nanocoai/nanoclawPublic

A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK

AI summary: A lightweight, secure alternative to OpenClaw that runs AI agents in isolated Linux containers.

Stars
30.5K
+21 today
Forks
12.9K
Watchers
129
Open issues
302
Open PRs
558
Contributors
~145
Commits
2.3K
Branches
140

TypeScriptMITCreated Jan 31, 2026Last push 1d agoLatest release v2.1.17+60 stars this week+60 this month

Star history

since May 10, 2026
010K20K30KMay 2026Jun 2026Jul 2026Aug 2026
30.5K stars as of Aug 7, 2026, tracked back to May 10, 2026. Historical curve reconstructed from public GitHub event archives, calibrated to the current total.

Contribution activity

commits per day, last 52 weeks
AugSepOctNovDecJanFebMarAprMayJunJulMonWedFri2025-08-02: 0 commits2025-08-03: 0 commits2025-08-04: 0 commits2025-08-05: 0 commits2025-08-06: 0 commits2025-08-07: 0 commits2025-08-08: 0 commits2025-08-09: 0 commits2025-08-10: 0 commits2025-08-11: 0 commits2025-08-12: 0 commits2025-08-13: 0 commits2025-08-14: 0 commits2025-08-15: 0 commits2025-08-16: 0 commits2025-08-17: 0 commits2025-08-18: 0 commits2025-08-19: 0 commits2025-08-20: 0 commits2025-08-21: 0 commits2025-08-22: 0 commits2025-08-23: 0 commits2025-08-24: 0 commits2025-08-25: 0 commits2025-08-26: 0 commits2025-08-27: 0 commits2025-08-28: 0 commits2025-08-29: 0 commits2025-08-30: 0 commits2025-08-31: 0 commits2025-09-01: 0 commits2025-09-02: 0 commits2025-09-03: 0 commits2025-09-04: 0 commits2025-09-05: 0 commits2025-09-06: 0 commits2025-09-07: 0 commits2025-09-08: 0 commits2025-09-09: 0 commits2025-09-10: 0 commits2025-09-11: 0 commits2025-09-12: 0 commits2025-09-13: 0 commits2025-09-14: 0 commits2025-09-15: 0 commits2025-09-16: 0 commits2025-09-17: 0 commits2025-09-18: 0 commits2025-09-19: 0 commits2025-09-20: 0 commits2025-09-21: 0 commits2025-09-22: 0 commits2025-09-23: 0 commits2025-09-24: 0 commits2025-09-25: 0 commits2025-09-26: 0 commits2025-09-27: 0 commits2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 18 commits2026-02-01: 37 commits2026-02-02: 12 commits2026-02-03: 5 commits2026-02-04: 3 commits2026-02-05: 2 commits2026-02-06: 8 commits2026-02-07: 2 commits2026-02-08: 1 commit2026-02-09: 6 commits2026-02-10: 0 commits2026-02-11: 2 commits2026-02-12: 4 commits2026-02-13: 7 commits2026-02-14: 1 commit2026-02-15: 6 commits2026-02-16: 5 commits2026-02-17: 0 commits2026-02-18: 5 commits2026-02-19: 3 commits2026-02-20: 8 commits2026-02-21: 11 commits2026-02-22: 18 commits2026-02-23: 9 commits2026-02-24: 14 commits2026-02-25: 14 commits2026-02-26: 0 commits2026-02-27: 3 commits2026-02-28: 0 commits2026-03-01: 9 commits2026-03-02: 6 commits2026-03-03: 2 commits2026-03-04: 17 commits2026-03-05: 1 commit2026-03-06: 16 commits2026-03-07: 0 commits2026-03-08: 10 commits2026-03-09: 3 commits2026-03-10: 18 commits2026-03-11: 9 commits2026-03-12: 0 commits2026-03-13: 9 commits2026-03-14: 13 commits2026-03-15: 0 commits2026-03-16: 6 commits2026-03-17: 1 commit2026-03-18: 15 commits2026-03-19: 10 commits2026-03-20: 4 commits2026-03-21: 16 commits2026-03-22: 2 commits2026-03-23: 6 commits2026-03-24: 24 commits2026-03-25: 35 commits2026-03-26: 14 commits2026-03-27: 22 commits2026-03-28: 8 commits2026-03-29: 0 commits2026-03-30: 5 commits2026-03-31: 1 commit2026-04-01: 5 commits2026-04-02: 5 commits2026-04-03: 7 commits2026-04-04: 10 commits2026-04-05: 19 commits2026-04-06: 3 commits2026-04-07: 1 commit2026-04-08: 13 commits2026-04-09: 26 commits2026-04-10: 7 commits2026-04-11: 6 commits2026-04-12: 13 commits2026-04-13: 14 commits2026-04-14: 24 commits2026-04-15: 22 commits2026-04-16: 18 commits2026-04-17: 24 commits2026-04-18: 15 commits2026-04-19: 14 commits2026-04-20: 42 commits2026-04-21: 26 commits2026-04-22: 44 commits2026-04-23: 54 commits2026-04-24: 17 commits2026-04-25: 3 commits2026-04-26: 4 commits2026-04-27: 6 commits2026-04-28: 7 commits2026-04-29: 34 commits2026-04-30: 28 commits2026-05-01: 14 commits2026-05-02: 19 commits2026-05-03: 14 commits2026-05-04: 9 commits2026-05-05: 26 commits2026-05-06: 10 commits2026-05-07: 34 commits2026-05-08: 28 commits2026-05-09: 29 commits2026-05-10: 13 commits2026-05-11: 12 commits2026-05-12: 4 commits2026-05-13: 3 commits2026-05-14: 6 commits2026-05-15: 13 commits2026-05-16: 1 commit2026-05-17: 1 commit2026-05-18: 5 commits2026-05-19: 5 commits2026-05-20: 2 commits2026-05-21: 1 commit2026-05-22: 8 commits2026-05-23: 8 commits2026-05-24: 0 commits2026-05-25: 3 commits2026-05-26: 0 commits2026-05-27: 0 commits2026-05-28: 2 commits2026-05-29: 0 commits2026-05-30: 1 commit2026-05-31: 2 commits2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 0 commits2026-06-04: 0 commits2026-06-05: 10 commits2026-06-06: 12 commits2026-06-07: 6 commits2026-06-08: 2 commits2026-06-09: 10 commits2026-06-10: 8 commits2026-06-11: 20 commits2026-06-12: 4 commits2026-06-13: 8 commits2026-06-14: 11 commits2026-06-15: 4 commits2026-06-16: 9 commits2026-06-17: 14 commits2026-06-18: 12 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 2 commits2026-06-22: 1 commit2026-06-23: 2 commits2026-06-24: 1 commit2026-06-25: 4 commits2026-06-26: 0 commits2026-06-27: 22 commits2026-06-28: 3 commits2026-06-29: 4 commits2026-06-30: 4 commits2026-07-01: 4 commits2026-07-02: 4 commits2026-07-03: 0 commits2026-07-04: 64 commits2026-07-05: 2 commits2026-07-06: 21 commits2026-07-07: 11 commits2026-07-08: 11 commits2026-07-09: 6 commits2026-07-10: 31 commits2026-07-11: 5 commits2026-07-12: 3 commits2026-07-13: 33 commits2026-07-14: 2 commits2026-07-15: 4 commits2026-07-16: 1 commit2026-07-17: 1 commit2026-07-18: 7 commits2026-07-19: 0 commits2026-07-20: 1 commit2026-07-21: 0 commits2026-07-22: 0 commits2026-07-23: 1 commit2026-07-24: 0 commits2026-07-25: 1 commit2026-07-26: 3 commits2026-07-27: 0 commits2026-07-28: 0 commits2026-07-29: 1 commit2026-07-30: 4 commits2026-07-31: 0 commits2026-08-01: 0 commits
1,664 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    30,464 stars

