Agent skill

Fwrest Client Generator

by totvs in totvs/engpro-advpl-tlpp-skills

Generate AdvPL/TLPP code that CONSUMES external REST APIs using the FWRest client class.

MITAuto-check passedBackend & APIs

Install Fwrest Client Generator

skills CLI
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill fwrest-client-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install totvs/engpro-advpl-tlpp-skills fwrest-client-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/advpl-tlpp/fwrest-client-generator .claude/skills/fwrest-client-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fwrest-client-generator
GitHub stars
143
Token cost
~2.9k tokens
SKILL.md length
1,270 words
Files
4 (incl. references)
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Generate AdvPL/TLPP code that CONSUMES external REST APIs using the FWRest client class.

  • Works in 5 steps: Gather Requirements → Load Templates → Pick the Status-Code Strategy → …
  • User says consume REST API
  • SKILL.md covers Overview, When to Use, FWRest Architecture and Bundled Reference Files, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Fwrest Client Generator is an agent skill from totvs/engpro-advpl-tlpp-skills. Generate AdvPL/TLPP code that CONSUMES external REST APIs using the FWRest client class. Covers GET, POST, PUT, DELETE verbs, header construction, query/path parameters, JSON body serialization, authentication (No Auth, HTTP Basic, Bearer Token/JWT, OAuth 2.0), timeout, SSL, status code handling, error treatment, and TLPP try/catch patterns. Use when user says 'consume REST API', 'call external API', 'FWRest', 'oRestClient', 'integrate with third-party API', 'HTTP client AdvPL', 'POST JSON Protheus', 'Bearer…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/fwrest-api-reference.md`, `references/fwrest-authentication-patterns.md` and `references/fwrest-client-templates.md`).

It sits in Backend & APIs, covering REST APIs, Authentication and Third-party API integration. The repository describes itself as: Repositório contendo skills para orientar desenvolvimento ADVPL/TLPP com agentes de IA. The licence is MIT.

When your agent uses it

  • User says consume REST API
  • Call external API
  • Integrate with third-party API
  • HTTP client AdvPL

Example prompts

  • “consume REST API”
  • “call external API”
  • “FWRest”
  • “/fwrest-client-generator”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Gather Requirements
  2. Load Templates
  3. Pick the Status-Code Strategy
  4. Wrap in Try/Catch + Logging
  5. Validate Against Checklist

What it can do on your machine

Read from SKILL.md and the folder at commit 3908e4e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fwrest Client Generator loads about 2.9k tokens when it runs, and up to ~8.9k if it reads all its reference files. Until then it costs about 138 tokens; SKILL.md has 1,270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from totvs/engpro-advpl-tlpp-skills at commit 3908e4e, republished under its MIT licence (© totvs). 1,270 words, ~2,949 tokens.

Download SKILL.mdSave it as .claude/skills/fwrest-client-generator/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
fwrest-client-generator
description
Generate AdvPL/TLPP code that CONSUMES external REST APIs using the FWRest client class. Covers GET, POST, PUT, DELETE verbs, header construction, query/path parameters, JSON body serialization, authentication (No Auth, HTTP Basic, Bearer Token/JWT, OAuth 2.0), timeout, SSL, status code handling, error treatment, and TLPP try/catch patterns. Use when user says 'consume REST API', 'call external API', 'FWRest', 'oRestClient', 'integrate with third-party API', 'HTTP client AdvPL', 'POST JSON Protheus', 'Bearer token AdvPL'.
license
MIT
metadata.domain
Protheus
metadata.maintainer
Customizações ADVPL/TLPP
metadata.author
Thalion Starforge
metadata.version
4.1.0
metadata.category
Code Generation

FWRest Client Generator

Overview

Generate production-ready AdvPL/TLPP code that consumes external REST APIs using the framework FWRest class. FWRest is the HTTP client class — it is the counterpart to the @Get/@Post annotation-based REST server (see tlpp-rest-endpoint-generator for exposing endpoints, not consuming them).

FWRest wraps low-level HTTP socket calls and supports the four standard verbs GET, POST, PUT, DELETE (no native PATCH support). It handles SSL automatically through appserver.ini socket configuration.

