esimpal-api-agent
Installation
SKILL.md
eSIMPal API - agent integration skill
Use this skill when implementing or testing an agent that uses the eSIMPal API to buy eSIMs for end-users (list plans, create orders, process payments, activate, and deliver).
Safety and approval rules
- This skill is for integration guidance and controlled runtime calls. It must not initiate purchases autonomously.
- Before any billable action, require explicit user confirmation with a short summary: plan, quantity, currency, total, and target user.
- Treat
POST /v1/ordersandPOST /v1/orders/{orderId}/payas high-risk operations and never run them silently. - Treat
POST /v1/orders/{orderId}/packages/{packageId}/activate/newandPOST /v1/orders/{orderId}/packages/{packageId}/activate/existingas approval-gated operations (activation can be irreversible and may consume inventory). - Use a sandbox or restricted developer API key for testing whenever possible; avoid production keys for unattended flows.
- Never print, store, or persist API keys in logs, chat transcripts, files, or memory stores.
- Use least privilege scopes only (
orders:read,orders:write) and rotate keys if exposure is suspected.