  • Very active

    1,664 commits in 52 weeks

  • Community-driven

    ~145 contributors

  • Well documented

    High community health score

  • Permissive license

    MIT

  • Continuous integration

    Automated checks passing

What nanoclaw does

NanoClaw provides a secure, minimal framework for running AI agents with full OS-level isolation rather than just application-level permission checks. It connects directly to popular messaging platforms like WhatsApp, Telegram, Slack, and Discord while maintaining an extremely small codebase. The core technical approach provisions individual Linux containers for each agent, ensuring complete filesystem separation and preventing shared memory vulnerabilities. What sets it apart from OpenClaw is its simplicity and transparency, replacing hundreds of dependencies with a single streamlined Node process. It automatically leverages Claude Code for self-diagnosis if installation steps fail.

This project is designed for developers and security-conscious users who want to run autonomous AI agents without giving them unfettered access to their host machines. It requires basic familiarity with terminal environments and Docker.

  • Containerized Isolation: runs each AI agent in a dedicated Linux container for true OS-level security.
  • Omnichannel Integration: connects natively to Telegram, Discord, WhatsApp, and CLI interfaces out of the box.
  • Minimalist Codebase: replaces massive dependency trees with a single Node process that is easy to audit.
  • Self-Healing Setup: invokes Claude Code automatically to diagnose and fix failures during the installation process.
  • Persistent Memory: retains context across sessions and supports scheduled background jobs for long-running tasks.

