{"id":"7c8a5995-8e4d-4b03-9205-5be8cd669641","entityType":"agent","slug":"clawhub-danhill-stripe-create-payment-credential","name":"Create Payment Credential","canonicalUrl":"https://www.xpersona.co/agent/clawhub-danhill-stripe-create-payment-credential","canonicalPath":"/agent/clawhub-danhill-stripe-create-payment-credential","generatedAt":"2026-10-11T17:42:38.346Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T15:36:10.042Z","emptyReason":null},"description":"Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says... Skill: Create Payment Credential Owner: danhill-stripe Summary: Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says... Tags: latest:0.6.0 Version history: v0.6.0 | 2026-05-28T20:16:33.614Z | auto - Added detailed instructions for inline polling in the authentication flow (auth login --interval and --timeout usage)","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17c3fz8thqgw71wn313rzw83n85z86w:create-payment-credential","sourceUrl":"https://clawhub.ai/danhill-stripe/create-payment-credential","homepage":"https://clawhub.ai/danhill-stripe/skills/create-payment-credential","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/danhill-stripe/create-payment-credential","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/danhill-stripe/skills/create-payment-credential","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says... "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:36:10.042Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:36:10.042Z","emptyReason":null},"stars":null,"forks":null,"downloads":1038,"packageName":null,"latestVersion":"0.6.0","tractionLabel":"1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:36:09.974Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T15:36:10.042Z","lastCrawledAt":"2026-10-11T15:36:09.974Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T15:36:09.974Z","lastVerifiedAt":null,"highlights":[{"version":"0.6.0","createdAt":"2026-05-28T20:16:33.614Z","changelog":"- Added detailed instructions for inline polling in the authentication flow (`auth login --interval` and `--timeout` usage). - Updated authentication step to reflect new `_next` command logic and handling for environments that cannot relay verification codes during blocking operations.","fileCount":3,"zipByteSize":7351},{"version":"0.5.0","createdAt":"2026-05-11T20:07:14.093Z","changelog":"Version 0.5.0 - Added support and documentation for the `--auth <path>` flag to specify location of auth credentials file. - Updated \"Get payment methods\" step to include guidance and command for fetching shipping addresses with `shipping-address list`. - Expanded the list of valid `--total` line item keys to include options like `items_base_amount`, `items_discount`, `discount`, `fulfillment`, `shipping`, `fee`, `gift_wrap`, `tip`, and `store_credit`. - Clarified handling for aborting/polling in spend requests and included cancellation command example. - Minor improvements and clarifications throughout the documentation.","fileCount":3,"zipByteSize":6875},{"version":"0.4.3","createdAt":"2026-05-05T16:07:05.231Z","changelog":"- Updated documentation in SKILL.md for clarity and conciseness, especially regarding flow and installation. - Improved step-by-step instructions for authentication, merchant evaluation, and credential creation. - Added guidance for both CLI and MCP server usage. - Reorganized and streamlined command examples and parameter explanations. - No changes to code or functionality—documentation-only update.","fileCount":2,"zipByteSize":5195},{"version":"0.4.1","createdAt":"2026-05-02T14:10:44.794Z","changelog":"- Improved documentation for using Link CLI via MCP server or CLI fallback. - Added detailed step-by-step checklist for agents: authenticate, evaluate merchant, get payment methods, create spend request, and complete payment. - Provided explicit instructions for determining the correct credential type (card or shared payment token) based on merchant site and payment challenges. - Documented the use of the `mpp decode` command for handling HTTP 402 responses and extracting necessary data for tokenized payments. - Clarified required fields and error handling to help agents avoid common issues and ensure a smooth payment credential flow.","fileCount":2,"zipByteSize":5381}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17c3fz8thqgw71wn313rzw83n85z86w:create-payment-credential","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T17:42:38.345Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-danhill-stripe-create-payment-credential/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T15:36:10.042Z","emptyReason":null},"readme":"Skill: Create Payment Credential\n\nOwner: danhill-stripe\n\nSummary: Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says...\n\nTags: latest:0.6.0\n\nVersion history:\n\nv0.6.0 | 2026-05-28T20:16:33.614Z | auto\n\n- Added detailed instructions for inline polling in the authentication flow (`auth login --interval` and `--timeout` usage).\n- Updated authentication step to reflect new `_next` command logic and handling for environments that cannot relay verification codes during blocking operations.\n\nv0.5.0 | 2026-05-11T20:07:14.093Z | auto\n\nVersion 0.5.0\n\n- Added support and documentation for the `--auth <path>` flag to specify location of auth credentials file.\n- Updated \"Get payment methods\" step to include guidance and command for fetching shipping addresses with `shipping-address list`.\n- Expanded the list of valid `--total` line item keys to include options like `items_base_amount`, `items_discount`, `discount`, `fulfillment`, `shipping`, `fee`, `gift_wrap`, `tip`, and `store_credit`.\n- Clarified handling for aborting/polling in spend requests and included cancellation command example.\n- Minor improvements and clarifications throughout the documentation.\n\nv0.4.3 | 2026-05-05T16:07:05.231Z | auto\n\n- Updated documentation in SKILL.md for clarity and conciseness, especially regarding flow and installation.\n- Improved step-by-step instructions for authentication, merchant evaluation, and credential creation.\n- Added guidance for both CLI and MCP server usage.\n- Reorganized and streamlined command examples and parameter explanations.\n- No changes to code or functionality—documentation-only update.\n\nv0.4.1 | 2026-05-02T14:10:44.794Z | auto\n\n- Improved documentation for using Link CLI via MCP server or CLI fallback.\n- Added detailed step-by-step checklist for agents: authenticate, evaluate merchant, get payment methods, create spend request, and complete payment.\n- Provided explicit instructions for determining the correct credential type (card or shared payment token) based on merchant site and payment challenges.\n- Documented the use of the `mpp decode` command for handling HTTP 402 responses and extracting necessary data for tokenized payments.\n- Clarified required fields and error handling to help agents avoid common issues and ensure a smooth payment credential flow.\n\nArchive index:\n\nArchive v0.6.0: 3 files, 7351 bytes\n\nFiles: skill-card.md (2779b), SKILL.md (13318b), _meta.json (144b)\n\nFile v0.6.0:SKILL.md\n\n---\nversion: 0.6.0\nname: create-payment-credential\ndescription: |\n  Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says \"get me a card\", \"buy something\", \"pay for X\", \"make a purchase\", \"I need to pay\", \"complete checkout\", or asks to transact on any merchant site. Use when the user asks to connect or log in to or sign up for their Link account.\nallowed-tools:\n - Bash(link-cli:*)\n - Bash(npx:*)\n - Bash(npm:*)\nlicense: Complete terms in LICENSE\nmetadata:\n  author: stripe\n  url: link.com/agents\n  openclaw:\n    emoji: \"💳\"\n    homepage: https://link.com/agents\n    requires:\n      bins:\n        - link-cli\n    install:\n      - kind: node\n        package: \"@stripe/link-cli\"\n        bins: [link-cli]\nuser-invocable: true\n---\n\n# Create Payment Credential\n\nUse [Link](https://link.com) to get secure, one-time-use payment credentials from a Link wallet to complete purchases.\n\nThe CLI can produce one of two credential types:\n- A virtual card (PAN) for use with a standard web checkout form. The issued card works anywhere.\n- A Shared Payment Token (SPT) when the seller is in the Stripe Network and accepts payments programmatically (for example with Machine Payment Protocols).\n\n## Installing\n\nInstall with `npm install -g @stripe/link-cli`. Or run directly with `npx @stripe/link-cli`.\n\n## Running commands\n\nLink CLI can run as an **MCP server** or as a **standalone CLI**.\n\n**MCP:** Add the following to your MCP client config (`.mcp.json`, etc.)