{"id":"b9228e78-74c4-4c5e-90cf-bcbbc8a2b67a","entityType":"agent","slug":"clawhub-chrischall-alphaportal-mcp","name":"alphaportal-mcp","canonicalUrl":"https://www.xpersona.co/agent/clawhub-chrischall-alphaportal-mcp","canonicalPath":"/agent/clawhub-chrischall-alphaportal-mcp","generatedAt":"2026-10-11T14:15:33.972Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T11:24:33.567Z","emptyReason":null},"description":"Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the alphaportal-mcp server. Capture the signed-in web app's refresh token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint access tokens and curl the REST API directly. Use when you want AlphaPortal data without the MCP, in a script, or on a machine where the MCP isn't installed. Skill: alphaportal-mcp Owner: chrischall Summary: Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the alphaportal-mcp server. Capture the signed-in web app's refresh token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint access tokens and curl the REST API directly. Use when you want Al","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:alphaportal-mcp","sourceUrl":"https://clawhub.ai/chrischall/alphaportal-mcp","homepage":"https://clawhub.ai/chrischall/skills/alphaportal-mcp","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/chrischall/alphaportal-mcp","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/chrischall/skills/alphaportal-mcp","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T11:24:33.567Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T11:24:33.567Z","emptyReason":null},"stars":null,"forks":null,"downloads":1077,"packageName":null,"latestVersion":"1.2.3","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T11:24:33.499Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T11:24:33.567Z","lastCrawledAt":"2026-10-11T11:24:33.499Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T11:24:33.499Z","lastVerifiedAt":null,"highlights":[{"version":"1.2.3","createdAt":"2026-10-09T23:25:53.518Z","changelog":"- Removed the skill-card.md file. - No changes to functionality or documentation in SKILL.md. - Housekeeping update; no user-facing impact.","fileCount":4,"zipByteSize":5414},{"version":"1.2.2","createdAt":"2026-10-07T13:35:55.854Z","changelog":"Minor update removing the obsolete skill card file. - Removed the redundant skill-card.md file. - No changes to functionality or usage.","fileCount":4,"zipByteSize":5427},{"version":"1.2.1","createdAt":"2026-10-05T02:47:21.570Z","changelog":"- Removed the sample file \"skill-card.md\". - No functional or user-facing changes were made to the skill's documentation or workflow.","fileCount":4,"zipByteSize":5384},{"version":"1.2.0","createdAt":"2026-10-03T01:41:39.898Z","changelog":"- Removed the file: skill-card.md - No changes to user-facing functionality or documented features.","fileCount":4,"zipByteSize":5465},{"version":"1.1.2","createdAt":"2026-09-28T14:00:13.450Z","changelog":"- Updated SKILL.md instructions for the fpx browser bridge, reflecting the rename to \"ContextMint Bridge\" (was fetchproxy extension). - Added details on obtaining/loading the new extension (ContextMint Bridge) and provided official links to its source and releases. - Clarified that Safari is not yet supported for the extension; Chrome use is required for now. - Removed obsolete references to the old skill-card.md file.","fileCount":4,"zipByteSize":5458},{"version":"1.1.1","createdAt":"2026-09-25T15:56:24.720Z","changelog":"- Removed the file skill-card.md. - No changes to user functionality or documentation.","fileCount":4,"zipByteSize":5109},{"version":"1.1.0","createdAt":"2026-09-24T15:12:02.083Z","changelog":"Version 1.1.0 - Updated documentation in SKILL.md to clarify that the shell skill no longer provides any preview or confirmation before executing write actions; all writes are immediate and permanent. - Expanded warning on write endpoints to note that the MCP server previously gated writes behind a prompt or confirmation, but this is not present when using curl. - Removed skill-card.md file.","fileCount":4,"zipByteSize":5211},{"version":"1.0.2","createdAt":"2026-09-23T21:39:13.581Z","changelog":"- Removed the skill-card.md file. - No user-facing features or documentation changes.","fileCount":4,"zipByteSize":5302}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:alphaportal-mcp","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T14:15:33.971Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chrischall-alphaportal-mcp/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T11:24:33.567Z","emptyReason":null},"readme":"Skill: alphaportal-mcp\n\nOwner: chrischall\n\nSummary: Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the alphaportal-mcp server. Capture the signed-in web app's refresh token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint access tokens and curl the REST API directly. Use when you want AlphaPortal data without the MCP, in a script, or on a machine where the MCP isn't installed.\n\nTags: latest:1.2.3\n\nVersion history:\n\nv1.2.3 | 2026-10-09T23:25:53.518Z | auto\n\n- Removed the skill-card.md file.\n- No changes to functionality or documentation in SKILL.md.\n- Housekeeping update; no user-facing impact.\n\nv1.2.2 | 2026-10-07T13:35:55.854Z | auto\n\nMinor update removing the obsolete skill card file.\n\n- Removed the redundant skill-card.md file.\n- No changes to functionality or usage.\n\nv1.2.1 | 2026-10-05T02:47:21.570Z | auto\n\n- Removed the sample file \"skill-card.md\".\n- No functional or user-facing changes were made to the skill's documentation or workflow.\n\nv1.2.0 | 2026-10-03T01:41:39.898Z | auto\n\n- Removed the file: skill-card.md\n- No changes to user-facing functionality or documented features.