AgentStack
SKILL unreviewed MIT Self-run

Api Gateway

skill-aaaaqwq-agi-super-team-api-gateway · by aAAaqwq

Passthrough proxy for direct access to third-party APIs using managed OAuth connections, provided by [Maton](https://maton.ai). The API gateway lets y

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add skill-aaaaqwq-agi-super-team-api-gateway

Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Reads credentials/environment and may exfiltrate them.

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Api Gateway? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

API Gateway

Passthrough proxy for direct access to third-party APIs using managed OAuth connections, provided by Maton. The API gateway lets you call native API endpoints directly.

Quick Start

# Native Slack API call
python <<'EOF'
import urllib.request, os, json
data = json.dumps({'channel': 'C0123456', 'text': 'Hello from gateway!'}).encode()
req = urllib.request.Request('https://gateway.maton.ai/slack/api/chat.postMessage', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

Base URL

https://gateway.maton.ai/{app}/{native-api-path}

Replace {app} with the service name and {native-api-path} with the actual API endpoint path.

IMPORTANT: The URL path MUST start with the connection's app name (eg. /google-mail/...). This prefix tells the gateway which app connection to use. For example, the native Gmail API path starts with gmail/v1/, so full paths look like /google-mail/gmail/v1/users/me/messages.

Authentication

All requests require the Maton API key in the Authorization header:

Authorization: Bearer $MATON_API_KEY

The API gateway automatically injects the appropriate OAuth token for the target service.

Environment Variable: You can set your API key as the MATON_API_KEY environment variable:

export MATON_API_KEY="YOUR_API_KEY"

Getting Your API Key

  1. Sign in or create an account at maton.ai
  2. Go to maton.ai/settings
  3. Click the copy button on the right side of API Key section to copy it

Connection Management

Connection management uses a separate base URL: https://ctrl.maton.ai

List Connections

python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections?app=slack&status=ACTIVE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

Query Parameters (optional):

  • app - Filter by service name (e.g., slack, hubspot, salesforce)
  • status - Filter by connection status (ACTIVE, PENDING, FAILED)

Response:

{
  "connections": [
    {
      "connection_id": "21fd90f9-5935-43cd-b6c8-bde9d915ca80",
      "status": "ACTIVE",
      "creation_time": "2025-12-08T07:20:53.488460Z",
      "last_updated_time": "2026-01-31T20:03:32.593153Z",
      "url": "https://connect.maton.ai/?session_token=5e9...",
      "app": "slack",
      "method": "OAUTH2",
      "metadata": {}
    }
  ]
}

Create Connection

python <<'EOF'
import urllib.request, os, json
data = json.dumps({'app': 'slack'}).encode()
req = urllib.request.Request('https://ctrl.maton.ai/connections', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

Request Body:

  • app (required) - Service name (e.g., slack, notion)
  • method (optional) - Connection method (API_KEY, BASIC, OAUTH1, OAUTH2, MCP)

Get Connection

python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

Response:

{
  "connection": {
    "connection_id": "21fd90f9-5935-43cd-b6c8-bde9d915ca80",
    "status": "ACTIVE",
    "creation_time": "2025-12-08T07:20:53.488460Z",
    "last_updated_time": "2026-01-31T20:03:32.593153Z",
    "url": "https://connect.maton.ai/?session_token=5e9...",
    "app": "slack",
    "metadata": {}
  }
}

Open the returned URL in a browser to complete OAuth.

Delete Connection

python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}', method='DELETE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

Specifying Connection

If you have multiple connections for the same app, you can specify which connection to use by adding the Maton-Connection header with the connection ID:

python <<'EOF'
import urllib.request, os, json
data = json.dumps({'channel': 'C0123456', 'text': 'Hello!'}).encode()
req = urllib.request.Request('https://gateway.maton.ai/slack/api/chat.postMessage', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
req.add_header('Maton-Connection', '21fd90f9-5935-43cd-b6c8-bde9d915ca80')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

If omitted, the gateway uses the default (oldest) active connection for that app.

