Securely integrate with the official LabArchives ELN REST-like API and Inventory API v1. Use for regional endpoint selection, signed-request construction, user authorization and UID flows, local LA container validation, and verified LabArchives integration workflows.
Use LabArchives APIs only from current, official method pages. The public documentation is a shared notebook, not a versioned SDK reference, so verify the specific page immediately before implementing a remote operation.
Do not combine these interfaces:
*api.labarchives.com
hosts, /api/<class>/<method> paths, XML for many responses, and signed query
parameters./public/v1/... paths, JSON schemas, and signed
X-LabArchives-* request headers.Read references/api_reference.md before writing
API code and references/integrations.md before
automating an advertised integration.
LabArchives ELN developer API access is an Enterprise capability. The current Inventory FAQ limits Inventory API access to Enterprise and Enterprise Plus licensees and requires an Inventory account with API permission. Contact the institution's LabArchives team or LabArchives support for access and the development documentation supplied with it.
The environment names below are conventions of this skill, not vendor-defined standards:
LABARCHIVES_ELN_API_URL — one exact regional ELN API URL ending in /apiLABARCHIVES_ACCESS_KEY_ID — LabArchives-issued Access Key ID (akid)LABARCHIVES_ACCESS_PASSWORD — HMAC signing secretLABARCHIVES_USER_ID — optional persistent UID bound to that Access Key IDLABARCHIVES_INVENTORY_LAB_ID — required for Inventory requestsKeep secrets in the process environment or an approved secret manager. Do not
put them in YAML, source code, command-line arguments, prompts, logs, notebooks,
or committed .env files. The bundled tools never search for .env files.
From this skill directory:
uv run scripts/setup_config.py regions
uv run scripts/setup_config.py check --require-user-id
setup_config.py validates only endpoint structure and named-variable presence;
it does not authenticate, persist, or print credentials. See
references/authentication_guide.md.
Browser login hosts and API hosts are different. The official ELN API overview currently lists US/rest of world, Australia/New Zealand, UK, Europe outside the UK, and Canada API hosts. The help center separately lists the five regional browser login hosts.
Use setup_config.py regions for the current allowlist and the complete table in
the authentication guide. Never build an API URL from a browser login URL.
The public Inventory v1 pages retrieved for this refresh document relative paths, but not a complete regional absolute base-URL table. Obtain that base URL from the institution/vendor documentation rather than guessing from an Inventory login host.
The official algorithm is fully documented:
expires to the current Unix epoch time in milliseconds, adjusted for
server clock difference if necessary. Despite its name, it is not a future
expiry time.<Access Key ID><API method name><expires>.akid, expires, and sig as the
documented query parameters.For ordinary ELN calls, the signature input is the method name only, not the API
class. User authorization is a documented special case: signing the
api_user_login redirect uses the unencoded redirect URI in place of a method
name.
Inventory shares the HMAC algorithm but signs the exact relative route, including resolved path parameters and excluding the query string. Its authentication page documents these headers:
X-LabArchives-UIdX-LabArchives-AKIdX-LabArchives-LabIdX-LabArchives-SignatureX-LabArchives-ExpiresCreate a fresh signature for every request. Do not move ELN query authentication into Inventory headers or Inventory headers into ELN calls.
scripts/entry_operations.py is deliberately network-free. It implements the
documented signature primitive and emits redacted JSON plans, never a live
request or reusable signature:
uv run scripts/entry_operations.py self-test
uv run scripts/entry_operations.py eln-plan \
--api-class entries --api-method entry_info
uv run scripts/entry_operations.py inventory-plan \
--path /public/v1/users/me
Import its create_signature, build_eln_auth_params, or
build_inventory_headers functions into institution-reviewed code when needed.
Pass returned authentication material directly to the HTTP client; never print
or persist it.
Before any remote write:
The bundled scripts perform no remote writes.
An LA container is a ZIP file with lamanifest.xml, an application file,
and optional preview/index files. It is not synonymous with a notebook backup.
Inspect one without extracting it:
uv run scripts/notebook_operations.py inspect example_lacontainer.zip
uv run scripts/notebook_operations.py inspect example_lacontainer.zip \
--output container-report.json
The inspector bounds archive size/member count, rejects unsafe member paths, checks manifest references, and writes JSON only to an explicitly selected safe path. It does not upload, download, or extract content.
verify=False.The bundled helpers use only the Python standard library. No official LabArchives Python SDK was identified in the official sources reviewed.
Do not install the old mcmero/labarchives-py repository by default: it has no
tags or releases and its last commit was in August 2022. A newer community
project exists, but it is not LabArchives-owned. If a user specifically chooses
a community client, review its code and release status, pin an exact stable
version with uv, and obtain institutional approval. See
references/sources.md for the dated status.
references/api_reference.md — ELN versus
Inventory v1, signing inputs, verified routes, and operational rulesreferences/authentication_guide.md —
credentials, regional login/API hosts, UID authorization, and troubleshootingreferences/integrations.md — official
integration behavior and safe automation boundariesreferences/sources.md — official URLs, page dates,
wrapper status, and unresolved public-documentation gapsCopy a source-pinned command for your client. You run it yourself.
Destination: .claude/skills/labarchive-integration · pinned to the source commit
git clone https://github.com/K-Dense-AI/scientific-agent-skills.git
cd scientific-agent-skills
git checkout 36d8f13a1e754618794bf42f417884940077b4ae
mkdir -p ".claude/skills/labarchive-integration"
cp -r "skills/labarchive-integration" ".claude/skills/labarchive-integration"Review the source before running. This copies files into your project; it is not a one-click install and does not verify runtime safety.
sudo apt update && sudo apt install -y gitnpm install -g @anthropic-ai/claude-codegit clone https://github.com/K-Dense-AI/scientific-agent-skills.git
cd scientific-agent-skills
git checkout 36d8f13a1e754618794bf42f417884940077b4ae
mkdir -p ".claude/skills/labarchive-integration"
cp -r "skills/labarchive-integration" ".claude/skills/labarchive-integration"Destination: .claude/skills/labarchive-integration
Scanner static-checks@0.1.0 · commit 36d8f13a1e75. Static checks cannot prove runtime safety – review the source and the exact diff before installing. How checks work.
References credentials, tokens or secret files that a skill should not need.
Evidence: [redacted]· fingerprint 0be64ae89ddd24e2