\n\nv1.1.2 | 2026-09-28T14:00:13.450Z | auto\n\n- Updated SKILL.md instructions for the fpx browser bridge, reflecting the rename to \"ContextMint Bridge\" (was fetchproxy extension).\n- Added details on obtaining/loading the new extension (ContextMint Bridge) and provided official links to its source and releases.\n- Clarified that Safari is not yet supported for the extension; Chrome use is required for now.\n- Removed obsolete references to the old skill-card.md file.\n\nv1.1.1 | 2026-09-25T15:56:24.720Z | auto\n\n- Removed the file skill-card.md.\n- No changes to user functionality or documentation.\n\nv1.1.0 | 2026-09-24T15:12:02.083Z | auto\n\nVersion 1.1.0\n\n- Updated documentation in SKILL.md to clarify that the shell skill no longer provides any preview or confirmation before executing write actions; all writes are immediate and permanent.\n- Expanded warning on write endpoints to note that the MCP server previously gated writes behind a prompt or confirmation, but this is not present when using curl.\n- Removed skill-card.md file.\n\nv1.0.2 | 2026-09-23T21:39:13.581Z | auto\n\n- Removed the skill-card.md file.\n- No user-facing features or documentation changes.\n\nv1.0.1 | 2026-09-23T15:42:00.967Z | auto\n\n- Removed the sample file skill-card.md.\n- No changes to functionality or documentation in SKILL.md.\n- No user-facing feature or behavior changes.\n\nv1.0.0 | 2026-09-20T02:49:46.186Z | auto\n\n- Removed the file skill-card.md.\n- No changes to functionality or documentation besides file removal.\n\nv0.4.0 | 2026-09-17T23:36:22.671Z | auto\n\n- Removed the skill-card.md file.\n- No user-facing functionality or documentation changes; core usage and instructions remain unchanged.\n\nv0.3.2 | 2026-09-15T19:27:42.273Z | auto\n\n- Removed the file: skill-card.md\n- No other changes to skill behavior or documentation.\n\nv0.3.1 | 2026-09-10T17:51:22.993Z | auto\n\n- Removed the skill-card.md file from the repository.\n- No changes to user-facing command-line usage or documentation.\n- No new features or behavior changes introduced in this release.\n\nv0.3.0 | 2026-09-04T22:22:32.284Z | auto\n\n- Removed the sample file skill-card.md.\n- No changes to core documentation or functionality.\n- Version bump to 0.3.0 for housekeeping/cleanup.\n\nv0.2.0 | 2026-08-29T13:53:55.029Z | auto\n\n- Removed the file: skill-card.md\n- No user-facing changes to functionality or documentation.\n\nv0.1.0 | 2026-08-28T11:34:43.445Z | auto\n\nInitial public release: enables direct AlphaPortal API access via curl, no MCP server required.\n\n- Capture your AlphaPortal web refresh token once and export it for script use.\n- Mint new access tokens and make raw API calls via curl, fully authenticated.\n- Supports all read endpoints: students, stops, live vehicle GPS, notifications, etc.\n- No runtime browser extension required after initial token capture.\n- Write endpoints are live; all issued calls take effect immediately—use with care.\n\nArchive index:\n\nArchive v1.2.3: 4 files, 5414 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (2043b), SKILL.md (4600b), _meta.json (134b)\n\nFile v1.2.3:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the ContextMint Bridge extension — from\nhttps://github.com/nullnet-app/contextmint-bridge/releases; Chrome: load the chrome\nzip unpacked; Safari isn't available yet, so use Chrome for now — plus a signed-in\n`*.alphaportal.app` tab). ContextMint Bridge is the fetchproxy extension renamed, same\nmaintainer; source is public at https://github.com/nullnet-app/contextmint-bridge — build\nit yourself or verify a release zip with `shasum -a 256 -c contextmint-bridge-chrome-<version>.zip.sha256`:\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in ContextMint Bridge\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\nconfirmation (a prompt, or a preview plus a one-time confirm token). This shell\nskill has **no preview or confirmation** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.2.3:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.2.3\",\n  \"publishedAt\": 1791588353518\n}\n\nFile v1.2.3:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.2.3:skill-card.md\n\n## Description:\n\nGuides authorized users through accessing AlphaPortal student transportation data with shell commands instead of running the MCP server.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nAuthorized parents, guardians, and developers use this skill to retrieve student stops, bus locations, and arrival notifications through the AlphaPortal API without an MCP server.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Copying a browser refresh token can expose account access.\n\nMitigation: Use only accounts you are authorized to access; treat tokens like passwords and keep them out of shared terminals, shell history, logs, and printed scripts.\n\nRisk: Student locations and transportation details are sensitive.\n\nMitigation: Limit access to authorized students and avoid logging or sharing returned student data.\n\nRisk: Write examples can change transportation settings without confirmation.\n\nMitigation: Run write commands only with explicit permission and an independent review step.\n\n## Reference(s):\n\n- [AlphaPortal endpoint recipes](references/endpoints.md)\n- [ContextMint Bridge source](https://github.com/nullnet-app/contextmint-bridge)\n- [AlphaPortal MCP skill release](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration instructions, Guidance]\n\n**Output Format:** [Markdown with shell and JavaScript examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands may expose account tokens or sensitive student transportation data.]