When to Use

Use this skill when generating code that:

  • Calls a third-party REST API from inside Protheus (integrations with CRMs, payment gateways, ERPs, government services, etc.)
  • Sends JSON payloads to external services
  • Pulls data from external endpoints into a Protheus routine
  • Needs HTTP Basic, Bearer/JWT, or OAuth 2.0 authentication
  • Replaces legacy HTTPCGet / HTTPCPost / HTTPQuote calls with the framework client

Do NOT use this skill for:

  • Exposing endpoints from Protheus → use ../tlpp-rest-endpoint-generator/SKILL.md
  • Workstation-side HTTP calls that must run on the user's machine → use HTTPCGet/HTTPCPost with WebAgent
  • File downloads from non-REST endpoints → use HTTPQuote or WSDownload

FWRest Architecture

Lifecycle

A typical FWRest call follows this five-step lifecycle:

  1. Instantiate — oClient := FWRest():New(cHost) where cHost is the base URL only (scheme + host + optional port), e.g. "https://api.example.com".
  2. Configure — SetPath(), SetPostParams(), SetGetParams(), SetTimeOut(), SetChkStatus(), SetLegacySuccess().
  3. Build headers — Plain Array of "Key: Value" strings, e.g. {"Content-Type: application/json", "Authorization: Bearer xyz"}.
  4. Invoke verb — :Get(aHead), :Post(aHead), :Put(aHead, cBody), :Delete(aHead, cBody). All return .T. on success.
  5. Read result — GetResult() on success (response body as character), GetLastError() on failure, GetHTTPCode() for the numeric status.
Path vs Query Parameters
ConcernAPIExample
Path segmentsSetPath("/api/v1/customers/123")URL: /api/v1/customers/123
Query string (inline)SetPath("/api/v1/customers?page=1")URL: /api/v1/customers?page=1
Query string (separate)SetGetParams("page=1&size=20")Appended after path
GET param via verb:Get(aHead, "page=1")Appended after path

Special characters in query values must be URI-encoded via the Escape() function — otherwise the request will fail or be misinterpreted.

Status Code Semantics
MethodBehavior
Get()Returns .T. only for HTTP 200 (legacy) or 200–299 (with SetLegacySuccess(.F.))
Post()Returns .T. for 200 or 201 (legacy) or 200–299 (with SetLegacySuccess(.F.))
Put() / Delete()Returns .T. for 200 or 201 (legacy) or 200–299 (with SetLegacySuccess(.F.))
SetChkStatus(.F.)Disables internal HTTP code validation — verb returns .T. if the connection succeeded, regardless of HTTP code. You then call GetHTTPCode() to decide. Use this for APIs that return 204, 207, 3xx, or 4xx as part of the contract.
No PATCH Support

FWRest does not support the PATCH verb. If the target API requires PATCH, generate code using HTTPQuote() instead and note this limitation explicitly.


Bundled Reference Files

This skill uses progressive disclosure. The SKILL.md body covers the architecture, decision logic, and the generation checklist. Detailed method reference, code templates, and authentication patterns are in the references/ directory — read them on demand based on the scenario:

Reference FileWhen to ReadContent
references/fwrest-api-reference.mdLooking up exact method signatures, parameter types, minimum LIB version per method, or behavior of SetChkStatus/SetLegacySuccess/SetTimeOut/GetHTTPCodeComplete FWRest method reference table with syntax, parameters, returns, LIB version requirements
references/fwrest-client-templates.mdGenerating any FWRest call — GET, POST, PUT, DELETE, JSON parsing, error handling, file upload (.gz), header constructionFull code templates for all 4 HTTP verbs, JSON body construction, response parsing, generic error-handling wrapper
references/fwrest-authentication-patterns.mdImplementing HTTP Basic, Bearer Token / JWT, API Key, or OAuth 2.0 (client credentials / authorization code) authenticationHeader templates for each auth scheme, token-refresh pattern, secret storage guidance

Also refer to references/sonarqube-rules-reference.md for the complete SonarQube rules reference shared across skills.


Generation Workflow

Step 1: Gather Requirements

Identify from the user's request:

  • Target API — base URL, path, and HTTP verb(s)
  • Authentication scheme — None, Basic, Bearer/JWT, API Key, or OAuth 2.0
  • Payload format — JSON (default), XML, form-encoded, binary/gzip
  • Expected response codes — only 2xx, or also 204/3xx/4xx as part of contract
  • Timeout requirement — default 120s vs custom (e.g. webhook endpoints with 5s SLA)
  • Whether the call is part of a transaction — affects error handling strategy
Step 2: Load Templates

Read references/fwrest-client-templates.md for the verb-specific template. Combine with the auth header pattern from references/fwrest-authentication-patterns.md.

Step 3: Pick the Status-Code Strategy
  • Standard CRUD (200/201 only matter): leave defaults.
  • API uses full 2xx range (e.g. 202 Accepted, 204 No Content): call oClient:SetLegacySuccess(.F.) (requires LIB 20240812+).
  • Need to read body of 4xx/5xx responses: call oClient:SetChkStatus(.F.) and inspect GetHTTPCode() + GetResult() manually.
Step 4: Wrap in Try/Catch + Logging

Wrap every FWRest invocation in a TLPP Try/Catch block. Log failures via FWLogMsg() including the URL, HTTP code, and the truncated response body. Never log secrets (tokens, passwords).

