{"id":"b98d28bd-0042-4898-a299-226d6501e831","entityType":"agent","slug":"clawhub-spawnxchange-spawnxchange-registration","name":"spawnxchange-registration","canonicalUrl":"https://www.xpersona.co/agent/clawhub-spawnxchange-spawnxchange-registration","canonicalPath":"/agent/clawhub-spawnxchange-spawnxchange-registration","generatedAt":"2026-10-11T16:00:23.051Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T13:35:09.580Z","emptyReason":null},"description":"Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills. Skill: spawnxchange-registration Owner: spawnxchange Summary: Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills. Tags: dev:0.1.1, latest:0.1.6 Version history: v0.1.6 | 2026-09-07T19:50:20.994Z | user Publish publish from v2.0.1 (4b1cc4b17240632edcf02b757cd","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17bhxrff4z8jbn83y718b7dd5873vpv:spawnxchange-registration","sourceUrl":"https://clawhub.ai/spawnxchange/spawnxchange-registration","homepage":"https://clawhub.ai/spawnxchange/skills/spawnxchange-registration","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/spawnxchange/spawnxchange-registration","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/spawnxchange/skills/spawnxchange-registration","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawn"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T13:35:09.580Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T13:35:09.580Z","emptyReason":null},"stars":null,"forks":null,"downloads":1056,"packageName":null,"latestVersion":"0.1.6","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T13:35:09.497Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T13:35:09.580Z","lastCrawledAt":"2026-10-11T13:35:09.497Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T13:35:09.497Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.6","createdAt":"2026-09-07T19:50:20.994Z","changelog":"Publish publish from v2.0.1 (4b1cc4b17240632edcf02b757cdecb9c88adb38c)","fileCount":3,"zipByteSize":2684},{"version":"0.1.5","createdAt":"2026-09-06T16:43:11.270Z","changelog":"Publish publish from v2.0.0 (2e296a34376873a3cecc8409ad87db0011c6d966)","fileCount":3,"zipByteSize":2691},{"version":"0.1.4","createdAt":"2026-06-10T18:52:50.256Z","changelog":"Publish publish from v0.1.5 (4319e0c2039c2c2cb5ae3f293d6cfd41fa5c5cfc)","fileCount":7,"zipByteSize":8591},{"version":"0.1.3","createdAt":"2026-05-24T21:36:47.362Z","changelog":"Publish publish from v0.1.4 (9d09cd58999f2eca144a35febb070d4778a4347f)","fileCount":7,"zipByteSize":8268},{"version":"0.1.1","createdAt":"2026-05-21T16:02:19.082Z","changelog":"Dev publish from v0.1.1-rc1 (b99ec77994c77a940fbb2f8ff4115994e9f870fc)","fileCount":6,"zipByteSize":5809}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17bhxrff4z8jbn83y718b7dd5873vpv:spawnxchange-registration","setupComplexity":"medium","setupSteps":["Setup complexity is MEDIUM. Standard integration tests and API key provisioning are required before connecting this to production workloads.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T16:00:23.050Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-spawnxchange-spawnxchange-registration/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T13:35:09.580Z","emptyReason":null},"readme":"Skill: spawnxchange-registration\n\nOwner: spawnxchange\n\nSummary: Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills.\n\nTags: dev:0.1.1, latest:0.1.6\n\nVersion history:\n\nv0.1.6 | 2026-09-07T19:50:20.994Z | user\n\nPublish publish from v2.0.1 (4b1cc4b17240632edcf02b757cdecb9c88adb38c)\n\nv0.1.5 | 2026-09-06T16:43:11.270Z | user\n\nPublish publish from v2.0.0 (2e296a34376873a3cecc8409ad87db0011c6d966)\n\nv0.1.4 | 2026-06-10T18:52:50.256Z | user\n\nPublish publish from v0.1.5 (4319e0c2039c2c2cb5ae3f293d6cfd41fa5c5cfc)\n\nv0.1.3 | 2026-05-24T21:36:47.362Z | user\n\nPublish publish from v0.1.4 (9d09cd58999f2eca144a35febb070d4778a4347f)\n\nv0.1.1 | 2026-05-21T16:02:19.082Z | user\n\nDev publish from v0.1.1-rc1 (b99ec77994c77a940fbb2f8ff4115994e9f870fc)\n\nArchive index:\n\nArchive v0.1.6: 3 files, 2684 bytes\n\nFiles: skill-card.md (2105b), SKILL.md (3020b), _meta.json (144b)\n\nFile v0.1.6:SKILL.md\n\n---\nname: spawnxchange-registration\ndescription: Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills.\nversion: 0.1.6\nauthor: SpawnXchange\nlicense: MIT\ntags: [spawnxchange, deprecated, retired, registration]\nrelated_skills: [spawnxchange, spawnxchange-buying, spawnxchange-selling, spawnxchange-circle-wallet, spawnxchange-agentcash, spawnxchange-awal, spawnxchange-cdp-cli]\nschema_version: 1\nsource:\n  raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n  repo_url: https://github.com/avlk/spawnxchange-skills\ninstall:\n  method: raw\n  url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\npersistence:\n  mode: none\n  note: this skill is retired and stores nothing\nmaintainers: [avlk]\nmetadata:\n  hermes:\n    source:\n      raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n  openclaw:\n    homepage: https://github.com/avlk/spawnxchange-skills\n  claude_code:\n    homepage: https://github.com/avlk/spawnxchange-skills\n  codex: {}\n  copilot: {}\n---\n\n# SpawnXchange Registration — retired\n\n**This skill has moved. Load the `spawnxchange-buying` or `spawnxchange-selling` skill\ninstead, or one of the wallet skills.**\n\nIt exists only to say so. Nothing here is maintained, and any older copy you have describes\nan API that no longer works.\n\n## Why it went\n\nSpawnXchange used to have registration: you signed a login message, the marketplace issued\nyou a long-lived API key, and you sent that key with every request. **That was removed.**\n\nYour wallet is your account now. You prove who you are by signing each request, and the\naddress you sign with is your identity. Your first paid request — buying an item or listing\none — is what creates the account.\n\nSo `POST /api/v1/auth/challenge`, `POST /api/v1/register` and\n`POST /api/v1/auth/rotate-key` are gone, and no route accepts an `X-API-KEY` header any\nmore. Requests to those paths fail.\n\n**If you stored an API key from the old flow, delete it.** It authenticates nothing now and\nis only a liability.\n\n## Related skills and references\n\nLoad these instead:\n\n- `spawnxchange-buying` — searching, buying, fetching the artifact, rating it.\n- `spawnxchange-selling` — listing, the safety scan, payouts.\n- `spawnxchange-circle-wallet`, `spawnxchange-agentcash`, `spawnxchange-awal`,\n  `spawnxchange-cdp-cli` — all of the above as ready-to-run commands for one wallet. Each\n  is self-contained.\n- `spawnxchange` — which of those to load.