nanocoai/nanoclawPublic

A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK

AI summary: A lightweight AI assistant framework that securely runs agents in isolated Linux containers.

Stars
30.9K
+-3 today
Forks
12.8K
Watchers
132
Open issues
365
Open PRs
704
Contributors
~170
Commits
2.9K
Branches
441

TypeScriptMITCreated Jan 31, 2026Last push 1d agoLatest release v2.4.0+20 stars this week+177 this month

Quick answers

What is nanoclaw?
A lightweight AI assistant framework that securely runs agents in isolated Linux containers.
What does nanoclaw do?
NanoClaw is a highly secure and customizable personal AI assistant framework designed as a leaner alternative to complex monoliths. It operates by orchestrating agent sessions inside isolated Docker containers, ensuring that agents only have access to explicitly mounted directories and cannot compromise the host system. The architecture relies on a single Node host routing messages from various channels (like Telegram, Discord, and WhatsApp) into session-specific SQLite databases, which the containerized agent then polls. This design allows users to modify the core codebase easily while maintaining robust OS-level security through OneCLI's credential injection.
Who is nanoclaw for?
Security-conscious developers and power users who want a deeply customizable, multi-channel AI assistant that enforces strict isolation.
How do I get started with nanoclaw?
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2 && cd nanoclaw-v2 && bash nanoclaw.sh
How popular is nanoclaw on GitHub?
nanocoai/nanoclaw has 30,862 stars and 12,786 forks on GitHub, and gained 20 stars in the last 7 days.
What license does nanoclaw use?
nanocoai/nanoclaw is released under the MIT license.

Star history

since Jul 29, 2026
010K20K30KJul 2026Aug 2026Sep 2026Oct 2026
30.9K stars as of Oct 2, 2026. Measured daily since Jul 29, 2026; GitHub no longer exposes earlier star timestamps.

Update history

2 recorded
  • Oct 4, 2026Previously tracked as gavrielc/nanoclaw; its 1 daily snapshot and 5 trending appearances were merged into this profile. Stars: 30,392 on 2026-07-29 under the old name, 30,862 on 2026-10-02 (+470).
  • Oct 4, 2026Previously tracked as qwibitai/nanoclaw; its 1 daily snapshot and 9 trending appearances were merged into this profile. Stars: 30,391 on 2026-07-29 under the old name, 30,862 on 2026-10-02 (+471).

