Token导航 LogoToken导航TokenDH.com
开发敏感数据github未标认证来源可访问许可证需确认审计提醒

frappe-core-apifrappe core API 文档

Agent Skill

用于辅助 API 设计、接口文档、请求响应结构和服务集成说明。它适合让 Agent 梳理 endpoint、生成 OpenAPI 草稿、检查字段命名、整理错误码或辅助前后端联调。使用时需要确认真实业务语义、鉴权方式、分页和错误处理规则;涉及生成接口文档时,应避免凭空补字段,最好从现有代码、schema 或接口样例中提取事实。

总安装

751

周安装

31

GitHub Stars

87

下载量

246
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:frappe-core-api(frappe core API 文档)
来源仓库:https://github.com/openaec-foundation/erpnext_anthropic_claude_development_skill_package
仓库路径:skills/frappe-core-api
安装命令:
npx skills add https://github.com/openaec-foundation/erpnext_anthropic_claude_development_skill_package --skill frappe-core-api
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/openaec-foundation/erpnext_anthropic_claude_development_skill_package --skill frappe-core-api

简介

用于辅助 API 设计、接口文档和请求响应结构梳理。

  • 适合生成 OpenAPI 草稿、检查字段命名或整理错误码。
  • 使用时需确认业务语义、鉴权方式和分页规则,避免凭空补字段。
  • 建议从现有代码或接口样例中提取事实,确保接口文档准确。
  • 安装前请核实权限范围和维护状态,避免误操作。frappe-core-api 属于开发类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Frappe API Patterns

Deterministic patterns for REST, RPC, and webhook integrations with Frappe.

Decision Tree

What do you need?
├── CRUD on documents (external client)
│   ├── v14: REST /api/resource/{doctype}
│   └── v15+: REST /api/v2/document/{doctype} (new) or /api/resource/ (still works)
│
├── Call custom server logic (external client)
│   └── RPC: POST /api/method/{dotted.path.to.function}
│
├── Notify external systems on document events
│   └── Webhooks (configured in UI or via DocType)
│
├── Client-side calls (JavaScript in Frappe desk)
│   ├── frappe.xcall() — async/await (RECOMMENDED)
│   └── frappe.call() — callback/promise pattern
│
└── Authentication method?
    ├── Server-to-server integration → Token Auth (RECOMMENDED)
    ├── Third-party app / mobile → OAuth 2.0
    ├── Browser session (short-lived) → Session/Cookie Auth
    └── Quick scripting / testing → Token Auth

Authentication Methods

Token Auth (RECOMMENDED for integrations)

headers = {
    'Authorization': 'token api_key:api_secret',
    'Accept': 'application/json',
    'Content-Type': 'application/json'
}

Generate keys: User > Settings > API Access > Generate Keys. ALWAYS store API secret immediately — it is shown only once.

Basic Auth (alternative token format)

import base64
credentials = base64.b64encode(b'api_key:api_secret').decode()
headers = {'Authorization': f'Basic {credentials}'}

OAuth 2.0 (third-party apps)

# Step 1: Authorization redirect
GET /api/method/frappe.integrations.oauth2.authorize
    ?client_id={id}&response_type=code&scope=openid all
    &redirect_uri={uri}&state={random}

# Step 2: Exchange code for token
POST /api/method/frappe.integrations.oauth2.get_token
    grant_type=authorization_code&code={code}
    &redirect_uri={uri}&client_id={id}

# Step 3: Use bearer token
Authorization: Bearer {access_token}

# Refresh token
POST /api/method/frappe.integrations.oauth2.get_token
    grant_type=refresh_token&refresh_token={token}&client_id={id}

Session/Cookie Auth

session = requests.Session()
session.post(url + '/api/method/login', json={'usr': 'email', 'pwd': 'pass'})
# Subsequent requests use session cookie automatically

Session cookies expire after ~3 days. NEVER use for long-running integrations.


REST API: Resource CRUD

Endpoints

OperationMethodv14 Endpointv15+ v2 Endpoint
ListGET/api/resource/{doctype}/api/v2/document/{doctype}
CreatePOST/api/resource/{doctype}/api/v2/document/{doctype}
ReadGET/api/resource/{doctype}/{name}/api/v2/document/{doctype}/{name}
UpdatePUT/api/resource/{doctype}/{name}PATCH /api/v2/document/{doctype}/{name}
DeleteDELETE/api/resource/{doctype}/{name}DELETE /api/v2/document/{doctype}/{name}
CopyGET /api/v2/document/{doctype}/{name}/copy [v15+]
Doc MethodPOST /api/v2/document/{doctype}/{name}/method/{method} [v15+]

ALWAYS include Accept: application/json header — without it, Frappe MAY return HTML.

