nevermined-router
Use when an AI agent needs to PAY an external service it does not have an account with — any x402 agent or MPP merchant — using the Nevermined Router. Covers discovering services in the Agent Services Catalog, creating a spending Delegation from an API key, funding the buyer wallet, pricing a call first with /api/v1/router/quote, making paid calls through /api/v1/router/route (or the streaming /proxy), reading the payment ledger, and the guardrails an autonomous buyer must respect. Complements the nevermined-payments skill, which is about RECEIVING payments and buying Nevermined plans.
Rank
62
Safety
84
Downloads
1.7k
Updated
Oct 10, 2026
Version
0.1.30
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.7K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.1.30release · observed Oct 8, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17beb0b7q3geaakdyrsav6nq188t5nd:nevermined-router- Install using `clawhub skill install s17beb0b7q3geaakdyrsav6nq188t5nd:nevermined-router` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/nevermined-io/nevermined-router before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-nevermined-io-nevermined-router/snapshot"
Documentation
CLAWHUB
153,146 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: nevermined-router
version: "0.1.5"
lastUpdated: "2026-09-26"
description: >
Use when an AI agent needs to PAY an external service it does not have an account
with — any x402 agent or MPP merchant — using the Nevermined Router. Covers
discovering services in the Agent Services Catalog, creating a spending Delegation
from an API key, funding the buyer wallet, pricing a call first with
/api/v1/router/quote, making paid calls through /api/v1/router/route (or the
streaming /proxy), reading the payment ledger, and the
guardrails an autonomous buyer must respect. Complements the nevermined-payments
skill, which is about RECEIVING payments and buying Nevermined plans.
metadata:
openclaw:
primaryEnv: NVM_API_KEY
requires:
env:
- NVM_API_KEY
envVars:
- name: NVM_API_KEY
required: true
description: >
Nevermined API key. Format `sandbox:...` for the sandbox environment,
`live:...` for production. Issued from https://nevermined.app under API
Keys. Must be a current-generation key — older keys are refused by the
Router with 403 BCK.ROUTER.0008.
---
# Nevermined Router — buy from any x402 or MPP service
> **Skill version**: 0.1.5 | **Last updated**: 2026-09-26 | **Canonical source (always latest):** https://github.com/nevermined-io/docs/tree/main/skills/nevermined-router
>
> **⚠️ Use the latest version.** If you have a cached copy, check its **Last updated** date against the canonical source and refresh if older.
>
> Human-readable twin of the Router documentation at https://nevermined.ai/docs/products/catalog/router/overview. Same facts, same error codes — if the two ever disagree, the docs site is authoritative and this skill has a bug.
## What this is for
You are an agent that needs something from a service you have **no account with, no API key for, and no billing relationship with**. The Router lets you pay it per request, from a budget a human capped in advance, and puts every spend on one ledger.
It works because a growing set of services quote their price **on the wire**: you call them, they answer `402 Payment Required` with what they want, you pay, you get the resource. The Router does the paying.
| | |
| --- | --- |
| **Use this skill when** | you need to buy a single call from an external x402 / MPP service |
| **Use `nevermined-payments` instead when** | you are *charging* callers, or buying a Nevermined **plan** with credits |
<a id="not-for"></a>
**This skill cannot help you with conventional SaaS APIs.** Exa, Firecrawl, Tavily and similar are billed out of band — a monthly plan, a long-lived key. They never quote a price for one call, so there is nothing on the wire for the Router to pay and no address to pay it to. The Router isn't missing a feature; the transaction it performs does not exist for those services. If a service answers `401` or `403` rather than `402`, it wants **authentication**, not payment — stop, and tell _meta.json
{
"ownerId": "kn7bk8z6x7ytxvdb48j34j2ahh812m3p",
"slug": "nevermined-router",
"version": "0.1.30",
"publishedAt": 1791451098137
}references/bootstrap.md
# Bootstrap — API key, Delegation, funded wallet
Three preconditions before any payment. Do them once and reuse.
## 1. The API key
Every Router call carries `Authorization: Bearer $NVM_API_KEY`. Issued from the Nevermined app —
this is the one step that needs a human.
Keys are environment-scoped: `sandbox:…` for sandbox, `live:…` for production. A key from the wrong
environment fails auth, not the Router's own checks.
**A key issued before the Router shipped is refused with `403 BCK.ROUTER.0008`.** It is bound to a
previous account model that cannot sign these payments. The fix is to create a new key — newly
issued keys work. Existing keys keep working for credit-based flows, so nothing else needs rotating.
This is not retryable and not a transient error; do not loop on it.