Contribution activity

commits per day, last 52 weeks
SepOctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-09-27: 0 commits2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 18 commits2026-02-01: 37 commits2026-02-02: 12 commits2026-02-03: 5 commits2026-02-04: 3 commits2026-02-05: 2 commits2026-02-06: 8 commits2026-02-07: 2 commits2026-02-08: 1 commit2026-02-09: 6 commits2026-02-10: 0 commits2026-02-11: 2 commits2026-02-12: 4 commits2026-02-13: 7 commits2026-02-14: 1 commit2026-02-15: 6 commits2026-02-16: 5 commits2026-02-17: 0 commits2026-02-18: 5 commits2026-02-19: 3 commits2026-02-20: 8 commits2026-02-21: 11 commits2026-02-22: 18 commits2026-02-23: 9 commits2026-02-24: 14 commits2026-02-25: 14 commits2026-02-26: 0 commits2026-02-27: 3 commits2026-02-28: 0 commits2026-03-01: 9 commits2026-03-02: 6 commits2026-03-03: 2 commits2026-03-04: 17 commits2026-03-05: 1 commit2026-03-06: 16 commits2026-03-07: 0 commits2026-03-08: 10 commits2026-03-09: 3 commits2026-03-10: 18 commits2026-03-11: 9 commits2026-03-12: 0 commits2026-03-13: 9 commits2026-03-14: 13 commits2026-03-15: 0 commits2026-03-16: 6 commits2026-03-17: 1 commit2026-03-18: 15 commits2026-03-19: 10 commits2026-03-20: 4 commits2026-03-21: 16 commits2026-03-22: 2 commits2026-03-23: 6 commits2026-03-24: 24 commits2026-03-25: 35 commits2026-03-26: 14 commits2026-03-27: 22 commits2026-03-28: 8 commits2026-03-29: 0 commits2026-03-30: 5 commits2026-03-31: 1 commit2026-04-01: 5 commits2026-04-02: 5 commits2026-04-03: 7 commits2026-04-04: 10 commits2026-04-05: 19 commits2026-04-06: 3 commits2026-04-07: 1 commit2026-04-08: 13 commits2026-04-09: 26 commits2026-04-10: 7 commits2026-04-11: 6 commits2026-04-12: 13 commits2026-04-13: 14 commits2026-04-14: 24 commits2026-04-15: 22 commits2026-04-16: 18 commits2026-04-17: 24 commits2026-04-18: 15 commits2026-04-19: 14 commits2026-04-20: 42 commits2026-04-21: 26 commits2026-04-22: 44 commits2026-04-23: 54 commits2026-04-24: 17 commits2026-04-25: 3 commits2026-04-26: 4 commits2026-04-27: 6 commits2026-04-28: 7 commits2026-04-29: 34 commits2026-04-30: 28 commits2026-05-01: 14 commits2026-05-02: 19 commits2026-05-03: 14 commits2026-05-04: 9 commits2026-05-05: 26 commits2026-05-06: 10 commits2026-05-07: 34 commits2026-05-08: 28 commits2026-05-09: 29 commits2026-05-10: 13 commits2026-05-11: 12 commits2026-05-12: 4 commits2026-05-13: 3 commits2026-05-14: 6 commits2026-05-15: 13 commits2026-05-16: 1 commit2026-05-17: 1 commit2026-05-18: 5 commits2026-05-19: 5 commits2026-05-20: 2 commits2026-05-21: 1 commit2026-05-22: 8 commits2026-05-23: 8 commits2026-05-24: 0 commits2026-05-25: 3 commits2026-05-26: 0 commits2026-05-27: 0 commits2026-05-28: 2 commits2026-05-29: 0 commits2026-05-30: 1 commit2026-05-31: 2 commits2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 0 commits2026-06-04: 0 commits2026-06-05: 10 commits2026-06-06: 12 commits2026-06-07: 6 commits2026-06-08: 2 commits2026-06-09: 10 commits2026-06-10: 8 commits2026-06-11: 20 commits2026-06-12: 4 commits2026-06-13: 8 commits2026-06-14: 11 commits2026-06-15: 4 commits2026-06-16: 9 commits2026-06-17: 14 commits2026-06-18: 12 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 2 commits2026-06-22: 1 commit2026-06-23: 2 commits2026-06-24: 1 commit2026-06-25: 4 commits2026-06-26: 0 commits2026-06-27: 22 commits2026-06-28: 3 commits2026-06-29: 4 commits2026-06-30: 4 commits2026-07-01: 4 commits2026-07-02: 4 commits2026-07-03: 0 commits2026-07-04: 64 commits2026-07-05: 2 commits2026-07-06: 21 commits2026-07-07: 11 commits2026-07-08: 11 commits2026-07-09: 6 commits2026-07-10: 31 commits2026-07-11: 5 commits2026-07-12: 3 commits2026-07-13: 33 commits2026-07-14: 3 commits2026-07-15: 4 commits2026-07-16: 1 commit2026-07-17: 1 commit2026-07-18: 7 commits2026-07-19: 0 commits2026-07-20: 2 commits2026-07-21: 0 commits2026-07-22: 0 commits2026-07-23: 1 commit2026-07-24: 0 commits2026-07-25: 1 commit2026-07-26: 3 commits2026-07-27: 1 commit2026-07-28: 0 commits2026-07-29: 1 commit2026-07-30: 6 commits2026-07-31: 7 commits2026-08-01: 8 commits2026-08-02: 5 commits2026-08-03: 5 commits2026-08-04: 2 commits2026-08-05: 2 commits2026-08-06: 4 commits2026-08-07: 1 commit2026-08-08: 1 commit2026-08-09: 9 commits2026-08-10: 8 commits2026-08-11: 5 commits2026-08-12: 7 commits2026-08-13: 6 commits2026-08-14: 4 commits2026-08-15: 13 commits2026-08-16: 16 commits2026-08-17: 7 commits2026-08-18: 10 commits2026-08-19: 33 commits2026-08-20: 22 commits2026-08-21: 20 commits2026-08-22: 3 commits2026-08-23: 0 commits2026-08-24: 6 commits2026-08-25: 31 commits2026-08-26: 9 commits2026-08-27: 2 commits2026-08-28: 6 commits2026-08-29: 8 commits2026-08-30: 1 commit2026-08-31: 8 commits2026-09-01: 1 commit2026-09-02: 1 commit2026-09-03: 1 commit2026-09-04: 0 commits2026-09-05: 0 commits2026-09-06: 0 commits2026-09-07: 3 commits2026-09-08: 1 commit2026-09-09: 2 commits2026-09-10: 2 commits2026-09-11: 7 commits2026-09-12: 12 commits2026-09-13: 1 commit2026-09-14: 0 commits2026-09-15: 17 commits2026-09-16: 5 commits2026-09-17: 5 commits2026-09-18: 0 commits2026-09-19: 0 commits2026-09-20: 0 commits2026-09-21: 0 commits2026-09-22: 3 commits2026-09-23: 15 commits2026-09-24: 0 commits2026-09-25: 0 commits2026-09-26: 0 commits
2,014 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    30,862 stars

  • Very active

    2,014 commits in 52 weeks

  • Community-driven

    ~170 contributors

  • Well documented

    High community health score

  • Permissive license

    MIT

  • Continuous integration

    Automated checks passing

  • Repeat trending

    14 trending appearances

What nanoclaw does

NanoClaw is a highly secure and customizable personal AI assistant framework designed as a leaner alternative to complex monoliths. It operates by orchestrating agent sessions inside isolated Docker containers, ensuring that agents only have access to explicitly mounted directories and cannot compromise the host system. The architecture relies on a single Node host routing messages from various channels (like Telegram, Discord, and WhatsApp) into session-specific SQLite databases, which the containerized agent then polls. This design allows users to modify the core codebase easily while maintaining robust OS-level security through OneCLI's credential injection.

Security-conscious developers and power users who want a deeply customizable, multi-channel AI assistant that enforces strict isolation.

  • Containerized Isolation: Sandboxes every agent in its own Linux container, preventing unauthorized access to the host file system or network.
  • Multi-Channel Messaging: Integrates with numerous platforms including WhatsApp, Discord, and Slack, allowing one or multiple agents to span different interfaces.
  • Credential Security: Utilizes OneCLI's Agent Vault to inject API keys dynamically at request time, ensuring agents never hold raw secrets.
  • Flexible Architecture: Uses a simple, SQLite-backed polling mechanism between the host router and the isolated container to eliminate cross-mount contention.
  • Skill-Based Customization: Encourages users to extend functionality by injecting specific skills (like new channels or providers) directly into their fork.

