Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…

MITAuto-check: notesBackend & APIs

Install Emulate

skills CLI
$ npx skills add UsefulSoftwareCo/executor --skill emulate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install UsefulSoftwareCo/executor emulate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/UsefulSoftwareCo/executor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/emulate .claude/skills/emulate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
emulate
GitHub stars
4.1k
Token cost
~2.2k tokens
SKILL.md length
921 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…

  • Works in 4 steps: Edit in the emulate repo, then rebuild… → Publish a version bump of… → Deploy the hosted Cloudflare emulators… → …
  • Demo needs a real-shaped upstream API
  • SKILL.md covers Two ways to get one, The typed control-plane client, Recipes and Changing or deploying an…, plus 1 more section
  • Calls bun; reaches emulators.dev and resend.emulators.dev

What it does

Emulate is an agent skill from UsefulSoftwareCo/executor. Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a request ledger for assertions. Use when a test or demo needs a real-shaped upstream API, an OAuth/OIDC provider, a spec to feed addSpec, or proof that a request actually landed.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect and OpenAPI specifications. It works with WorkOS, GitHub and Stripe. The repository describes itself as: The missing integration layer for AI agents. Let them call any OpenAPI / MCP / GraphQL / custom js functions in secure environment. The licence is MIT.

When your agent uses it

  • Demo needs a real-shaped upstream API
  • An OAuth/OIDC provider
  • A spec to feed addSpec
  • Proof that a request actually landed

Example prompts

  • “/emulate”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Edit in the emulate repo, then rebuild the package you changed. It
  2. Publish a version bump of @executor-js/emulate to npm.
  3. Deploy the hosted Cloudflare emulators (the emulate-hosts worker behind
  4. Back in executor, bump the @executor-js/emulate dependency to the version

What it can do on your machine

Read from SKILL.md and the folder at commit 27dccb8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • emulators.dev
    • resend.emulators.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Emulate loads about 2.2k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 921 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:88
    human-pokeable cloud instance with zero .env**:

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from UsefulSoftwareCo/executor at commit 27dccb8, republished under its MIT licence (© UsefulSoftwareCo). 921 words, ~2,178 tokens.

Download SKILL.mdSave it as .claude/skills/emulate/SKILL.md (or your agent's skills folder).
name
emulate
description
Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a request ledger for assertions. Use when a test or demo needs a real-shaped upstream API, an OAuth/OIDC provider, a spec to feed addSpec, or proof that a request actually landed.

Emulate: production-fidelity service emulators

@executor-js/emulate (our fork of Vercel Labs' emulate) provides stateful, wire-level emulators for 16 services: github vercel google okta microsoft spotify slack apple aws resend stripe mongoatlas clerk x workos autumn. These are not mocks: real SDKs and real product code run against them unmodified — the cloud e2e target points the actual WorkOS SDK (sealed sessions, JWKS, hosted AuthKit login) and Autumn billing at emulators and exercises the product's real auth code.

This repo only consumes the published npm package. There is no vendor/emulate submodule — everything imports @executor-js/emulate from npm. The emulator source is its own standalone project; to change or deploy an emulator, see "Changing or deploying an emulator" at the bottom.

Two ways to get one

Local, programmatic (what e2e/setup/cloud.boot.ts does):

ts
import { createEmulator } from "@executor-js/emulate";
const github = await createEmulator({ service: "github", port: 4501 });
// github.url, await github.close() — plus the full typed client below

baseUrl sets the advertised origin (redirects, form actions, spec servers) when a proxy fronts the emulator — the bind stays on port.

Attach to a running one (another process, or hosted on Cloudflare with Durable Object state at https://<service>.<instance>.emulators.dev — catalog at GET https://emulators.dev/_emulate/services). Service hosts (https://<service>.emulators.dev) are control plane only, with no shared default instance behind them: create a private instance first and connect to the returned providerBaseUrl.

ts
import { connectEmulator } from "@executor-js/emulate";
const created = await fetch("https://resend.emulators.dev/_emulate/instances", { method: "POST" });
const { providerBaseUrl } = await created.json();
const resend = await connectEmulator({ baseUrl: providerBaseUrl });
// optional: { service: "resend" } verifies the manifest on connect

In e2e scenarios use createEmulatorInstance from e2e/src/emulator-instance.ts, which wraps this.

