Skip to content
unfenced.ai

NemoClaw integration

On this page

NemoClaw can expose Unfenced's remote MCP tools to its sandboxed agent. Register the connection through NemoClaw on the host so OpenShell manages the credential and endpoint policy.

Before you start

You need a running NemoClaw sandbox, a version supporting managed MCP, and an Unfenced API key from the dashboard. The example uses my-sandbox; substitute your sandbox's name.

Add Unfenced from the host

In Bash, read the key without writing it into shell history, then register the server:

Terminal
read -rsp "Unfenced API key: " UNFENCED_TOKEN
printf '\n'
export UNFENCED_TOKEN

nemoclaw my-sandbox mcp add unfenced \
  --url https://unfenced.ai/api/mcp \
  --env UNFENCED_TOKEN

unset UNFENCED_TOKEN
nemoclaw my-sandbox mcp status unfenced

Run this on the host, not in the sandbox. Pass the variable name to --env, never UNFENCED_TOKEN=YOUR_KEY. OpenShell stores the credential; the agent configuration receives a resolver placeholder. Unsetting the host variable afterward does not remove the stored credential.

Check the connection

Inspect the managed status for provider, policy, and adapter readiness. Registration can finish even when its probe is skipped or inconclusive; that is not proof of a working connection. Resolve any reported readiness problem before testing an agent call.

Use the managed status probe rather than a curl command inside the sandbox. The generated network policy is scoped to the agent adapter and may refuse an interactive shell tool.

Try your first fetch

In your sandbox agent's normal conversation, ask:

Agent prompt
Use Unfenced fetch_page to read https://example.com.
Summarize the page and include its source URL.

Confirm an Unfenced tool call returns content from Example Domain.

If it does not connect

  • No managed MCP command: check your NemoClaw release and installed runtime.
  • Endpoint or policy denied: inspect nemoclaw my-sandbox mcp status unfenced and the reported policy issue.
  • Unauthorized: check the Unfenced key; use NVIDIA's documented credential-rotation procedure to replace the stored credential.
  • Registration ready but no tools: inspect the selected agent adapter and start a fresh agent turn.

What to try next

Read JavaScript websites or authenticated pages. NVIDIA documents adding a managed MCP server and managing or rotating it.

Configuration reviewed: 2026-10-04. Check the connection in your client before relying on it.

Request accessSign in