Install the "api-gateway" agent skill from https://github.com/CraftOS-dev/CraftBot/tree/main/skills/api-gateway into .claude/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add CraftOS-dev/CraftBot --skill api-gateway -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "api-gateway" agent skill from https://github.com/CraftOS-dev/CraftBot/tree/main/skills/api-gateway into .agents/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add CraftOS-dev/CraftBot --skill api-gateway -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "api-gateway" agent skill from https://github.com/CraftOS-dev/CraftBot/tree/main/skills/api-gateway into .cursor/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add CraftOS-dev/CraftBot --skill api-gateway -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "api-gateway" agent skill from https://github.com/CraftOS-dev/CraftBot/tree/main/skills/api-gateway into .gemini/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add CraftOS-dev/CraftBot --skill api-gateway -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "api-gateway" agent skill from https://github.com/CraftOS-dev/CraftBot/tree/main/skills/api-gateway into .github/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add CraftOS-dev/CraftBot --skill api-gateway -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "api-gateway" agent skill from https://github.com/CraftOS-dev/CraftBot/tree/main/skills/api-gateway into .opencode/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
api-gateway
GitHub stars
392
Used in
3 other repos
Token cost
~7.1k tokens
SKILL.md length
1,698 words
Files
120 (incl. references)
Skills in repo
89
Repo updated
First seen
Licence
MIT
At a glance
Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth.
Works in 3 steps: Sign in or create an account at maton.ai → Go to maton.ai/settings → Click the copy button on the right side…
Users want to interact with external services
SKILL.md covers Quick Start, Base URL, Authentication and Getting Your API Key, plus 8 more sections
Calls python; reaches gateway.maton.ai and ctrl.maton.ai; needs MATON_API_KEY
What it does
API Gateway is an agent skill from CraftOS-dev/CraftBot. Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth. Use this skill when users want to interact with external services. Security: The MATONAPIKEY authenticates with Maton.ai but grants NO access to third-party services by itself. Each service requires explicit OAuth authorization by the user through Maton's connect flow. Access is strictly scoped to connections the user has authorized. Provided by Maton (https://maton.ai).
Its SKILL.md is about 7.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 121 other files, including reference files (for example `.clawhub/origin.json`, `_meta.json` and `references/active-campaign.md`). Compatibility notes: Requires network access and valid Maton API key
It sits in Backend & APIs, covering Microservices, Cloud office suites and CRM management. It works with Airtable, HubSpot, Google Workspace and Microsoft 365. The repository describes itself as: One agent. Every kind of work. The licence is MIT.
When your agent uses it
Users want to interact with external services
Tasks that involve Microservices
Tasks that involve Cloud office suites
Example prompts
“/api-gateway”
Requirements
Python 3
A credential in MATON_API_KEY
A credential in YOUR_API_KEY
Compatibility (from SKILL.md): Requires network access and valid Maton API key
Workflow steps
3 steps, taken from the first numbered list in SKILL.md.
1Sign in or create an account at maton.ai
2Go to maton.ai/settings
3Click the copy button on the right side of API Key section to copy it
What it can do on your machine
Read from SKILL.md and the folder at commit b50970c. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
python
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
gateway.maton.ai
ctrl.maton.ai
connect.maton.ai
slack.com
api.hubapi.com
sheets.googleapis.com
api.airtable.com
api.notion.com
api.stripe.com
Also links to:
maton.ai
github.com
discord.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names these keys or tokens, usually read from environment variables:
MATON_API_KEY
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Compatibility
Requires network access and valid Maton API key
From compatibility in the SKILL.md frontmatter.
Context cost
API Gateway loads about 7.1k tokens when it runs, and up to ~123k if it reads all its reference files. Until then it costs about 126 tokens; SKILL.md has 1,698 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~126
When it runs· the whole SKILL.md, loaded when a task matches
~7.1k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~123k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/api-gateway/SKILL.md (or your agent's skills folder). This skill also uses 119 other files; get the full folder from GitHub.
name
api-gateway
description
Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth.
Use this skill when users want to interact with external services.
Security: The MATON_API_KEY authenticates with Maton.ai but grants NO access to third-party services by itself. Each service requires explicit OAuth authorization by the user through Maton's connect flow. Access is strictly scoped to connections the user has authorized. Provided by Maton (https://maton.ai).
compatibility
Requires network access and valid Maton API key
metadata.author
maton
metadata.version
1.0
API Gateway
Passthrough proxy for direct access to third-party APIs using managed OAuth connections, provided by Maton. The API gateway lets you call native API endpoints directly.
