" go on the following line.\n- Read and follow `publish_result.*` lines from script stderr to determine auth mode.\n- When `publish_result.account_url` is non-empty (workspace publishes), share it as the primary team URL alongside `siteUrl`.\n- When `publish_result.primary_url` is non-empty, share it first; `siteUrl` stays valid.\n- When `publish_result.folder` is non-empty, mention that the Site is filed in that folder in their dashboard.\n- When `publish_result.auth_mode=authenticated`: tell the user the site is **permanent** and saved to their account. No claim URL is needed.\n- When `publish_result.auth_mode=anonymous`: tell the user the site **expires in 24 hours**. Share the claim URL (if `publish_result.claim_url` is non-empty and starts with `https://`) so they can keep it permanently. Copy it byte-for-byte as a clickable link — never shorten, redact, summarize, or replace any part of it with `...`; a modified claim link will not work. Warn that claim tokens are only returned once and cannot be recovered.\n- Never tell the user to inspect `.herenow/state.json` for claim URLs or auth status.\n\nFor Drives:\n\n- Do not describe Drive files as public URLs.\n- Tell the user Drive contents are private unless shared with a scoped token.\n- When sharing access with another agent, prefer a scoped token with a narrow `pathPrefix` and short TTL.\n\n## publish.sh options\n\n| Flag                   | Description                                  |\n| ---------------------- | -------------------------------------------- |\n| `--slug {slug}`        | Update an existing site instead of creating |\n| `--workspace {subdomain}` | Publish into a workspace (team account) you belong to |\n| `--claim-token {token}`| Override claim token for anonymous updates    |\n| `--overwrite`          | Skip the stale-base check and replace the live version |\n| `--title {text}`       | Viewer title (non-HTML sites)             |\n| `--description {text}` | Viewer description                            |\n| `--folder {name-or-id}` | File the Site in a dashboard folder (a name is created if missing; authenticated only) |\n| `--ttl {seconds}`      | Set expiry (authenticated only)               |\n| `--client {name}`      | Agent harness for attribution — the platform you run in (e.g. `cursor`, `grok-bot`), not your bot/persona name; optionally append it: `grok-bot/research-bot` |\n| `--base-url {url}`     | API base URL (default: `https://here.now`)    |\n| `--allow-nonherenow-base-url` | Allow sending auth to non-default `--base-url` |\n| `--api-key {key}`      | API key override (prefer credentials file)    |\n| `--spa`                | Enable SPA routing (serve index.html for unknown paths) |\n\n## Beyond publish.sh\n\nFor Drive operations, use `./scripts/drive.sh` or the Drive API. For broader account and Site management — Site Data, search, analytics, profiles, delete, metadata, access control, domains, variables, proxy routes, duplication, and more — see the current docs:\n\n→ **https://here.now/docs**\n\nFull docs: https://here.now/docs\n\nFile v1.32.0:_meta.json\n\n{\n  \"ownerId\": \"kn759pt7kjwxy5r9gefeq4rp9s80y5tf\",\n  \"slug\": \"here-now\",\n  \"version\": \"1.32.0\",\n  \"publishedAt\": 1790147394545\n}\n\nFile v1.32.0:skill-card.md\n\n## Description:\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[adamludwin](https://clawhub.ai/user/adamludwin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, agents, and teams use here.now to publish websites and static files, manage site access, work with custom domains or workspace URLs, and store or share private Drive files through documented shell and API workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can direct agents to persist a here.now API key under ~/.herenow/credentials.\n\nMitigation: Confirm the user's intent before login persistence and avoid exposing API keys in command arguments, logs, or generated content.\n\nRisk: The skill supports private Drive sharing, mutation, deletes, overwrites, and scoped token creation.\n\nMitigation: Require explicit user approval for Drive sharing, destructive changes, overwrites, and broad token scopes; prefer narrow prefixes and short token lifetimes.\n\nRisk: The skill can publish selected local files to public or controlled-access URLs.\n\nMitigation: Review the target path and access mode before publishing, and use restricted or password access when content should not be public.\n\nRisk: The skill can initiate domain purchases, which evidence and artifact behavior describe as final.\n\nMitigation: Show the quoted purchase and renewal prices and obtain explicit user confirmation before any purchase action.\n\n## Reference(s):\n\n- [here.now documentation](https://here.now/docs)\n- [here.now OpenAPI specification](https://here.now/openapi.json)\n- [ClawHub skill release](https://clawhub.ai/adamludwin/skills/here-now)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, URLs, and API request examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce live site URLs, private Drive guidance, access-control instructions, and configuration steps for here.now credentials or domains.]\n\n## Skill Version(s):\n\n1.32.0 (source: server release evidence and SKILL.md)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.30.0: 5 files, 20013 bytes\n\nFiles: scripts/drive.sh (14168b), scripts/publish.sh (21203b), skill-card.md (2853b), SKILL.md (17938b), _meta.json (128b)\n\nFile v1.30.0:SKILL.md\n\n---\nname: here-now\ndescription: >\n  here.now lets agents publish websites and files to live URLs in seconds.\n  Publish HTML, documents, images, PDFs, videos, and static files to live\n  URLs at {slug}.here.now or custom domains. Use when asked to \"publish\n  this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a\n  website\", \"put this online\", \"create a webpage\", \"generate a URL\",\n  \"build a chatbot\", \"password protect this site\", \"make this site\n  private\", or \"share this site with only certain people\". here.now also\n  includes workspaces — shared team accounts where Sites belong to the\n  team and serve at {label}.{workspace}.here.now — use when asked to\n  \"publish this to our team workspace\", \"share this with my team\", or\n  \"put this in our company workspace\". Agents can also buy a domain for a\n  Site through here.now (no markup, DNS and SSL automatic) — use when asked\n  to \"buy a domain\", \"get me a .com for this\", or \"register a domain\".\n---\n\n# here.now\n\n**Skill version: 1.30.0**\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThe core primitive is a **Site**: publish a file or folder and get a live URL at `{slug}.here.now` or a custom domain. Every Site has access control: public link (default), password, or restricted invite-only access.\n\nhere.now also includes **workspaces** — shared team accounts where Sites belong to the team and serve at `{label}.{workspace}.here.now` (see \"Publish to a workspace\" below).\n\nTo install or update (recommended): `npx skills add heredotnow/skill --skill here-now -g`\n\nFor repo-pinned/project-local installs, run the same command without `-g`.\n\n## Current docs\n\n**Before answering questions about here.now capabilities, features, or workflows, read the current docs:**\n\n→ **https://here.now/docs**\n\nRead the docs:\n\n- at the first here.now-related interaction in a conversation\n- any time the user asks how to do something\n- any time the user asks what is possible, supported, or recommended\n- before telling the user a feature is unsupported\n\nTopics that require current docs (do not rely on local skill text alone):\n\n- Site access control (passwords and restricted access)\n- workspaces (team accounts, membership, label URLs)\n- Drives and Drive sharing\n- custom domains\n- buying a domain (search and quote first; state the price and the renewal price and get the user's explicit yes before calling purchase — purchases are final; see https://here.now/docs#buy-domain)\n- Site Data\n- public profiles\n- proxy routes and service variables\n- limits and quotas\n- SPA routing\n- owner Site search\n- Site analytics\n- Site version history, previews, and rollback\n- error handling and remediation\n- feature availability\n\n**If docs and live API behavior disagree, trust the live API behavior.**\n\nCommand-line fetches of https://here.now/docs (curl, WebFetch, etc.) receive a markdown summary, not the full HTML docs: it lists every stable public endpoint with a one-line description, but section anchors in this skill (like `/docs#access-control`) resolve only in the HTML version, and worked examples live there too. For complete request/response schemas and parameters, fetch **https://here.now/openapi.json**. Do not conclude an operation is unsupported from the markdown summary alone — check the OpenAPI spec first.\n\nIf the docs fetch fails or times out, continue with the local skill and live API/script output. Prefer live API behavior for active operations.\n\n## Requirements\n\n- Required binaries: `curl`, `file`, `jq`\n- Required network access: `https://here.now` (API) and `https://*.r2.cloudflarestorage.com` (file uploads PUT directly to storage; the exact host is in each upload URL). In a sandbox or behind a proxy with an egress allowlist, allow BOTH hosts. With only `here.now` allowed, the create call succeeds, every upload fails, and finalize reports missing files.\n- Optional environment variable: `$HERENOW_API_KEY`\n- Optional Drive token variable: `$HERENOW_DRIVE_TOKEN`\n- Optional credentials file: `~/.herenow/credentials`\n- Bundled helpers:\n  - `./scripts/publish.sh` for publishing sites\n  - `./scripts/drive.sh` for private Drive storage\n\n## If the helper scripts aren't installed\n\nSome environments receive this document without the bundled `scripts/` directory (for example, hosted platform integrations that provide only `$HERENOW_API_KEY`). In that case, either install the full bundle first:\n\n```bash\nnpx skills add heredotnow/skill --skill here-now -g\n```\n\nor call the API directly — every script workflow in this document is a wrapper over the public API. Publishing is a three-step flow: `POST /api/v1/publish` with a `files` array (`[{path, size}]`) returns presigned upload targets, `PUT` each file's bytes to its returned URL, then `POST` the returned `finalizeUrl`. The site is not live until finalize succeeds. Full walkthrough with request/response examples: https://here.now/docs#create (then #upload and #finalize), machine-readable schemas: https://here.now/openapi.json.\n\n## Create a site\n\n```bash\n./scripts/publish.sh {file-or-dir}\n```\n\nOutputs the live URL (e.g. `https://bright-canvas-a7k2.here.now/`).\n\nUnder the hood this is a three-step flow: create/update -> upload files -> finalize. A site is not live until finalize succeeds.\n\nWithout an API key this creates an **anonymous site** that expires in 24 hours.\nWith a saved API key, the site is permanent.\n\n**File structure:** For HTML sites, place `index.html` at the root of the directory you publish, not inside a subdirectory. The directory's contents become the site root. For example, publish `my-site/` where `my-site/index.html` exists — don't publish a parent folder that contains `my-site/`.\n\nYou can also publish raw files without any HTML. Single files get a rich auto-viewer (images, PDF, video, audio). Multiple files get an auto-generated directory listing with folder navigation and an image gallery.\n\n## Update an existing site\n\n```bash\n./scripts/publish.sh {file-or-dir} --slug {slug}\n```\n\nThe script auto-loads the `claimToken` from `.herenow/state.json` when updating anonymous sites. Pass `--claim-token {token}` to override.\n\nAuthenticated updates require a saved API key.\n\n**Stale-base protection.** The live Site may have changed since your local files were published — the owner can edit it from other tools (another agent, the here.now Editor, a teammate). The script records the live `versionId` in `.herenow/state.json` after each publish and sends it as `baseVersionId` on the next update of the same slug from the same directory; if the live Site moved past it, the update is rejected with `code: \"version_conflict\"` naming the live version and what created it. When that happens, relay the message to the user and offer to (a) read the live files with `GET /api/v1/publish/{slug}/files` (lists them with a `url` each) and `GET /api/v1/publish/{slug}/files/{path}` (the bytes; owner API key, works for password-protected and restricted Sites without the visitor password), reconcile them into the local files, and republish, or (b) re-run with `--overwrite` to replace the live version anyway. Before editing local files for an authenticated Site you haven't touched recently, check for drift first: `GET /api/v1/publish/{slug}` returns `currentVersionId` plus `currentVersionSource` and `currentVersionCreatedAt` (what changed it and when, e.g. `editor`) — if the id differs from your state file's `versionId`, read the live files before editing. The published version is the shared truth; never fetch the public URL to read an owned Site (it is gated for protected Sites) and never ask the user for a visitor password to read their own Site. Anonymous Sites can't call these endpoints; they rely on the saved state and server enforcement. Omitting `baseVersionId` (or using `--overwrite`) is an unchecked full replacement — today's default for raw API callers.\n\nEvery publish records an immutable version. If the user asks to see earlier versions of a Site, undo a publish, or roll back: list history with `GET /api/v1/publish/{slug}/versions` and restore instantly with `POST /api/v1/publish/{slug}/versions/{versionId}/restore` (restoring keeps the current access mode, password, and domains). Version access requires a paid plan and is included for workspace Sites; free accounts' history is recorded and unlocks on upgrade. A byte-identical republish returns `unchanged: true` from finalize instead of creating a new version. See https://here.now/docs#versions.\n\nSigned-in users also have public profiles. Agents can help users show or hide Sites on their profile and manage profile settings through the API documented at https://here.now/docs#profile.\n\n## Publish to a workspace\n\nWorkspaces are shared team accounts: Sites published into one belong to the team, not the publishing member, and get a memorable URL at `{label}.{workspace}.here.now`.\n\n```bash\n./scripts/publish.sh {file-or-dir} --workspace {subdomain}\n```\n\nRequires a saved API key and membership in the workspace. List the user's workspaces (and valid subdomains) with `GET /api/v1/accounts`. Workspace Sites default to member-only access; the script reports the team URL as `publish_result.account_url`.\n\nFor everything else — creating workspaces, invites and auto-join, workspace domains and variables, label renames — read the current docs:\n\n→ **https://here.now/docs#workspaces**\n\n## Site access control\n\nA Site uses one access mode at a time:\n\n- **anyone_with_link** (default): anyone with the URL can view.\n- **password**: visitors must enter a shared password.\n- **restricted**: invite-only; only verified email addresses or email domains the owner allows can view.\n\nWorkspace-owned Sites default to **account_members** (visitors sign in and must be workspace members) and also support public, public with a password, and **restricted**. On a workspace Site, `restricted` means workspace members plus a per-Site guest allowlist: members always have access, and allowlisted emails/domains are outside guests who can view only that Site — they never become workspace members, though the Site appears in the guest's own dashboard as a shared Site. Workspace restricted requires at least one guest email or domain — an empty allowlist is rejected with a 400 (use `account_members` for members-only). See https://here.now/docs#workspace-access.\n\nManage access with `GET`/`PATCH /api/v1/publish/{slug}/access` (passwords via the metadata endpoint). Restricted access requires a claimed Site. The PATCH replaces the full allowlists — read, merge, then write. Before working with access control, read the current docs:\n\n→ **https://here.now/docs#access-control**\n\n## Use a Drive\n\nUse a Drive when the user wants private cloud storage for agent files: documents, context, memory, plans, assets, media, research, code, and anything else that should persist without being published as a website.