\n\n## Skill Version(s):\n\n1.2.3 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.2.2: 4 files, 5427 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (2081b), SKILL.md (4600b), _meta.json (134b)\n\nFile v1.2.2:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the ContextMint Bridge extension — from\nhttps://github.com/nullnet-app/contextmint-bridge/releases; Chrome: load the chrome\nzip unpacked; Safari isn't available yet, so use Chrome for now — plus a signed-in\n`*.alphaportal.app` tab). ContextMint Bridge is the fetchproxy extension renamed, same\nmaintainer; source is public at https://github.com/nullnet-app/contextmint-bridge — build\nit yourself or verify a release zip with `shasum -a 256 -c contextmint-bridge-chrome-<version>.zip.sha256`:\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in ContextMint Bridge\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\nconfirmation (a prompt, or a preview plus a one-time confirm token). This shell\nskill has **no preview or confirmation** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.2.2:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.2.2\",\n  \"publishedAt\": 1791380155854\n}\n\nFile v1.2.2:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.2.2:skill-card.md\n\n## Description:\n\nGuides authorized users through accessing AlphaPortal student transportation, bus location, and notification data with shell commands instead of the MCP server.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nAuthorized parents, guardians, and developers use this skill to retrieve AlphaPortal student transportation details, live bus locations, and arrival notifications from a shell without running the MCP server.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Browser refresh tokens and bearer tokens can expose sensitive student and live-location data if copied into shared shells, logs, or optional bridge tooling.\n\nMitigation: Use only an authorized account, treat tokens as credentials, and avoid shared terminals and logs; assess optional bridge access before pairing.\n\nRisk: Documented write commands change transportation records without a built-in preview or confirmation.\n\nMitigation: Avoid write endpoints unless the exact student, endpoint, and payload have been checked through a separate confirmation step.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n- [AlphaPortal endpoint reference](artifact/references/endpoints.md)\n- [Optional ContextMint Bridge](https://github.com/nullnet-app/contextmint-bridge)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration instructions, Guidance]\n\n**Output Format:** [Markdown with shell and JavaScript snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands access live account data and return JSON from AlphaPortal.]\n\n## Skill Version(s):\n\n1.2.2 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.2.1: 4 files, 5384 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (1965b), SKILL.md (4600b), _meta.json (134b)\n\nFile v1.2.1:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the ContextMint Bridge extension — from\nhttps://github.com/nullnet-app/contextmint-bridge/releases; Chrome: load the chrome\nzip unpacked; Safari isn't available yet, so use Chrome for now — plus a signed-in\n`*.alphaportal.app` tab). ContextMint Bridge is the fetchproxy extension renamed, same\nmaintainer; source is public at https://github.com/nullnet-app/contextmint-bridge — build\nit yourself or verify a release zip with `shasum -a 256 -c contextmint-bridge-chrome-<version>.zip.sha256`:\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in ContextMint Bridge\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\nconfirmation (a prompt, or a preview plus a one-time confirm token). This shell\nskill has **no preview or confirmation** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.2.1:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.2.1\",\n  \"publishedAt\": 1791168441570\n}\n\nFile v1.2.1:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.2.1:skill-card.md\n\n## Description:\n\nGuides authorized users in accessing AlphaPortal student transportation, stops, live bus locations, and notifications through shell commands without running an MCP server.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nAuthorized AlphaPortal users and developers use this skill to retrieve school-bus transportation information or prepare direct API requests from a shell when the MCP server is unavailable or unwanted.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: A captured refresh token could expose sensitive student and bus-location data if shared or logged.\n\nMitigation: Use only with authorized accounts; protect the refresh token like a password and avoid putting it in logs or shared shell history.\n\nRisk: Direct write commands can permanently change transportation settings without confirmation.\n\nMitigation: Prefer the MCP flow for writes, or manually review each request and its student identifier before execution.\n\n## Reference(s):\n\n- [AlphaPortal MCP release](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n- [AlphaPortal endpoint reference](references/endpoints.md)\n- [ContextMint Bridge source](https://github.com/nullnet-app/contextmint-bridge)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance]\n\n**Output Format:** [Markdown with shell and JavaScript code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands may read sensitive student and location data or make account changes.]