Replace {app} with the service name and {native-api-path} with the actual API endpoint path.
IMPORTANT: The URL path MUST start with the connection's app name (eg. /google-mail/...). This prefix tells the gateway which app connection to use. For example, the native Gmail API path starts with gmail/v1/, so full paths look like /google-mail/gmail/v1/users/me/messages.
Authentication
All requests require the Maton API key in the Authorization header:
Authorization: Bearer $MATON_API_KEY
The API gateway automatically injects the appropriate OAuth token for the target service.
Environment Variable: You can set your API key as the MATON_API_KEY environment variable:
If you have multiple connections for the same app, you can specify which connection to use by adding the Maton-Connection header with the connection ID:
A 500 error may indicate an expired OAuth token. Try creating a new connection via the Connection Management section above and completing OAuth authorization. If the new connection is "ACTIVE", delete the old connection to ensure the gateway uses the new one.
Rate Limits
10 requests per second per account
Target API rate limits also apply
Notes
When using curl with URLs containing brackets (fields[], sort[], records[]), use the -g flag to disable glob parsing
When piping curl output to jq, environment variables may not expand correctly in some shells, which can cause "Invalid API key" errors
Tips
Use native API docs: Refer to each service's official API documentation for endpoint paths and parameters.
Headers are forwarded: Custom headers (except Host and Authorization) are forwarded to the target API.
Query params work: URL query parameters are passed through to the target API.
All HTTP methods supported: GET, POST, PUT, PATCH, DELETE are all supported.
QuickBooks special case: Use :realmId in the path and it will be replaced with the connected realm ID.
We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in CraftOS-dev/CraftBot, which our catalogue first saw on October 7, 2026.
API Gateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…
Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth. API Gateway is an agent skill from CraftOS-dev/CraftBot.) with managed OAuth.
When should I use API Gateway?
API Gateway fits situations like: users want to interact with external services; tasks that involve Microservices; tasks that involve Cloud office suites.
How do I install API Gateway in Claude Code?
Run `npx skills add CraftOS-dev/CraftBot --skill api-gateway -a claude-code`. Or copy the skill folder (skills/api-gateway in CraftOS-dev/CraftBot) into .claude/skills/api-gateway in your project. Claude Code loads it when a task matches its description.
How do I install API Gateway in Codex?
Run `npx skills add CraftOS-dev/CraftBot --skill api-gateway -a codex`. Or copy the skill folder (skills/api-gateway in CraftOS-dev/CraftBot) into .agents/skills/api-gateway in your project. Codex loads it when a task matches its description.
Can I use API Gateway in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CraftOS-dev/CraftBot --skill api-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-gateway, .gemini/skills/api-gateway, .github/skills/api-gateway and .opencode/skills/api-gateway in your project.
What does API Gateway need to run?
Going by SKILL.md and its folder, API Gateway needs the command-line tools its instructions call (python) and credentials named MATON_API_KEY. Our summary lists: Python 3; A credential in MATON_API_KEY; A credential in YOUR_API_KEY. Compatibility (from SKILL.md): Requires network access and valid Maton API key.
Does API Gateway access the network?
SKILL.md names 12 domains. In commands or code: gateway.maton.ai, ctrl.maton.ai, connect.maton.ai, slack.com, api.hubapi.com, sheets.googleapis.com, api.airtable.com, api.notion.com and api.stripe.com; the agent is likely to contact these when it follows the instructions. As links in the text: maton.ai, github.com and discord.com. This is read from the text; nothing was executed.
Is API Gateway safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does API Gateway use?
API Gateway is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does API Gateway use?
About 7.1k tokens (SKILL.md is roughly 29k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 116k tokens, read only when the agent opens those files.
What are the alternatives to API Gateway?
Skills that share tags, products or a category with API Gateway: Implementing Zero Trust For SaaS Applications (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Google Workspace (RedWoodOG/Hermes-Desktop, 177 stars) and Sap Btp Build Work Zone Advanced (secondsky/sap-skills, 460 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains API Gateway?
CraftOS-dev (a GitHub user) maintains it in CraftOS-dev/CraftBot, which has 392 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 7, 2026.
Source: CraftOS-dev/CraftBot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.