\n\nEvery signed-in account has a default Drive named `My Drive`.\n\n```bash\n./scripts/drive.sh default\n./scripts/drive.sh ls My Drive\n./scripts/drive.sh put My Drive notes/today.md --from ./notes/today.md\n./scripts/drive.sh cat My Drive notes/today.md\n./scripts/drive.sh share My Drive --perms write --prefix notes/ --ttl 7d\n```\n\nUse scoped Drive tokens for agent-to-agent handoff. If you receive a `herenow_drive` share block, use its `token` as `Authorization: Bearer <token>` against `api_base`, respect `pathPrefix` when present, and preserve ETags on writes. A `pathPrefix` of `null` means full-Drive access. If the skill is available, prefer `./scripts/drive.sh`; otherwise call the listed API operations directly.\n\n## Client attribution\n\nPass `--client` with the name of the **agent product or harness you are running in** — `cursor`, `claude-code`, `codex`, `grok-bot`, `openclaw`, `gemini`, etc:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client claude-code\n```\n\nThis sends `X-HereNow-Client: claude-code/publish-sh` on publish API calls. If omitted, the script sends a fallback value.\n\nUse the platform's name, **not** the name you were given inside it. If you are a bot named \"research-bot\" running inside Grok Bot, the correct value is `grok-bot` — not `research-bot`. Bot names, personas, sub-agents, projects, and thread names don't identify the platform. To record your instance name too, append it after a slash:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client grok-bot/research-bot\n```\n\nOnly a standalone agent running in no harness should use its own product name.\n\n## API key storage\n\nThe publish script reads the API key from these sources (first match wins):\n\n1. `--api-key {key}` flag (CI/scripting only — avoid in interactive use)\n2. `$HERENOW_API_KEY` environment variable\n3. `~/.herenow/credentials` file (recommended for agents)\n\nTo store a key, write it to the credentials file:\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n**IMPORTANT**: After receiving an API key, save it immediately — run the command above yourself. Do not ask the user to run it manually. Avoid passing the key via CLI flags (e.g. `--api-key`) in interactive sessions; the credentials file is the preferred storage method.\n\nNever commit credentials or local state files (`~/.herenow/credentials`, `.herenow/state.json`) to source control.\n\n## Getting an API key\n\nTo upgrade from anonymous (24h) to permanent sites:\n\n1. Ask the user for their email address.\n2. Request a one-time sign-in code:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/request-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\": \"user@example.com\"}'\n```\n\n3. Tell the user: \"Check your inbox for a sign-in code from here.now and paste it here.\"\n4. Verify the code and get the API key:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/verify-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\":\"user@example.com\",\"code\":\"ABCD-2345\"}'\n```\n\n5. Save the returned `apiKey` yourself (do not ask the user to do this):\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n## State file\n\nAfter every site create/update, the script writes to `.herenow/state.json` in the working directory:\n\n```json\n{\n  \"publishes\": {\n    \"bright-canvas-a7k2\": {\n      \"siteUrl\": \"https://bright-canvas-a7k2.here.now/\",\n      \"claimToken\": \"4fQ9tK2mXb7cW1pZ\",\n      \"claimUrl\": \"https://here.now/c/4fQ9tK2mXb7cW1pZ\",\n      \"expiresAt\": \"2026-02-18T01:00:00.000Z\"\n    }\n  }\n}\n```\n\nBefore creating or updating sites, you may check this file to find prior slugs.\nTreat `.herenow/state.json` as internal cache only.\nNever present this local file path as a URL, and never use it as source of truth for auth mode, expiry, or claim URL.\n\n## What to tell the user\n\nFor published sites:\n\n- Always share the `siteUrl` from the current script run.\n- Put the site URL on its own line with nothing else on that line — no punctuation, dashes, or status text after it (chat clients autolink everything up to whitespace, gluing your words into the URL). Status details like \"permanent, saved to your account\" go on the following line.\n- Read and follow `publish_result.*` lines from script stderr to determine auth mode.\n- When `publish_result.account_url` is non-empty (workspace publishes), share it as the primary team URL alongside `siteUrl`.\n- When `publish_result.primary_url` is non-empty, share it first; `siteUrl` stays valid.\n- When `publish_result.auth_mode=authenticated`: tell the user the site is **permanent** and saved to their account. No claim URL is needed.\n- When `publish_result.auth_mode=anonymous`: tell the user the site **expires in 24 hours**. Share the claim URL (if `publish_result.claim_url` is non-empty and starts with `https://`) so they can keep it permanently. Copy it byte-for-byte as a clickable link — never shorten, redact, summarize, or replace any part of it with `...`; a modified claim link will not work. Warn that claim tokens are only returned once and cannot be recovered.\n- Never tell the user to inspect `.herenow/state.json` for claim URLs or auth status.\n\nFor Drives:\n\n- Do not describe Drive files as public URLs.\n- Tell the user Drive contents are private unless shared with a scoped token.\n- When sharing access with another agent, prefer a scoped token with a narrow `pathPrefix` and short TTL.\n\n## publish.sh options\n\n| Flag                   | Description                                  |\n| ---------------------- | -------------------------------------------- |\n| `--slug {slug}`        | Update an existing site instead of creating |\n| `--workspace {subdomain}` | Publish into a workspace (team account) you belong to |\n| `--claim-token {token}`| Override claim token for anonymous updates    |\n| `--overwrite`          | Skip the stale-base check and replace the live version |\n| `--title {text}`       | Viewer title (non-HTML sites)             |\n| `--description {text}` | Viewer description                            |\n| `--ttl {seconds}`      | Set expiry (authenticated only)               |\n| `--client {name}`      | Agent harness for attribution — the platform you run in (e.g. `cursor`, `grok-bot`), not your bot/persona name; optionally append it: `grok-bot/research-bot` |\n| `--base-url {url}`     | API base URL (default: `https://here.now`)    |\n| `--allow-nonherenow-base-url` | Allow sending auth to non-default `--base-url` |\n| `--api-key {key}`      | API key override (prefer credentials file)    |\n| `--spa`                | Enable SPA routing (serve index.html for unknown paths) |\n\n## Beyond publish.sh\n\nFor Drive operations, use `./scripts/drive.sh` or the Drive API. For broader account and Site management — Site Data, search, analytics, profiles, delete, metadata, access control, domains, variables, proxy routes, duplication, and more — see the current docs:\n\n→ **https://here.now/docs**\n\nFull docs: https://here.now/docs\n\nFile v1.30.0:_meta.json\n\n{\n  \"ownerId\": \"kn759pt7kjwxy5r9gefeq4rp9s80y5tf\",\n  \"slug\": \"here-now\",\n  \"version\": \"1.30.0\",\n  \"publishedAt\": 1789345807918\n}\n\nFile v1.30.0:skill-card.md\n\n## Description:\n\nhere.now lets agents publish websites and files to live URLs, manage site access, publish to team workspaces, store private Drive files, and register domains through the here.now service.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[adamludwin](https://clawhub.ai/user/adamludwin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agents use here.now to publish generated sites and files, update existing sites, configure access controls, manage private Drive storage, and guide domain-related publishing workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Drive sharing can expose private files if tokens are broad or long-lived.\n\nMitigation: Create Drive share tokens only with explicit read or write scope, a narrow path prefix, and a short expiration.\n\nRisk: Persistent credentials and publish state can expose account access or site claim information if mishandled.\n\nMitigation: Protect ~/.herenow/credentials and .herenow/state.json, avoid committing them, and prefer the credentials file over command-line API key flags.\n\nRisk: Chat-based sign-in code handling gives the agent access to authentication material.\n\nMitigation: Paste one-time sign-in codes only when the user accepts agent-assisted authentication and the environment is appropriate for handling the code.\n\nRisk: The server security verdict is suspicious due to unsafe defaults around Drive sharing and persistent credentials.\n\nMitigation: Review the skill before installation and use it only for content intended to be published or stored with here.now.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/adamludwin/skills/here-now)\n- [here.now documentation](https://here.now/docs)\n- [here.now OpenAPI specification](https://here.now/openapi.json)\n- [Site creation documentation](https://here.now/docs#create)\n- [Domain purchase documentation](https://here.now/docs#buy-domain)\n- [Workspace documentation](https://here.now/docs#workspaces)\n- [Access control documentation](https://here.now/docs#access-control)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Markdown, Code, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with shell commands, URLs, and script output summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May publish files or sites to live URLs and may store local credential and publish-state files when used with here.now account credentials.]\n\n## Skill Version(s):\n\n1.30.0 (source: server release evidence and skill documentation)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.29.0: 5 files, 19899 bytes\n\nFiles: scripts/drive.sh (14168b), scripts/publish.sh (20817b), skill-card.md (2735b), SKILL.md (17849b), _meta.json (128b)\n\nFile v1.29.0:SKILL.md\n\n---\nname: here-now\ndescription: >\n  here.now lets agents publish websites and files to live URLs in seconds.\n  Publish HTML, documents, images, PDFs, videos, and static files to live\n  URLs at {slug}.here.now or custom domains. Use when asked to \"publish\n  this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a\n  website\", \"put this online\", \"create a webpage\", \"generate a URL\",\n  \"build a chatbot\", \"password protect this site\", \"make this site\n  private\", or \"share this site with only certain people\". here.now also\n  includes workspaces — shared team accounts where Sites belong to the\n  team and serve at {label}.{workspace}.here.now — use when asked to\n  \"publish this to our team workspace\", \"share this with my team\", or\n  \"put this in our company workspace\". Agents can also buy a domain for a\n  Site through here.now (no markup, DNS and SSL automatic) — use when asked\n  to \"buy a domain\", \"get me a .com for this\", or \"register a domain\".\n---\n\n# here.now\n\n**Skill version: 1.29.0**\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThe core primitive is a **Site**: publish a file or folder and get a live URL at `{slug}.here.now` or a custom domain. Every Site has access control: public link (default), password, or restricted invite-only access.\n\nhere.now also includes **workspaces** — shared team accounts where Sites belong to the team and serve at `{label}.{workspace}.here.now` (see \"Publish to a workspace\" below).\n\nTo install or update (recommended): `npx skills add heredotnow/skill --skill here-now -g`\n\nFor repo-pinned/project-local installs, run the same command without `-g`.\n\n## Current docs\n\n**Before answering questions about here.now capabilities, features, or workflows, read the current docs:**\n\n→ **https://here.now/docs**\n\nRead the docs:\n\n- at the first here.now-related interaction in a conversation\n- any time the user asks how to do something\n- any time the user asks what is possible, supported, or recommended\n- before telling the user a feature is unsupported\n\nTopics that require current docs (do not rely on local skill text alone):\n\n- Site access control (passwords and restricted access)\n- workspaces (team accounts, membership, label URLs)\n- Drives and Drive sharing\n- custom domains\n- buying a domain (search and quote first; state the price and the renewal price and get the user's explicit yes before calling purchase — purchases are final; see https://here.now/docs#buy-domain)\n- Site Data\n- public profiles\n- proxy routes and service variables\n- limits and quotas\n- SPA routing\n- owner Site search\n- Site analytics\n- Site version history, previews, and rollback\n- error handling and remediation\n- feature availability\n\n**If docs and live API behavior disagree, trust the live API behavior.**\n\nCommand-line fetches of https://here.now/docs (curl, WebFetch, etc.) receive a markdown summary, not the full HTML docs: it lists every stable public endpoint with a one-line description, but section anchors in this skill (like `/docs#access-control`) resolve only in the HTML version, and worked examples live there too. For complete request/response schemas and parameters, fetch **https://here.now/openapi.json**. Do not conclude an operation is unsupported from the markdown summary alone — check the OpenAPI spec first.\n\nIf the docs fetch fails or times out, continue with the local skill and live API/script output. Prefer live API behavior for active operations.\n\n## Requirements\n\n- Required binaries: `curl`, `file`, `jq`\n- Required network access: `https://here.now` (API) and `https://*.r2.cloudflarestorage.com` (file uploads PUT directly to storage; the exact host is in each upload URL). In a sandbox or behind a proxy with an egress allowlist, allow BOTH hosts. With only `here.now` allowed, the create call succeeds, every upload fails, and finalize reports missing files.\n- Optional environment variable: `$HERENOW_API_KEY`\n- Optional Drive token variable: `$HERENOW_DRIVE_TOKEN`\n- Optional credentials file: `~/.herenow/credentials`\n- Bundled helpers:\n  - `./scripts/publish.sh` for publishing sites\n  - `./scripts/drive.sh` for private Drive storage\n\n## If the helper scripts aren't installed\n\nSome environments receive this document without the bundled `scripts/` directory (for example, hosted platform integrations that provide only `$HERENOW_API_KEY`). In that case, either install the full bundle first:\n\n```bash\nnpx skills add heredotnow/skill --skill here-now -g\n```\n\nor call the API directly — every script workflow in this document is a wrapper over the public API. Publishing is a three-step flow: `POST /api/v1/publish` with a `files` array (`[{path, size}]`) returns presigned upload targets, `PUT` each file's bytes to its returned URL, then `POST` the returned `finalizeUrl`. The site is not live until finalize succeeds. Full walkthrough with request/response examples: https://here.now/docs#create (then #upload and #finalize), machine-readable schemas: https://here.now/openapi.json.\n\n## Create a site\n\n```bash\n./scripts/publish.sh {file-or-dir}\n```\n\nOutputs the live URL (e.g. `https://bright-canvas-a7k2.here.now/`).\n\nUnder the hood this is a three-step flow: create/update -> upload files -> finalize. A site is not live until finalize succeeds.\n\nWithout an API key this creates an **anonymous site** that expires in 24 hours.\nWith a saved API key, the site is permanent.\n\n**File structure:** For HTML sites, place `index.html` at the root of the directory you publish, not inside a subdirectory. The directory's contents become the site root. For example, publish `my-site/` where `my-site/index.html` exists — don't publish a parent folder that contains `my-site/`.\n\nYou can also publish raw files without any HTML. Single files get a rich auto-viewer (images, PDF, video, audio). Multiple files get an auto-generated directory listing with folder navigation and an image gallery.