Where teams use it

Secure Personal Assistants

Privacy-conscious individuals deploy agents that can access local files without risking system-wide compromise.

Automated Community Management

Discord and Slack administrators run background agents to answer questions using persistent memory of previous conversations.

Auditable Agent Development

Developers use the minimal codebase to study and build custom agentic workflows without fighting complex abstractions.

Cross-Platform Messaging Bots

Teams maintain a single agent identity that can respond across WhatsApp, Telegram, and internal communication tools.

Getting started: git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2 && cd nanoclaw-v2 && bash nanoclaw.sh

README

main branch

NanoClaw

An AI assistant that runs agents securely in their own containers. Lightweight, built to be easily understood and completely customized for your needs.

nanoclaw.dev  •   docs  •   中文  •   日本語  •   한국어  •   Discord  •   repo tokens


Why I Built NanoClaw

OpenClaw is an impressive project, but I wouldn't have been able to sleep if I had given complex software I didn't understand full access to my life. OpenClaw has nearly half a million lines of code, 53 config files, and 70+ dependencies. Its security is at the application level (allowlists, pairing codes) rather than true OS-level isolation. Everything runs in one Node process with shared memory.

NanoClaw provides that same core functionality, but in a codebase small enough to understand: one process and a handful of files. Agents run in their own Linux containers with filesystem isolation, not merely behind permission checks.

Quick Start

git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
cd nanoclaw-v2
bash nanoclaw.sh

nanoclaw.sh walks you from a fresh machine to a named agent you can message. It installs Node, pnpm, and Docker if missing, registers your Anthropic credential with OneCLI, builds the agent container, and pairs your first channel (Telegram, Discord, WhatsApp, or a local CLI). If a step fails, Claude Code is invoked automatically to diagnose and resume from where it broke.

Migrating from NanoClaw v1?

Run from a fresh v2 checkout next to your v1 install:

git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
cd nanoclaw-v2
bash migrate-v2.sh

migrate-v2.sh finds your v1 install (sibling directory, or NANOCLAW_V1_PATH=/path/to/nanoclaw), migrates state into the v2 checkout, then execs into Claude Code to finish the parts that need judgment (owner seeding, shared-memory migration, fork-customisation replay).

Run the script directly, not from inside a Claude session — the deterministic side needs interactive prompts and real shell I/O for Node/pnpm bootstrap, Docker, OneCLI, and the container build.

What it does: merges .env, seeds the v2 DB from registered_groups, copies group folders + session data + scheduled tasks, installs the channel adapters you select, copies channel auth state (including the Baileys keystore for WhatsApp — LID mapping is now resolved per-message by the Baileys v7 adapter, not migrated), builds the agent container.

What it doesn't: flip the system service. Pick "switch to v2" at the prompt, or do it manually after testing — your v1 install is left untouched.

See docs/v1-to-v2-changes.md for what's different and docs/migration-dev.md for development notes.

Philosophy

Small enough to understand. One process, a few source files and no microservices. If you want to understand the full NanoClaw codebase, just ask Claude Code to walk you through it.

Secure by isolation. Agents run in Linux containers and they can only see what's explicitly mounted. Bash access is safe because commands run inside the container, not on your host.

Built for the individual user. NanoClaw isn't a monolithic framework; it's software that fits each user's exact needs. Instead of becoming bloatware, NanoClaw is designed to be bespoke. You make your own fork and have Claude Code modify it to match your needs.

Customization = code changes. No configuration sprawl. Want different behavior? Modify the code. The codebase is small enough that it's safe to make changes.

AI-native, hybrid by design. The install and onboarding flow is an optimized scripted path, fast and deterministic. When a step needs judgment, whether a failed install, a guided decision, or a customization, control hands off to Claude Code seamlessly. Beyond setup there's no monitoring dashboard or debugging UI either: describe the problem in chat and Claude Code handles it.

Skills over features. Trunk ships the registry and infrastructure, not specific channel adapters or alternative agent providers. Channels (Discord, Slack, Telegram, WhatsApp, …) live on a long-lived channels branch; alternative providers (OpenCode, Ollama) live on providers. You run /add-telegram, /add-opencode, etc. and the skill copies exactly the module(s) you need into your fork. No feature you didn't ask for.

Best harness, best model. NanoClaw natively uses Claude Code via Anthropic's official Claude Agent SDK, so you get the latest Claude models and Claude Code's full toolset, including the ability to modify and expand your own NanoClaw fork. Other providers are drop-in options: /add-codex for OpenAI's Codex (ChatGPT subscription or API key), /add-opencode for OpenRouter, Google, DeepSeek and more via OpenCode, and /add-ollama-provider for local open-weight models. Provider is configurable per agent group.