\n\n```json\n{\n  \"mcpServers\": {\n    \"link\": {\n      \"command\": \"npx\",\n      \"args\": [\"@stripe/link-cli\", \"--mcp\"]\n    }\n  }\n}\n```\n\nRun the MCP server directly with `npx @stripe/link-cli@latest --mcp`.\n\nCall `tools/list` to see all available MCP tools.\n\n### Common commands/options\n\n- List all commands: `link-cli --llms`\n- List all commands with parameters: `link-cli --llms-full`\n- Get a command's exact schema with `--schema`. For example, `link-cli spend-request create --schema`\n- Multi-step commands return a `_next` action. For example, authenticating or creating a spend request returns a `_next.command` that must be run to complete the flow.\n- By default all output is in `toon` format. Pass `--format [json|md|yaml]` to change output format.\n- Some commands return a verification or approval URL. **These** must be presented to the user clearly for their action.\n- `--auth <path>` flag to store auth credentials in a specific file instead of the default location. `auth login` writes to this file; all other commands read from it. Example: `link-cli auth login --auth credentials.json`\n\n_Recommended_: Run `link-cli --llms` to understand all the available commands. The `--llms-full` output is the canonical reference for parameter names, types, and valid values. Pass `--schema` before invoking a command to understand its parameters and constraints.\n\n## Core flow\n\nCopy this checklist and track progress:\n\n- Step 1: Authenticate with Link\n- Step 2: Evaluate merchant site (determine credential type)\n- Step 3: Get payment methods\n- Step 4: Create spend request with correct credential type\n- Step 5: Complete payment\n\n### Step 1: Authenticate with Link\n\nCheck auth status:\n\n```bash\nlink-cli auth status\n```\n\nIf the response includes an `update` field, a newer version of `link-cli` is available — run the `update_command` from that field to upgrade before proceeding.\n\nIf not authenticated:\n\n```bash\nlink-cli auth login --client-name \"<your-agent-name>\"\n```\n\nReplace `<your-agent-name>` with the name of your agent or application (for example, `\"Personal Assistant\"`, `\"Shopping Bot\"`). This name appears in the user's Link app when they approve the connection. Use a clear, unique, identifiable name.\n\nThe response includes a `_next` command — run it to poll until authenticated. If your environment cannot relay the verification code while a separate polling command blocks I/O, use inline polling instead: `auth login --client-name \"<name>\" --interval 5 --timeout 300`. This yields the code immediately then polls in the same command.\n\nDO NOT PROCEED until the user is authenticated with Link.\n\nAlways check the current authentication status before starting a new login flow — the user might already be logged in.\n\n### Step 2: Evaluate the merchant site BEFORE creating a spend request\n\n**CRITICAL:** Before calling `spend-request create` you must complete this checklist:\n1. Understand how the merchant accepts payments (cards or machine payments or other). **Do NOT** default to `card` credential type. The merchant determines the credential type — you cannot know it without checking first. Skipping this step will produce a spend request with the wrong credential type.\n2. Have the final total amount needed. Inclusive of any shipping costs, taxes or other costs. Skipping this step will produce a spend request that does not cover the full amount needed, and will be rejected.\n3. Clear context and understanding of what the user is purchasing. Be sure to know sizes, colors, shipping options, etc. Skipping this step will produce a spend request that the user does not recognize or understand.\n\n**Determine how the merchant accepts payment:**\n\n1. **Navigate to the merchant page** — browse it, read the page content, and understand how the site accepts payment.\n2. **If the page has a credit card form, Stripe Elements, or traditional checkout UI** — use `card`.\n3. **If the page describes an API or programmatic payment flow** — make a request to the relevant endpoint. If it returns **HTTP 402** with a `www-authenticate` header, use `shared_payment_token`.\n\nWhat you find determines which credential type to use:\n\n| What you see | Credential type | What to request |\n|---|---|---|\n| Credit card form / Stripe Elements | `card` (default) | Card |\n| HTTP 402 with `method=\"stripe\"` in `www-authenticate` | `shared_payment_token` | Shared payment token (SPT) |\n| HTTP 402 without `method=\"stripe\"` in `www-authenticate` | not supported | Do not continue |\n\n**For 402 responses:** The `www-authenticate` header may contain **multiple** payment challenges (e.g. `tempo`, `stripe`) in a single header value. Do not try to decode the payload manually. Pass the **full raw `WWW-Authenticate` header value** to Link CLI and let `mpp decode` select and validate the `method=\"stripe\"` challenge.\n\nTo derive `network_id`, use Link CLI's challenge decoder:\n\n```bash\nlink-cli mpp decode --challenge '<raw WWW-Authenticate header>'\n```\n\nThis validates the Stripe challenge, decodes the `request` payload, and returns both the extracted `network_id` and the decoded request JSON. Pass the full header exactly as received, even if it also contains non-Stripe or multiple `Payment` challenges.\n\n### Step 3: Get payment methods and potentially shipping addresses\n\nUse the default payment method, unless the user explicitly asks to select a different one.\n\n```bash\nlink-cli payment-methods list\n```\n\nIf the merchant checkout requires a shipping or delivery address, fetch the user's saved shipping addresses. Use the default address unless the user specifies otherwise.\n\n```bash\nlink-cli shipping-address list\n```\n\n### Step 4: Create the spend request with the right credential type\n\n```bash\nlink-cli spend-request create \\\n  --payment-method-id <id> \\\n  --amount <cents> \\\n  --context \"<description>\" \\\n  --merchant-name \"<name>\" \\\n  --merchant-url \"<url>\" \\\n  --line-item \"name:<product>,unit_amount:<cents>,quantity:<n>\" \\\n  --total \"type:total,display_text:Total,amount:<cents>\" \\\n \n```\n\n**`--line-item` keys:** `name` (required), `quantity`, `unit_amount`, `description`, `sku`, `url`, `image_url`, `product_url`. Repeatable for multiple items.\n\n**`--total` keys:** `type` (required; one of: `subtotal`, `tax`, `total`, `items_base_amount`, `items_discount`, `discount`, `fulfillment`, `shipping`, `fee`, `gift_wrap`, `tip`, `store_credit`), `display_text` (required), `amount` (required). Repeatable (e.g. subtotal + tax + shipping + total).\n\nDo not proceed to payment while the request is still `created` or `pending_approval`. If polling exits with `POLLING_TIMEOUT`, keep waiting or ask the user whether to continue polling. If they deny, ask for clarification what to do next. If the user wants to abort, cancel the spend request:\n\n```bash\nlink-cli spend-request cancel <id>\n```\n\nRecommend the user approves with the [Link app](https://link.com/download). Show the download URL.\n\n**Test mode:** Add `--test` to create testmode credentials instead of real ones. Useful for development and integration testing.\n\n### Step 5: Complete payment\n\n**Card:** Run `link-cli spend-request retrieve <id> --include card` to get the `card` object with `number`, `cvc`, `exp_month`, `exp_year`, `billing_address` (name, line1, line2, city, state, postal_code, country), and `valid_until` (Unix timestamp — the card stops working after this time). Enter these details into the merchant's checkout form.\n\n**Safe credential handoff:** To avoid leaking card data into transcripts or logs, add `--output-file <path>` to write the full card to a local file (created with `0600` permissions) while stdout shows only redacted data. Use `--force` to overwrite an existing file. Example:\n\n```bash\nlink-cli spend-request retrieve <id> --include card --output-file /tmp/link-card.json --format json\n```\n\n**SPT with 402 flow:** The SPT is **one-time use** — if the payment fails, you need a new spend request and new SPT.\n\n```bash\nlink-cli mpp pay <url> --spend-request-id <id> [--method POST] [--data '{\"amount\":100}'] [--header 'Name: Value']\n```\n\n`mpp pay` handles the full 402 flow automatically: probes the URL, parses the `www-authenticate` header, builds the `Authorization: Payment` credential using the SPT, and retries.\n\n\n## Important\n\n- Treat the user's payment methods, credentials, and shipping addresses as sensitive — card numbers and SPTs grant real spending power; shipping addresses are PII. Mask or abbreviate addresses when displaying to the user (e.g. show city and zip only) unless they request full details.\n- Respect `/agents.txt` and `/llm.txt` and other directives on sites you browse — these files declare whether the site permits automated agent interactions; ignoring them may violate the merchant's terms.