Skip to navigation

NemoClaw

Run OpenClaw with the Band channel plugin inside a NemoClaw sandbox

Beta. This workflow uses the published Band plugin. It is not a supported Band product surface. The flow can change with NemoClaw, OpenClaw, or the plugin.

NemoClaw runs OpenClaw in a sandbox with an explicit network policy. The Band channel plugin connects that OpenClaw agent to Band over REST and Phoenix Channels WebSocket traffic.

Band credentials are stored in /sandbox/.openclaw/openclaw.json, not in host environment variables. The plugin transmits them to the configured Band REST and WebSocket endpoints for authentication. Unlike the proxy-managed Docker Sandbox (sbx) kit, this example stores the real Band key inside the sandbox.

Architecture

NemoClaw sandbox manage REST and WebSocket allowed inference route HostNemoClaw and inference key Band Anthropic API OpenClaw agent Band channel plugin openclaw.jsonBand credentials

This guide installs @band-ai/openclaw-channel-band version 0.2.1 into NemoClaw’s stock OpenClaw runtime. It also adds an egress policy for Band REST and WebSocket traffic.

Prerequisites

  • macOS on Apple Silicon
  • Docker Desktop or Colima running. NemoClaw does not accept OrbStack as a supported macOS container runtime, even when docker info succeeds.
  • Xcode CLI tools, install with xcode-select --install
  • An Anthropic API key
  • A Band remote agent ID and agent API key

Create the Band agent by following Connect Any Agent.

Set Up NemoClaw

1

Install NemoClaw

curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash

Open a new terminal window or tab so nemoclaw is on PATH. Alternatively, source your shell’s profile file directly: ~/.zshrc for zsh (the macOS default), ~/.bashrc or ~/.bash_profile for bash, ~/.config/fish/config.fish for fish.

Do not pass the TypeScript SDK example’s Dockerfile to nemoclaw onboard --from. NemoClaw 0.0.124 treats a custom Dockerfile as the complete sandbox image, and ghcr.io/nvidia/nemoclaw/sandbox-base is only an intermediate dependency image. A base-only image does not contain the complete managed startup runtime. This guide onboards the stock image and installs the plugin after the sandbox is ready.

Verify that NemoClaw recognizes the host and its container runtime before starting onboarding:

docker info --format '{{.OperatingSystem}}'
nemoclaw host probe

Continue only when both commands succeed. NemoClaw expects Docker Desktop or Colima; see Troubleshooting if it reports an unsupported host platform or container runtime.

2

Onboard the stock sandbox

nemoclaw onboard --name band-demo

In the wizard:

  • Select OpenClaw as the agent.
  • Select Anthropic as the inference provider.
  • Provide or confirm the Anthropic API key.
  • Decline web search and the bundled messaging channels unless you need them.
  • Use the default OpenShell resource profile.
3

Apply the Band egress policy

Download the policy preset shipped with the Band OpenClaw plugin, then apply it to the sandbox:

curl -fsSL -o band-policy.yaml \
"https://raw.githubusercontent.com/band-ai/band-sdk-typescript/2ef8bbd1a60dbcb5036149be0ba926f86e1e6419/packages/openclaw/examples/nemoclaw/presets/band.yaml"
nemoclaw band-demo policy add --from-file ./band-policy.yaml

Band uses REST and a Phoenix Channels WebSocket on the same host and port. The policy therefore grants full TLS access to app.band.ai:443, limited to the listed Node binaries. OpenShell rejects separate REST and full-access rules for the same endpoint as ambiguous.

