Agent skill

LangBot Core Development

by langbot-app in langbot-app/LangBot

Covers developing the LangBot core backend and web UI: dev setup, repo layout, API auth types, adding endpoints, migrations and keeping the MCP server in step.

Apache-2.0Auto-check: notesDevelopment

Install LangBot Core Development

skills CLI
$ npx skills add langbot-app/LangBot --skill langbot-dev -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbot-app/LangBot langbot-dev --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbot-app/LangBot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skills/langbot-dev .claude/skills/langbot-dev && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
langbot-dev
GitHub stars
18k
Token cost
~1.4k tokens
SKILL.md length
403 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Covers developing the LangBot core backend and web UI: dev setup, repo layout, API auth types, adding endpoints, migrations and keeping the MCP server in step.

  • Works in 2 steps: the global key from config.yaml… → web-UI keys whose one-time lbk_ secret…
  • Adding an HTTP API endpoint to the LangBot backend
  • SKILL.md covers Stack, Dev environment, Repo layout (key paths) and HTTP API auth model, plus 5 more sections
  • Calls uv, pnpm and pip; needs USER_TOKEN and API_KEY

What it does

This skill is for work inside the main LangBot repository, as opposed to plugin development or deployment, which have their own skills. The backend is Python on the Quart framework with dependencies managed by `uv`, and the web UI under `web/` is Vite with React Router, shadcn/ui and Tailwind, managed with `pnpm`. It notes that the UI is not Next.js, since the dev script runs `vite`.

The first run generates `data/config.yaml`, the database defaults to SQLite with PostgreSQL supported, and migrations run automatically on startup. Route authentication is declared per route as `NONE`, `USER_TOKEN`, `API_KEY` or `USER_TOKEN_OR_API_KEY`; authenticated routes receive an immutable request context, and API keys take their workspace from the key record, not from a request header. New endpoints need a controller, a matching service method and the right auth type, and the description adds that API changes must also update the MCP server and skills.

When your agent uses it

  • Adding an HTTP API endpoint to the LangBot backend
  • Choosing between user token, API key and public access for a route
  • Setting up the Python and pnpm dev environment for LangBot
  • Writing an Alembic migration for a LangBot schema change

Example prompts

  • “Add a GET endpoint that lists a bot's recent messages, protected by an API key.”
  • “Why does my LangBot route return 401 when I call it with the global key?”
  • “Set up the LangBot backend and web UI dev servers on my machine.”
  • “I changed an API response in LangBot. What else do I need to update?”

Requirements

  • Python with `uv`
  • pnpm for the web frontend

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. the global key from config.yaml api.global_api_key only for a
  2. web-UI keys whose one-time lbk_ secret is stored only as a hash and is

What it can do on your machine

Read from SKILL.md and the folder at commit de886ed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • pnpm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • USER_TOKEN
    • API_KEY
    • USER_TOKEN_OR_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

LangBot Core Development loads about 1.4k tokens when it runs. Until then it costs about 142 tokens; SKILL.md has 403 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:28
    cp .env.example .env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langbot-app/LangBot at commit de886ed, republished under its Apache-2.0 licence (© langbot-app). 403 words, ~1,396 tokens.

Download SKILL.mdSave it as .claude/skills/langbot-dev/SKILL.md (or your agent's skills folder).
name
langbot-dev
description
Develop, build, and debug the LangBot core backend and web frontend. Use when working inside the LangBot repository — backend (Python/Quart, src/langbot/pkg), the Vite/React web UI, HTTP API controllers/services, Alembic migrations, or the MCP server. Covers the dev environment (uv, pnpm), repo layout, the API auth model (user token / API key / global key), adding API endpoints, and the rule that API changes must update the MCP server and skills. Triggers on "langbot backend", "langbot dev", "langbot api", "add langbot endpoint", "langbot migration".

LangBot Core Development

This skill covers developing the LangBot core (the main repo), distinct from plugin development (see langbot-plugin-dev) and deployment (langbot-deploy).

Stack

  • Backend: Python >=3.11,<4.0, deps via uv. Framework: Quart (async Flask). Serves the HTTP API + pre-built web UI on http://127.0.0.1:5300.
  • Frontend (web/): Vite + React Router 7 + shadcn/ui + Tailwind, managed by pnpm. Dev server on :3000. (NOT Next.js — dev script is vite.)

Dev environment

bash
# Backend
pip install uv
uv sync --dev
uv run main.py            # API + UI on http://127.0.0.1:5300

# Frontend (separate terminal)
cd web
cp .env.example .env
pnpm install
pnpm dev                  # http://127.0.0.1:3000 (reads VITE_API_BASE_URL)

# Lint/format hooks (CI runs the same checks)
uv run pre-commit install

First run generates data/config.yaml; DB defaults to SQLite (PostgreSQL supported). Migrations run automatically on startup.

