Hermes and OpenClaw
Run Thirdfy from a Hermes or OpenClaw agent runtime with the Agent CLI. Install, secrets, startup checks, and the commands each cycle runs.
Hermes and OpenClaw agents run shell commands, so the Agent CLI is the simplest way to give them Thirdfy. Every command returns JSON the agent can read, and the same commands work in a cron job.
The shortcut: give your agent this prompt and it sets itself up on the CLI path.
1. Get the agent's keys once
On your own machine, sign in by email once:
You need two values for the runtime:
| Secret | Where to find it |
|---|---|
THIRDFY_AGENT_API_KEY | The agent API key (agent-...), saved in ~/.thirdfy/config.json under agent.apiKey |
THIRDFY_AGENT_KEY | The agent's 0x address, shown by whoami as agent.agentKey |
Store both in the runtime's secrets, never in prompts or skill files.
2. Install the CLI in the runtime
Pin the version, so a CLI release never changes your agent under you:
Set the environment before the runtime starts:
With these set, the runtime needs no saved login. If THIRDFY_AGENT_KEY is missing, runs fail with MISSING_USER_DID.
3. Check at startup
doctor certify execution checks the CLI version and command set without writing anything. Stop the runtime if it fails.
4. What the agent runs each cycle
Read success, code and data from each response. Continue to a write only when venue readiness says ready: true. Use a stable --idempotency-key per decision, so a retried cycle does not place the order twice.
Hermes
- Provision the environment above before the Hermes dashboard or runtime starts.
- Run the startup checks as part of the runtime's health check.
- Use
agent_walletfor the agent's own wallet. Switch tothirdfyonly for fan-out to delegated wallets.
OpenClaw
- Keep both secrets in OpenClaw's runtime secrets.
- Have the agent call
thirdfy-agent actions --provider <id>before it plans, so it only uses actions it may call. - Use
agent_walletfor own-wallet actions. Useselfonly when local signing is configured. Usehybridorthirdfyonly after delegation is ready.
OpenClaw can also connect over MCP instead: see OpenClaw and Hermes (MCP).
Hosted on EarnOrg
Runtimes hosted on EarnOrg also set THIRDFY_EXECUTION_RUNTIME_ID and THIRDFY_EXECUTION_ORG_ID. The CLI sends them with every write, so credits and history are attributed to the right runtime and organization.
Troubleshooting
| Error | Fix |
|---|---|
MISSING_USER_DID | Set THIRDFY_AGENT_KEY to the agent's 0x address |
401 / auth errors | Check THIRDFY_AGENT_API_KEY is set in the runtime, not only on your machine |
DAILY_FREE_LIMIT_EXCEEDED | Free requests are used up; top up at thirdfy.com/credits |
blockingReasons from venue readiness | Fund or set up the venue first. See the venue's integration page |