What It Supports

  • Multi-channel messaging — WhatsApp, Telegram, Discord, Slack, Microsoft Teams, iMessage, Matrix, Google Chat, Webex, Linear, GitHub, WeChat, and email via Resend. Installed on demand with /add-<channel> skills. Run one or many at the same time.
  • Flexible isolation — connect each channel to its own agent for full privacy, share one agent across many channels for unified memory with separate conversations, or fold multiple channels into a single shared session so one conversation spans many surfaces. Pick per channel via /manage-channels. See docs/isolation-model.md.
  • Per-agent workspace — each agent group has its own CLAUDE.md, its own memory, its own container, and only the mounts you allow. Nothing crosses the boundary unless you wire it to.
  • Scheduled tasks: recurring jobs executed by the agent, with optional script gates that avoid waking it when there is no work
  • Web access — search and fetch content from the web
  • Container isolation — agents are sandboxed in Docker containers (macOS/Linux/WSL2)
  • Credential security — agents never hold raw API keys. Outbound requests route through OneCLI's Agent Vault, which injects credentials at request time and enforces per-agent policies and rate limits.
  • Agent templates: stamp a ready-to-run agent (instructions + MCP tools + skills, no secrets) from a reusable bundle via ncl groups create --template <ref>. Templates load from the local templates/ folder; populate it by hand or by copying from the public library. See docs/templates.md.

Accounts and what leaves your machine

NanoClaw has no user accounts. The only thing it reports is anonymous setup diagnostics, and NANOCLAW_NO_DIAGNOSTICS=1 turns those off. Your agents, messages, files and keys never leave your machine.

One opt-in exception: you can fetch a prebuilt agent image instead of building it locally. Fetching ours needs a free account, so we see your email address and when you ask for an image — nothing about your agents, and nothing after the image lands. Building locally needs no account and contacts nothing, and is the default.

Usage

Talk to your assistant with the trigger word (default: @Andy):

@Andy send an overview of the sales pipeline every weekday morning at 9am (has access to my Obsidian vault folder)
@Andy review the git history for the past week each Friday and update the README if there's drift
@Andy every Monday at 8am, compile news on AI developments from Hacker News and TechCrunch and message me a briefing

From a channel you own or administer, you can manage groups and tasks:

@Andy list all scheduled tasks across groups
@Andy pause the Monday briefing task
@Andy join the Family Chat group

Customizing

NanoClaw doesn't use configuration files. To make changes, just tell Claude Code what you want:

  • "Change the trigger word to @Bob"
  • "Remember in the future to make responses shorter and more direct"
  • "Add a custom greeting when I say good morning"
  • "Store conversation summaries weekly"

Or run /customize for guided changes.

The codebase is small enough that Claude can safely modify it.

Contributing

Don't add features. Add skills.

If you want to add a new channel or agent provider, don't add it to trunk. New channel adapters land on the channels branch; new agent providers land on providers. Users install them in their own fork with /add-<name> skills, which copy the relevant module(s) into the standard paths, wire the registration, and pin dependencies.

This keeps trunk as pure registry and infra, and every fork stays lean — users get the channels and providers they asked for and nothing else.

RFS (Request for Skills)

No channel or provider skills are currently requested — propose one via an issue.

Requirements

  • macOS or Linux (Windows via WSL2)
  • Node.js 20+ and pnpm 10+ (the installer will install both if missing)
  • Docker Desktop (macOS/Windows) or Docker Engine (Linux)
  • Claude Code for /customize, /debug, error recovery during setup, and all /add-<channel> skills

Architecture

messaging apps → host process (router) → inbound.db → container (Bun, Claude Agent SDK) → outbound.db → host process (delivery) → messaging apps

A single Node host orchestrates per-session agent containers. When a message arrives, the host routes it via the entity model (user → messaging group → agent group → session), writes it to the session's inbound.db, and wakes the container. The agent-runner inside the container polls inbound.db, runs the agent, and writes responses to outbound.db. The host polls outbound.db and delivers back through the channel adapter.

Two SQLite files per session, each with exactly one writer — no cross-mount contention, no IPC, no stdin piping. Channels and alternative providers self-register at startup; trunk ships the registry and the Chat SDK bridge, while the adapters themselves are skill-installed per fork.

For the full architecture writeup see docs/architecture.md; for the three-level isolation model see docs/isolation-model.md.

