IdentyClaw
IdentyClaw API workflows — multi-API JWT sessions (auto-login), HOLA peer handshake lines, DID resolution, and Passport lookup. Requires an IdentyClaw Passport on the Gateway. Use when calling home or federated APIs, creating or verifying HOLA lines, resolving Passport IDs, or reading agent discovery metadata. For agent-to-agent A2A messaging use the separate identyclaw-a2a plugin.
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 9, 2026
Version
1.9.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 1.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.9.6release · observed Oct 6, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s170pyvwn8ckxjt7575svq7r71881627:identyclaw- Install using `clawhub skill install s170pyvwn8ckxjt7575svq7r71881627:identyclaw` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/identyclaw/identyclaw before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-identyclaw-identyclaw/snapshot"
Documentation
CLAWHUB
155,256 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: identyclaw
description: >-
IdentyClaw API workflows — multi-API JWT sessions (auto-login), HOLA peer
handshake lines, DID resolution, and Passport lookup. Requires an IdentyClaw
Passport on the Gateway. Use when calling home or federated APIs, creating or
verifying HOLA lines, resolving Passport IDs, or reading agent discovery
metadata. For agent-to-agent A2A messaging use the separate identyclaw-a2a plugin.
version: 1.9.6
metadata:
openclaw:
envVars:
- name: IDENTYCLAW_BASE_URL
required: false
description: Home API base URL (default https://api.identyclaw.com)
- name: IDENTYCLAW_API_ENDPOINTS
required: false
description: Comma-separated federated API URLs for concurrent sessions (e.g. https://api-b.example.com)
- name: IDENTYCLAW_ACCOUNT_ID
required: false
description: NEAR implicit account id (64-char hex) for API login
- name: IDENTYCLAW_NEAR_PRIVATE_KEY
required: false
description: Passport Ed25519 key (ed25519:...) — API login signature + HOLA line signing (Gateway only)
homepage: https://api.identyclaw.com/docs
---
# IdentyClaw
**Home API (default):** `https://api.identyclaw.com`
**Federated example:** `https://api-b.example.com` (same Rodit login family; configure via `apiEndpoints`)
IdentyClaw is an HTTP API for IdentyClaw Passport holders and the **HOLA** mutual authentication protocol. This skill is a **convenience cheat sheet** for agents; tool catalog and install steps live in the plugin [README](https://github.com/discernible-io/openclaw-identyclaw-plugin/blob/main/README.md). Deep specs live in bundled `references/` and MCP `doc:*` resources.
> **Convenience document:** Change the plugin README and MCP `doc:*` resources first; update this skill only to keep the walkthrough accurate.
**Live docs:** MCP `doc:discovery` · `doc:skills` · `curl https://api.identyclaw.com/api/mcp/resource/doc:skills`
**ClawHub:** [identyclaw/identyclaw](https://clawhub.ai/identyclaw/identyclaw) · [OpenClaw plugin](https://clawhub.ai/plugins/@identyclaw/openclaw-identyclaw-plugin) · [Source (skill + plugin)](https://github.com/discernible-io/openclaw-identyclaw-plugin)
---
## Home vs federated — do not assume shared routes
Federation shares **Rodit login** only (`GET /api/login/timestamp` → sign → `POST /api/login` → JWT cached per URL). A federated peer may expose **any** product routes. It does **not** inherit the home IdentyClaw surface (`/api/me/identity`, HOLA, DID, `/api/agents`, …).
| Target | What to call |
| --- | --- |
| **Home** (`baseUrl`, omit `apiEndpoint`) | Passport/HOLA/DID tools: `identyclaw_get_my_identity`, `identyclaw_create_hola`, `identyclaw_verify_hola`, `identyclaw_get_agent_identity`, `identyclaw_resolve_did`, … |
| **Federated peer** (`apiEndpoint=…`) | `identyclaw_ensure_session` → **discover** (`identyclaw_list_resources` / `identyclaw_get_resource` / peer skill.md / OpenAPI) → **product calls** via README.md
# IdentyClaw ClawHub skill
Workflow skill for OpenClaw agents. Published separately from the code plugin on ClawHub (`clawhub:identyclaw`).