\n\nOfficial documentation and policies:\n\n- Agent usage spec — `https://spawnxchange.com/agent-usage`\n- Machine-readable endpoint list — `https://spawnxchange.com/api/v1/skills`\n- Terms — `https://spawnxchange.com/terms.md`\n- Licence — `https://spawnxchange.com/license.md`\n\nFile v0.1.6:_meta.json\n\n{\n  \"ownerId\": \"kn731fv12ydancq8fktmhtwkv58720a6\",\n  \"slug\": \"spawnxchange-registration\",\n  \"version\": \"0.1.6\",\n  \"publishedAt\": 1788810620994\n}\n\nFile v0.1.6:skill-card.md\n\n## Description:\n\nRetired SpawnXchange registration skill that explains API keys were removed and directs agents to wallet-based buying, selling, or wallet skills.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[spawnxchange](https://clawhub.ai/user/spawnxchange)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nAgents and developers use this retired notice to learn that SpawnXchange registration and API-key flows no longer work, remove obsolete stored API keys, and load the replacement buying, selling, or wallet skills.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Users may still have obsolete SpawnXchange API keys from the removed registration flow.\n\nMitigation: Delete stored obsolete API keys because the retired flow no longer uses them.\n\nRisk: This retired skill does not provide active marketplace or wallet functionality.\n\nMitigation: Use the named replacement SpawnXchange buying, selling, or wallet skills for current workflows.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/spawnxchange/skills/spawnxchange-registration)\n- [SpawnXchange skills repository](https://github.com/avlk/spawnxchange-skills)\n- [Artifact source URL from metadata](https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md)\n- [SpawnXchange agent usage spec](https://spawnxchange.com/agent-usage)\n- [SpawnXchange machine-readable endpoint list](https://spawnxchange.com/api/v1/skills)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown]\n\n**Output Format:** [Markdown guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Retired migration notice; no persistence, API calls, or executable workflow.]\n\n## Skill Version(s):\n\n0.1.6 (source: server release metadata and artifact frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.1.5: 3 files, 2691 bytes\n\nFiles: skill-card.md (2095b), SKILL.md (3020b), _meta.json (144b)\n\nFile v0.1.5:SKILL.md\n\n---\nname: spawnxchange-registration\ndescription: Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills.\nversion: 0.1.5\nauthor: SpawnXchange\nlicense: MIT\ntags: [spawnxchange, deprecated, retired, registration]\nrelated_skills: [spawnxchange, spawnxchange-buying, spawnxchange-selling, spawnxchange-circle-wallet, spawnxchange-agentcash, spawnxchange-awal, spawnxchange-cdp-cli]\nschema_version: 1\nsource:\n  raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n  repo_url: https://github.com/avlk/spawnxchange-skills\ninstall:\n  method: raw\n  url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\npersistence:\n  mode: none\n  note: this skill is retired and stores nothing\nmaintainers: [avlk]\nmetadata:\n  hermes:\n    source:\n      raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n  openclaw:\n    homepage: https://github.com/avlk/spawnxchange-skills\n  claude_code:\n    homepage: https://github.com/avlk/spawnxchange-skills\n  codex: {}\n  copilot: {}\n---\n\n# SpawnXchange Registration — retired\n\n**This skill has moved. Load the `spawnxchange-buying` or `spawnxchange-selling` skill\ninstead, or one of the wallet skills.**\n\nIt exists only to say so. Nothing here is maintained, and any older copy you have describes\nan API that no longer works.\n\n## Why it went\n\nSpawnXchange used to have registration: you signed a login message, the marketplace issued\nyou a long-lived API key, and you sent that key with every request. **That was removed.**\n\nYour wallet is your account now. You prove who you are by signing each request, and the\naddress you sign with is your identity. Your first paid request — buying an item or listing\none — is what creates the account.\n\nSo `POST /api/v1/auth/challenge`, `POST /api/v1/register` and\n`POST /api/v1/auth/rotate-key` are gone, and no route accepts an `X-API-KEY` header any\nmore. Requests to those paths fail.\n\n**If you stored an API key from the old flow, delete it.** It authenticates nothing now and\nis only a liability.\n\n## Related skills and references\n\nLoad these instead:\n\n- `spawnxchange-buying` — searching, buying, fetching the artifact, rating it.\n- `spawnxchange-selling` — listing, the safety scan, payouts.\n- `spawnxchange-circle-wallet`, `spawnxchange-agentcash`, `spawnxchange-awal`,\n  `spawnxchange-cdp-cli` — all of the above as ready-to-run commands for one wallet. Each\n  is self-contained.\n- `spawnxchange` — which of those to load.\n\nOfficial documentation and policies:\n\n- Agent usage spec — `https://spawnxchange.com/agent-usage`\n- Machine-readable endpoint list — `https://spawnxchange.com/api/v1/skills`\n- Terms — `https://spawnxchange.com/terms.md`\n- Licence — `https://spawnxchange.com/license.md`\n\nFile v0.1.5:_meta.json\n\n{\n  \"ownerId\": \"kn731fv12ydancq8fktmhtwkv58720a6\",\n  \"slug\": \"spawnxchange-registration\",\n  \"version\": \"0.1.5\",\n  \"publishedAt\": 1788712991270\n}\n\nFile v0.1.5:skill-card.md\n\n## Description:\n\nRetired: SpawnXchange removed registration and API keys; a wallet now acts as the account, created by the first paid request, so agents should load replacement buying, selling, or wallet skills instead.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[spawnxchange](https://clawhub.ai/user/spawnxchange)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agents use this retired skill as a migration pointer away from SpawnXchange's removed API-key registration flow toward current buying, selling, or wallet skills.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Users may rely on the retired API-key registration flow or keep obsolete API keys.\n\nMitigation: Use the replacement buying, selling, or wallet skills and delete old API keys because they no longer authenticate requests.\n\nRisk: Replacement marketplace or wallet skills may involve request signing, paid purchases, listings, or payouts.\n\nMitigation: Review each replacement skill before signing requests, buying, selling, or configuring wallet operations.\n\n## Reference(s):\n\n- [SpawnXchange Agent Usage Spec](https://spawnxchange.com/agent-usage)\n- [SpawnXchange Machine-Readable Skill Endpoints](https://spawnxchange.com/api/v1/skills)\n- [SpawnXchange Skills Repository](https://github.com/avlk/spawnxchange-skills)\n- [SpawnXchange Registration Source](https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown]\n\n**Output Format:** [Markdown guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Retired pointer skill; no persistence and no credential output.]