**Never forward this key to a merchant.** It authenticates you to Nevermined. If the merchant needs
its own credential, pass that separately (`headers` in mode B, `X-Router-Upstream-Authorization` on
`/proxy`) — see `paying.md`.
## 2. The Delegation
Your budget. A hard cap in cents plus an expiry, enforced server-side on **every** payment.
```bash
curl -sX POST "$NVM_API_URL/api/v1/delegation/create" \
-H "Authorization: Bearer $NVM_API_KEY" \
-H "Content-Type: application/json" \
-d '{"provider":"erc4337","currency":"usdc","spendingLimitCents":500,"durationSecs":604800}'
# → { "delegationId": "5e7481c3-e972-45bd-bdc5-a0b99c4de4a1" }
```
| Field | Required | Notes |
| --- | --- | --- |
| `provider` | **yes** | `erc4337` for both stablecoin rails. No default — omitting it is a 4xx |
| `currency` | **yes** | `usdc` · `eurc` · `usd` · `eur`. No default |
| `spendingLimitCents` | **yes** | Integer ≥ 1. The hard cap, in cents |
| `durationSecs` | **yes** | Integer ≥ 1. `604800` = 7 days |
| `allowedRecipients` | no | Up to 100 `0x…` EVM addresses. **Omit = no restriction** |
| `maxTransactions` | no | Cap on number of charges. Omit = unlimited |
`provider: "erc4337"` is the crypto-funded Delegation both stablecoin rails require. Card-funded
Delegations use a different provider and are refused on those rails (and vice versa) with
`400 BCK.ROUTER.0001`.
### Two ways creation is refused before your fields are even read
Both guard the *caller*, not the request body, so a perfectly valid payload still fails. Neither is
retryable and neither can be fixed from your side alone.
**`403 BCK.OAUTH.0030` — this API key may not create Delegations.** An **OAuth-minted** credential
(one issued through an OAuth consent ceremony — today `credits_purchase`, `account_access` or
`commerce`, but the guard keys on the binding rather than the consent type, so any future ceremony
type is refused too) is refused on
`POST /delegation/create` *and* on the paying routes — `POST /router/payments`, `POST /router/route`,
`POST /router/route/with-controls`, `POST /router/quote`, `POST /router/select`, `ALL /router/proxy`,
`ALL /router/svc/<slug>`. Those routes sign from the account's full wallreferences/discovery.md
# Discovery — finding something to buy
The **Agent Services Catalog** is a Nevermined-curated list of external agent services. Discovery is
**public, unauthenticated and free**. Send no `Authorization` header; none is required.
| Surface | Use it for |
| --- | --- |
| `https://nevermined.app/catalog/ai-catalog.json` | **The default.** Every listed service in one JSON document — fetch once, filter locally |
| Catalog MCP at `https://mcp.live.nevermined.app/mcp` | Server-side search: `search_services`, `get_service`, `list_categories` |
| `https://nevermined.app/.well-known/ard.json` | The ARD host document, for registries crawling the Catalog — and per-service health |
| `https://nevermined.app/catalog/llms.txt` | Plain-text entry point for an agent landing cold |
| `https://nevermined.app/catalog/services` | Human browsing |
⚠️ **`/api/v1/catalog/services`, `/api/v1/catalog/services/{slug}` and `/api/v1/catalog/categories`
are not a public integration.** They return `403` on both `api.live` and `api.sandbox`, by design —
not an outage, and not something a key fixes. Do not retry them; read the feed.
The feed lists the **live** Catalog. It is live-only for payment: listed services settle on mainnet,
and a sandbox deployment funds testnets only.
## The feed
```bash
curl -s https://nevermined.app/catalog/ai-catalog.json -o ai-catalog.json
jq '{total, generatedAt}' ai-catalog.json
```
`{ version, catalog, generatedAt, total, count, services: [ … ] }`. It is cached for five minutes
(`Cache-Control: max-age=300`), so re-fetching more often buys nothing. There are no query
parameters and no pagination — `services` is the whole Catalog.
