{"id":"099ef0c2-50bc-485e-bbf2-71d1457cfe41","entityType":"agent","slug":"clawhub-skills-actuallymentor-tpn-proxy","name":"tpn-proxy","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-actuallymentor-tpn-proxy","canonicalPath":"/agent/clawhub-skills-actuallymentor-tpn-proxy","generatedAt":"2026-10-09T18:38:56.732Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Make web requests through decentralized SOCKS5 proxies via the Tao Private Network (TPN). This skill is also known as \"TPN\", \"TPN proxy\", \"subnet 65\", or \"SN65\" — if the user asks to \"run TPN\", \"use a proxy\", \"use TPN to open\", or references \"subnet 65\", this is the skill they mean. Use when the user wants to route HTTP traffic through a proxy, make anonymous web requests, access geo-restricted content, use a decentralized VPN, fetch a URL through a SOCKS5 proxy, or needs residential proxy IPs. Supports both centralised API key authentication and decentralised x402 micropayments. --- name: tpn-proxy aliases: [tpn, subnet-65, sn65, proxy, socks5] description: Make web requests through decentralized SOCKS5 proxies via the Tao Private Network (TPN). This skill is also known as \"TPN\", \"TPN proxy\", \"subnet 65\", or \"SN65\" — if the user asks to \"run TPN\", \"use a proxy\", \"use TPN to open\", or references \"subnet 65\", this is the skill they mean. Use when the user wants to route HTTP traffic through a","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:actuallymentor:tpn-proxy","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/actuallymentor/tpn-proxy","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/actuallymentor/tpn-proxy","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Make web requests through decentralized SOCKS5 proxies via the Tao Private Network (TPN). This skill is also known as \"TPN\", \"TPN proxy\", \"subnet 65\", or \"SN65\""},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"do","status":"self-declared"},{"label":"run","status":"self-declared"},{"label":"pay","status":"self-declared"},{"label":"immediately","status":"self-declared"},{"label":"buy","status":"self-declared"},{"label":"generate","status":"self-declared"},{"label":"x402","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":8,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"do","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"run","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"pay","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"immediately","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"buy","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"generate","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"x402","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:do|supported|profile capability:run|supported|profile capability:pay|supported|profile capability:immediately|supported|profile capability:buy|supported|profile capability:generate|supported|profile capability:x402|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T05:55:37.797Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T05:55:37.797Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T05:55:37.797Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:actuallymentor:tpn-proxy","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T18:38:56.731Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-actuallymentor-tpn-proxy/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\nname: tpn-proxy\naliases: [tpn, subnet-65, sn65, proxy, socks5]\ndescription: Make web requests through decentralized SOCKS5 proxies via the Tao Private Network (TPN). This skill is also known as \"TPN\", \"TPN proxy\", \"subnet 65\", or \"SN65\" — if the user asks to \"run TPN\", \"use a proxy\", \"use TPN to open\", or references \"subnet 65\", this is the skill they mean. Use when the user wants to route HTTP traffic through a proxy, make anonymous web requests, access geo-restricted content, use a decentralized VPN, fetch a URL through a SOCKS5 proxy, or needs residential proxy IPs. Supports both centralised API key authentication and decentralised x402 micropayments.