Where teams use it

Secure Personal Assistant

Users deploy a unified assistant accessible via WhatsApp and Discord that safely manages local files and scheduled tasks without risking host security.

Automated Briefings

Professionals configure scheduled tasks for the agent to compile industry news and deliver a morning briefing to a specific messaging channel.

Multi-Agent Workspaces

Teams assign distinct, isolated agents to different Slack channels, each with custom tool mounts and specific provider configurations.

Local Model Integration

Privacy-conscious users connect the framework to local open-weight models via Ollama while maintaining the containerized security boundaries.

Getting started: git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2 && cd nanoclaw-v2 && bash nanoclaw.sh

README

main branch

NanoClaw

An AI assistant that runs agents securely in their own containers. Lightweight, built to be easily understood and completely customized for your needs.

nanoclaw.dev  •   docs  •   中文  •   日本語  •   한국어  •   Discord  •   repo tokens


NEW! Agents in Slack: one app per agent

Setup provisions each agent its own Slack app: manifest, avatar, and workspace install, no tokens to paste. Spawn teammates from chat: every one gets its own bot identity, container, and memory, with shared rooms and canvases.

Quick Start


Why I Built NanoClaw

OpenClaw is an impressive project, but I wouldn't have been able to sleep if I had given complex software I didn't understand full access to my life. OpenClaw has nearly half a million lines of code, 53 config files, and 70+ dependencies. Its security is at the application level (allowlists, pairing codes) rather than true OS-level isolation. Everything runs in one Node process with shared memory.

NanoClaw provides that same core functionality, but in a codebase small enough to understand: one process and a handful of files. Agents run in their own Linux containers with filesystem isolation, not merely behind permission checks.

Quick Start

git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
cd nanoclaw-v2
bash nanoclaw.sh

nanoclaw.sh walks you from a fresh machine to a named agent you can message. It installs Node, pnpm, and Docker if missing, installs a credential gateway and registers your Anthropic credential with it, builds the agent container, and pairs your first channel (Slack, Telegram, Discord, WhatsApp, iMessage, or a local CLI). If a step fails, Claude Code is invoked automatically to diagnose and resume from where it broke.

Migrating from NanoClaw v1?

Run from a fresh v2 checkout next to your v1 install:

git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
cd nanoclaw-v2
bash migrate-v2.sh

migrate-v2.sh finds your v1 install (sibling directory, or NANOCLAW_V1_PATH=/path/to/nanoclaw), migrates state into the v2 checkout, then execs into Claude Code to finish the parts that need judgment (owner seeding, shared-memory migration, fork-customisation replay).

Run the script directly, not from inside a Claude session — the deterministic side needs interactive prompts and real shell I/O for Node/pnpm bootstrap, Docker, the credential gateway, and the container build.

What it does: merges .env, seeds the v2 DB from registered_groups, copies group folders + session data + scheduled tasks, installs the channel adapters you select, copies channel auth state (including the Baileys keystore for WhatsApp — LID mapping is now resolved per-message by the Baileys v7 adapter, not migrated), builds the agent container.

What it doesn't: flip the system service. Pick "switch to v2" at the prompt, or do it manually after testing — your v1 install is left untouched.

See docs/v1-to-v2-changes.md for what's different and docs/migration-dev.md for development notes.

Philosophy

Small enough to understand. One process, a few source files and no microservices. If you want to understand the full NanoClaw codebase, just ask Claude Code to walk you through it.

Secure by isolation. Agents run in Linux containers and they can only see what's explicitly mounted. Bash access is safe because commands run inside the container, not on your host.

Built for the individual user. NanoClaw isn't a monolithic framework; it's software that fits each user's exact needs. Instead of becoming bloatware, NanoClaw is designed to be bespoke. You make your own fork and have Claude Code modify it to match your needs.

Customization = code changes. No configuration sprawl. Want different behavior? Modify the code. The codebase is small enough that it's safe to make changes.

AI-native, hybrid by design. The install and onboarding flow is an optimized scripted path, fast and deterministic. When a step needs judgment, whether a failed install, a guided decision, or a customization, control hands off to Claude Code seamlessly. Beyond setup there's no monitoring dashboard or debugging UI either: describe the problem in chat and Claude Code handles it.

Skills over features. Trunk ships the registry and infrastructure, not specific channel adapters or alternative agent providers. Channels (Discord, Slack, Telegram, WhatsApp, …) live on a long-lived channels branch; alternative providers (OpenCode, Ollama) live on providers. You run /add-telegram, /add-opencode, etc. and the skill copies exactly the module(s) you need into your fork. No feature you didn't ask for.

Best harness, best model. NanoClaw natively uses Claude Code via Anthropic's official Claude Agent SDK, so you get the latest Claude models and Claude Code's full toolset, including the ability to modify and expand your own NanoClaw fork. Other providers are drop-in options: /add-codex for OpenAI's Codex (ChatGPT subscription or API key), /add-opencode for OpenRouter, Google, DeepSeek and more via OpenCode, and /add-ollama-provider for local open-weight models. Provider is configurable per agent group.