Key files:

  • src/index.ts — entry point: DB init, channel adapters, delivery polls, sweep
  • src/router.ts — inbound routing: messaging group → agent group → session → inbound.db
  • src/delivery.ts — polls outbound.db, delivers via adapter, handles system actions
  • src/host-sweep.ts — 60s sweep: stale detection, due-message wake, recurrence
  • src/session-manager.ts — resolves sessions, opens inbound.db / outbound.db
  • src/container-runner.ts — spawns per-agent-group containers, OneCLI credential injection
  • src/db/ — central DB (users, roles, agent groups, messaging groups, wiring, migrations)
  • src/channels/ — channel adapter infra (adapters installed via /add-<channel> skills)
  • src/providers/ — host-side provider config (claude baked in; others via skills)
  • container/agent-runner/ — Bun agent-runner: poll loop, MCP tools, provider abstraction
  • groups/<folder>/ — per-agent-group filesystem (CLAUDE.md, skills, container config)

FAQ

Why Docker?

Docker provides cross-platform support (macOS, Linux and Windows via WSL2) and a mature ecosystem.

Can I run this on Linux or Windows?

Yes. Docker is the default runtime and works on macOS, Linux, and Windows (via WSL2). Just run bash nanoclaw.sh.

Is this secure?

Agents run in containers, not behind application-level permission checks. They can only access explicitly mounted directories. Credentials never enter the container — outbound API requests route through OneCLI's Agent Vault, which injects authentication at the proxy level and supports rate limits and access policies. You should still review what you're running, but the codebase is small enough that you actually can. See the security documentation for the full security model.

Why no configuration files?

We don't want configuration sprawl. Every user should customize NanoClaw so that the code does exactly what they want, rather than configuring a generic system. If you prefer having config files, you can tell Claude to add them.

Can I use third-party or open-source models?

Yes. The supported path is /add-opencode (OpenRouter, OpenAI, Google, DeepSeek, and more via OpenCode config) or /add-ollama-provider (local open-weight models via Ollama). Both are configurable per agent group, so different agents can run on different backends in the same install.

For one-off experiments, any Claude API-compatible endpoint also works via .env:

ANTHROPIC_BASE_URL=https://your-api-endpoint.com
ANTHROPIC_AUTH_TOKEN=your-token-here

How do I debug issues?

Ask Claude Code. "Why isn't the scheduler running?" "What's in the recent logs?" "Why did this message not get a response?" That's the AI-native approach that underlies NanoClaw.

Why isn't the setup working for me?

If a step fails, nanoclaw.sh hands off to Claude Code to diagnose and resume. If that doesn't resolve it, run claude, then /debug. If Claude identifies an issue likely to affect other users, open a PR against the relevant setup step or skill.

How do I uninstall NanoClaw?

bash nanoclaw.sh --uninstall

Every install is tagged with a per-checkout id, so the uninstaller removes only what belongs to that copy: the background service, containers and image, app data and logs, your agents' files, and this copy's OneCLI vault agents. Shared things — the OneCLI app and your credentials, other NanoClaw copies on the machine — are left alone. It shows exactly what it found and asks for confirmation per group; nothing is deleted until you say yes. Use --dry-run to preview without changing anything, or --yes to skip the prompts. Your .env is backed up before removal. To finish, delete the checkout folder itself.

What changes will be accepted into the codebase?

Only security fixes, bug fixes, and clear improvements will be accepted to the base configuration. That's all.

Everything else (new capabilities, OS compatibility, hardware support, enhancements) should be contributed as skills: channel and provider code on the channels/providers registry branches, everything else as a self-contained skill. See docs/customizing.md and CONTRIBUTING.md.

This keeps the base system minimal and lets every user customize their installation without inheriting features they don't want.

Community

Questions? Ideas? Join the Discord.

Changelog

See CHANGELOG.md for breaking changes, or the full release history on the documentation site.

License

MIT

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

4 total
  1. v2.1.17v2.1.17Jun 17, 2026

    Rollup release covering v2.1.1 through v2.1.17 — every `package.json` bump merged since the v2.1.0 tag. ## Changes - [BREAKING] **`@onecli-sh/sdk` 0.5.0 → 2.2.1 — requires a OneCLI server with the `/v1` API.** Older servers 404 every SDK call. The sanctioned gateway and CLI versions are now pinned in `versions.json`, and the `onecli` setup step enforces them. **The gateway is a separate component — updating NanoClaw does not upgrade it for you:** `/update-nanoclaw` upgrades the gateway when its pin moves, otherwise upgrade manually. See [docs/onecli-upgrades.md](https://github.com/nanocoai/nanoclaw/blob/main/docs/onecli-upgrades.md). - **New agent provider: Codex (OpenAI) — run `/add-codex`.** Full runtime via `codex app-server` (planning, MCP tools, server-side history, resume). Trunk ships the seams and the skill; the payload installs from the `providers` branch — via the skill, the setup picker, or `--step provider-auth codex`. Auth is vault-only; no credential ever enters a container. - **Setup can now select, install, and authenticate a non-default agent provider.** A provider registry feeds the setup picker, an installer pulls the provider's payload from its branch, a vault