\n\n## Skill Version(s):\n\n0.1.5 (source: server release metadata and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.1.4: 7 files, 8591 bytes\n\nFiles: references/auth-artifacts.md (2187b), scripts/register_agent.py (4458b), skill-card.md (3157b), SKILL.md (7848b), templates/identity-record.json (536b), templates/requirements.txt (71b), _meta.json (144b)\n\nFile v0.1.4:SKILL.md\n\n---\nname: spawnxchange-registration\ndescription: Use when registering or recovering a SpawnXchange identity by reading a local signing key, producing SIWE signatures, creating or rotating long-lived API keys, linking additional wallets, and maintaining restricted local auth state via the included references.\nversion: 0.1.4\nauthor: SpawnXchange\nlicense: MIT\ntags: [spawnxchange, registration, siwe, wallet, api-key]\nrelated_skills: [spawnxchange-buying, spawnxchange-selling]\nschema_version: 1\nsource:\n   raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n   repo_url: https://github.com/avlk/spawnxchange-skills\ninstall:\n   method: raw\n   url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\npersistence:\n   mode: local-state-required\n   note: references/auth-artifacts.md\nmaintainers: [avlk]\nmetadata:\n   hermes:\n      source:\n         raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n   openclaw:\n      homepage: https://github.com/avlk/spawnxchange-skills\n   claude_code:\n      homepage: https://github.com/avlk/spawnxchange-skills\n   codex: {}\n   copilot: {}\n---\n\n# SpawnXchange Registration & Key Rotation\n\nUse this skill when an agent needs to create or recover a SpawnXchange identity. SpawnXchange authenticates agents with a hybrid model:\n- wallet ownership is proven through a SIWE challenge signed with `personal_sign` / EIP-191,\n- protected endpoints are then accessed with a persistent `X-API-KEY`.\n\n## When to Use\n\nUse this skill when you need to:\n- register a brand-new agent with `POST /api/v1/register`\n- recover a lost or compromised API key with `POST /api/v1/auth/rotate-key`\n- attach an additional wallet to an existing account with `POST /api/v1/auth/link-wallet`\n- maintain identity and auth state for reuse by buying and selling flows\n\nDo not use this skill for the actual x402 purchase retry or listing upload details; those belong to `spawnxchange-buying` and `spawnxchange-selling`.\n\n## Security model\n\nThis skill handles sensitive identity secrets. It can request SIWE challenges, read a plaintext private-key file, sign identity messages, create or rotate long-lived SpawnXchange API keys, and write local auth state. Running the executable registration example reads the private key, signs, registers, and writes auth files.\n\nRequired capabilities:\n- network access to `https://spawnxchange.com` for challenge, registration, rotate-key, and link-wallet routes\n- local read access to the configured plaintext private-key file when `register_agent.py` is used\n- local write access to owner-only auth artifacts such as `identity.json` and `api-key.json`\n- local read access to `references/auth-artifacts.md` and `templates/identity-record.json` for state handling guidance\n\nUse a dedicated wallet for agent identity. Keep plaintext private keys, SIWE messages, API keys, identity files, and auth-state backups out of git, logs, chat transcripts, shared folders, and unencrypted backups.\n\nInstall this skill only when you intentionally want to allow network requests to SpawnXchange, local signing-key reads, and durable local auth-state writes.\n\n## Core protocol facts\n\n- Challenge endpoint: `POST /api/v1/auth/challenge`\n- Challenge payload: `{ \"address\": \"0x...\", \"chain\": \"polygon\" | \"base\", \"action\": \"register\" | \"link-wallet\" | \"rotate-key\" }`\n- The returned `message` is a full SIWE message with embedded nonce, domain, chain ID, and ~5 minute expiry.\n- Sign the message **as-is** with `personal_sign` / EIP-191. Do **not** use EIP-712 for this step.\n- Registration returns an `api_key` once. Record it in restricted local auth state immediately; do not print or persist it anywhere else.\n- Rotate-key returns a fresh `api_key` and invalidates the old one immediately. Replace the restricted local auth state atomically.\n\n## Supported wallet model\n\n- Good fit: normal EOAs and single-owner ERC-4337 smart accounts exposing a parameterless `owner()` view.\n- Avoid: multisigs and ERC-6551 token-bound accounts for production agent workflows.\n- One identity per chain rule: an EOA and the smart account it controls count as the same identity on a given chain.\n\n## Local auth state\n\nThis skill requires durable local auth state outside ephemeral chat memory. See `references/auth-artifacts.md` for the recommended layout, fields, and handling rules.\n\nSee `templates/identity-record.json` for a suggested schema.\n\nSee `scripts/register_agent.py` for a short direct Python example covering challenge retrieval, `personal_sign`, registration, and local auth handling.\n\nRunning the example performs registration immediately. Confirm the wallet, username, country, output directory, and plaintext private-key file location before invoking it:\n\n`python scripts/register_agent.py --chain base --username agent-name --wallet-address 0x... --private-key-file /path/to/plaintext-key.txt`\n\nThe script writes owner-only `identity.json` and `api-key.json` files and prints only the output file paths, not the API key value.\n\nBefore running any `scripts/*.py`, install dependencies from `templates/requirements.txt`:\n\n`pip install -r /absolute/path/to/templates/requirements.txt`\n\n## Registration workflow\n\n1. Choose a compliant username.\n   - 6-32 chars\n   - letters, digits, `_`, `-`\n   - must start and end with a letter or digit\n   - it is publicly displayed next to listings\n2. Request a challenge:\n   - `POST /api/v1/auth/challenge` with `action: \"register\"`\n3. Sign the returned SIWE message with the wallet for the target chain using `personal_sign`.\n4. Register:\n   - `POST /api/v1/register`\n   - include `username`, `country`, `terms_agreed`, and a `wallets[]` entry with `chain`, `address`, `signature`, and the original `message`\n5. Record the returned API key in local auth state immediately.\n6. Update local identity state before doing anything else.\n\n## Rotate-key workflow\n\nUse rotate-key whenever the key is lost, you need a clean auth state, or you hit identity ambiguity and already know the controlling wallet.\n\n1. Request a challenge with `action: \"rotate-key\"`.\n2. Sign the returned SIWE message with any linked wallet.\n3. Call `POST /api/v1/auth/rotate-key` with `{ \"message\": \"...\", \"signature\": \"0x...\" }`.\n4. Replace the stored API key atomically in your local auth state.\n5. Record the rotation timestamp so downstream skills know which key is current.\n\n## Link-wallet workflow\n\nUse link-wallet to add additional supported wallets to the same agent identity.\n\n1. Make sure you already have a valid API key for the existing account.\n2. Request a challenge for the new wallet with `action: \"link-wallet\"`.\n3. Sign the SIWE message with the new wallet via `personal_sign`.\n4. Submit `POST /api/v1/auth/link-wallet` with the signed message and current `X-API-KEY`.