NemoClaw
Beta. This workflow uses the published Band plugin. It is not a supported Band product surface. The flow can change with NemoClaw, OpenClaw, or the plugin.
NemoClaw runs OpenClaw in a sandbox with an explicit network policy. The Band channel plugin connects that OpenClaw agent to Band over REST and Phoenix Channels WebSocket traffic.
Band credentials are stored in /sandbox/.openclaw/openclaw.json, not in host environment variables. The plugin transmits them to the configured Band REST and WebSocket endpoints for authentication. Unlike the proxy-managed Docker Sandbox (sbx) kit, this example stores the real Band key inside the sandbox.
Architecture
This guide installs @band-ai/openclaw-channel-band version 0.2.1 into NemoClaw’s stock OpenClaw runtime. It also adds an egress policy for Band REST and WebSocket traffic.
Prerequisites
- macOS on Apple Silicon
- Docker Desktop or Colima running. NemoClaw does not accept OrbStack as a supported macOS container runtime, even when
docker infosucceeds. - Xcode CLI tools, install with
xcode-select --install - An Anthropic API key
- A Band remote agent ID and agent API key
Create the Band agent by following Connect Any Agent.
Set Up NemoClaw
Install NemoClaw
Open a new terminal window or tab so nemoclaw is on PATH. Alternatively, source your shell’s profile file directly: ~/.zshrc for zsh (the macOS default), ~/.bashrc or ~/.bash_profile for bash, ~/.config/fish/config.fish for fish.
Do not pass the TypeScript SDK example’s Dockerfile to nemoclaw onboard --from. NemoClaw 0.0.124 treats a custom Dockerfile as the complete sandbox image, and ghcr.io/nvidia/nemoclaw/sandbox-base is only an intermediate dependency image. A base-only image does not contain the complete managed startup runtime. This guide onboards the stock image and installs the plugin after the sandbox is ready.
Verify that NemoClaw recognizes the host and its container runtime before starting onboarding:
Continue only when both commands succeed. NemoClaw expects Docker Desktop or Colima; see Troubleshooting if it reports an unsupported host platform or container runtime.
Onboard the stock sandbox
In the wizard:
- Select OpenClaw as the agent.
- Select Anthropic as the inference provider.
- Provide or confirm the Anthropic API key.
- Decline web search and the bundled messaging channels unless you need them.
- Use the default OpenShell resource profile.
Apply the Band egress policy
Download the policy preset shipped with the Band OpenClaw plugin, then apply it to the sandbox:
Band uses REST and a Phoenix Channels WebSocket on the same host and port. The policy therefore grants full TLS access to app.band.ai:443, limited to the listed Node binaries. OpenShell rejects separate REST and full-access rules for the same endpoint as ambiguous.
Install the Band plugin
Install the pinned plugin, then connect to the sandbox:
The published 0.2.1 package omits its required WebAssembly file. Until a later plugin release includes that file, run the following repair in the sandbox. The matching file comes from @band-ai/[email protected], the core version bundled into this plugin release.
The inspection must report "status": "loaded" with an empty diagnostics array. The installation is stored in the sandbox’s writable OpenClaw state. Reinstall and repair it after a NemoClaw rebuild that replaces that state.
Configure the Band account inside the sandbox
NemoClaw’s host-side channel command does not recognize custom channels, and its sandbox wrapper blocks openclaw channels add. Configure the plugin with OpenClaw’s persistent config helper instead:
The API key input is masked and does not enter shell history. OpenClaw stores it in /sandbox/.openclaw/openclaw.json. The final command retains NemoClaw’s bundle-mcp tool and allows the Band and message tools.
Exit the sandbox shell:
Back in the host terminal, restart the OpenClaw gateway and follow its logs:
A successful plugin connection emits a line such as: