本文へ移動
cccskills
無料GitHub で公開

1claw

HSM-backed secret management for AI agents — store, retrieve, rotate, and share secrets via the 1Claw vault without exposing them in context.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md27.3 KB
  • CONFIG.md4.5 KB
  • EXAMPLES.md4.6 KB
  • README.md1.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

1Claw — HSM-Backed Secret Management for AI Agents

1Claw is a cloud HSM-backed secrets manager. Agents access API keys, passwords, and credentials at runtime without them ever entering the conversation context. Secrets are encrypted with keys that never leave the HSM.

API base URL: https://api.1claw.xyz MCP endpoint: https://mcp.1claw.xyz/mcp Dashboard: https://1claw.xyz Docs: https://docs.1claw.xyz

When to use this skill

  • You need an API key, password, or credential to complete a task
  • You want to store a newly generated credential securely
  • You need to share a secret with a user or another agent
  • You need to rotate a credential after regenerating it
  • You want to check what secrets are available before using one
  • You need to sign or simulate an EVM transaction without exposing private keys

Setup

Option 1: MCP server (recommended for AI agents)

Add to your MCP client configuration. The server auto-refreshes JWT tokens.

{
    "mcpServers": {
        "1claw": {
            "command": "npx",
            "args": ["-y", "@1claw/mcp"],
            "env": {
                "ONECLAW_AGENT_ID": "<agent-uuid>",
                "ONECLAW_AGENT_API_KEY": "<agent-api-key>",
                "ONECLAW_VAULT_ID": "<vault-uuid>"
            }
        }
    }
}

Hosted HTTP streaming mode:

URL: https://mcp.1claw.xyz/mcp
Headers:
  Authorization: Bearer <agent-jwt>
  X-Vault-ID: <vault-uuid>

Option 2: TypeScript SDK

npm install @1claw/sdk
import { createClient } from "@1claw/sdk";

const client = createClient({
    baseUrl: "https://api.1claw.xyz",
    agentId: process.env.ONECLAW_AGENT_ID,
    apiKey: process.env.ONECLAW_AGENT_API_KEY,
});

Option 3: Direct REST API

Authenticate, then pass the Bearer token on every request.

# Exchange agent credentials for a JWT
TOKEN=$(curl -s -X POST https://api.1claw.xyz/v1/auth/agent-token \
  -H "Content-Type: application/json" \
  -d '{"agent_id":"<uuid>","api_key":"<key>"}' | jq -r .access_token)

# Use the JWT
curl -H "Authorization: Bearer $TOKEN" https://api.1claw.xyz/v1/vaults

Alternative: 1ck_ API keys (personal or agent) can be used directly as Bearer tokens — no JWT exchange needed.


Authentication

Agent auth flow

  1. Human registers an agent in the dashboard or via POST /v1/agents with an auth_method (api_key default, mtls, or oidc_client_credentials). For api_key agents → receives agent_id + api_key (prefix ocv_). For mTLS/OIDC agents → receives agent_id only (no API key).
  2. All agents auto-receive an Ed25519 SSH keypair (public key on agent record, private key in __agent-keys vault).
  3. API key agents exchange credentials: POST /v1/auth/agent-token with { "agent_id": "<uuid>", "api_key": "<key>" } → returns { "access_token": "<jwt>", "token_type": "bearer", "expires_in": 3600 }.
  4. Agent uses Authorization: Bearer <jwt> on all subsequent requests.
  5. JWT scopes derive from the agent's access policies (path patterns). If no policies exist, scopes are empty (zero access). The agent's vault_ids are also included in the JWT — requests to unlisted vaults are rejected.
  6. Token TTL defaults to ~1 hour but can be set per-agent via token_ttl_seconds. The MCP server auto-refreshes 60s before expiry.

API key auth

Tokens starting with 1ck_ (human personal API keys) or ocv_ (agent API keys) can be used as Bearer tokens directly on any authenticated endpoint.


MCP Tools Reference

list_secrets

List all secrets in the vault. Returns paths, types, and versions — never values.