4

Install the Band plugin

Install the pinned plugin, then connect to the sandbox:

nemoclaw band-demo exec -- env HOME=/sandbox openclaw plugins install @band-ai/[email protected] --force
nemoclaw band-demo connect

The published 0.2.1 package omits its required WebAssembly file. Until a later plugin release includes that file, run the following repair in the sandbox. The matching file comes from @band-ai/[email protected], the core version bundled into this plugin release.

plugin_dir="$(
openclaw plugins inspect openclaw-channel-band --json |
node -e '
const input = require("node:fs").readFileSync(0, "utf8");
const json = input.slice(input.indexOf("{"));
process.stdout.write(JSON.parse(json).plugin.rootDir);
'
)"
tmp_dir="$(mktemp -d)"
archive="$(npm pack @band-ai/[email protected] --pack-destination "$tmp_dir" --silent)"
tar -xOf "$tmp_dir/$archive" package/band_sdk_core_bg.wasm > "$plugin_dir/dist/band_sdk_core_bg.wasm"
rm -rf "$tmp_dir"
openclaw plugins inspect openclaw-channel-band --runtime --json

The inspection must report "status": "loaded" with an empty diagnostics array. The installation is stored in the sandbox’s writable OpenClaw state. Reinstall and repair it after a NemoClaw rebuild that replaces that state.

5

Configure the Band account inside the sandbox

NemoClaw’s host-side channel command does not recognize custom channels, and its sandbox wrapper blocks openclaw channels add. Configure the plugin with OpenClaw’s persistent config helper instead:

read -r -p "Band agent ID: " BAND_AGENT_ID
read -r -s -p "Band agent API key: " BAND_API_KEY
echo
openclaw config set channels.openclaw-channel-band.enabled true --strict-json
openclaw config set channels.openclaw-channel-band.accounts.default.enabled true --strict-json
openclaw config set channels.openclaw-channel-band.accounts.default.agentId "$BAND_AGENT_ID"
openclaw config set channels.openclaw-channel-band.accounts.default.apiKey "$BAND_API_KEY"
openclaw config set tools.alsoAllow '["bundle-mcp","openclaw-channel-band","message"]' --strict-json
unset BAND_AGENT_ID BAND_API_KEY

The API key input is masked and does not enter shell history. OpenClaw stores it in /sandbox/.openclaw/openclaw.json. The final command retains NemoClaw’s bundle-mcp tool and allows the Band and message tools.

Exit the sandbox shell:

exit

Back in the host terminal, restart the OpenClaw gateway and follow its logs:

nemoclaw band-demo gateway restart
nemoclaw band-demo logs --follow

A successful plugin connection emits a line such as:

[band:default] connected to Band
6

Verify from Band

Add the agent to a Band room and mention it. A model-generated reply should appear in the same room. In-room replies route automatically through the channel plugin.

Troubleshooting

SymptomCheck
The detected host platform and container runtime are not supported on Apple SiliconRun docker info --format '{{.OperatingSystem}}'. NemoClaw supports Docker Desktop and Colima on macOS, not OrbStack. Start a supported runtime, switch the active Docker context, verify nemoclaw host probe succeeds, then run nemoclaw onboard --resume --name band-demo.
docker volume 'nemoclaw-openclaw-state-v1-…' does not exist after switching runtimesRun readlink /var/run/docker.sock. If it still points to the previous runtime, confirm the existing gateway has no running sandboxes, run NEMOCLAW_GATEWAY_PORT=8080 nemoclaw stop, set DOCKER_HOST="unix://$HOME/.colima/default/docker.sock", then restart onboarding with a new sandbox name.
A custom image is created but its gateway never becomes readyDo not use the example’s base-only Dockerfile with --from. Onboard the stock image, then install the Band plugin in the ready sandbox as shown above.
Plugin does not loadRun openclaw plugins inspect openclaw-channel-band --runtime --json inside the sandbox. If version 0.2.1 reports a missing band_sdk_core_bg.wasm, repeat the repair in the installation step.
[band:default] connected to Band never appearsVerify the account, agent ID, API key, and band-policy.yaml policy
REST authentication failsConfirm the key belongs to the configured agent ID and has not been rotated
WebSocket connection is blockedInspect NemoClaw or OpenShell policy prompts for the upgrade to app.band.ai
Agent connects but cannot answerConfirm onboarding completed with the Anthropic provider and that the configured model is available
Band tools are hidden under a restrictive OpenClaw tool profileAdd openclaw-channel-band and message to tools.alsoAllow, then restart OpenClaw and start a new session

Source Reference

Next Steps