ironclaw

NEAR AI·NearAI.IronClaw

Unleash Your AI Agent, With Peace of Mind

IronClaw is the secure, open-source alternative to OpenClaw that runs in encrypted enclaves on NEAR AI Cloud. AI agents that actually do things, but your secrets never touch the LLM. Philosophy IronClaw is built on a simple principle: your AI assistant should work for you, not against you. In a world where AI systems are increasingly opaque about data handling and aligned with corporate interests, IronClaw takes a different approach: - Your data stays yours - All information is stored locally, encrypted, and never leaves your control - Transparency by design - Open source, auditable, no hidden telemetry or data harvesting - Self-expanding capabilities - Build new tools on the fly without waiting for vendor updates - Defense in depth - Multiple security layers protect against prompt injection and data exfiltration IronClaw is the AI assistant you can actually trust with your personal and professional life. Features Security First - WASM Sandbox - Untrusted tools run in isolated WebAssembly containers with capability-based permissions - Credential Protection - Secrets are never exposed to tools; injected at the host boundary with leak detection - Prompt Injection Defense - Pattern detection, content sanitization, and policy enforcement - Endpoint Allowlisting - HTTP requests only to explicitly approved hosts and paths Always Available - Multi-channel - REPL, HTTP webhooks, WASM channels (Telegram, Slack), and web gateway - Docker Sandbox - Isolated container execution with per-job tokens and orchestrator/worker pattern - Web Gateway - Browser UI with real-time SSE/WebSocket streaming - Routines - Cron schedules, event triggers, webhook handlers for background automation - Heartbeat System - Proactive background execution for monitoring and maintenance tasks - Parallel Jobs - Handle multiple requests concurrently with isolated contexts - Self-repair - Automatic detection and recovery of stuck operations Self-Expanding - Dynamic Tool Building - Describe what you need, and IronClaw builds it as a WASM tool - MCP Protocol - Connect to Model Context Protocol servers for additional capabilities - Plugin Architecture - Drop in new WASM tools and channels without restarting Persistent Memory - Hybrid Search - Full-text + vector search using Reciprocal Rank Fusion - Workspace Filesystem - Flexible path-based storage for notes, logs, and context - Identity Files - Maintain consistent personality and preferences across sessions

winget install --id NearAI.IronClaw --exact --source winget

Latest 1.4.0·August 28, 2026

Release Notes

Release Notes Stable promotion of 1.4.0-rc.1, covering the 81 commits since ironclaw-v1.3.0 and the complete release-candidate scope below. Added

  • Durable notification inbox: runs publish authoritative outcomes and actionable gates to a per-user inbox, surfaced by the WebUI notification center, so approvals and auth prompts survive a missed session.
  • Background subagents: a parent turn can spawn children that run and deliver on their own, with per-child delivery, activation provenance, a derived cap on autonomous wakes, and healing sweeps for orphaned children.
  • Persistent per-user sandbox containers on the local-Docker profile, reached over Docker Exec so container-local installs and state survive between commands. The Railway preview profile still runs an ephemeral worker per command and keeps only its checkpointed workspace.
  • Managed per-user sandbox egress proxy, with manifest-declared direct-exec credential bindings that stay behind it so secrets are never handed to sandboxed code.
  • Run-now for automations, plus exact run capability facts.
  • Durable backend suggestions generated over the user's own no-approval, read-only tools and gated on connected extensions.
  • Google Docs semantic editing tools; run timing evidence in downloadable conversation artifacts.
  • Opt-in in-worker SSH in the runtime image (see Operators below). Fixed
  • Structured finalization stalls are bounded, and OpenAI-compatible reasoning-only responses are preserved.
  • Provider failures and auth diagnostics reach the model as readable context instead of opaque errors.
  • libSQL write-lane starvation no longer cascades through the resource governor as unrelated tool failures.
  • Telegram separates workspace-bot pairing from personal device linking, and keeps paired channels ready while collapsing streaming reply drafts.
  • Slack delivers the unlinked-user connect nudge privately with a one-click connect link.
  • Installation state written by 1.2.x is accepted and preserved, so a deployment that skipped 1.3 upgrades directly.
  • Incremental compaction summary context is preserved. Operators
  • The runtime image can start an in-worker SSH listener. It is off unless IRONCLAW_REBORN_SSH_PUBLIC_KEY is set to an OpenSSH public key, which enables public-key-only login as user agent on container port 2222; that port must be published to be reachable. agent shares uid 1000 with the ironclaw runtime user, so an SSH session holds the full runtime identity -- treat the private key like shell access to the service.
  • IRONCLAW_REBORN_WORKSPACE_ROOT is honored on both CLI boot paths. Neither it nor IRONCLAW_REBORN_HOME may be set to the filesystem root.
  • New sandbox knobs: IRONCLAW_REBORN_SANDBOX_PROXY_IMAGE and IRONCLAW_SANDBOX_EXTRA_ALLOWED_DOMAINS. Upgrading No migration steps from 1.3.0.

