Conto
Back to blog
By Conto Team

Conto for OpenClaw: The Spend Management Layer Your Agents Need

Your agent can make payments. That's the easy part. The hard part is making sure it should.

Today we're launching our OpenClaw integration, a skill that checks payments routed through it against owner-defined policy. If you're building on OpenClaw, you can now drop in Conto and get per-transaction limits, daily budgets, category restrictions, approval workflows, and 40+ other rule types with quick setup.

We're offering access to the full suite of Conto policies for teams trying the integration. We'd love your feedback. Join our Discord community to drop us a note.

The Problem

OpenClaw gives agents the ability to execute payments. That's powerful, but also dangerous. Without guardrails, an agent can drain a wallet on a bad API call, pay a blacklisted address, or blow through a monthly budget in an afternoon.

Most teams end up hand-rolling ad-hoc checks that don't scale and miss edge cases. Giving agents the ability to pay requires a lot of trust. Conto helps you add controls to get you there.

How It Works

In the connected skill flow, Conto evaluates each payment attempt against your configured policies before execution:

  1. User sets payment policies
  2. Agent initiates a payment
  3. The Conto skill calls our approval endpoint
  4. We evaluate against all active policies
  5. We return APPROVED, DENIED, or REQUIRES_APPROVAL
  6. The agent proceeds (or doesn't)

Most OpenClaw agents use the external wallet flow, where the agent holds its own keys. The buyer runtime must require this check before signing; Conto cannot block transfers sent outside the connected path:

POST /api/sdk/payments/approve    (policy check)
POST /api/sdk/payments/{id}/confirm   (report tx hash)

If you use a Conto-managed wallet, one call to /api/sdk/payments/request runs the policy check, and nothing leaves the wallet until the decision comes back approved.

Every applicable policy is evaluated for requests sent through the connected Conto flow. Approved requests can proceed through that flow; denied or unresolved requests must not be signed or submitted.

Setup

Getting Started

Install the Conto skill from ClawHub:

npx clawhub install conto

You can inspect the raw skill manifest at conto.finance/skill.md, but use ClawHub for installation so the helper script is installed with the skill.

Configuration

Add your SDK key to ~/.openclaw/openclaw.json:

{
  "skills": {
    "entries": {
      "conto": {
        "env": {
          "CONTO_SDK_KEY": "conto_agent_your_key_here",
          "CONTO_API_URL": "https://conto.finance"
        }
      }
    }
  }
}

Generate keys from the dashboard under Agents > SDK Keys > Generate New Key. Standard keys cover payment evaluation and visibility. Admin keys add policy creation and wallet administration.

What You Can Enforce

We support 40+ rule types across several categories:

  • Approval Workflows. Require human sign-off above a spending threshold.
  • Spend Controls. Per-transaction caps, daily/weekly/monthly limits, budget allocations.
  • Category Management. Whitelist or blacklist specific API providers and payment categories.
  • Counterparty Rules. Block suspicious addresses, allowlist approved vendors.
  • Time-Based Restrictions. Business hours only, weekday-only, maintenance blackout windows.
  • API Cost Controls. Cap per-request costs and limit daily spend per service.

Policies can be created via structured input or natural language:

/conto create a policy that limits each transaction to 200 pathUSD

Two Wallet Modes

Managed wallet: The keys stay in managed wallet infrastructure, never with the agent, and your policies run on every request. Nothing leaves the wallet until the decision comes back approved, and you get the receipt without holding keys yourself.

External wallet: Your agent holds the keys. Conto approves the payment, your agent executes the transfer, then confirms back with the transaction hash:

POST /api/sdk/payments/{REQUEST_ID}/confirm

This gives you full custody while still enforcing every policy.

Chain Support

The integration works across Base, Tempo, and Solana with support for their respective stablecoins.

Get Started

  1. Sign up at conto.finance
  2. Install the skill from ClawHub:
npx clawhub install conto

You can inspect the raw manifest at conto.finance/skill.md; use ClawHub for installation so the helper script is installed too.

  1. Connect your agent in the dashboard
  2. Link your wallet to the agent
  3. Generate an SDK key
  4. Add the config to your OpenClaw setup
  5. Create your first policy

Full SDK reference: conto.finance/docs/sdk/skills


Your agents can pay. Now make sure they pay correctly.