All skills
aws avatar

/agents-pay

@9766f27

Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits. Covers payment setup, policy, session budgets, and troubleshooting. Triggers on: "my agent hit a 402 while calling an API", "a tool call returned 402 Payment Required", "my agent needs to pay for x402-protected content", "let the agent pay for content, capped at $5 per session", "set a spend limit for the agent", "ProcessPayment failed", or "why did my agent refuse to pay". Not for BUILDING payment capability for end users, including wallets and framework middleware; use agents-build and references/payments.md. For non-paid APIs via Gateway use agents-connect. For inbound auth use agents-harden. For project scaffolding use agents-get-started.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/agents-pay

This session only. Nothing lands on disk.

packagesopenclawREADME.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

AWS Agents Pay for OpenClaw

The @aws/aws-agents-pay OpenClaw plugin performs guarded x402 v2 payments through AWS AgentCore Payments. It exposes two runtime tools:

  • get_payment_session_status checks an operator-provisioned session.
  • get_paid_content pays an approved HTTPS resource and returns response metadata and a SHA-256 body digest, never the signed proof or paid body.

Install from ClawHub:

openclaw plugins install clawhub:@aws/aws-agents-pay

Getting started

After installation, provision AWS resources and configure the plugin before activation. The fastest path is to ask your agent to walk you through it:

Ask OpenClaw: "help me set up the agents-pay skill"

This drives the bundled skill's interactive setup wizard end-to-end — it prompts for AWS credentials, network, recipients, and spend limits, then provisions the payment instrument and session for you.

If you'd rather run it yourself, or want to see the raw steps first, open skills/agents-pay/SKILL.md directly (there is no openclaw skills read command — use openclaw skills info agents-pay once the skill is installed/staged, or just open the file). For OpenClaw-specific configuration, see skills/agents-pay/references/openclaw-setup.md.

The package bundles the canonical agents-pay skill. It guides users through human-run setup in a separate terminal while the plugin keeps only the two runtime payment tools model-visible.

The plugin accepts an unconfigured installation state so OpenClaw can load the bundled skill before setup. The payment tools validate the complete trusted configuration when invoked and fail closed while it is absent or incomplete.

The plugin keeps policy validation and paid HTTP replay in TypeScript. It uses the package-local Python virtual environment created during setup for only GetPaymentSession and ProcessPayment, through a fixed helper path with no shell. This preserves the standard boto3 AWS credential chain without adding the JavaScript AgentCore SDK to the runtime dependency graph.

The runtime requires an existing payment manager, instrument, user, and session. It cannot provision payment infrastructure or create replacement sessions. Configure approved origins, a recipient mode, networks, assets, and a positive per-payment ceiling before enabling the payment tool.

Required configuration:

  • paymentManagerArn, paymentInstrumentId, payment_session_id, and userId
  • Exactly one recipient mode: allowedRecipients, or the explicit high-risk allowAnyRecipient: true
  • Optional allowedOrigins and networkPreferences
  • allowedAssetsByNetwork for exact network-to-asset policy
  • maxPaymentAmountAtomic — required, no default. Set this to the maximum amount the agent may spend in a single payment, in the asset's smallest unit (e.g. "100000" = 0.10 USDC at 6 decimals). This is the PER-PAYMENT ceiling; it is not a substitute for the session budget, which caps cumulative spend.
  • Optional returnBody (boolean, default unset/false). When true, get_paid_content returns the actual paid response body (capped at 10 KiB, marked untrusted: true) instead of metadata only. Leave this unset unless you have deliberately decided to accept the risk: unsanitized paid content may contain prompt injection aimed at the agent. See "Content isolation" in references/security-model.md for the full tradeoff. This is a separate, TypeScript-runtime-only setting from the Python x402_fetch.py path's return_body policy field — set both if you run both runtimes and want consistent behavior.

The manifest accepts either an unconfigured installation or the complete configuration listed above. Partial payment configuration is rejected. Both tools fail closed unless every required field is present in trusted plugin settings or the protected ~/.x402/config.json file.

allowAnyRecipient delegates beneficiary choice to the publisher. It is mutually exclusive with allowedRecipients and does not relax origin, network, asset, per-payment, or cumulative session limits.

Hard boundary: sessions are human-only

Payment sessions are created outside the agent loop by a human operator using the AWS CLI or console — never inside an OpenClaw conversation. The plugin exposes no tool to create, extend, or replace a session. If a session expires or drains, the operator must create a new one and update the config; the agent cannot self-authorize continued spending.

This is by design: the payment_session_id in config is a spending credential that names the budget being drawn down. Keeping session creation out of the agent's reach means a compromised or manipulated agent cannot point itself at a larger budget.

Provision infrastructure and create the bounded session outside the model-facing runtime. Use separate administration and runtime IAM roles, and never put CDP or Privy credentials in prompts, tool arguments, transcripts, or plugin config.

References:

Source: SKILL.md on GitHub

1 alert1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a secure framework for AI agents to settle x402-protected payment challenges using AWS AgentCore. It includes robust security measures such as SSRF protection, strict IAM role separation, and content isolation to prevent prompt injection from paid external resources.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: CRITICAL · 3 issues

Signed by skilld at 9766f27. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "type": "skill",
  "version": "1.0.0",
  "author": "aws-agentcore"
}
All 1 allowed tools
Read Bash

README badge

README badge for aws/agent-toolkit-for-aws/agents-pay