lnd-macaroon-bakery
Bake, inspect, and manage lnd macaroons for least-privilege agent access.
Setup & Installation
Install command
clawhub install roasbeef/lnd-macaroon-bakeryIf the CLI is not installed:
Install command
npx clawhub@latest install roasbeef/lnd-macaroon-bakeryOr install with OpenClaw CLI:
Install command
openclaw skills install roasbeef/lnd-macaroon-bakeryor paste the repo link into your assistant's chat
Install command
https://github.com/openclaw/skills/tree/main/skills/roasbeef/lnd-macaroon-bakeryWhat This Skill Does
Bakes scoped lnd macaroons so each agent receives only the permissions it needs. Supports preset roles (pay-only, invoice-only, read-only, channel-admin, signer-only) and custom URI-level permission sets. Works with local nodes, Docker containers, and remote lnd instances.
Baking per-role macaroons eliminates the need to distribute admin.macaroon, reducing blast radius if any single agent credential is compromised.
When to Use It
- Issuing pay-only credentials to a payment bot without exposing channel management
- Giving a billing service invoice-only access to create and look up invoices
- Scoping signer credentials on a dedicated remote signing node
- Rotating a macaroon after a suspected credential leak
- Auditing what permissions an existing macaroon grants before deployment
Example Workflow
Here's how your AI assistant might use this skill in practice.
User asks: Issuing pay-only credentials to a payment bot without exposing channel management
- 1Issuing pay-only credentials to a payment bot without exposing channel management
- 2Giving a billing service invoice-only access to create and look up invoices
- 3Scoping signer credentials on a dedicated remote signing node
- 4Rotating a macaroon after a suspected credential leak
- 5Auditing what permissions an existing macaroon grants before deployment
Bake, inspect, and manage lnd macaroons for least-privilege agent access.
Security Audits
These signals reflect official OpenClaw status values. A Suspicious status means the skill should be used with extra caution.
Similar Skills
VIEW ALLairfrance-afkl
Track Air France flights using the Air France–KLM Open Data APIs.
idfm-journey-skill
Query Île-de-France Mobilités (IDFM) PRIM/Navitia.
charger
Check EV charger availability (favorites, nearby search) via Google Places.
sholat
Ambil jadwal sholat (imsak, subuh, dzuhur, ashar, maghrib, isya) untuk kota/kabupaten di Indonesia dari API Muslim.