ParameterTypeRequiredDescription
prefixstringnoPath prefix to filter (e.g. api-keys/)

get_secret

Fetch the decrypted value of a secret. Use immediately before the API call that needs it. Never store the value or include it in summaries.

ParameterTypeRequiredDescription
pathstringyesSecret path (e.g. api-keys/stripe)

put_secret

Store a new secret or update an existing one. Each call creates a new version.

ParameterTypeRequiredDefaultDescription
pathstringyesSecret path
valuestringyesThe secret value
typestringnoapi_keyOne of: api_key, password, private_key, certificate, file, note, ssh_key, env_bundle
metadataobjectnoArbitrary JSON metadata
expires_atstringnoISO 8601 expiry datetime
max_access_countnumbernoMax reads before auto-expiry (0 = unlimited)

delete_secret

Soft-delete a secret. Reversible by an admin.

ParameterTypeRequiredDescription
pathstringyesSecret path to delete

describe_secret

Get metadata (type, version, expiry) without fetching the value. Use to check existence.

ParameterTypeRequiredDescription
pathstringyesSecret path

rotate_and_store

Store a new value for an existing secret, creating a new version. Use after regenerating a key.

ParameterTypeRequiredDescription
pathstringyesSecret path
valuestringyesNew secret value

get_env_bundle

Fetch an env_bundle secret and parse its KEY=VALUE lines as JSON.

ParameterTypeRequiredDescription
pathstringyesPath to an env_bundle secret

create_vault

Create a new vault for organizing secrets.

ParameterTypeRequiredDescription
namestringyesVault name (1–255 chars)
descriptionstringnoShort description

list_vaults

List all vaults accessible to you. No parameters.

grant_access

Grant a user or agent access to a vault path pattern.

ParameterTypeRequiredDefaultDescription
vault_idstring (UUID)yesVault ID
principal_typeuser | agentyesWho to grant access to
principal_idstring (UUID)yesThe user or agent UUID
permissionsstring[]no["read"]["read"], ["write"], or ["read","write"]
secret_path_patternstringno**Glob pattern for secret paths

share_secret

Share a secret via link, with your creator, or with a specific user/agent.

ParameterTypeRequiredDescription
secret_idstring (UUID)yesThe secret's UUID
recipient_typeuser | agent | anyone_with_link | creatoryescreator shares with the human who registered this agent — no ID needed
recipient_idstring (UUID)conditionalRequired for user and agent types
expires_atstringyesISO 8601 expiry
max_access_countnumberno (default 5)Max reads (0 = unlimited)

Targeted shares (creator/user/agent) require the recipient to explicitly accept before access.

simulate_transaction

Simulate an EVM transaction via Tenderly without signing. Returns balance changes, gas estimates, success/revert status.

ParameterTypeRequiredDefaultDescription
tostringyesDestination address (0x-prefixed)
valuestringyesValue in ETH (e.g. "0.01")
chainstringyesChain name or chain ID (see Supported Chains)
datastringnoHex-encoded calldata
signing_key_pathstringnokeys/{chain}-signerVault path to signing key
gas_limitnumberno21000Gas limit

submit_transaction

Submit an EVM transaction for signing and optional broadcast. Requires crypto_proxy_enabled.

ParameterTypeRequiredDefaultDescription
tostringyesDestination address
valuestringyesValue in ETH
chainstringyesChain name or chain ID
datastringnoHex-encoded calldata
signing_key_pathstringnokeys/{chain}-signerVault path to signing key
noncenumbernoauto-resolvedTransaction nonce
gas_pricestringnoGas price in wei (legacy mode)
gas_limitnumberno21000Gas limit
max_fee_per_gasstringnoEIP-1559 max fee in wei (triggers Type 2)
max_priority_fee_per_gasstringnoEIP-1559 priority fee in wei
simulate_firstbooleannotrueRun Tenderly simulation before signing

REST API Quick Reference

Base URL: https://api.1claw.xyz. All authenticated endpoints require Authorization: Bearer <token>.

