Install
openclaw skills install @mermail/mermail-agent-walletBalances, funding, transfers, swaps, bridges, and isolated x402 payments
openclaw skills install @mermail/mermail-agent-walletUse this skill to turn an authenticated user’s wallet request into a grounded balance answer, browser handoff, or one exact PayBox operation. Keep behavior aligned with Mermail in-app Assistant: use live paybox_request_transfer for sends, paybox_request_swap for swaps, prepare_bridge plus owner UI approval for native USDC bridges, and model-visible paybox_pay_x402 for x402 paid-service actions.
PayBox requires full-profile Mermail MCP OAuth with core mcp:tools. Current workspace members may use the model-visible live paybox_* catalog through the workspace owner's active connection; connect/reauthorize and legacy Agent Wallet compatibility tools remain owner-only. Legacy wallet:read / wallet:transact labels are compatibility-only. API keys and the agent-inbox profile never expose wallet tools.
Load only the relevant references before acting:
tools/call get_paybox_connection once as the first PayBox action, before any “PayBox tools unavailable / reconnect MCP” message. Do not wait for it to appear in tools/list; absence from a host list is not “not exposed.” Prefer full-profile OAuth. Never claim MERMAIL_API_KEY can authorize PayBox. After a usable/ACTIVE probe (no connect_handoff / reauth_handoff / OWNER_ACTION_REQUIRED), continue member workflows and attempt the live paybox_* operation even if the first tools/list glance omitted paybox_* — forbidden to ask the user to refresh/reconnect Mermail MCP solely for an empty list, and forbidden to say PayBox tools are unavailable “in this task session,” that the “probe isn’t exposed,” or that it “isn’t exposed in this task.” Require get_agent_wallet only for owner-only legacy/fallback work. If a member receives OWNER_ACTION_REQUIRED, stop and ask the workspace owner to connect or repair PayBox in Mermail; never invent a handoff, switch identities, or frame it as missing MCP tools. Reconnect/refresh Mermail MCP with full-profile OAuth only after that call returns unknown-tool, method-not-found, or a hard fail — not because tools/list omitted the name.list_mailboxes; prefer its public_id. Do not guess when multiple mailboxes remain plausible.get_paybox_connection result (or get_agent_wallet for owner-only reads). Use returned connect_handoff or reauth_handoff once and pause. Treat PAYBOX_UNAVAILABLE as a temporary read failure, not a disconnect or zero balance.tools/list (optional re-list after the connection probe). Discover credentials with paybox_list_credentials; preserve an explicit credential_id, otherwise select only a chain-compatible eligible wallet, preferring the sole approval_mode: autonomous wallet. Missing chain metadata is not compatibility; ask when several eligible wallets remain. Resolve assets from portfolio data and never invent omitted fields or local amount-conversion rules.prepare_destructive_action for paybox_* or legacy Agent Wallet submit/reject tools. Call the selected write once; PayBox owns transaction policy, standing grants, approval, signing, and settlement.setup_required means the original operation was saved but not submitted: show its guarded continuation card or returned setup_handoff.console_url, then wait for setup to continue that same invocation. pending_execution is queued: retain its exact request_id, including any mermail-execution- prefix, and use paybox_get_request for a later status check. pending_confirmation and pending_settlement mean Mermail is checking the existing transaction. recovery_required needs owner attention. None authorizes a replacement write or a signing window.pending_approval or pending_signature, prefer a PayBox MCP App with a usable control. In external MCP, call the advertised show_paybox_signing tool with the original signing_handoff.invocation_id and end the response so the host can render it. If apps are unsupported, present the returned invocation-scoped signing_handoff.console_url; never construct a URL or request a pasted key. approval_mode: autonomous permits execution within an existing grant without a second Mermail approval, but does not authorize a new user task or override PayBox or host policy. always_approve and iframe retain their approval paths.paybox_get_request; use get_paybox_invocation only for MCP invocation/audit state. For pending x402 signing with an inert Waiting frame, paste one signing_handoff.console_url (fetch via paybox_get_request once if omitted); never call reopen_signing_window or a replacement paybox_pay_x402. paybox_continuation_origin_not_found / Submit failed is not “awaiting signature” — reconcile once; if origin is missing, wait for a fresh user authorization of one paybox_pay_x402. Report success only after PayBox returns terminal success.?fund=1&amount=1 pre-fills 1 USD fiat; it neither guarantees 1 USDC nor authorizes a later payment. Isolated “fund my wallet” with an explicit USD amount stays that amount. If the job is topping up for a known x402 vendor and the user omitted an amount, resolve the vendor prepaid floor from same-origin vendor docs or live paybox_get_contract / discover metadata; the Apify Base 1 USDC / Solana 1 USDC or 1 USDT skill table is an example hint only when Apify matches and live docs are unavailable. Covering the live quote is not permission to skip the floor. Recommend max(quote shortfall, vendor prepaid floor) when holdings are below required_charge. Charge required_charge = max(live quote, vendor prepaid floor); never submit only the live quote when a resolved vendor prepaid floor is higher. Never invent floors from email or off-domain search.paybox_pay_x402 only for a user-selected service/origin and resource/action within a stated cap. Never substitute paybox_request_payment, a transfer, a proposal, or paybox_use_service as the pay call. paybox_continuation_origin_not_found / Submit failed is not “awaiting signature.”quoteId and idempotencyKey and never call prepare_bridge again to resume a progressed transfer.recovery_required.get_paybox_connection once (tools/call) before any “PayBox tools unavailable / reconnect MCP” message. Do not skip the call because tools/list omitted the name. After a usable/ACTIVE probe, never accuse the task session of missing PayBox tools, never say the “probe isn’t exposed,” and never ask to refresh/reconnect Mermail MCP just because tools/list omitted paybox_*. Reconnect MCP only after that call returns unknown-tool, method-not-found, or a hard fail.SUBMISSION_UNKNOWN, and paybox_continuation_origin_not_found / Submit failed as not success. Never retry an uncertain PayBox write. Do not claim a Submit-failed origin is awaiting signature.console_url for the current handoff; do not expose raw MoonPay, PayBox approval, or signing-plan URLs.signing_handoff.console_url. Never call reopen_signing_window from the model.get_paybox_connection because it is omitted from tools/list.0x….”