Supported Services

| Service | App Name | Base URL Proxied | |---------|----------|------------------| | ActiveCampaign | active-campaign | {account}.api-us1.com | | Acuity Scheduling | acuity-scheduling | acuityscheduling.com | | Airtable | airtable | api.airtable.com | | Apollo | apollo | api.apollo.io | | Asana | asana | app.asana.com | | Attio | attio | api.attio.com | | Basecamp | basecamp | 3.basecampapi.com | | Baserow | baserow | api.baserow.io | | beehiiv | beehiiv | api.beehiiv.com | | Box | box | api.box.com | | Brevo | brevo | api.brevo.com | | Calendly | calendly | api.calendly.com | | Cal.com | cal-com | api.cal.com | | CallRail | callrail | api.callrail.com | | Chargebee | chargebee | {subdomain}.chargebee.com | | ClickFunnels | clickfunnels | {subdomain}.myclickfunnels.com | | ClickSend | clicksend | rest.clicksend.com | | ClickUp | clickup | api.clickup.com | | Clockify | clockify | api.clockify.me | | Coda | coda | coda.io | | Confluence | confluence | api.atlassian.com | | CompanyCam | companycam | api.companycam.com | | Cognito Forms | cognito-forms | www.cognitoforms.com | | Constant Contact | constant-contact | api.cc.email | | Dropbox | dropbox | api.dropboxapi.com | | Dropbox Business | dropbox-business | api.dropboxapi.com | | ElevenLabs | elevenlabs | api.elevenlabs.io | | Eventbrite | eventbrite | www.eventbriteapi.com | | Exa | exa | api.exa.ai | | Fathom | fathom | api.fathom.ai | | Firebase | firebase | firebase.googleapis.com | | Fireflies | fireflies | api.fireflies.ai | | GetResponse | getresponse | api.getresponse.com | | Grafana | grafana | User's Grafana instance | | GitHub | github | api.github.com | | Gumroad | gumroad | api.gumroad.com | | Granola MCP | granola | mcp.granola.ai | | Google Ads | google-ads | googleads.googleapis.com | | Google BigQuery | google-bigquery | bigquery.googleapis.com | | Google Analytics Admin | google-analytics-admin | analyticsadmin.googleapis.com | | Google Analytics Data | google-analytics-data | analyticsdata.googleapis.com | | Google Calendar | google-calendar | www.googleapis.com | | Google Classroom | google-classroom | classroom.googleapis.com | | Google Contacts | google-contacts | people.googleapis.com | | Google Docs | google-docs | docs.googleapis.com | | Google Drive | google-drive | www.googleapis.com | | Google Forms | google-forms | forms.googleapis.com | | Gmail | google-mail | gmail.googleapis.com | | Google Merchant | google-merchant | merchantapi.googleapis.com | | Google Meet | google-meet | meet.googleapis.com | | Google Play | google-play | androidpublisher.googleapis.com | | Google Search Console | google-search-console | www.googleapis.com | | Google Sheets | google-sheets | sheets.googleapis.com | | Google Slides | google-slides | slides.googleapis.com | | Google Tasks | google-tasks | tasks.googleapis.com | | Google Workspace Admin | google-workspace-admin | admin.googleapis.com | | HubSpot | hubspot | api.hubapi.com | | Instantly | instantly | api.instantly.ai | | Jira | jira | api.atlassian.com | | Jobber | jobber | api.getjobber.com | | JotForm | jotform | api.jotform.com | | Kaggle | kaggle | api.kaggle.com | | Keap | keap | api.infusionsoft.com | | Kibana | kibana | User's Kibana instance | | Kit | kit | api.kit.com | | Klaviyo | klaviyo | a.klaviyo.com | | Lemlist | lemlist | api.lemlist.com | | Linear | linear | api.linear.app | | LinkedIn | linkedin | api.linkedin.com | | Mailchimp | mailchimp | {dc}.api.mailchimp.com | | MailerLite | mailerlite | connect.mailerlite.com | | Mailgun | mailgun | api.mailgun.net | | ManyChat | manychat | api.manychat.com | | Manus | manus | api.manus.ai | | Microsoft Excel | microsoft-excel | graph.microsoft.com | | Microsoft Teams | microsoft-teams | graph.microsoft.com | | Microsoft To Do | microsoft-to-do | graph.microsoft.com | | Monday.com | monday | api.monday.com | | Motion | motion | api.usemotion.com | | Netlify | netlify | api.netlify.com | | Notion | notion | api.notion.com | | Notion MCP | notion | mcp.notion.com | | OneDrive | one-drive | graph.microsoft.com | | Outlook | outlook | graph.microsoft.com | | PDF.co | pdf-co | api.pdf.co | | Pipedrive | pipedrive | api.pipedrive.com | | Podio | podio | api.podio.com | | PostHog | posthog | {subdomain}.posthog.com | | QuickBooks | quickbooks | quickbooks.api.intuit.com | | Quo | quo | api.openphone.com | | Reducto | reducto | platform.reducto.ai | | Salesforce | salesforce | {instance}.salesforce.com | | Sentry | sentry | {subdomain}.sentry.io | | SharePoint | sharepoint | graph.microsoft.com | | SignNow | signnow | api.signnow.com | | Slack | slack | slack.com | | Snapchat | snapchat | adsapi.snapchat.com | | Square | squareup | connect.squareup.com | | Squarespace | squarespace | api.squarespace.com | | Sunsama MCP | sunsama | MCP server | | Stripe | stripe | api.stripe.com | | Systeme.io | systeme | api.systeme.io | | Tally | tally | api.tally.so | | Tavily | tavily | api.tavily.com | | Telegram | telegram | api.telegram.org | | TickTick | ticktick | api.ticktick.com | | Todoist | todoist | api.todoist.com | | Toggl Track | toggl-track | api.track.toggl.com | | Trello | trello | api.trello.com | | Twilio | twilio | api.twilio.com | | Typeform | typeform | api.typeform.com | | Unbounce | unbounce | api.unbounce.com | | Vimeo | vimeo | api.vimeo.com | | WhatsApp Business | whatsapp-business | graph.facebook.com | | WooCommerce | woocommerce | {store-url}/wp-json/wc/v3 | | WordPress.com | wordpress | public-api.wordpress.com | | Xero | xero | api.xero.com | | YouTube | youtube | www.googleapis.com | | Zoho Bigin | zoho-bigin | www.zohoapis.com | | Zoho Bookings | zoho-bookings | www.zohoapis.com | | Zoho Books | zoho-books | www.zohoapis.com | | Zoho Calendar | zoho-calendar | calendar.zoho.com | | Zoho CRM | zoho-crm | www.zohoapis.com | | Zoho Inventory | zoho-inventory | www.zohoapis.com | | Zoho Mail | zoho-mail | mail.zoho.com | | Zoho People | zoho-people | people.zoho.com | | Zoho Projects | zoho-projects | projectsapi.zoho.com | | Zoho Recruit | zoho-recruit | recruit.zoho.com |