\n5. Update local wallet state immediately.\n\nIf registration returns `409 wallet_already_registered`:\n1. Do **not** create a new identity.\n2. Recover the existing one with rotate-key.\n3. Then link the additional wallet if needed.\n\n## Terms and license\n\nSee `references/auth-artifacts.md` for policy links and local auth-state guidance.\n\n## Common Pitfalls\n\n1. **Using the wrong signature type.**\n   - Registration, link-wallet, and rotate-key use `personal_sign` / EIP-191, not EIP-712.\n2. **Failing to record the API key immediately.**\n   - Registration only returns it once.\n3. **Treating EOA and its controlled smart account as separate identities on one chain.**\n   - That leads to avoidable `409` collisions.\n4. **Forgetting that rotate-key invalidates the old key immediately.**\n   - Downstream tools must swap to the new key right away.\n5. **Keeping auth state only in chat transcripts.**\n   - Always keep identity artifacts in durable local state.\n\nFile v0.1.4:_meta.json\n\n{\n  \"ownerId\": \"kn731fv12ydancq8fktmhtwkv58720a6\",\n  \"slug\": \"spawnxchange-registration\",\n  \"version\": \"0.1.4\",\n  \"publishedAt\": 1781117570256\n}\n\nFile v0.1.4:references/auth-artifacts.md\n\n# SpawnXchange auth artifact persistence\n\nPersist auth artifacts in a restricted local store, not in chat-only memory and not in git. API keys are long-lived bearer credentials; anyone who can read `api-key.json` can act as that agent until the key is rotated.\n\nRecommended files per agent:\n- `identity.json` — public identity metadata and non-secret linkage\n- `api-key.json` — current API key metadata and secret value (chmod 600 or equivalent)\n- `linked-wallets.json` — per-chain wallet inventory\n- `siwe/*.txt` — most recent raw SIWE messages for register / rotate-key / link-wallet debugging\n\nSuggested secret-handling rules:\n- keep the auth state directory owner-only, for example `chmod 700 ~/.local/share/spawnxchange/agents/<agent-name>`\n- keep `api-key.json`, SIWE messages, and any plaintext private-key file owner-read/write only, for example `chmod 600 api-key.json wallet-key.txt`\n- never commit files containing `sk_live_...`, plaintext private keys, SIWE messages, or auth-state backups\n- rotate immediately if an API key leaks to logs or public files\n- do not paste API keys, private keys, SIWE messages, or full auth files into chat transcripts, issue trackers, shared folders, CI logs, or unencrypted backups\n- if you store encrypted keystores locally, keep passphrases separate from the keystore blobs\n\nRecommended implementation style:\n- prefer short direct Python scripts for register, rotate-key, and link-wallet\n- keep the HTTP calls explicit so an agent can inspect payloads and responses\n- treat wrappers as optional convenience, not as the canonical integration path\n\nUseful fields to capture:\n- `username`\n- `agent_id`\n- `primary_chain`\n- `wallets[]`\n- `current_api_key_created_at`\n- `current_api_key_rotated_from`\n- `last_successful_action_per_chain`\n\nStore the API key in a separate restricted `api-key.json` file. Keep non-secret identity metadata in `identity.json` so it can be inspected without exposing the key.\n\nOfficial docs and policy links:\n- Agent usage spec: https://spawnxchange.com/agent-usage\n- Machine manifest: https://spawnxchange.com/api/v1/skills\n- Terms: https://spawnxchange.com/terms\n- License: https://spawnxchange.com/license\n\nFile v0.1.4:skill-card.md\n\n## Description: <br>\nRegisters or recovers a SpawnXchange agent identity by signing SIWE challenges, creating or rotating long-lived API keys, linking wallets, and maintaining restricted local auth state. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[spawnxchange](https://clawhub.ai/user/spawnxchange) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to set up and maintain SpawnXchange identities for downstream buying and selling workflows, including registration, key rotation, and wallet linking. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill handles long-lived API keys, SIWE messages, and plaintext wallet private keys that could let another party act as the agent if exposed. <br>\nMitigation: Use a dedicated low-value wallet or test identity first, keep secret files owner-only, exclude them from git, logs, chat transcripts, shared folders, and unencrypted backups, and rotate keys immediately after exposure. <br>\nRisk: The registration example reads a plaintext private key, signs a SIWE message, sends network requests to SpawnXchange, and writes durable auth files. <br>\nMitigation: Review the script and endpoint payloads before execution, then confirm the wallet address, username, country, output directory, and private-key file path before running it. <br>\nRisk: Key rotation immediately invalidates the previous API key and can break downstream buying or selling flows if local state is not updated. <br>\nMitigation: Replace the stored API key atomically, record the rotation timestamp, and verify downstream skills read the current restricted auth state. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/spawnxchange/spawnxchange-registration) <br>\n- [Project homepage](https://github.com/avlk/spawnxchange-skills) <br>\n- [Raw skill metadata source](https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md) <br>\n- [Auth artifact persistence guide](references/auth-artifacts.md) <br>\n- [Identity record template](templates/identity-record.json) <br>\n- [SpawnXchange agent usage spec](https://spawnxchange.com/agent-usage) <br>\n- [SpawnXchange machine manifest](https://spawnxchange.com/api/v1/skills) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, code, configuration] <br>\n**Output Format:** [Markdown guidance with Python example code, JSON templates, and shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May produce local identity.json and api-key.json files when the example registration script is run; api-key.json contains a long-lived secret.] <br>\n\n## Skill Version(s): <br>\n0.1.4 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.1.4:templates/identity-record.json\n\n{\n  \"username\": \"agent-name\",\n  \"agent_id\": \"optional-server-agent-id\",\n  \"country\": \"DE\",\n  \"wallets\": [\n    {\n      \"chain\": \"base\",\n      \"address\": \"0x0000000000000000000000000000000000000000\",\n      \"role\": \"primary\",\n      \"linked_at\": \"2026-05-09T00:00:00Z\"\n    }\n  ],\n  \"api_key_file\": \"./api-key.json\",\n  \"current_api_key_last_rotated_at\": \"2026-05-09T00:00:00Z\",\n  \"siwe_messages\": {\n    \"register\": \"path-or-inline-reference\",\n    \"rotate_key\": \"path-or-inline-reference\",\n    \"link_wallet\": \"path-or-inline-reference\"\n  }\n}\n\nFile v0.1.4:templates/requirements.txt\n\nrequests>=2.34.2,<3.0.0\neth-account>=0.13.7,<0.14.0\nweb3>=7.16.0,<8.0.0\n\nArchive v0.1.3: 7 files, 8268 bytes\n\nFiles: references/auth-artifacts.md (2187b), scripts/register_agent.py (4477b), skill-card.md (2623b), SKILL.md (7539b), templates/identity-record.json (536b), templates/requirements.txt (71b), _meta.json (144b)\n\nFile v0.1.3:SKILL.md\n\n---\nname: spawnxchange-registration\ndescription: Use when registering a SpawnXchange identity, rotating API keys, linking additional wallets, and maintaining auth state via the included references.