Auth (public — no token required)

MethodPathDescription
POST/v1/auth/tokenLogin (email + password) → { access_token }
POST/v1/auth/agent-tokenAgent login (agent_id + api_key) → { access_token }
POST/v1/auth/googleGoogle OAuth
POST/v1/auth/signupCreate account → sends verification email
POST/v1/auth/verify-emailVerify email token → creates user
POST/v1/auth/mfa/verifyVerify MFA code during login

Auth (authenticated)

MethodPathDescription
GET/v1/auth/meGet current user profile
PATCH/v1/auth/meUpdate profile (display_name, marketing_emails)
DELETE/v1/auth/meDelete account (body: { "confirmation": "DELETE MY ACCOUNT" })
DELETE/v1/auth/tokenRevoke current token
POST/v1/auth/change-passwordChange password

Vaults

MethodPathDescription
POST/v1/vaultsCreate vault ({ name, description? }) → 201
GET/v1/vaultsList vaults → { vaults: [...] }
GET/v1/vaults/{id}Get vault details
DELETE/v1/vaults/{id}Delete vault → 204
POST/v1/vaults/{id}/cmekEnable CMEK ({ fingerprint })
DELETE/v1/vaults/{id}/cmekDisable CMEK
POST/v1/vaults/{id}/cmek-rotateStart CMEK key rotation (headers: X-CMEK-Old-Key, X-CMEK-New-Key)
GET/v1/vaults/{id}/cmek-rotate/{job_id}Get rotation job status

Secrets

MethodPathDescription
PUT/v1/vaults/{id}/secrets/{path}Store/update secret ({ type, value, metadata?, expires_at?, max_access_count? }) → 201
GET/v1/vaults/{id}/secrets/{path}Read secret → { path, type, value, version, metadata }
DELETE/v1/vaults/{id}/secrets/{path}Delete secret → 204
GET/v1/vaults/{id}/secrets?prefix=...List secrets (metadata only, no values)

Agents

MethodPathDescription
POST/v1/agentsCreate agent → { agent: {...}, api_key: "ocv_..." }
GET/v1/agentsList agents → { agents: [...] }
GET/v1/agents/{id}Get agent
GET/v1/agents/meGet current agent (self)
PATCH/v1/agents/{id}Update agent (is_active, scopes, crypto_proxy_enabled, guardrails)
DELETE/v1/agents/{id}Delete agent → 204
POST/v1/agents/{id}/rotate-keyRotate agent API key → { api_key: "ocv_..." }

Policies (Access Control)

MethodPathDescription
POST/v1/vaults/{id}/policiesCreate policy ({ principal_type, principal_id, secret_path_pattern, permissions, conditions?, expires_at? })
GET/v1/vaults/{id}/policiesList policies for vault
PUT/v1/vaults/{id}/policies/{pid}Update policy (permissions, conditions, expires_at only)
DELETE/v1/vaults/{id}/policies/{pid}Delete policy → 204

Sharing

MethodPathDescription
POST/v1/secrets/{id}/shareCreate share link
GET/v1/shares/outboundList shares you created
GET/v1/shares/inboundList shares sent to you
POST/v1/shares/{id}/acceptAccept an inbound share
POST/v1/shares/{id}/declineDecline an inbound share
DELETE/v1/share/{id}Revoke a share
GET/v1/share/{id}Access a share (public, may require passphrase)

Crypto Proxy (requires crypto_proxy_enabled)

MethodPathDescription
POST/v1/agents/{id}/transactionsSubmit transaction for signing
GET/v1/agents/{id}/transactionsList agent's transactions
GET/v1/agents/{id}/transactions/{txid}Get transaction details
POST/v1/agents/{id}/transactions/simulateSimulate single transaction
POST/v1/agents/{id}/transactions/simulate-bundleSimulate transaction bundle

Audit

MethodPathDescription
GET/v1/audit/events?limit=N&action=...&from=...&to=...Query audit events

Billing

MethodPathDescription
GET/v1/billing/subscriptionSubscription status, usage, credit balance
GET/v1/billing/credits/balanceCredit balance + expiring credits
GET/v1/billing/credits/transactionsCredit transaction ledger
PATCH/v1/billing/overage-methodSet overage method (credits or x402)
GET/v1/billing/usageUsage summary (current month)
GET/v1/billing/historyUsage event history