\n- Avoid suspicious merchants, checkout pages and websites — phishing pages that mimic legitimate merchants can steal credentials; if anything about the page feels off (mismatched domain, unusual redirect, unexpected login prompt), stop and ask the user to verify.\n- When outputting card information to the user apply basic masking to the card number and address to protect their information. Only reveal the raw values if directly requested to do so.\n\n## Limits\n\n| Limit | Value |\n|-------|-------|\n| Max amount per spend request | $500 (50,000 cents) |\n| Approval window | 10 minutes — user must approve within 10 min of `spend-request request-approval` |\n| Card / SPT validity (`valid_until`) | 12 hours from spend request creation |\n| Daily spend per account | $500 |\n| Concurrent active requests (created + approved) | 30 |\n| Concurrent approved requests | 10 |\n| Hourly creation rate | 50 per hour |\n| Rolling creation rate | 200 per 60 days |\n\nIf a spend request is created but approval is not requested within the window, or the user does not approve within 10 minutes, the request expires. Create a new one. Do not poll indefinitely — if the approval window is nearly exhausted and the user hasn't responded, surface this to the user.\n\n## Errors\n\nAll errors are output as JSON with `code` and `message` fields, with exit code 1.\n\n### Common errors and recovery\n\n| Error / Symptom | Cause | Recovery |\n|---|---|---|\n| `verification-failed` in error body from `mpp pay` | SPT was already consumed (one-time use) | Create a new spend request with `credential_type: \"shared_payment_token\"` — do not retry with the same spend request ID |\n| `context` validation error on `spend-request create` | `context` field is under 100 characters | Rewrite `context` as a full sentence explaining what is being purchased and why; the user reads this when approving |\n| API rejects `merchant_name` or `merchant_url` | These fields are forbidden when `credential_type` is `shared_payment_token` | Remove both fields from the request; SPT flows identify the merchant via `network_id` instead |\n| Spend request approved but payment fails immediately | Wrong credential type for the merchant (e.g. `card` on a 402-only endpoint) | Go back to Step 2, re-evaluate the merchant, create a new spend request with the correct `credential_type` |\n| Auth token expired mid-session (exit code 1 during approval polling) | Token refresh failure during background polling | Re-authenticate with `auth login`, then retrieve the existing spend request or resume polling. Only create a new spend request if the original one expired, was denied, was canceled, or its shared payment token was already consumed |\n\n## Further docs\n\n- MPP/x402 protocol: https://mpp.dev/protocol.md, https://mpp.dev/protocol/http-402.md, https://mpp.dev/protocol/challenges.md\n- Link: https://link.com/agents\n- Link App (for account management): https://app.link.com\n- Link support (if the user needs help with Link): https://support.link.com/topics/about-link\n\nFile v0.6.0:_meta.json\n\n{\n  \"ownerId\": \"kn70d9rxm3564f99rv3gg4z2e985z4n5\",\n  \"slug\": \"create-payment-credential\",\n  \"version\": \"0.6.0\",\n  \"publishedAt\": 1779999393614\n}\n\nFile v0.6.0:skill-card.md\n\n## Description:\n\nGets secure, one-time-use payment credentials such as cards and tokens from a Link wallet so agents can complete purchases on behalf of users.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[danhill-stripe](https://clawhub.ai/user/danhill-stripe)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users and agent developers use this skill when an agent needs to authenticate with Link, evaluate a merchant checkout, create a user-approved spend request, and retrieve the correct one-time payment credential for a purchase.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can enable real payment actions and handles payment credentials, payment methods, and shipping addresses.\n\nMitigation: Require explicit user confirmation before merchant, amount, item, payment method, shipping address, or domain changes; mask sensitive values unless the user directly requests disclosure.\n\nRisk: The skill relies on broad package execution and mutable CLI installation paths.\n\nMitigation: Prefer a pinned and reviewed @stripe/link-cli version, avoid global installs where possible, and review the CLI before enabling it for agent use.\n\nRisk: Persistent authentication files and retrieved card/SPT data could leak through shared workspaces, transcripts, or logs.\n\nMitigation: Store auth files outside shared workspaces with restricted permissions and use output-file handling for credential retrieval so stdout remains redacted.\n\n## Reference(s):\n\n- [Create Payment Credential on ClawHub](https://clawhub.ai/danhill-stripe/skills/create-payment-credential)\n- [Link Agents](https://link.com/agents)\n- [Link](https://link.com)\n- [MPP/x402 Protocol](https://mpp.dev/protocol.md)\n- [MPP HTTP 402 Protocol](https://mpp.dev/protocol/http-402.md)\n- [MPP Challenges](https://mpp.dev/protocol/challenges.md)\n- [Link App](https://app.link.com)\n- [Link Support](https://support.link.com/topics/about-link)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, JSON, Text]\n\n**Output Format:** [Markdown guidance with inline shell commands, JSON/MCP configuration snippets, and CLI output references]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [CLI output may be toon, JSON, Markdown, YAML, or local files; sensitive payment credentials should be redacted in stdout or written to restricted-permission files.]\n\n## Skill Version(s):\n\n0.6.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.5.0: 3 files, 6875 bytes\n\nFiles: skill-card.md (2784b), SKILL.md (12184b), _meta.json (144b)\n\nFile v0.5.0:SKILL.md\n\n---\nversion: 0.5.0\nname: create-payment-credential\ndescription: |\n  Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says \"get me a card\", \"buy something\", \"pay for X\", \"make a purchase\", \"I need to pay\", \"complete checkout\", or asks to transact on any merchant site. Use when the user asks to connect or log in to or sign up for their Link account.\nallowed-tools:\n - Bash(link-cli:*)\n - Bash(npx:*)\n - Bash(npm:*)\nlicense: Complete terms in LICENSE\nmetadata:\n  author: stripe\n  url: link.com/agents\n  openclaw:\n    emoji: \"💳\"\n    homepage: https://link.com/agents\n    requires:\n      bins:\n        - link-cli\n    install:\n      - kind: node\n        package: \"@stripe/link-cli\"\n        bins: [link-cli]\nuser-invocable: true\n---\n\n# Create Payment Credential\n\nUse [Link](https://link.com) to get secure, one-time-use payment credentials from a Link wallet to complete purchases.\n\nThe CLI can produce one of two credential types:\n- A virtual card (PAN) for use with a standard web checkout form. The issued card works anywhere.\n- A Shared Payment Token (SPT) when the seller is in the Stripe Network and accepts payments programmatically (for example with Machine Payment Protocols).\n\n## Installing\n\nInstall with `npm install -g @stripe/link-cli`. Or run directly with `npx @stripe/link-cli`.\n\n## Running commands\n\nLink CLI can run as an **MCP server** or as a **standalone CLI**.\n\n**MCP:** Add the following to your MCP client config (`.mcp.json`, etc.)\n\n```json\n{\n  \"mcpServers\": {\n    \"link\": {\n      \"command\": \"npx\",\n      \"args\": [\"@stripe/link-cli\", \"--mcp\"]\n    }\n  }\n}\n```\n\nRun the MCP server directly with `npx @stripe/link-cli@latest --mcp`.\n\nCall `tools/list` to see all available MCP tools.\n\n### Common commands/options\n\n- List all commands: `link-cli --llms`\n- List all commands with parameters: `link-cli --llms-full`\n- Get a command's exact schema with `--schema`. For example, `link-cli spend-request create --schema`\n- Multi-step commands return a `_next` action. For example, authenticating or creating a spend request returns a `_next.command` that must be run to complete the flow.\n- By default all output is in `toon` format. Pass `--format [json|md|yaml]` to change output format.\n- Some commands return a verification or approval URL. **These** must be presented to the user clearly for their action.\n- `--auth <path>` flag to store auth credentials in a specific file instead of the default location. `auth login` writes to this file; all other commands read from it. Example: `link-cli auth login --auth credentials.json`\n\n_Recommended_: Run `link-cli --llms` to understand all the available commands. The `--llms-full` output is the canonical reference for parameter names, types, and valid values. Pass `--schema` before invoking a command to understand its parameters and constraints.