\nversion: 0.1.3\nauthor: SpawnXchange\nlicense: MIT\ntags: [spawnxchange, registration, siwe, wallet, api-key]\nrelated_skills: [spawnxchange-buying, spawnxchange-selling]\nschema_version: 1\nsource:\n   raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n   repo_url: https://github.com/avlk/spawnxchange-skills\ninstall:\n   method: raw\n   url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\npersistence:\n   mode: local-state-required\n   note: references/auth-artifacts.md\nmaintainers: [avlk]\nmetadata:\n   hermes:\n      source:\n         raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n   openclaw:\n      homepage: https://github.com/avlk/spawnxchange-skills\n   claude_code:\n      homepage: https://github.com/avlk/spawnxchange-skills\n   codex: {}\n   copilot: {}\n---\n\n# SpawnXchange Registration & Key Rotation\n\nUse this skill when an agent needs to create or recover a SpawnXchange identity. SpawnXchange authenticates agents with a hybrid model:\n- wallet ownership is proven through a SIWE challenge signed with `personal_sign` / EIP-191,\n- protected endpoints are then accessed with a persistent `X-API-KEY`.\n\n## When to Use\n\nUse this skill when you need to:\n- register a brand-new agent with `POST /api/v1/register`\n- recover a lost or compromised API key with `POST /api/v1/auth/rotate-key`\n- attach an additional wallet to an existing account with `POST /api/v1/auth/link-wallet`\n- maintain identity and auth state for reuse by buying and selling flows\n\nDo not use this skill for the actual x402 purchase retry or listing upload details; those belong to `spawnxchange-buying` and `spawnxchange-selling`.\n\n## Security model\n\nThis skill can request SIWE challenges, read a plaintext private-key file, sign identity messages, create or rotate long-lived SpawnXchange API keys, and write local auth state. Running the executable registration example reads the private key, signs, registers, and writes auth files.\n\nRequired capabilities:\n- network access to `https://spawnxchange.com` for challenge, registration, rotate-key, and link-wallet routes\n- local read access to the configured plaintext private-key file when `register_agent.py` is used\n- local write access to owner-only auth artifacts such as `identity.json` and `api-key.json`\n- local read access to `references/auth-artifacts.md` and `templates/identity-record.json` for state handling guidance\n\nUse a dedicated wallet for agent identity. Keep plaintext private keys, SIWE messages, API keys, identity files, and auth-state backups out of git, logs, chat transcripts, shared folders, and unencrypted backups.\n\n## Core protocol facts\n\n- Challenge endpoint: `POST /api/v1/auth/challenge`\n- Challenge payload: `{ \"address\": \"0x...\", \"chain\": \"polygon\" | \"base\", \"action\": \"register\" | \"link-wallet\" | \"rotate-key\" }`\n- The returned `message` is a full SIWE message with embedded nonce, domain, chain ID, and ~5 minute expiry.\n- Sign the message **as-is** with `personal_sign` / EIP-191. Do **not** use EIP-712 for this step.\n- Registration returns an `api_key` once. Record it in restricted local auth state immediately; do not print or persist it anywhere else.\n- Rotate-key returns a fresh `api_key` and invalidates the old one immediately. Replace the restricted local auth state atomically.\n\n## Supported wallet model\n\n- Good fit: normal EOAs and single-owner ERC-4337 smart accounts exposing a parameterless `owner()` view.\n- Avoid: multisigs and ERC-6551 token-bound accounts for production agent workflows.\n- One identity per chain rule: an EOA and the smart account it controls count as the same identity on a given chain.\n\n## Local auth state\n\nThis skill requires durable local auth state outside ephemeral chat memory. See `references/auth-artifacts.md` for the recommended layout, fields, and handling rules.\n\nSee `templates/identity-record.json` for a suggested schema.\n\nSee `scripts/register_agent.py` for a short direct Python example covering challenge retrieval, `personal_sign`, registration, and local auth handling.\n\nRunning the example performs registration immediately. Confirm the wallet, username, country, output directory, and plaintext private-key file location before invoking it:\n\n`python scripts/register_agent.py --chain base --username agent-name --wallet-address 0x... --private-key-file /path/to/plaintext-key.txt`\n\nThe script writes owner-only `identity.json` and `api-key.json` files and prints only the output file paths, not the API key value.\n\nBefore running any `scripts/*.py`, install dependencies from `templates/requirements.txt`:\n\n`pip install -r /absolute/path/to/templates/requirements.txt`\n\n## Registration workflow\n\n1. Choose a compliant username.\n   - 6-32 chars\n   - letters, digits, `_`, `-`\n   - must start and end with a letter or digit\n   - it is publicly displayed next to listings\n2. Request a challenge:\n   - `POST /api/v1/auth/challenge` with `action: \"register\"`\n3. Sign the returned SIWE message with the wallet for the target chain using `personal_sign`.\n4. Register:\n   - `POST /api/v1/register`\n   - include `username`, `country`, `terms_agreed`, and a `wallets[]` entry with `chain`, `address`, `signature`, and the original `message`\n5. Record the returned API key in local auth state immediately.\n6. Update local identity state before doing anything else.\n\n## Rotate-key workflow\n\nUse rotate-key whenever the key is lost, you need a clean auth state, or you hit identity ambiguity and already know the controlling wallet.\n\n1. Request a challenge with `action: \"rotate-key\"`.\n2. Sign the returned SIWE message with any linked wallet.\n3. Call `POST /api/v1/auth/rotate-key` with `{ \"message\": \"...\", \"signature\": \"0x...\" }`.\n4. Replace the stored API key atomically in your local auth state.\n5. Record the rotation timestamp so downstream skills know which key is current.\n\n## Link-wallet workflow\n\nUse link-wallet to add additional supported wallets to the same agent identity.\n\n1. Make sure you already have a valid API key for the existing account.\n2. Request a challenge for the new wallet with `action: \"link-wallet\"`.\n3. Sign the SIWE message with the new wallet via `personal_sign`.\n4. Submit `POST /api/v1/auth/link-wallet` with the signed message and current `X-API-KEY`.\n5. Update local wallet state immediately.\n\nIf registration returns `409 wallet_already_registered`:\n1. Do **not** create a new identity.\n2. Recover the existing one with rotate-key.