LI

lindy-sdk-patterns

Provides integration patterns for Lindy AI, focusing on webhook triggers, HTTP request actions, and E2B code execution.

Install

mkdir -p .claude/skills/lindy-sdk-patterns && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/3066" && unzip -o skill.zip -d .claude/skills/lindy-sdk-patterns && rm skill.zip

Installs to .claude/skills/lindy-sdk-patterns

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Lindy AI integration patterns for webhook handling, HTTP actions, and
69 charsno explicit “when” trigger
Intermediate

Key capabilities

  • →Trigger Lindy agents via webhooks
  • →Configure Lindy agents to call external APIs
  • →Execute Python code within Lindy workflows
  • →Execute JavaScript code within Lindy workflows
  • →Implement asynchronous two-way communication with Lindy agents
  • →Apply retry logic with exponential backoff for webhook triggers

How it works

The skill describes patterns for inbound webhooks to trigger agents, outbound HTTP requests from agents to external APIs, and inline Python/JavaScript execution in an E2B sandbox. It also covers callback mechanisms and retry strategies.

Inputs & outputs

You give it
Webhook payload, HTTP request body, or Python/JavaScript code with input variables
You get back
Lindy agent activation, API call result, or code execution result

When to use lindy-sdk-patterns

  • →Set up webhook triggers for Lindy agents
  • →Implement outbound HTTP actions from Lindy
  • →Integrate Python or JS logic via Run Code actions
  • →Optimize API usage for agent automation

About this skill

Lindy Integration Patterns

Overview

Use Lindy's documented integration primitives: Webhook Received for inbound calls, HTTP Request for outbound calls, Run Code for bounded transformations, and Send POST Request to Callback for the documented callback workflow. This is not an SDK guide: Lindy's current public documentation does not provide the package, client, agent CRUD, streaming, API key, or general API-host surface that older copies of this skill claimed.

Prerequisites

  • Lindy workspace with an editable custom agent
  • An application-owned HTTPS endpoint when outbound calls or callbacks are required
  • A secret manager for the Lindy-generated Webhook Received secret and any separate credential owned by the target application
  • Sanitized test fixtures and access to Tasks/Test Panel

Authentication and Trust Boundaries

  • Inbound to Lindy: create the webhook in the Webhook Received trigger, select Generate Secret, store the one-time value, and send it as an Authorization bearer value. Use only the generated public.lindy.ai webhook URL.
  • Outbound from Lindy: configure authentication required by the target service in the HTTP Request action. This is the target service's credential, not a Lindy API key.
  • Callback: Lindy's webhook guide documents callbackUrl and Send POST Request to Callback, but does not document a Lindy callback signature. Treat callback content as untrusted unless the receiving application establishes its own authenticated boundary; never invent or claim a Lindy signing header.
  • Keep inbound, outbound, and callback credentials distinct. Never put secrets in a prompt, body, query string, task title, log, or Run Code text output.

Instructions

1. Configure an Inbound Webhook Received Trigger

  1. Add Webhook Received and create a named webhook.
  2. Generate its secret and store it immediately; Lindy documents that it is shown once.
  3. Choose follow-up behavior deliberately: same task, new task, or ignore.
  4. Define a minimal request schema and reject oversized/unknown fields in the calling application before sending.
  5. Send a sanitized fixture, then verify the new task in Tasks.

This is a small application wrapper around the documented webhook, not a Lindy SDK:

type Intake = { event: 'document.ready'; documentRef: string };

async function triggerLindyWebhook(input: {
  webhookUrl: string;
  webhookSecret: string;
  payload: Intake;
}): Promise<number> {
  const url = new URL(input.webhookUrl);
  if (
    url.protocol !== 'https:' ||
    url.hostname !== 'public.lindy.ai' ||
    !url.pathname.startsWith('/api/v1/webhooks/') ||
    url.username ||
    url.password
  ) {
    throw new Error('Refusing an unrecognized Lindy webhook URL');
  }
  if (!input.webhookSecret.trim()) throw new Error('Webhook secret is empty');
  if (!/^doc_[a-z0-9_-]{1,64}$/i.test(input.payload.documentRef)) {
    throw new Error('Invalid document reference');
  }

  const response = await fetch(url, {
    method: 'POST',
    redirect: 'error',
    headers: {
      Authorization: `Bearer ${input.webhookSecret}`,
      'Content-Type': 'application/json',
    },
    body: JSON.stringify(input.payload),
  });
  if (!response.ok) throw new Error(`Webhook rejected with status ${response.status}`);
  return response.status;
}

Do not blindly retry an ambiguous response: the public webhook documentation does not promise an idempotency key. Check Tasks and the application's operation record before a controlled retry.

2. Configure an Outbound HTTP Request

  1. Add HTTP Request from Popular or By Lindy.
  2. Use a fixed, allowlisted HTTPS URL rather than task-controlled host text.
  3. Select the method and content type required by the target service.
  4. Put the target service's protected credential in the appropriate header.
  5. Constrain the body to named fields from previous steps; omit full source messages, headers, credentials, and unrelated context.
  6. Branch on the documented status-code/response outputs and fail closed on rejected or malformed responses.