\n\n## Update an existing site\n\n```bash\n./scripts/publish.sh {file-or-dir} --slug {slug}\n```\n\nThe script auto-loads the `claimToken` from `.herenow/state.json` when updating anonymous sites. Pass `--claim-token {token}` to override.\n\nAuthenticated updates require a saved API key.\n\n**Stale-base protection.** The live Site may have changed since your local files were published — the owner can edit it from other tools (another agent, the here.now Editor, a teammate). The script records the live `versionId` in `.herenow/state.json` after each publish and sends it as `baseVersionId` on the next update of the same slug from the same directory; if the live Site moved past it, the update is rejected with `code: \"version_conflict\"` naming the live version and what created it. When that happens, relay the message to the user and offer to (a) read the live files with `GET /api/v1/publish/{slug}/files` (lists them with a `url` each) and `GET /api/v1/publish/{slug}/files/{path}` (the bytes; owner API key, works for password-protected and restricted Sites without the visitor password), reconcile them into the local files, and republish, or (b) re-run with `--overwrite` to replace the live version anyway. Before editing local files for an authenticated Site you haven't touched recently, check for drift first: `GET /api/v1/publish/{slug}` returns `currentVersionId` plus `currentVersionSource` and `currentVersionCreatedAt` (what changed it and when, e.g. `editor`) — if the id differs from your state file's `versionId`, read the live files before editing. The published version is the shared truth; never fetch the public URL to read an owned Site (it is gated for protected Sites) and never ask the user for a visitor password to read their own Site. Anonymous Sites can't call these endpoints; they rely on the saved state and server enforcement. Omitting `baseVersionId` (or using `--overwrite`) is an unchecked full replacement — today's default for raw API callers.\n\nEvery publish records an immutable version. If the user asks to see earlier versions of a Site, undo a publish, or roll back: list history with `GET /api/v1/publish/{slug}/versions` and restore instantly with `POST /api/v1/publish/{slug}/versions/{versionId}/restore` (restoring keeps the current access mode, password, and domains). Version access requires a paid plan and is included for workspace Sites; free accounts' history is recorded and unlocks on upgrade. A byte-identical republish returns `unchanged: true` from finalize instead of creating a new version. See https://here.now/docs#versions.\n\nSigned-in users also have public profiles. Agents can help users show or hide Sites on their profile and manage profile settings through the API documented at https://here.now/docs#profile.\n\n## Publish to a workspace\n\nWorkspaces are shared team accounts: Sites published into one belong to the team, not the publishing member, and get a memorable URL at `{label}.{workspace}.here.now`.\n\n```bash\n./scripts/publish.sh {file-or-dir} --workspace {subdomain}\n```\n\nRequires a saved API key and membership in the workspace. List the user's workspaces (and valid subdomains) with `GET /api/v1/accounts`. Workspace Sites default to member-only access; the script reports the team URL as `publish_result.account_url`.\n\nFor everything else — creating workspaces, invites and auto-join, workspace domains and variables, label renames — read the current docs:\n\n→ **https://here.now/docs#workspaces**\n\n## Site access control\n\nA Site uses one access mode at a time:\n\n- **anyone_with_link** (default): anyone with the URL can view.\n- **password**: visitors must enter a shared password.\n- **restricted**: invite-only; only verified email addresses or email domains the owner allows can view.\n\nWorkspace-owned Sites default to **account_members** (visitors sign in and must be workspace members) and also support public, public with a password, and **restricted**. On a workspace Site, `restricted` means workspace members plus a per-Site guest allowlist: members always have access, and allowlisted emails/domains are outside guests who can view only that Site — they never become workspace members, though the Site appears in the guest's own dashboard as a shared Site. Workspace restricted requires at least one guest email or domain — an empty allowlist is rejected with a 400 (use `account_members` for members-only). See https://here.now/docs#workspace-access.\n\nManage access with `GET`/`PATCH /api/v1/publish/{slug}/access` (passwords via the metadata endpoint). Restricted access requires a claimed Site. The PATCH replaces the full allowlists — read, merge, then write. Before working with access control, read the current docs:\n\n→ **https://here.now/docs#access-control**\n\n## Use a Drive\n\nUse a Drive when the user wants private cloud storage for agent files: documents, context, memory, plans, assets, media, research, code, and anything else that should persist without being published as a website.\n\nEvery signed-in account has a default Drive named `My Drive`.\n\n```bash\n./scripts/drive.sh default\n./scripts/drive.sh ls My Drive\n./scripts/drive.sh put My Drive notes/today.md --from ./notes/today.md\n./scripts/drive.sh cat My Drive notes/today.md\n./scripts/drive.sh share My Drive --perms write --prefix notes/ --ttl 7d\n```\n\nUse scoped Drive tokens for agent-to-agent handoff. If you receive a `herenow_drive` share block, use its `token` as `Authorization: Bearer <token>` against `api_base`, respect `pathPrefix` when present, and preserve ETags on writes. A `pathPrefix` of `null` means full-Drive access. If the skill is available, prefer `./scripts/drive.sh`; otherwise call the listed API operations directly.\n\n## Client attribution\n\nPass `--client` with the name of the **agent product or harness you are running in** — `cursor`, `claude-code`, `codex`, `grok-bot`, `openclaw`, `gemini`, etc:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client claude-code\n```\n\nThis sends `X-HereNow-Client: claude-code/publish-sh` on publish API calls. If omitted, the script sends a fallback value.\n\nUse the platform's name, **not** the name you were given inside it. If you are a bot named \"research-bot\" running inside Grok Bot, the correct value is `grok-bot` — not `research-bot`. Bot names, personas, sub-agents, projects, and thread names don't identify the platform. To record your instance name too, append it after a slash:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client grok-bot/research-bot\n```\n\nOnly a standalone agent running in no harness should use its own product name.\n\n## API key storage\n\nThe publish script reads the API key from these sources (first match wins):\n\n1. `--api-key {key}` flag (CI/scripting only — avoid in interactive use)\n2. `$HERENOW_API_KEY` environment variable\n3. `~/.herenow/credentials` file (recommended for agents)\n\nTo store a key, write it to the credentials file:\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n**IMPORTANT**: After receiving an API key, save it immediately — run the command above yourself. Do not ask the user to run it manually. Avoid passing the key via CLI flags (e.g. `--api-key`) in interactive sessions; the credentials file is the preferred storage method.\n\nNever commit credentials or local state files (`~/.herenow/credentials`, `.herenow/state.json`) to source control.\n\n## Getting an API key\n\nTo upgrade from anonymous (24h) to permanent sites:\n\n1. Ask the user for their email address.\n2. Request a one-time sign-in code:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/request-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\": \"user@example.com\"}'\n```\n\n3. Tell the user: \"Check your inbox for a sign-in code from here.now and paste it here.\"\n4. Verify the code and get the API key:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/verify-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\":\"user@example.com\",\"code\":\"ABCD-2345\"}'\n```\n\n5. Save the returned `apiKey` yourself (do not ask the user to do this):\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n## State file\n\nAfter every site create/update, the script writes to `.herenow/state.json` in the working directory:\n\n```json\n{\n  \"publishes\": {\n    \"bright-canvas-a7k2\": {\n      \"siteUrl\": \"https://bright-canvas-a7k2.here.now/\",\n      \"claimToken\": \"4fQ9tK2mXb7cW1pZ\",\n      \"claimUrl\": \"https://here.now/c/4fQ9tK2mXb7cW1pZ\",\n      \"expiresAt\": \"2026-02-18T01:00:00.000Z\"\n    }\n  }\n}\n```\n\nBefore creating or updating sites, you may check this file to find prior slugs.\nTreat `.herenow/state.json` as internal cache only.\nNever present this local file path as a URL, and never use it as source of truth for auth mode, expiry, or claim URL.\n\n## What to tell the user\n\nFor published sites:\n\n- Always share the `siteUrl` from the current script run.\n- Put the site URL on its own line with nothing else on that line — no punctuation, dashes, or status text after it (chat clients autolink everything up to whitespace, gluing your words into the URL). Status details like \"permanent, saved to your account\" go on the following line.\n- Read and follow `publish_result.*` lines from script stderr to determine auth mode.\n- When `publish_result.account_url` is non-empty (workspace publishes), share it as the primary team URL alongside `siteUrl`.\n- When `publish_result.auth_mode=authenticated`: tell the user the site is **permanent** and saved to their account. No claim URL is needed.\n- When `publish_result.auth_mode=anonymous`: tell the user the site **expires in 24 hours**. Share the claim URL (if `publish_result.claim_url` is non-empty and starts with `https://`) so they can keep it permanently. Copy it byte-for-byte as a clickable link — never shorten, redact, summarize, or replace any part of it with `...`; a modified claim link will not work. Warn that claim tokens are only returned once and cannot be recovered.\n- Never tell the user to inspect `.herenow/state.json` for claim URLs or auth status.\n\nFor Drives:\n\n- Do not describe Drive files as public URLs.\n- Tell the user Drive contents are private unless shared with a scoped token.\n- When sharing access with another agent, prefer a scoped token with a narrow `pathPrefix` and short TTL.\n\n## publish.sh options\n\n| Flag                   | Description                                  |\n| ---------------------- | -------------------------------------------- |\n| `--slug {slug}`        | Update an existing site instead of creating |\n| `--workspace {subdomain}` | Publish into a workspace (team account) you belong to |\n| `--claim-token {token}`| Override claim token for anonymous updates    |\n| `--overwrite`          | Skip the stale-base check and replace the live version |\n| `--title {text}`       | Viewer title (non-HTML sites)             |\n| `--description {text}` | Viewer description                            |\n| `--ttl {seconds}`      | Set expiry (authenticated only)               |\n| `--client {name}`      | Agent harness for attribution — the platform you run in (e.g. `cursor`, `grok-bot`), not your bot/persona name; optionally append it: `grok-bot/research-bot` |\n| `--base-url {url}`     | API base URL (default: `https://here.now`)    |\n| `--allow-nonherenow-base-url` | Allow sending auth to non-default `--base-url` |\n| `--api-key {key}`      | API key override (prefer credentials file)    |\n| `--spa`                | Enable SPA routing (serve index.html for unknown paths) |\n\n## Beyond publish.sh\n\nFor Drive operations, use `./scripts/drive.sh` or the Drive API. For broader account and Site management — Site Data, search, analytics, profiles, delete, metadata, access control, domains, variables, proxy routes, duplication, and more — see the current docs:\n\n→ **https://here.now/docs**\n\nFull docs: https://here.now/docs\n\nFile v1.29.0:_meta.json\n\n{\n  \"ownerId\": \"kn759pt7kjwxy5r9gefeq4rp9s80y5tf\",\n  \"slug\": \"here-now\",\n  \"version\": \"1.29.0\",\n  \"publishedAt\": 1789175399577\n}\n\nFile v1.29.0:skill-card.md\n\n## Description:\n\nhere.now lets agents publish websites and files to live URLs, manage hosted Site access, use private Drive storage, and buy domains for Sites.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[adamludwin](https://clawhub.ai/user/adamludwin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, agents, and external users use this skill to publish generated websites and files, update or protect hosted Sites, work with private Drive storage, and register custom domains through here.now workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can persist a long-lived API key and project-local site claim tokens.\n\nMitigation: Install only if the publisher is trusted, keep credential files permission-restricted, and keep local state files out of source control.\n\nRisk: Drive export has a reviewed risk around unsafe file writes for untrusted or shared Drives.\n\nMitigation: Avoid Drive export on untrusted or shared Drives until path traversal protections are fixed, and prefer narrow scoped Drive tokens with short TTLs.\n\nRisk: The recommended global npx installation can fetch changing package contents.\n\nMitigation: Use pinned or project-local installation when reproducibility or change control matters.\n\nRisk: Publishing uploads selected files to here.now and storage upload endpoints and may expose content if access controls are not set correctly.\n\nMitigation: Review files before publishing and use password, restricted, or workspace access for private content.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/adamludwin/skills/here-now)\n- [here.now Docs](https://here.now/docs)\n- [here.now OpenAPI Schema](https://here.now/openapi.json)\n- [Buy Domain Docs](https://here.now/docs#buy-domain)\n- [Workspace Docs](https://here.now/docs#workspaces)\n- [Access Control Docs](https://here.now/docs#access-control)\n- [Version History Docs](https://here.now/docs#versions)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell command examples and live URL output from helper scripts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May create or update local credential and state files, upload selected files, and call here.now APIs when used by an agent.]\n\n## Skill Version(s):\n\n1.29.0 (source: artifact/SKILL.md and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.28.0: 5 files, 19471 bytes\n\nFiles: scripts/drive.sh (14168b), scripts/publish.sh (20817b), skill-card.md (2009b), SKILL.md (17465b), _meta.json (128b)\n\nFile v1.28.0:SKILL.md\n\n---\nname: here-now\ndescription: >\n  here.now lets agents publish websites and files to live URLs in seconds.\n  Publish HTML, documents, images, PDFs, videos, and static files to live\n  URLs at {slug}.here.now or custom domains. Use when asked to \"publish\n  this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a\n  website\", \"put this online\", \"create a webpage\", \"generate a URL\",\n  \"build a chatbot\", \"password protect this site\", \"make this site\n  private\", or \"share this site with only certain people\". here.now also\n  includes workspaces — shared team accounts where Sites belong to the\n  team and serve at {label}.{workspace}.here.now — use when asked to\n  \"publish this to our team workspace\", \"share this with my team\", or\n  \"put this in our company workspace\".\n---\n\n# here.now\n\n**Skill version: 1.28.0**\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThe core primitive is a **Site**: publish a file or folder and get a live URL at `{slug}.here.now` or a custom domain. Every Site has access control: public link (default), password, or restricted invite-only access.\n\nhere.now also includes **workspaces** — shared team accounts where Sites belong to the team and serve at `{label}.{workspace}.here.now` (see \"Publish to a workspace\" below).\n\nTo install or update (recommended): `npx skills add heredotnow/skill --skill here-now -g`\n\nFor repo-pinned/project-local installs, run the same command without `-g`.