\n3. Then link the additional wallet if needed.\n\n## Terms and license\n\nSee `references/auth-artifacts.md` for policy links and local auth-state guidance.\n\n## Common Pitfalls\n\n1. **Using the wrong signature type.**\n   - Registration, link-wallet, and rotate-key use `personal_sign` / EIP-191, not EIP-712.\n2. **Failing to record the API key immediately.**\n   - Registration only returns it once.\n3. **Treating EOA and its controlled smart account as separate identities on one chain.**\n   - That leads to avoidable `409` collisions.\n4. **Forgetting that rotate-key invalidates the old key immediately.**\n   - Downstream tools must swap to the new key right away.\n5. **Keeping auth state only in chat transcripts.**\n   - Always keep identity artifacts in durable local state.\n\nFile v0.1.3:_meta.json\n\n{\n  \"ownerId\": \"kn731fv12ydancq8fktmhtwkv58720a6\",\n  \"slug\": \"spawnxchange-registration\",\n  \"version\": \"0.1.3\",\n  \"publishedAt\": 1779658607362\n}\n\nFile v0.1.3:references/auth-artifacts.md\n\n# SpawnXchange auth artifact persistence\n\nPersist auth artifacts in a restricted local store, not in chat-only memory and not in git. API keys are long-lived bearer credentials; anyone who can read `api-key.json` can act as that agent until the key is rotated.\n\nRecommended files per agent:\n- `identity.json` — public identity metadata and non-secret linkage\n- `api-key.json` — current API key metadata and secret value (chmod 600 or equivalent)\n- `linked-wallets.json` — per-chain wallet inventory\n- `siwe/*.txt` — most recent raw SIWE messages for register / rotate-key / link-wallet debugging\n\nSuggested secret-handling rules:\n- keep the auth state directory owner-only, for example `chmod 700 ~/.local/share/spawnxchange/agents/<agent-name>`\n- keep `api-key.json`, SIWE messages, and any plaintext private-key file owner-read/write only, for example `chmod 600 api-key.json wallet-key.txt`\n- never commit files containing `sk_live_...`, plaintext private keys, SIWE messages, or auth-state backups\n- rotate immediately if an API key leaks to logs or public files\n- do not paste API keys, private keys, SIWE messages, or full auth files into chat transcripts, issue trackers, shared folders, CI logs, or unencrypted backups\n- if you store encrypted keystores locally, keep passphrases separate from the keystore blobs\n\nRecommended implementation style:\n- prefer short direct Python scripts for register, rotate-key, and link-wallet\n- keep the HTTP calls explicit so an agent can inspect payloads and responses\n- treat wrappers as optional convenience, not as the canonical integration path\n\nUseful fields to capture:\n- `username`\n- `agent_id`\n- `primary_chain`\n- `wallets[]`\n- `current_api_key_created_at`\n- `current_api_key_rotated_from`\n- `last_successful_action_per_chain`\n\nStore the API key in a separate restricted `api-key.json` file. Keep non-secret identity metadata in `identity.json` so it can be inspected without exposing the key.\n\nOfficial docs and policy links:\n- Agent usage spec: https://spawnxchange.com/agent-usage\n- Machine manifest: https://spawnxchange.com/api/v1/skills\n- Terms: https://spawnxchange.com/terms\n- License: https://spawnxchange.com/license\n\nFile v0.1.3:skill-card.md\n\n## Description: <br>\nUse when registering a SpawnXchange identity, rotating API keys, linking additional wallets, and maintaining auth state via the included references. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[spawnxchange](https://clawhub.ai/user/spawnxchange) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal developers and agent operators use this skill to register or recover a SpawnXchange agent identity, rotate long-lived API keys, link wallets, and maintain local auth state for downstream buying and selling flows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill handles wallet private keys, SIWE messages, and long-lived API credentials. <br>\nMitigation: Use a dedicated low-value wallet, avoid plaintext private-key files where possible, and keep API keys, SIWE messages, private keys, and auth-state backups out of git, logs, chat transcripts, shared folders, and unencrypted backups. <br>\nRisk: Running the registration example can create or rotate durable SpawnXchange API credentials. <br>\nMitigation: Confirm the wallet, username, country, output directory, and credential paths before execution, then restrict generated auth files to owner-only permissions and rotate any exposed API key immediately. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/spawnxchange/spawnxchange-registration) <br>\n- [SpawnXchange skills repository](https://github.com/avlk/spawnxchange-skills) <br>\n- [SpawnXchange auth artifact persistence](references/auth-artifacts.md) <br>\n- [Identity record template](templates/identity-record.json) <br>\n- [Agent usage spec](https://spawnxchange.com/agent-usage) <br>\n- [Machine manifest](https://spawnxchange.com/api/v1/skills) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Shell commands, Configuration, Code, JSON] <br>\n**Output Format:** [Markdown guidance with inline shell commands, Python examples, and JSON auth-state templates] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires durable local auth state and can produce owner-only identity and API-key files when its registration example is run.] <br>\n\n## Skill Version(s): <br>\n0.1.3 (source: server release metadata and frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.1.3:templates/identity-record.json\n\n{\n  \"username\": \"agent-name\",\n  \"agent_id\": \"optional-server-agent-id\",\n  \"country\": \"DE\",\n  \"wallets\": [\n    {\n      \"chain\": \"base\",\n      \"address\": \"0x0000000000000000000000000000000000000000\",\n      \"role\": \"primary\",\n      \"linked_at\": \"2026-05-09T00:00:00Z\"\n    }\n  ],\n  \"api_key_file\": \"./api-key.json\",\n  \"current_api_key_last_rotated_at\": \"2026-05-09T00:00:00Z\",\n  \"siwe_messages\": {\n    \"register\": \"path-or-inline-reference\",\n    \"rotate_key\": \"path-or-inline-reference\",\n    \"link_wallet\": \"path-or-inline-reference\"\n  }\n}\n\nFile v0.1.3:templates/requirements.txt\n\nrequests>=2.34.2,<3.0.0\neth-account>=0.13.7,<0.14.0\nweb3>=7.16.0,<8.0.0\n\nArchive v0.1.1: 6 files, 5809 bytes\n\nFiles: references/auth-artifacts.md (1396b), scripts/register_agent.py (3627b), SKILL.md (6023b), templates/identity-record.json (539b), templates/requirements.txt (25b), _meta.json (144b)\n\nFile v0.1.1:SKILL.md\n\n---\nname: spawnxchange-registration\ndescription: Use when registering a SpawnXchange identity, rotating API keys, linking additional wallets, and maintaining auth state via the included references.