conto-check.sh) and the same Conto REST API. Only the install command and the config file location differ.
In the examples below,
pathUSD refers to Tempo Testnet. For production wallets on Tempo Mainnet,
use USDC.e.How it works
1
The agent wants to pay
For example, 50 pathUSD to
0xabc....2
The skill asks Conto
The skill calls the matching Conto payment endpoint.
3
Conto checks your policies
APPROVED: the agent makes the payment.DENIED: the agent stops and reports the reason.REQUIRES_APPROVAL: the agent waits for a person to sign off.
EXTERNAL, so the skill uses approve, the agent’s own
transfer, then confirm. An approval token expires after 10 minutes. Managed wallets use request,
then execute. See wallet custody.
The default Standard SDK key preset includes the payment scopes these flows need:
payments:execute, payments:approve, and payments:confirm. Only the
policy management commands need an Admin SDK key.Install
Requirements:conto-check.sh uses curl, jq, and python3. Install jq via your package
manager if missing (brew install jq, apt install jq). python3 handles the temporary browser
callback during authentication.
- OpenClaw
- Nous Hermes
Install from ClawHub:You can inspect the raw skill manifest at
conto.finance/skill.md.
Use ClawHub for installation so the helper script is installed with the skill.Choose how to start
Claiming a sandbox does not enable live payments. The skill’s own instructions carry the same
choices in their Choose How to Start section.
Quick setup
After installing, run setup with your agent name and wallet address:- An agent record linked to your organization
- Your wallet registered as
EXTERNALcustody - Default spend limits (500/day)
- An SDK key written to the framework’s config file (see below)
Verify it works:
bash ~/.hermes/skills/conto/conto-check.sh ... instead of
bash skills/conto/conto-check.sh ....
You can adjust spend limits, add policies, and manage the agent in the Conto dashboard.
Config file locations
The skill writes the SDK key to a framework-specific path:- OpenClaw
- Nous Hermes
~/.openclaw/openclaw.json:CONTO_SDK_KEY holds the same agent SDK key (conto_agent_...) that the TypeScript SDK, CLI, and
MCP server read from CONTO_API_KEY. CONTO_API_URL is the skill’s name for the API origin that
they read from CONTO_BASE_URL.
Manual setup
If browser-based setup doesn’t work, configure manually:- Connect your agent in Conto. Sign in to the Conto dashboard and create the agent record.
- Link your wallet. Register the address under Wallets > Import Watch-Only. Then go to Agents > your agent > Wallets > Link Wallet, pick the wallet, and set initial spending limits.
- Generate an SDK key. Go to Agents > your agent > SDK Integration > Generate SDK Key. Pick Standard for payment flows. The preset includes the request, execute, approve, and confirm scopes this skill uses. Pick Admin only if you also want the skill to manage policies, agents, or wallets.
- Save the key to the config path for your framework (above).
Finding your wallet address
Existing MCP wallet. Ask your agent or run its balance or account-listing tool. Copy the address for the chain you want to use. Create a wallet in Conto. Dashboard > Wallets > Create Wallet > chooseMANAGED > select a chain. Conto creates the wallet and shows its address.
Your own external wallet (hardware, MetaMask, etc.). Register the address in Conto as EXTERNAL custody. Your agent handles the onchain transfer itself.
Usage
x402 payments
When the skill records x402 or MPP protocol payments, it sends the aggregate settlement fields at the top level and per-call details inbatchItems. Do not wrap protocol records in a top-level
payments array. It also sends back the grantId and grantSignature from the approved
pre-authorization. A record without a valid grant is flagged as a policy bypass and alerts the
owner. The helper takes the grant as a required argument:
paymentId for both calls. A retried pre-authorization with that paymentId
returns the same live grant.
Policy management
Policy commands need an admin SDK key. With one, manage policies in natural language:Supported rules
Rules cover spend caps, categories, counterparties, schedules, velocity, approval thresholds, agent identity, geography, contracts, and x402 and MPP limits. See Policy overview for the full list.End-to-end example: pay a vendor on Tempo Testnet
This walks the external-wallet flow on Tempo Testnet (chain ID42431). Fund the wallet first
with the Tempo testnet faucet.