\nmetadata: { \"openclaw\": { \"emoji\": \"📡\", \"requires\": { \"bins\": [\"curl\"], \"env\": [\"TPN_API_KEY\"] }, \"primaryEnv\": \"TPN_API_KEY\" } }\n---\n\n# TPN Decentralized SOCKS5 Proxy\n\nRoute web traffic through Tao Private Network's decentralized SOCKS5 proxies — a Bittensor subnet (SN65) with commercial and residential exit nodes across 80+ countries.\n\nAsk this skill things like:\n\n- Open https://ipv4.icanhazip.com through a proxy in Germany\n- Show me a curl command that proxies google.com through a US ip address\n- I need a socks5 proxy in Japan for 30 minutes\n- Which countries are available on TPN for proxies?\n\n---\n\n## Security Posture\n\n| Aspect | Detail |\n|--------|--------|\n| Environment variables | `TPN_API_KEY` — existence-checked only (`[ -n \"$TPN_API_KEY\" ]`), never echoed or logged |\n| Files read/written | None |\n| Other secrets accessed | None — no signing keys, no credentials beyond `TPN_API_KEY` |\n| Network destinations | `api.taoprivatenetwork.com` (API calls) + user-specified URLs (validated per Step 5) |\n| x402 signing | Handled entirely by external libraries (`@x402/*`); this skill provides endpoint URLs only |\n\n---\n\n## This is an action skill\n\nThis skill executes API calls and returns results directly — it does not output documentation or instructions for the user to follow.\n\n**Expected behaviour:**\n\n- Call the TPN API yourself (via `curl` or equivalent) and return the full proxy credentials to the user.\n- When the user asks you to fetch a URL through a proxy, make that request yourself too.\n- Show the full SOCKS5 credentials (username, password, host, port) — these are short-lived and scoped to the proxy lease.\n- The only time you should show the user how to call the API is when they explicitly ask \"how do I do this myself?\" or similar.\n- If no API key exists, guide the user through account setup — that's the one step only they can do.\n\n**A good check:** if your response contains \"you can run this command to…\" or \"use this curl to generate…\", reconsider — the user invoked this skill expecting you to run the command and hand them the output.\n\n---\n\n## Step-by-Step Procedure\n\nFollow this procedure every time the user requests a proxy or asks you to fetch something through a proxy.\n\n### Security: Input validation (mandatory)\n\nBefore constructing any shell command, **validate every user-provided value**. Never interpolate raw user input into shell commands.\n\n| Input              | Validation rule                                                                                     |\n|--------------------|------------------------------------------------------------------------------------------------------|\n| `geo`              | Must be exactly 2 uppercase ASCII letters (ISO 3166-1 alpha-2). Reject anything else.                |\n| `minutes`          | Must be a positive integer between 1 and 1440. Reject non-numeric or out-of-range values.            |\n| `connection_type`  | Must be one of: `any`, `datacenter`, `residential`. Reject anything else.                            |\n| `format`           | Must be one of: `text`, `json`. Reject anything else.                                                |\n| URLs (for Step 5)  | Must start with `http://` or `https://`, contain no shell metacharacters (`` ` `` `$` `(` `)` `;` `&` `|` `<` `>` `\\n`), and be a well-formed URL. |\n\n**Rules:**\n\n- **Never** interpolate raw user input directly into shell commands. Always validate first.