Repo layout (key paths)

src/langbot/
├── __main__.py             # entrypoint, CLI flags (--standalone-runtime/-box/--debug)
├── pkg/
│   ├── api/
│   │   ├── http/           # Quart controllers + services
│   │   │   ├── controller/groups/   # route groups (@group.group_class)
│   │   │   └── service/             # business logic (called by controllers AND MCP)
│   │   └── mcp/            # MCP server (server.py = tools, mount.py = ASGI dispatch)
│   ├── core/               # app bootstrap, stages, task manager
│   ├── platform/ provider/ pipeline/ plugin/ box/ skill/ rag/ vector/
│   ├── command/ persistence/ storage/ config/ entity/ telemetry/
│   └── templates/config.yaml        # config template (top-level: api, system, plugin, box, space...)
├── web/                    # Vite SPA
└── docker/                 # compose deployment

HTTP API auth model

Route auth is declared per-route via AuthType in pkg/api/http/controller/group.py:

  • NONE — public.
  • USER_TOKEN — web UI JWT (Authorization: Bearer <jwt>).
  • API_KEY — X-API-Key or Authorization: Bearer <key>.
  • USER_TOKEN_OR_API_KEY — either.

Authenticated routes receive an immutable RequestContext containing the principal, authorized Workspace membership, fixed-role permissions, instance, request id, and placement generation. A browser's X-Workspace-Id is only a selector and is always checked against the Account membership. Tenant services must accept this context (or an explicit trusted execution context) and fail closed when it is absent.

API-key authentication accepts:

  1. the global key from config.yaml api.global_api_key only for a community instance with exactly one local Workspace, then
  2. web-UI keys whose one-time lbk_ secret is stored only as a hash and is bound to one Workspace, explicit scopes, status, and optional expiry.

An API key derives its Workspace from the key record and ignores a caller's Workspace selector. Public Bot/Webhook routes similarly derive Workspace from the opaque owning resource rather than a header.

Route groups self-register via @group.group_class(name, path) and are discovered by importutil.import_modules_in_pkg.

Show full SKILL.md (147 more words)Show less

Adding an API endpoint

  1. Add/extend a controller in pkg/api/http/controller/groups/ and the matching service method in pkg/api/http/service/.
  2. Pick the right AuthType.
  3. If the endpoint should be agent-accessible, add/adjust the matching MCP tool in pkg/api/mcp/server.py and update the langbot-mcp-ops skill. API and MCP surface must stay aligned (see AGENTS.md).
  4. If lbctl uses the route or capability, check the separate langbot-cli client for compatibility.
  5. Update docs/service-api-openapi.json if you maintain the OpenAPI overview.

Database migrations (Alembic)

Single migration set supports SQLite + PostgreSQL. Files in src/langbot/pkg/persistence/alembic/versions/.

bash
# From project root (needs data/config.yaml)
uv run python -m langbot.pkg.persistence.alembic_runner autogenerate "description"

Standards

  • All code comments/docstrings in English; user-facing strings need i18n (en_US + zh_Hans minimum, ja_JP where present).
  • Consider toC and toB compatibility + security.
  • Commit format: <type>(<scope>): <subject> (feat/fix/docs/refactor/...).

Tests

bash
uv run pytest tests/unit_tests -q          # unit tests
uv run pytest tests/unit_tests/api -q      # API service tests
uv run python tests/manual/mcp_smoke.py    # MCP server e2e smoke

See also

  • langbot-plugin-dev — plugin SDK / runtime development.
  • langbot-testing — WebUI/e2e QA harness (bin/lbs).
  • langbot-deploy — Docker/compose deployment + config.
  • langbot-mcp-ops — operating the LangBot MCP server.
  • langbot-cli — lbctl, a standalone Service API client for managing running Workspaces.

© langbot-app, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/skills/langbot-dev of langbot-app/LangBot.

Open the folder on GitHubat commit de886ed

Compare with similar skills

LangBot Core Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

LangBot Core Development compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
LangBot Core Development this skilllangbot-app/LangBot18k—~1.4kAutomated safety check: NotesApache-2.0
Spa Auth Developmentgdarko/laravel-vue-starter145—~668Automated safety check: NotesMIT
Vue Component Developmentgdarko/laravel-vue-starter145—~1.1kAutomated safety check: PassMIT
Fastapi Appccplugins/awesome-claude-code-plugins967—~1.1kAutomated safety check: NotesApache-2.0
Fullstack DevHHU3637kr/skills1453 repos~8.6kAutomated safety check: NotesMIT
Fullstack Devinfometa/workbuddyskills342—~1kAutomated safety check: PassMIT

Similar skills

  • Spa Auth Development

    gdarko/laravel-vue-starter

    Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

    145 GitHub stars~668 tokensUpdated 6 mo ago
    Backend & APIsAuto-check: notes
  • Vue Component Development

    gdarko/laravel-vue-starter

    Activate when creating or modifying Vue 3 components, pages, layouts, stores, or services in the frontend.