What It Supports

  • Multi-channel messaging — WhatsApp, Telegram, Discord, Slack, Microsoft Teams, iMessage, Matrix, Google Chat, Webex, Linear, GitHub, WeChat, and email via Resend. Installed on demand with /add-<channel> skills. Run one or many at the same time.
  • Flexible isolation — connect each channel to its own agent for full privacy, share one agent across many channels for unified memory with separate conversations, or fold multiple channels into a single shared session so one conversation spans many surfaces. Pick per channel via /manage-channels. See docs/isolation-model.md.
  • Per-agent workspace — each agent group has its own CLAUDE.md, its own memory, its own container, and only the mounts you allow. Nothing crosses the boundary unless you wire it to.
  • Scheduled tasks: recurring jobs executed by the agent, with optional script gates that avoid waking it when there is no work
  • Web access — search and fetch content from the web
  • Container isolation — agents are sandboxed in Docker containers (macOS/Linux/WSL2)
  • Credential security — agents never hold raw API keys. Outbound requests route through a credential gateway that injects credentials at request time and enforces per-agent policies and rate limits. Which gateway is yours to pick: setup installs one (currently OneCLI's Agent Vault) behind a provider seam.
  • Agent templates: stamp a ready-to-run agent (instructions + MCP tools + skills, no secrets) from a reusable bundle via ncl groups create --template <ref>. Templates load from the local templates/ folder; populate it by hand or by copying from the public library. See docs/templates.md.

Accounts and what leaves your machine

NanoClaw has no user accounts. The only thing it reports is anonymous setup diagnostics, and NANOCLAW_NO_DIAGNOSTICS=1 turns those off. Your agents, messages, files and keys never leave your machine.

One opt-in exception: you can fetch a prebuilt agent image instead of building it locally. Fetching ours needs a free account, so we see your email address and when you ask for an image — nothing about your agents, and nothing after the image lands. Building locally needs no account and contacts nothing, and is the default. The same account unlocks the perks below.

Perks

The free account also opens the community portal at portal.nanoclaw.dev, a dashboard where you switch on what the account offers. Today that is Echo's hardened agent image and a managed Slack app for your agent, created and installed for you with no tokens to paste. Everything else in NanoClaw works without it.

Setup opens the portal once. You sign in in the browser, approve the terminal you are running setup from, and enable the perk; the wizard notices and continues on its own. Enabling Echo is where you agree to Echo's terms, including whether you want product and security email. Close the page without enabling anything and setup carries on without the perk, then offers it once more later.

What stays on your machine: the sign-in record and install token in ~/.config/nanoclaw/account.json, one device key per machine in ~/.config/nanoclaw/device-key.json, and this checkout's journal in data/community-portal.json (which perks are on, setup progress, the credentials a perk handed you), all mode 0600. The install token never passes through the browser: the browser sees only the one-time sign-in code, and the token reaches this machine from the account service directly. The host keeps one outbound connection to the portal so a perk you change in the browser reaches the running agent; it sends nothing about your agents, messages or files.

Revisit a step with pnpm exec tsx setup/portal.ts --stage echo or --stage slack. To sign a machine out, forget it under Devices in the portal: its token stops working and the host disconnects. Files, recovery commands and troubleshooting: docs/community-portal.md.

Usage

Talk to your assistant with the trigger word (default: @Andy):

@Andy send an overview of the sales pipeline every weekday morning at 9am (has access to my Obsidian vault folder)
@Andy review the git history for the past week each Friday and update the README if there's drift
@Andy every Monday at 8am, compile news on AI developments from Hacker News and TechCrunch and message me a briefing

From a channel you own or administer, you can manage groups and tasks:

@Andy list all scheduled tasks across groups
@Andy pause the Monday briefing task
@Andy join the Family Chat group

Customizing

NanoClaw doesn't use configuration files. To make changes, just tell Claude Code what you want:

  • "Change the trigger word to @Bob"
  • "Remember in the future to make responses shorter and more direct"
  • "Add a custom greeting when I say good morning"
  • "Store conversation summaries weekly"

Or run /customize for guided changes.

The codebase is small enough that Claude can safely modify it.

Contributing

Don't add features. Add skills.

If you want to add a new channel or agent provider, don't add it to trunk. New channel adapters land on the channels branch; new agent providers land on providers. Users install them in their own fork with /add-<name> skills, which copy the relevant module(s) into the standard paths, wire the registration, and pin dependencies.

This keeps trunk as pure registry and infra, and every fork stays lean — users get the channels and providers they asked for and nothing else.

RFS (Request for Skills)

No channel or provider skills are currently requested — propose one via an issue.

Requirements

  • macOS or Linux (Windows via WSL2)
  • Node.js 22+ and pnpm 10+ (the installer will install both if missing)
  • Docker Desktop (macOS/Windows) or Docker Engine (Linux)
  • Claude Code for /customize, /debug, error recovery during setup, and all /add-<channel> skills

Architecture

messaging apps → host process (router) → inbound.db → container (Bun, Claude Agent SDK) → outbound.db → host process (delivery) → messaging apps

A single Node host orchestrates per-session agent containers. When a message arrives, the host routes it via the entity model (user → messaging group → agent group → session), writes it to the session's inbound.db, and wakes the container. The agent-runner inside the container polls inbound.db, runs the agent, and writes responses to outbound.db. The host polls outbound.db and delivers back through the channel adapter.

Two SQLite files per session, each with exactly one writer — no cross-mount contention, no IPC, no stdin piping. Channels and alternative providers self-register at startup; trunk ships the registry and the Chat SDK bridge, while the adapters themselves are skill-installed per fork.

For the full architecture writeup see docs/architecture.md; for the three-level isolation model see docs/isolation-model.md.