\n- **Never** construct `-d` JSON payloads via string concatenation with user input. Use a safe static template and only insert validated values.\n- When using `curl`, always **quote** the URL and proxy URI arguments.\n- Prefer using the agent's built-in HTTP tools (e.g. `WebFetch`) for fetching user-specified URLs rather than constructing `curl` commands.\n\n### Step 1: Resolve the API key\n\nCheck whether `$TPN_API_KEY` is set in the environment (OpenClaw injects this automatically from your config):\n\n1. Test the variable: `[ -n \"$TPN_API_KEY\" ] && echo \"API key is set\" || echo \"API key is not set\"` — **never** echo, log, or display the key value itself.\n2. If not set → check if the user can pay via [x402](https://www.x402.org) (no API key needed), otherwise guide them through account setup (see the \"Set up TPN\" example)\n\n### Step 2: Choose response format\n\n| Situation | Use `format` | Why |\n|-----------|--------------|-----|\n| Just need a working proxy URI | `text` (default) | No parsing needed |\n| Need to show structured host/port/user/pass breakdown | `json` | Gives individual fields |\n| Not sure | `text` | Simpler, fewer things to break |\n\nIf you choose `json`, parse the response with `jq`:\n\n```bash\ncurl -s ... | jq -r '.vpnConfig.username'\n```\n\nIf `jq` is not available, use `format=text` instead — it returns a plain `socks5://` URI that needs no parsing.\n\n> **Do not** use `python -c`, `grep`, `cut`, or other shell-based JSON parsing fallbacks. These patterns risk shell injection when combined with dynamic inputs. Stick to `jq` or `format=text`.\n\n### Step 3: Generate the proxy\n\n```bash\ncurl -s -X POST https://api.taoprivatenetwork.com/api/v1/proxy/generate \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $TPN_API_KEY\" \\\n  -d '{\"minutes\": 60, \"format\": \"text\", \"connection_type\": \"any\"}'\n```\n\nMap the user's request to these parameters:\n\n| Field             | Type    | Required | Default | Description                                    |\n|-------------------|---------|----------|---------|------------------------------------------------|\n| `minutes`         | integer | yes      | —       | Lease duration (1–1440). Default to 60 if not specified. |\n| `geo`             | string  | no       | any     | ISO country code (e.g. `\"US\"`, `\"DE\"`, `\"JP\"`) |\n| `format`          | string  | no       | `text`  | `\"text\"` for URI string, `\"json\"` for object   |\n| `connection_type` | string  | no       | `any`   | `\"any\"`, `\"datacenter\"`, or `\"residential\"`    |\n\n> **Safe JSON body construction:** Always build the `-d` JSON payload as a static single-quoted string with only validated values inserted. Validate `geo` (2 uppercase letters), `minutes` (integer 1–1440), `connection_type` (enum), and `format` (enum) per the validation rules above **before** constructing the curl command. Never concatenate raw user input into the JSON body or any part of the command.\n\n### Step 4: Present the result\n\nShow the **full proxy credentials** so the user can immediately connect. These are temporary (scoped to the lease duration) and safe to display in context. Use the `socks5h://` scheme (with `h`) to ensure DNS resolves through the proxy — this protects user DNS privacy. (When the agent fetches URLs in Step 5, it uses `socks5://` instead — see Step 5.) Include:\n\n- Structured config block (host, port, username, password, scheme, expiry)\n- Full `socks5h://` URI\n- A ready-to-paste `curl` example when relevant\n\n### Step 5: If the user asked you to fetch a URL\n\nAfter generating the proxy, make the request yourself. Use `socks5://` (not `socks5h://`) so DNS resolves locally — the validated IP is the connected IP.