\n\n## Skill Version(s):\n\n1.2.1 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.2.0: 4 files, 5465 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (2176b), SKILL.md (4600b), _meta.json (134b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the ContextMint Bridge extension — from\nhttps://github.com/nullnet-app/contextmint-bridge/releases; Chrome: load the chrome\nzip unpacked; Safari isn't available yet, so use Chrome for now — plus a signed-in\n`*.alphaportal.app` tab). ContextMint Bridge is the fetchproxy extension renamed, same\nmaintainer; source is public at https://github.com/nullnet-app/contextmint-bridge — build\nit yourself or verify a release zip with `shasum -a 256 -c contextmint-bridge-chrome-<version>.zip.sha256`:\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in ContextMint Bridge\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\nconfirmation (a prompt, or a preview plus a one-time confirm token). This shell\nskill has **no preview or confirmation** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1790991699898\n}\n\nFile v1.2.0:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.2.0:skill-card.md\n\n## Description:\n\nGuides authorized users through accessing AlphaPortal student transportation records, live bus locations, and notifications with shell-based API calls instead of the MCP server.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nAuthorized AlphaPortal account holders and developers use this skill to retrieve student transportation data and, when needed, change notification preferences or walk-zone radius via direct API calls.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Extracting and handling a browser refresh token can expose account access.\n\nMitigation: Use only with explicit account authorization; prefer approved workflows with scoped credentials and auditability, and do not share tokens.\n\nRisk: API responses can expose student records and live bus locations.\n\nMitigation: Restrict access to authorized users and protect or avoid retaining sensitive responses.\n\nRisk: Direct write calls can change real transportation settings without confirmation.\n\nMitigation: Prefer an approved workflow with a preview and confirmation gate; independently verify the target and intended change before any write.\n\n## Reference(s):\n\n- [AlphaPortal MCP release](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n- [AlphaPortal endpoint reference](artifact/references/endpoints.md)\n- [ContextMint Bridge](https://github.com/nullnet-app/contextmint-bridge)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance]\n\n**Output Format:** [Markdown with shell snippets and JSON response examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands may expose sensitive account and student data; write calls have no built-in confirmation.]\n\n## Skill Version(s):\n\n1.2.0 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.1.2: 4 files, 5458 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (2229b), SKILL.md (4600b), _meta.json (134b)\n\nFile v1.1.2:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the ContextMint Bridge extension — from\nhttps://github.com/nullnet-app/contextmint-bridge/releases; Chrome: load the chrome\nzip unpacked; Safari isn't available yet, so use Chrome for now — plus a signed-in\n`*.alphaportal.app` tab). ContextMint Bridge is the fetchproxy extension renamed, same\nmaintainer; source is public at https://github.com/nullnet-app/contextmint-bridge — build\nit yourself or verify a release zip with `shasum -a 256 -c contextmint-bridge-chrome-<version>.zip.sha256`:\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in ContextMint Bridge\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\nconfirmation (a prompt, or a preview plus a one-time confirm token). This shell\nskill has **no preview or confirmation** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.1.2:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.1.2\",\n  \"publishedAt\": 1790604013450\n}\n\nFile v1.1.2:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.1.2:skill-card.md\n\n## Description:\n\nGuides authorized users to access AlphaPortal student transportation, bus location, and notification data with shell commands instead of running the MCP server.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and authorized AlphaPortal account holders use this skill to retrieve student bus routes, live vehicle locations, and notifications through direct API calls without installing the MCP server. It also documents account-changing requests that require extra care.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Extracting a reusable browser refresh token exposes sensitive account access and student transportation data if the token or command output is disclosed.\n\nMitigation: Use only an account you are authorized to access; keep tokens and outputs out of shared machines and logs, and store them securely.\n\nRisk: Direct write requests can change real transportation records without a preview or confirmation step.\n\nMitigation: Avoid write endpoints unless necessary, and independently review the exact student ID and request body before sending.\n\n## Reference(s):\n\n- [AlphaPortal endpoint reference](references/endpoints.md)\n- [ContextMint Bridge source](https://github.com/nullnet-app/contextmint-bridge)\n- [ContextMint Bridge releases](https://github.com/nullnet-app/contextmint-bridge/releases)\n- [ClawHub skill release](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration instructions, Guidance]\n\n**Output Format:** [Markdown with shell and JavaScript snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Example commands can return sensitive student transportation records and live bus locations.]\n\n## Skill Version(s):\n\n1.1.2 (source: server-resolved release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.1.1: 4 files, 5109 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (1903b), SKILL.md (4161b), _meta.json (134b)\n\nFile v1.1.1:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the Transporter extension + a signed-in\n`*.alphaportal.app` tab):\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in Transporter\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\nconfirmation (a prompt, or a preview plus a one-time confirm token). This shell\nskill has **no preview or confirmation** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.1.1\",\n  \"publishedAt\": 1790351784720\n}\n\nFile v1.1.1:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.1.1:skill-card.md\n\n## Description:\n\nGuides authorized users through accessing AlphaPortal school transportation data and account settings from a shell without running the MCP server.