Key files:

  • src/index.ts — entry point: DB init, channel adapters, delivery polls, sweep
  • src/router.ts — inbound routing: messaging group → agent group → session → inbound.db
  • src/delivery.ts — polls outbound.db, delivers via adapter, handles system actions
  • src/host-sweep.ts — 60s sweep: stale detection, due-message wake, recurrence
  • src/session-manager.ts — resolves sessions, opens inbound.db / outbound.db
  • src/container-runner.ts — spawns per-agent-group containers, leases the session's gateway contribution
  • src/db/ — central DB (users, roles, agent groups, messaging groups, wiring, migrations)
  • src/channels/ — channel adapter infra (adapters installed via /add-<channel> skills)
  • src/providers/ — host-side provider config (claude baked in; others via skills)
  • container/agent-runner/ — Bun agent-runner: poll loop, MCP tools, provider abstraction
  • groups/<folder>/ — per-agent-group filesystem (CLAUDE.md, skills, container config)

FAQ

Why Docker?

Docker provides cross-platform support (macOS, Linux and Windows via WSL2) and a mature ecosystem.

Can I run this on Linux or Windows?

Yes. Docker is the default runtime and works on macOS, Linux, and Windows (via WSL2). Just run bash nanoclaw.sh.

Is this secure?

Agents run in containers, not behind application-level permission checks. They can only access explicitly mounted directories. Credentials never enter the container — outbound API requests route through the installed credential gateway, which injects authentication at the proxy level and supports rate limits and access policies. You should still review what you're running, but the codebase is small enough that you actually can. See the security documentation for the full security model.

Why no configuration files?

We don't want configuration sprawl. Every user should customize NanoClaw so that the code does exactly what they want, rather than configuring a generic system. If you prefer having config files, you can tell Claude to add them.

Can I use third-party or open-source models?

Yes. The supported path is /add-opencode (OpenRouter, OpenAI, Google, DeepSeek, and more via OpenCode config) or /add-ollama-provider (local open-weight models via Ollama). Both are configurable per agent group, so different agents can run on different backends in the same install.

For one-off experiments, any Claude API-compatible endpoint also works via .env:

ANTHROPIC_BASE_URL=https://your-api-endpoint.com
ANTHROPIC_AUTH_TOKEN=your-token-here

How do I debug issues?

Ask Claude Code. "Why isn't the scheduler running?" "What's in the recent logs?" "Why did this message not get a response?" That's the AI-native approach that underlies NanoClaw.

Why isn't the setup working for me?

If a step fails, nanoclaw.sh hands off to Claude Code to diagnose and resume. If that doesn't resolve it, run claude, then /debug. If Claude identifies an issue likely to affect other users, open a PR against the relevant setup step or skill.

How do I uninstall NanoClaw?

bash nanoclaw.sh --uninstall

Every install is tagged with a per-checkout id, so the uninstaller removes only what belongs to that copy: the background service, containers and image, app data and logs, your agents' files, and this copy's gateway agents. Shared things — the gateway service and your credentials, other NanoClaw copies on the machine — are left alone. It shows exactly what it found and asks for confirmation per group; nothing is deleted until you say yes. Use --dry-run to preview without changing anything, or --yes to skip the prompts. Your .env is backed up before removal. To finish, delete the checkout folder itself.

What changes will be accepted into the codebase?

Only security fixes, bug fixes, and clear improvements will be accepted to the base configuration. That's all.

Everything else (new capabilities, OS compatibility, hardware support, enhancements) should be contributed as skills: channel and provider code on the channels/providers registry branches, everything else as a self-contained skill. See docs/customizing.md and CONTRIBUTING.md.

This keeps the base system minimal and lets every user customize their installation without inheriting features they don't want.

Community

Questions? Ideas? Join the Discord.

Changelog

See CHANGELOG.md for breaking changes, or the full release history on the documentation site.

License

MIT

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

8 total
  1. v2.4.0v2.4.0Sep 23, 2026

    NanoClaw 2.4.0 adds credential gateways installed through skills (OneCLI stays the default, Iron Proxy is new), community-portal setup for Echo's hardened image and a managed Slack app, install-wide and per-group model and speed controls, a Mattermost channel, and a reworked OpenCode provider. Agents now receive all of their capability instructions, replies stay in the thread they answer, and host restarts and `/update-nanoclaw` are more reliable. The default Claude model moves to Opus 5.5 and new Codex threads to `gpt-6-astra`, so check the section below before you update. ### ⚠️ Before you update - [BREAKING] **Custom source that composes agent instructions must move to the new module.** `CLAUDE.md` was a list of `@` imports into `/app`, and Claude Code silently drops imports that resolve outside the project directory, so eight of nine instruction sections never reached the model; it is now one flat file with every source inlined, shared with the Codex provider. `src/claude-md-compose.ts` is now `src/project-doc-compose.ts`, `composeGroupClaudeMd(group)` became `composeGroupProjectDoc(group, groupDir, spec)`, and the `/app/CLAUDE.md` and `/workspace/agent/.claude-fragments` mou

