AI Agent Hub
Back to skills
IdentyClaw HOLA Mutual Authentication Assistant icon

IdentyClaw HOLA Mutual Authentication Assistant

AI Agent Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md and install @user_15292d5a/yjkj-identyclaw.

About this skill

Problem

When two agents need to prove identity to each other, local signatures and chat context are not enough: they need a verifiable Passport identity, short-lived session credentials, and HOLA messages that can resist replay and forgery. The IdentyClaw skill turns the HTTP API workflow into a practical agent flow: get a JWT, create or verify HOLA messages, and resolve tokenId, DID, or public agent details.

How it works

  • Credential model: the Passport signing key (accountid and nearPrivateKey) signs locally; the JWT protects API routes and lasts about one hour.
  • Core loop: log in for jwt_token; fetch a fresh nonce before creating outbound HOLA; verify inbound HOLA with POST /api/identity/verify, which checks format, checksum, freshness, nonce replay, token status, and on-chain signature.
  • Identity resolution: after a successful check, read peerTokenId, then query full DN, contactUri, and traits; resolve did:rodit:{tokenId} when needed.
  • Unknown-agent contact: verify first, then lookup, compare the official Passport ID, and check signer authorization when delegation is present.

Limits

This skill targets IdentyClaw Passport holders and HOLA mutual authentication. It does not mint Passports, manage general wallets, or replace business-level trust policies. A successful protocol check still requires official-channel validation and any project-specific allowlist.

Use Cases

  • Before replying to an external agent, validate the incoming HOLA for freshness, nonce replay, and signature checks in an IdentyClaw integration.
  • In an OpenClaw gateway, build and sign outbound HOLA messages locally instead of manually assembling curl calls and nonce handling.
  • After receiving an unknown agent's HOLA, resolve peerTokenId to DN, contactUri, and traits, then compare the official Passport ID.
  • When a subagent acts on behalf of another agent, check the delegated signer authorization after HOLA verification and record the result.

Best For

  • Identity engineers adding external agent auth to OpenClaw gateways, who need to wrap HOLA creation and verification in typed tools.
  • Security reviewers auditing agent trust, who need to confirm inbound HOLA passes freshness, nonce replay, and on-chain signature checks.
  • Integration engineers automating cross-agent workflows, who need JWT login and resolution of peerTokenId to full DN and contactUri.
  • Engineers maintaining subagent authorization flows, who need to check delegated signer validity after primary HOLA verification.