  2. v2.1.0v2.1.0Jun 17, 2026

    Rollup release covering v2.0.65 through v2.1.0 — every `package.json` bump merged since the v2.0.64 tag. ## Changes - [BREAKING] **Startup now requires an upgrade marker.** The host refuses to boot unless `data/upgrade-state.json` records that this install reached the current version through a sanctioned path (`/setup`, `/update-nanoclaw`, `/migrate-nanoclaw`). After this update completes — and before restarting the service — stamp the marker by running `pnpm exec tsx scripts/upgrade-state.ts set`. If the host has already tripped on restart with "update did not go through the supported path", that same command clears it. (The tripwire code actually shipped in v2.1.1; v2.1.0 is the meaningful release boundary because the version bump and the feature merge sequenced in that order — every install on v2.1.1 or higher carries the tripwire.) See [docs/upgrade-recovery.md](https://github.com/nanocoai/nanoclaw/blob/main/docs/upgrade-recovery.md). - **`/upload-trace` ships the session transcript to Hugging Face.** A runner-handled slash command (admin-gated, like `/clear`) pushes the current session's Claude Code transcript to the user's own private `{hf_user}/nanoclaw-traces` dataset, br

  3. v2.0.64v2.0.64May 18, 2026

    ## Changes - **`ncl destinations add` and `remove` through the approval flow now reach the receiver immediately.** Approved destinations weren't being projected into the receiving agent's local session state, so a freshly-added destination silently failed at `send_message` with `unknown destination`, and a removed destination stayed resolvable until the next container restart. Both now take effect the moment the approval executes. Direct (non-approval) calls were unaffected. ## Contributors - @glifocat — #2509, #2510, #2536 **Full Changelog**: https://github.com/nanocoai/nanoclaw/compare/v2.0.63...v2.0.64

  4. v2.0.63v2.0.63May 15, 2026

    > **First properly published release.** Starting with v2.0.63, the goal is to publish a GitHub Release for every `package.json` version bump that lands on `main` — releases are cut manually by a maintainer, so there can be lag. Until now only the bumps landed and tags were sporadic, which made it hard for packagers and users to pin to a known version. See [RELEASING.md](https://github.com/nanocoai/nanoclaw/blob/main/RELEASING.md) for the policy. Rollup release covering v2.0.55 through v2.0.63 — everything merged since the v2.0.54 tag. ## Changes - [BREAKING] **Service names are now per-install.** On v2 installs the launchd label and systemd unit are slugged to your project root: `com.nanoclaw.<sha1(projectRoot)[:8]>` and `nanoclaw-<slug>.service`. The old `com.nanoclaw` / `nanoclaw.service` names no longer match a real service — update any copy-pasted restart or status commands. Find your install's names with `source setup/lib/install-slug.sh && launchd_label` (macOS) or `systemd_unit` (Linux). The `ncl` transport-error help text and 26 skill files now use the canonical helper-driven pattern; see [`setup/lib/install-slug.sh`](https://github.com/nanocoai/nanoclaw/blob/main/setup/

