Install
$ agentstack add skill-aaaaqwq-agi-super-team-api-gateway Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Reads credentials/environment and may exfiltrate them.
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
API Gateway
Passthrough proxy for direct access to third-party APIs using managed OAuth connections, provided by Maton. The API gateway lets you call native API endpoints directly.
Quick Start
# Native Slack API call
python <<'EOF'
import urllib.request, os, json
data = json.dumps({'channel': 'C0123456', 'text': 'Hello from gateway!'}).encode()
req = urllib.request.Request('https://gateway.maton.ai/slack/api/chat.postMessage', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Base URL
https://gateway.maton.ai/{app}/{native-api-path}
Replace {app} with the service name and {native-api-path} with the actual API endpoint path.
IMPORTANT: The URL path MUST start with the connection's app name (eg. /google-mail/...). This prefix tells the gateway which app connection to use. For example, the native Gmail API path starts with gmail/v1/, so full paths look like /google-mail/gmail/v1/users/me/messages.
Authentication
All requests require the Maton API key in the Authorization header:
Authorization: Bearer $MATON_API_KEY
The API gateway automatically injects the appropriate OAuth token for the target service.
Environment Variable: You can set your API key as the MATON_API_KEY environment variable:
export MATON_API_KEY="YOUR_API_KEY"
Getting Your API Key
- Sign in or create an account at maton.ai
- Go to maton.ai/settings
- Click the copy button on the right side of API Key section to copy it
Connection Management
Connection management uses a separate base URL: https://ctrl.maton.ai
List Connections
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections?app=slack&status=ACTIVE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Query Parameters (optional):
app- Filter by service name (e.g.,slack,hubspot,salesforce)status- Filter by connection status (ACTIVE,PENDING,FAILED)
Response:
{
"connections": [
{
"connection_id": "21fd90f9-5935-43cd-b6c8-bde9d915ca80",
"status": "ACTIVE",
"creation_time": "2025-12-08T07:20:53.488460Z",
"last_updated_time": "2026-01-31T20:03:32.593153Z",
"url": "https://connect.maton.ai/?session_token=5e9...",
"app": "slack",
"method": "OAUTH2",
"metadata": {}
}
]
}
Create Connection
python <<'EOF'
import urllib.request, os, json
data = json.dumps({'app': 'slack'}).encode()
req = urllib.request.Request('https://ctrl.maton.ai/connections', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Request Body:
app(required) - Service name (e.g.,slack,notion)method(optional) - Connection method (API_KEY,BASIC,OAUTH1,OAUTH2,MCP)
Get Connection
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"connection": {
"connection_id": "21fd90f9-5935-43cd-b6c8-bde9d915ca80",
"status": "ACTIVE",
"creation_time": "2025-12-08T07:20:53.488460Z",
"last_updated_time": "2026-01-31T20:03:32.593153Z",
"url": "https://connect.maton.ai/?session_token=5e9...",
"app": "slack",
"metadata": {}
}
}
Open the returned URL in a browser to complete OAuth.
Delete Connection
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}', method='DELETE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Specifying Connection
If you have multiple connections for the same app, you can specify which connection to use by adding the Maton-Connection header with the connection ID:
python <<'EOF'
import urllib.request, os, json
data = json.dumps({'channel': 'C0123456', 'text': 'Hello!'}).encode()
req = urllib.request.Request('https://gateway.maton.ai/slack/api/chat.postMessage', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
req.add_header('Maton-Connection', '21fd90f9-5935-43cd-b6c8-bde9d915ca80')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
If omitted, the gateway uses the default (oldest) active connection for that app.