\n\n## Core flow\n\nCopy this checklist and track progress:\n\n- Step 1: Authenticate with Link\n- Step 2: Evaluate merchant site (determine credential type)\n- Step 3: Get payment methods\n- Step 4: Create spend request with correct credential type\n- Step 5: Complete payment\n\n### Step 1: Authenticate with Link\n\nCheck auth status:\n\n```bash\nlink-cli auth status\n```\n\nIf the response includes an `update` field, a newer version of `link-cli` is available — run the `update_command` from that field to upgrade before proceeding.\n\nIf not authenticated:\n\n```bash\nlink-cli auth login --client-name \"<your-agent-name>\"\n```\n\nReplace `<your-agent-name>` with the name of your agent or application (for example, `\"Personal Assistant\"`, `\"Shopping Bot\"`). This name appears in the user's Link app when they approve the connection. Use a clear, unique, identifiable name.\n\nDO NOT PROCEED until the user is authenticated with Link.\n\nAlways check the current authentication status before starting a new login flow — the user might already be logged in.\n\n### Step 2: Evaluate the merchant site BEFORE creating a spend request\n\n**CRITICAL:** Before calling `spend-request create` you must complete this checklist:\n1. Understand how the merchant accepts payments (cards or machine payments or other). **Do NOT** default to `card` credential type. The merchant determines the credential type — you cannot know it without checking first. Skipping this step will produce a spend request with the wrong credential type.\n2. Have the final total amount needed. Inclusive of any shipping costs, taxes or other costs. Skipping this step will produce a spend request that does not cover the full amount needed, and will be rejected.\n3. Clear context and understanding of what the user is purchasing. Be sure to know sizes, colors, shipping options, etc. Skipping this step will produce a spend request that the user does not recognize or understand.\n\n**Determine how the merchant accepts payment:**\n\n1. **Navigate to the merchant page** — browse it, read the page content, and understand how the site accepts payment.\n2. **If the page has a credit card form, Stripe Elements, or traditional checkout UI** — use `card`.\n3. **If the page describes an API or programmatic payment flow** — make a request to the relevant endpoint. If it returns **HTTP 402** with a `www-authenticate` header, use `shared_payment_token`.\n\nWhat you find determines which credential type to use:\n\n| What you see | Credential type | What to request |\n|---|---|---|\n| Credit card form / Stripe Elements | `card` (default) | Card |\n| HTTP 402 with `method=\"stripe\"` in `www-authenticate` | `shared_payment_token` | Shared payment token (SPT) |\n| HTTP 402 without `method=\"stripe\"` in `www-authenticate` | not supported | Do not continue |\n\n**For 402 responses:** The `www-authenticate` header may contain **multiple** payment challenges (e.g. `tempo`, `stripe`) in a single header value. Do not try to decode the payload manually. Pass the **full raw `WWW-Authenticate` header value** to Link CLI and let `mpp decode` select and validate the `method=\"stripe\"` challenge.\n\nTo derive `network_id`, use Link CLI's challenge decoder:\n\n```bash\nlink-cli mpp decode --challenge '<raw WWW-Authenticate header>'\n```\n\nThis validates the Stripe challenge, decodes the `request` payload, and returns both the extracted `network_id` and the decoded request JSON. Pass the full header exactly as received, even if it also contains non-Stripe or multiple `Payment` challenges.\n\n### Step 3: Get payment methods and potentially shipping addresses\n\nUse the default payment method, unless the user explicitly asks to select a different one.\n\n```bash\nlink-cli payment-methods list\n```\n\nIf the merchant checkout requires a shipping or delivery address, fetch the user's saved shipping addresses. Use the default address unless the user specifies otherwise.\n\n```bash\nlink-cli shipping-address list\n```\n\n### Step 4: Create the spend request with the right credential type\n\n```bash\nlink-cli spend-request create \\\n  --payment-method-id <id> \\\n  --amount <cents> \\\n  --context \"<description>\" \\\n  --merchant-name \"<name>\" \\\n  --merchant-url \"<url>\" \\\n  --line-item \"name:<product>,unit_amount:<cents>,quantity:<n>\" \\\n  --total \"type:total,display_text:Total,amount:<cents>\" \\\n \n```\n\n**`--line-item` keys:** `name` (required), `quantity`, `unit_amount`, `description`, `sku`, `url`, `image_url`, `product_url`. Repeatable for multiple items.\n\n**`--total` keys:** `type` (required; one of: `subtotal`, `tax`, `total`, `items_base_amount`, `items_discount`, `discount`, `fulfillment`, `shipping`, `fee`, `gift_wrap`, `tip`, `store_credit`), `display_text` (required), `amount` (required). Repeatable (e.g. subtotal + tax + shipping + total).\n\nDo not proceed to payment while the request is still `created` or `pending_approval`. If polling exits with `POLLING_TIMEOUT`, keep waiting or ask the user whether to continue polling. If they deny, ask for clarification what to do next. If the user wants to abort, cancel the spend request:\n\n```bash\nlink-cli spend-request cancel <id>\n```\n\nRecommend the user approves with the [Link app](https://link.com/download). Show the download URL.\n\n**Test mode:** Add `--test` to create testmode credentials instead of real ones. Useful for development and integration testing.\n\n### Step 5: Complete payment\n\n**Card:** Run `link-cli spend-request retrieve <id> --include card` to get the `card` object with `number`, `cvc`, `exp_month`, `exp_year`, `billing_address` (name, line1, line2, city, state, postal_code, country), and `valid_until` (Unix timestamp — the card stops working after this time). Enter these details into the merchant's checkout form.\n\n**Safe credential handoff:** To avoid leaking card data into transcripts or logs, add `--output-file <path>` to write the full card to a local file (created with `0600` permissions) while stdout shows only redacted data. Use `--force` to overwrite an existing file. Example:\n\n```bash\nlink-cli spend-request retrieve <id> --include card --output-file /tmp/link-card.json --format json\n```\n\n**SPT with 402 flow:** The SPT is **one-time use** — if the payment fails, you need a new spend request and new SPT.\n\n```bash\nlink-cli mpp pay <url> --spend-request-id <id> [--method POST] [--data '{\"amount\":100}'] [--header 'Name: Value']\n```\n\n`mpp pay` handles the full 402 flow automatically: probes the URL, parses the `www-authenticate` header, builds the `Authorization: Payment` credential using the SPT, and retries.\n\n\n## Important\n\n- Treat the user's payment methods, credentials, and shipping addresses as sensitive — card numbers and SPTs grant real spending power; shipping addresses are PII. Mask or abbreviate addresses when displaying to the user (e.g. show city and zip only) unless they request full details.\n- Respect `/agents.txt` and `/llm.txt` and other directives on sites you browse — these files declare whether the site permits automated agent interactions; ignoring them may violate the merchant's terms.\n- Avoid suspicious merchants, checkout pages and websites — phishing pages that mimic legitimate merchants can steal credentials; if anything about the page feels off (mismatched domain, unusual redirect, unexpected login prompt), stop and ask the user to verify.\n- When outputting card information to the user apply basic masking to the card number and address to protect their information. Only reveal the raw values if directly requested to do so.\n\n## Errors\n\nAll errors are output as JSON with `code` and `message` fields, with exit code 1.\n\n### Common errors and recovery\n\n| Error / Symptom | Cause | Recovery |\n|---|---|---|\n| `verification-failed` in error body from `mpp pay` | SPT was already consumed (one-time use) | Create a new spend request with `credential_type: \"shared_payment_token\"` — do not retry with the same spend request ID |\n| `context` validation error on `spend-request create` | `context` field is under 100 characters | Rewrite `context` as a full sentence explaining what is being purchased and why; the user reads this when approving |\n| API rejects `merchant_name` or `merchant_url` | These fields are forbidden when `credential_type` is `shared_payment_token` | Remove both fields from the request; SPT flows identify the merchant via `network_id` instead |\n| Spend request approved but payment fails immediately | Wrong credential type for the merchant (e.g. `card` on a 402-only endpoint) | Go back to Step 2, re-evaluate the merchant, create a new spend request with the correct `credential_type` |\n| Auth token expired mid-session (exit code 1 during approval polling) | Token refresh failure during background polling | Re-authenticate with `auth login`, then retrieve the existing spend request or resume polling. Only create a new spend request if the original one expired, was denied, was canceled, or its shared payment token was already consumed |\n\n## Further docs\n\n- MPP/x402 protocol: https://mpp.dev/protocol.md, https://mpp.dev/protocol/http-402.md, https://mpp.dev/protocol/challenges.md\n- Link: https://link.com/agents\n- Link App (for account management): https://app.link.com\n- Link support (if the user needs help with Link): https://support.link.com/topics/about-link\n\nFile v0.5.0:_meta.json\n\n{\n  \"ownerId\": \"kn70d9rxm3564f99rv3gg4z2e985z4n5\",\n  \"slug\": \"create-payment-credential\",\n  \"version\": \"0.5.0\",\n  \"publishedAt\": 1778530034093\n}\n\nFile v0.5.0:skill-card.md\n\n## Description: <br>\nGets secure, one-time-use payment credentials from a Link wallet so agents can complete purchases on behalf of users. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[danhill-stripe](https://clawhub.ai/user/danhill-stripe) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nAgents and their operators use this skill to authenticate with Link, inspect merchant payment requirements, request approved one-time payment credentials, and complete card or Stripe-network programmatic payments. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can create real one-time payment credentials and support purchases. <br>\nMitigation: Require explicit purchase approval and verify the merchant, items, shipping, taxes, final amount, credential type, and Link approval prompt before payment. <br>\nRisk: Payment methods, card data, shared payment tokens, and shipping addresses are sensitive. <br>\nMitigation: Prefer local output files for raw card data, mask card and address details in chat, and avoid exposing raw values unless the user directly requests them. <br>\nRisk: A suspicious merchant or incorrect payment-type assessment can expose credentials or create an unusable spend request. <br>\nMitigation: Inspect the merchant domain and checkout flow, stop on suspicious redirects or prompts, respect site automation directives, and use Link CLI schema and MPP decoding instead of guessing. <br>\n\n\n## Reference(s): <br>\n- [Create Payment Credential on ClawHub](https://clawhub.ai/danhill-stripe/create-payment-credential) <br>\n- [Link Agents](https://link.com/agents) <br>\n- [Link](https://link.com) <br>\n- [MPP Protocol](https://mpp.dev/protocol.md) <br>\n- [MPP HTTP 402](https://mpp.dev/protocol/http-402.md) <br>\n- [MPP Challenges](https://mpp.dev/protocol/challenges.md) <br>\n- [Link App](https://app.link.com) <br>\n- [Link Support](https://support.link.com/topics/about-link) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown guidance with bash and JSON snippets; Link CLI output can be toon, JSON, Markdown, or YAML.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May produce local credential files with restricted permissions when --output-file is used.] <br>\n\n## Skill Version(s): <br>\n0.5.0 (source: frontmatter and server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.4.3: 2 files, 5195 bytes\n\nFiles: SKILL.md (11386b), _meta.json (144b)\n\nFile v0.4.3:SKILL.md\n\n---\nname: create-payment-credential\ndescription: |\n  Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says \"get me a card\", \"buy something\", \"pay for X\", \"make a purchase\", \"I need to pay\", \"complete checkout\", or asks to transact on any merchant site. Use when the user asks to connect or log in to or sign up for their Link account.\nallowed-tools:\n - Bash(link-cli:*)\n - Bash(npx:*)\n - Bash(npm:*)\nlicense: Complete terms in LICENSE\nmetadata:\n  author: stripe\n  url: link.com/agents\n  openclaw:\n    emoji: \"💳\"\n    homepage: https://link.com/agents\n    requires:\n      bins:\n        - link-cli\n    install:\n      - kind: node\n        package: \"@stripe/link-cli\"\n        bins: [link-cli]\nuser-invocable: true\n---\n\n# Create Payment Credential\n\nUse [Link](https://link.com) to get secure, one-time-use payment credentials from a Link wallet to complete purchases.\n\nThe CLI can produce one of two credential types:\n- A virtual card (PAN) for use with a standard web checkout form. The issued card works anywhere.\n- A Shared Payment Token (SPT) when the seller is in the Stripe Network and accepts payments programmatically (for example with Machine Payment Protocols).\n\n## Installing\n\nInstall with `npm install -g @stripe/link-cli`. Or run directly with `npx @stripe/link-cli`.\n\n## Running commands\n\nLink CLI can run as an **MCP server** or as a **standalone CLI**.\n\n**MCP:** Add the following to your MCP client config (`.mcp.json`, etc.)\n\n```json\n{\n  \"mcpServers\": {\n    \"link\": {\n      \"command\": \"npx\",\n      \"args\": [\"@stripe/link-cli\", \"--mcp\"]\n    }\n  }\n}\n```\n\nRun the MCP server directly with `npx @stripe/link-cli@latest --mcp`.\n\nCall `tools/list` to see all available MCP tools.\n\n### Common commands/options\n\n- List all commands: `link-cli --llms`\n- List all commands with parameters: `link-cli --llms-full`\n- Get a command's exact schema with `--schema`. For example, `link-cli spend-request create --schema`\n- Multi-step commands return a `_next` action. For example, authenticating or creating a spend request returns a `_next.command` that must be run to complete the flow.\n- By default all output is in `toon` format. Pass `--format [json|md|yaml]` to change output format.\n- Some commands return a verification or approval URL. **These** must be presented to the user clearly for their action.\n\n_Recommended_: Run `link-cli --llms` to understand all the available commands. The `--llms-full` output is the canonical reference for parameter names, types, and valid values. Pass `--schema` before invoking a command to understand its parameters and constraints.\n\n## Core flow\n\nCopy this checklist and track progress:\n\n- Step 1: Authenticate with Link\n- Step 2: Evaluate merchant site (determine credential type)\n- Step 3: Get payment methods\n- Step 4: Create spend request with correct credential type\n- Step 5: Complete payment\n\n### Step 1: Authenticate with Link\n\nCheck auth status:\n\n```bash\nlink-cli auth status\n```\n\nIf the response includes an `update` field, a newer version of `link-cli` is available — run the `update_command` from that field to upgrade before proceeding.\n\nIf not authenticated:\n\n```bash\nlink-cli auth login --client-name \"<your-agent-name>\"\n```\n\nReplace `<your-agent-name>` with the name of your agent or application (for example, `\"Personal Assistant\"`, `\"Shopping Bot\"`). This name appears in the user's Link app when they approve the connection. Use a clear, unique, identifiable name.\n\nDO NOT PROCEED until the user is authenticated with Link.\n\nAlways check the current authentication status before starting a new login flow — the user might already be logged in.\n\n### Step 2: Evaluate the merchant site BEFORE creating a spend request\n\n**CRITICAL:** Before calling `spend-request create` you must complete this checklist:\n1. Understand how the merchant accepts payments (cards or machine payments or other). **Do NOT** default to `card` credential type. The merchant determines the credential type — you cannot know it without checking first. Skipping this step will produce a spend request with the wrong credential type.\n2. Have the final total amount needed. Inclusive of any shipping costs, taxes or other costs. Skipping this step will produce a spend request that does not cover the full amount needed, and will be rejected.\n3. Clear context and understanding of what the user is purchasing. Be sure to know sizes, colors, shipping options, etc. Skipping this step will produce a spend request that the user does not recognize or understand.\n\n**Determine how the merchant accepts payment:**\n\n1. **Navigate to the merchant page** — browse it, read the page content, and understand how the site accepts payment.\n2. **If the page has a credit card form, Stripe Elements, or traditional checkout UI** — use `card`.\n3. **If the page describes an API or programmatic payment flow** — make a request to the relevant endpoint. If it returns **HTTP 402** with a `www-authenticate` header, use `shared_payment_token`.