\n\n## Current docs\n\n**Before answering questions about here.now capabilities, features, or workflows, read the current docs:**\n\n→ **https://here.now/docs**\n\nRead the docs:\n\n- at the first here.now-related interaction in a conversation\n- any time the user asks how to do something\n- any time the user asks what is possible, supported, or recommended\n- before telling the user a feature is unsupported\n\nTopics that require current docs (do not rely on local skill text alone):\n\n- Site access control (passwords and restricted access)\n- workspaces (team accounts, membership, label URLs)\n- Drives and Drive sharing\n- custom domains\n- Site Data\n- public profiles\n- proxy routes and service variables\n- limits and quotas\n- SPA routing\n- owner Site search\n- Site analytics\n- Site version history, previews, and rollback\n- error handling and remediation\n- feature availability\n\n**If docs and live API behavior disagree, trust the live API behavior.**\n\nCommand-line fetches of https://here.now/docs (curl, WebFetch, etc.) receive a markdown summary, not the full HTML docs: it lists every stable public endpoint with a one-line description, but section anchors in this skill (like `/docs#access-control`) resolve only in the HTML version, and worked examples live there too. For complete request/response schemas and parameters, fetch **https://here.now/openapi.json**. Do not conclude an operation is unsupported from the markdown summary alone — check the OpenAPI spec first.\n\nIf the docs fetch fails or times out, continue with the local skill and live API/script output. Prefer live API behavior for active operations.\n\n## Requirements\n\n- Required binaries: `curl`, `file`, `jq`\n- Required network access: `https://here.now` (API) and `https://*.r2.cloudflarestorage.com` (file uploads PUT directly to storage; the exact host is in each upload URL). In a sandbox or behind a proxy with an egress allowlist, allow BOTH hosts. With only `here.now` allowed, the create call succeeds, every upload fails, and finalize reports missing files.\n- Optional environment variable: `$HERENOW_API_KEY`\n- Optional Drive token variable: `$HERENOW_DRIVE_TOKEN`\n- Optional credentials file: `~/.herenow/credentials`\n- Bundled helpers:\n  - `./scripts/publish.sh` for publishing sites\n  - `./scripts/drive.sh` for private Drive storage\n\n## If the helper scripts aren't installed\n\nSome environments receive this document without the bundled `scripts/` directory (for example, hosted platform integrations that provide only `$HERENOW_API_KEY`). In that case, either install the full bundle first:\n\n```bash\nnpx skills add heredotnow/skill --skill here-now -g\n```\n\nor call the API directly — every script workflow in this document is a wrapper over the public API. Publishing is a three-step flow: `POST /api/v1/publish` with a `files` array (`[{path, size}]`) returns presigned upload targets, `PUT` each file's bytes to its returned URL, then `POST` the returned `finalizeUrl`. The site is not live until finalize succeeds. Full walkthrough with request/response examples: https://here.now/docs#create (then #upload and #finalize), machine-readable schemas: https://here.now/openapi.json.\n\n## Create a site\n\n```bash\n./scripts/publish.sh {file-or-dir}\n```\n\nOutputs the live URL (e.g. `https://bright-canvas-a7k2.here.now/`).\n\nUnder the hood this is a three-step flow: create/update -> upload files -> finalize. A site is not live until finalize succeeds.\n\nWithout an API key this creates an **anonymous site** that expires in 24 hours.\nWith a saved API key, the site is permanent.\n\n**File structure:** For HTML sites, place `index.html` at the root of the directory you publish, not inside a subdirectory. The directory's contents become the site root. For example, publish `my-site/` where `my-site/index.html` exists — don't publish a parent folder that contains `my-site/`.\n\nYou can also publish raw files without any HTML. Single files get a rich auto-viewer (images, PDF, video, audio). Multiple files get an auto-generated directory listing with folder navigation and an image gallery.\n\n## Update an existing site\n\n```bash\n./scripts/publish.sh {file-or-dir} --slug {slug}\n```\n\nThe script auto-loads the `claimToken` from `.herenow/state.json` when updating anonymous sites. Pass `--claim-token {token}` to override.\n\nAuthenticated updates require a saved API key.\n\n**Stale-base protection.** The live Site may have changed since your local files were published — the owner can edit it from other tools (another agent, the here.now Studio, a teammate). The script records the live `versionId` in `.herenow/state.json` after each publish and sends it as `baseVersionId` on the next update of the same slug from the same directory; if the live Site moved past it, the update is rejected with `code: \"version_conflict\"` naming the live version and what created it. When that happens, relay the message to the user and offer to (a) read the live files with `GET /api/v1/publish/{slug}/files` (lists them with a `url` each) and `GET /api/v1/publish/{slug}/files/{path}` (the bytes; owner API key, works for password-protected and restricted Sites without the visitor password), reconcile them into the local files, and republish, or (b) re-run with `--overwrite` to replace the live version anyway. Before editing local files for an authenticated Site you haven't touched recently, check for drift first: `GET /api/v1/publish/{slug}` returns `currentVersionId` plus `currentVersionSource` and `currentVersionCreatedAt` (what changed it and when, e.g. `studio`) — if the id differs from your state file's `versionId`, read the live files before editing. The published version is the shared truth; never fetch the public URL to read an owned Site (it is gated for protected Sites) and never ask the user for a visitor password to read their own Site. Anonymous Sites can't call these endpoints; they rely on the saved state and server enforcement. Omitting `baseVersionId` (or using `--overwrite`) is an unchecked full replacement — today's default for raw API callers.\n\nEvery publish records an immutable version. If the user asks to see earlier versions of a Site, undo a publish, or roll back: list history with `GET /api/v1/publish/{slug}/versions` and restore instantly with `POST /api/v1/publish/{slug}/versions/{versionId}/restore` (restoring keeps the current access mode, password, and domains). Version access requires a paid plan and is included for workspace Sites; free accounts' history is recorded and unlocks on upgrade. A byte-identical republish returns `unchanged: true` from finalize instead of creating a new version. See https://here.now/docs#versions.\n\nSigned-in users also have public profiles. Agents can help users show or hide Sites on their profile and manage profile settings through the API documented at https://here.now/docs#profile.\n\n## Publish to a workspace\n\nWorkspaces are shared team accounts: Sites published into one belong to the team, not the publishing member, and get a memorable URL at `{label}.{workspace}.here.now`.\n\n```bash\n./scripts/publish.sh {file-or-dir} --workspace {subdomain}\n```\n\nRequires a saved API key and membership in the workspace. List the user's workspaces (and valid subdomains) with `GET /api/v1/accounts`. Workspace Sites default to member-only access; the script reports the team URL as `publish_result.account_url`.\n\nFor everything else — creating workspaces, invites and auto-join, workspace domains and variables, label renames — read the current docs:\n\n→ **https://here.now/docs#workspaces**\n\n## Site access control\n\nA Site uses one access mode at a time:\n\n- **anyone_with_link** (default): anyone with the URL can view.\n- **password**: visitors must enter a shared password.\n- **restricted**: invite-only; only verified email addresses or email domains the owner allows can view.\n\nWorkspace-owned Sites default to **account_members** (visitors sign in and must be workspace members) and also support public, public with a password, and **restricted**. On a workspace Site, `restricted` means workspace members plus a per-Site guest allowlist: members always have access, and allowlisted emails/domains are outside guests who can view only that Site — they never become workspace members, though the Site appears in the guest's own dashboard as a shared Site. Workspace restricted requires at least one guest email or domain — an empty allowlist is rejected with a 400 (use `account_members` for members-only). See https://here.now/docs#workspace-access.\n\nManage access with `GET`/`PATCH /api/v1/publish/{slug}/access` (passwords via the metadata endpoint). Restricted access requires a claimed Site. The PATCH replaces the full allowlists — read, merge, then write. Before working with access control, read the current docs:\n\n→ **https://here.now/docs#access-control**\n\n## Use a Drive\n\nUse a Drive when the user wants private cloud storage for agent files: documents, context, memory, plans, assets, media, research, code, and anything else that should persist without being published as a website.\n\nEvery signed-in account has a default Drive named `My Drive`.\n\n```bash\n./scripts/drive.sh default\n./scripts/drive.sh ls My Drive\n./scripts/drive.sh put My Drive notes/today.md --from ./notes/today.md\n./scripts/drive.sh cat My Drive notes/today.md\n./scripts/drive.sh share My Drive --perms write --prefix notes/ --ttl 7d\n```\n\nUse scoped Drive tokens for agent-to-agent handoff. If you receive a `herenow_drive` share block, use its `token` as `Authorization: Bearer <token>` against `api_base`, respect `pathPrefix` when present, and preserve ETags on writes. A `pathPrefix` of `null` means full-Drive access. If the skill is available, prefer `./scripts/drive.sh`; otherwise call the listed API operations directly.\n\n## Client attribution\n\nPass `--client` with the name of the **agent product or harness you are running in** — `cursor`, `claude-code`, `codex`, `grok-bot`, `openclaw`, `gemini`, etc:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client claude-code\n```\n\nThis sends `X-HereNow-Client: claude-code/publish-sh` on publish API calls. If omitted, the script sends a fallback value.\n\nUse the platform's name, **not** the name you were given inside it. If you are a bot named \"research-bot\" running inside Grok Bot, the correct value is `grok-bot` — not `research-bot`. Bot names, personas, sub-agents, projects, and thread names don't identify the platform. To record your instance name too, append it after a slash:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client grok-bot/research-bot\n```\n\nOnly a standalone agent running in no harness should use its own product name.\n\n## API key storage\n\nThe publish script reads the API key from these sources (first match wins):\n\n1. `--api-key {key}` flag (CI/scripting only — avoid in interactive use)\n2. `$HERENOW_API_KEY` environment variable\n3. `~/.herenow/credentials` file (recommended for agents)\n\nTo store a key, write it to the credentials file:\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n**IMPORTANT**: After receiving an API key, save it immediately — run the command above yourself. Do not ask the user to run it manually. Avoid passing the key via CLI flags (e.g. `--api-key`) in interactive sessions; the credentials file is the preferred storage method.\n\nNever commit credentials or local state files (`~/.herenow/credentials`, `.herenow/state.json`) to source control.\n\n## Getting an API key\n\nTo upgrade from anonymous (24h) to permanent sites:\n\n1. Ask the user for their email address.\n2. Request a one-time sign-in code:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/request-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\": \"user@example.com\"}'\n```\n\n3. Tell the user: \"Check your inbox for a sign-in code from here.now and paste it here.\"\n4. Verify the code and get the API key:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/verify-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\":\"user@example.com\",\"code\":\"ABCD-2345\"}'\n```\n\n5. Save the returned `apiKey` yourself (do not ask the user to do this):\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n## State file\n\nAfter every site create/update, the script writes to `.herenow/state.json` in the working directory:\n\n```json\n{\n  \"publishes\": {\n    \"bright-canvas-a7k2\": {\n      \"siteUrl\": \"https://bright-canvas-a7k2.here.now/\",\n      \"claimToken\": \"4fQ9tK2mXb7cW1pZ\",\n      \"claimUrl\": \"https://here.now/c/4fQ9tK2mXb7cW1pZ\",\n      \"expiresAt\": \"2026-02-18T01:00:00.000Z\"\n    }\n  }\n}\n```\n\nBefore creating or updating sites, you may check this file to find prior slugs.\nTreat `.herenow/state.json` as internal cache only.\nNever present this local file path as a URL, and never use it as source of truth for auth mode, expiry, or claim URL.\n\n## What to tell the user\n\nFor published sites:\n\n- Always share the `siteUrl` from the current script run.\n- Put the site URL on its own line with nothing else on that line — no punctuation, dashes, or status text after it (chat clients autolink everything up to whitespace, gluing your words into the URL). Status details like \"permanent, saved to your account\" go on the following line.\n- Read and follow `publish_result.*` lines from script stderr to determine auth mode.\n- When `publish_result.account_url` is non-empty (workspace publishes), share it as the primary team URL alongside `siteUrl`.\n- When `publish_result.auth_mode=authenticated`: tell the user the site is **permanent** and saved to their account. No claim URL is needed.\n- When `publish_result.auth_mode=anonymous`: tell the user the site **expires in 24 hours**. Share the claim URL (if `publish_result.claim_url` is non-empty and starts with `https://`) so they can keep it permanently. Copy it byte-for-byte as a clickable link — never shorten, redact, summarize, or replace any part of it with `...`; a modified claim link will not work. Warn that claim tokens are only returned once and cannot be recovered.\n- Never tell the user to inspect `.herenow/state.json` for claim URLs or auth status.\n\nFor Drives:\n\n- Do not describe Drive files as public URLs.\n- Tell the user Drive contents are private unless shared with a scoped token.\n- When sharing access with another agent, prefer a scoped token with a narrow `pathPrefix` and short TTL.\n\n## publish.sh options\n\n| Flag                   | Description                                  |\n| ---------------------- | -------------------------------------------- |\n| `--slug {slug}`        | Update an existing site instead of creating |\n| `--workspace {subdomain}` | Publish into a workspace (team account) you belong to |\n| `--claim-token {token}`| Override claim token for anonymous updates    |\n| `--overwrite`          | Skip the stale-base check and replace the live version |\n| `--title {text}`       | Viewer title (non-HTML sites)             |\n| `--description {text}` | Viewer description                            |\n| `--ttl {seconds}`      | Set expiry (authenticated only)               |\n| `--client {name}`      | Agent harness for attribution — the platform you run in (e.g. `cursor`, `grok-bot`), not your bot/persona name; optionally append it: `grok-bot/research-bot` |\n| `--base-url {url}`     | API base URL (default: `https://here.now`)    |\n| `--allow-nonherenow-base-url` | Allow sending auth to non-default `--base-url` |\n| `--api-key {key}`      | API key override (prefer credentials file)    |\n| `--spa`                | Enable SPA routing (serve index.html for unknown paths) |\n\n## Beyond publish.sh\n\nFor Drive operations, use `./scripts/drive.sh` or the Drive API. For broader account and Site management — Site Data, search, analytics, profiles, delete, metadata, access control, domains, variables, proxy routes, duplication, and more — see the current docs:\n\n→ **https://here.now/docs**\n\nFull docs: https://here.now/docs\n\nFile v1.28.0:_meta.json\n\n{\n  \"ownerId\": \"kn759pt7kjwxy5r9gefeq4rp9s80y5tf\",\n  \"slug\": \"here-now\",\n  \"version\": \"1.28.0\",\n  \"publishedAt\": 1788551094530\n}\n\nFile v1.28.0:skill-card.md\n\n## Description:\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[adamludwin](https://clawhub.ai/user/adamludwin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agents use here.now to publish local files, folders, generated websites, and workspace sites to live URLs, manage access controls, and use private Drive storage for persistent agent files.