name: subly-pay description: Fetch a paywalled (HTTP 402) URL and pay for it automatically from the agent wallet's Kamino vault yield, without spending the principal. Also manages the Subly vault (deposit/withdraw) and the human owner's spending mandate (setup link, Face ID approvals). Use when a request returns 402, when the user asks to buy/access a paid API or resource, or mentions Subly / x402 / yield-funded payment. version: 0.2.1 metadata: openclaw: requires: bins: - node - npm primaryEnv: SUBLY_DEMO_AGENT_KEYPAIR_PATH envVars: - name: SUBLY_DEMO_AGENT_KEYPAIR_PATH required: true description: Path to the agent wallet keypair JSON (create with solana-keygen). The private key never leaves this file. - name: SUBLY_RELAYER_URL required: false description: Subly relayer API base URL. Defaults to https://api.demo.sublyfi.com. - name: SOLANA_RPC_URL required: false description: Solana RPC endpoint. Defaults to the public mainnet RPC. - name: SUBLY_MCP_MAX_AMOUNT_RAW_USDC required: false description: Per-payment cap in raw USDC units (6 decimals). Defaults to 10000 (0.01 USDC). emoji: "💸" homepage: https://github.com/SublyFi/subly-payment-protocol
This skill lets you fetch a paid HTTP resource and settle a standard x402
Solana USDC exact 402 challenge automatically. Payment comes from the agent
wallet's Kamino vault yield — the deposited principal is never spent, and
the Subly relayer refuses any payment the spendable yield cannot cover.
Subly does NOT create wallets — bring your own Solana keypair. If
SUBLY_DEMO_AGENT_KEYPAIR_PATH is not set or the wallet has no vault
balance, guide the user through this once:
solana-keygen new --no-bip39-passphrase -o ~/.subly/agent.json
The printed public key is the agent wallet address. The private key
stays in that file — never share or print it.export SUBLY_DEMO_AGENT_KEYPAIR_PATH=~/.subly/agent.jsonnpx -y @subly_fi/pay setup-link --initial-deposit 1010000
Paste the printed setupUrl to the user VERBATIM — it expires in 10
minutes and works once. The human opens it on their phone, reviews the
limits, and confirms with Face ID (passkey) or a Solana wallet signature.
After they say they finished, verify and deposit:
npx -y @subly_fi/pay setup-status <sessionId> (the pasted setupUrl
works as the argument too) → status "completed"
npx -y @subly_fi/pay deposit 1010000 (the pre-approved first deposit
is picked up automatically; deposit also self-registers the wallet).Run the one-shot pay command (no clone — uses the published package via npx) with the resource URL:
npx -y @subly_fi/pay fetch "<url>"
To set a tighter per-call cap (raw USDC, 6 decimals — e.g. 100 = 0.0001 USDC):
npx -y @subly_fi/pay fetch "<url>" 100
The command prints a single JSON object on stdout. On success it contains
"paid": true plus a payment object with amountUsdc, payTo,
paymentId, and solscanUrl (the on-chain receipt). Report the delivered
body and the receipt to the user.
paid: true with a payment block → the resource was delivered and paid.
Show the content and the Solscan link.refused: true with a reason:insufficient_yield → not enough vault yield accrued yet. This is normal;
tell the user to wait (yield accrues over time) — do NOT retry in a loop.amount_exceeds_client_cap → the price exceeds the cap. Only re-run with a
higher cap if the user confirms the price is expected.payment_outcome_unknown → a previous external x402 attempt may already
have settled. Do not blindly re-pay; report the message and ask the user
before using SUBLY_PAY_FORCE_NEW_PAYMENT=1.approval_required → the price exceeds the owner's approval threshold;
NOTHING was paid. The output carries an approveUrl, an approvalId,
and a ready-made retry command: paste the approveUrl to the user, and
once they approved (Face ID / wallet sign), run the retry command
exactly as printed. It repeats the SAME cap — approval-needing prices
exceed the default cap, so dropping it would refuse with
amount_exceeds_client_cap:
npx -y @subly_fi/pay fetch "<url>" <sameMaxAmountRawUsdc> apr_<approvalId>state_persist_failed → the local pending-payment marker could not be
stored. Do not retry until the state path/disk issue is fixed.npx -y @subly_fi/pay deposit <amountRawUsdc> [apr_<approvalId>]npx -y @subly_fi/pay withdraw <amountRawUsdc> [apr_<approvalId>]Deposits move principal into DeFi risk, so they require the human owner's
approval. If the output contains "approvalRequired": true, paste the
approveUrl to the user and retry with the printed apr_... id once they
approved. If it contains "setupRequired": true, run the owner onboarding
(setup-link) from the wallet-setup section first — its initial deposit is
pre-approved by the same single Face ID. Withdrawals are normally automatic
(they exit risk back to the agent wallet); the same approvalRequired flow
applies only when the owner's mandate opts into withdrawal approval.
SUBLY_DEMO_AGENT_KEYPAIR_PATH. Only the public receipt is shared.整体质量良好,文档描述准确完整,风险提示充分到位。主要优点是安全机制设计完善,支付流程清晰易懂,用户能清楚了解每一步操作的后果。不足之处在于初次配置需要理解多个环境变量,对非技术用户有一定门槛,且缺少直观的示例引导。适合有一定技术基础的用户使用。