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nAuthorized AlphaPortal users and developers can retrieve student transportation details, bus locations, and notifications or change account settings using shell commands instead of the MCP server.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The workflow exposes a reusable browser credential to the shell and can disclose sensitive student transportation and location data.\n\nMitigation: Use only with authorized account access; keep credentials out of shared terminals, logs, transcripts, and version control.\n\nRisk: Documented write requests change live transportation settings without a preview or confirmation step.\n\nMitigation: Use write requests only with explicit authority, after independently verifying the student and exact request body.\n\n## Reference(s):\n\n- [AlphaPortal endpoint reference](references/endpoints.md)\n- [ClawHub skill release](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance]\n\n**Output Format:** [Markdown with shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands may return sensitive student transportation and location data or make account changes.]\n\n## Skill Version(s):\n\n1.1.1 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.1.0: 4 files, 5211 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (2077b), SKILL.md (4161b), _meta.json (134b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the Transporter extension + a signed-in\n`*.alphaportal.app` tab):\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in Transporter\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\nconfirmation (a prompt, or a preview plus a one-time confirm token). This shell\nskill has **no preview or confirmation** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1790262722083\n}\n\nFile v1.1.0:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.1.0:skill-card.md\n\n## Description:\n\nAccess AlphaPortal (AlphaRoute) school-bus data such as students, stops, live bus location, and arrival notifications from a shell using curl.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and authorized AlphaPortal users use this skill to retrieve school transportation information and run documented AlphaRoute API calls from scripts or a shell without running the alphaportal-mcp server.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Copied AlphaPortal refresh tokens act like durable account secrets and can expose sensitive student transportation data.\n\nMitigation: Use the skill only with authorized accounts, keep tokens out of shell history, logs, scripts, and shared terminals, and rotate or recapture tokens when needed.\n\nRisk: Documented write endpoints can change real transportation settings without a preview or confirmation step.\n\nMitigation: Do not run write endpoint commands unless explicit permission and an independent confirmation process are in place.\n\n## Reference(s):\n\n- [AlphaPortal endpoint reference](references/endpoints.md)\n- [AlphaPortal API base URL](https://api.alpharoute.app)\n- [ClawHub skill page](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, shell commands, configuration]\n\n**Output Format:** [Markdown with inline shell commands and curl examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes commands that can read sensitive transportation data and call write endpoints when supplied with valid AlphaPortal tokens.]\n\n## Skill Version(s):\n\n1.1.0 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.2: 4 files, 5302 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (2296b), SKILL.md (4095b), _meta.json (134b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the Transporter extension + a signed-in\n`*.alphaportal.app` tab):\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in Transporter\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\n`confirm` dry-run. This shell skill has **no dry-run** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1790199553581\n}\n\nFile v1.0.2:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.0.2:skill-card.md\n\n## Description:\n\nProvides shell-based AlphaPortal (AlphaRoute) access guidance for student transportation data, including students, stops, live bus GPS, and notifications, by capturing a browser refresh token, minting access tokens, and calling the REST API with curl.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and authorized AlphaPortal users use this skill to retrieve school-bus student, stop, notification, and vehicle-location data from scripts or shell sessions without running the MCP server. It is intended for accounts and records the user is already permitted to access.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Refresh and access tokens can expose AlphaPortal accounts and sensitive student transportation data if copied into chats, logs, shared shells, or persistent history.\n\nMitigation: Use the skill only for accounts and student records you are authorized to access; treat tokens like passwords; avoid shared machines and persistent shell history; do not paste tokens or student-location output into chats or logs.\n\nRisk: Shell write endpoints can change real transportation records without the MCP server's dry-run confirmation flow.\n\nMitigation: Prefer official or MCP flows with confirmations and audit controls for write operations; review request bodies before execution and limit use to authorized changes.