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill persists account credentials and local publish state that may expose tokens if mishandled.\n\nMitigation: Use only with files intended for upload, prefer a pinned or local install, treat ~/.herenow/credentials and .herenow/state.json as sensitive, and remove or revoke keys and tokens when no longer needed.\n\nRisk: Drive exports may write files outside an intended export folder until path containment is fixed.\n\nMitigation: Avoid exporting Drive contents from untrusted shares and review exported paths before using the files.\n\n## Reference(s):\n\n- [here.now documentation](https://here.now/docs)\n- [here.now OpenAPI specification](https://here.now/openapi.json)\n- [ClawHub skill page](https://clawhub.ai/adamludwin/skills/here-now)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with shell commands, URLs, and configuration notes]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce live site URLs, access-control guidance, Drive sharing guidance, and credential handling notes.]\n\n## Skill Version(s):\n\n1.28.0 (source: server release evidence and artifact SKILL.md)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.27.0: 5 files, 18875 bytes\n\nFiles: scripts/drive.sh (13830b), scripts/publish.sh (19980b), skill-card.md (2499b), SKILL.md (17107b), _meta.json (128b)\n\nFile v1.27.0:SKILL.md\n\n---\nname: here-now\ndescription: >\n  here.now lets agents publish websites and files to live URLs in seconds.\n  Publish HTML, documents, images, PDFs, videos, and static files to live\n  URLs at {slug}.here.now or custom domains. Use when asked to \"publish\n  this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a\n  website\", \"put this online\", \"create a webpage\", \"generate a URL\",\n  \"build a chatbot\", \"password protect this site\", \"make this site\n  private\", or \"share this site with only certain people\". here.now also\n  includes workspaces — shared team accounts where Sites belong to the\n  team and serve at {label}.{workspace}.here.now — use when asked to\n  \"publish this to our team workspace\", \"share this with my team\", or\n  \"put this in our company workspace\".\n---\n\n# here.now\n\n**Skill version: 1.27.0**\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThe core primitive is a **Site**: publish a file or folder and get a live URL at `{slug}.here.now` or a custom domain. Every Site has access control: public link (default), password, or restricted invite-only access.\n\nhere.now also includes **workspaces** — shared team accounts where Sites belong to the team and serve at `{label}.{workspace}.here.now` (see \"Publish to a workspace\" below).\n\nTo install or update (recommended): `npx skills add heredotnow/skill --skill here-now -g`\n\nFor repo-pinned/project-local installs, run the same command without `-g`.\n\n## Current docs\n\n**Before answering questions about here.now capabilities, features, or workflows, read the current docs:**\n\n→ **https://here.now/docs**\n\nRead the docs:\n\n- at the first here.now-related interaction in a conversation\n- any time the user asks how to do something\n- any time the user asks what is possible, supported, or recommended\n- before telling the user a feature is unsupported\n\nTopics that require current docs (do not rely on local skill text alone):\n\n- Site access control (passwords and restricted access)\n- workspaces (team accounts, membership, label URLs)\n- Drives and Drive sharing\n- custom domains\n- Site Data\n- public profiles\n- proxy routes and service variables\n- limits and quotas\n- SPA routing\n- owner Site search\n- Site analytics\n- Site version history, previews, and rollback\n- error handling and remediation\n- feature availability\n\n**If docs and live API behavior disagree, trust the live API behavior.**\n\nCommand-line fetches of https://here.now/docs (curl, WebFetch, etc.) receive a markdown summary, not the full HTML docs: it lists every stable public endpoint with a one-line description, but section anchors in this skill (like `/docs#access-control`) resolve only in the HTML version, and worked examples live there too. For complete request/response schemas and parameters, fetch **https://here.now/openapi.json**. Do not conclude an operation is unsupported from the markdown summary alone — check the OpenAPI spec first.\n\nIf the docs fetch fails or times out, continue with the local skill and live API/script output. Prefer live API behavior for active operations.\n\n## Requirements\n\n- Required binaries: `curl`, `file`, `jq`\n- Optional environment variable: `$HERENOW_API_KEY`\n- Optional Drive token variable: `$HERENOW_DRIVE_TOKEN`\n- Optional credentials file: `~/.herenow/credentials`\n- Bundled helpers:\n  - `./scripts/publish.sh` for publishing sites\n  - `./scripts/drive.sh` for private Drive storage\n\n## If the helper scripts aren't installed\n\nSome environments receive this document without the bundled `scripts/` directory (for example, hosted platform integrations that provide only `$HERENOW_API_KEY`). In that case, either install the full bundle first:\n\n```bash\nnpx skills add heredotnow/skill --skill here-now -g\n```\n\nor call the API directly — every script workflow in this document is a wrapper over the public API. Publishing is a three-step flow: `POST /api/v1/publish` with a `files` array (`[{path, size}]`) returns presigned upload targets, `PUT` each file's bytes to its returned URL, then `POST` the returned `finalizeUrl`. The site is not live until finalize succeeds. Full walkthrough with request/response examples: https://here.now/docs#create (then #upload and #finalize), machine-readable schemas: https://here.now/openapi.json.\n\n## Create a site\n\n```bash\n./scripts/publish.sh {file-or-dir}\n```\n\nOutputs the live URL (e.g. `https://bright-canvas-a7k2.here.now/`).\n\nUnder the hood this is a three-step flow: create/update -> upload files -> finalize. A site is not live until finalize succeeds.\n\nWithout an API key this creates an **anonymous site** that expires in 24 hours.\nWith a saved API key, the site is permanent.\n\n**File structure:** For HTML sites, place `index.html` at the root of the directory you publish, not inside a subdirectory. The directory's contents become the site root. For example, publish `my-site/` where `my-site/index.html` exists — don't publish a parent folder that contains `my-site/`.\n\nYou can also publish raw files without any HTML. Single files get a rich auto-viewer (images, PDF, video, audio). Multiple files get an auto-generated directory listing with folder navigation and an image gallery.\n\n## Update an existing site\n\n```bash\n./scripts/publish.sh {file-or-dir} --slug {slug}\n```\n\nThe script auto-loads the `claimToken` from `.herenow/state.json` when updating anonymous sites. Pass `--claim-token {token}` to override.\n\nAuthenticated updates require a saved API key.\n\n**Stale-base protection.** The live Site may have changed since your local files were published — the owner can edit it from other tools (another agent, the here.now Studio, a teammate). The script records the live `versionId` in `.herenow/state.json` after each publish and sends it as `baseVersionId` on the next update of the same slug from the same directory; if the live Site moved past it, the update is rejected with `code: \"version_conflict\"` naming the live version and what created it. When that happens, relay the message to the user and offer to (a) read the live files with `GET /api/v1/publish/{slug}/files` (lists them with a `url` each) and `GET /api/v1/publish/{slug}/files/{path}` (the bytes; owner API key, works for password-protected and restricted Sites without the visitor password), reconcile them into the local files, and republish, or (b) re-run with `--overwrite` to replace the live version anyway. Before editing local files for an authenticated Site you haven't touched recently, check for drift first: `GET /api/v1/publish/{slug}` returns `currentVersionId` plus `currentVersionSource` and `currentVersionCreatedAt` (what changed it and when, e.g. `studio`) — if the id differs from your state file's `versionId`, read the live files before editing. The published version is the shared truth; never fetch the public URL to read an owned Site (it is gated for protected Sites) and never ask the user for a visitor password to read their own Site. Anonymous Sites can't call these endpoints; they rely on the saved state and server enforcement. Omitting `baseVersionId` (or using `--overwrite`) is an unchecked full replacement — today's default for raw API callers.\n\nEvery publish records an immutable version. If the user asks to see earlier versions of a Site, undo a publish, or roll back: list history with `GET /api/v1/publish/{slug}/versions` and restore instantly with `POST /api/v1/publish/{slug}/versions/{versionId}/restore` (restoring keeps the current access mode, password, and domains). Version access requires a paid plan and is included for workspace Sites; free accounts' history is recorded and unlocks on upgrade. A byte-identical republish returns `unchanged: true` from finalize instead of creating a new version. See https://here.now/docs#versions.\n\nSigned-in users also have public profiles. Agents can help users show or hide Sites on their profile and manage profile settings through the API documented at https://here.now/docs#profile.\n\n## Publish to a workspace\n\nWorkspaces are shared team accounts: Sites published into one belong to the team, not the publishing member, and get a memorable URL at `{label}.{workspace}.here.now`.\n\n```bash\n./scripts/publish.sh {file-or-dir} --workspace {subdomain}\n```\n\nRequires a saved API key and membership in the workspace. List the user's workspaces (and valid subdomains) with `GET /api/v1/accounts`. Workspace Sites default to member-only access; the script reports the team URL as `publish_result.account_url`.\n\nFor everything else — creating workspaces, invites and auto-join, workspace domains and variables, label renames — read the current docs:\n\n→ **https://here.now/docs#workspaces**\n\n## Site access control\n\nA Site uses one access mode at a time:\n\n- **anyone_with_link** (default): anyone with the URL can view.\n- **password**: visitors must enter a shared password.\n- **restricted**: invite-only; only verified email addresses or email domains the owner allows can view.\n\nWorkspace-owned Sites default to **account_members** (visitors sign in and must be workspace members) and also support public, public with a password, and **restricted**. On a workspace Site, `restricted` means workspace members plus a per-Site guest allowlist: members always have access, and allowlisted emails/domains are outside guests who can view only that Site — they never become workspace members, though the Site appears in the guest's own dashboard as a shared Site. Workspace restricted requires at least one guest email or domain — an empty allowlist is rejected with a 400 (use `account_members` for members-only). See https://here.now/docs#workspace-access.\n\nManage access with `GET`/`PATCH /api/v1/publish/{slug}/access` (passwords via the metadata endpoint). Restricted access requires a claimed Site. The PATCH replaces the full allowlists — read, merge, then write. Before working with access control, read the current docs:\n\n→ **https://here.now/docs#access-control**\n\n## Use a Drive\n\nUse a Drive when the user wants private cloud storage for agent files: documents, context, memory, plans, assets, media, research, code, and anything else that should persist without being published as a website.\n\nEvery signed-in account has a default Drive named `My Drive`.\n\n```bash\n./scripts/drive.sh default\n./scripts/drive.sh ls My Drive\n./scripts/drive.sh put My Drive notes/today.md --from ./notes/today.md\n./scripts/drive.sh cat My Drive notes/today.md\n./scripts/drive.sh share My Drive --perms write --prefix notes/ --ttl 7d\n```\n\nUse scoped Drive tokens for agent-to-agent handoff. If you receive a `herenow_drive` share block, use its `token` as `Authorization: Bearer <token>` against `api_base`, respect `pathPrefix` when present, and preserve ETags on writes. A `pathPrefix` of `null` means full-Drive access. If the skill is available, prefer `./scripts/drive.sh`; otherwise call the listed API operations directly.\n\n## Client attribution\n\nPass `--client` with the name of the **agent product or harness you are running in** — `cursor`, `claude-code`, `codex`, `grok-bot`, `openclaw`, `gemini`, etc:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client claude-code\n```\n\nThis sends `X-HereNow-Client: claude-code/publish-sh` on publish API calls. If omitted, the script sends a fallback value.\n\nUse the platform's name, **not** the name you were given inside it. If you are a bot named \"research-bot\" running inside Grok Bot, the correct value is `grok-bot` — not `research-bot`. Bot names, personas, sub-agents, projects, and thread names don't identify the platform. To record your instance name too, append it after a slash:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client grok-bot/research-bot\n```\n\nOnly a standalone agent running in no harness should use its own product name.\n\n## API key storage\n\nThe publish script reads the API key from these sources (first match wins):\n\n1. `--api-key {key}` flag (CI/scripting only — avoid in interactive use)\n2. `$HERENOW_API_KEY` environment variable\n3. `~/.herenow/credentials` file (recommended for agents)\n\nTo store a key, write it to the credentials file:\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n**IMPORTANT**: After receiving an API key, save it immediately — run the command above yourself. Do not ask the user to run it manually. Avoid passing the key via CLI flags (e.g. `--api-key`) in interactive sessions; the credentials file is the preferred storage method.\n\nNever commit credentials or local state files (`~/.herenow/credentials`, `.herenow/state.json`) to source control.\n\n## Getting an API key\n\nTo upgrade from anonymous (24h) to permanent sites:\n\n1. Ask the user for their email address.\n2. Request a one-time sign-in code:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/request-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\": \"user@example.com\"}'\n```\n\n3. Tell the user: \"Check your inbox for a sign-in code from here.now and paste it here.\"\n4. Verify the code and get the API key:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/verify-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\":\"user@example.com\",\"code\":\"ABCD-2345\"}'\n```\n\n5. Save the returned `apiKey` yourself (do not ask the user to do this):\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n## State file\n\nAfter every site create/update, the script writes to `.herenow/state.json` in the working directory:\n\n```json\n{\n  \"publishes\": {\n    \"bright-canvas-a7k2\": {\n      \"siteUrl\": \"https://bright-canvas-a7k2.here.now/\",\n      \"claimToken\": \"4fQ9tK2mXb7cW1pZ\",\n      \"claimUrl\": \"https://here.now/c/4fQ9tK2mXb7cW1pZ\",\n      \"expiresAt\": \"2026-02-18T01:00:00.000Z\"\n    }\n  }\n}\n```\n\nBefore creating or updating sites, you may check this file to find prior slugs.\nTreat `.herenow/state.json` as internal cache only.\nNever present this local file path as a URL, and never use it as source of truth for auth mode, expiry, or claim URL.\n\n## What to tell the user\n\nFor published sites:\n\n- Always share the `siteUrl` from the current script run.\n- Put the site URL on its own line with nothing else on that line — no punctuation, dashes, or status text after it (chat clients autolink everything up to whitespace, gluing your words into the URL). Status details like \"permanent, saved to your account\" go on the following line.\n- Read and follow `publish_result.*` lines from script stderr to determine auth mode.