Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Set up Attio REST API authentication with access tokens or OAuth 2.0. Use when configuring API keys, setting token scopes, initializing the Attio client, or connecting an app via OAuth. Trigger: "install attio", "setup attio", "attio auth", "attio API key", "attio OAuth", "attio access token".
.claude/skills/jeremylongshore-attio-install-auth/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 28% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 11% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 36% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 138% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 51% | 0% |
Configure authentication for the Attio REST API (https://api.attio.com/v2). Attio offers two auth methods: access tokens (scoped to a single workspace) and OAuth 2.0 (for multi-workspace integrations). There is no official first-party Node SDK -- use fetch or a community client like attio-js.
my-integration-dev)| Scope | Grants access to | |-------|-----------------| | object_configuration:read | List/get objects and attributes | | record_permission:read | Read records (people, companies, deals) | | record_permission:read-write | Create/update/delete records | | list_entry:read | Read list entries | | list_entry:read-write | Create/update/delete list entries | | note:read-write | Create and read notes | | task:read / task:read-write | Read or manage tasks | | user_management:read | Read workspace members | | webhook:read-write | Manage webhooks |
sk_ and never expires (but can be revoked)bash# .env (add to .gitignore immediately) ATTIO_API_KEY=sk_your_token_here # .gitignore .env .env.local .env.*.local
typescript// src/attio/client.ts const ATTIO_BASE = "https://api.attio.com/v2"; interface AttioRequestOptions { method?: string; path: string; body?: Record<string, unknown>; } export async function attioFetch<T>({ method = "GET", path, body, }: AttioRequestOptions): Promise<T> { const res = await fetch(`${ATTIO_BASE}${path}`, { method, headers: { Authorization: `Bearer ${process.env.ATTIO_API_KEY}`, "Content-Type": "application/json", }, body: body ? JSON.stringify(body) : undefined, }); if (!res.ok) { const error = await res.json(); throw new Error( `Attio ${res.status}: ${error.code} - ${error.message}` ); } return res.json() as Promise<T>; }
typescript// Verify by listing workspace objects const objects = await attioFetch<{ data: Array<{ api_slug: string }> }>({ path: "/objects", }); console.log( "Connected! Objects:", objects.data.map((o) => o.api_slug) ); // Output: Connected! Objects: ["people", "companies", "deals", ...]
bash# Quick verification with curl curl -s https://api.attio.com/v2/objects \ -H "Authorization: Bearer ${ATTIO_API_KEY}" | jq '.data[].api_slug'
For apps that other workspaces install, use OAuth 2.0 Authorization Code Grant (RFC 6749 section 4.1).
typescript// Step 1: Redirect user to authorize const authUrl = new URL("https://app.attio.com/authorize"); authUrl.searchParams.set("client_id", process.env.ATTIO_CLIENT_ID!); authUrl.searchParams.set("redirect_uri", "https://yourapp.com/callback"); authUrl.searchParams.set("response_type", "code"); // Step 2: Exchange code for access token const tokenRes = await fetch("https://app.attio.com/oauth/token", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ grant_type: "authorization_code", client_id: process.env.ATTIO_CLIENT_ID, client_secret: process.env.ATTIO_CLIENT_SECRET, code: authorizationCode, redirect_uri: "https://yourapp.com/callback", }), }); const { access_token } = await tokenRes.json(); // Store access_token securely per workspace
Following this guide produces the Attio integration outcome for its topic—configuration, validation evidence, operational recovery, or a documented migration result. Record command output and relevant identifiers so a failed step is traceable.
Start with the smallest applicable command or code example in the relevant section, using a dedicated test record or workspace and non-production credentials. Confirm the expected response or validation result before applying the pattern to production.
