Agent skill

Runtime Admin API

by mendixlabs in mendixlabs/mxcli

Call the Mendix M2EE admin API on port 8090 directly — OQL, runtime info, and the rest, with curl examples.

Apache-2.0Auto-check: notesDevelopment

Install Runtime Admin API

skills CLI
$ npx skills add mendixlabs/mxcli --skill runtime-admin-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mendixlabs/mxcli runtime-admin-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mendixlabs/mxcli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/mendix/runtime-admin-api .claude/skills/runtime-admin-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
runtime-admin-api
GitHub stars
128
Token cost
~2k tokens
SKILL.md length
655 words
Files
1
Skills in repo
72
Repo updated
First seen
Licence
Apache-2.0

At a glance

Call the Mendix M2EE admin API on port 8090 directly — OQL, runtime info, and the rest, with curl examples.

  • Querying a running app from a script
  • SKILL.md covers When to Use This Skill, Admin API Overview, Authentication and curl Examples, plus 6 more sections
  • Calls curl, docker and jq; needs DB_PASSWORD
  • Debugging connectivity to the admin port

What it does

Runtime Admin API is an agent skill from mendixlabs/mxcli. Call the Mendix M2EE admin API on port 8090 directly — OQL, runtime info, and the rest, with curl examples. Use when querying a running app from a script, or when debugging connectivity to the admin port.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: Mendix cli tool, a headless way to work with Mendix projects. Enables Mendix projects for use with 3rd party agentic coding tools like Claude Code and Copilot. Includes a… The licence is Apache-2.0.

When your agent uses it

  • Querying a running app from a script
  • Debugging connectivity to the admin port

Example prompts

  • “/runtime-admin-api”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 20a6c89. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • docker
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DB_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Runtime Admin API loads about 2k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 655 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:20
    onfigurable via `ADMIN_PORT` in `.docker/.env`). This API is used by the Mendix Cloud, M2EE tools, and `mxcli oql` to ma
  • NoteMentions a .env fileSKILL.md:22
    **Default credentials** (from `.docker/.env`):
  • NoteMentions a .env fileSKILL.md:132
    ql` auto-reads credentials from `.docker/.env` when `-p` is provided.
  • NoteMentions a .env fileSKILL.md:170
    All settings are in `.docker/.env`:
  • NoteMentions a .env fileSKILL.md:187
    rd | Check `M2EE_ADMIN_PASS` in `.docker/.env` |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mendixlabs/mxcli at commit 20a6c89, republished under its Apache-2.0 licence (© mendixlabs). 655 words, ~2,034 tokens.

Download SKILL.mdSave it as .claude/skills/runtime-admin-api/SKILL.md (or your agent's skills folder).
name
runtime-admin-api
description
Call the Mendix M2EE admin API on port 8090 directly — OQL, runtime info, and the rest, with curl examples. Use when querying a running app from a script, or when debugging connectivity to the admin port.

Runtime Admin API Skill

This skill documents the Mendix M2EE admin API exposed on port 8090, including how to call it directly with curl.

When to Use This Skill

Use this when:

  • The user wants to query the running Mendix app directly (OQL, runtime info)
  • The user needs to debug connectivity to the admin port
  • The user wants to call the M2EE admin API from scripts or external tools
  • The user asks about the Mendix admin console or management API

Admin API Overview

The Mendix runtime exposes an HTTP admin API on port 8090 (configurable via ADMIN_PORT in .docker/.env). This API is used by the Mendix Cloud, M2EE tools, and mxcli oql to manage and query the runtime.

Default credentials (from .docker/.env):

  • Port: 8090
  • Password: AdminPassword1!
  • Auth method: X-M2EE-authentication header with the password base64-encoded

Authentication

All requests require the X-M2EE-authentication header containing the base64-encoded admin password:

bash
# Encode the password
echo -n 'AdminPassword1!' | base64
# Result: QWRtaW5QYXNzd29yZDEh

The header value is base64(password) — NOT base64(user:password) (this is not HTTP Basic Auth).

curl Examples

OQL Query (Read-Only Preview)

Mendix 11.11 changed the wire protocol. OQL preview moved off the M2EE action dispatch onto a dedicated REST endpoint POST /dev/preview_execute_oql, where the request body is the params object directly and the response is {"data":[...]} (no action/params wrapper, no feedback envelope). The auth header is unchanged. mxcli oql tries this endpoint first and falls back to the legacy action below on a 404 (older runtimes), so it works on both.

