ironclaw

NEAR AI·NearAI.IronClaw

Unleash Your AI Agent, With Peace of Mind

IronClaw is the secure, open-source alternative to OpenClaw that runs in encrypted enclaves on NEAR AI Cloud. AI agents that actually do things, but your secrets never touch the LLM. Philosophy IronClaw is built on a simple principle: your AI assistant should work for you, not against you. In a world where AI systems are increasingly opaque about data handling and aligned with corporate interests, IronClaw takes a different approach: - Your data stays yours - All information is stored locally, encrypted, and never leaves your control - Transparency by design - Open source, auditable, no hidden telemetry or data harvesting - Self-expanding capabilities - Build new tools on the fly without waiting for vendor updates - Defense in depth - Multiple security layers protect against prompt injection and data exfiltration IronClaw is the AI assistant you can actually trust with your personal and professional life. Features Security First - WASM Sandbox - Untrusted tools run in isolated WebAssembly containers with capability-based permissions - Credential Protection - Secrets are never exposed to tools; injected at the host boundary with leak detection - Prompt Injection Defense - Pattern detection, content sanitization, and policy enforcement - Endpoint Allowlisting - HTTP requests only to explicitly approved hosts and paths Always Available - Multi-channel - REPL, HTTP webhooks, WASM channels (Telegram, Slack), and web gateway - Docker Sandbox - Isolated container execution with per-job tokens and orchestrator/worker pattern - Web Gateway - Browser UI with real-time SSE/WebSocket streaming - Routines - Cron schedules, event triggers, webhook handlers for background automation - Heartbeat System - Proactive background execution for monitoring and maintenance tasks - Parallel Jobs - Handle multiple requests concurrently with isolated contexts - Self-repair - Automatic detection and recovery of stuck operations Self-Expanding - Dynamic Tool Building - Describe what you need, and IronClaw builds it as a WASM tool - MCP Protocol - Connect to Model Context Protocol servers for additional capabilities - Plugin Architecture - Drop in new WASM tools and channels without restarting Persistent Memory - Hybrid Search - Full-text + vector search using Reciprocal Rank Fusion - Workspace Filesystem - Flexible path-based storage for notes, logs, and context - Identity Files - Maintain consistent personality and preferences across sessions

winget install --id NearAI.IronClaw --exact --source winget

Latest 1.3.0·August 19, 2026

Release Notes

Release Notes Stable promotion of 1.3.0-rc.2, including the upgrade and container fixes validated in RC2 and the complete RC1 scope below. Fixed in 1.3.0-rc.2

  • Upgrades from 1.2 now accept and preserve the released extension activation_state field instead of crash-looping during startup.
  • The canonical Reborn runtime image again supports opt-in, public-key-only worker SSH on port 2222 while running IronClaw as an unprivileged user. Added
  • Per-user model preferences. Each user picks their own model from WebUI settings, the CLI, or chat commands, and the choice follows them through channel turns and inbound replay. Admins bound what is selectable with a tenant-scoped model selection policy.
  • Structured automations. A scheduled trigger now carries a validated execution contract — prompt spec, execution policy, required skills — checked by a fail-closed preflight at creation instead of a free-form prompt string, and unattended runs get their own protocol. A deterministic no-result sentinel lets a run that has nothing to report finish silently instead of delivering filler.
  • Document editing. Structural edits to .docx, .xlsx, and .pptx files, and PDF rendering from HTML.
  • Telegram linked devices. Pair a personal Telegram account with the bot channel so the agent can read your conversations and act as you through the standard messaging operations. Reads are live against Telegram's own servers — there is no local mirror, retention policy, or search index of the account — while message content a run actually reads is retained in that run's transcript like any other tool result.
  • The full Slack messaging vocabulary. Eight more standard operations — edit message, delete message, add reaction, remove reaction, open DM, get message, resolve user, list members — complete the core surface.
  • Ranked memory recall. Retrieval ranks by relevance instead of requiring every term of the question to appear in the saved fact, so a differently worded question still finds it, and broken memory is visibly different from empty memory. Memory-save guidance ships with an always-on MEMORY.md prompt lane.
  • Opt-in parallel tool batches in the agent loop.
  • Explicit Anthropic cache_control prompt-cache breakpoints on both transports.
  • A shared WebUI search field, and per-field help text on admin extension configuration forms alongside a rewritten channel setup guide. Changed
  • Substantially fewer database writes per turn. Capability invocation state persists at gate and terminal edges only; runtime milestone events, thread index touches, message lookup indexes, trigger and outbound state, and process heartbeats all coalesce or fold into existing rows.
  • Turn execution runs on prepared-context ("unbound") turns behind one accept door, replacing the kernel binding-ref path.
  • Channel ingress is normalized once, with reply split from delivery.
  • The public documentation site deploys from a docs-live branch that stable releases move, so published docs describe the released binary rather than unreleased main. Fixed
  • Context-window eviction compacts instead of discarding: the accepted task and any steering survive the eviction.
  • Lease expiry recovers safe runs instead of failing them, and the journal heartbeat pool is isolated.
  • An unavailable capability call is repaired instead of aborting the run, and repeated-call detection is advisory rather than fatal.
  • Model-bound secrets are redacted without rejecting the turn.
  • Telegram sticker and voice attachments no longer brick the channel, and the 2FA gate on migrated data centers is recognized and says where the login code arrives.
  • Extension cards and install results report what actually happened; bundled MCP state refreshes after auth; hosted MCP OAuth supports origin-scoped servers.
  • WebUI: SSE reconnect storms are bounded, long conversation titles reveal on hover, exposed-route copy is localized, and a failed tool call reads as a subtle badge instead of a loud summary.
  • The resource governor keeps retrying through a full libSQL writer attempt instead of surfacing the contention as a failure, and libSQL write-lane starvation no longer cascades through it: the delta journal gets its own bounded write lane, congestion is distinguished from storage damage so a contended write replays instead of invalidating the authority, and stale reservations are swept rather than leaking as permanent Active holds. Removed
  • Retired WebUI surfaces: the standalone missions page, the routines surface, admin analytics placeholders, and project mission placeholders.
  • Retired IronLoop network settings.

