If you run more than one OpenClaw agent — or agents that talk to peers outside your VPC — you have probably felt the friction: every instance needs its own API keys, every redeploy breaks hard-coded webhook URLs, and sessions_send alone cannot prove who sent a message.

IdentyClaw Passport adds a portable trust layer on top of OpenClaw: a stable 12-letter tokenId, mutual authentication (HOLA) on whatever channel already carries messages, and three complementary wire surfaces — A2A, webhooks, and the IdentyClaw API.

This guide is the operator walkthrough we wished existed when we wired our first multi-tenant fleet. It goes deeper than the marketing site and assumes you already run (or plan to run) an OpenClaw gateway.

What you get after onboarding

Capability