Skip to main content
The Conto skill adds spending-policy checks to supported payment flows built on OpenClaw or Nous Hermes. It checks payments routed through the skill against your policies before the connected flow executes them. An external signer that can send outside this path can bypass the check. Both frameworks use the same wrapper script (conto-check.sh) and the same Conto REST API. Only the install command and the config file location differ.
In the examples below, pathUSD refers to Tempo Testnet. For production wallets on Tempo Mainnet, use USDC.e.

How it works

1

The agent wants to pay

For example, 50 pathUSD to 0xabc....
2

The skill asks Conto

The skill calls the matching Conto payment endpoint.
3

Conto checks your policies

  • APPROVED: the agent makes the payment.
  • DENIED: the agent stops and reports the reason.
  • REQUIRES_APPROVAL: the agent waits for a person to sign off.
Quick setup registers your wallet as EXTERNAL, so the skill uses approve, the agent’s own transfer, then confirm. An approval token expires after 10 minutes. Managed wallets use request, then execute. See wallet custody.
The default Standard SDK key preset includes the payment scopes these flows need: payments:execute, payments:approve, and payments:confirm. Only the policy management commands need an Admin SDK key.

Install

Requirements: conto-check.sh uses curl, jq, and python3. Install jq via your package manager if missing (brew install jq, apt install jq). python3 handles the temporary browser callback during authentication.
Install from ClawHub:
You can inspect the raw skill manifest at conto.finance/skill.md. Use ClawHub for installation so the helper script is installed with the skill.
Do not run npm install @conto_finance/sdk. The OpenClaw skill calls the Conto REST API directly through conto-check.sh, which ClawHub installs. @conto_finance/sdk is a separate TypeScript SDK that this skill does not need.

Choose how to start

Claiming a sandbox does not enable live payments. The skill’s own instructions carry the same choices in their Choose How to Start section.

Quick setup

After installing, run setup with your agent name and wallet address:
This opens your browser for Conto login. After you approve, setup provisions:
  • An agent record linked to your organization
  • Your wallet registered as EXTERNAL custody
  • Default spend limits (100/tx,100/tx, 500/day)
  • An SDK key written to the framework’s config file (see below)
Verify it works:
For Hermes installs, use bash ~/.hermes/skills/conto/conto-check.sh ... instead of bash skills/conto/conto-check.sh .... You can adjust spend limits, add policies, and manage the agent in the Conto dashboard.

Config file locations

The skill writes the SDK key to a framework-specific path:
~/.openclaw/openclaw.json:
This must be valid JSON. Trailing commas or missing braces will make every OpenClaw command fail. Validate with cat ~/.openclaw/openclaw.json | jq ..
CONTO_SDK_KEY holds the same agent SDK key (conto_agent_...) that the TypeScript SDK, CLI, and MCP server read from CONTO_API_KEY. CONTO_API_URL is the skill’s name for the API origin that they read from CONTO_BASE_URL.

Manual setup

If browser-based setup doesn’t work, configure manually:
  1. Connect your agent in Conto. Sign in to the Conto dashboard and create the agent record.
  2. Link your wallet. Register the address under Wallets > Import Watch-Only. Then go to Agents > your agent > Wallets > Link Wallet, pick the wallet, and set initial spending limits.
  3. Generate an SDK key. Go to Agents > your agent > SDK Integration > Generate SDK Key. Pick Standard for payment flows. The preset includes the request, execute, approve, and confirm scopes this skill uses. Pick Admin only if you also want the skill to manage policies, agents, or wallets.
  4. Save the key to the config path for your framework (above).

Finding your wallet address

Existing MCP wallet. Ask your agent or run its balance or account-listing tool. Copy the address for the chain you want to use. Create a wallet in Conto. Dashboard > Wallets > Create Wallet > choose MANAGED > select a chain. Conto creates the wallet and shows its address. Your own external wallet (hardware, MetaMask, etc.). Register the address in Conto as EXTERNAL custody. Your agent handles the onchain transfer itself.
EXTERNAL custody keeps full key control in your wallet stack. Conto can approve, deny, record, and alert on payments routed through Conto, but it cannot cryptographically block a direct transfer signed outside Conto.

Usage

CLI (OpenClaw example):

x402 payments

When the skill records x402 or MPP protocol payments, it sends the aggregate settlement fields at the top level and per-call details in batchItems. Do not wrap protocol records in a top-level payments array. It also sends back the grantId and grantSignature from the approved pre-authorization. A record without a valid grant is flagged as a policy bypass and alerts the owner. The helper takes the grant as a required argument:
Reuse the same paymentId for both calls. A retried pre-authorization with that paymentId returns the same live grant.