The typed control-plane client

Both createEmulator and connectEmulator return the same EmulatorClient surface (since 0.7.0) — use it instead of hand-rolling /_emulate fetches:

CallUse
client.openapiUrlThe spec URL — feed it straight to Executor's addSpec to register the emulator as an integration
client.credentials.mint({type:"api-key"})IssuedCredential in the service's real shape: API keys, bearer tokens, OAuth/OIDC clients, client-credentials apps
client.ledger.list() / .clear()LedgerEntry[]: matched operationId, sanitized headers/body, auth identity, response status, webhook deliveries
client.seed({...})Add state via the service's seed schema (e.g. WorkOS {oauth:{default_access_token_ttl_seconds:60}} to compress token expiry)
client.reset()Reset state + logs, replay seed — works remotely, unlike the old local-only reset
client.manifest() / .quickstart() / .specs() / .coverage()What the service is, which operations are real vs partial
client.state() / .logs() / .connections()Store snapshot, webhook deliveries, copyable SDK/env/curl snippets

The same routes exist as raw HTTP under /_emulate/* (start at GET /_emulate/quickstart, written for agents) for curl/browser use — but in TypeScript, reach for the client; the types are the point.

Recipes

Test an integration end-to-end for real (the connect-handoff pattern): client.credentials.mint(...) → register client.openapiUrl with the product → invoke a tool through the product → find the call in client.ledger.list() (match on entry.request.body / operationId). The ledger is the proof — "the product made this exact upstream call with this auth" — which beats asserting on the product's own response.

Real OAuth/OIDC flows: google/okta/microsoft/apple/clerk/workos mint OAuth clients and run real authorize/token endpoints. The WorkOS emulator additionally serves hosted AuthKit login pages (any email signs in — users are minted on the fly, no password), an OAuth authorization server for MCP clients, and Vault KV. Real SDK + WORKOS_API_URL override = the product's untouched auth code against it. Set EMULATE_WORKOS_AUDIENCE=<client_id> before createEmulator so minted MCP access tokens carry the right audience.

A live, human-pokeable cloud instance with zero .env: cd e2e && bun run cli up cloud --share — WorkOS + Autumn emulators + the app's real dev stack (recipe in e2e/setup/cloud.boot.ts), fronted with tailscale HTTPS.

Show full SKILL.md (414 more words)Show less

Changing or deploying an emulator

The emulators live in their own repo — not in executor and not a submodule: github.com/UsefulSoftwareCo/emulate (clone it as a sibling of executor). It's a pnpm + turbo monorepo on node ≥ 24 — a different toolchain from executor's bun, which is exactly why it's standalone rather than vendored here.

You have full autonomy over it: work directly on main, and commit, push, publish, and deploy without asking. The loop:

  1. Edit in the emulate repo, then rebuild the package you changed. It resolves through built dist, so a source-only edit does nothing until you build it — this is the single most common mistake. @emulators/* packages are a workspace:* graph, so adding or renaming one needs an install + rebuild too.
  2. Publish a version bump of @executor-js/emulate to npm.
  3. Deploy the hosted Cloudflare emulators (the emulate-hosts worker behind *.emulators.dev) when behavior the hosted instances serve has changed.
  4. Back in executor, bump the @executor-js/emulate dependency to the version you just published. Never point a consumer at a local checkout to ship — publish, then bump.

The emulate repo's own AGENTS.md / README.md carry the current build, publish, and deploy commands (npm + Cloudflare creds are in 1Password). Read them there rather than memorizing flags here — they move.

A hot deploy can redden other people's e2e. The emulate-hosts worker behind *.emulators.dev is shared infrastructure; a control-plane regression there has failed unrelated PRs' suites before. Scenarios always run on private per-run instances (POST /_emulate/instances); when a scenario needs behavior that isn't deployed yet, pin to a published package version.

Gotchas

  • Secure cookies need HTTPS off-localhost. Browser-driven flows work on 127.0.0.1, but from another device (tailnet) the app's secure: true auth cookies are dropped over http → "Invalid login state". Front BOTH the app and the emulator with HTTPS (tailscale serve), and give the emulator its public origin via baseUrl AND the app's WORKOS_API_URL — the authorize URL the browser follows is derived from the latter.
  • State is per-process and id counters restart. The WorkOS emulator mints org ids from a per-boot counter — a persisted app DB from a previous boot collides with new ids. Wipe the app's data dir when you restart the emulator (the e2e globalsetup and cloud-demo both do).
  • Don't hand-write fake upstreams. If a scenario needs an upstream API, OAuth provider, or webhook source, reach for an emulator before writing a bespoke stub server — you get specs, auth, and the ledger for free, and the e2e AGENTS.md "never modify product code or stubs" rule stays intact.