Chains

MethodPathDescription
GET/v1/chainsList supported chains
GET/v1/chains/{name_or_id}Get chain details

Other

MethodPathDescription
GET/v1/healthHealth check → { status, service, version }
GET/v1/health/hsmHSM health → { status, hsm_provider, connected }
POST/GET/DELETE/v1/auth/api-keys[/{id}]Manage personal API keys
GET/POST/DELETE/v1/security/ip-rules[/{id}]Manage IP allowlist/blocklist
GET/PATCH/DELETE/v1/org/members[/{id}]Manage org members

SDK Method Reference

All methods return Promise<OneclawResponse<T>>. Access via client.<resource>.<method>(...).

ResourceMethodDescription
vaultscreate({ name, description? })Create vault
vaultsget(vaultId)Get vault
vaultslist()List vaults
vaultsdelete(vaultId)Delete vault
secretsset(vaultId, key, value, { type?, metadata?, expires_at?, max_access_count? })Store/update secret
secretsget(vaultId, key)Read secret (decrypted)
secretslist(vaultId, prefix?)List secret metadata
secretsdelete(vaultId, key)Delete secret
secretsrotate(vaultId, key, newValue)Rotate secret to new version
agentscreate({ name, description?, scopes?, expires_at?, crypto_proxy_enabled?, token_ttl_seconds?, vault_ids? })Create agent → returns agent + api_key
agentsget(agentId)Get agent
agentslist()List agents
agentsupdate(agentId, { is_active?, scopes?, crypto_proxy_enabled?, tx_*? })Update agent
agentsdelete(agentId)Delete agent
agentsrotateKey(agentId)Rotate agent API key
agentssubmitTransaction(agentId, { to, value, chain, ... })Submit EVM transaction
agentssimulateTransaction(agentId, { to, value, chain, ... })Simulate transaction
agentssimulateBundle(agentId, bundle)Simulate transaction bundle
agentsgetTransaction(agentId, txId)Get transaction
agentslistTransactions(agentId)List agent transactions
accessgrantAgent(vaultId, agentId, permissions, { path?, conditions?, expires_at? })Grant agent access
accessgrantHuman(vaultId, userId, permissions, { path?, conditions?, expires_at? })Grant user access
accesslistGrants(vaultId)List policies
accessupdate(vaultId, policyId, { permissions?, conditions?, expires_at? })Update policy
accessrevoke(vaultId, policyId)Revoke policy
sharingcreate(secretId, { recipient_type, recipient_id?, expires_at, max_access_count? })Create share
sharingaccess(shareId)Access shared secret
sharinglistOutbound()Shares you created
sharinglistInbound()Shares sent to you
sharingaccept(shareId)Accept inbound share
sharingdecline(shareId)Decline inbound share
sharingrevoke(shareId)Revoke outbound share
auditquery({ action?, actor_id?, from?, to?, limit?, offset? })Query audit events
billingusage()Current month usage
billinghistory(limit?)Usage event history
authlogin({ email, password })Human login
authagentToken({ agent_id, api_key })Agent JWT exchange
authlogout()Revoke token
apiKeyscreate({ name, scopes?, expires_at? })Create personal API key
apiKeyslist()List API keys
apiKeysrevoke(keyId)Revoke key
chainslist()List supported chains
chainsget(identifier)Get chain by name or ID
orglistMembers()List org members
orgupdateMemberRole(userId, role)Update member role
orgremoveMember(userId)Remove member

OpenAPI spec for custom SDKs

The API spec is published as an npm package for generating clients in any language:

npm install @1claw/openapi-spec

Ships openapi.yaml and openapi.json. Use with any OpenAPI 3.1 codegen tool:

# TypeScript
npx openapi-typescript node_modules/@1claw/openapi-spec/openapi.yaml -o ./types.ts

# Python
openapi-generator generate -i node_modules/@1claw/openapi-spec/openapi.yaml -g python -o ./oneclaw-py

# Go
oapi-codegen -package oneclaw node_modules/@1claw/openapi-spec/openapi.yaml > oneclaw.go

SDK also re-exports generated types: import type { ApiSchemas } from "@1claw/sdk".


