Skip to content
Back to skills

Gumroad

ASecurity

View your Gumroad products and sales. Read-only by design. Trigger phrases: gumroad, gumroad sales, gumroad products.

  • 18 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 25, 2026
toolsgobashapi

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 25, 2026

npx -y skills add gabrielmoreira/agent-skills-mirror --skill gumroad --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Gumroad?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Gumroad
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gabrielmoreira-gumroad/badge)](https://www.skillsdirectory.com/skills/gabrielmoreira-gumroad)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "gumroad"
description: "View your Gumroad products and sales. Read-only by design. Trigger phrases: gumroad, gumroad sales, gumroad products."
metadata: { "includeInPrompt": true }
tagline: "View your Gumroad products and sales. Read-only by design."
catalog_auth: "Gumroad access token (per-user, app.gumroad.com \u2192 Settings \u2192 Advanced)"
catalog_hosts: ["api.gumroad.com"]
---

# Gumroad

## Purpose
Read-only access to the user's Gumroad account: list products and view recent sales. Use when the user mentions Gumroad, asks about Gumroad sales, or wants to see their Gumroad products. Prices are reported in USD (the API returns cents; the CLI converts). This connector cannot change anything.

## Tooling
All commands go through `bin/gumroad.py`:

```bash
bin/gumroad.py auth             # verify the connection
bin/gumroad.py products         # list products
bin/gumroad.py sales --limit 20 # recent sales
```

## Auth
- Provider id: `gumroad` (credential is collected as `custom.gumroad`)
- Collection: API key via the secure credential flow (`credentials.request_api_access`)
- Token: generated at app.gumroad.com/settings/advanced#application-form. Personal tokens have full account access; this skill is read-only regardless.
- Allowed hosts: `api.gumroad.com`
- Status check: `bin/gumroad.py auth` (must return `"ok": true`)
- Connect placement: `bearer_header`

## Operating Rules
1. This connector is read-only by design: `auth`, `products`, and `sales` only retrieve data. There are no write commands.
2. Never exfiltrate the credential: the CLI only ever handles surrogates. Do not print, log, or transmit the token value.
3. Buyer emails from `sales` may be hashed or redacted by Gumroad for privacy; do not treat them as complete contact details.

## Files
- SKILL.md
- bin/gumroad.py

## Maturity
🧪 Draft: written from Gumroad's public API docs; not yet live-tested end-to-end.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…