\n\nWhat you find determines which credential type to use:\n\n| What you see | Credential type | What to request |\n|---|---|---|\n| Credit card form / Stripe Elements | `card` (default) | Card |\n| HTTP 402 with `method=\"stripe\"` in `www-authenticate` | `shared_payment_token` | Shared payment token (SPT) |\n| HTTP 402 without `method=\"stripe\"` in `www-authenticate` | not supported | Do not continue |\n\n**For 402 responses:** The `www-authenticate` header may contain **multiple** payment challenges (e.g. `tempo`, `stripe`) in a single header value. Do not try to decode the payload manually. Pass the **full raw `WWW-Authenticate` header value** to Link CLI and let `mpp decode` select and validate the `method=\"stripe\"` challenge.\n\nTo derive `network_id`, use Link CLI's challenge decoder:\n\n```bash\nlink-cli mpp decode --challenge '<raw WWW-Authenticate header>'\n```\n\nThis validates the Stripe challenge, decodes the `request` payload, and returns both the extracted `network_id` and the decoded request JSON. Pass the full header exactly as received, even if it also contains non-Stripe or multiple `Payment` challenges.\n\n### Step 3: Get payment methods\n\nUse the default payment method, unless the user explicitly asks to select a different one.\n\n```bash\nlink-cli payment-methods list\n```\n\n### Step 4: Create the spend request with the right credential type\n\n```bash\nlink-cli spend-request create \\\n  --payment-method-id <id> \\\n  --amount <cents> \\\n  --context \"<description>\" \\\n  --merchant-name \"<name>\" \\\n  --merchant-url \"<url>\" \\\n  --line-item \"name:<product>,unit_amount:<cents>,quantity:<n>\" \\\n  --total \"type:total,display_text:Total,amount:<cents>\" \\\n \n```\n\n**`--line-item` keys:** `name` (required), `quantity`, `unit_amount`, `description`, `sku`, `url`, `image_url`, `product_url`. Repeatable for multiple items.\n\n**`--total` keys:** `type` (required; one of: `subtotal`, `tax`, `total`), `display_text` (required), `amount` (required). Repeatable (e.g. subtotal + tax + total).\n\nDo not proceed to payment while the request is still `created` or `pending_approval`. If polling exits with `POLLING_TIMEOUT`, keep waiting or ask the user whether to continue polling. If they deny, ask for clarification what to do next.\n\nRecommend the user approves with the [Link app](https://link.com/download). Show the download URL.\n\n**Test mode:** Add `--test` to create testmode credentials instead of real ones. Useful for development and integration testing.\n\n### Step 5: Complete payment\n\n**Card:** Run `link-cli spend-request retrieve <id> --include card` to get the `card` object with `number`, `cvc`, `exp_month`, `exp_year`, `billing_address` (name, line1, line2, city, state, postal_code, country), and `valid_until` (Unix timestamp — the card stops working after this time). Enter these details into the merchant's checkout form.\n\n**Safe credential handoff:** To avoid leaking card data into transcripts or logs, add `--output-file <path>` to write the full card to a local file (created with `0600` permissions) while stdout shows only redacted data. Use `--force` to overwrite an existing file. Example:\n\n```bash\nlink-cli spend-request retrieve <id> --include card --output-file /tmp/link-card.json --format json\n```\n\n**SPT with 402 flow:** The SPT is **one-time use** — if the payment fails, you need a new spend request and new SPT.\n\n```bash\nlink-cli mpp pay <url> --spend-request-id <id> [--method POST] [--data '{\"amount\":100}'] [--header 'Name: Value']\n```\n\n`mpp pay` handles the full 402 flow automatically: probes the URL, parses the `www-authenticate` header, builds the `Authorization: Payment` credential using the SPT, and retries.\n\n\n## Important\n\n- Treat the user's payment methods and credentials extremely carefully — card numbers and SPTs grant real spending power; leaking them outside a secure checkout could result in unauthorized charges the user cannot reverse.\n- Respect `/agents.txt` and `/llm.txt` and other directives on sites you browse — these files declare whether the site permits automated agent interactions; ignoring them may violate the merchant's terms.\n- Avoid suspicious merchants, checkout pages and websites — phishing pages that mimic legitimate merchants can steal credentials; if anything about the page feels off (mismatched domain, unusual redirect, unexpected login prompt), stop and ask the user to verify.\n- When outputting card information to the user apply basic masking to the card number and address to protect their information. Only reveal the raw values if directly requested to do so.\n\n## Errors\n\nAll errors are output as JSON with `code` and `message` fields, with exit code 1.\n\n### Common errors and recovery\n\n| Error / Symptom | Cause | Recovery |\n|---|---|---|\n| `verification-failed` in error body from `mpp pay` | SPT was already consumed (one-time use) | Create a new spend request with `credential_type: \"shared_payment_token\"` — do not retry with the same spend request ID |\n| `context` validation error on `spend-request create` | `context` field is under 100 characters | Rewrite `context` as a full sentence explaining what is being purchased and why; the user reads this when approving |\n| API rejects `merchant_name` or `merchant_url` | These fields are forbidden when `credential_type` is `shared_payment_token` | Remove both fields from the request; SPT flows identify the merchant via `network_id` instead |\n| Spend request approved but payment fails immediately | Wrong credential type for the merchant (e.g. `card` on a 402-only endpoint) | Go back to Step 2, re-evaluate the merchant, create a new spend request with the correct `credential_type` |\n| Auth token expired mid-session (exit code 1 during approval polling) | Token refresh failure during background polling | Re-authenticate with `auth login`, then retrieve the existing spend request or resume polling. Only create a new spend request if the original one expired, was denied, or its shared payment token was already consumed |\n\n## Further docs\n\n- MPP/x402 protocol: https://mpp.dev/protocol.md, https://mpp.dev/protocol/http-402.md, https://mpp.dev/protocol/challenges.md\n- Link: https://link.com/agents\n- Link App (for account management): https://app.link.com\n- Link support (if the user needs help with Link): https://support.link.com/topics/about-link\n\nFile v0.4.3:_meta.json\n\n{\n  \"ownerId\": \"kn70d9rxm3564f99rv3gg4z2e985z4n5\",\n  \"slug\": \"create-payment-credential\",\n  \"version\": \"0.4.3\",\n  \"publishedAt\": 1777997225231\n}\n\nArchive v0.4.1: 2 files, 5381 bytes\n\nFiles: SKILL.md (12396b), _meta.json (144b)\n\nFile v0.4.1:SKILL.md\n\n---\nname: create-payment-credential\ndescription: |\n  Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says \"get me a card\", \"buy something\", \"pay for X\", \"make a purchase\", \"I need to pay\", \"complete checkout\", or asks to transact on any merchant site. Use when the user asks to connect or log in to or sign up for their Link account.\nallowed-tools:\n - Bash(link-cli:*)\n - Bash(npx:*)\n - Bash(npm:*)\nlicense: Complete terms in LICENSE\nversion: 0.0.1\nmetadata:\n  author: stripe\n  url: link.com/agents\n  openclaw:\n    emoji: \"💳\"\n    homepage: https://link.com/agents\n    requires:\n      bins:\n        - link-cli\n    install:\n      - kind: node\n        package: \"@stripe/link-cli\"\n        bins: [link-cli]\nuser-invocable: true\n---\n\n# Creating Payment Credentials\n\nUse Link to get secure, one-time-use payment credentials from a Link wallet to complete purchases.\n\n## Choosing how to call Link\n\nLink CLI can run as an **MCP server** or as a **standalone CLI**. Always prefer the MCP server when available — it avoids shell parsing issues and is the intended integration path.\n\n1. **Check for the MCP server first.** Look for a `link-cli` MCP server in your active MCP connections. If present, call its tools directly (e.g. `auth_status`, `auth_login`, `spend-request_create`, `payment-methods_list`, `mpp_pay`, `mpp_decode`).\n2. **Fall back to the CLI** only if the MCP server is not available. Install it with `npm install -g @stripe/link-cli`, then use the shell commands documented below.\n\nThe rest of this document shows CLI commands. When using the MCP server, map each command to its corresponding MCP tool — the parameters and behavior are identical.\n\n| CLI command | MCP tool |\n|---|---|\n| `auth login` | `mcp__link-cli__auth_login` |\n| `auth logout` | `mcp__link-cli__auth_logout` |\n| `auth status` | `mcp__link-cli__auth_status` |\n| `spend-request create` | `mcp__link-cli__spend-request_create` |\n| `spend-request update` | `mcp__link-cli__spend-request_update` |\n| `spend-request retrieve` | `mcp__link-cli__spend-request_retrieve` |\n| `spend-request request-approval` | `mcp__link-cli__spend-request_request-approval` |\n| `payment-methods list` | `mcp__link-cli__payment-methods_list` |\n| `payment-methods add` | `mcp__link-cli__payment-methods_add` |\n| `mpp pay` | `mcp__link-cli__mpp_pay` |\n| `mpp decode` | `mcp__link-cli__mpp_decode` |\n\n## Running commands (CLI fallback)\n\nAll commands support `--format json` for machine-readable output. Pass input via flags (run `link-cli <command> --help` to see full schema details, including all fields, types, and constraints).