\n\n**Use the agent's built-in HTTP tools** (e.g. `WebFetch`) to fetch the URL through the proxy. This is the preferred method — it avoids shell command construction entirely.\n\n**URL validation — every check must pass before fetching:**\n\n1. Scheme must be `http://` or `https://`\n2. No shell metacharacters: `` ` `` `$` `(` `)` `;` `&` `|` `<` `>` newlines\n3. Domain names only — reject raw IP addresses (IPv4 or IPv6)\n4. Reject internal hostnames: `*.internal`, `*.local`, `*.localhost`, `*.localdomain`, `*.corp`, `*.lan`, `metadata.*`, single-label hostnames\n5. Hostname must resolve via local DNS — reject unresolvable hostnames\n6. Resolved IP must be publicly routable — reject `127.0.0.0/8`, `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`, `169.254.0.0/16`, `::1`, `fd00::/8`, `169.254.169.254`\n\n**Fallback — curl** (only if WebFetch is unavailable). Always double-quote the URL and proxy URI:\n\n```bash\ncurl --proxy \"socks5://username:password@ip:port\" \\\n  --connect-timeout 10 --max-time 30 \\\n  \"https://validated-target-url.com\"\n```\n\nReturn the response content to the user — the goal is a complete answer, not a proxy they still need to use themselves.\n\n---\n\n## Examples\n\nThese show exactly what users ask and what you should respond. Study these — they are the gold standard.\n\n---\n\n**User:** \"Give me a socks5 config for Belgium\"\n\n**You:** *(generate a BE proxy yourself, then respond:)*\n\n> Here's your Belgian SOCKS5 proxy (valid 60 minutes):\n>\n> ```\n> Host:     185.42.170.3\n> Port:     1080\n> Username: u_0CKaBqdE\n> Password: p_sT6yM3zabqRuhqrahzGOl4i4RTEDgQ7V\n> Scheme:   socks5h\n> Expires:  2026-02-16T15:30:00Z\n> ```\n>\n> **Full URI:** `socks5h://u_0CKaBqdE:p_sT6yM3zabqRuhqrahzGOl4i4RTEDgQ7V@185.42.170.3:1080`\n>\n> **curl example:**\n>\n> ```bash\n> curl --proxy socks5h://u_0CKaBqdE:p_sT6yM3zabqRuhqrahzGOl4i4RTEDgQ7V@185.42.170.3:1080 \\\n>   --connect-timeout 10 --max-time 30 \\\n>   https://ipv4.icanhazip.com\n> ```\n>\n> This should return a Belgian IP. The proxy expires in 60 minutes — let me know if you need a longer lease.\n\n---\n\n**User:** \"Show me a curl command that proxies over Germany\"\n\n**You:** *(generate a DE proxy yourself, then respond:)*\n\n> Here's a curl command routed through a German proxy:\n>\n> ```bash\n> curl --proxy socks5h://u_0E4k7kJ6:p_z2HsXTEXJHYiobwCcfOaU1YMS1tg3m0i@5.39.255.64:1080 \\\n>   --connect-timeout 10 --max-time 30 \\\n>   https://example.com\n> ```\n>\n> Replace `https://example.com` with your target URL. This proxy expires at 2026-02-16T14:47:20Z.\n\n---\n\n**User:** \"Call icanhazip.com from the Netherlands\"\n\n**You:** *(generate an NL proxy yourself, fetch icanhazip.com through it, then respond:)*\n\n> I fetched `https://ipv4.icanhazip.com` through a Dutch proxy. The response:\n>\n> ```\n> 82.148.30.91\n> ```\n>\n> That's the exit IP in the Netherlands. The proxy is still active until 2026-02-16T15:12:00Z if you need more requests.\n\n---\n\n**User:** \"I need a residential US proxy for 2 hours\"\n\n**You:** *(generate a US residential proxy with minutes=120, then respond:)*\n\n> Here's your US residential proxy (valid 2 hours, 25 credits):\n>\n> ```\n> Host:     68.210.185.149\n> Port:     1080\n> Username: u_02NyffuT\n> Password: p_CIYLqgIyLZ1rSvZGQbdh3lyxQQBcBsQn\n> Scheme:   socks5h\n> Type:     residential\n> Expires:  2026-02-16T16:41:00Z\n> ```\n>\n> **Full URI:** `socks5h://u_02NyffuT:p_CIYLqgIyLZ1rSvZGQbdh3lyxQQBcBsQn@68.210.185.149:1080`\n>\n> Residential IPs are less likely to be blocked. Let me know if you need a different country.\n\n---\n\n**User:** \"How many credits do I have left?\"\n\n**You:** *(call `GET /api/v1/user/balance` yourself, then respond:)*\n\n> You have **74 credits** remaining.