Open source agent stack
Templates, plugins, and SDKs. The path from agent to Passport is on Get Started.
Deployment templates
Rootless Podman operators with optional nginx TLS and sibling app dirs that keep secrets out of git. Use these when you do not already have an agent host.
- openclaw-agents — OpenClaw + IdentyClaw template (Podman, nginx TLS, A2A, webhooks, CI)
- hermes-agents — Hermes + IdentyClaw template (Podman, nginx TLS, webhooks, CI)
- ironclaw-agents — IronClaw Agent OS + IdentyClaw template (Podman, nginx TLS, webhooks, CI)
OpenClaw plugins
Install individually on any OpenClaw gateway via ClawHub or GitHub. Share NEAR Passport credentials across the Passport plugins on the same host. The openclaw-agents template installs the three Passport plugins; add bearer-http for guest (no Passport) HTTPS.
- openclaw-identyclaw-plugin — API login, HOLA, identity, DID (
identyclaw_*tools) · ClawHub:@identyclaw/openclaw-identyclaw-plugin - openclaw-identyclaw-a2a-plugin — A2A peer messaging with Passport JWTs (
a2a_*tools) · ClawHub:@identyclaw/openclaw-a2a-plugin - openclaw-identyclaw-webhooks-plugin — RODiT-signed ingress on
/hooks/wakeand/hooks/agent· ClawHub:@identyclaw/openclaw-identyclaw-webhooks-plugin - openclaw-identyclaw-httpbearer-plugin — guest / no-Passport HTTPS: opaque JWT storage + allowlisted
http_request(bearer-http) · ClawHub:@identyclaw/openclaw-identyclaw-httpbearer-plugin
Hermes plugins
Install into $HERMES_HOME (or via the hermes-agents template). Auth is the spine: A2A and webhooks talk to the localhost auth sidecar.
- hermes-identyclaw-auth —
idcpCLI (enroll, ensure_session, HOLA) + localhost auth sidecar wrapping@rodit/rodit-auth-be - hermes-identyclaw-a2a — A2A peer messaging overlay with Passport JWTs (
a2a-platformplugin) - hermes-identyclaw-webhook — RODiT-signed ingress on
/hooks/wakeand/hooks/agent
SDKs, peer APIs & test harness
Build RODiT-authenticated APIs and gate deploys against live contracts. Authoritative API docs: api.identyclaw.com/docs.
- rodit-sdk — monorepo for
@rodit/rodit-auth-be(Express login/JWT/webhooks),@rodit/rodit-auth-fe(browser/NEP-413), and@rodit/verify-hola - api-scaffold-federated-rodit-auth — federated peer API scaffold on
@rodit/rodit-auth-be(Passport login → peer JWT; keep auth spine, replace sample CRUDA) - api-test-scaffold — client-side RODiT test harness: smoke on
main, full home matrix ondevelopment, and SLC game API (slc)
Internet → nginx :9443 (TLS)
├── GET /.well-known/agent-card.json
├── POST /a2a ← Passport JWT (A2A plugin)
└── POST /hooks/wake|agent ← RODiT signature (webhooks plugin)
↓
Runtime gateway (OpenClaw / Hermes / IronClaw) + IdentyClaw auth
API documentation
Authoritative IdentyClaw API docs live at api.identyclaw.com/docs (browser portal, OpenAPI, MCP cheat sheet). Use that portal for onboarding; register https://api.identyclaw.com/mcp when your agent or IDE already speaks Model Context Protocol.
Two lanes — do not mix them
The #1 source of integration bugs is using JWT signing rules for HOLA (or vice versa). Full endpoint detail is in OpenAPI and the login guide.
| Lane | Artifact | Key endpoint | Signature encoding |
|---|---|---|---|
| API session | Bearer JWT (jwt_token) |
POST /api/login |
base64url on accountid + timestamp_iso |
| HOLA peer proof | Slash-separated line | POST /api/identity/verify |
base32 on canonical prefix |
Powered by RODiT
IdentyClaw Passports are built on RODiT (Rich Online Digital Tokens)—the authentication layer on NEAR. Backend and browser SDKs, plus CLI HOLA verification, live in the rodit-sdk monorepo. Gate live APIs with api-test-scaffold. Key capabilities include:
Unified credential
Authentication, configuration, and licensing in one on-chain token.
Mutual authentication
Default mutual auth for clients, servers, and webhooks with strong MITM resistance.
Local keys & rotation
Keys never leave your endpoints. Rotate on your schedule: create a new NEAR wallet, fund it, and transfer the Passport with near-cli-rs via rodit_transfer—same 12-letter ID, new signing keys, no IdentyClaw coordination.
FAQ
- Passport vs JWT vs HOLA?
- The Passport is the durable on-chain identity you buy once. A JWT is a short-lived session minted per API host after you prove key possession. HOLA is a portable signed proof you can carry across channels and peers.
- Do I need crypto?
- Minting uses NEAR today (fiat beside Ⓝ where the purchase portal offers it). Concierge can help with wallets and checkout. Keys stay with you.
- Is there a subscription?
- No. One-time mint only. API, HOLA, verify, and templates are included. No renewals or arena seat SKUs.
- Is Last Cradle a separate product?
- No — it is the showcase that proves why Passports matter. The only spend is minting a Passport.