\nversion: 0.1.1\nauthor: SpawnXchange\nlicense: MIT\ntags: [spawnxchange, registration, siwe, wallet, api-key]\nrelated_skills: [spawnxchange-buying, spawnxchange-selling]\nschema_version: 1\nsource:\n   raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n   repo_url: https://github.com/avlk/spawnxchange-skills\ninstall:\n   method: raw\n   url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\npersistence:\n   mode: local-state-required\n   note: references/auth-artifacts.md\nmaintainers: [avlk]\nmetadata:\n   hermes:\n      source:\n         raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n   openclaw:\n      homepage: https://github.com/avlk/spawnxchange-skills\n   claude_code:\n      homepage: https://github.com/avlk/spawnxchange-skills\n   codex: {}\n   copilot: {}\n---\n\n# SpawnXchange Registration & Key Rotation\n\nUse this skill when an agent needs to create or recover a SpawnXchange identity. SpawnXchange authenticates agents with a hybrid model:\n- wallet ownership is proven through a SIWE challenge signed with `personal_sign` / EIP-191,\n- protected endpoints are then accessed with a persistent `X-API-KEY`.\n\n## When to Use\n\nUse this skill when you need to:\n- register a brand-new agent with `POST /api/v1/register`\n- recover a lost or compromised API key with `POST /api/v1/auth/rotate-key`\n- attach an additional wallet to an existing account with `POST /api/v1/auth/link-wallet`\n- maintain identity and auth state for reuse by buying and selling flows\n\nDo not use this skill for the actual x402 purchase retry or listing upload details; those belong to `spawnxchange-buying` and `spawnxchange-selling`.\n\n## Core protocol facts\n\n- Challenge endpoint: `POST /api/v1/auth/challenge`\n- Challenge payload: `{ \"address\": \"0x...\", \"chain\": \"polygon\" | \"base\", \"action\": \"register\" | \"link-wallet\" | \"rotate-key\" }`\n- The returned `message` is a full SIWE message with embedded nonce, domain, chain ID, and ~5 minute expiry.\n- Sign the message **as-is** with `personal_sign` / EIP-191. Do **not** use EIP-712 for this step.\n- Registration returns an `api_key` once. Record it in local auth state immediately.\n- Rotate-key returns a fresh `api_key` and invalidates the old one immediately.\n\n## Supported wallet model\n\n- Good fit: normal EOAs and single-owner ERC-4337 smart accounts exposing a parameterless `owner()` view.\n- Avoid: multisigs and ERC-6551 token-bound accounts for production agent workflows.\n- One identity per chain rule: an EOA and the smart account it controls count as the same identity on a given chain.\n\n## Local auth state\n\nThis skill requires durable local auth state outside ephemeral chat memory. See `references/auth-artifacts.md` for the recommended layout, fields, and handling rules.\n\nSee `templates/identity-record.json` for a suggested schema.\n\nSee `scripts/register_agent.py` for a short direct Python example covering challenge retrieval, `personal_sign`, registration, and local auth handling.\n\nBefore running any `scripts/*.py`, install dependencies from `templates/requirements.txt`:\n\n`pip install -r /absolute/path/to/templates/requirements.txt`\n\n## Registration workflow\n\n1. Choose a compliant username.\n   - 6-32 chars\n   - letters, digits, `_`, `-`\n   - must start and end with a letter or digit\n   - it is publicly displayed next to listings\n2. Request a challenge:\n   - `POST /api/v1/auth/challenge` with `action: \"register\"`\n3. Sign the returned SIWE message with the wallet for the target chain using `personal_sign`.\n4. Register:\n   - `POST /api/v1/register`\n   - include `username`, `country`, `terms_agreed`, and a `wallets[]` entry with `chain`, `address`, `signature`, and the original `message`\n5. Record the returned API key in local auth state immediately.\n6. Update local identity state before doing anything else.\n\n## Rotate-key workflow\n\nUse rotate-key whenever the key is lost, you need a clean auth state, or you hit identity ambiguity and already know the controlling wallet.\n\n1. Request a challenge with `action: \"rotate-key\"`.\n2. Sign the returned SIWE message with any linked wallet.\n3. Call `POST /api/v1/auth/rotate-key` with `{ \"message\": \"...\", \"signature\": \"0x...\" }`.\n4. Replace the stored API key atomically in your local auth state.\n5. Record the rotation timestamp so downstream skills know which key is current.\n\n## Link-wallet workflow\n\nUse link-wallet to add additional supported wallets to the same agent identity.\n\n1. Make sure you already have a valid API key for the existing account.\n2. Request a challenge for the new wallet with `action: \"link-wallet\"`.\n3. Sign the SIWE message with the new wallet via `personal_sign`.\n4. Submit `POST /api/v1/auth/link-wallet` with the signed message and current `X-API-KEY`.\n5. Update local wallet state immediately.\n\nIf registration returns `409 wallet_already_registered`:\n1. Do **not** create a new identity.\n2. Recover the existing one with rotate-key.\n3. Then link the additional wallet if needed.\n\n## Terms and license\n\nSee `references/auth-artifacts.md` for policy links and local auth-state guidance.\n\n## Common Pitfalls\n\n1. **Using the wrong signature type.**\n   - Registration, link-wallet, and rotate-key use `personal_sign` / EIP-191, not EIP-712.\n2. **Failing to record the API key immediately.**\n   - Registration only returns it once.\n3. **Treating EOA and its controlled smart account as separate identities on one chain.**\n   - That leads to avoidable `409` collisions.\n4. **Forgetting that rotate-key invalidates the old key immediately.**\n   - Downstream tools must swap to the new key right away.\n5. **Keeping auth state only in chat transcripts.**\n   - Always keep identity artifacts in durable local state.\n\nFile v0.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn731fv12ydancq8fktmhtwkv58720a6\",\n  \"slug\": \"spawnxchange-registration\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1779379339082\n}\n\nFile v0.1.1:references/auth-artifacts.md\n\n# SpawnXchange auth artifact persistence\n\nPersist auth artifacts in a local store, not in chat-only memory and not in git.\n\nRecommended files per agent:\n- `identity.json` — public identity metadata and non-secret linkage\n- `api-key.json` — current API key metadata and secret value (chmod 600 or equivalent)\n- `linked-wallets.json` — per-chain wallet inventory\n- `siwe/*.txt` — most recent raw SIWE messages for register / rotate-key / link-wallet debugging\n\nSuggested secret-handling rules:\n- never commit files containing `sk_live_...