\n\n## Reference(s):\n\n- [AlphaPortal endpoint reference](references/endpoints.md)\n- [AlphaRoute API base](https://api.alpharoute.app)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell and JavaScript code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes curl and jq examples for authenticated AlphaPortal API calls.]\n\n## Skill Version(s):\n\n1.0.2 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.1: 4 files, 5357 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (2413b), SKILL.md (4095b), _meta.json (134b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the Transporter extension + a signed-in\n`*.alphaportal.app` tab):\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in Transporter\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\n`confirm` dry-run. This shell skill has **no dry-run** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1790178120967\n}\n\nFile v1.0.1:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.0.1:skill-card.md\n\n## Description:\n\nAccess AlphaPortal school-bus data, including students, stops, live bus GPS location, and arrival notifications, from a shell with curl after capturing a signed-in web app refresh token.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and authorized AlphaPortal account users can use this skill to retrieve student transportation records, bus stop details, live vehicle location, and notification data from shell scripts without running the MCP server.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill teaches users to extract and reuse a browser refresh token for an AlphaPortal account.\n\nMitigation: Use only with explicit authorization, keep refresh tokens out of shared shells, logs, scripts, screenshots, and source control, and prefer an official or scoped integration path when available.\n\nRisk: The skill can expose sensitive student transportation records and live location data.\n\nMitigation: Limit use to authorized accounts and workflows, minimize copied output, and avoid sharing student identifiers, route details, notification contents, or live GPS results.\n\nRisk: The artifact documents write endpoints that can change real transportation records without a dry-run safeguard.\n\nMitigation: Avoid write endpoints unless the user is authorized and fully understands the real-world effect; verify read-only calls first and confirm request bodies before execution.\n\n## Reference(s):\n\n- [AlphaPortal endpoint reference](references/endpoints.md)\n- [ClawHub skill page](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration instructions, API Calls, Code, Guidance]\n\n**Output Format:** [Markdown with inline shell and JavaScript code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes curl and jq examples for token minting, read endpoints, and write-capable endpoint calls.]\n\n## Skill Version(s):\n\n1.0.1 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.0: 4 files, 5401 bytes\n\nFiles: references/endpoints.md (3677b), skill-card.md (2570b), SKILL.md (4095b), _meta.json (134b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the Transporter extension + a signed-in\n`*.alphaportal.app` tab):\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in Transporter\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the envelope is `{success,data,message}`,\nso pipe `.data` to `jq`.\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'\n```\n\nSee `references/endpoints.md` for the full endpoint list, path variables, and\nready-to-run `jq` recipes.\n\n## Status codes\n\n- `401` — the access token expired (re-run step 2) or the refresh token died\n  (re-capture, step 1).\n- `400` with `developerMessage` — a required param is missing (e.g. a path\n  `studentId`, or `studentId`/`radius` on a write).\n- `success:false` in a `200` body — the API rejected the request; read\n  `.developerMessage` / `.message`.\n\n## Writes\n\nWrite endpoints (`radius-edit`, `setnotification`) exist and change real\ntransportation records; the `alphaportal-mcp` server gates them behind a\n`confirm` dry-run. This shell skill has **no dry-run** — curl just does it — so\ntreat every write as real and permanent. Request bodies are in\n`references/endpoints.md`. The transportation-request submission flow is\ndeliberately undocumented here (its body was not fully verified).\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1789872586186\n}\n\nFile v1.0.0:references/endpoints.md\n\n# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email). The web client sends the whole set at once.\napost AlphaPortal/v1/user-students/setnotification \\\n  '{\"studentId\":218652901,\"schoolArrivalNotifyAm\":1,\"schoolArrivalNotifyPm\":1,\"schoolArrivalEmailAm\":0,\"schoolArrivalEmailPm\":0}' | jq\n```\n\n## Refresh (mint a new access token, rotating the refresh token)\n\n```sh\n# returns {token, refreshToken, lang}; the refresh token is reusable, but each\n# call also issues a fresh 8-day one you can save to roll the window forward.\ncurl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq '.data | {token, refreshToken}'\n```\n\nFile v1.0.0:skill-card.md\n\n## Description:\n\nAccess AlphaPortal (AlphaRoute) school-bus data such as students, stops, live bus GPS location, and arrival notifications from a shell with curl by using a captured web-app refresh token to mint access tokens.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and authorized AlphaPortal users use this skill to query school transportation data from shells or scripts without running the alphaportal-mcp server. It also documents write calls for transportation settings, which should only be used with explicit authorization and intent.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Long-lived browser refresh tokens can expose AlphaPortal account access and sensitive school transportation data.\n\nMitigation: Install and use the skill only with explicit authorization; avoid shared shells, logs, shell history, and scripts that store tokens or API responses, and prefer an official or vendor-approved API/auth flow where available.