Mmcp.market

api-gateway skill

by maton-ai·maton-ai/api-gateway-skill·32 stars·MIT

Call third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, run a query through a connected search or scraping provider. Every call goes to an app the user connected. It is not a general-purpose browser or network client, and it cannot reach a service with no Maton connection. It also manages event triggers, webhook destinations that forward event payloads to an external URL until deleted, and local `--exec` handlers that run a script per event - separate, high-risk capabilities beyond a normal API call. Default to read and list calls; every write, connection, trigger, destination, or handler needs explicit user confirmation.

A100/100content scan

Is the api-gateway skill safe?

Clean: nothing in its files matched our rules. We read 235 files in the folder on 2026-09-28.

No findings.

Install the api-gateway skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/maton-ai/api-gateway-skill.git /tmp/api-gateway-skill
mkdir -p ~/.claude/skills
cp -r /tmp/api-gateway-skill/providers/codex/plugin/skills/api-gateway ~/.claude/skills/api-gateway
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Maton API Gateway

Managed API routing for third-party apps, provided by Maton.

Installation

NPM

npm install -g @maton/cli

Homebrew

brew install maton-ai/cli/maton

Authentication

OAuth (Recommended)

maton login --oauth

Opens the OAuth login page in the browser and waits for authorization. Once complete, it creates a profile in config.toml (eg. $HOME/.config/maton/config.toml) and stores the access and refresh tokens in the operating system's credential store (Keychain on macOS, Credential Manager on Windows, Secret Service on Linux), auto-renewed on expiry. The CLI reads them when it needs them; nothing else should.

API Key

maton login --interactive

Requires manually copying an API key from Settings, which is error prone. Once complete, it also creates a profile in config.toml and stores the key in the same credential store. It is preferred over export MATONAPIKEY=..., which exposes a long-lived credential to every child process. When MATONAPIKEY is set, it overrides the active profile. If the CLI cannot be installed at all, see Appendix: Environments Without the CLI for the raw HTTP form and the rules for handling the key.

Verify

maton whoami --json
{
  "authenticated": true,
  "profile_name": "alice@example.com",
  "auth_type": "oauth"
}
  • If authenticated is false, stop and login again via maton login --oauth.
  • If authtype is apikey, it is recommended to login via maton login --oauth and avoid keeping a long-lived credential.

Connections

List Connections

maton connection list slack --status ACTIVE
{
  "connections": [
    {
      "connection_id": "{connection_id}",
      "status": "ACTIVE",
      "creation_time": "2025-12-08T07:20:53.488460Z",
      "last_updated_time": "2026-01-31T20:03:32.593153Z",
      "url": "https://connect.maton.ai/?session_token=5e9...",
      "app": "slack",
      "method": "OAUTH2",
      "metadata": {}
    }
  ]
}

Refer to maton connection list --help for possible flags and values.

Create Connection

Requires explicit user approval. Confirm the specific app and that the user intends to authorize access. Never create a connection on your own initiative.

maton connection create slack

Refer to maton connection create --help for possible flags and values.

Get Connection

maton connection get {connection_id}
{
  "connection": {
    "connection_id": "{connection_id}",
    "status": "PENDING",
    "creation_time": "2025-12-08T07:20:53.488460Z",
    "last_updated_time": "2026-01-31T20:03:32.593153Z",
    "url": "https://connect.maton.ai/?session_token=5e9...",
    "app": "slack",
    "metadata": {}
  }
}

Open the returned URL in a browser to complete authorizing the app. If the app offers scope selection, choose only the scopes the current task needs.

Refer to maton connection get --help for possible flags and values.

Delete Connection

maton connection delete {connection_id} --yes

Refer to maton connection delete --help for possible flags and values.

Specifying Connection

If there are multiple connections for the same app, specify which one to use to ensure requests go to the intended account:

maton slack channel list --types public_channel --limit 10 --connection {connection_id}

Gateway

App Command

maton slack --help                # resources under the app
maton slack message --help        # verbs under the resource
maton slack message send --help   # flags, requirements, examples

Refer to maton --help for a list of supported apps.

API Command

Use maton api to call an API endpoint that has no app command.

maton api '/google-mail/gmail/v1/users/me/messages'
maton api '/slack/api/conversations.list?types=public_channel&limit=10'
maton api '/airtable/v0/meta/bases/{base_id}/tables'

The first path segment is the app identifier. Everything after it is the native API path, forwarded to the upstream host unchanged, including the query string. Check app references under references/.

Refer to maton api --help for possible flags and values.

Functions

List Functions

maton function list --visibility PRIVATE -L 20
{
  "functions": [
    {
      "function_id": "{function_id}",
      "name": "my-fn",
      "description": null,
      "runtime": "python3.12",
      "visibility": "PRIVATE",
      "account_id": "{account_id}",
      "url": "https://my-fn-3k9xq2v.maton.app",
      "star_count": 0,
      "view_count": 0
    }
  ],
  "next_token": "gAAAAABqN6tD5X7..."
}

Refer to maton function list --help for possible flags and values.

Search Functions

maton function search 'stripe refund'
maton function search '"def handler("' --context 2
maton function search '/def\s+handler/' --owner ALL

Refer to maton function search --help for possible flags and values.

Create Function

def handler(event, context):
    return {"hello": "ada"}
maton function create --name my-fn --file main.py

Refer to maton function create --help for possible flags and values.

Update Function

More skills from maton-ai/api-gateway-skill

  • Aapi-gatewayCall third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, run a query through a connected search or scraping provider. Every call goes to an app the user connected. It is not a general-purpose browser or network client, and it cannot reach a service with no Maton connection. It also manages event triggers, webhook destinations that forward event payloads to an external URL until deleted, and local `--exec` handlers that run a script per event - separate, high-risk capabilities beyond a normal API call. Default to read and list calls; every write, connection, trigger, destination, or handler needs explicit user confirmation.
  • Aapi-gatewayCall third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, run a query through a connected search or scraping provider. Every call goes to an app the user connected. It is not a general-purpose browser or network client, and it cannot reach a service with no Maton connection. It also manages event triggers, webhook destinations that forward event payloads to an external URL until deleted, and local `--exec` handlers that run a script per event - separate, high-risk capabilities beyond a normal API call. Default to read and list calls; every write, connection, trigger, destination, or handler needs explicit user confirmation.
  • Aapi-gatewayCall third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, run a query through a connected search or scraping provider. Every call goes to an app the user connected. It is not a general-purpose browser or network client, and it cannot reach a service with no Maton connection. It also manages event triggers, webhook destinations that forward event payloads to an external URL until deleted, and local `--exec` handlers that run a script per event - separate, high-risk capabilities beyond a normal API call. Default to read and list calls; every write, connection, trigger, destination, or handler needs explicit user confirmation.

All agent skills → · MCP servers