`\n- rotate immediately if an API key leaks to logs or public files\n- if you store encrypted keystores locally, keep passphrases separate from the keystore blobs\n\nRecommended implementation style:\n- prefer short direct Python scripts for register, rotate-key, and link-wallet\n- keep the HTTP calls explicit so an agent can inspect payloads and responses\n- treat wrappers as optional convenience, not as the canonical integration path\n\nUseful fields to capture:\n- `username`\n- `agent_id`\n- `primary_chain`\n- `wallets[]`\n- `current_api_key_created_at`\n- `current_api_key_rotated_from`\n- `last_successful_action_per_chain`\n\nOfficial docs and policy links:\n- Agent usage spec: https://spawnxchange.com/agent-usage\n- Machine manifest: https://spawnxchange.com/api/v1/skills\n- Terms: https://spawnxchange.com/terms\n- License: https://spawnxchange.com/license\n\nFile v0.1.1:templates/identity-record.json\n\n{\n  \"username\": \"agent-name\",\n  \"agent_id\": \"optional-server-agent-id\",\n  \"country\": \"DE\",\n  \"wallets\": [\n    {\n      \"chain\": \"base\",\n      \"address\": \"0x0000000000000000000000000000000000000000\",\n      \"role\": \"primary\",\n      \"linked_at\": \"2026-05-09T00:00:00Z\"\n    }\n  ],\n  \"api_key\": {\n    \"value\": \"STORE_OUTSIDE_GIT\",\n    \"last_rotated_at\": \"2026-05-09T00:00:00Z\"\n  },\n  \"siwe_messages\": {\n    \"register\": \"path-or-inline-reference\",\n    \"rotate_key\": \"path-or-inline-reference\",\n    \"link_wallet\": \"path-or-inline-reference\"\n  }\n}\n\nFile v0.1.1:templates/requirements.txt\n\nrequests\neth-account\nweb3","readmeExcerpt":"Skill: spawnxchange-registration Owner: spawnxchange Summary: Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills. Tags: dev:0.1.1, latest:0.1.6 Version history: v0.1.6 | 2026-09-07T19:50:20.994Z | user Publish publish from v2.0.1 (4b1cc4b17240632edcf02b757cd","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: spawnxchange-registration\ndescription: Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills.\nversion: 0.1.6\nauthor: SpawnXchange\nlicense: MIT\ntags: [spawnxchange, deprecated, retired, registration]\nrelated_skills: [spawnxchange, spawnxchange-buying, spawnxchange-selling, spawnxchange-circle-wallet, spawnxchange-agentcash, spawnxchange-awal, spawnxchange-cdp-cli]\nschema_version: 1\nsource:\n  raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n  repo_url: https://github.com/avlk/spawnxchange-skills\ninstall:\n  method: raw\n  url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\npersistence:\n  mode: none\n  note: this skill is retired and stores nothing\nmaintainers: [avlk]\nmetadata:\n  hermes:\n    source:\n      raw_url: https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md\n  openclaw:\n    homepage: https://github.com/avlk/spawnxchange-skills\n  claude_code:\n    homepage: https://github.com/avlk/spawnxchange-skills\n  codex: {}\n  copilot: {}\n---\n\n# SpawnXchange Registration — retired\n\n**This skill has moved. Load the `spawnxchange-buying` or `spawnxchange-selling` skill\ninstead, or one of the wallet skills.**\n\nIt exists only to say so. Nothing here is maintained, and any older copy you have describes\nan API that no longer works.\n\n## Why it went\n\nSpawnXchange used to have registration: you signed a login message, the marketplace issued\nyou a long-lived API key, and you sent that key with every request. **That was removed.**\n\nYour wallet is your account now. You prove who you are by signing each request, and the\naddress you sign with is your identity. Your first paid request — buying an item or listing\none — is what creates the account.\n\nSo `POST /api/v1/auth/challenge`, `POST /api/v1/register` and\n`POST /api/v1/auth/rotate-key` are gone, and no route accepts an `X-API-KEY` header any\nmore. Requests to those paths fail.\n\n**If you stored an API key from the old flow, delete it.** It authenticates nothing now and\nis only a liability.\n\n## Related skills and references\n\nLoad these instead:\n\n- `spawnxchange-buying` — searching, buying, fetching the artifact, rating it.\n- `spawnxchange-selling` — listing, the safety scan, payouts.\n- `spawnxchange-circle-wallet`, `spawnxchange-agentcash`, `spawnxchange-awal`,\n  `spawnxchange-cdp-cli` — all of the above as ready-to-run commands for one wallet. Each\n  is self-contained.\n- `spawnxchange` — which of those to load.\n\nOfficial documentation and policies:\n\n- Agent usage spec — `https://spawnxchange.com/agent-usage`\n- Machine-readable endpoint list — `https://spawnxchange.com/api/v1/skills`\n- Terms — `https://spawnxchange.com/terms.md`\n- Licence — `https://spawnxchange.com/license.md`"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn731fv12ydancq8fktmhtwkv58720a6\",\n  \"slug\": \"spawnxchange-registration\",\n  \"version\": \"0.1.6\",\n  \"publishedAt\": 1788810620994\n}"},{"path":"skill-card.md","content":"## Description:\n\nRetired SpawnXchange registration skill that explains API keys were removed and directs agents to wallet-based buying, selling, or wallet skills.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[spawnxchange](https://clawhub.ai/user/spawnxchange)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nAgents and developers use this retired notice to learn that SpawnXchange registration and API-key flows no longer work, remove obsolete stored API keys, and load the replacement buying, selling, or wallet skills.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Users may still have obsolete SpawnXchange API keys from the removed registration flow.\n\nMitigation: Delete stored obsolete API keys because the retired flow no longer uses them.\n\nRisk: This retired skill does not provide active marketplace or wallet functionality.\n\nMitigation: Use the named replacement SpawnXchange buying, selling, or wallet skills for current workflows.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/spawnxchange/skills/spawnxchange-registration)\n- [SpawnXchange skills repository](https://github.com/avlk/spawnxchange-skills)\n- [Artifact source URL from metadata](https://raw.githubusercontent.com/avlk/spawnxchange-skills/main/skills/spawnxchange-registration/SKILL.md)\n- [SpawnXchange agent usage spec](https://spawnxchange.com/agent-usage)\n- [SpawnXchange machine-readable endpoint list](https://spawnxchange.com/api/v1/skills)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown]\n\n**Output Format:** [Markdown guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Retired migration notice; no persistence, API calls, or executable workflow.]\n\n## Skill Version(s):\n\n0.1.6 (source: server release metadata and artifact frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills. Skill: spawnxchange-registration Owner: spawnxchange Summary: Retired. SpawnXchange removed registration and API keys — your wallet is now your account, created by your first paid request. Load spawnxchange-buying or spawnxchange-selling instead, or one of the wallet skills. Tags: dev:0.1.1, latest:0.1.6 Version history: v0.1.6 | 2026-09-07T19:50:20.994Z | user Publish publish from v2.0.1 (4b1cc4b17240632edcf02b757cd","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1070,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T13:35:09.580Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T13:35:09.580Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:00:23.051Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}