Step 5: Validate Against Checklist

Use the checklist below to verify the generated code covers all requirements.


FWRest Client Generation Checklist

Show full SKILL.md (522 more words)Show less
Structure
  • #include "totvs.ch" (AdvPL) or #include "tlpp-core.th" (TLPP) present, in lowercase
  • User Function declares oClient, aHeader, cBody, cResponse, nHttpCode as locals with explicit types (TLPP as Object, as Array, etc.)
  • FWRest():New(cHost) receives ONLY the base URL — path is set via SetPath()
Request Construction
  • SetPath() called with leading /
  • Query parameter values passed through Escape() when they may contain spaces or special chars
  • Headers built as an Array of "Key: Value" strings (note the literal space after the colon)
  • Content-Type header included for POST/PUT bodies (application/json, application/xml, etc.)
  • Body serialized via oJson:toJson() — never built by string concatenation when the data is dynamic
  • SetPostParams(cBody) called before :Post() (Post body is NOT a parameter of :Post())
  • PUT/DELETE bodies passed as the second positional argument of :Put(aHead, cBody) / :Delete(aHead, cBody)
Authentication
  • Secrets read from GetMV() parameter or environment, never hardcoded
  • HTTP Basic: "Authorization: Basic " + Encode64(cUser + ":" + cPass)
  • Bearer/JWT: "Authorization: Bearer " + cToken
  • OAuth 2.0 token-acquisition call is a separate FWRest call to the auth server, cached for the token's expires_in window
  • Token never logged or echoed in error responses
Response Handling
  • Verb result captured in a local lOk (e.g. lOk := oClient:Post(aHeader))
  • GetHTTPCode() retrieved into a local before any branching
  • GetResult() parsed via JsonObject():New() + :fromJson() and the fromJson() return checked (returns Nil on success, error string otherwise)
  • Failure branch reads GetLastError() AND GetHTTPCode() (both can be informative)
Robustness
  • SetTimeOut() set explicitly (default 120s is often too long for synchronous calls)
  • Calls wrapped in Try/Catch to capture transport-layer exceptions
  • SetChkStatus(.F.) used when the API returns 204/4xx as part of contract
  • SetLegacySuccess(.F.) used when the API uses the full 2xx range
  • FreeObj(oClient) after use in long-running routines to release the socket promptly
Logging & Observability
  • Successful calls logged at INFO level with URL + HTTP code (no body)
  • Failed calls logged at ERROR level with URL + HTTP code + truncated response (max ~500 chars)
  • FWLogMsg("ERROR", , "REST_CLIENT", FunName(), , "01", cMessage, 0, 0, {}) pattern used
  • No use of ConOut() for production logging (only acceptable in standalone smoke tests)
  • No secrets, tokens, passwords, or full request bodies emitted to logs
SonarQube Compliance
  • No hardcoded passwords, tokens, or API keys in source code
  • No IIF() — use If/Else/EndIf blocks
  • GetMV() calls outside of loops
  • No UI functions (MsgAlert, MsgYesNo, Aviso, Help) inside the call path of a transaction or scheduled job
  • Includes in lowercase (e.g., #include "totvs.ch")
  • No use of RpcSetEnv inside REST endpoint handlers that themselves invoke FWRest — environment must already be prepared

Refer to references/sonarqube-rules-reference.md for the complete SonarQube rules reference.


Common Pitfalls

PitfallSymptomFix
Full URL passed to New()404 or empty resultPass only https://host:port; use SetPath() for the path
Body passed to :Post() as argumentBody ignored, empty POST sentUse SetPostParams(cBody) before :Post(aHead)
204 response hangs ~2 minutesSlow integrationsSet SetTimeOut(nSec) to a small value, or use HTTPQuote() as alternative
Header missing space after colonServer rejects requestAlways write "Key: Value" with a space
Query string not escapedGarbled parametersWrap values with Escape()
4xx body unreadableGetResult() returns emptyCall SetChkStatus(.F.) first; then read GetResult() even on failure
Hardcoded credentialsSonarQube blockerRead from GetMV("MV_XYZTOK",,"") parameter
PATCH attemptedCompile error / no such methodFWRest does not support PATCH — use HTTPQuote()

© totvs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/advpl-tlpp/fwrest-client-generator of totvs/engpro-advpl-tlpp-skills.

  • SKILL.md
  • references/fwrest-api-reference.md
  • references/fwrest-authentication-patterns.md
  • references/fwrest-client-templates.md

Open the folder on GitHubat commit 3908e4e

Compare with similar skills

Fwrest Client Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fwrest Client Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fwrest Client Generator this skilltotvs/engpro-advpl-tlpp-skills143—~2.9kAutomated safety check: PassMIT
Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~3.2kAutomated safety check: PassMIT
Soundcloud API Integrationsoundcloud/api258—~787Automated safety check: PassNone
OmniRoute Provider Managementdiegosouzapw/OmniRoute74k—~2.4kAutomated safety check: PassMIT
Passport Developmenttrypostit/trypost678—~1.9kAutomated safety check: PassMIT
Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~4kAutomated safety check: PassMIT

Similar skills

  • Frappe Core API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.