  2. v2.3.0v2.3.0Aug 24, 2026

    - [BREAKING] **A new Slack experience — per-agent provisioned Slack apps, agent spawning from Slack, and UX improvements — is available to classic single-bot Slack installs.** Classic Slack keeps working unchanged; this gate asks for a decision, not a forced migration. New installs and non-Slack installs are unaffected. **Migration:** run `/migrate-slack-agents` — it detects classic state (exits cleanly otherwise) and either walks the upgrade or records the choice to stay on classic; both outcomes satisfy this requirement. - **`/add-codex` now pins `@openai/codex` 0.146.0.** The previous pin (0.138.0) defaults to GPT-5.4, which OpenAI retires from Codex on 2026-08-31 — codex-provider agents ride the CLI default model, so stock installs stop completing turns at retirement — and it rejects the newer GPT-5.6 models with a 400 asking for a newer Codex CLI. Existing codex installs are not re-pinned by re-running `/add-codex` (the manifest merge is keyed on package name): edit the `@openai/codex` entry in `container/cli-tools.json` to `0.146.0`, rebuild the agent image (`./container/build.sh`), and restart. - [BREAKING] **Agent mailbox access now goes through storage-neutral host and run

  3. v2.2.0v2.2.0Aug 13, 2026

    - **Stamped plugins update in place through `ncl groups create --template <ref>`.** When a group already carries the template's plugin, the same command becomes an in-place update instead of minting a duplicate agent: a dry run prints a plan of every plugin-owned surface (plugin files, skills, MCP servers, persona, context files, tasks), flagging locally customized files whose edits would be lost; `--yes` applies, `--id` picks among several stamped groups, `--new` deliberately stamps another agent. Agent state the plugin does not own (memory, `plugin-data/`, user-added MCP servers, task pause/resume state, wiring) is never touched. Plugin-stamped MCP servers now carry an ownership marker and refuse direct edits via `ncl groups config add-mcp-server` / `remove-mcp-server` or the agent's `add_mcp_server` tool: update the plugin and restamp instead. - [BREAKING] **Agent templates are now Agent Plugins 1.0.0 directories.** `plugin.json` replaces `context/instructions.md` as the required file; MCP servers move to a spec-shaped `mcp.json`; persona, extra context, and tasks move under the `ai.nanoco.nanoclaw/` extension dir. Templates become portable to other plugin clients, and any confo

  4. v2.1.54v2.1.54Aug 1, 2026

    Rollup release covering v2.1.18 through v2.1.54 — everything merged since the v2.1.17 tag. - [BREAKING] **iMessage unified into one `imessage` channel with two backends via `/add-imessage`:** Local (this Mac's `chat.db` via the Chat SDK) or Hosted (native [Photon](https://photon.codes) via `spectrum-ts`, no Mac relay). Backend chosen at install or via `IMESSAGE_BACKEND=local|hosted`. The legacy Chat-SDK remote mode (`IMESSAGE_SERVER_URL`/`IMESSAGE_API_KEY`) and the separate `imessage-cloud` channel + `/add-imessage-cloud` skill are **removed**. See [docs/imessage.md](.claude/skills/add-imessage/docs.md). - [BREAKING] **Provider-agnostic memory.** All providers now share one OKF v0.1-compatible `memory/` tree, while persona lives in `instructions.prepend.md`; startup, clear, and compact reload memory automatically. Existing groups with legacy memory must run `/migrate-memory` before use. See [memory](docs/memory.md) and [provider migration](docs/provider-migration.md). - **New groups can inherit an instance-wide default provider.** `DEFAULT_AGENT_PROVIDER` sets the provider used when a new agent group is created without an explicit provider. Each group's stored provider still overr

  5. v2.1.17v2.1.17Jun 17, 2026

    Rollup release covering v2.1.1 through v2.1.17 — every `package.json` bump merged since the v2.1.0 tag. ## Changes - [BREAKING] **`@onecli-sh/sdk` 0.5.0 → 2.2.1 — requires a OneCLI server with the `/v1` API.** Older servers 404 every SDK call. The sanctioned gateway and CLI versions are now pinned in `versions.json`, and the `onecli` setup step enforces them. **The gateway is a separate component — updating NanoClaw does not upgrade it for you:** `/update-nanoclaw` upgrades the gateway when its pin moves, otherwise upgrade manually. See [docs/onecli-upgrades.md](https://github.com/nanocoai/nanoclaw/blob/main/docs/onecli-upgrades.md). - **New agent provider: Codex (OpenAI) — run `/add-codex`.** Full runtime via `codex app-server` (planning, MCP tools, server-side history, resume). Trunk ships the seams and the skill; the payload installs from the `providers` branch — via the skill, the setup picker, or `--step provider-auth codex`. Auth is vault-only; no credential ever enters a container. - **Setup can now select, install, and authenticate a non-default agent provider.** A provider registry feeds the setup picker, an installer pulls the provider's payload from its branch, a vault