| Error | HTTP Status | Cause | Solution | |-------|------------|-------|----------| | invalid_grant | 401 | Bad or expired auth code | Re-authorize the user | | insufficient_scopes | 403 | Token missing required scope | Add scope in dashboard, regenerate | | invalid_request | 400 | Malformed Authorization header | Use Bearer <token> format | | not_found | 404 | Token revoked or workspace deleted | Generate new token |
All Attio errors return JSON with a consistent structure:
json{ "status_code": 403, "type": "authorization_error", "code": "insufficient_scopes", "message": "Token requires 'record_permission:read' scope" }
After verifying auth, proceed to attio-hello-world for your first real API call.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 44,476 | 40,736 | -8% | 1 | 1 | 0% | 3,018 | 3,859 | +28% | 0 | 0 | — |
case-02 | fail→pass | 17,828 | 10,585 | -41% | 1 | 1 | 0% | 3,551 | 3,951 | +11% | 0 | 0 | — |
case-03 | fail→pass | 17,395 | 12,932 | -26% | 1 | 1 | 0% | 3,212 | 4,369 | +36% | 0 | 0 | — |
case-04 | fail→fail | 9,161 | 12,621 | +38% | 1 | 1 | 0% | 1,810 | 4,143 | +129% | 0 | 0 | — |
case-05 | fail→fail | 21,937 | 48,930 | +123% | 1 | 1 | 0% | 3,531 | 5,467 | +55% | 0 | 0 | — |
case-06 | fail→fail | 11,105 | 12,852 | +16% | 1 | 1 | 0% | 2,061 | 4,363 | +112% | 0 | 0 | — |
case-15 | fail→pass | 5,146 | 2,580 | -50% | 1 | 1 | 0% | 868 | 2,064 | +138% | 0 | 0 | — |
case-07 | fail→pass | 9,904 | 5,586 | -44% | 1 | 1 | 0% | 1,707 | 2,574 | +51% | 0 | 0 | — |
case-08 | pass→pass | 4,811 | 4,759 | -1% | 1 | 1 | 0% | 942 | 2,466 | +162% | 0 | 0 | — |
case-09 | fail→pass | 20,644 | 2,768 | -87% | 1 | 1 | 0% | 3,560 | 1,882 | -47% | 0 | 0 | — |
case-10 | fail→pass | 10,568 | 5,077 | -52% | 1 | 1 | 0% | 1,524 | 2,486 | +63% | 0 | 0 | — |
case-11 | pass→pass | 8,655 | 4,977 | -42% | 1 | 1 | 0% | 1,512 | 2,538 | +68% | 0 | 0 | — |
case-12 | fail→pass | 5,361 | 3,054 | -43% | 1 | 1 | 0% | 943 | 2,154 | +128% | 0 | 0 | — |
case-13 | fail→pass | 11,478 | 4,219 | -63% | 1 | 1 | 0% | 2,157 | 2,252 | +4% | 0 | 0 | — |
case-14 | pass→pass | 4,621 | 3,668 | -21% | 1 | 1 | 0% | 751 | 2,180 | +190% | 0 | 0 | — |
case-16 | pass→pass | 5,098 | 2,946 | -42% | 1 | 1 | 0% | 986 | 2,222 | +125% | 0 | 0 | — |
case-17 | pass→pass | 7,753 | 4,039 | -48% | 1 | 1 | 0% | 1,473 | 2,427 | +65% | 0 | 0 | — |
case-18 | fail→pass | 4,328 | 4,393 | +2% | 1 | 1 | 0% | 830 | 2,537 | +206% | 0 | 0 | — |
case-19 | pass→pass | 8,738 | 7,230 | -17% | 1 | 1 | 0% | 1,595 | 3,022 | +89% | 0 | 0 | — |
case-20 | pass→pass | 9,103 | 7,462 | -18% | 1 | 1 | 0% | 1,609 | 2,931 | +82% | 0 | 0 | — |
case-21 | pass→pass | 3,102 | 2,864 | -8% | 1 | 1 | 0% | 598 | 2,211 | +270% | 0 | 0 | — |
case-22 | fail→pass | 5,513 | 1,964 | -64% | 1 | 1 | 0% | 997 | 1,888 | +89% | 0 | 0 | — |
case-23 | fail→pass | 6,707 | 2,164 | -68% | 1 | 1 | 0% | 1,220 | 1,970 | +61% | 0 | 0 | — |
case-24 | fail→pass | 14,351 | 4,013 | -72% | 1 | 1 | 0% | 1,324 | 1,975 | +49% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 24 cases were attempted, and 23 counted toward the lift figure. The other 1 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +54 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
| Model | Method | Date | Lift |
|---|---|---|---|
| gemini-3.6-flash | verified | 8/13/2026 | +55% |
Other measured skills in the registry, with their headline benchmark lift.