Supported Services
| Service | App Name | Base URL Proxied | |---------|----------|------------------| | ActiveCampaign | active-campaign | {account}.api-us1.com | | Acuity Scheduling | acuity-scheduling | acuityscheduling.com | | Airtable | airtable | api.airtable.com | | Apollo | apollo | api.apollo.io | | Asana | asana | app.asana.com | | Attio | attio | api.attio.com | | Basecamp | basecamp | 3.basecampapi.com | | Baserow | baserow | api.baserow.io | | beehiiv | beehiiv | api.beehiiv.com | | Box | box | api.box.com | | Brevo | brevo | api.brevo.com | | Calendly | calendly | api.calendly.com | | Cal.com | cal-com | api.cal.com | | CallRail | callrail | api.callrail.com | | Chargebee | chargebee | {subdomain}.chargebee.com | | ClickFunnels | clickfunnels | {subdomain}.myclickfunnels.com | | ClickSend | clicksend | rest.clicksend.com | | ClickUp | clickup | api.clickup.com | | Clockify | clockify | api.clockify.me | | Coda | coda | coda.io | | Confluence | confluence | api.atlassian.com | | CompanyCam | companycam | api.companycam.com | | Cognito Forms | cognito-forms | www.cognitoforms.com | | Constant Contact | constant-contact | api.cc.email | | Dropbox | dropbox | api.dropboxapi.com | | Dropbox Business | dropbox-business | api.dropboxapi.com | | ElevenLabs | elevenlabs | api.elevenlabs.io | | Eventbrite | eventbrite | www.eventbriteapi.com | | Exa | exa | api.exa.ai | | Fathom | fathom | api.fathom.ai | | Firebase | firebase | firebase.googleapis.com | | Fireflies | fireflies | api.fireflies.ai | | GetResponse | getresponse | api.getresponse.com | | Grafana | grafana | User's Grafana instance | | GitHub | github | api.github.com | | Gumroad | gumroad | api.gumroad.com | | Granola MCP | granola | mcp.granola.ai | | Google Ads | google-ads | googleads.googleapis.com | | Google BigQuery | google-bigquery | bigquery.googleapis.com | | Google Analytics Admin | google-analytics-admin | analyticsadmin.googleapis.com | | Google Analytics Data | google-analytics-data | analyticsdata.googleapis.com | | Google Calendar | google-calendar | www.googleapis.com | | Google Classroom | google-classroom | classroom.googleapis.com | | Google Contacts | google-contacts | people.googleapis.com | | Google Docs | google-docs | docs.googleapis.com | | Google Drive | google-drive | www.googleapis.com | | Google Forms | google-forms | forms.googleapis.com | | Gmail | google-mail | gmail.googleapis.com | | Google Merchant | google-merchant | merchantapi.googleapis.com | | Google Meet | google-meet | meet.googleapis.com | | Google Play | google-play | androidpublisher.googleapis.com | | Google Search Console | google-search-console | www.googleapis.com | | Google Sheets | google-sheets | sheets.googleapis.com | | Google Slides | google-slides | slides.googleapis.com | | Google Tasks | google-tasks | tasks.googleapis.com | | Google Workspace Admin | google-workspace-admin | admin.googleapis.com | | HubSpot | hubspot | api.hubapi.com | | Instantly | instantly | api.instantly.ai | | Jira | jira | api.atlassian.com | | Jobber | jobber | api.getjobber.com | | JotForm | jotform | api.jotform.com | | Kaggle | kaggle | api.kaggle.com | | Keap | keap | api.infusionsoft.com | | Kibana | kibana | User's Kibana instance | | Kit | kit | api.kit.com | | Klaviyo | klaviyo | a.klaviyo.com | | Lemlist | lemlist | api.lemlist.com | | Linear | linear | api.linear.app | | LinkedIn | linkedin | api.linkedin.com | | Mailchimp | mailchimp | {dc}.api.mailchimp.com | | MailerLite | mailerlite | connect.mailerlite.com | | Mailgun | mailgun | api.mailgun.net | | ManyChat | manychat | api.manychat.com | | Manus | manus | api.manus.ai | | Microsoft Excel | microsoft-excel | graph.microsoft.com | | Microsoft Teams | microsoft-teams | graph.microsoft.com | | Microsoft To Do | microsoft-to-do | graph.microsoft.com | | Monday.com | monday | api.monday.com | | Motion | motion | api.usemotion.com | | Netlify | netlify | api.netlify.com | | Notion | notion | api.notion.com | | Notion MCP | notion | mcp.notion.com | | OneDrive | one-drive | graph.microsoft.com | | Outlook | outlook | graph.microsoft.com | | PDF.co | pdf-co | api.pdf.co | | Pipedrive | pipedrive | api.pipedrive.com | | Podio | podio | api.podio.com | | PostHog | posthog | {subdomain}.posthog.com | | QuickBooks | quickbooks | quickbooks.api.intuit.com | | Quo | quo | api.openphone.com | | Reducto | reducto | platform.reducto.ai | | Salesforce | salesforce | {instance}.salesforce.com | | Sentry | sentry | {subdomain}.sentry.io | | SharePoint | sharepoint | graph.microsoft.com | | SignNow | signnow | api.signnow.com | | Slack | slack | slack.com | | Snapchat | snapchat | adsapi.snapchat.com | | Square | squareup | connect.squareup.com | | Squarespace | squarespace | api.squarespace.com | | Sunsama MCP | sunsama | MCP server | | Stripe | stripe | api.stripe.com | | Systeme.io | systeme | api.systeme.io | | Tally | tally | api.tally.so | | Tavily | tavily | api.tavily.com | | Telegram | telegram | api.telegram.org | | TickTick | ticktick | api.ticktick.com | | Todoist | todoist | api.todoist.com | | Toggl Track | toggl-track | api.track.toggl.com | | Trello | trello | api.trello.com | | Twilio | twilio | api.twilio.com | | Typeform | typeform | api.typeform.com | | Unbounce | unbounce | api.unbounce.com | | Vimeo | vimeo | api.vimeo.com | | WhatsApp Business | whatsapp-business | graph.facebook.com | | WooCommerce | woocommerce | {store-url}/wp-json/wc/v3 | | WordPress.com | wordpress | public-api.wordpress.com | | Xero | xero | api.xero.com | | YouTube | youtube | www.googleapis.com | | Zoho Bigin | zoho-bigin | www.zohoapis.com | | Zoho Bookings | zoho-bookings | www.zohoapis.com | | Zoho Books | zoho-books | www.zohoapis.com | | Zoho Calendar | zoho-calendar | calendar.zoho.com | | Zoho CRM | zoho-crm | www.zohoapis.com | | Zoho Inventory | zoho-inventory | www.zohoapis.com | | Zoho Mail | zoho-mail | mail.zoho.com | | Zoho People | zoho-people | people.zoho.com | | Zoho Projects | zoho-projects | projectsapi.zoho.com | | Zoho Recruit | zoho-recruit | recruit.zoho.com |
See [references/](references/) for detailed routing guides per provider:
- [ActiveCampaign](references/active-campaign/README.md) - Contacts, deals, tags, lists, automations, campaigns
- [Acuity Scheduling](references/acuity-scheduling/README.md) - Appointments, calendars, clients, availability
- [Airtable](references/airtable/README.md) - Records, bases, tables
- [Apollo](references/apollo/README.md) - People search, enrichment, contacts
- [Asana](references/asana/README.md) - Tasks, projects, workspaces, webhooks
- [Attio](references/attio/README.md) - People, companies, records, tasks
- [Basecamp](references/basecamp/README.md) - Projects, to-dos, messages, schedules, documents
- [Baserow](references/baserow/README.md) - Database rows, fields, tables, batch operations
- [beehiiv](references/beehiiv/README.md) - Publications, subscriptions, posts, custom fields
- [Box](references/box/README.md) - Files, folders, collaborations, shared links
- [Brevo](references/brevo/README.md) - Contacts, email campaigns, transactional emails, templates
- [Calendly](references/calendly/README.md) - Event types, scheduled events, availability, webhooks
- [Cal.com](references/cal-com/README.md) - Event types, bookings, schedules, availability slots, webhooks
- [CallRail](references/callrail/README.md) - Calls, trackers, companies, tags, analytics
- [Chargebee](references/chargebee/README.md) - Subscriptions, customers, invoices
- [ClickFunnels](references/clickfunnels/README.md) - Contacts, products, orders, courses, webhooks
- [ClickSend](references/clicksend/README.md) - SMS, MMS, voice messages, contacts, lists
- [ClickUp](references/clickup/README.md) - Tasks, lists, folders, spaces, webhooks
- [Clockify](references/clockify/README.md) - Time tracking, projects, clients, tasks, workspaces
- [Coda](references/coda/README.md) - Docs, pages, tables, rows, formulas, controls
- [Confluence](references/confluence/README.md) - Pages, spaces, blogposts, comments, attachments
- [CompanyCam](references/companycam/README.md) - Projects, photos, users, tags, groups, documents
- [Cognito Forms](references/cognito-forms/README.md) - Forms, entries, documents, files
- [Constant Contact](references/constant-contact/README.md) - Contacts, email campaigns, lists, segments
- [Dropbox](references/dropbox/README.md) - Files, folders, search, metadata, revisions, tags
- [Dropbox Business](references/dropbox-business/README.md) - Team members, groups, team folders, devices, audit logs
- [ElevenLabs](references/elevenlabs/README.md) - Text-to-speech, voice cloning, sound effects, audio processing
- [Eventbrite](references/eventbrite/README.md) - Events, venues, tickets, orders, attendees
- [Exa](references/exa/README.md) - Neural web search, content extraction, similar pages, AI answers, research tasks
- [Fathom](references/fathom/README.md) - Meeting recordings, transcripts, summaries, webhooks
- [Firebase](references/firebase/README.md) - Projects, web apps, Android apps, iOS apps, configurations
- [Fireflies](references/fireflies/README.md) - Meeting transcripts, summaries, AskFred AI, channels
- [GetResponse](references/getresponse/README.md) - Campaigns, contacts, newsletters, autoresponders, tags, segments
- [Grafana](references/grafana/README.md) - Dashboards, data sources, folders, annotations, alerts, teams
- [GitHub](references/github/README.md) - Repositories, issues, pull requests, commits
- [Gumroad](references/gumroad/README.md) - Products, sales, subscribers, licenses, webhooks
- [Granola MCP](references/granola-mcp/README.md) - MCP-based interface for meeting notes, transcripts, queries
- [Google Ads](references/google-ads/README.md) - Campaigns, ad groups, GAQL queries
- [Google Analytics Admin](references/google-analytics-admin/README.md) - Reports, dimensions, metrics
- [Google Analytics Data](references/google-analytics-data/README.md) - Reports, dimensions, metrics
- [Google BigQuery](references/google-bigquery/README.md) - Datasets, tables, jobs, SQL queries
- [Google Calendar](references/google-calendar/README.md) - Events, calendars, free/busy
- [Google Classroom](references/google-classroom/README.md) - Courses, coursework, students, teachers, announcements
- [Google Contacts](references/google-contac
…
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: aAAaqwq
- Source: aAAaqwq/AGI-Super-Team
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.