Code frequency

additions and deletions
+49.9K-49.9KWeek of 2026-01-25: +7,119 linesWeek of 2026-01-25: -762 linesWeek of 2026-02-01: +10,211 linesWeek of 2026-02-01: -3,501 linesWeek of 2026-02-08: +10,582 linesWeek of 2026-02-08: -2,681 linesWeek of 2026-02-15: +18,756 linesWeek of 2026-02-15: -2,716 linesWeek of 2026-02-22: +15,359 linesWeek of 2026-02-22: -7,298 linesWeek of 2026-03-01: +14,255 linesWeek of 2026-03-01: -8,869 linesWeek of 2026-03-08: +16,696 linesWeek of 2026-03-08: -36,795 linesWeek of 2026-03-15: +4,241 linesWeek of 2026-03-15: -2,739 linesWeek of 2026-03-22: +3,487 linesWeek of 2026-03-22: -3,721 linesWeek of 2026-03-29: +3,403 linesWeek of 2026-03-29: -722 linesWeek of 2026-04-05: +32,363 linesWeek of 2026-04-05: -12,778 linesWeek of 2026-04-12: +38,962 linesWeek of 2026-04-12: -49,930 linesWeek of 2026-04-19: +35,018 linesWeek of 2026-04-19: -14,972 linesWeek of 2026-04-26: +8,228 linesWeek of 2026-04-26: -4,419 linesWeek of 2026-05-03: +8,194 linesWeek of 2026-05-03: -2,164 linesWeek of 2026-05-10: +1,489 linesWeek of 2026-05-10: -606 linesWeek of 2026-05-17: +1,435 linesWeek of 2026-05-17: -172 linesWeek of 2026-05-24: +380 linesWeek of 2026-05-24: -30 linesWeek of 2026-05-31: +5,588 linesWeek of 2026-05-31: -4,320 linesWeek of 2026-06-07: +7,204 linesWeek of 2026-06-07: -1,817 linesWeek of 2026-06-14: +9,731 linesWeek of 2026-06-14: -3,232 linesWeek of 2026-06-21: +4,938 linesWeek of 2026-06-21: -4,902 linesWeek of 2026-06-28: +7,094 linesWeek of 2026-06-28: -3,347 linesWeek of 2026-07-05: +11,464 linesWeek of 2026-07-05: -3,801 linesWeek of 2026-07-12: +5,480 linesWeek of 2026-07-12: -1,981 linesWeek of 2026-07-19: +335 linesWeek of 2026-07-19: -79 linesWeek of 2026-07-26: +5,100 linesWeek of 2026-07-26: -273 linesJan 25, 2026Jul 26, 2026
+287.1K lines added, -178.6K removed over the last year.