Policy management

Policy commands need an admin SDK key. With one, manage policies in natural language:
With a standard key, create policies under Policies > Create Policy in the dashboard.

Supported rules

Rules cover spend caps, categories, counterparties, schedules, velocity, approval thresholds, agent identity, geography, contracts, and x402 and MPP limits. See Policy overview for the full list.

End-to-end example: pay a vendor on Tempo Testnet

This walks the external-wallet flow on Tempo Testnet (chain ID 42431). Fund the wallet first with the Tempo testnet faucet.

Step 1. Install the skill

Run the install command for your framework from Install.

Step 2. Run setup

Setup links the wallet with a 100per−paymentand100 per-payment and 500 daily limit.

Step 3. Request a payment

The skill calls:
If approved immediately, the response includes decision: "approved", status: "ready_to_send", an approvalId, a short-lived approvalToken, the network, and a nextAction with the confirmation URL. If review is required, save approvalRequestId and follow the returned statusUrl instead of sending funds. The agent then sends pathUSD with its own wallet tool. The Conto skill does not sign or send transfers.

Step 4. Confirm back to Conto

After the onchain transfer succeeds:
Conto records the payment, updates spend counters, and the transaction appears in the dashboard. The confirmation receipt includes the requestId, transactionId, normalized status, network, explorer URL, and transaction statusUrl.

Step 5. Verify

Open Transactions in the dashboard and follow the explorer link.

What happens when a policy blocks the payment?

The $100 per-payment limit from setup denies it. The response carries a fixed denial reason and no transfer happens. The denied attempt appears under Alerts & Approvals in the dashboard.

Review a pending payment in OpenClaw

The OpenClaw skill can list and decide payment reviews for the human owner assigned to the agent:
The helper uses approvalRequestId, not approvalId. approvalId is the payment request ID. approvalRequestId is a different ID for the human review. The workflow still enforces eligible roles and users, sequential approval order, required approval count, and expiry. The skill must show the amount, currency, recipient, purpose, and approval progress. It submits a decision only after the human gives an explicit decision and the matching one-time token from their approval email. Never retrieve that token from the human’s email or messaging account. On the final approval, managed wallets execute automatically and the response includes receiptUrl. If OpenClaw controls an external wallet, the response instead includes an EXECUTE_EXTERNALLY handoff with the exact transfer fields. After the wallet tool returns a hash, confirm without a token within 24 hours of the approval:
PAYMENT_REQUEST_ID is the approvalId from the original approve response, the same ID as APPROVAL_ID in Step 4. Do not pass the approvalRequestId here.

Rate limits

On 429, the response body includes retryAfter in seconds. conto-check.sh does not retry. It exits with the error, so wait that long before calling again. See Defaults for the per-agent limits.

Troubleshooting

Verify CONTO_API_URL is correct. For the hosted platform, use https://conto.finance. Test:
A valid JSON response means the URL is reachable.
SDK keys are scoped to a single agent. Check that:
  • The key starts with conto_agent_ (not conto_)
  • The key has not been revoked on the agent’s SDK Integration tab
  • You’re using the correct key for the correct agent
Generate a new key under Agents > your agent > SDK Integration > Generate SDK Key.
The denial response includes fixed reasons. Common causes:
  • No usable wallet is linked to this agent. Link an active wallet on the agent’s page.
  • Spend limit exceeded. Check the daily, weekly, and monthly counters on the agent’s Wallets tab.
  • Counterparty not on allowlist. If you have an ALLOWED_COUNTERPARTIES policy, the recipient must be listed.
  • Outside time window. TIME_WINDOW and DAY_OF_WEEK policy rules take an optional IANA timezone and use UTC without one.
  • Category mismatch. Both category rules, ALLOWED_CATEGORIES and BLOCKED_CATEGORIES, deny a payment with no category. Send category on every payment when you use category rules.
In external wallet mode, Conto only enforces policy. The agent must transfer funds itself. If approve succeeds but no transfer happens:
  • Check the agent has enough pathUSD in its wallet.
  • Check the agent logs for transfer errors.
  • Ensure the wallet address in Conto matches the agent’s actual wallet.
If the transfer succeeded but Conto doesn’t show it, the confirm call may have failed. Run it again with the same hash:
Policy management requires an Admin SDK key. The default Standard preset covers the payment lifecycle (payments:request, payments:execute, payments:approve, payments:confirm) and reads, but not management scopes like policies:write. Check the key type on the agent’s SDK Integration tab.