\n>\n> For reference, a 60-minute proxy costs 20 credits and a 10-minute proxy costs 10 credits. You can buy more at https://api.taoprivatenetwork.com — packages start at 1,000 credits for $9.99.\n\n---\n\n**User:** \"Use a proxy to check if my site looks right from Germany\"\n\n**You:** *(generate a DE proxy, fetch their site through it, then respond:)*\n\n> I fetched your site through a German proxy (IP: `91.203.50.12`):\n>\n> - **Status:** 200 OK\n> - **Content-Language:** `de` — looks like your site detected the German IP and served the German version\n> - **Page title:** \"Willkommen bei Example\"\n>\n> Everything seems to be working correctly for German visitors. Want me to check from another country?\n\n---\n\n**User:** \"Set up TPN\" / \"How do I get started with TPN?\"\n\n**You:** *(check if a key already exists — if yes, tell them they're set up; if no:)*\n\n> To get started with TPN:\n>\n> 1. Go to https://api.taoprivatenetwork.com and create an account\n> 2. From the dashboard, create an API key (it'll look like `tpn-abc123...`)\n> 3. Your first key comes with **100 free credits** — enough for about 5 one-hour proxies\n>\n> Once you have the key, share it with me and I'll save it for future sessions. Then I can generate proxies for you anytime.\n\n---\n\nThe pattern: **the user asks, you act, you return results.** You never tell the user how to call the API — you call it yourself and hand them the output.\n\n---\n\n## API Reference\n\n**Base URL:** `https://api.taoprivatenetwork.com`\n\n**Authentication:** Pass `X-API-Key: <your-key>` as a request header. Not `Authorization: Bearer`.\n\n### Endpoints\n\n| Method | Path                          | Auth       | Description                     |\n|--------|-------------------------------|------------|---------------------------------|\n| POST   | `/api/v1/proxy/generate`      | API key    | Generate SOCKS5 proxy           |\n| POST   | `/api/v1/vpn/generate`        | API key    | Generate WireGuard VPN          |\n| GET    | `/api/v1/user/balance`        | API key    | Check credit balance            |\n| GET    | `/api/v1/vpn/countries`       | none       | List available countries        |\n| POST   | `/api/v1/vpn/cost`            | none       | Calculate credit cost           |\n| GET    | `/api/v1/vpn/stats`           | none       | Network statistics              |\n| GET    | `/api/v1/health`              | none       | Health check                    |\n| POST   | `/api/v1/x402/proxy/generate` | x402       | Generate SOCKS5 proxy (x402)    |\n| POST   | `/api/v1/x402/vpn/generate`   | x402       | Generate WireGuard VPN (x402)   |\n\n### Response shapes\n\n**`/proxy/generate` with `format=text`:**\n\n```json\n{\n  \"success\": true,\n  \"vpnConfig\": \"socks5://u_02NyffuT:p_CIYLqgIyLZ1rSvZGQbdh3lyxQQBcBsQn@9.160.73.2:1080\",\n  \"minutes\": 60,\n  \"expiresAt\": \"2026-02-14T19:08:25.690Z\",\n  \"creditsUsed\": 20,\n  \"type\": \"socks5\"\n}\n```\n\n**`/proxy/generate` with `format=json`:**\n\n```json\n{\n  \"success\": true,\n  \"vpnConfig\": {\n    \"username\": \"u_0CKaBqdE\",\n    \"password\": \"p_sT6yM3zabqRuhqrahzGOl4i4RTEDgQ7V\",\n    \"ip_address\": \"68.210.185.149\",\n    \"port\": 1080\n  },\n  \"minutes\": 60,\n  \"expiresAt\": \"2026-02-14T19:08:23.958Z\",\n  \"creditsUsed\": 20,\n  \"usedFallback\": false,\n  \"type\": \"socks5\",\n  \"connection_type\": \"any\"\n}\n```\n\n### `/vpn/countries` query parameters\n\n| Param             | Type   | Default | Description                                      |\n|-------------------|--------|---------|--------------------------------------------------|\n| `format`          | string | `json`  | `\"json\"` for array, `\"text\"` for newline-separated |\n| `type`            | string | `code`  | `\"code\"` for ISO codes, `\"name\"` for full names   |\n| `connection_type` | string | `any`   | `\"any\"`, `\"datacenter\"`, or `\"residential\"`       |\n\n### Using the proxy (for user-facing code examples)\n\nOnly show these if the user explicitly asks \"how do I use this in my code?