\n- When `publish_result.account_url` is non-empty (workspace publishes), share it as the primary team URL alongside `siteUrl`.\n- When `publish_result.auth_mode=authenticated`: tell the user the site is **permanent** and saved to their account. No claim URL is needed.\n- When `publish_result.auth_mode=anonymous`: tell the user the site **expires in 24 hours**. Share the claim URL (if `publish_result.claim_url` is non-empty and starts with `https://`) so they can keep it permanently. Copy it byte-for-byte as a clickable link — never shorten, redact, summarize, or replace any part of it with `...`; a modified claim link will not work. Warn that claim tokens are only returned once and cannot be recovered.\n- Never tell the user to inspect `.herenow/state.json` for claim URLs or auth status.\n\nFor Drives:\n\n- Do not describe Drive files as public URLs.\n- Tell the user Drive contents are private unless shared with a scoped token.\n- When sharing access with another agent, prefer a scoped token with a narrow `pathPrefix` and short TTL.\n\n## publish.sh options\n\n| Flag                   | Description                                  |\n| ---------------------- | -------------------------------------------- |\n| `--slug {slug}`        | Update an existing site instead of creating |\n| `--workspace {subdomain}` | Publish into a workspace (team account) you belong to |\n| `--claim-token {token}`| Override claim token for anonymous updates    |\n| `--overwrite`          | Skip the stale-base check and replace the live version |\n| `--title {text}`       | Viewer title (non-HTML sites)             |\n| `--description {text}` | Viewer description                            |\n| `--ttl {seconds}`      | Set expiry (authenticated only)               |\n| `--client {name}`      | Agent harness for attribution — the platform you run in (e.g. `cursor`, `grok-bot`), not your bot/persona name; optionally append it: `grok-bot/research-bot` |\n| `--base-url {url}`     | API base URL (default: `https://here.now`)    |\n| `--allow-nonherenow-base-url` | Allow sending auth to non-default `--base-url` |\n| `--api-key {key}`      | API key override (prefer credentials file)    |\n| `--spa`                | Enable SPA routing (serve index.html for unknown paths) |\n\n## Beyond publish.sh\n\nFor Drive operations, use `./scripts/drive.sh` or the Drive API. For broader account and Site management — Site Data, search, analytics, profiles, delete, metadata, access control, domains, variables, proxy routes, duplication, and more — see the current docs:\n\n→ **https://here.now/docs**\n\nFull docs: https://here.now/docs\n\nFile v1.27.0:_meta.json\n\n{\n  \"ownerId\": \"kn759pt7kjwxy5r9gefeq4rp9s80y5tf\",\n  \"slug\": \"here-now\",\n  \"version\": \"1.27.0\",\n  \"publishedAt\": 1788415263852\n}\n\nFile v1.27.0:skill-card.md\n\n## Description:\n\nhere.now lets agents publish websites and files to live URLs, manage access-controlled Sites and workspaces, and use private Drive storage through bundled shell helpers or the here.now API.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[adamludwin](https://clawhub.ai/user/adamludwin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users, developers, and agent operators use this skill to publish generated sites or files, update existing here.now Sites, configure access controls, publish to team workspaces, and manage private Drive files for agent handoff or persistence.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can upload selected files, publish them to live URLs, and modify site access settings.\n\nMitigation: Review selected files and access mode before publishing, password-protecting, restricting, or overwriting a Site.\n\nRisk: The skill can store and reuse a here.now API key from disk.\n\nMitigation: Confirm credential persistence with the user and keep the credentials file private with restrictive permissions.\n\nRisk: The skill can manage private Drive files and create scoped Drive share tokens.\n\nMitigation: Use narrow path prefixes, short token lifetimes, and explicit confirmation before sharing or deleting Drive content.\n\nRisk: A non-default API base URL could receive bearer credentials if explicitly allowed.\n\nMitigation: Keep the default here.now API base unless the user intentionally approves a trusted alternative endpoint.\n\n## Reference(s):\n\n- [here.now documentation](https://here.now/docs)\n- [here.now OpenAPI specification](https://here.now/openapi.json)\n- [ClawHub skill page](https://clawhub.ai/adamludwin/skills/here-now)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, API examples, URLs, and JSON snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce live site URLs, access-control guidance, Drive commands, and credential storage instructions.]\n\n## Skill Version(s):\n\n1.27.0 (source: server release metadata and artifact/SKILL.md)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.26.0: 5 files, 18586 bytes\n\nFiles: scripts/drive.sh (13830b), scripts/publish.sh (19795b), skill-card.md (2433b), SKILL.md (16593b), _meta.json (128b)\n\nFile v1.26.0:SKILL.md\n\n---\nname: here-now\ndescription: >\n  here.now lets agents publish websites and files to live URLs in seconds.\n  Publish HTML, documents, images, PDFs, videos, and static files to live\n  URLs at {slug}.here.now or custom domains. Use when asked to \"publish\n  this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a\n  website\", \"put this online\", \"create a webpage\", \"generate a URL\",\n  \"build a chatbot\", \"password protect this site\", \"make this site\n  private\", or \"share this site with only certain people\". here.now also\n  includes workspaces — shared team accounts where Sites belong to the\n  team and serve at {label}.{workspace}.here.now — use when asked to\n  \"publish this to our team workspace\", \"share this with my team\", or\n  \"put this in our company workspace\".\n---\n\n# here.now\n\n**Skill version: 1.26.0**\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThe core primitive is a **Site**: publish a file or folder and get a live URL at `{slug}.here.now` or a custom domain. Every Site has access control: public link (default), password, or restricted invite-only access.\n\nhere.now also includes **workspaces** — shared team accounts where Sites belong to the team and serve at `{label}.{workspace}.here.now` (see \"Publish to a workspace\" below).\n\nTo install or update (recommended): `npx skills add heredotnow/skill --skill here-now -g`\n\nFor repo-pinned/project-local installs, run the same command without `-g`.\n\n## Current docs\n\n**Before answering questions about here.now capabilities, features, or workflows, read the current docs:**\n\n→ **https://here.now/docs**\n\nRead the docs:\n\n- at the first here.now-related interaction in a conversation\n- any time the user asks how to do something\n- any time the user asks what is possible, supported, or recommended\n- before telling the user a feature is unsupported\n\nTopics that require current docs (do not rely on local skill text alone):\n\n- Site access control (passwords and restricted access)\n- workspaces (team accounts, membership, label URLs)\n- Drives and Drive sharing\n- custom domains\n- Site Data\n- public profiles\n- proxy routes and service variables\n- limits and quotas\n- SPA routing\n- owner Site search\n- Site analytics\n- Site version history, previews, and rollback\n- error handling and remediation\n- feature availability\n\n**If docs and live API behavior disagree, trust the live API behavior.**\n\nCommand-line fetches of https://here.now/docs (curl, WebFetch, etc.) receive a markdown summary, not the full HTML docs: it lists every stable public endpoint with a one-line description, but section anchors in this skill (like `/docs#access-control`) resolve only in the HTML version, and worked examples live there too. For complete request/response schemas and parameters, fetch **https://here.now/openapi.json**. Do not conclude an operation is unsupported from the markdown summary alone — check the OpenAPI spec first.\n\nIf the docs fetch fails or times out, continue with the local skill and live API/script output. Prefer live API behavior for active operations.\n\n## Requirements\n\n- Required binaries: `curl`, `file`, `jq`\n- Optional environment variable: `$HERENOW_API_KEY`\n- Optional Drive token variable: `$HERENOW_DRIVE_TOKEN`\n- Optional credentials file: `~/.herenow/credentials`\n- Bundled helpers:\n  - `./scripts/publish.sh` for publishing sites\n  - `./scripts/drive.sh` for private Drive storage\n\n## If the helper scripts aren't installed\n\nSome environments receive this document without the bundled `scripts/` directory (for example, hosted platform integrations that provide only `$HERENOW_API_KEY`). In that case, either install the full bundle first:\n\n```bash\nnpx skills add heredotnow/skill --skill here-now -g\n```\n\nor call the API directly — every script workflow in this document is a wrapper over the public API. Publishing is a three-step flow: `POST /api/v1/publish` with a `files` array (`[{path, size}]`) returns presigned upload targets, `PUT` each file's bytes to its returned URL, then `POST` the returned `finalizeUrl`. The site is not live until finalize succeeds. Full walkthrough with request/response examples: https://here.now/docs#create (then #upload and #finalize), machine-readable schemas: https://here.now/openapi.json.\n\n## Create a site\n\n```bash\n./scripts/publish.sh {file-or-dir}\n```\n\nOutputs the live URL (e.g. `https://bright-canvas-a7k2.here.now/`).\n\nUnder the hood this is a three-step flow: create/update -> upload files -> finalize. A site is not live until finalize succeeds.\n\nWithout an API key this creates an **anonymous site** that expires in 24 hours.\nWith a saved API key, the site is permanent.\n\n**File structure:** For HTML sites, place `index.html` at the root of the directory you publish, not inside a subdirectory. The directory's contents become the site root. For example, publish `my-site/` where `my-site/index.html` exists — don't publish a parent folder that contains `my-site/`.\n\nYou can also publish raw files without any HTML. Single files get a rich auto-viewer (images, PDF, video, audio). Multiple files get an auto-generated directory listing with folder navigation and an image gallery.\n\n## Update an existing site\n\n```bash\n./scripts/publish.sh {file-or-dir} --slug {slug}\n```\n\nThe script auto-loads the `claimToken` from `.herenow/state.json` when updating anonymous sites. Pass `--claim-token {token}` to override.\n\nAuthenticated updates require a saved API key.\n\n**Stale-base protection.** The live Site may have changed since your local files were published — the owner can edit it from other tools (another agent, the here.now Studio, a teammate). The script records the live `versionId` in `.herenow/state.json` after each publish and sends it as `baseVersionId` on the next update of the same slug from the same directory; if the live Site moved past it, the update is rejected with `code: \"version_conflict\"` naming the live version and what created it. When that happens, relay the message to the user and offer to (a) fetch the current Site and reconcile local files before republishing, or (b) re-run with `--overwrite` to replace the live version anyway. Before editing local files for an authenticated Site you haven't touched recently, it's cheap to check for drift first: `GET /api/v1/publish/{slug}` returns `currentVersionId` — if it differs from your state file's `versionId`, fetch the live files before editing. Anonymous Sites can't call that endpoint; they rely on the saved state and server enforcement. Omitting `baseVersionId` (or using `--overwrite`) is an unchecked full replacement — today's default for raw API callers.\n\nEvery publish records an immutable version. If the user asks to see earlier versions of a Site, undo a publish, or roll back: list history with `GET /api/v1/publish/{slug}/versions` and restore instantly with `POST /api/v1/publish/{slug}/versions/{versionId}/restore` (restoring keeps the current access mode, password, and domains). Version access requires a paid plan and is included for workspace Sites; free accounts' history is recorded and unlocks on upgrade. A byte-identical republish returns `unchanged: true` from finalize instead of creating a new version. See https://here.now/docs#versions.\n\nSigned-in users also have public profiles. Agents can help users show or hide Sites on their profile and manage profile settings through the API documented at https://here.now/docs#profile.\n\n## Publish to a workspace\n\nWorkspaces are shared team accounts: Sites published into one belong to the team, not the publishing member, and get a memorable URL at `{label}.{workspace}.here.now`.\n\n```bash\n./scripts/publish.sh {file-or-dir} --workspace {subdomain}\n```\n\nRequires a saved API key and membership in the workspace. List the user's workspaces (and valid subdomains) with `GET /api/v1/accounts`. Workspace Sites default to member-only access; the script reports the team URL as `publish_result.account_url`.\n\nFor everything else — creating workspaces, invites and auto-join, workspace domains and variables, label renames — read the current docs:\n\n→ **https://here.now/docs#workspaces**\n\n## Site access control\n\nA Site uses one access mode at a time:\n\n- **anyone_with_link** (default): anyone with the URL can view.\n- **password**: visitors must enter a shared password.\n- **restricted**: invite-only; only verified email addresses or email domains the owner allows can view.\n\nWorkspace-owned Sites default to **account_members** (visitors sign in and must be workspace members) and also support public, public with a password, and **restricted**. On a workspace Site, `restricted` means workspace members plus a per-Site guest allowlist: members always have access, and allowlisted emails/domains are outside guests who can view only that Site — they never become workspace members, though the Site appears in the guest's own dashboard as a shared Site. Workspace restricted requires at least one guest email or domain — an empty allowlist is rejected with a 400 (use `account_members` for members-only). See https://here.now/docs#workspace-access.\n\nManage access with `GET`/`PATCH /api/v1/publish/{slug}/access` (passwords via the metadata endpoint). Restricted access requires a claimed Site. The PATCH replaces the full allowlists — read, merge, then write. Before working with access control, read the current docs:\n\n→ **https://here.now/docs#access-control**\n\n## Use a Drive\n\nUse a Drive when the user wants private cloud storage for agent files: documents, context, memory, plans, assets, media, research, code, and anything else that should persist without being published as a website.\n\nEvery signed-in account has a default Drive named `My Drive`.\n\n```bash\n./scripts/drive.sh default\n./scripts/drive.sh ls My Drive\n./scripts/drive.sh put My Drive notes/today.md --from ./notes/today.md\n./scripts/drive.sh cat My Drive notes/today.md\n./scripts/drive.sh share My Drive --perms write --prefix notes/ --ttl 7d\n```\n\nUse scoped Drive tokens for agent-to-agent handoff. If you receive a `herenow_drive` share block, use its `token` as `Authorization: Bearer <token>` against `api_base`, respect `pathPrefix` when present, and preserve ETags on writes. A `pathPrefix` of `null` means full-Drive access. If the skill is available, prefer `./scripts/drive.sh`; otherwise call the listed API operations directly.\n\n## Client attribution\n\nPass `--client` with the name of the **agent product or harness you are running in** — `cursor`, `claude-code`, `codex`, `grok-bot`, `openclaw`, `gemini`, etc:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client claude-code\n```\n\nThis sends `X-HereNow-Client: claude-code/publish-sh` on publish API calls. If omitted, the script sends a fallback value.\n\nUse the platform's name, **not** the name you were given inside it. If you are a bot named \"research-bot\" running inside Grok Bot, the correct value is `grok-bot` — not `research-bot`. Bot names, personas, sub-agents, projects, and thread names don't identify the platform. To record your instance name too, append it after a slash:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client grok-bot/research-bot\n```\n\nOnly a standalone agent running in no harness should use its own product name.