Core Pluggy integration patterns and best practices. Use when setting up Pluggy SDK, implementing Connect Widget, managing Items, or configuring webhooks.
Install
npx skills add https://github.com/pluggyai/agent-skills --skill pluggy-integrationSKILL.md
Pluggy Integration
Comprehensive integration guide for Pluggy Open Finance API. Contains rules across 5 categories, prioritized by impact to guide accurate implementation.
When to Apply
Reference these guidelines when:
- Setting up Pluggy SDK and authentication
- Implementing the Connect Widget in frontend applications
- Creating, updating, or managing Items (connections)
- Handling MFA (Multi-Factor Authentication) flows
- Configuring webhooks for real-time data sync
- Managing API keys and tokens
- Handling connection errors and edge cases
Rule Categories by Priority
| Priority | Category | Impact | Prefix |
|---|---|---|---|
| 1 | Authentication | CRITICAL | auth- |
| 2 | Connect Widget | CRITICAL | widget- |
| 3 | Webhook Configuration | CRITICAL | webhook- |
| 4 | Item Lifecycle | HIGH | item- |
| 5 | Error Handling | MEDIUM | error- |
How to Use
Read individual rule files for detailed explanations and code examples:
rules/auth-api-keys.md
rules/widget-integration.md
rules/item-lifecycle.md
Each rule file contains:
- Brief explanation of why it matters
- Incorrect code example with explanation
- Correct code example with explanation
- Additional context and references
- Pluggy-specific notes
Key Concepts
Connection Sync vs Data Sync
| Responsibility | Who Handles | How |
|---|---|---|
| Connection sync | Pluggy | Auto-sync every 24/12/8h |
| Triggering updates | User | Only when user explicitly requests |
| Entity data sync | You | Fetch all on item/updated webhook |
| Transaction sync | You | Use transactions/* webhook events |
API Key vs Connect Token
- API Key: Backend token (2h expiration) for accessing user data
- Connect Token: Frontend token (30min expiration) for Connect Widget only
Item Lifecycle
- User opens Connect Widget with Connect Token
- User selects connector and authenticates
- Pluggy creates Item and starts data sync
- Webhook notifies when sync completes
- Backend retrieves data using API Key
- Pluggy auto-syncs daily; webhook triggers data refresh
Full Compiled Document
For the complete guide with all rules expanded: AGENTS.md
Related skills
entra-app-registrationmicrosoft606KGuides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.azure-messagingmicrosoft595KTroubleshoot and resolve issues with Azure Messaging SDKs for Event Hubs and Service Bus. Covers connection failures, authentication errors, message processing issues, and SDK configuration problems. WHEN: event hub SDK error, service bus SDK issue, messaging connection failure, AMQP error, event processor host issue, message lock lost, message lock expired, lock renewal, lock renewal batch, send timeout, receiver disconnected, SDK troubleshooting, azure messaging SDK, event hub consumer, servicentra-agent-idmicrosoft328KProvision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmi_path, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar. USE FOR: Agent Identity Blueprint, BlueprintPrincipal, agent OAuth, fmi_path token exchange, agent OBO, Workload Identity Federation for agents, polyglot agent auth, Microsoft.Identity.Web.AgentIdentities. DO NOT USE FOR: standard Entra app registsupabasesupabase298KUse when doing ANY task involving Supabase. Triggers: Supabase products (Database, Auth, Edge Functions, Realtime, Storage, Vectors, Cron, Queues); client libraries and SSR integrations (supabase-js, @supabase/ssr) in Next.js, React, SvelteKit, Astro, Remix; auth issues (login, logout, sessions, JWT, cookies, getSession, getUser, getClaims, RLS); Supabase CLI or MCP server; schema changes, migrations, declarative schemas, security audits, Postgres extensions (pg_graphql, pg_cron, pg_vector); deb