\" — otherwise just hand them the config.\n\n> **User-facing code should always use `socks5h://`** (with `h`) to resolve DNS through the proxy, preserving DNS privacy. (The agent uses `socks5://` for its own fetching in Step 5, where local DNS resolution is a security feature — see Step 5.)\n\n> If proxy credentials contain special characters (`@`, `:`, `/`, `#`, `?`), percent-encode them (e.g. `p@ss` → `p%40ss`).\n\n**curl:**\n\n```bash\ncurl --proxy socks5h://username:password@ip_address:port \\\n  --connect-timeout 10 --max-time 30 \\\n  https://ipv4.icanhazip.com\n```\n\n**Node.js:**\n\n```js\nimport { SocksProxyAgent } from 'socks-proxy-agent'\nimport fetch from 'node-fetch'\n\nconst agent = new SocksProxyAgent( 'socks5h://username:password@ip_address:1080' )\nconst controller = new AbortController()\nconst timeout = setTimeout( () => controller.abort(), 30_000 )\n\nconst response = await fetch( 'https://ipv4.icanhazip.com', { agent, signal: controller.signal } )\nclearTimeout( timeout )\nconsole.log( await response.text() )\n```\n\n**Python:**\n\n```python\nimport requests\n\nproxies = {\n    'http': 'socks5h://username:password@ip_address:1080',\n    'https': 'socks5h://username:password@ip_address:1080'\n}\n\nresponse = requests.get( 'https://ipv4.icanhazip.com', proxies=proxies, timeout=( 10, 30 ) )\nprint( response.text )\n```\n\nSee `{baseDir}/references/api-examples.md` for end-to-end examples (generate + use) in curl, JS, Node.js, and Python.\n\n---\n\n## Credit Costs\n\nFormula: `credits = ceil( 4.1 × minutes ^ 0.375 )`\n\n| Duration | Credits |\n|----------|---------|\n| 1 min    | 5       |\n| 5 min    | 8       |\n| 10 min   | 10      |\n| 30 min   | 15      |\n| 60 min   | 20      |\n| 120 min  | 25      |\n| 720 min  | 49      |\n| 1440 min | 63      |\n\nUse `POST /api/v1/vpn/cost` with `{\"minutes\": N}` to calculate before purchasing.\n\nCredit packages: Starter 1,000/$9.99 · Pro 5,000/$49.99 · Premium 20,000/$199.99\n\n---\n\n## Troubleshooting & Operational Notes\n\n| Problem                   | Solution                                                       |\n|---------------------------|----------------------------------------------------------------|\n| `401 Unauthorized`        | Verify API key is valid — use `X-API-Key` header, not Bearer   |\n| `402 Payment Required`    | Insufficient credits — buy more or use the x402 flow           |\n| `503 Service Unavailable` | No miners available — credits are refunded, retry later        |\n| Connection timeout        | Proxy lease may have expired — generate a new one              |\n| DNS not resolving (user)  | Use `socks5h://` (with `h`) for remote DNS resolution          |\n| DNS not resolving (agent) | Agent uses `socks5://` — verify local DNS resolution in check 5 |\n\n**Operational rules:**\n\n- User-facing credentials and code examples: always use `socks5h://` for DNS privacy\n- Agent-side fetching (Step 5): always use `socks5://` so local DNS validation is authoritative\n- Check credit balance with `GET /api/v1/user/balance` before generating proxies in bulk\n- Proxy leases expire at `expiresAt` — never cache or reuse credentials beyond that time\n- If a `503` occurs, credits are refunded automatically — retry after a short delay\n\n---\n\n## x402 Payment Flow (Advanced)\n\nThe [x402 protocol](https://www.x402.org) enables pay-per-request access using USDC on Base. No account or API key needed — ideal for autonomous agents that already support x402.