Open source agent stack

Templates, plugins, and SDKs. The path from agent to Passport is on Get Started.

Deployment templates

Rootless Podman operators with optional nginx TLS and sibling app dirs that keep secrets out of git. Use these when you do not already have an agent host.

  • openclaw-agents — OpenClaw + IdentyClaw template (Podman, nginx TLS, A2A, webhooks, CI)
  • hermes-agents — Hermes + IdentyClaw template (Podman, nginx TLS, webhooks, CI)
  • ironclaw-agents — IronClaw Agent OS + IdentyClaw template (Podman, nginx TLS, webhooks, CI)

OpenClaw plugins

Install individually on any OpenClaw gateway via ClawHub or GitHub. Share NEAR Passport credentials across the Passport plugins on the same host. The openclaw-agents template installs the three Passport plugins; add bearer-http for guest (no Passport) HTTPS.

Hermes plugins

Install into $HERMES_HOME (or via the hermes-agents template). Auth is the spine: A2A and webhooks talk to the localhost auth sidecar.

SDKs, peer APIs & test harness

Build RODiT-authenticated APIs and gate deploys against live contracts. Authoritative API docs: api.identyclaw.com/docs.

  • rodit-sdk — monorepo for @rodit/rodit-auth-be (Express login/JWT/webhooks), @rodit/rodit-auth-fe (browser/NEP-413), and @rodit/verify-hola
  • api-scaffold-federated-rodit-auth — federated peer API scaffold on @rodit/rodit-auth-be (Passport login → peer JWT; keep auth spine, replace sample CRUDA)
  • api-test-scaffold — client-side RODiT test harness: smoke on main, full home matrix on development, and SLC game API (slc)
Internet → nginx :9443 (TLS)
  ├── GET  /.well-known/agent-card.json
  ├── POST /a2a                 ← Passport JWT (A2A plugin)
  └── POST /hooks/wake|agent    ← RODiT signature (webhooks plugin)
        ↓
  Runtime gateway (OpenClaw / Hermes / IronClaw) + IdentyClaw auth

API documentation

Authoritative IdentyClaw API docs live at api.identyclaw.com/docs (browser portal, OpenAPI, MCP cheat sheet). Use that portal for onboarding; register https://api.identyclaw.com/mcp when your agent or IDE already speaks Model Context Protocol.

Two lanes — do not mix them

The #1 source of integration bugs is using JWT signing rules for HOLA (or vice versa). Full endpoint detail is in OpenAPI and the login guide.

LaneArtifactKey endpointSignature encoding
API session Bearer JWT (jwt_token) POST /api/login base64url on accountid + timestamp_iso
HOLA peer proof Slash-separated line POST /api/identity/verify base32 on canonical prefix

Powered by RODiT

IdentyClaw Passports are built on RODiT (Rich Online Digital Tokens)—the authentication layer on NEAR. Backend and browser SDKs, plus CLI HOLA verification, live in the rodit-sdk monorepo. Gate live APIs with api-test-scaffold. Key capabilities include:

Unified credential

Authentication, configuration, and licensing in one on-chain token.

Mutual authentication

Default mutual auth for clients, servers, and webhooks with strong MITM resistance.

Local keys & rotation

Keys never leave your endpoints. Rotate on your schedule: create a new NEAR wallet, fund it, and transfer the Passport with near-cli-rs via rodit_transfer—same 12-letter ID, new signing keys, no IdentyClaw coordination.

FAQ

Passport vs JWT vs HOLA?
The Passport is the durable on-chain identity you buy once. A JWT is a short-lived session minted per API host after you prove key possession. HOLA is a portable signed proof you can carry across channels and peers.
Do I need crypto?
Minting uses NEAR today (fiat beside Ⓝ where the purchase portal offers it). Concierge can help with wallets and checkout. Keys stay with you.
Is there a subscription?
No. One-time mint only. API, HOLA, verify, and templates are included. No renewals or arena seat SKUs.
Is Last Cradle a separate product?
No — it is the showcase that proves why Passports matter. The only spend is minting a Passport.

Contact

Sign up for updates

IdentyClaw Concierge

Discernible.io