11.11+ (new endpoint):

bash
curl -sf -X post http://localhost:8090/dev/preview_execute_oql \
  -H 'Content-Type: application/json' \
  -H "X-M2EE-authentication: $(echo -n 'AdminPassword1!' | base64)" \
  -d '{"oql":"SELECT Name FROM System.User","numberHandling":"asString"}'
# -> {"data":[{"Name":"MxAdmin"}, ...]}

A failed query on the dev endpoint returns HTTP 200 (not 4xx/5xx) with an {"error":"..."} body and no data field, e.g.:

json
{"error":"An exception has occurred for the following request(s):\n\tInternalOqlTextGetRequest (depth = -1): SELECT ..."}

So an error must be detected by the presence of the error field, not by the HTTP status. mxcli oql surfaces this message instead of returning empty.

Pre-11.11 (legacy action):

bash
curl -sf -X post http://localhost:8090/ \
  -H 'Content-Type: application/json' \
  -H "X-M2EE-authentication: $(echo -n 'AdminPassword1!' | base64)" \
  -d '{"action":"preview_execute_oql","params":{"oql":"SELECT Name FROM System.User","numberHandling":"asString"}}'

Response format (all M2EE responses use this envelope):

json
{
  "result": 0,
  "feedback": {
    "data": [
      {"Name": "MxAdmin"},
      {"Name": "demo_user"}
    ]
  }
}
  • result: 0 = success, non-zero = error
  • On error: cause and/or message fields contain the error description
  • Data rows are JSON objects with column names as keys
More OQL Examples
bash
# count entities
curl -sf -X post http://localhost:8090/ \
  -H 'Content-Type: application/json' \
  -H "X-M2EE-authentication: $(echo -n 'AdminPassword1!' | base64)" \
  -d '{"action":"preview_execute_oql","params":{"oql":"SELECT count(*) AS Total FROM MyModule.Customer","numberHandling":"asString"}}'

# join query
curl -sf -X post http://localhost:8090/ \
  -H 'Content-Type: application/json' \
  -H "X-M2EE-authentication: $(echo -n 'AdminPassword1!' | base64)" \
  -d '{"action":"preview_execute_oql","params":{"oql":"SELECT o.OrderNumber, c.Name FROM MyModule.Order o JOIN o/MyModule.Order_Customer/MyModule.Customer c","numberHandling":"asString"}}'
Runtime Info
bash
curl -sf -X post http://localhost:8090/ \
  -H 'Content-Type: application/json' \
  -H "X-M2EE-authentication: $(echo -n 'AdminPassword1!' | base64)" \
  -d '{"action":"runtime_status"}'

Using mxcli oql (Preferred)

mxcli oql wraps the admin API with automatic credential resolution and output formatting:

bash
# table output (default)
./mxcli oql -p app.mpr "select Name from System.User"

# json output for piping
./mxcli oql -p app.mpr --json "SELECT Name FROM System.User" | jq '.[].Name'

# Explicit connection (no project needed)
./mxcli oql --host localhost --port 8090 --token 'AdminPassword1!' "SELECT 1"

mxcli oql auto-reads credentials from .docker/.env when -p is provided.

Devcontainer / DinD Connectivity

In a devcontainer with Docker-in-Docker, port 8090 on the Mendix container may bind to 127.0.0.1 inside the DinD daemon and be unreachable from the devcontainer host. mxcli oql handles this automatically by routing through docker compose exec:

bash
# What mxcli does internally (docker exec mode):
docker compose -f .docker/docker-compose.yml exec -T mendix sh -c \
  "curl -sf -X post http://localhost:8090/ \
   -H 'Content-Type: application/json' \
   -H 'X-M2EE-Authentication: QWRtaW5QYXNzd29yZDEh' \
   -d '{\"action\":\"preview_execute_oql\",\"params\":{\"oql\":\"SELECT 1\",\"numberHandling\":\"asString\"}}'"

Use --direct to bypass docker exec and connect via HTTP directly (when the port is reachable):

bash
./mxcli oql -p app.mpr --direct "SELECT 1"
Show full SKILL.md (245 more words)Show less

Prerequisites

The preview_execute_oql action requires a JVM flag on the runtime:

-Dmendix.live-preview=enabled

This is included in the default docker-compose template generated by mxcli docker init. If you get "action not found: preview_execute_oql", re-initialize:

bash
./mxcli docker init -p app.mpr --force
./mxcli docker run -p app.mpr --wait

Configuration Reference

All settings are in .docker/.env:

VariableDefaultDescription
APP_PORT8080Web application port
ADMIN_PORT8090Admin API port
M2EE_ADMIN_PASSAdminPassword1!Admin password (used for auth header)
DB_PORT5432PostgreSQL port (exposed to host)
DB_NAMEmendixDatabase name
DB_USERmendixDatabase user
DB_PASSWORDmendixDatabase password