Code frequency

additions and deletions
+49.9K-49.9KWeek of 2026-01-25: +7,119 linesWeek of 2026-01-25: -762 linesWeek of 2026-02-01: +10,211 linesWeek of 2026-02-01: -3,501 linesWeek of 2026-02-08: +10,582 linesWeek of 2026-02-08: -2,681 linesWeek of 2026-02-15: +18,756 linesWeek of 2026-02-15: -2,716 linesWeek of 2026-02-22: +15,359 linesWeek of 2026-02-22: -7,298 linesWeek of 2026-03-01: +14,255 linesWeek of 2026-03-01: -8,869 linesWeek of 2026-03-08: +16,696 linesWeek of 2026-03-08: -36,795 linesWeek of 2026-03-15: +4,241 linesWeek of 2026-03-15: -2,739 linesWeek of 2026-03-22: +3,487 linesWeek of 2026-03-22: -3,721 linesWeek of 2026-03-29: +3,403 linesWeek of 2026-03-29: -722 linesWeek of 2026-04-05: +32,363 linesWeek of 2026-04-05: -12,778 linesWeek of 2026-04-12: +38,962 linesWeek of 2026-04-12: -49,930 linesWeek of 2026-04-19: +35,018 linesWeek of 2026-04-19: -14,972 linesWeek of 2026-04-26: +8,228 linesWeek of 2026-04-26: -4,419 linesWeek of 2026-05-03: +8,194 linesWeek of 2026-05-03: -2,164 linesWeek of 2026-05-10: +1,489 linesWeek of 2026-05-10: -606 linesWeek of 2026-05-17: +1,435 linesWeek of 2026-05-17: -172 linesWeek of 2026-05-24: +380 linesWeek of 2026-05-24: -30 linesWeek of 2026-05-31: +5,588 linesWeek of 2026-05-31: -4,320 linesWeek of 2026-06-07: +7,204 linesWeek of 2026-06-07: -1,817 linesWeek of 2026-06-14: +9,731 linesWeek of 2026-06-14: -3,232 linesWeek of 2026-06-21: +4,938 linesWeek of 2026-06-21: -4,902 linesWeek of 2026-06-28: +7,094 linesWeek of 2026-06-28: -3,347 linesWeek of 2026-07-05: +11,464 linesWeek of 2026-07-05: -3,801 linesWeek of 2026-07-12: +6,365 linesWeek of 2026-07-12: -1,982 linesWeek of 2026-07-19: +864 linesWeek of 2026-07-19: -193 linesWeek of 2026-07-26: +9,958 linesWeek of 2026-07-26: -720 linesWeek of 2026-08-02: +5,311 linesWeek of 2026-08-02: -3,097 linesWeek of 2026-08-09: +9,203 linesWeek of 2026-08-09: -871 linesWeek of 2026-08-16: +36,525 linesWeek of 2026-08-16: -13,811 linesWeek of 2026-08-23: +15,548 linesWeek of 2026-08-23: -2,684 linesWeek of 2026-08-30: +9,527 linesWeek of 2026-08-30: -247 linesWeek of 2026-09-06: +7,033 linesWeek of 2026-09-06: -213 linesJan 25, 2026Sep 6, 2026
+376.5K lines added, -200.1K removed over the last year.