See [references/](references/) for detailed routing guides per provider:

  • [ActiveCampaign](references/active-campaign/README.md) - Contacts, deals, tags, lists, automations, campaigns
  • [Acuity Scheduling](references/acuity-scheduling/README.md) - Appointments, calendars, clients, availability
  • [Airtable](references/airtable/README.md) - Records, bases, tables
  • [Apollo](references/apollo/README.md) - People search, enrichment, contacts
  • [Asana](references/asana/README.md) - Tasks, projects, workspaces, webhooks
  • [Attio](references/attio/README.md) - People, companies, records, tasks
  • [Basecamp](references/basecamp/README.md) - Projects, to-dos, messages, schedules, documents
  • [Baserow](references/baserow/README.md) - Database rows, fields, tables, batch operations
  • [beehiiv](references/beehiiv/README.md) - Publications, subscriptions, posts, custom fields
  • [Box](references/box/README.md) - Files, folders, collaborations, shared links
  • [Brevo](references/brevo/README.md) - Contacts, email campaigns, transactional emails, templates
  • [Calendly](references/calendly/README.md) - Event types, scheduled events, availability, webhooks
  • [Cal.com](references/cal-com/README.md) - Event types, bookings, schedules, availability slots, webhooks
  • [CallRail](references/callrail/README.md) - Calls, trackers, companies, tags, analytics
  • [Chargebee](references/chargebee/README.md) - Subscriptions, customers, invoices
  • [ClickFunnels](references/clickfunnels/README.md) - Contacts, products, orders, courses, webhooks
  • [ClickSend](references/clicksend/README.md) - SMS, MMS, voice messages, contacts, lists
  • [ClickUp](references/clickup/README.md) - Tasks, lists, folders, spaces, webhooks
  • [Clockify](references/clockify/README.md) - Time tracking, projects, clients, tasks, workspaces
  • [Coda](references/coda/README.md) - Docs, pages, tables, rows, formulas, controls
  • [Confluence](references/confluence/README.md) - Pages, spaces, blogposts, comments, attachments
  • [CompanyCam](references/companycam/README.md) - Projects, photos, users, tags, groups, documents
  • [Cognito Forms](references/cognito-forms/README.md) - Forms, entries, documents, files
  • [Constant Contact](references/constant-contact/README.md) - Contacts, email campaigns, lists, segments
  • [Dropbox](references/dropbox/README.md) - Files, folders, search, metadata, revisions, tags
  • [Dropbox Business](references/dropbox-business/README.md) - Team members, groups, team folders, devices, audit logs
  • [ElevenLabs](references/elevenlabs/README.md) - Text-to-speech, voice cloning, sound effects, audio processing
  • [Eventbrite](references/eventbrite/README.md) - Events, venues, tickets, orders, attendees
  • [Exa](references/exa/README.md) - Neural web search, content extraction, similar pages, AI answers, research tasks
  • [Fathom](references/fathom/README.md) - Meeting recordings, transcripts, summaries, webhooks
  • [Firebase](references/firebase/README.md) - Projects, web apps, Android apps, iOS apps, configurations
  • [Fireflies](references/fireflies/README.md) - Meeting transcripts, summaries, AskFred AI, channels
  • [GetResponse](references/getresponse/README.md) - Campaigns, contacts, newsletters, autoresponders, tags, segments
  • [Grafana](references/grafana/README.md) - Dashboards, data sources, folders, annotations, alerts, teams
  • [GitHub](references/github/README.md) - Repositories, issues, pull requests, commits
  • [Gumroad](references/gumroad/README.md) - Products, sales, subscribers, licenses, webhooks
  • [Granola MCP](references/granola-mcp/README.md) - MCP-based interface for meeting notes, transcripts, queries
  • [Google Ads](references/google-ads/README.md) - Campaigns, ad groups, GAQL queries
  • [Google Analytics Admin](references/google-analytics-admin/README.md) - Reports, dimensions, metrics
  • [Google Analytics Data](references/google-analytics-data/README.md) - Reports, dimensions, metrics
  • [Google BigQuery](references/google-bigquery/README.md) - Datasets, tables, jobs, SQL queries
  • [Google Calendar](references/google-calendar/README.md) - Events, calendars, free/busy
  • [Google Classroom](references/google-classroom/README.md) - Courses, coursework, students, teachers, announcements
  • [Google Contacts](references/google-contac

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.