NemoClaw integration
On this page
NemoClaw can expose Unfenced's remote MCP tools to its sandboxed agent. Register the connection through NemoClaw on the host so OpenShell manages the credential and endpoint policy.
Before you start
You need a running NemoClaw sandbox, a version supporting managed MCP, and an Unfenced API key from the dashboard. The example uses my-sandbox; substitute your sandbox's name.
Add Unfenced from the host
In Bash, read the key without writing it into shell history, then register the server:
read -rsp "Unfenced API key: " UNFENCED_TOKEN
printf '\n'
export UNFENCED_TOKEN
nemoclaw my-sandbox mcp add unfenced \
--url https://unfenced.ai/api/mcp \
--env UNFENCED_TOKEN
unset UNFENCED_TOKEN
nemoclaw my-sandbox mcp status unfencedRun this on the host, not in the sandbox. Pass the variable name to --env, never UNFENCED_TOKEN=YOUR_KEY. OpenShell stores the credential; the agent configuration receives a resolver placeholder. Unsetting the host variable afterward does not remove the stored credential.
Check the connection
Inspect the managed status for provider, policy, and adapter readiness. Registration can finish even when its probe is skipped or inconclusive; that is not proof of a working connection. Resolve any reported readiness problem before testing an agent call.
Use the managed status probe rather than a curl command inside the sandbox. The generated network policy is scoped to the agent adapter and may refuse an interactive shell tool.
Try your first fetch
In your sandbox agent's normal conversation, ask:
Use Unfenced fetch_page to read https://example.com.
Summarize the page and include its source URL.Confirm an Unfenced tool call returns content from Example Domain.
If it does not connect
- No managed MCP command: check your NemoClaw release and installed runtime.
- Endpoint or policy denied: inspect
nemoclaw my-sandbox mcp status unfencedand the reported policy issue. - Unauthorized: check the Unfenced key; use NVIDIA's documented credential-rotation procedure to replace the stored credential.
- Registration ready but no tools: inspect the selected agent adapter and start a fresh agent turn.
What to try next
Read JavaScript websites or authenticated pages. NVIDIA documents adding a managed MCP server and managing or rotating it.
Configuration reviewed: 2026-10-04. Check the connection in your client before relying on it.