    187 GitHub starsUsed in 1 repo~3.2k tokens
    Backend & APIsAuto-check passed
  • Integrates applications with the SoundCloud HTTP API using OAuth 2.1, OpenAPI, and developer docs.

    258 GitHub stars~787 tokensUpdated 8 days ago
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    74k GitHub stars~2.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    678 GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Frappe Errors API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.

    187 GitHub starsUsed in 1 repo~4k tokens
    Backend & APIsAuto-check passed
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed

More from totvs/engpro-advpl-tlpp-skills

All 19 skills in this repo
  • AdvPL UTF-8 to CP1252 Converter

    totvs/engpro-advpl-tlpp-skills

    Converts AdvPL and TLPP source files from UTF-8 to Windows-1252 in place after code generation, because the Protheus compiler accepts only CP1252 files.

    143 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • AdvPL/TLPP Compile in VS Code

    totvs/engpro-advpl-tlpp-skills

    Compiles AdvPL and TLPP sources from VS Code with the TOTVS Developer Studio extension, handling server setup, connection and compile result reporting.

    143 GitHub stars~3.7k tokensUpdated 3 days ago
    Auto-check passed
  • Protheus Spec-Driven Development

    totvs/engpro-advpl-tlpp-skills

    Plans and builds Protheus AdvPL/TLPP features through Specify, Design, Tasks and Execute phases whose depth scales with the size of the change.

    143 GitHub stars~3.6k tokensUpdated 3 days ago
    Auto-check passed
  • AdvPL and TLPP Code Review

    totvs/engpro-advpl-tlpp-skills

    Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity.

    143 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Protheus Data Dictionary Lookup

    totvs/engpro-advpl-tlpp-skills

    Queries the TOTVS Protheus ERP data dictionary for tables, fields, indexes, parameters, triggers and lookups, including impact checks during refactoring.

    143 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed
  • Protheus MVC Generator

    totvs/engpro-advpl-tlpp-skills

    Generates Protheus MVC screens in ADVPL/TLPP, with ModelDef, ViewDef, MenuDef and Browse functions for single-entity and master-detail layouts.

    143 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Fwrest Client Generator

What does Fwrest Client Generator do?

Generate AdvPL/TLPP code that CONSUMES external REST APIs using the FWRest client class. Fwrest Client Generator is an agent skill from totvs/engpro-advpl-tlpp-skills. Generate AdvPL/TLPP code that CONSUMES external REST APIs using the FWRest client class.

When should I use Fwrest Client Generator?

Fwrest Client Generator fits situations like: user says consume REST API; call external API; integrate with third-party API; HTTP client AdvPL.

How do I install Fwrest Client Generator in Claude Code?

Run `npx skills add totvs/engpro-advpl-tlpp-skills --skill fwrest-client-generator -a claude-code`. Or copy the skill folder (skills/advpl-tlpp/fwrest-client-generator in totvs/engpro-advpl-tlpp-skills) into .claude/skills/fwrest-client-generator in your project. Claude Code loads it when a task matches its description.

How do I install Fwrest Client Generator in Codex?

Run `npx skills add totvs/engpro-advpl-tlpp-skills --skill fwrest-client-generator -a codex`. Or copy the skill folder (skills/advpl-tlpp/fwrest-client-generator in totvs/engpro-advpl-tlpp-skills) into .agents/skills/fwrest-client-generator in your project. Codex loads it when a task matches its description.

Can I use Fwrest Client Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add totvs/engpro-advpl-tlpp-skills --skill fwrest-client-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fwrest-client-generator, .gemini/skills/fwrest-client-generator, .github/skills/fwrest-client-generator and .opencode/skills/fwrest-client-generator in your project.

What does Fwrest Client Generator need to run?

SKILL.md names no scripts, command-line tools or credentials: Fwrest Client Generator is instructions for the agent only.

Does Fwrest Client Generator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fwrest Client Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fwrest Client Generator use?

Fwrest Client Generator is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fwrest Client Generator use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6k tokens, read only when the agent opens those files.

What are the alternatives to Fwrest Client Generator?

Skills that share tags, products or a category with Fwrest Client Generator: Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars), Soundcloud API Integration (soundcloud/api, 258 stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 74k stars) and Passport Development (trypostit/trypost, 678 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fwrest Client Generator?

totvs (a GitHub organization) maintains it in totvs/engpro-advpl-tlpp-skills, which has 143 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 5, 2026.

Source: totvs/engpro-advpl-tlpp-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.