\n\nIMPORTANT: Run `auth login` with `run_in_background=true` (or `TaskOutput(task_id, block: false)`). It emits JSON to stdout before it exits, then keeps running while it polls for user action.\n\nThe agent-facing JSON contract is:\n\n- `auth login --format json`: first object contains `verification_url` and `phrase`; final object contains authentication result after approval succeeds\n- `spend-request create --request-approval --format json`: returns the created spend request immediately with an `_next.command` polling hint\n- `spend-request request-approval --format json`: returns the approval link immediately with an `_next.command` polling hint\n- `spend-request retrieve <id> --interval <seconds> --format json`: polls until the spend request reaches a terminal status, then returns the terminal spend request. It exits non-zero with `code: \"POLLING_TIMEOUT\"` if `--timeout` is reached or `--max-attempts` is exhausted while the request is still non-terminal.\n\nFor `auth login`, keep reading stdout until the process exits. For spend request approval, present the `approval_url` to the user and start the `_next.command` polling command immediately. The user MUST visit the verification or approval URL to continue, and you should always show that full URL in clear text.\n\n## Core flow\n\nCopy this checklist and track progress:\n\n- Step 1: Authenticate with Link\n- Step 2: Evaluate merchant site (determine credential type)\n- Step 3: Get payment methods\n- Step 4: Create spend request with correct credential type\n- Step 5: Complete payment\n\n### Step 1: Authenticate with Link\n\nCheck auth status:\n\n```bash\nlink-cli auth status --format json\n```\n\nIf the response includes an `update` field, a newer version of `link-cli` is available — run the `update_command` from that field to upgrade before proceeding.\n\nIf not authenticated:\n\n```bash\nlink-cli auth login --client-name \"<your-agent-name>\" --format json\n```\n\nReplace `<your-agent-name>` with the name of your agent or application (e.g. `\"Personal Assistant\", \"Shopping Bot\"`). This name appears in the user's Link app when they approve the connection. Use a clear, unique, identifiable name. Display the url and phrase to the user, with the guidance \"Please visit the following URL to approve secure access to Link.”\n\nDO NOT PROCEED until the user is authenticated with Link.\n\nAlways check the current authentication status before starting a new login flow - the user may already be logged in.\n\n### Step 2: Evaluate the merchant site BEFORE creating a spend request\n\n**CRITICAL** before calling `spend-request create` you must complete this checklist:\n1. Understand how the merchant accepts payments (cards or machine payments or other). **Do NOT default to `card` credential type. The merchant determines the credential type — you cannot know it without checking first. Skipping this step will produce a spend request with the wrong credential type.\n2. Have the final total amount needed. Inclusive of any shipping costs, taxes or other costs. Skipping this step will produce a spend request that does not cover the full amount needed, and will be rejected.\n3. Clear context and understanding of what the user is purchasing. Be sure to know sizes, colors, shipping options, etc. Skipping this step will produce a spend request that the user does not recognize or understand.\n\n**Determine how the merchant accepts payment:**\n\n1. **Navigate to the merchant page** — browse it, read the page content, and understand how the site accepts payment.\n2. **If the page has a credit card form, Stripe Elements, or traditional checkout UI** — use `card`.\n3. **If the page describes an API or programmatic payment flow** — make a request to the relevant endpoint. If it returns **HTTP 402** with a `www-authenticate` header, use `shared_payment_token`.\n\nWhat you find determines which credential type to use:\n\n| What you see | Credential type | What to request |\n|---|---|---|\n| Credit card form / Stripe Elements | `card` (default) | Card |\n| HTTP 402 with `method=\"stripe\"` in `www-authenticate` | `shared_payment_token` | Shared payment token (SPT) |\n| HTTP 402 without `method=\"stripe\"` in `www-authenticate` | not supported | Do not continue |\n\n**For 402 responses:** The `www-authenticate` header may contain **multiple** payment challenges (e.g. `tempo`, `stripe`) in a single header value. Do not try to decode the payload manually. Pass the **full raw `WWW-Authenticate` header value** to Link CLI and let `mpp decode` select and validate the `method=\"stripe\"` challenge.\n\nTo derive `network_id`, use Link CLI's challenge decoder:\n\n```bash\nlink-cli mpp decode --challenge '<raw WWW-Authenticate header>' --format json\n```\n\nThis validates the Stripe challenge, decodes the `request` payload, and returns both the extracted `network_id` and the decoded request JSON. Pass the full header exactly as received, even if it also contains non-Stripe or multiple `Payment` challenges.\n\n### Step 3: Get payment methods\n\nUse the default payment method, unless the user explicitly asks to select a different one.\n\n```bash\nlink-cli payment-methods list --format json\n```\n\n### Step 4: Create the spend request with the right credential type\n\n```bash\nlink-cli spend-request create \\\n  --payment-method-id <id> \\\n  --amount <cents> \\\n  --context \"<description>\" \\\n  --merchant-name \"<name>\" \\\n  --merchant-url \"<url>\" \\\n  --format json\n```\n\nAfter creating or requesting approval for a spend request, run the returned `_next.command` to poll for the terminal status. Do not proceed to payment while the request is still `created` or `pending_approval`. If polling exits with `POLLING_TIMEOUT`, keep waiting or ask the user whether to continue polling. If they deny, ask for clarification what to do next.\n\nRecommend the user approves with the [Link app](https://link.com/download). Show the download URL.\n\n**Test mode:** Add `--test` to create testmode credentials instead of real ones. Useful for development and integration testing.\n\n### Step 5: Complete payment\n\n**Card:** Run `link-cli spend-request retrieve <id> --include card --format json` to get the `card` object with `number`, `cvc`, `exp_month`, `exp_year`, `billing_address` (name, line1, line2, city, state, postal_code, country), and `valid_until` (unix timestamp — the card stops working after this time). Enter these details into the merchant's checkout form.\n\n**SPT with 402 flow:** The SPT is **one-time use** — if the payment fails, you need a new spend request and new SPT.\n\n```bash\nlink-cli mpp pay <url> --spend-request-id <id> [--method POST] [--data '{\"amount\":100}'] [--header 'Name: Value'] --format json\n```\n\n`mpp pay` handles the full 402 flow automatically: probes the URL, parses the `www-authenticate` header, builds the `Authorization: Payment` credential using the SPT, and retries.\n\n\n## Important\n\n- Treat the user's payment methods and credentials extremely carefully — card numbers and SPTs grant real spending power; leaking them outside a secure checkout could result in unauthorized charges the user cannot reverse.\n- Respect `/agents.txt` and `/llm.txt` and other directives on sites you browse — these files declare whether the site permits automated agent interactions; ignoring them may violate the merchant's terms.\n- Avoid suspicious merchants, checkout pages and websites — phishing pages that mimic legitimate merchants can steal credentials; if anything about the page feels off (mismatched domain, unusual redirect, unexpected login prompt), stop and ask the user to verify.\n- When outputting card information to the user apply basic masking to the card number and address to protect their information. Only reveal the raw values if directly requested to do so.\n\n## Errors\n\nAll errors are output as JSON with `code` and `message` fields, with exit code 1.