Supported Chains

Default chain registry (query GET /v1/chains for live list):

NameChain IDTestnet
ethereum1no
base8453no
optimism10no
arbitrum-one42161no
polygon137no
sepolia11155111yes
base-sepolia84532yes

Use chain names (e.g. "base", "sepolia") or numeric chain IDs in transaction requests.


Access Control Model

Agents do not get blanket access. A human must create a policy to grant an agent access to specific secret paths.

  • Path patterns: Glob syntax — api-keys/*, db/**, ** (all)
  • Permissions: read, write (delete requires write)
  • Conditions: IP allowlist, time windows (JSON)
  • Expiry: Optional ISO 8601 date

If no policy matches → 403 Forbidden. Vault creators always have full access (owner bypass).

Vault binding and token scoping

Agents can be restricted beyond policies:

  • vault_ids: Restrict the agent to specific vaults. If non-empty, any request to a vault not in the list returns 403.
  • token_ttl_seconds: Custom JWT expiry per agent (e.g., 300 for 5-minute tokens).
  • Scopes from policies: JWT scopes are derived from the agent's access policies. If an agent has no policies and no explicit scopes, it has zero access.

Set via dashboard, CLI (--token-ttl, --vault-ids), SDK, or API.

Customer-Managed Encryption Keys (CMEK)

Enterprise opt-in feature (Business tier and above). A human generates a 256-bit AES key in the dashboard — the key never leaves their device. Only its SHA-256 fingerprint is stored on the server.

  • Enable: POST /v1/vaults/{id}/cmek with { fingerprint }
  • Disable: DELETE /v1/vaults/{id}/cmek
  • Rotate: POST /v1/vaults/{id}/cmek-rotate (server-assisted, batched in 100s)
  • Secrets stored in a CMEK vault have cmek_encrypted: true in responses

Agents reading from a CMEK vault receive the encrypted blob. The CMEK key is required to decrypt client-side. This is designed for organizations with compliance requirements — the default HSM encryption is already strong.

Crypto transaction proxy

When crypto_proxy_enabled = true (set by a human):

  1. Agent gains transaction signing via the crypto proxy (keys stay in HSM)
  2. Agent is blocked from reading private_key and ssh_key secrets directly (403)

Default signing key path: keys/{chain}-signer. Override with signing_key_path.

Transaction guardrails

Human-configured, server-enforced limits on what the crypto proxy allows:

GuardrailFieldEffect
Allowed destinationstx_to_allowlistOnly listed addresses permitted. Empty = unrestricted
Max value per txtx_max_value_ethSingle-tx cap in ETH. NULL = unlimited
Daily spend limittx_daily_limit_ethRolling 24h cumulative cap. NULL = unlimited
Allowed chainstx_allowed_chainsChain names. Empty = all chains

Agents cannot modify their own guardrails. Violations return 403 with a descriptive error.


Security Model

  • Credentials are configured by the human, not the agent. The MCP server reads them from env vars.
  • The agent never sees its own credentials. The MCP server authenticates on the agent's behalf.
  • Access is deny-by-default. Even with valid credentials, only policy-allowed secrets are accessible.
  • Secret values are fetched just-in-time and must never be stored, echoed, or included in summaries.
  • Agents cannot create email-based shares (prevents phishing).
  • Crypto proxy is opt-in. When enabled, raw key reads are blocked.
  • Transaction guardrails are human-controlled and server-enforced.

Error Handling

CodeMeaningAction
400Bad requestCheck request body format
401Not authenticatedToken expired — re-authenticate
402Quota exhausted / payment requiredInform user to top up credits or upgrade at 1claw.xyz/settings/billing
403No permissionAsk user to grant access via a policy. Or: guardrail violation (check error detail)
403Resource limit reached (type: "resource_limit_exceeded")Tier limit on vaults/secrets/agents hit — ask user to upgrade at 1claw.xyz/settings/billing
404Not foundCheck path with list_secrets
405Method not allowedWrong HTTP verb for this endpoint
409ConflictResource already exists (e.g. duplicate vault name)
410GoneSecret expired or max access count reached — ask user to store a new version
422Validation error or simulation revertedCheck input. For simulate_first: transaction would revert
429Rate limitedWait and retry. Share creation: 10/min/org

All error responses include a detail field with a human-readable message.