    145 GitHub stars~1.1k tokensUpdated 6 mo ago
    Frontend & DesignAuto-check passed
  • Fastapi App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Fullstack Dev

    HHU3637kr/skills

    Full-stack backend architecture and frontend-backend integration guide.

    145 GitHub starsUsed in 3 repos~8.6k tokens
    Backend & APIsAuto-check: notes
  • Fullstack Dev

    infometa/workbuddyskills

    Full-stack backend architecture and frontend-backend integration guide.

    342 GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Mastering Python Skill

    SpillwaveSolutions/agent-brain

    Modern Python coaching covering language foundations through advanced production patterns.

    120 GitHub stars~1.4k tokensUpdated 17 days ago
    DevelopmentAuto-check: notes

More from langbot-app/LangBot

All 9 skills in this repo
  • LangBot Plugin Development

    langbot-app/LangBot

    Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.

    18k GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Guides building, migrating and testing LangBot messaging-platform adapters for the Event-Based Agents layout, with unified event and message conversion.

    18k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • LangBot MCP Operations

    langbot-app/LangBot

    Manages a LangBot instance over its built-in MCP server: endpoint, API-key authentication, client config and the tool set for bots, processors and more.

    18k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • LangBot Space MCP

    langbot-app/LangBot

    Browses and searches the LangBot Space marketplaces for plugins, MCP servers and skills through its read-only MCP server, authenticated with a personal access token.

    18k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • LangBot Environment Setup

    langbot-app/LangBot

    Prepares a LangBot development and testing environment for an agent, covering service startup, proxy settings and browser access through Computer Use or Playwright MCP.

    18k GitHub stars~496 tokensUpdated today
    Auto-check: notes

Questions about LangBot Core Development

What does LangBot Core Development do?

Covers developing the LangBot core backend and web UI: dev setup, repo layout, API auth types, adding endpoints, migrations and keeping the MCP server in step. This skill is for work inside the main LangBot repository, as opposed to plugin development or deployment, which have their own skills. The backend is Python on the Quart framework with dependencies managed by `uv`, and the web UI under `web/` is Vite with React Router, shadcn/ui and Tailwind, managed with `pnpm`.

When should I use LangBot Core Development?

LangBot Core Development fits situations like: adding an HTTP API endpoint to the LangBot backend; choosing between user token, API key and public access for a route; setting up the Python and pnpm dev environment for LangBot; writing an Alembic migration for a LangBot schema change.

How do I install LangBot Core Development in Claude Code?

Run `npx skills add langbot-app/LangBot --skill langbot-dev -a claude-code`. Or copy the skill folder (skills/skills/langbot-dev in langbot-app/LangBot) into .claude/skills/langbot-dev in your project. Claude Code loads it when a task matches its description.

How do I install LangBot Core Development in Codex?

Run `npx skills add langbot-app/LangBot --skill langbot-dev -a codex`. Or copy the skill folder (skills/skills/langbot-dev in langbot-app/LangBot) into .agents/skills/langbot-dev in your project. Codex loads it when a task matches its description.

Can I use LangBot Core Development in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbot-app/LangBot --skill langbot-dev -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/langbot-dev, .gemini/skills/langbot-dev, .github/skills/langbot-dev and .opencode/skills/langbot-dev in your project.

What does LangBot Core Development need to run?

Going by SKILL.md and its folder, LangBot Core Development needs the command-line tools its instructions call (uv, pnpm and pip) and credentials named USER_TOKEN, API_KEY and USER_TOKEN_OR_API_KEY. Our summary lists: Python with `uv`; pnpm for the web frontend.

Does LangBot Core Development access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is LangBot Core Development safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does LangBot Core Development use?

LangBot Core Development is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does LangBot Core Development use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to LangBot Core Development?

Skills that share tags, products or a category with LangBot Core Development: Spa Auth Development (gdarko/laravel-vue-starter, 145 stars), Vue Component Development (gdarko/laravel-vue-starter, 145 stars), Fastapi App (ccplugins/awesome-claude-code-plugins, 967 stars) and Fullstack Dev (HHU3637kr/skills, 145 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains LangBot Core Development?

langbot-app (a GitHub organization) maintains it in langbot-app/LangBot, which has 18,033 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: langbot-app/LangBot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.