\n\n## API key storage\n\nThe publish script reads the API key from these sources (first match wins):\n\n1. `--api-key {key}` flag (CI/scripting only — avoid in interactive use)\n2. `$HERENOW_API_KEY` environment variable\n3. `~/.herenow/credentials` file (recommended for agents)\n\nTo store a key, write it to the credentials file:\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n**IMPORTANT**: After receiving an API key, save it immediately — run the command above yourself. Do not ask the user to run it manually. Avoid passing the key via CLI flags (e.g. `--api-key`) in interactive sessions; the credentials file is the preferred storage method.\n\nNever commit credentials or local state files (`~/.herenow/credentials`, `.herenow/state.json`) to source control.\n\n## Getting an API key\n\nTo upgrade from anonymous (24h) to permanent sites:\n\n1. Ask the user for their email address.\n2. Request a one-time sign-in code:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/request-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\": \"user@example.com\"}'\n```\n\n3. Tell the user: \"Check your inbox for a sign-in code from here.now and paste it here.\"\n4. Verify the code and get the API key:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/verify-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\":\"user@example.com\",\"code\":\"ABCD-2345\"}'\n```\n\n5. Save the returned `apiKey` yourself (do not ask the user to do this):\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n## State file\n\nAfter every site create/update, the script writes to `.herenow/state.json` in the working directory:\n\n```json\n{\n  \"publishes\": {\n    \"bright-canvas-a7k2\": {\n      \"siteUrl\": \"https://bright-canvas-a7k2.here.now/\",\n      \"claimToken\": \"4fQ9tK2mXb7cW1pZ\",\n      \"claimUrl\": \"https://here.now/c/4fQ9tK2mXb7cW1pZ\",\n      \"expiresAt\": \"2026-02-18T01:00:00.000Z\"\n    }\n  }\n}\n```\n\nBefore creating or updating sites, you may check this file to find prior slugs.\nTreat `.herenow/state.json` as internal cache only.\nNever present this local file path as a URL, and never use it as source of truth for auth mode, expiry, or claim URL.\n\n## What to tell the user\n\nFor published sites:\n\n- Always share the `siteUrl` from the current script run.\n- Put the site URL on its own line with nothing else on that line — no punctuation, dashes, or status text after it (chat clients autolink everything up to whitespace, gluing your words into the URL). Status details like \"permanent, saved to your account\" go on the following line.\n- Read and follow `publish_result.*` lines from script stderr to determine auth mode.\n- When `publish_result.account_url` is non-empty (workspace publishes), share it as the primary team URL alongside `siteUrl`.\n- When `publish_result.auth_mode=authenticated`: tell the user the site is **permanent** and saved to their account. No claim URL is needed.\n- When `publish_result.auth_mode=anonymous`: tell the user the site **expires in 24 hours**. Share the claim URL (if `publish_result.claim_url` is non-empty and starts with `https://`) so they can keep it permanently. Copy it byte-for-byte as a clickable link — never shorten, redact, summarize, or replace any part of it with `...`; a modified claim link will not work. Warn that claim tokens are only returned once and cannot be recovered.\n- Never tell the user to inspect `.herenow/state.json` for claim URLs or auth status.\n\nFor Drives:\n\n- Do not describe Drive files as public URLs.\n- Tell the user Drive contents are private unless shared with a scoped token.\n- When sharing access with another agent, prefer a scoped token with a narrow `pathPrefix` and short TTL.\n\n## publish.sh options\n\n| Flag                   | Description                                  |\n| ---------------------- | -------------------------------------------- |\n| `--slug {slug}`        | Update an existing site instead of creating |\n| `--workspace {subdomain}` | Publish into a workspace (team account) you belong to |\n| `--claim-token {token}`| Override claim token for anonymous updates    |\n| `--overwrite`          | Skip the stale-base check and replace the live version |\n| `--title {text}`       | Viewer title (non-HTML sites)             |\n| `--description {text}` | Viewer description                            |\n| `--ttl {seconds}`      | Set expiry (authenticated only)               |\n| `--client {name}`      | Agent harness for attribution — the platform you run in (e.g. `cursor`, `grok-bot`), not your bot/persona name; optionally append it: `grok-bot/research-bot` |\n| `--base-url {url}`     | API base URL (default: `https://here.now`)    |\n| `--allow-nonherenow-base-url` | Allow sending auth to non-default `--base-url` |\n| `--api-key {key}`      | API key override (prefer credentials file)    |\n| `--spa`                | Enable SPA routing (serve index.html for unknown paths) |\n\n## Beyond publish.sh\n\nFor Drive operations, use `./scripts/drive.sh` or the Drive API. For broader account and Site management — Site Data, search, analytics, profiles, delete, metadata, access control, domains, variables, proxy routes, duplication, and more — see the current docs:\n\n→ **https://here.now/docs**\n\nFull docs: https://here.now/docs\n\nFile v1.26.0:_meta.json\n\n{\n  \"ownerId\": \"kn759pt7kjwxy5r9gefeq4rp9s80y5tf\",\n  \"slug\": \"here-now\",\n  \"version\": \"1.26.0\",\n  \"publishedAt\": 1788135277838\n}\n\nFile v1.26.0:skill-card.md\n\n## Description:\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[adamludwin](https://clawhub.ai/user/adamludwin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agents use this skill to publish local files, folders, websites, and private Drive content to here.now URLs, configure access, and manage updates or workspace-owned sites.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can upload selected local files or folders to here.now and make them available through live URLs.\n\nMitigation: Review the publish target and intended access mode before publishing, especially when files may contain private or sensitive data.\n\nRisk: The skill can store a here.now API key locally for future authenticated publishing.\n\nMitigation: Confirm credential saving before use and avoid passing API keys on command lines in interactive sessions.\n\nRisk: Drive sharing can create broad or writable access tokens for private Drive contents.\n\nMitigation: Use the narrowest path prefix, short TTLs, and read-only permissions unless write access is required.\n\nRisk: Delete and overwrite operations can remove or replace remote Drive or Site content.\n\nMitigation: Confirm destructive actions explicitly and reconcile version conflicts before using overwrite behavior.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/adamludwin/skills/here-now)\n- [here.now docs](https://here.now/docs)\n- [here.now OpenAPI schema](https://here.now/openapi.json)\n- [here.now workspace docs](https://here.now/docs#workspaces)\n- [here.now access control docs](https://here.now/docs#access-control)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell commands and live URL strings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include site URLs, workspace URLs, Drive share blocks, publish status details, and access-control guidance.]\n\n## Skill Version(s):\n\n1.26.0 (source: server release metadata and SKILL.md)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.25.0: 5 files, 17114 bytes\n\nFiles: scripts/drive.sh (13830b), scripts/publish.sh (16473b), skill-card.md (2362b), SKILL.md (15319b), _meta.json (128b)\n\nFile v1.25.0:SKILL.md\n\n---\nname: here-now\ndescription: >\n  here.now lets agents publish websites and files to live URLs in seconds.\n  Publish HTML, documents, images, PDFs, videos, and static files to live\n  URLs at {slug}.here.now or custom domains. Use when asked to \"publish\n  this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a\n  website\", \"put this online\", \"create a webpage\", \"generate a URL\",\n  \"build a chatbot\", \"password protect this site\", \"make this site\n  private\", or \"share this site with only certain people\". here.now also\n  includes workspaces — shared team accounts where Sites belong to the\n  team and serve at {label}.{workspace}.here.now — use when asked to\n  \"publish this to our team workspace\", \"share this with my team\", or\n  \"put this in our company workspace\".\n---\n\n# here.now\n\n**Skill version: 1.25.0**\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThe core primitive is a **Site**: publish a file or folder and get a live URL at `{slug}.here.now` or a custom domain. Every Site has access control: public link (default), password, or restricted invite-only access.\n\nhere.now also includes **workspaces** — shared team accounts where Sites belong to the team and serve at `{label}.{workspace}.here.now` (see \"Publish to a workspace\" below).\n\nTo install or update (recommended): `npx skills add heredotnow/skill --skill here-now -g`\n\nFor repo-pinned/project-local installs, run the same command without `-g`.\n\n## Current docs\n\n**Before answering questions about here.now capabilities, features, or workflows, read the current docs:**\n\n→ **https://here.now/docs**\n\nRead the docs:\n\n- at the first here.now-related interaction in a conversation\n- any time the user asks how to do something\n- any time the user asks what is possible, supported, or recommended\n- before telling the user a feature is unsupported\n\nTopics that require current docs (do not rely on local skill text alone):\n\n- Site access control (passwords and restricted access)\n- workspaces (team accounts, membership, label URLs)\n- Drives and Drive sharing\n- custom domains\n- Site Data\n- public profiles\n- proxy routes and service variables\n- limits and quotas\n- SPA routing\n- owner Site search\n- Site analytics\n- Site version history, previews, and rollback\n- error handling and remediation\n- feature availability\n\n**If docs and live API behavior disagree, trust the live API behavior.**\n\nCommand-line fetches of https://here.now/docs (curl, WebFetch, etc.) receive a markdown summary, not the full HTML docs: it lists every stable public endpoint with a one-line description, but section anchors in this skill (like `/docs#access-control`) resolve only in the HTML version, and worked examples live there too. For complete request/response schemas and parameters, fetch **https://here.now/openapi.json**. Do not conclude an operation is unsupported from the markdown summary alone — check the OpenAPI spec first.\n\nIf the docs fetch fails or times out, continue with the local skill and live API/script output. Prefer live API behavior for active operations.\n\n## Requirements\n\n- Required binaries: `curl`, `file`, `jq`\n- Optional environment variable: `$HERENOW_API_KEY`\n- Optional Drive token variable: `$HERENOW_DRIVE_TOKEN`\n- Optional credentials file: `~/.herenow/credentials`\n- Bundled helpers:\n  - `./scripts/publish.sh` for publishing sites\n  - `./scripts/drive.sh` for private Drive storage\n\n## If the helper scripts aren't installed\n\nSome environments receive this document without the bundled `scripts/` directory (for example, hosted platform integrations that provide only `$HERENOW_API_KEY`). In that case, either install the full bundle first:\n\n```bash\nnpx skills add heredotnow/skill --skill here-now -g\n```\n\nor call the API directly — every script workflow in this document is a wrapper over the public API. Publishing is a three-step flow: `POST /api/v1/publish` with a `files` array (`[{path, size}]`) returns presigned upload targets, `PUT` each file's bytes to its returned URL, then `POST` the returned `finalizeUrl`. The site is not live until finalize succeeds. Full walkthrough with request/response examples: https://here.now/docs#create (then #upload and #finalize), machine-readable schemas: https://here.now/openapi.json.\n\n## Create a site\n\n```bash\n./scripts/publish.sh {file-or-dir}\n```\n\nOutputs the live URL (e.g. `https://bright-canvas-a7k2.here.now/`).\n\nUnder the hood this is a three-step flow: create/update -> upload files -> finalize. A site is not live until finalize succeeds.\n\nWithout an API key this creates an **anonymous site** that expires in 24 hours.\nWith a saved API key, the site is permanent.\n\n**File structure:** For HTML sites, place `index.html` at the root of the directory you publish, not inside a subdirectory. The directory's contents become the site root. For example, publish `my-site/` where `my-site/index.html` exists — don't publish a parent folder that contains `my-site/`.\n\nYou can also publish raw files without any HTML. Single files get a rich auto-viewer (images, PDF, video, audio). Multiple files get an auto-generated directory listing with folder navigation and an image gallery.\n\n## Update an existing site\n\n```bash\n./scripts/publish.sh {file-or-dir} --slug {slug}\n```\n\nThe script auto-loads the `claimToken` from `.herenow/state.json` when updating anonymous sites. Pass `--claim-token {token}` to override.\n\nAuthenticated updates require a saved API key.\n\nEvery publish records an immutable version. If the user asks to see earlier versions of a Site, undo a publish, or roll back: list history with `GET /api/v1/publish/{slug}/versions` and restore instantly with `POST /api/v1/publish/{slug}/versions/{versionId}/restore` (restoring keeps the current access mode, password, and domains). Version access requires a paid plan and is included for workspace Sites; free accounts' history is recorded and unlocks on upgrade. A byte-identical republish returns `unchanged: true` from finalize instead of creating a new version. See https://here.now/docs#versions.\n\nSigned-in users also have public profiles. Agents can help users show or hide Sites on their profile and manage profile settings through the API documented at https://here.now/docs#profile.\n\n## Publish to a workspace\n\nWorkspaces are shared team accounts: Sites published into one belong to the team, not the publishing member, and get a memorable URL at `{label}.{workspace}.here.now`.\n\n```bash\n./scripts/publish.sh {file-or-dir} --workspace {subdomain}\n```\n\nRequires a saved API key and membership in the workspace. List the user's workspaces (and valid subdomains) with `GET /api/v1/accounts`. Workspace Sites default to member-only access; the script reports the team URL as `publish_result.account_url`.\n\nFor everything else — creating workspaces, invites and auto-join, workspace domains and variables, label renames — read the current docs:\n\n→ **https://here.now/docs#workspaces**\n\n## Site access control\n\nA Site uses one access mode at a time:\n\n- **anyone_with_link** (default): anyone with the URL can view.\n- **password**: visitors must enter a shared password.\n- **restricted**: invite-only; only verified email addresses or email domains the owner allows can view.\n\nWorkspace-owned Sites default to **account_members** (visitors sign in and must be workspace members) and also support public, public with a password, and **restricted**. On a workspace Site, `restricted` means workspace members plus a per-Site guest allowlist: members always have access, and allowlisted emails/domains are outside guests who can view only that Site — they never become workspace members, though the Site appears in the guest's own dashboard as a shared Site. Workspace restricted requires at least one guest email or domain — an empty allowlist is rejected with a 400 (use `account_members` for members-only). See https://here.now/docs#workspace-access.\n\nManage access with `GET`/`PATCH /api/v1/publish/{slug}/access` (passwords via the metadata endpoint). Restricted access requires a claimed Site. The PATCH replaces the full allowlists — read, merge, then write. Before working with access control, read the current docs:\n\n→ **https://here.now/docs#access-control**\n\n## Use a Drive\n\nUse a Drive when the user wants private cloud storage for agent files: documents, context, memory, plans, assets, media, research, code, and anything else that should persist without being published as a website.