List Parameters

ParameterTypeDescriptionDefault
fieldsJSON arrayFields to return["name"]
filtersJSON arrayAND conditionsnone
or_filtersJSON arrayOR conditionsnone
order_bystringSort expressionmodified desc
limit_startintPagination offset0
limit_page_lengthintPage size20
limitintAlias for limit_page_length [v15+]
debugboolShow SQL in responsefalse

Filter Operators

filters = [["status", "=", "Open"]]
filters = [["amount", ">", 1000]]
filters = [["status", "in", ["Open", "Pending"]]]
filters = [["date", "between", ["2024-01-01", "2024-12-31"]]]
filters = [["reference", "is", "set"]]       # NOT NULL
filters = [["reference", "is", "not set"]]   # IS NULL
filters = [["name", "like", "%INV%"]]
filters = [["status", "not in", ["Cancelled"]]]

Full operator list: =, !=, >, <, >=, <=, like, not like, in, not in, is, between.

Pagination Pattern

import json, requests

def get_all_records(doctype, headers, base_url, page_size=100):
    all_data, offset = [], 0
    while True:
        params = {
            'fields': json.dumps(["name", "modified"]),
            'limit_start': offset,
            'limit_page_length': page_size
        }
        resp = requests.get(f'{base_url}/api/resource/{doctype}',
                            params=params, headers=headers)
        data = resp.json().get('data', [])
        if not data:
            break
        all_data.extend(data)
        if len(data) < page_size:
            break
        offset += page_size
    return all_data

Create with Child Table

requests.post(f'{base_url}/api/resource/Sales Order', json={
    "customer": "CUST-001",
    "items": [
        {"item_code": "ITEM-001", "qty": 5, "rate": 100},
        {"item_code": "ITEM-002", "qty": 2, "rate": 250}
    ]
}, headers=headers)

Update (Partial)

# Only specified fields are changed
requests.put(f'{base_url}/api/resource/Customer/CUST-001',
             json={"customer_group": "Premium"}, headers=headers)

File Upload

requests.post(f'{base_url}/api/method/upload_file',
    files={'file': ('doc.pdf', open('doc.pdf', 'rb'), 'application/pdf')},
    data={'doctype': 'Customer', 'docname': 'CUST-001', 'is_private': 1},
    headers={'Authorization': 'token api_key:api_secret'})
# NOTE: Do NOT set Content-Type header — requests sets multipart boundary automatically

RPC API: Custom Methods

Server-Side Endpoint

@frappe.whitelist()
def get_balance(customer):
    """GET /api/method/myapp.api.get_balance?customer=CUST-001"""
    return frappe.db.get_value("Customer", customer, "outstanding_amount")

@frappe.whitelist(methods=["POST"])
def create_payment(customer, amount):
    """POST /api/method/myapp.api.create_payment"""
    if not frappe.has_permission("Payment Entry", "create"):
        frappe.throw(_("Not permitted"), frappe.PermissionError)
    pe = frappe.new_doc("Payment Entry")
    pe.party_type = "Customer"
    pe.party = customer
    pe.paid_amount = float(amount)
    pe.insert()
    return pe.name

@frappe.whitelist(allow_guest=True)
def public_status():
    """No authentication required."""
    return {"status": "ok"}

Decorator Options

OptionEffectVersion
allow_guest=TrueNo authentication neededAll
methods=["POST"]Restrict HTTP methods[v14+]
xss_safe=TrueSkip XSS escaping on responseAll

Response Structure

// RPC success
{"message": "return_value"}

// REST success
{"data": {...}}

// Error
{"exc_type": "ValidationError", "_server_messages": "[{\"message\": \"...\"}]"}

Client-Side Calls (JavaScript)

// RECOMMENDED: async/await with frappe.xcall
const result = await frappe.xcall('myapp.api.get_balance', {
    customer: 'CUST-001'
});