### Fields you will actually use
| Field | Use |
| --- | --- |
| `slug` | Stable id. Case-sensitive — how you address the service through the Router |
| `protocol` | **`x402` or `mpp` = payable through the Router.** See below |
| `endpoints[]` | `{ path, method, description, priceLabel }`, plus `invokePath`, `requestExample`, `responseFields` on some — see [rule 2](#2-pay-by-slug-and-send-invokepath--path) |
| `priceLabel` | Human string like `"$0.001"`. **Indicative only** — the wire price governs |
| `network` / `networks` | Display names (`"Base"`, `"Tempo"`). Not chain ids |
| `category` | One of the **13 curated values** — see [Categories](#categories) |
| `subCategory` | Granular label under `category`. **Absent** (no key, not `null`) for the generic top bucket — in JS test `s.subCategory == null`, not `=== null` |
| `tags[]` | Selection signals |
| `invokeUrl` | The service's Router URL: `…/api/v1/router/svc/<slug>` |
| `invoke` | A ready-made Router call: `method`, `router`, `invokeUrl` and the `X-Router-*` headers |
| `url` | The service's human page in the Catalog |
The feed deliberately omits health status, long descriptions and the merchant's own URL. For health,
read the ARD host document (each entry's `nvm:catalog.healthStatus` and `uptime30d` — see
[below](#the-ard-host-document)); for a request breferences/errors.md
# Errors and guardrails The Router signs payments from your wallet in response to instructions written by a merchant nobody vetted. It is deliberately suspicious. **A refusal is the system working.** Before you widen a cap or drop an idempotency key to make an error go away, read what it was protecting you from. An autonomous agent that treats guardrails as obstacles is exactly the failure mode this design exists to prevent. ## Every Router code Codes `0029` and `0031`–`0033` are exposed from API 1.55 onward; older API pins retain the legacy unbound quote and service-selection request shapes. | Code | Status | Meaning | Retry? | | --- | --- | --- | --- | | `BCK.ROUTER.0001` | 400 | Bad input: unsupported protocol, malformed/empty challenge, no fundable option, recipient outside the Delegation's scope, non-allowlisted asset, wrong-provider Delegation, missing `delegationId`. **`details` names the specific problem — read it** | No | | `BCK.ROUTER.0002` | 409 | This `requestId` already minted a payment. The original `paymentId` is in the response | No | | `BCK.ROUTER.0003` | 402 | Delegation over cap, expired, exhausted, or revoked | No — **stop** | | `BCK.ROUTER.0004` | 404 | No Router payment with that id belongs to you | No | | `BCK.ROUTER.0005` | 409 | Payment not settleable. Only `Issued` → `Settled`; same hash is a no-op, a different hash is rejected | No | | `BCK.ROUTER.0006` | 500 | Transient failure building the payments summary | **Yes** | | `BCK.ROUTER.0007` | 429 | Too many concurrent routed requests in flight | **Yes**, after backoff | | `BCK.ROUTER.0008` | 403 | Legacy API key — create a new one | No | | `BCK.ROUTER.0009` | 402 | Wallet doesn't hold enough of the asset on the target network. **Nothing was signed** | No — **stop** | | `BCK.ROUTER.0010` | 500 | Internal: the rail reported a charge amount that isn't a non-negative integer, so the Router can't reserve anything against the cap | No — **never blind-retry** | | `BCK.ROUTER.0011` | 402 | Card rail: the charge needs cardholder 3-D Secure, and an agent has no browser to complete it. Nothing was charged and the seller got no usable credential. | No — **needs a human** | | `BCK.ROUTER.0012` | 400 | The seller's 402 advertises an EIP-712 domain its own settlement token does not sign under, so the Router refuses to sign. Nothing signed, charged or reserved — an authorization under the wrong domain is unspendable anyway. Seller-side bug | No — **report it, pay elsewhere** | | `BCK.ROUTER.0013` | 500 | Nevermined holds no EIP-712 signing domain for the token the funding filter selected — a gap in OUR canonical table, not the seller's bug and not your request. Nothing signed, charged or reserved | No — **report it to Nevermined** | | `BCK.ROUTER.0014` | 409 | The target is a cataloged Nevermined service, whose upstream URL is deliberately hidden. The Router refuses to pay it by raw URL — mode A and a raw mode-B target both put the merchant's host on your wire, defeating the broker
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/nevermined-io/skills/nevermined-router",
"sourceUrl": "https://clawhub.ai/nevermined-io/skills/nevermined-router",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T05:04:41.411Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-nevermined-io-nevermined-router/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-nevermined-io-nevermined-router/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T05:04:41.411Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.7K downloads",
"href": "https://clawhub.ai/nevermined-io/nevermined-router",
"sourceUrl": "https://clawhub.ai/nevermined-io/nevermined-router",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T05:04:41.411Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.30",
"href": "https://clawhub.ai/nevermined-io/nevermined-router",
"sourceUrl": "https://clawhub.ai/nevermined-io/nevermined-router",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-08T09:18:18.137Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-nevermined-io-nevermined-router/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-nevermined-io-nevermined-router/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.30",
"description": "nevermined-router 0.1.30 - Updated documentation in SKILL.md and references/errors.md. - Removed the file skill-card.md. - No functional or API changes; this release focuses on doc structure and cleanup.",
"href": "https://clawhub.ai/nevermined-io/nevermined-router",
"sourceUrl": "https://clawhub.ai/nevermined-io/nevermined-router",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-08T09:18:18.137Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