\n\n### Common errors and recovery\n\n| Error / Symptom | Cause | Recovery |\n|---|---|---|\n| `verification-failed` in error body from `mpp pay` | SPT was already consumed (one-time use) | Create a new spend request with `credential_type: \"shared_payment_token\"` — do not retry with the same spend request ID |\n| `context` validation error on `spend-request create` | `context` field is under 100 characters | Rewrite `context` as a full sentence explaining what is being purchased and why; the user reads this when approving |\n| API rejects `merchant_name` or `merchant_url` | These fields are forbidden when `credential_type` is `shared_payment_token` | Remove both fields from the request; SPT flows identify the merchant via `network_id` instead |\n| Command hangs indefinitely | `auth login` or `spend-request create` run synchronously | Always run these commands with `run_in_background=true` — they block until the user acts, so synchronous execution freezes the agent |\n| Spend request approved but payment fails immediately | Wrong credential type for the merchant (e.g. `card` on a 402-only endpoint) | Go back to Step 2, re-evaluate the merchant, create a new spend request with the correct `credential_type` |\n| Auth token expired mid-session (exit code 1 during approval polling) | Token refresh failure during background polling | Re-authenticate with `auth login`, then retrieve the existing spend request or resume polling. Only create a new spend request if the original one expired, was denied, or its shared payment token was already consumed |\n\n## Further docs\n\n- MPP/x402 protocol: https://mpp.dev/protocol.md, https://mpp.dev/protocol/http-402.md, https://mpp.dev/protocol/challenges.md\n- Link: https://link.com/agents\n- Link App (for account management): https://app.link.com\n- Link support (if the user needs help with Link): https://support.link.com/topics/about-link\n\nFile v0.4.1:_meta.json\n\n{\n  \"ownerId\": \"kn70d9rxm3564f99rv3gg4z2e985z4n5\",\n  \"slug\": \"create-payment-credential\",\n  \"version\": \"0.4.1\",\n  \"publishedAt\": 1777731044794\n}","readmeExcerpt":"Skill: Create Payment Credential Owner: danhill-stripe Summary: Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says... Tags: latest:0.6.0 Version history: v0.6.0 | 2026-05-28T20:16:33.614Z | auto - Added detailed instructions for inline polling in the authentication flow (auth login --interval and --timeout usage)","codeSnippets":[],"executableExamples":[{"language":"json","snippet":"{\n  \"mcpServers\": {\n    \"link\": {\n      \"command\": \"npx\",\n      \"args\": [\"@stripe/link-cli\", \"--mcp\"]\n    }\n  }\n}"},{"language":"bash","snippet":"link-cli auth status"},{"language":"bash","snippet":"link-cli auth login --client-name \"<your-agent-name>\""},{"language":"bash","snippet":"link-cli mpp decode --challenge '<raw WWW-Authenticate header>'"},{"language":"bash","snippet":"link-cli payment-methods list"},{"language":"bash","snippet":"link-cli shipping-address list"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nversion: 0.6.0\nname: create-payment-credential\ndescription: |\n  Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says \"get me a card\", \"buy something\", \"pay for X\", \"make a purchase\", \"I need to pay\", \"complete checkout\", or asks to transact on any merchant site. Use when the user asks to connect or log in to or sign up for their Link account.\nallowed-tools:\n - Bash(link-cli:*)\n - Bash(npx:*)\n - Bash(npm:*)\nlicense: Complete terms in LICENSE\nmetadata:\n  author: stripe\n  url: link.com/agents\n  openclaw:\n    emoji: \"💳\"\n    homepage: https://link.com/agents\n    requires:\n      bins:\n        - link-cli\n    install:\n      - kind: node\n        package: \"@stripe/link-cli\"\n        bins: [link-cli]\nuser-invocable: true\n---\n\n# Create Payment Credential\n\nUse [Link](https://link.com) to get secure, one-time-use payment credentials from a Link wallet to complete purchases.\n\nThe CLI can produce one of two credential types:\n- A virtual card (PAN) for use with a standard web checkout form. The issued card works anywhere.\n- A Shared Payment Token (SPT) when the seller is in the Stripe Network and accepts payments programmatically (for example with Machine Payment Protocols).\n\n## Installing\n\nInstall with `npm install -g @stripe/link-cli`. Or run directly with `npx @stripe/link-cli`.\n\n## Running commands\n\nLink CLI can run as an **MCP server** or as a **standalone CLI**.\n\n**MCP:** Add the following to your MCP client config (`.mcp.json`, etc.)\n\n```json\n{\n  \"mcpServers\": {\n    \"link\": {\n      \"command\": \"npx\",\n      \"args\": [\"@stripe/link-cli\", \"--mcp\"]\n    }\n  }\n}\n```\n\nRun the MCP server directly with `npx @stripe/link-cli@latest --mcp`.\n\nCall `tools/list` to see all available MCP tools.\n\n### Common commands/options\n\n- List all commands: `link-cli --llms`\n- List all commands with parameters: `link-cli --llms-full`\n- Get a command's exact schema with `--schema`. For example, `link-cli spend-request create --schema`\n- Multi-step commands return a `_next` action. For example, authenticating or creating a spend request returns a `_next.command` that must be run to complete the flow.\n- By default all output is in `toon` format. Pass `--format [json|md|yaml]` to change output format.\n- Some commands return a verification or approval URL. **These** must be presented to the user clearly for their action.\n- `--auth <path>` flag to store auth credentials in a specific file instead of the default location. `auth login` writes to this file; all other commands read from it. Example: `link-cli auth login --auth credentials.json`\n\n_Recommended_: Run `link-cli --llms` to understand all the available commands. The `--llms-full` output is the canonical reference for parameter names, types, and valid values. Pass `--schema` before invoking a command to understand its parameters and constraints.\n\n## Core flow\n\nCopy this checklist and track progress:\n\n- Step 1: Authenticate with L"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn70d9rxm3564f99rv3gg4z2e985z4n5\",\n  \"slug\": \"create-payment-credential\",\n  \"version\": \"0.6.0\",\n  \"publishedAt\": 1779999393614\n}"},{"path":"skill-card.md","content":"## Description:\n\nGets secure, one-time-use payment credentials such as cards and tokens from a Link wallet so agents can complete purchases on behalf of users.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[danhill-stripe](https://clawhub.ai/user/danhill-stripe)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users and agent developers use this skill when an agent needs to authenticate with Link, evaluate a merchant checkout, create a user-approved spend request, and retrieve the correct one-time payment credential for a purchase.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can enable real payment actions and handles payment credentials, payment methods, and shipping addresses.\n\nMitigation: Require explicit user confirmation before merchant, amount, item, payment method, shipping address, or domain changes; mask sensitive values unless the user directly requests disclosure.\n\nRisk: The skill relies on broad package execution and mutable CLI installation paths.\n\nMitigation: Prefer a pinned and reviewed @stripe/link-cli version, avoid global installs where possible, and review the CLI before enabling it for agent use.\n\nRisk: Persistent authentication files and retrieved card/SPT data could leak through shared workspaces, transcripts, or logs.\n\nMitigation: Store auth files outside shared workspaces with restricted permissions and use output-file handling for credential retrieval so stdout remains redacted.\n\n## Reference(s):\n\n- [Create Payment Credential on ClawHub](https://clawhub.ai/danhill-stripe/skills/create-payment-credential)\n- [Link Agents](https://link.com/agents)\n- [Link](https://link.com)\n- [MPP/x402 Protocol](https://mpp.dev/protocol.md)\n- [MPP HTTP 402 Protocol](https://mpp.dev/protocol/http-402.md)\n- [MPP Challenges](https://mpp.dev/protocol/challenges.md)\n- [Link App](https://app.link.com)\n- [Link Support](https://support.link.com/topics/about-link)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, JSON, Text]\n\n**Output Format:** [Markdown guidance with inline shell commands, JSON/MCP configuration snippets, and CLI output references]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [CLI output may be toon, JSON, Markdown, YAML, or local files; sensitive payment credentials should be redacted in stdout or written to restricted-permission files.]\n\n## Skill Version(s):\n\n0.6.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says... Skill: Create Payment Credential Owner: danhill-stripe Summary: Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says... Tags: latest:0.6.0 Version history: v0.6.0 | 2026-05-28T20:16:33.614Z | auto - Added detailed instructions for inline polling in the authentication flow (auth login --interval and --timeout usage)","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1422,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T15:36:10.042Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T15:36:10.042Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:42:38.346Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}