Best Practices

  1. Fetch secrets just-in-time. Call get_secret immediately before the API call that needs the credential.
  2. Never echo secret values. Say "I retrieved the API key and used it" — never include raw values in responses.
  3. Use describe_secret first to check existence or validity before fetching the full value.
  4. Use list_secrets to discover available credentials before guessing paths.
  5. Rotate after regeneration. If you regenerate an API key at a provider, immediately rotate_and_store the new value.
  6. Use grant_access for vault-level sharing — creates a fine-grained policy with path patterns.
  7. Use share_secret for one-off sharing — creates a time-limited, access-counted share link.
  8. Simulate before signing. Always use simulate_first: true (default) or call simulate_transaction before submit_transaction.
  9. Check list_vaults before creating. Avoid creating duplicate vaults.
  10. Handle 402 gracefully. Billing/quota errors should be surfaced to the user, not retried.

Billing Tiers

TierRequests/moVaultsSecretsAgentsPrice
Free1,0003502$0
Pro25,0002550010$29/mo
Business100,0001005,00050$149/mo (+ CMEK)
EnterpriseCustomUnlimitedUnlimitedUnlimitedContact (+ CMEK + KMS delegation)

Overage methods: prepaid credits (top up via Stripe, deducted per request) or x402 micropayments (per-query on-chain payments on Base).

Audit, org, security, chain, billing, and auth endpoints are free and never consume quota.


Links

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

name: 4d-compression-core version: 1.0.2 description: "把长内容压缩成结构化向量——节省 60-80% Token,保留核心信息" metadata: { "openclaw": { "emoji": "🌀", "requires": { "bins": ["jq", "awk"] }, "triggers": ["压缩", "4d",...

日本語の概要は準備中です。原文の説明を表示しています。

modbender/skill-library-mcp162026年9月28日 更新

Use cheap, TEE-verified AI models from the 0G Compute Network as OpenClaw providers. Discover available models and compare pricing vs OpenRouter, verify provider integrity via hardware attestation (Intel TDX), manage your 0G wallet and sub-accounts, and configure models in OpenClaw with one workflow. Supports DeepSeek, GLM-5, Qwen, and other models available on the 0G marketplace.

日本語の概要は準備中です。原文の説明を表示しています。

modbender/skill-library-mcp162026年9月28日 更新

Send and receive P2P messages using disposable numbers and PINs. No servers, no accounts. Use for human notifications, approval flows, and agent-to-agent communication.

日本語の概要は準備中です。原文の説明を表示しています。

modbender/skill-library-mcp162026年9月28日 更新

0xarchive

無料

Query historical crypto market data from 0xArchive across Hyperliquid, Lighter.xyz, and HIP-3. Covers orderbooks, trades, candles, funding rates, open interest, liquidations, and data quality. Use when the user asks about crypto market data, orderbooks, trades, funding rates, or historical prices on Hyperliquid, Lighter.xyz, or HIP-3.

日本語の概要は準備中です。原文の説明を表示しています。

modbender/skill-library-mcp162026年9月28日 更新

0xwork

無料

Find and complete paid tasks on the 0xWork decentralized marketplace (Base chain, USDC escrow). Use when: the agent wants to earn money/USDC by doing work, discover available tasks, claim a bounty, submit deliverables, check earnings or wallet balance, or set up as a 0xWork worker. Task categories: Writing, Research, Social, Creative, Code, Data. NOT for: posting tasks (use the website), managing the 0xWork platform, or frontend development.

日本語の概要は準備中です。原文の説明を表示しています。

modbender/skill-library-mcp162026年9月28日 更新

Patterns and practices that dramatically accelerate development velocity. Covers parallel execution, automation, feedback loops, workflow optimization, and anti-pattern avoidance. Use when starting projects, planning sprints, optimizing workflows, or onboarding developers.

日本語の概要は準備中です。原文の説明を表示しています。

modbender/skill-library-mcp162026年9月28日 更新

modbender のスキルをすべて見る

このスキルの問題を報告する