Get Started
Install OpenClaw or Hermes, mint a Passport to the NEAR account it prints, and your agent has an identity. Keys stay on disk.
Your agent
-
1
Have OpenClaw
Install OpenClaw from the getting started guide, then install a background gateway. Skip if you already have a running gateway.
openclaw gateway install openclaw gateway statusCheck:
gateway statusreports the gateway is running. Full host with Podman + nginx TLS: openclaw-agents. -
2
Install the Passport plugin
Install the IdentyClaw Passport plugin and restart the gateway:
openclaw plugins install clawhub:@identyclaw/openclaw-identyclaw-plugin --accept-capabilities openclaw gateway restartCheck: Restart succeeds. Prefer the auto-bootstrap 64-character hex account id the gateway printed (
implicit_account_id). If none printed, create one:mkdir -p "${HOME}/.local/bin" # Point PLUGIN_ROOT at the installed plugin dir (often under ~/.openclaw/extensions/) ln -sfn "${PLUGIN_ROOT}/scripts/generate-near-account.mjs" "${HOME}/.local/bin/identyclaw-generate-near-account" export PATH="${HOME}/.local/bin:${PATH}" identyclaw-generate-near-accountCheck: Command prints a 64-character hex id. Copy that id for step 3 — never a private key or JWT.
Advanced: webhooks, A2A, and guest HTTPS
PLUGIN_FLAGS=(--accept-capabilities) openclaw plugins install clawhub:@identyclaw/openclaw-identyclaw-webhooks-plugin "${PLUGIN_FLAGS[@]}" openclaw plugins install clawhub:@identyclaw/openclaw-a2a-plugin "${PLUGIN_FLAGS[@]}" openclaw plugins install clawhub:@identyclaw/openclaw-identyclaw-httpbearer-plugin "${PLUGIN_FLAGS[@]}" openclaw gateway restartCheck: Each install completes; gateway restart succeeds. Optional public HTTPS for Telegram / A2A / webhooks: use openclaw-agents or your own reverse proxy. Skip if you only need the Passport.
-
3
Obtain a Passport
Open purchase.identyclaw.com, paste the 64-character hex account id, and mint. Then restart and open the TUI:
openclaw gateway restart openclaw tuiIn the TUI, ask the agent to call
identyclaw_ensure_session, thenidentyclaw_get_my_identity.Check: Identity shows Passport fields including
token_id. If lookup fails, wait for on-chain confirm and retry — do not create a new account. -
4
Write IDENTITY.md
In the TUI (or
openclaw tui), send:please read all your idcp passport details and use that information to write IDENTITY.mdCheck:
IDENTITY.mdexists and contains Passport details (includingtoken_id). -
Optional: Showcase
Join the IdentyClaw Telegram group, then play Synthetics' Last Cradle.
-
1
Have Hermes
Install Hermes Agent. Skip if
hermes --versionalready works. Expect a few minutes and about 2.3 GB under~/.hermes.curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --non-interactive --skip-browser --skip-computer-use export PATH="$HOME/.local/bin:$PATH" hermes --versionCheck:
hermes --versionprints a version. If a new terminal cannot findhermes, add thePATHexport to your shell rc. -
2
Install the Passport plugin
Install
libatomic, thenidentyclaw-auth, then runinstall-deps:# Fedora / RHEL sudo dnf install -y libatomic # Debian / Ubuntu sudo apt-get update && sudo apt-get install -y libatomic1 hermes plugins install discernible-io/hermes-identyclaw-auth --enable hermes identyclaw install-depsCheck:
install-depsprints a 64-character hexaccount_id. Copy that id for step 3 — never a private key or JWT. To reprint later:hermes identyclaw enroll.Advanced: webhooks, A2A, and sidecar
hermes identyclaw sidecar start hermes plugins install discernible-io/hermes-identyclaw-a2a hermes plugins install discernible-io/hermes-identyclaw-webhookCheck: Sidecar starts; both plugin installs complete. Optional public HTTPS: use hermes-agents or your own reverse proxy. Skip if you only need the Passport.
Force remint / federated peer / debug (returns metadata only — never the full JWT):
hermes identyclaw ensure_session --force hermes identyclaw ensure_session --base https://peer.example.com -
3
Obtain a Passport
Open purchase.identyclaw.com, paste the printed
account_id, and mint. Then confirm:hermes identyclaw meCheck: Output includes Passport fields with
token_id. If you see nestedRODIT_NOT_FOUND, wait for on-chain confirm and retry — do not re-enroll. -
4
Write IDENTITY.md
In Hermes chat, send:
please read all your idcp passport details and use that information to write IDENTITY.mdCheck:
IDENTITY.mdexists and contains Passport details (includingtoken_id). -
Optional: Showcase
Join the IdentyClaw Telegram group, then play Synthetics' Last Cradle.
Hermes FAQ
hermes identyclaw mesaysRODIT_NOT_FOUNDafter mint?- Wait for on-chain confirm, then retry
hermes identyclaw me. Do not re-enroll. libatomic.so.1: cannot open shared object file?- Install libatomic (step 2), then re-run
hermes identyclaw install-deps. - Need the
account_idagain? - Run
hermes identyclaw enroll— reprints the same id (already: true), no overwrite. - Override
HERMES_HOME? - Optional. Default is
~/.hermes.
-
1
Install near-cli-rs
Install the
nearbinary from near-cli-rs (required foridcp-wallet.sh). Pick one path:# Mac / Linux installer curl --proto '=https' --tlsv1.2 -LsSf https://github.com/near/near-cli-rs/releases/latest/download/near-cli-rs-installer.sh | sh # or npm npm install -g near-cli-rs@latest # or Cargo (needs Rust; on Debian/Ubuntu also: sudo apt install libudev-dev) cargo install near-cli-rs near --versionCheck:
near --versionprints a version. -
2
Create a NEAR account
Clone discernible-io/infra and create an account:
git clone https://github.com/discernible-io/infra.git ~/infra cd ~/infra ./idcp-wallet.sh help ./idcp-wallet.sh gennearaccountCheck:
gennearaccountprints a 64-character hex account id under~/.near-credentials/. Copy that id for step 3 — never a private key or JWT. New accounts need ~0.01 NEAR to initialize. SetBLOCKCHAIN_ENV=mainnet(ortestnet) as needed. -
3
Obtain a Passport
Open purchase.identyclaw.com, paste the account id, and mint. Then list it:
./idcp-wallet.sh <accountID>Check: Listing shows the Passport. If empty, wait for on-chain confirm and retry.
Other runtimes
- ironclaw-agents — Podman / Passport enrollment spine
- Custom gateway — ClawHub plugins, rodit-sdk, Developers