\n\nRisk: The skill includes curl examples for write endpoints that can permanently change real transportation settings.\n\nMitigation: Use write examples only when you intend to make the documented change, confirm the target student and request body before execution, and avoid unattended automation for these calls.\n\nRisk: Student records, notification data, and live bus location data are sensitive and may be exposed through command output or saved responses.\n\nMitigation: Minimize displayed fields, redact outputs before sharing, and avoid persisting response payloads unless required by an authorized workflow.\n\n## Reference(s):\n\n- [AlphaPortal endpoint reference](references/endpoints.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with shell, JavaScript, curl, and jq code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Handles browser refresh tokens, bearer access tokens, student transportation records, live vehicle location, notifications, and write examples for real transportation settings.]\n\n## Skill Version(s):\n\n1.0.0 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: alphaportal-mcp Owner: chrischall Summary: Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the alphaportal-mcp server. Capture the signed-in web app's refresh token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint access tokens and curl the REST API directly. Use when you want Al","codeSnippets":[],"executableExamples":[{"language":"js","snippet":"JSON.parse(localStorage.user).User.RefreshToken"},{"language":"sh","snippet":"export ALPHAPORTAL_RT='<paste the refresh token>'"},{"language":"sh","snippet":"npm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in ContextMint Bridge\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')"},{"language":"sh","snippet":"curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'"},{"language":"sh","snippet":"export ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)"},{"language":"sh","snippet":"alpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\n\n# your students (grab each studentId here first)\nalpha AlphaPortal/v1/user-students/list | jq '.data.students[] | {studentId, name, gradeName}'\n\n# live bus GPS for a student's PM run (shift 0=AM, 1=PM)\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# arrival/departure notifications\nalpha AlphaPortal/v1/notifications/list | jq '.data.notifications[] | {title, body, creationDate}'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: alphaportal-fpx\ndescription: >-\n  Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus\n  GPS location, arrival notifications — from a shell with curl instead of\n  running the alphaportal-mcp server. Capture the signed-in web app's refresh\n  token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint\n  access tokens and curl the REST API directly. Use when you want AlphaPortal\n  data without the MCP, in a script, or on a machine where the MCP isn't\n  installed.\n---\n\n# AlphaPortal via curl (no MCP, no runtime bridge)\n\nAlphaPortal's app (e.g. `cmsnc.alphaportal.app` — the `cmsnc` subdomain is the\nschool district) has **no bot wall** on its API (`api.alpharoute.app`): once you\nhold a token, plain `curl` does every call — no browser extension at runtime.\nLogin itself is reCAPTCHA-gated and can't be scripted, so the credential is the\n**refresh token** the web app stores in your signed-in browser. It's an 8-day,\nreusable JWT; from it you mint a 30-minute access token with one unauthenticated\nPOST (no reCAPTCHA, no MFA).\n\nSo the flow is: **capture the refresh token once → mint an access token → curl.**\n\n## 1. Capture the refresh token (once; repeat when it expires after ~8 days)\n\n**Option A — paste-in-console (no fpx needed).** In a signed-in AlphaPortal tab,\nopen DevTools → Console and run:\n\n```js\nJSON.parse(localStorage.user).User.RefreshToken\n```\n\nCopy the value into your shell:\n\n```sh\nexport ALPHAPORTAL_RT='<paste the refresh token>'\n```\n\n**Option B — fpx browser bridge** (needs the ContextMint Bridge extension — from\nhttps://github.com/nullnet-app/contextmint-bridge/releases; Chrome: load the chrome\nzip unpacked; Safari isn't available yet, so use Chrome for now — plus a signed-in\n`*.alphaportal.app` tab). ContextMint Bridge is the fetchproxy extension renamed, same\nmaintainer; source is public at https://github.com/nullnet-app/contextmint-bridge — build\nit yourself or verify a release zip with `shasum -a 256 -c contextmint-bridge-chrome-<version>.zip.sha256`:\n\n```sh\nnpm install -g @fetchproxy/cli                              # provides `fpx`\nfpx profile add alphaportal --domain alphaportal.app\nfpx profile declare alphaportal --local-storage user       # declare scope BEFORE first pairing\nfpx local-storage user -p alphaportal                      # first call prints a pair code → approve in ContextMint Bridge\nexport ALPHAPORTAL_RT=$(fpx local-storage user -p alphaportal | jq -r '.user | fromjson | .User.RefreshToken')\n```\n\n## 2. Mint an access token (each session, or when the last one is >30 min old)\n\n```sh\nexport ALPHAPORTAL_TOKEN=$(\n  curl -s -X POST https://api.alpharoute.app/AlphaCore/v1/public/refresh-token \\\n    -H 'Content-Type: application/json' \\\n    -d \"{\\\"refreshToken\\\":\\\"$ALPHAPORTAL_RT\\\"}\" | jq -r '.data.token'\n)\n```\n\nIf `ALPHAPORTAL_TOKEN` is `null`, the refresh token is expired/invalid —\nre-capture it (step 1).\n\n## 3. Core call pattern\n\nEvery read is a GET with the bearer token; the"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn700jq4sjtf2anb0rk3ft4p7n856872\",\n  \"slug\": \"alphaportal-mcp\",\n  \"version\": \"1.2.3\",\n  \"publishedAt\": 1791588353518\n}"},{"path":"references/endpoints.md","content":"# AlphaPortal endpoint reference (curl)\n\nBase: `https://api.alpharoute.app`. Auth: `Authorization: Bearer $ALPHAPORTAL_TOKEN`\n(see `SKILL.md` for minting). Envelope: `{success, data, message}`.