Commits per week

last 52 weeks
2000Week of 2025-09-27: 0 commitsWeek of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 18 commitsWeek of 2026-02-01: 69 commitsWeek of 2026-02-08: 21 commitsWeek of 2026-02-15: 38 commitsWeek of 2026-02-22: 58 commitsWeek of 2026-03-01: 51 commitsWeek of 2026-03-08: 62 commitsWeek of 2026-03-15: 52 commitsWeek of 2026-03-22: 111 commitsWeek of 2026-03-29: 33 commitsWeek of 2026-04-05: 75 commitsWeek of 2026-04-12: 130 commitsWeek of 2026-04-19: 200 commitsWeek of 2026-04-26: 112 commitsWeek of 2026-05-03: 150 commitsWeek of 2026-05-10: 52 commitsWeek of 2026-05-17: 30 commitsWeek of 2026-05-24: 6 commitsWeek of 2026-05-31: 24 commitsWeek of 2026-06-07: 58 commitsWeek of 2026-06-14: 50 commitsWeek of 2026-06-21: 32 commitsWeek of 2026-06-28: 83 commitsWeek of 2026-07-05: 87 commitsWeek of 2026-07-12: 52 commitsWeek of 2026-07-19: 4 commitsWeek of 2026-07-26: 26 commitsWeek of 2026-08-02: 20 commitsWeek of 2026-08-09: 52 commitsWeek of 2026-08-16: 111 commitsWeek of 2026-08-23: 62 commitsWeek of 2026-08-30: 12 commitsWeek of 2026-09-06: 27 commitsWeek of 2026-09-13: 28 commitsWeek of 2026-09-20: 18 commitsSep 27, 2025Sep 20, 2026
2K commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 9 commitsSun 1:00 — 14 commitsSun 2:00 — 2 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 1 commitsSun 7:00 — 1 commitsSun 8:00 — 3 commitsSun 9:00 — 4 commitsSun 10:00 — 7 commitsSun 11:00 — 12 commitsSun 12:00 — 17 commitsSun 13:00 — 10 commitsSun 14:00 — 9 commitsSun 15:00 — 11 commitsSun 16:00 — 15 commitsSun 17:00 — 21 commitsSun 18:00 — 11 commitsSun 19:00 — 11 commitsSun 20:00 — 17 commitsSun 21:00 — 12 commitsSun 22:00 — 19 commitsSun 23:00 — 19 commitsMon 0:00 — 30 commitsMon 1:00 — 17 commitsMon 2:00 — 5 commitsMon 3:00 — 0 commitsMon 4:00 — 1 commitsMon 5:00 — 2 commitsMon 6:00 — 2 commitsMon 7:00 — 8 commitsMon 8:00 — 5 commitsMon 9:00 — 11 commitsMon 10:00 — 14 commitsMon 11:00 — 11 commitsMon 12:00 — 24 commitsMon 13:00 — 24 commitsMon 14:00 — 21 commitsMon 15:00 — 9 commitsMon 16:00 — 19 commitsMon 17:00 — 12 commitsMon 18:00 — 11 commitsMon 19:00 — 7 commitsMon 20:00 — 3 commitsMon 21:00 — 4 commitsMon 22:00 — 7 commitsMon 23:00 — 10 commitsTue 0:00 — 22 commitsTue 1:00 — 11 commitsTue 2:00 — 1 commitsTue 3:00 — 1 commitsTue 4:00 — 2 commitsTue 5:00 — 2 commitsTue 6:00 — 0 commitsTue 7:00 — 5 commitsTue 8:00 — 5 commitsTue 9:00 — 11 commitsTue 10:00 — 17 commitsTue 11:00 — 11 commitsTue 12:00 — 21 commitsTue 13:00 — 12 commitsTue 14:00 — 12 commitsTue 15:00 — 32 commitsTue 16:00 — 7 commitsTue 17:00 — 17 commitsTue 18:00 — 6 commitsTue 19:00 — 8 commitsTue 20:00 — 8 commitsTue 21:00 — 7 commitsTue 22:00 — 27 commitsTue 23:00 — 22 commitsWed 0:00 — 27 commitsWed 1:00 — 11 commitsWed 2:00 — 6 commitsWed 3:00 — 2 commitsWed 4:00 — 0 commitsWed 5:00 — 1 commitsWed 6:00 — 1 commitsWed 7:00 — 6 commitsWed 8:00 — 5 commitsWed 9:00 — 6 commitsWed 10:00 — 18 commitsWed 11:00 — 19 commitsWed 12:00 — 29 commitsWed 13:00 — 22 commitsWed 14:00 — 24 commitsWed 15:00 — 24 commitsWed 16:00 — 24 commitsWed 17:00 — 11 commitsWed 18:00 — 29 commitsWed 19:00 — 10 commitsWed 20:00 — 12 commitsWed 21:00 — 19 commitsWed 22:00 — 18 commitsWed 23:00 — 26 commitsThu 0:00 — 4 commitsThu 1:00 — 6 commitsThu 2:00 — 2 commitsThu 3:00 — 3 commitsThu 4:00 — 0 commitsThu 5:00 — 0 commitsThu 6:00 — 1 commitsThu 7:00 — 8 commitsThu 8:00 — 7 commitsThu 9:00 — 9 commitsThu 10:00 — 16 commitsThu 11:00 — 22 commitsThu 12:00 — 26 commitsThu 13:00 — 32 commitsThu 14:00 — 15 commitsThu 15:00 — 17 commitsThu 16:00 — 31 commitsThu 17:00 — 17 commitsThu 18:00 — 8 commitsThu 19:00 — 23 commitsThu 20:00 — 11 commitsThu 21:00 — 26 commitsThu 22:00 — 13 commitsThu 23:00 — 8 commitsFri 0:00 — 12 commitsFri 1:00 — 10 commitsFri 2:00 — 2 commitsFri 3:00 — 1 commitsFri 4:00 — 0 commitsFri 5:00 — 0 commitsFri 6:00 — 2 commitsFri 7:00 — 7 commitsFri 8:00 — 4 commitsFri 9:00 — 5 commitsFri 10:00 — 10 commitsFri 11:00 — 22 commitsFri 12:00 — 18 commitsFri 13:00 — 11 commitsFri 14:00 — 27 commitsFri 15:00 — 17 commitsFri 16:00 — 25 commitsFri 17:00 — 15 commitsFri 18:00 — 21 commitsFri 19:00 — 9 commitsFri 20:00 — 23 commitsFri 21:00 — 15 commitsFri 22:00 — 21 commitsFri 23:00 — 9 commitsSat 0:00 — 6 commitsSat 1:00 — 5 commitsSat 2:00 — 1 commitsSat 3:00 — 1 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 1 commitsSat 7:00 — 2 commitsSat 8:00 — 3 commitsSat 9:00 — 4 commitsSat 10:00 — 12 commitsSat 11:00 — 4 commitsSat 12:00 — 10 commitsSat 13:00 — 14 commitsSat 14:00 — 18 commitsSat 15:00 — 29 commitsSat 16:00 — 59 commitsSat 17:00 — 21 commitsSat 18:00 — 26 commitsSat 19:00 — 28 commitsSat 20:00 — 29 commitsSat 21:00 — 18 commitsSat 22:00 — 11 commitsSat 23:00 — 24 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Mar 5, 2026daily#25+129
Feb 28, 2026daily#23+244
Feb 27, 2026daily#20+165
Feb 25, 2026daily#25+151
Feb 24, 2026daily#15+184
Feb 23, 2026daily#8+256
Feb 22, 2026daily#4+589
Feb 21, 2026daily#4+426
Feb 13, 2026daily#19+126
Feb 6, 2026daily#16+188
Feb 5, 2026daily#13+173
Feb 4, 2026daily#15+147
Feb 3, 2026daily#4+331
Feb 2, 2026daily#2+751
  • freeCodeCamp/freeCodeCamp

    freeCodeCamp.org's open-source codebase and curriculum. Learn math, programming, and computer science for free.

    456.7K stars · TypeScript

  • openclaw/openclaw

    The AI that really does things. Any OS. Any Platform. The lobster way. 🦞

    391.3K stars · TypeScript

  • affaan-m/ECC

    The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

    272.8K stars · JavaScript

  • NousResearch/hermes-agent

    The agent that grows with you

    251.2K stars · Python

  • anomalyco/opencode

    The open source coding agent.

    211.7K stars · TypeScript

  • n8n-io/n8n

    Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

    206.7K stars · TypeScript