Step 1. Install the skill
Run the install command for your framework from Install.Step 2. Run setup
Step 3. Request a payment
decision: "approved", status: "ready_to_send",
an approvalId, a short-lived approvalToken, the network, and a nextAction with the confirmation
URL. If review is required, save approvalRequestId and follow the returned statusUrl instead of
sending funds.
The agent then sends pathUSD with its own wallet tool. The Conto skill does not sign or send
transfers.
Step 4. Confirm back to Conto
After the onchain transfer succeeds:requestId, transactionId, normalized status, network,
explorer URL, and transaction statusUrl.
Step 5. Verify
Open Transactions in the dashboard and follow the explorer link.What happens when a policy blocks the payment?
Review a pending payment in OpenClaw
The OpenClaw skill can list and decide payment reviews for the human owner assigned to the agent:approvalRequestId, not approvalId. approvalId is the payment request ID.
approvalRequestId is a different ID for the human review. The workflow still enforces eligible
roles and users, sequential approval order, required approval count, and expiry. The skill must show
the amount, currency, recipient, purpose, and approval progress. It submits a decision only after
the human gives an explicit decision and the matching one-time token from their approval email.
Never retrieve that token from the human’s email or messaging account.
On the final approval, managed wallets execute automatically and the response includes receiptUrl.
If OpenClaw controls an external wallet, the response instead includes an EXECUTE_EXTERNALLY
handoff with the exact transfer fields. After the wallet tool returns a hash, confirm without a token
within 24 hours of the approval:
PAYMENT_REQUEST_ID is the approvalId from the original approve response, the same ID as
APPROVAL_ID in Step 4. Do not pass the approvalRequestId here.
Rate limits
On429, the response body includes retryAfter in seconds. conto-check.sh does not retry. It
exits with the error, so wait that long before calling again. See Defaults
for the per-agent limits.
Troubleshooting
Skill can't reach Conto (connection refused or timeout)
Skill can't reach Conto (connection refused or timeout)
Verify A valid JSON response means the URL is reachable.
CONTO_API_URL is correct. For the hosted platform, use https://conto.finance. Test:401 AUTH_FAILED
401 AUTH_FAILED
SDK keys are scoped to a single agent. Check that:
- The key starts with
conto_agent_(notconto_) - The key has not been revoked on the agent’s SDK Integration tab
- You’re using the correct key for the correct agent
Payment denied unexpectedly
Payment denied unexpectedly
The denial response includes fixed
reasons. Common causes:- No usable wallet is linked to this agent. Link an active wallet on the agent’s page.
- Spend limit exceeded. Check the daily, weekly, and monthly counters on the agent’s Wallets tab.
- Counterparty not on allowlist. If you have an
ALLOWED_COUNTERPARTIESpolicy, the recipient must be listed. - Outside time window.
TIME_WINDOWandDAY_OF_WEEKpolicy rules take an optional IANAtimezoneand use UTC without one. - Category mismatch. Both category rules,
ALLOWED_CATEGORIESandBLOCKED_CATEGORIES, deny a payment with nocategory. Sendcategoryon every payment when you use category rules.
Payment approved but no onchain transfer (external wallet)
Payment approved but no onchain transfer (external wallet)
In external wallet mode, Conto only enforces policy. The agent must transfer funds itself. If
approve succeeds but no transfer happens:- Check the agent has enough
pathUSDin its wallet. - Check the agent logs for transfer errors.
- Ensure the wallet address in Conto matches the agent’s actual wallet.
confirm call may have failed. Run it
again with the same hash:Admin commands fail with 403
Admin commands fail with 403
Policy management requires an Admin SDK key. The default Standard preset covers the payment
lifecycle (
payments:request, payments:execute, payments:approve, payments:confirm) and
reads, but not management scopes like policies:write. Check the key type on the agent’s
SDK Integration tab.