Troubleshooting

ProblemCauseFix
Connection refused on :8090App not runningmxcli docker up -p app.mpr --wait
HTTP 401/403Wrong passwordCheck M2EE_ADMIN_PASS in .docker/.env
"Action not found: preview_execute_oql"Missing JVM flagmxcli docker init -p app.mpr --force then restart
Empty responseRuntime still startingWait for "Runtime successfully started" in logs
Can't reach port from devcontainerDinD network isolationUse mxcli oql (auto-routes via docker exec) or --direct if port is forwarded
Admin API binds to localhost onlyDefault HOCON configRebuild with mxcli docker build — auto-patches admin.addresses = ["*"]
--direct Mode

By default, mxcli oql routes queries through docker compose exec to avoid DinD networking issues. When the admin port is directly reachable (e.g., after the admin.addresses build patch), use --direct for faster queries:

bash
# Direct HTTP connection (no docker exec overhead)
mxcli oql -p app.mpr --direct "SELECT Name FROM System.User"

The build patch admin.addresses = ["*"] is applied automatically by mxcli docker build. After rebuilding, --direct mode works out of the box.

© mendixlabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/mendix/runtime-admin-api of mendixlabs/mxcli.

Open the folder on GitHubat commit 20a6c89

Compare with similar skills

Runtime Admin API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Runtime Admin API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Runtime Admin API this skillmendixlabs/mxcli128—~2kAutomated safety check: NotesApache-2.0
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from mendixlabs/mxcli

All 72 skills in this repo
  • Mendix Odata Pushdown

    mendixlabs/mxcli

    Push OData query options into the SQL of a Mendix resource served by a read microflow, so $filter, $orderby, $top, $skip, $count and the key lookup reach the database instead of being silently…

    128 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Mendix Vega Charts

    mendixlabs/mxcli

    Chart a Mendix app with Vega-Lite through a pluggable widget that takes the specification and the data as separate properties, so the model emits rows and never assembles a chart payload.

    128 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Agents

    mendixlabs/mxcli

    Author Mendix AI agent documents in MDL — Model, Knowledge Base, Consumed MCP Service and Agent, with variables, tools and multi-line prompts.

    128 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Mendix Bulk Oql Dml

    mendixlabs/mxcli

    Run set-based INSERT, UPDATE and DELETE against Mendix entities through OQL statements, which the runtime supports and Studio Pro cannot author.

    128 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Business Events

    mendixlabs/mxcli

    Define event-driven APIs over Kafka with Mendix business event services — publish and subscribe contracts, CREATE/DROP/DESCRIBE.

    128 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Catalog Search

    mendixlabs/mxcli

    Search the Mendix Catalog platform service registry (catalog.mendix.com) from the CLI to find services published across an organisation.

    128 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Categories

Questions about Runtime Admin API

What does Runtime Admin API do?

Call the Mendix M2EE admin API on port 8090 directly — OQL, runtime info, and the rest, with curl examples. Runtime Admin API is an agent skill from mendixlabs/mxcli. Call the Mendix M2EE admin API on port 8090 directly — OQL, runtime info, and the rest, with curl examples.

When should I use Runtime Admin API?

Runtime Admin API fits situations like: querying a running app from a script; debugging connectivity to the admin port.

How do I install Runtime Admin API in Claude Code?

Run `npx skills add mendixlabs/mxcli --skill runtime-admin-api -a claude-code`. Or copy the skill folder (.claude/skills/mendix/runtime-admin-api in mendixlabs/mxcli) into .claude/skills/runtime-admin-api in your project. Claude Code loads it when a task matches its description.

How do I install Runtime Admin API in Codex?

Run `npx skills add mendixlabs/mxcli --skill runtime-admin-api -a codex`. Or copy the skill folder (.claude/skills/mendix/runtime-admin-api in mendixlabs/mxcli) into .agents/skills/runtime-admin-api in your project. Codex loads it when a task matches its description.

Can I use Runtime Admin API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mendixlabs/mxcli --skill runtime-admin-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/runtime-admin-api, .gemini/skills/runtime-admin-api, .github/skills/runtime-admin-api and .opencode/skills/runtime-admin-api in your project.

What does Runtime Admin API need to run?

Going by SKILL.md and its folder, Runtime Admin API needs the command-line tools its instructions call (curl, docker and jq) and credentials named DB_PASSWORD. Our summary lists: Docker.

Does Runtime Admin API access the network?

SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Runtime Admin API safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Runtime Admin API use?

Runtime Admin API is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Runtime Admin API use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Runtime Admin API?

Skills that share tags, products or a category with Runtime Admin API: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Runtime Admin API?

mendixlabs (a GitHub organization) maintains it in mendixlabs/mxcli, which has 128 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 7, 2026.

Source: mendixlabs/mxcli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.