// Alternative: frappe.call with promise
frappe.call({
    method: 'myapp.api.get_balance',
    args: {customer: 'CUST-001'},
    freeze: true,
    freeze_message: __('Loading...')
}).then(r => console.log(r.message));

// Document method (frm.call)
frm.call('get_linked_doc', {throw_if_missing: true})
    .then(r => console.log(r.message));

Standard frappe.client Methods

MethodEndpointPurpose
frappe.client.get_valuePOSTGet single field value
frappe.client.get_listPOSTList with filters
frappe.client.getPOSTGet full document
frappe.client.insertPOSTCreate document
frappe.client.savePOSTUpdate document
frappe.client.deletePOSTDelete document
frappe.client.submitPOSTSubmit document
frappe.client.cancelPOSTCancel document
frappe.client.get_countPOSTCount documents

Webhooks

Configure via Webhook DocType in the UI. Events:

EventTrigger
after_insertNew document created
on_updateEvery save
on_submitAfter submit (docstatus=1)
on_cancelAfter cancel (docstatus=2)
on_trashBefore delete
on_update_after_submitAfter amendment
on_changeOn every change

Security: ALWAYS set a Webhook Secret. Frappe adds X-Frappe-Webhook-Signature header with base64-encoded HMAC-SHA256 of payload. Verify on receiving end.

Conditions: Use Jinja2 — {{doc.grand_total > 10000}}.

See references/webhooks-reference.md for complete handler examples.


HTTP Status Codes

CodeMeaningCommon Cause
200Success
400Bad requestValidation error
401UnauthorizedMissing or invalid auth
403ForbiddenNo permission for operation
404Not foundDocument does not exist
417Expectation failedServer exception (frappe.throw)
429Rate limitedToo many requests
500Server errorUnhandled exception

Critical Rules

  1. ALWAYS include Accept: application/json header in API requests
  2. ALWAYS add permission checks in @frappe.whitelist() methods
  3. ALWAYS validate and sanitize input in whitelisted methods
  4. ALWAYS use parameterized queries — NEVER string-interpolate SQL
  5. ALWAYS use timeout=30 on external requests calls
  6. ALWAYS store credentials in frappe.conf or env vars — NEVER hardcode
  7. ALWAYS verify webhook signatures with HMAC-SHA256
  8. ALWAYS paginate list responses — NEVER return unbounded result sets
  9. NEVER use allow_guest=True on state-changing endpoints
  10. NEVER log credentials or sensitive data
  11. NEVER use Administrator API keys for integrations — create dedicated API users

Anti-Patterns

Do NOTDo Instead
No permission check in whitelistfrappe.has_permission() before action
frappe.db.sql(f"...{user_input}")Parameterized %s queries
allow_guest=True + state changeRequire authentication
Return all records without limitPaginate with limit_page_length
Hardcode API credentialsfrappe.conf.get("api_key")
Synchronous heavy processingfrappe.enqueue() for long tasks
No timeout on external callsrequests.get(url, timeout=30)
Inconsistent response formatALWAYS return {"status": "...", "data":...}

Version Differences

Featurev14v15v16
/api/resource/ (v1)YesYesYes
/api/v2/document/ (v2)NoYesYes
/api/v2/doctype/{dt}/metaNoYesYes
/api/v2/doctype/{dt}/countNoYesYes
limit alias parameterNoYesYes
PKCE for OAuth2LimitedYesYes
Server Script rate limitingNoYesYes
Doc method via v2 URLNoYesYes

Reference Files

FileContents
authentication-methods.mdToken, Session, OAuth2 with code examples
rest-api-reference.mdComplete REST CRUD with filters and pagination
rpc-api-reference.mdWhitelisted methods, frappe.call, frappe.xcall
webhooks-reference.mdWebhook config, security, handler examples
anti-patterns.mdCommon mistakes with fixes
examples.mdPython/JS/cURL client implementations

Related Skills

  • frappe-core-permissions — Permission system for API endpoints
  • frappe-core-database — Database queries behind API methods
  • frappe-syntax-hooks — Hook configuration for webhooks
  • frappe-syntax-controllers — Controller methods called via API

*Verified against Frappe docs 2026-03-20 | Frappe v14/v15/v16*

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.17%
按下载量换算89

Claude

29.69%
按下载量换算73

Cursor

19.27%
按下载量换算47

Gemini CLI

8.4%
按下载量换算21

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills