NemoClaw
Run agents inside NVIDIA NemoClaw sandboxes with Nebul as the inference endpoint.
NemoClaw is NVIDIA's open-source reference stack for running AI agents more safely. It puts an agent such as OpenClaw, Hermes, or LangChain Deep Agents inside an OpenShell sandbox, and routes all model traffic through a gateway you control. Pointing that gateway at Nebul means your agent runs on your project's models with EU-resident processing.
Prerequisites
- A supported Linux host or WSL2 installation; see the NemoClaw prerequisites
- A Nebul AI Studio account with API access
- An API key for your active project
- A model ID from the Model Catalog
Installation
Install from your terminal and answer the onboarding prompts. Decline Express to choose the agent and provider yourself:
# follow the installer for your platform from the NemoClaw docs
nemoclaw onboardThe installer offers OpenClaw by default; Hermes and LangChain Deep Agents Code are alternatives. For the full procedure, see the NemoClaw quickstart.
Point it at Nebul
NemoClaw registers inference providers during onboarding. Nebul falls under Other OpenAI-compatible endpoint, the adapter for servers that implement /v1/chat/completions or /v1/responses.
- Run
nemoclaw onboard. - Select Other OpenAI-compatible endpoint.
- Enter the base URL:
https://api.inference.nebul.io/v1 - Enter the model ID:
zai-org/GLM-5.3, or any model your project can access. - When asked for the API key, provide your Nebul key. It's read from the
COMPATIBLE_API_KEYenvironment variable:
export COMPATIBLE_API_KEY=sk-your-api-key-hereBecause api.inference.nebul.io is a public HTTPS endpoint, no private-host trust settings are needed; the loopback-only rules apply to no-auth local servers, not to an authenticated endpoint like Nebul.
For scripted setups, the same steps run non-interactively:
NEMOCLAW_PROVIDER=custom \
NEMOCLAW_ENDPOINT_URL=https://api.inference.nebul.io/v1 \
NEMOCLAW_MODEL=zai-org/GLM-5.3 \
COMPATIBLE_API_KEY="$NEBUL_API_KEY" \
nemoclaw onboard --non-interactiveNemoClaw validates the endpoint, including API, tool-calling, and streaming paths, before it creates the sandbox. If you also want the reasoning effort pinned, NEMOCLAW_REASONING_EFFORT accepts low, medium, or high and is passed through as reasoning_effort on OpenAI-completions routes.
Run it
After onboarding, start or attach to your sandbox and verify the route:
nemoclaw <sandbox-name> statusThe agent inside the sandbox sends its model requests to inference.local, and OpenShell forwards them to Nebul. Usage lands on the API key's project in AI Studio.
Troubleshooting
- Validation fails during onboarding: check the base URL includes
/v1andCOMPATIBLE_API_KEYis exported in the shell runningnemoclaw. model not found: the model ID must exactly match a catalog ID, including vendor prefix and casing.- Traffic blocked at runtime: NemoClaw's network policy controls egress from the sandbox. The managed compatible-endpoint route is registered automatically; see network policies if you customized them.
- Agent behaves oddly on reasoning:
NEMOCLAW_REASONING=truenarrows validation to chat only. Don't enable it unless the endpoint serves a reasoning-only model, since it skips tool-calling and streaming checks.
Data and telemetry
NemoClaw runs on your host and in local containers. Model traffic goes only to the endpoint you configure, and its network policies control what leaves the sandbox at all. See the NemoClaw security docs for the controls and hardening options.
For how Nebul treats the requests it receives, see Privacy & Security.