## Layout
```text
skill/
├── SKILL.md # ClawHub publish source (version in frontmatter)
├── references/ # gitignored — populated by skill:sync
└── scripts/
├── sync-references.mjs
└── publish-clawhub.mjs
```
Reference docs are copied from **idclawserver-idc** at publish time (canonical API specs). Default path: `../idclawserver-idc/references`.
## Development
From repository root:
```bash
npm run skill:sync
npm run skill:publish:dry-run
npm run skill:publish
```
Override references source:
```bash
IDENTYCLAW_REFERENCES=/path/to/idclawserver-idc/references npm run skill:sync
```
## ClawHub
- Skill: `openclaw skills install clawhub:identyclaw`
- Plugin: `openclaw plugins install clawhub:@identyclaw/openclaw-identyclaw-plugin`
See [PUBLISH.md](./PUBLISH.md) and root [PUBLISH.md](../PUBLISH.md) for ClawHub auth._meta.json
{
"ownerId": "kn7ev9fw0fs1g0z9r4wt5bg5bh86bmj7",
"slug": "identyclaw",
"version": "1.9.6",
"publishedAt": 1791308517689
}references/api-reference.md
# API Reference
Complete endpoint listing for IdentyClaw API.
## Table of Contents
- [Public Endpoints](#public-endpoints)
- [Protected Endpoints](#protected-endpoints)
- [Privileged Endpoints](#privileged-endpoints)
- [DID Resolution](#did-resolution)
- [MCP Resources](#mcp-resources)
- [Policy Documents](#policy-documents)
## Public Endpoints
No authentication required.
### Discovery
| Endpoint | Method | Description |
|----------|--------|-------------|
| `/` | GET | API overview with enrollment URL and endpoint listing |
| `/health` | GET | Health check endpoint |
| `/.well-known/enrollment` | GET | Complete enrollment guide with pricing and steps |
| `/.well-known/mcp` | GET | MCP discovery metadata — see [mcp-connection-guide.md](mcp-connection-guide.md) |
| `/openapi.json` | GET | Canonical OpenAPI 3.0 specification |
| `/swagger.json` | GET | OpenAPI 3.0 specification (alias of `/openapi.json`) |
| `/api/v1/openapi.json` | GET | Deprecated redirect to `/openapi.json` |
| `/docs/enrollment` | GET | **Removed** — always returns `410 ENDPOINT_REMOVED` |
| `/api-docs` | * | **Removed** — always returns `410 ENDPOINT_REMOVED` |
### Authentication
| Endpoint | Method | Description |
|----------|--------|-------------|
| `/api/login/timestamp` | GET | Get single-use timestamp challenge pair for login |
| `/api/login` | POST | Authenticate with accountid signature and fresh challenge, get JWT |
Login request/response shapes, field constraints, and error semantics are maintained in OpenAPI:
- Canonical contract: [`../api-docs/swagger.json`](../../api-docs/swagger.json)
- Runtime endpoints: `GET /openapi.json`, `GET /swagger.json`
For step-by-step API login implementation guidance (challenge retrieval, signing flow, retries, and troubleshooting), use:
- [`login-authentication.md`](login-authentication.md)
### Agent Discovery
| Endpoint | Method | Description |
|----------|--------|-------------|
| `/api/agents` | GET | List all IdentyClaw Passport holders (cursor-paginated) |
**Query Parameters**:
- `limit` (default: 20, max: 100)
- `cursor` (optional, for pagination)
**Response**:
```json
{
"agents": [
{
"tokenId": "bkbvehbdcrgm",
"creature": "Legal Specialist",
"face": {
"checksumValid": true,
"categories": {
"skinTone": { "index": 2, "letter": "c", "value": "pale-skinned" },
"ethnicity": { "index": 1, "letter": "b", "value": "Nordic" },
"faceShape": { "index": 0, "letter": "a", "value": "oval-faced" }
}
}
}
],
"nextCursor": "cursor_string_or_null",
"requestId": "01HQXYZ...",
"disclaimer": "The creature field and other agent metadata are self-declared by the agent. It is your responsibility to verify the accuracy and authenticity of this information before relying on it."
}
```
### Client Token Signing
| Endpoint | Method | Description |
|----------|--------|-------------|
| `/api/signclient` | POST | Request server to sign client toreferences/collaboration-envelope.md
# Channel-Agnostic Collaboration Envelope
**Schema:** `identyclaw.collaboration.v1`
**MCP resource URI:** `doc:reference:collaboration-envelope`
IdentyClaw provides **identity and trust**, not transport. Email, chat, webhooks, game private side-channels, and paste-in-message channels each need a shared envelope so agents can attach cryptographic trust (HOLA), carry a task payload, and verify inbound messages uniformly.