Installer type: wix

x64—25836062C21994C9B38377F42208EB709A61A0EEDC9161B0A06AE4AAC8AE630C

Details

Homepage
https://www.ironclaw.com/
License
Apache-2.0 or MIT
Publisher
NEAR AI
Support
https://github.com/nearai/ironclaw/issues
Privacy Policy
https://near.ai/privacy-policy
Copyright
Copyright (c) 2026 NEAR AI

Tags

agentagenticaichatbotclawlarge-language-modelllm

Older versions (27)

1.3.0
x64—7C4B48B29F95B1FE3B501056F8D07FAD96B16F90C893B5364B66A4FACF108ECD
1.2.0
x64—BB3001C5F0BE06878667A3D311CDFDF60BF8CBF576D02FEC293A558A827268C5
1.1.0
x64—26895B7E2CDA5A9BA5F4F1055DA40D1901B67552164B4E24223A82E39F7633F3
1.0.0-rc.1
x64—D41430531CEEC3D297D9DD5712E9F91A4D0E9EAB0F67C3355E522E510115950E
1.0.0
x64—A1B9AF9AE890AE2C5B6875DDD4A8267129ABC7A8803A6D315482F28E109A64DD
0.29.1
x64—4F3A17248C46E74D202D30975D4775C2EFFA2BC0D45F44E45EC443C1EBFD5DEA
0.29.0
x64—C930041E56161A8D7511C82F0E233EB8589A1AA24C77B14505F6E7451D716963
0.28.2
x64—FAAEBE88848CF1F9D63C2278CE6D4C3686FB386A47FB7EA8E67FEE4691FF9BAB
0.28.1
x64—3698892A8E06F810B0436B3FF88DED3F531790F097F56510231CFEC01B216DD4
0.28.0
x64—AA5A4ED9AE5925848FDC23E056EBAD4C8FA2542E19F1967C5664265CDEE19860
0.27.0
x64—20E181E2F14D95B8EE01D7B60E36DD4A4B7A8B90B42D5BD742230BDDD157786B
0.26.0
x64—BAD3EEB04EED8361332077AE470CA2B1AFF92546D21F8CD758E699ED1F602736
0.25.0
x64—6CBA78F5E97AB7D68E9CD2450C6CBA7C4428924953A4CD71FD80F48ACEBDF92C
0.24.0
x64—24AB21581E0B997D3DBFC1343FFF61A7BCF6AE9CDE8D933A21A395FE7F01ED50
0.23.0
x64—C59213D3898581887B4AF7EFFE94A2E0CA6956427A266D8B1BFCC7A8CECA10C6
0.22.0
x64—8271CAD949300220E88B5C1AC8D5C0C162666462D3AC6652A48CF91E48F5ADF2
0.21.0
x64—91AAA028B798D9B116DDA69D80CC3A063568254C0B56809200A5CF332E1DC447
0.20.0
x64—500A5ED096326C4562F50DE2EE0330122A5F0784A209A294C95F1DD6022FA567
0.19.0
x64—9291E2B527828864D3A21D499FEBE899543B4E7D1C3AAA0872CE0D9610F67307
0.18.0
x64—A95F3B2E9B36DF32902059617E0BE62D684BC5FA4F36C080FD5526ECE98D0CCA
0.17.0
x64—08472F7963BCDB105AC10FE7306733DEA50B5DE71CA9C334B9138B07734481CB
0.16.1
x64—E390B375768E97B7F47AFCFB5373C4DAD095FED3D0A09828277C7B91EF571F17
0.16.0
x64—E294E3F9E85824FC59BDFC107BCA2CBC33E333CF14604F9F676771615FED6B44
0.15.0
x64—917FB130F31077DBACFD542765CC91B866C6B772F175803255758E349E160F2E
0.13.1
x64—34149E68BF36AF86B0F2BC12257918FFBAFE1DFFD05D5D0FF4AE5FA369819F4F
0.13.0
x64—5C3C1E46D3979231CE681030DC86CAE995537F96AA11ACB2E29ACF94A1AFC0A8
0.12.0
x64—596EC569BE3FC984931C3A4E396635DED5506B57A5703426F4B2CE6F76CD0D63