\n`{sid}` = a numeric `studentId`; `{shift}` = `0` (AM, to school) / `1` (PM, home).\n\nAll reads below are **live-verified** (2026-08-25). Define the helper once:\n\n```sh\nalpha() { curl -s \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\"; }\napost() { curl -s -X POST \"https://api.alpharoute.app/$1\" -H \"Authorization: Bearer $ALPHAPORTAL_TOKEN\" -H 'Content-Type: application/json' -d \"$2\"; }\n```\n\n## Students & transportation\n\n```sh\n# full student records\nalpha AlphaPortal/v1/user-students/list | jq '.data.students'\n\n# slim list (id + name only)\nalpha AlphaPortal/v1/user-students/lightlist | jq '.data.students'\n\n# one student: school + morning/afternoon stops\nalpha AlphaPortal/v1/user-students/retrieve/218652901 | jq '.data'\n\n# a student's assigned stops (name, time, lat/lng, days)\nalpha AlphaPortal/v1/user-students/stops/218652901 \\\n  | jq '.data.stops[] | {stopName, time, afternoonFlag, saLat, saLng, vehicleName}'\n\n# LIVE bus GPS for a run (shift 0=AM, 1=PM); empty location = not running\nalpha AlphaPortal/v1/user-students/vehicle-location/218652901/1 | jq '.data.location'\n\n# a one-time PDF report link\nalpha \"AlphaPortal/v1/user-students/reports-bulk?studentId=218652901\" | jq '.data'\n\n# the account groups (districts) you belong to\nalpha AlphaPortal/v1/user-students/account-groups | jq '.data.accountGroups'\n```\n\n## Notifications & requests\n\n```sh\n# arrival/departure notification feed (the real one)\nalpha AlphaPortal/v1/notifications/list \\\n  | jq '.data.notifications[] | {title, personName, body, creationDate}'\n\n# your submitted transportation requests (tracking numbers, status)\nalpha AlphaPortal/v1/requests/list | jq '.data.requestTransportations'\n```\n\n## Account & district reference\n\n```sh\napost AlphaCore/v1/user/profile '{}' | jq '.data.Profile'\nalpha AlphaCore/v1/user/accountdate | jq '.data'          # server date + timezone\nalpha AlphaCore/v1/account/inforetrieve | jq '.data.Account'\nalpha AlphaPortal/v1/applicationsetting/retrieve | jq '.data.settings'   # feature flags\nalpha AlphaPlan/v1/school/lightlist | jq '.data.School[] | {SchoolName, Lat, Lng}'\nalpha AlphaPlan/v1/student/gradelist | jq '.data.Grades'\nalpha AlphaPlan/v1/distanceunit/list | jq '.data.Units'\n```\n\n## Writes (real & permanent here — no dry-run)\n\nBoth require a `studentId`. Bodies are transcribed from the AlphaPortal web\nclient. Values for notification toggles are `0`/`1`.\n\n```sh\n# set walk-zone radius (meters) — affects eligibility\napost AlphaPortal/v1/user-students/radius-edit '{\"studentId\":218652901,\"radius\":800}' | jq\n\n# set notification preferences (per category, push/email, AM/PM).\n# Categories the district enables: stopRadiusEntry, studentScan, backupBus,\n# schoolArrival, stopServiced. Fields: <category>NotifyAm/Pm (push),\n# <category>EmailAm/Pm (email)."},{"path":"skill-card.md","content":"## Description:\n\nGuides authorized users through accessing AlphaPortal student transportation data with shell commands instead of running the MCP server.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chrischall](https://clawhub.ai/user/chrischall)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nAuthorized parents, guardians, and developers use this skill to retrieve student stops, bus locations, and arrival notifications through the AlphaPortal API without an MCP server.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Copying a browser refresh token can expose account access.\n\nMitigation: Use only accounts you are authorized to access; treat tokens like passwords and keep them out of shared terminals, shell history, logs, and printed scripts.\n\nRisk: Student locations and transportation details are sensitive.\n\nMitigation: Limit access to authorized students and avoid logging or sharing returned student data.\n\nRisk: Write examples can change transportation settings without confirmation.\n\nMitigation: Run write commands only with explicit permission and an independent review step.\n\n## Reference(s):\n\n- [AlphaPortal endpoint recipes](references/endpoints.md)\n- [ContextMint Bridge source](https://github.com/nullnet-app/contextmint-bridge)\n- [AlphaPortal MCP skill release](https://clawhub.ai/chrischall/skills/alphaportal-mcp)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration instructions, Guidance]\n\n**Output Format:** [Markdown with shell and JavaScript examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands may expose account tokens or sensitive student transportation data.]\n\n## Skill Version(s):\n\n1.2.3 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the alphaportal-mcp server. Capture the signed-in web app's refresh token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint access tokens and curl the REST API directly. Use when you want AlphaPortal data without the MCP, in a script, or on a machine where the MCP isn't installed. Skill: alphaportal-mcp Owner: chrischall Summary: Access AlphaPortal (AlphaRoute) school-bus data — students, stops, live bus GPS location, arrival notifications — from a shell with curl instead of running the alphaportal-mcp server. Capture the signed-in web app's refresh token ONCE (a paste-in-console one-liner, or the fpx browser bridge), then mint access tokens and curl the REST API directly. Use when you want Al","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1375,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T11:24:33.567Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T11:24:33.567Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:15:33.972Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}