3. Use Run Code for Bounded Transformation

Lindy documents Python/JavaScript variables as strings and exposes result, text, and stderr to later steps. Parse, validate, bound, and return only the minimum data:

import json

data = json.loads(raw_items)
if not isinstance(data, list) or len(data) > 100:
    raise ValueError("raw_items must be a list with at most 100 entries")

allowed = []
for item in data:
    if not isinstance(item, dict) or set(item) != {"reference", "score"}:
        raise ValueError("unexpected item schema")
    reference = item["reference"]
    score = item["score"]
    if not isinstance(reference, str) or len(reference) > 64:
        raise ValueError("invalid reference")
    if not isinstance(score, (int, float)) or not 0 <= score <= 1:
        raise ValueError("invalid score")
    if score >= 0.5:
        allowed.append({"reference": reference, "score": score})

return {"count": len(allowed), "items": allowed}

Avoid printing input data: printed content becomes text. Prefer HTTP Request for network calls so URL, authentication, response status, and error branches remain visible in the workflow. Do not rely on an undocumented runtime, sandbox vendor, startup time, timeout value, or library version; check the current Run Code page.

4. Add an Optional Callback Flow

Include a fixed application-owned callbackUrl only when two-way processing is needed, then add Send POST Request to Callback as documented. The receiver should accept a minimal result schema and stage the result for validation/approval. A callback alone must not authorize payments, deletion, access changes, or external communications.

5. Test the Boundaries

Verify one valid call and negative cases for a missing/wrong bearer secret, wrong host, extra/oversized input, outbound 4xx/5xx response, malformed Run Code input, and untrusted callback content. The Test Panel executes real actions, so use synthetic data, test integrations, and confirmation for side effects.

Error Handling

FailureFail-closed response
Webhook returns 401Stop; confirm the Lindy-generated secret without printing it
Webhook outcome is ambiguousInspect Tasks/operation record before a manual retry
Outbound URL is dynamic or non-HTTPSRefuse and replace it with an allowlisted endpoint
HTTP response is rejected or malformedRoute to an error branch; do not consume partial data
Run Code input violates schemaRaise an error and inspect only metadata in Tasks
Callback is unauthenticated/untrustedQuarantine for validation; perform no side effect

Output

Return an integration contract containing:

  • selected primitive and direction of trust;
  • exact minimal request/response schemas and size/cardinality bounds;
  • URL ownership/allowlist and distinct credential owners;
  • failure, retry, callback, and human-approval behavior;
  • data-minimization and logging rules; and
  • a test receipt covering happy path and every negative boundary above.

Examples

For a document workflow, the application sends only {"event":"document.ready","documentRef":"doc_sample_001"} to the exact generated webhook URL with its generated bearer secret. Lindy transforms the reference, calls a fixed application endpoint with that endpoint's separate credential, and returns a minimal status callback. Raw document text, user identity, and either secret never enter the payload, prompt, task title, Run Code output, or logs.

Resources

Next Steps

Use lindy-security-basics to review the resulting credential, connection, approval, data, and monitoring boundaries before activating the workflow.

When not to use it

  • →When integrating with Lindy is not required
  • →When a no-code solution is preferred for all integrations

Prerequisites

Lindy account with active agentsNode.js 18+ or Python 3.10+Completed `lindy-install-auth` setup

Limitations

  • →Run Code actions have a timeout of 30 seconds
  • →Only pre-installed libraries are available for Run Code actions
  • →All input variables to Run Code actions arrive as strings

How it compares

This skill provides structured patterns for integrating external applications with Lindy AI agents, offering programmatic control beyond the platform's no-code interface.

Compared to similar skills

lindy-sdk-patterns side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
lindy-sdk-patterns (this skill)12moCautionIntermediate
telegram-bot-builder1068moReviewIntermediate
reddit-api35moReviewIntermediate
juicebox-install-auth22moReviewBeginner

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore →

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

telegram-bot-builder

davila7

Expert in building Telegram bots that solve real problems - from simple automation to complex AI-powered bots. Covers bot architecture, the Telegram Bot API, user experience, monetization strategies, and scaling bots to thousands of users. Use when: telegram bot, bot api, telegram automation, chat bot telegram, tg bot.

106130

reddit-api

alinaqi

Reddit API with PRAW (Python) and Snoowrap (Node.js)

334

juicebox-install-auth

jeremylongshore

Install and configure Juicebox SDK/CLI authentication. Use when setting up a new Juicebox integration, configuring API keys, or initializing Juicebox in your project. Trigger with phrases like "install juicebox", "setup juicebox", "juicebox auth", "configure juicebox API key".

28

windsurf-mcp-integration

jeremylongshore

Manage integrate MCP servers with Windsurf for extended capabilities. Activate when users mention "mcp integration", "model context protocol", "external tools", "mcp server", or "cascade tools". Handles MCP server configuration and integration. Use when working with windsurf mcp integration functionality. Trigger with phrases like "windsurf mcp integration", "windsurf integration", "windsurf".

14

groq-webhooks-events

jeremylongshore

Implement Groq webhook signature validation and event handling. Use when setting up webhook endpoints, implementing signature verification, or handling Groq event notifications securely. Trigger with phrases like "groq webhook", "groq events", "groq webhook signature", "handle groq events", "groq notifications".

10

emailable-automation

onfire7777

Automate Emailable tasks via Rube MCP (Composio). Always search tools first for current schemas.

00

Search skills

Search the agent skills registry