© UsefulSoftwareCo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/emulate of UsefulSoftwareCo/executor.

Open the folder on GitHubat commit 27dccb8

Compare with similar skills

Emulate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Emulate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Emulate this skillUsefulSoftwareCo/executor4.1k—~2.2kAutomated safety check: NotesMIT
OneCLI Gatewaynanocoai/nanoclaw31k—~856Automated safety check: PassMIT
Emulate Seedyonatangross/orchestkit288—~4.5kAutomated safety check: PassMIT
Stripe Appsfossasia/eventyay1.7k1 repos~3.6kAutomated safety check: PassApache-2.0
Stripe Best Practiceskanchengw/cnllm1753 repos~925Automated safety check: PassApache-2.0
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence

Similar skills

  • OneCLI Gateway

    nanocoai/nanoclaw

    Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

    31k GitHub stars~856 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Emulate Seed

    yonatangross/orchestkit

    Generate emulate seed configs for stateful API emulation. An agent skill from yonatangross/orchestkit.

    288 GitHub stars~4.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Stripe Apps

    fossasia/eventyay

    A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.

    1.7k GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    175 GitHub starsUsed in 3 repos~925 tokens
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Backend & APIsAuto-check passed
  • GitHub OAuth Nango Integration

    AgentWorkforce/relay

    A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling

    865 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed

More from UsefulSoftwareCo/executor

All 21 skills in this repo
  • Effect Client Wrapper

    UsefulSoftwareCo/executor

    Pattern for wrapping third-party SDK clients (Stripe, Resend, AWS, etc.) with Effect.

    4.1k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • CLI Release

    UsefulSoftwareCo/executor

    Runbook for releasing the executor CLI package (stable and beta).

    4.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Effect Atom Optimistic Updates

    UsefulSoftwareCo/executor

    Pattern for implementing optimistic UI updates with effect-atom in this codebase.

    4.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Effect HTTP Testing

    UsefulSoftwareCo/executor

    Testing Effect HttpApi services end-to-end. An agent skill from UsefulSoftwareCo/executor.

    4.1k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Prod Telemetry

    UsefulSoftwareCo/executor

    Query Executor's production telemetry — Axiom traces (executor-cloud dataset), prod Postgres via PlanetScale, PostHog product analytics — through the Executor MCP.

    4.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Self Contained Modals

    UsefulSoftwareCo/executor

    Build modals/dialogs self-contained: form and in-flight state lives inside, closing unmounts it.

    4.1k GitHub stars~878 tokensUpdated today
    Auto-check passed

Categories

Questions about Emulate

What does Emulate do?

Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…. Emulate is an agent skill from UsefulSoftwareCo/executor. Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a request ledger for assertions.

When should I use Emulate?

Emulate fits situations like: demo needs a real-shaped upstream API; an OAuth/OIDC provider; A spec to feed addSpec; proof that a request actually landed.

How do I install Emulate in Claude Code?

Run `npx skills add UsefulSoftwareCo/executor --skill emulate -a claude-code`. Or copy the skill folder (.claude/skills/emulate in UsefulSoftwareCo/executor) into .claude/skills/emulate in your project. Claude Code loads it when a task matches its description.

How do I install Emulate in Codex?

Run `npx skills add UsefulSoftwareCo/executor --skill emulate -a codex`. Or copy the skill folder (.claude/skills/emulate in UsefulSoftwareCo/executor) into .agents/skills/emulate in your project. Codex loads it when a task matches its description.

Can I use Emulate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add UsefulSoftwareCo/executor --skill emulate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/emulate, .gemini/skills/emulate, .github/skills/emulate and .opencode/skills/emulate in your project.

What does Emulate need to run?

Going by SKILL.md and its folder, Emulate needs the command-line tools its instructions call (bun).

Does Emulate access the network?

SKILL.md names 2 domains. In commands or code: emulators.dev and resend.emulators.dev; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Emulate safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Emulate use?

Emulate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Emulate use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Emulate?

Skills that share tags, products or a category with Emulate: OneCLI Gateway (nanocoai/nanoclaw, 31k stars), Emulate Seed (yonatangross/orchestkit, 288 stars), Stripe Apps (fossasia/eventyay, 1.7k stars) and Stripe Best Practices (kanchengw/cnllm, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Emulate?

UsefulSoftwareCo (a GitHub organization) maintains it in UsefulSoftwareCo/executor, which has 4,085 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: UsefulSoftwareCo/executor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.