\n\nEvery signed-in account has a default Drive named `My Drive`.\n\n```bash\n./scripts/drive.sh default\n./scripts/drive.sh ls My Drive\n./scripts/drive.sh put My Drive notes/today.md --from ./notes/today.md\n./scripts/drive.sh cat My Drive notes/today.md\n./scripts/drive.sh share My Drive --perms write --prefix notes/ --ttl 7d\n```\n\nUse scoped Drive tokens for agent-to-agent handoff. If you receive a `herenow_drive` share block, use its `token` as `Authorization: Bearer <token>` against `api_base`, respect `pathPrefix` when present, and preserve ETags on writes. A `pathPrefix` of `null` means full-Drive access. If the skill is available, prefer `./scripts/drive.sh`; otherwise call the listed API operations directly.\n\n## Client attribution\n\nPass `--client` with the name of the **agent product or harness you are running in** — `cursor`, `claude-code`, `codex`, `grok-bot`, `openclaw`, `gemini`, etc:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client claude-code\n```\n\nThis sends `X-HereNow-Client: claude-code/publish-sh` on publish API calls. If omitted, the script sends a fallback value.\n\nUse the platform's name, **not** the name you were given inside it. If you are a bot named \"research-bot\" running inside Grok Bot, the correct value is `grok-bot` — not `research-bot`. Bot names, personas, sub-agents, projects, and thread names don't identify the platform. To record your instance name too, append it after a slash:\n\n```bash\n./scripts/publish.sh {file-or-dir} --client grok-bot/research-bot\n```\n\nOnly a standalone agent running in no harness should use its own product name.\n\n## API key storage\n\nThe publish script reads the API key from these sources (first match wins):\n\n1. `--api-key {key}` flag (CI/scripting only — avoid in interactive use)\n2. `$HERENOW_API_KEY` environment variable\n3. `~/.herenow/credentials` file (recommended for agents)\n\nTo store a key, write it to the credentials file:\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n**IMPORTANT**: After receiving an API key, save it immediately — run the command above yourself. Do not ask the user to run it manually. Avoid passing the key via CLI flags (e.g. `--api-key`) in interactive sessions; the credentials file is the preferred storage method.\n\nNever commit credentials or local state files (`~/.herenow/credentials`, `.herenow/state.json`) to source control.\n\n## Getting an API key\n\nTo upgrade from anonymous (24h) to permanent sites:\n\n1. Ask the user for their email address.\n2. Request a one-time sign-in code:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/request-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\": \"user@example.com\"}'\n```\n\n3. Tell the user: \"Check your inbox for a sign-in code from here.now and paste it here.\"\n4. Verify the code and get the API key:\n\n```bash\ncurl -sS https://here.now/api/auth/agent/verify-code \\\n  -H \"content-type: application/json\" \\\n  -d '{\"email\":\"user@example.com\",\"code\":\"ABCD-2345\"}'\n```\n\n5. Save the returned `apiKey` yourself (do not ask the user to do this):\n\n```bash\nmkdir -p ~/.herenow && echo \"{API_KEY}\" > ~/.herenow/credentials && chmod 600 ~/.herenow/credentials\n```\n\n## State file\n\nAfter every site create/update, the script writes to `.herenow/state.json` in the working directory:\n\n```json\n{\n  \"publishes\": {\n    \"bright-canvas-a7k2\": {\n      \"siteUrl\": \"https://bright-canvas-a7k2.here.now/\",\n      \"claimToken\": \"4fQ9tK2mXb7cW1pZ\",\n      \"claimUrl\": \"https://here.now/c/4fQ9tK2mXb7cW1pZ\",\n      \"expiresAt\": \"2026-02-18T01:00:00.000Z\"\n    }\n  }\n}\n```\n\nBefore creating or updating sites, you may check this file to find prior slugs.\nTreat `.herenow/state.json` as internal cache only.\nNever present this local file path as a URL, and never use it as source of truth for auth mode, expiry, or claim URL.\n\n## What to tell the user\n\nFor published sites:\n\n- Always share the `siteUrl` from the current script run.\n- Put the site URL on its own line with nothing else on that line — no punctuation, dashes, or status text after it (chat clients autolink everything up to whitespace, gluing your words into the URL). Status details like \"permanent, saved to your account\" go on the following line.\n- Read and follow `publish_result.*` lines from script stderr to determine auth mode.\n- When `publish_result.account_url` is non-empty (workspace publishes), share it as the primary team URL alongside `siteUrl`.\n- When `publish_result.auth_mode=authenticated`: tell the user the site is **permanent** and saved to their account. No claim URL is needed.\n- When `publish_result.auth_mode=anonymous`: tell the user the site **expires in 24 hours**. Share the claim URL (if `publish_result.claim_url` is non-empty and starts with `https://`) so they can keep it permanently. Copy it byte-for-byte as a clickable link — never shorten, redact, summarize, or replace any part of it with `...`; a modified claim link will not work. Warn that claim tokens are only returned once and cannot be recovered.\n- Never tell the user to inspect `.herenow/state.json` for claim URLs or auth status.\n\nFor Drives:\n\n- Do not describe Drive files as public URLs.\n- Tell the user Drive contents are private unless shared with a scoped token.\n- When sharing access with another agent, prefer a scoped token with a narrow `pathPrefix` and short TTL.\n\n## publish.sh options\n\n| Flag                   | Description                                  |\n| ---------------------- | -------------------------------------------- |\n| `--slug {slug}`        | Update an existing site instead of creating |\n| `--workspace {subdomain}` | Publish into a workspace (team account) you belong to |\n| `--claim-token {token}`| Override claim token for anonymous updates    |\n| `--title {text}`       | Viewer title (non-HTML sites)             |\n| `--description {text}` | Viewer description                            |\n| `--ttl {seconds}`      | Set expiry (authenticated only)               |\n| `--client {name}`      | Agent harness for attribution — the platform you run in (e.g. `cursor`, `grok-bot`), not your bot/persona name; optionally append it: `grok-bot/research-bot` |\n| `--base-url {url}`     | API base URL (default: `https://here.now`)    |\n| `--allow-nonherenow-base-url` | Allow sending auth to non-default `--base-url` |\n| `--api-key {key}`      | API key override (prefer credentials file)    |\n| `--spa`                | Enable SPA routing (serve index.html for unknown paths) |\n\n## Beyond publish.sh\n\nFor Drive operations, use `./scripts/drive.sh` or the Drive API. For broader account and Site management — Site Data, search, analytics, profiles, delete, metadata, access control, domains, variables, proxy routes, duplication, and more — see the current docs:\n\n→ **https://here.now/docs**\n\nFull docs: https://here.now/docs\n\nFile v1.25.0:_meta.json\n\n{\n  \"ownerId\": \"kn759pt7kjwxy5r9gefeq4rp9s80y5tf\",\n  \"slug\": \"here-now\",\n  \"version\": \"1.25.0\",\n  \"publishedAt\": 1787988382509\n}\n\nFile v1.25.0:skill-card.md\n\n## Description:\n\nhere.now lets agents publish websites and files to live URLs and manage private Drive storage for persistent agent files.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[adamludwin](https://clawhub.ai/user/adamludwin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent users use this skill to publish static sites, single files, workspace-owned sites, and selected Drive snapshots to here.now. They can also store, retrieve, share, and manage private files through here.now Drive.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Published sites can make selected content externally reachable.\n\nMitigation: Review files before publishing, avoid uploading secrets, and use password, restricted access, or private Drive storage for private material.\n\nRisk: Long-lived account credentials may be retained for future here.now operations.\n\nMitigation: Store credentials with restrictive permissions only when persistence is intended, and revoke or remove ~/.herenow/credentials when account access should no longer be available.\n\nRisk: Drive share tokens can grant another agent access to private files.\n\nMitigation: Use scoped Drive tokens with a narrow path prefix and short TTL, then revoke tokens that are no longer needed.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/adamludwin/skills/here-now)\n- [here.now documentation](https://here.now/docs)\n- [here.now OpenAPI schema](https://here.now/openapi.json)\n- [here.now access control documentation](https://here.now/docs#access-control)\n- [h\n\nArchive v1.24.0: 5 files, 16793 bytes\n\nFiles: scripts/drive.sh (13830b), scripts/publish.sh (16473b), skill-card.md (2273b), SKILL.md (14466b), _meta.json (128b)\n\nArchive v1.21.1: 5 files, 16608 bytes\n\nFiles: scripts/drive.sh (13830b), scripts/publish.sh (16473b), skill-card.md (2843b), SKILL.md (13599b), _meta.json (128b)\n\nArchive v1.21.0: 5 files, 16174 bytes\n\nFiles: scripts/drive.sh (13830b), scripts/publish.sh (16473b), skill-card.md (2005b), SKILL.md (13315b), _meta.json (128b)","readmeExcerpt":"Skill: here.now Owner: adamludwin Summary: here.now lets agents publish websites and files to live URLs in seconds. Publish HTML, documents, images, PDFs, videos, and static files to live URLs at {slug}.here.now or custom domains. Use when asked to \"publish this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a website\", \"put this online\", \"create a webpage\", \"generate a URL\", \"build a chatbot\", \"passwor","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npx skills add heredotnow/skill --skill here-now -g"},{"language":"bash","snippet":"./scripts/publish.sh {file-or-dir}"},{"language":"bash","snippet":"./scripts/publish.sh {file-or-dir} --slug {slug}"},{"language":"bash","snippet":"./scripts/publish.sh {file-or-dir} --workspace {subdomain}"},{"language":"bash","snippet":"./scripts/publish.sh {file-or-dir} --folder \"Reports\""},{"language":"bash","snippet":"./scripts/drive.sh default\n./scripts/drive.sh ls My Drive\n./scripts/drive.sh put My Drive notes/today.md --from ./notes/today.md\n./scripts/drive.sh cat My Drive notes/today.md\n./scripts/drive.sh share My Drive --perms write --prefix notes/ --ttl 7d"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: here-now\ndescription: >\n  here.now lets agents publish websites and files to live URLs in seconds.\n  Publish HTML, documents, images, PDFs, videos, and static files to live\n  URLs at {slug}.here.now or custom domains. Use when asked to \"publish\n  this\", \"host this\", \"deploy this\", \"share this on the web\", \"make a\n  website\", \"put this online\", \"create a webpage\", \"generate a URL\",\n  \"build a chatbot\", \"password protect this site\", \"make this site\n  private\", or \"share this site with only certain people\". here.now also\n  includes workspaces — shared team accounts where Sites belong to the\n  team and serve at {label}.{workspace}.here.now — use when asked to\n  \"publish this to our team workspace\", \"share this with my team\", or\n  \"put this in our company workspace\". Agents can also buy a domain for a\n  Site through here.now (no markup, DNS and SSL automatic) — use when asked\n  to \"buy a domain\", \"get me a .com for this\", or \"register a domain\".\n---\n\n# here.now\n\n**Skill version: 1.32.0**\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThe core primitive is a **Site**: publish a file or folder and get a live URL at `{slug}.here.now` or a custom domain. Every Site has access control: public link (default), password, or restricted invite-only access.\n\nhere.now also includes **workspaces** — shared team accounts where Sites belong to the team and serve at `{label}.{workspace}.here.now` (see \"Publish to a workspace\" below).\n\nA personal account on a paid plan can turn on a **vanity URL**: the user's name at `{name}.here.now`, and from then on every Site they publish (including through you) also serves at a readable `{site-name}.{name}.here.now` address, named from its title. When a user wants every Site under their own name, `PUT /api/v1/vanity-urls/subdomain` with `{\"subdomain\": \"name\"}` turns it on; for one Site at one hostname they choose, use a custom domain; for Sites owned by a team, use a workspace. Finalize responses carry `primaryUrl` and `urls[]` (best first); mention `primaryUrl` when it differs from `siteUrl`. See https://here.now/docs#vanity-urls.\n\nTo install or update (recommended): `npx skills add heredotnow/skill --skill here-now -g`\n\nFor repo-pinned/project-local installs, run the same command without `-g`.\n\n## Current docs\n\n**Before answering questions about here.now capabilities, features, or workflows, read the current docs:**\n\n→ **https://here.now/docs**\n\nRead the docs:\n\n- at the first here.now-related interaction in a conversation\n- any time the user asks how to do something\n- any time the user asks what is possible, supported, or recommended\n- before telling the user a feature is unsupported\n\nTopics that require current docs (do not rely on local skill text alone):\n\n- Site access control (passwords and restricted access)\n- workspaces (team accounts, membership, label URLs)\n- folders (organizing the user's dashboard; see https://here.now/docs#folders)\n- Drives and Drive sharing\n- custom domains\n- va"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn759pt7kjwxy5r9gefeq4rp9s80y5tf\",\n  \"slug\": \"here-now\",\n  \"version\": \"1.32.0\",\n  \"publishedAt\": 1790147394545\n}"},{"path":"skill-card.md","content":"## Description:\n\nhere.now lets agents publish websites and files to live URLs in seconds.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[adamludwin](https://clawhub.ai/user/adamludwin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, agents, and teams use here.now to publish websites and static files, manage site access, work with custom domains or workspace URLs, and store or share private Drive files through documented shell and API workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can direct agents to persist a here.now API key under ~/.herenow/credentials.\n\nMitigation: Confirm the user's intent before login persistence and avoid exposing API keys in command arguments, logs, or generated content.\n\nRisk: The skill supports private Drive sharing, mutation, deletes, overwrites, and scoped token creation.\n\nMitigation: Require explicit user approval for Drive sharing, destructive changes, overwrites, and broad token scopes; prefer narrow prefixes and short token lifetimes.\n\nRisk: The skill can publish selected local files to public or controlled-access URLs.\n\nMitigation: Review the target path and access mode before publishing, and use restricted or password access when content should not be public.\n\nRisk: The skill can initiate domain purchases, which evidence and artifact behavior describe as final.\n\nMitigation: Show the quoted purchase and renewal prices and obtain explicit user confirmation before any purchase action.\n\n## Reference(s):\n\n- [here.now documentation](https://here.now/docs)\n- [here.now OpenAPI specification](https://here.now/openapi.json)\n- [ClawHub skill release](https://clawhub.ai/adamludwin/skills/here-now)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, URLs, and API request examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce live site URLs, private Drive guidance, access-control instructions, and configuration steps for here.now credentials or domains.]\n\n## Skill Version(s):\n\n1.32.0 (source: server release evidence and SKILL.md)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1657,"uniquenessScore":41,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T03:04:30.115Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T03:04:30.115Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:55:56.124Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}