\n\nIf you are an x402-capable agent, you already know how to handle the payment handshake. The TPN x402 endpoints follow the standard protocol:\n\n1. `POST /api/v1/x402/proxy/generate` — returns `HTTP 402` with a standard `payment-required` header\n2. Complete the x402 payment flow per the [protocol specification](https://www.x402.org)\n3. Retry with the payment header to receive SOCKS5 credentials\n\nSame request body as the centralised endpoint. No `X-API-Key` needed.\n\nSee `{baseDir}/references/x402-examples.md` for curl and browser JS examples, and the [x402 spec](https://www.x402.org) for full protocol details. Signing is handled entirely by external libraries — this skill provides endpoint URLs only.\n\n---\n\n## Links\n\n- Dashboard & Account: https://api.taoprivatenetwork.com\n- API Docs: https://api.taoprivatenetwork.com/docs/getting-started/\n- Swagger UI: https://api.taoprivatenetwork.com/api-docs/\n- OpenAPI Spec: https://api.taoprivatenetwork.com/api-docs/openapi.json\n- LLM-friendly docs: https://api.taoprivatenetwork.com/docs/llms-full.txt\n- x402 Protocol: https://www.x402.org\n","readmeExcerpt":"--- name: tpn-proxy aliases: [tpn, subnet-65, sn65, proxy, socks5] description: Make web requests through decentralized SOCKS5 proxies via the Tao Private Network (TPN). This skill is also known as \"TPN\", \"TPN proxy\", \"subnet 65\", or \"SN65\" — if the user asks to \"run TPN\", \"use a proxy\", \"use TPN to open\", or references \"subnet 65\", this is the skill they mean. Use when the user wants to route HTTP traffic through a ","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"curl -s ... | jq -r '.vpnConfig.username'"},{"language":"bash","snippet":"curl -s ... | jq -r '.vpnConfig.username'"},{"language":"bash","snippet":"curl -s -X POST https://api.taoprivatenetwork.com/api/v1/proxy/generate \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $TPN_API_KEY\" \\\n  -d '{\"minutes\": 60, \"format\": \"text\", \"connection_type\": \"any\"}'"},{"language":"bash","snippet":"curl -s -X POST https://api.taoprivatenetwork.com/api/v1/proxy/generate \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $TPN_API_KEY\" \\\n  -d '{\"minutes\": 60, \"format\": \"text\", \"connection_type\": \"any\"}'"},{"language":"bash","snippet":"curl --proxy \"socks5://username:password@ip:port\" \\\n  --connect-timeout 10 --max-time 30 \\"},{"language":"bash","snippet":"curl --proxy \"socks5://username:password@ip:port\" \\\n  --connect-timeout 10 --max-time 30 \\\n  \"https://validated-target-url.com\""}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Make web requests through decentralized SOCKS5 proxies via the Tao Private Network (TPN). This skill is also known as \"TPN\", \"TPN proxy\", \"subnet 65\", or \"SN65\" — if the user asks to \"run TPN\", \"use a proxy\", \"use TPN to open\", or references \"subnet 65\", this is the skill they mean. Use when the user wants to route HTTP traffic through a proxy, make anonymous web requests, access geo-restricted content, use a decentralized VPN, fetch a URL through a SOCKS5 proxy, or needs residential proxy IPs. Supports both centralised API key authentication and decentralised x402 micropayments. --- name: tpn-proxy aliases: [tpn, subnet-65, sn65, proxy, socks5] description: Make web requests through decentralized SOCKS5 proxies via the Tao Private Network (TPN). This skill is also known as \"TPN\", \"TPN proxy\", \"subnet 65\", or \"SN65\" — if the user asks to \"run TPN\", \"use a proxy\", \"use TPN to open\", or references \"subnet 65\", this is the skill they mean. Use when the user wants to route HTTP traffic through a","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":464,"uniquenessScore":57,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T18:38:56.732Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}