Installer type: wix

x647C4B48B29F95B1FE3B501056F8D07FAD96B16F90C893B5364B66A4FACF108ECD

Details

Homepage
https://www.ironclaw.com/
License
Apache-2.0 or MIT
Publisher
NEAR AI
Support
https://github.com/nearai/ironclaw/issues
Privacy Policy
https://near.ai/privacy-policy
Copyright
Copyright (c) 2026 NEAR AI

Tags

agentagenticaichatbotclawlarge-language-modelllm

Older versions (26)

1.2.0
x64BB3001C5F0BE06878667A3D311CDFDF60BF8CBF576D02FEC293A558A827268C5
1.1.0
x6426895B7E2CDA5A9BA5F4F1055DA40D1901B67552164B4E24223A82E39F7633F3
1.0.0-rc.1
x64D41430531CEEC3D297D9DD5712E9F91A4D0E9EAB0F67C3355E522E510115950E
1.0.0
x64A1B9AF9AE890AE2C5B6875DDD4A8267129ABC7A8803A6D315482F28E109A64DD
0.29.1
x644F3A17248C46E74D202D30975D4775C2EFFA2BC0D45F44E45EC443C1EBFD5DEA
0.29.0
x64C930041E56161A8D7511C82F0E233EB8589A1AA24C77B14505F6E7451D716963
0.28.2
x64FAAEBE88848CF1F9D63C2278CE6D4C3686FB386A47FB7EA8E67FEE4691FF9BAB
0.28.1
x643698892A8E06F810B0436B3FF88DED3F531790F097F56510231CFEC01B216DD4
0.28.0
x64AA5A4ED9AE5925848FDC23E056EBAD4C8FA2542E19F1967C5664265CDEE19860
0.27.0
x6420E181E2F14D95B8EE01D7B60E36DD4A4B7A8B90B42D5BD742230BDDD157786B
0.26.0
x64BAD3EEB04EED8361332077AE470CA2B1AFF92546D21F8CD758E699ED1F602736
0.25.0
x646CBA78F5E97AB7D68E9CD2450C6CBA7C4428924953A4CD71FD80F48ACEBDF92C
0.24.0
x6424AB21581E0B997D3DBFC1343FFF61A7BCF6AE9CDE8D933A21A395FE7F01ED50
0.23.0
x64C59213D3898581887B4AF7EFFE94A2E0CA6956427A266D8B1BFCC7A8CECA10C6
0.22.0
x648271CAD949300220E88B5C1AC8D5C0C162666462D3AC6652A48CF91E48F5ADF2
0.21.0
x6491AAA028B798D9B116DDA69D80CC3A063568254C0B56809200A5CF332E1DC447
0.20.0
x64500A5ED096326C4562F50DE2EE0330122A5F0784A209A294C95F1DD6022FA567
0.19.0
x649291E2B527828864D3A21D499FEBE899543B4E7D1C3AAA0872CE0D9610F67307
0.18.0
x64A95F3B2E9B36DF32902059617E0BE62D684BC5FA4F36C080FD5526ECE98D0CCA
0.17.0
x6408472F7963BCDB105AC10FE7306733DEA50B5DE71CA9C334B9138B07734481CB
0.16.1
x64E390B375768E97B7F47AFCFB5373C4DAD095FED3D0A09828277C7B91EF571F17
0.16.0
x64E294E3F9E85824FC59BDFC107BCA2CBC33E333CF14604F9F676771615FED6B44
0.15.0
x64917FB130F31077DBACFD542765CC91B866C6B772F175803255758E349E160F2E
0.13.1
x6434149E68BF36AF86B0F2BC12257918FFBAFE1DFFD05D5D0FF4AE5FA369819F4F
0.13.0
x645C3C1E46D3979231CE681030DC86CAE995537F96AA11ACB2E29ACF94A1AFC0A8
0.12.0
x64596EC569BE3FC984931C3A4E396635DED5506B57A5703426F4B2CE6F76CD0D63