**HOLA travels offline, peer-to-peer.** Agents exchange envelopes and HOLA lines **directly** on the channel they already use. Each peer **verifies independently** (IdentyClaw API or direct NEAR RPC — peer's choice). Do not route HOLA **exchange** through IdentyClaw HTTP API or a game server — those are separate services, not brokers for the wire path.
**Related:** MCP `doc:reference:inter-agent-communication` (optional email/Himalaya patterns — **out of scope** for the ClawHub `identyclaw` skill; A2A uses the separate plugin), [`multi-tenant-collaboration.md`](multi-tenant-collaboration.md) (operator patterns), [`identity-verification-policy.md`](identity-verification-policy.md) (proof bar), `doc:reference:hola-subagent-authentication`, `doc:reference:openclaw-integration-guide`.
---
## Envelope shape
```json
{
"schema": "identyclaw.collaboration.v1",
"messageId": "01HXABCDEFGHJKMNPQRSTVWXYZ0",
"timestamp": "2026-06-06T12:00:00.000Z",
"from": { "tokenId": "bkbvehbdcrgm" },
"to": { "tokenId": "lncnsfsnskzr", "contactUri": "mailto:[email protected]" },
"hola": "HOLA/MUNDO/bkbvehbdcrgm/2026-06-06T12:00:00.000Z/4F9A3C7E2D1B9A4C/API.IDENTYCLAW.COM/MFRGG.../J",
"task": {
"type": "TASK_REQUEST",
"payload": {
"summary": "Run benchmark X and return JSON metrics"
}
},
"channelHints": {
"replyVia": "contactUri",
"subjectPrefix": "TASK_RESULT:"
}
}
```
| Field | Required | Notes |
| --- | --- | --- |
| `schema` | yes | Must be `identyclaw.collaboration.v1` |
| `messageId` | yes | ULID or UUID — dedupe on receiver |
| `timestamp` | yes | ISO 8601 UTC — reject stale envelopes beyond HOLA TTL |
| `from.tokenId` | yes | Sender Passport ID (12 lowercase letters) |
| `to.tokenId` | no | Intended recipient Passport ID |
| `to.contactUri` | no | Routing hint from sender's view (`mailto:`, `https://`, etc.) |
| `hola` | yes* | Full HOLA line from sender (*omit only in trusted internal channels with separate verify) |
| `task` | yes | `{ type, payload }` — channel-independent work description |
| `channelHints` | no | Reply routing (`subjectPrefix`, `replyVia`) |
**Subagent delegation:** When `hola` uses the subagent format, also run `POST /api/isauthorizedsigner` after verify succeeds — see `doc:reference:hola-subagent-authentication`.
---
## Verification order (receiver)
**Verify before execute** — the norm for every channel. Copy-paste verifier recipes: [`verify-hola-recipes.md`](verify-hola-recipes.md) (MCP `doc:reference:verify-hola-recipes`).
1. **Parse** — valid JSON, `schema === identAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/identyclaw/skills/identyclaw",
"sourceUrl": "https://clawhub.ai/identyclaw/skills/identyclaw",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:05:35.518Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-identyclaw-identyclaw/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-identyclaw-identyclaw/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T23:05:35.518Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.9K downloads",
"href": "https://clawhub.ai/identyclaw/identyclaw",
"sourceUrl": "https://clawhub.ai/identyclaw/identyclaw",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:05:35.518Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.6",
"href": "https://clawhub.ai/identyclaw/identyclaw",
"sourceUrl": "https://clawhub.ai/identyclaw/identyclaw",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-06T17:41:57.689Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-identyclaw-identyclaw/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-identyclaw-identyclaw/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.6",
"description": "v1.9.6: ClawHub skill republish of the 1.9.5 recipient-validation work (1.9.5 was reserved but not promoted on the skill registry). Matching plugin **1.9.6**.",
"href": "https://clawhub.ai/identyclaw/identyclaw",
"sourceUrl": "https://clawhub.ai/identyclaw/identyclaw",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-06T17:41:57.689Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
