Skip to content
Back to skills

Webflow

ASecurity

Manage Webflow sites: list sites and CMS collections, read and edit CMS items, and publish. Trigger phrases: webflow, webflow cms, publish webflow site.

  • 18 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 25, 2026
toolsgobashapi

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 25, 2026

npx -y skills add gabrielmoreira/agent-skills-mirror --skill webflow --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Webflow?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Webflow
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gabrielmoreira-webflow/badge)](https://www.skillsdirectory.com/skills/gabrielmoreira-webflow)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "webflow"
description: "Manage Webflow sites: list sites and CMS collections, read and edit CMS items, and publish. Trigger phrases: webflow, webflow cms, publish webflow site."
metadata: { "includeInPrompt": true }
tagline: "Work with the Webflow Data API v2: list sites, inspect site details, browse CMS collections and items, create/update/delete CMS items, and publish a site. Uses a per-site token from Site Settings."
catalog_auth: "per-site token via the secure credential flow"
catalog_hosts: ["api.webflow.com"]
---

# Webflow

## Purpose
Work with the Webflow Data API v2: list sites, inspect site details, browse CMS collections and items, create/update/delete CMS items, and publish a site. Uses a per-site token from Site Settings.

## Tooling
All commands go through `bin/webflow.py`:

```bash
bin/webflow.py auth                                        # verify the connection (lists accessible sites)
bin/webflow.py sites                                       # list sites
bin/webflow.py site --id SITE_ID                           # site details (domains, publish status)
bin/webflow.py collections --site-id SITE_ID               # list CMS collections on a site
bin/webflow.py items --collection-id COLLECTION_ID         # list CMS items in a collection
bin/webflow.py create-item --collection-id COLLECTION_ID --data '{"items":[{"fieldData":{"name":"Hello"}}]}'
                                                           # create CMS item(s) (raw JSON body, per Webflow docs)
bin/webflow.py update-item --collection-id COLLECTION_ID --item-id ITEM_ID --data '{"fieldData":{"name":"New name"}}'
                                                           # update a CMS item (raw JSON body, per Webflow docs)
bin/webflow.py delete-item --collection-id COLLECTION_ID --item-id ITEM_ID   # delete a CMS item
bin/webflow.py publish --site-id SITE_ID                   # publish the site
```

## Auth
- Provider id: `webflow` (credential is collected as `custom.webflow`)
- Collection: per-site token via the secure credential flow (`credentials.request_api_access`); generate one in Webflow at Site Settings, Integrations, API access (workspace tokens are enterprise-only, so site tokens are the default)
- Required scopes: whatever scopes were granted to the site token
- Allowed hosts: `api.webflow.com`
- Status check: `bin/webflow.py auth`

## Operating Rules
1. Confirm with the user before publishing a site or CMS items and before deleting items: these change the live site.
2. Rate limit is about 60 requests/minute: keep calls modest and honor `Retry-After` / `X-RateLimit-Remaining` headers.
3. The API is server-side only (browser clients are CORS-blocked); always call it from this CLI, never from a page.
4. Never exfiltrate the credential: the CLI only ever handles surrogates. Do not print, log, or transmit the token value.

## Files
- SKILL.md
- bin/webflow.py

## Maturity
🧪 Draft: written from Webflow's public Data API v2 docs; not yet live-tested end to end.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…