Commits per week

last 52 weeks
2000Week of 2025-08-02: 0 commitsWeek of 2025-08-09: 0 commitsWeek of 2025-08-16: 0 commitsWeek of 2025-08-23: 0 commitsWeek of 2025-08-30: 0 commitsWeek of 2025-09-06: 0 commitsWeek of 2025-09-13: 0 commitsWeek of 2025-09-20: 0 commitsWeek of 2025-09-27: 0 commitsWeek of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 18 commitsWeek of 2026-02-01: 69 commitsWeek of 2026-02-08: 21 commitsWeek of 2026-02-15: 38 commitsWeek of 2026-02-22: 58 commitsWeek of 2026-03-01: 51 commitsWeek of 2026-03-08: 62 commitsWeek of 2026-03-15: 52 commitsWeek of 2026-03-22: 111 commitsWeek of 2026-03-29: 33 commitsWeek of 2026-04-05: 75 commitsWeek of 2026-04-12: 130 commitsWeek of 2026-04-19: 200 commitsWeek of 2026-04-26: 112 commitsWeek of 2026-05-03: 150 commitsWeek of 2026-05-10: 52 commitsWeek of 2026-05-17: 30 commitsWeek of 2026-05-24: 6 commitsWeek of 2026-05-31: 24 commitsWeek of 2026-06-07: 58 commitsWeek of 2026-06-14: 50 commitsWeek of 2026-06-21: 32 commitsWeek of 2026-06-28: 83 commitsWeek of 2026-07-05: 87 commitsWeek of 2026-07-12: 51 commitsWeek of 2026-07-19: 3 commitsWeek of 2026-07-26: 8 commitsAug 2, 2025Jul 26, 2026
1.7K commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 8 commitsSun 1:00 — 5 commitsSun 2:00 — 2 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 0 commitsSun 7:00 — 1 commitsSun 8:00 — 3 commitsSun 9:00 — 4 commitsSun 10:00 — 6 commitsSun 11:00 — 12 commitsSun 12:00 — 16 commitsSun 13:00 — 10 commitsSun 14:00 — 8 commitsSun 15:00 — 10 commitsSun 16:00 — 12 commitsSun 17:00 — 20 commitsSun 18:00 — 11 commitsSun 19:00 — 8 commitsSun 20:00 — 14 commitsSun 21:00 — 8 commitsSun 22:00 — 17 commitsSun 23:00 — 18 commitsMon 0:00 — 23 commitsMon 1:00 — 14 commitsMon 2:00 — 5 commitsMon 3:00 — 0 commitsMon 4:00 — 1 commitsMon 5:00 — 2 commitsMon 6:00 — 2 commitsMon 7:00 — 4 commitsMon 8:00 — 5 commitsMon 9:00 — 9 commitsMon 10:00 — 14 commitsMon 11:00 — 11 commitsMon 12:00 — 23 commitsMon 13:00 — 24 commitsMon 14:00 — 18 commitsMon 15:00 — 8 commitsMon 16:00 — 15 commitsMon 17:00 — 11 commitsMon 18:00 — 3 commitsMon 19:00 — 4 commitsMon 20:00 — 2 commitsMon 21:00 — 4 commitsMon 22:00 — 6 commitsMon 23:00 — 10 commitsTue 0:00 — 22 commitsTue 1:00 — 3 commitsTue 2:00 — 1 commitsTue 3:00 — 0 commitsTue 4:00 — 2 commitsTue 5:00 — 2 commitsTue 6:00 — 0 commitsTue 7:00 — 5 commitsTue 8:00 — 2 commitsTue 9:00 — 5 commitsTue 10:00 — 8 commitsTue 11:00 — 7 commitsTue 12:00 — 14 commitsTue 13:00 — 9 commitsTue 14:00 — 9 commitsTue 15:00 — 27 commitsTue 16:00 — 4 commitsTue 17:00 — 12 commitsTue 18:00 — 2 commitsTue 19:00 — 7 commitsTue 20:00 — 3 commitsTue 21:00 — 7 commitsTue 22:00 — 24 commitsTue 23:00 — 21 commitsWed 0:00 — 23 commitsWed 1:00 — 7 commitsWed 2:00 — 4 commitsWed 3:00 — 2 commitsWed 4:00 — 0 commitsWed 5:00 — 1 commitsWed 6:00 — 1 commitsWed 7:00 — 5 commitsWed 8:00 — 5 commitsWed 9:00 — 6 commitsWed 10:00 — 17 commitsWed 11:00 — 17 commitsWed 12:00 — 22 commitsWed 13:00 — 18 commitsWed 14:00 — 20 commitsWed 15:00 — 18 commitsWed 16:00 — 12 commitsWed 17:00 — 9 commitsWed 18:00 — 23 commitsWed 19:00 — 9 commitsWed 20:00 — 7 commitsWed 21:00 — 15 commitsWed 22:00 — 13 commitsWed 23:00 — 22 commitsThu 0:00 — 4 commitsThu 1:00 — 5 commitsThu 2:00 — 2 commitsThu 3:00 — 2 commitsThu 4:00 — 0 commitsThu 5:00 — 0 commitsThu 6:00 — 1 commitsThu 7:00 — 8 commitsThu 8:00 — 7 commitsThu 9:00 — 8 commitsThu 10:00 — 14 commitsThu 11:00 — 22 commitsThu 12:00 — 23 commitsThu 13:00 — 31 commitsThu 14:00 — 10 commitsThu 15:00 — 16 commitsThu 16:00 — 19 commitsThu 17:00 — 14 commitsThu 18:00 — 5 commitsThu 19:00 — 17 commitsThu 20:00 — 9 commitsThu 21:00 — 25 commitsThu 22:00 — 13 commitsThu 23:00 — 6 commitsFri 0:00 — 9 commitsFri 1:00 — 6 commitsFri 2:00 — 1 commitsFri 3:00 — 0 commitsFri 4:00 — 0 commitsFri 5:00 — 0 commitsFri 6:00 — 2 commitsFri 7:00 — 7 commitsFri 8:00 — 3 commitsFri 9:00 — 4 commitsFri 10:00 — 10 commitsFri 11:00 — 21 commitsFri 12:00 — 15 commitsFri 13:00 — 11 commitsFri 14:00 — 22 commitsFri 15:00 — 15 commitsFri 16:00 — 17 commitsFri 17:00 — 14 commitsFri 18:00 — 17 commitsFri 19:00 — 5 commitsFri 20:00 — 20 commitsFri 21:00 — 14 commitsFri 22:00 — 19 commitsFri 23:00 — 9 commitsSat 0:00 — 4 commitsSat 1:00 — 5 commitsSat 2:00 — 1 commitsSat 3:00 — 0 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 1 commitsSat 7:00 — 2 commitsSat 8:00 — 3 commitsSat 9:00 — 2 commitsSat 10:00 — 5 commitsSat 11:00 — 4 commitsSat 12:00 — 10 commitsSat 13:00 — 14 commitsSat 14:00 — 16 commitsSat 15:00 — 22 commitsSat 16:00 — 55 commitsSat 17:00 — 21 commitsSat 18:00 — 25 commitsSat 19:00 — 28 commitsSat 20:00 — 26 commitsSat 21:00 — 15 commitsSat 22:00 — 10 commitsSat 23:00 — 12 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
  • freeCodeCamp/freeCodeCamp

    freeCodeCamp.org's open-source codebase and curriculum. Learn math, programming, and computer science for free.

    453.6K stars · TypeScript

  • openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    385.5K stars · TypeScript

  • openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    384.4K stars · TypeScript

  • openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    384.4K stars · TypeScript

  • openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    384.4K stars · TypeScript

  • affaan-m/ECC

    The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

    238.5K stars · JavaScript