nearai/ironclawPublic

IronClaw is an Agent OS focused on privacy, security and extensibility

AI summary: A secure, privacy-focused Agent Operating System designed as an extensible personal AI assistant.

Stars
12.6K
+-3 today
Forks
1.5K
Watchers
78
Open issues
1.4K
Open PRs
178
Contributors
~120
Commits
4.1K
Branches
1.3K

RustApache-2.0Created Feb 3, 2026Last push 3d agoLatest release ironclaw-v1.4.0+3 stars this week+30 this month

Quick answers

What is ironclaw?
A secure, privacy-focused Agent Operating System designed as an extensible personal AI assistant.
What does ironclaw do?
IronClaw functions as an advanced Agent Operating System that fundamentally prioritizes user privacy, strict security protocols, and high extensibility. It operates as a personal AI assistant uniquely designed to securely handle complex tasks while keeping all user data strictly protected in localized environments. The core architecture is explicitly built to ensure that the assistant remains reliably on the user's side, effectively mitigating the risks of data exposure or unwanted external influence via WASM sandboxing. By providing a highly secure foundational layer, it empowers users to confidently extend the system's capabilities without compromising their personal or professional environment.
Who is ironclaw for?
IronClaw is aimed directly at privacy advocates, security professionals, and developers who necessitate a strictly secure environment for autonomous agents. It requires a solid understanding of self-hosted software and secure system configuration.
How do I get started with ironclaw?
git clone https://github.com/nearai/ironclaw.git
How popular is ironclaw on GitHub?
nearai/ironclaw has 12,634 stars and 1,481 forks on GitHub, and gained 3 stars in the last 7 days.
What license does ironclaw use?
nearai/ironclaw is released under the Apache-2.0 license.

Star history

since Jul 29, 2026
05K10KJul 2026Aug 2026Sep 2026Oct 2026
12.6K stars as of Oct 2, 2026. Measured daily since Jul 29, 2026; GitHub no longer exposes earlier star timestamps.

Contribution activity

commits per day, last 52 weeks
SepOctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-09-27: 0 commits2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 17 commits2026-02-03: 23 commits2026-02-04: 11 commits2026-02-05: 17 commits2026-02-06: 10 commits2026-02-07: 1 commit2026-02-08: 2 commits2026-02-09: 4 commits2026-02-10: 0 commits2026-02-11: 2 commits2026-02-12: 15 commits2026-02-13: 8 commits2026-02-14: 4 commits2026-02-15: 5 commits2026-02-16: 9 commits2026-02-17: 15 commits2026-02-18: 15 commits2026-02-19: 13 commits2026-02-20: 26 commits2026-02-21: 11 commits2026-02-22: 12 commits2026-02-23: 9 commits2026-02-24: 3 commits2026-02-25: 7 commits2026-02-26: 5 commits2026-02-27: 6 commits2026-02-28: 6 commits2026-03-01: 17 commits2026-03-02: 7 commits2026-03-03: 12 commits2026-03-04: 16 commits2026-03-05: 12 commits2026-03-06: 18 commits2026-03-07: 16 commits2026-03-08: 13 commits2026-03-09: 31 commits2026-03-10: 31 commits2026-03-11: 30 commits2026-03-12: 53 commits2026-03-13: 13 commits2026-03-14: 17 commits2026-03-15: 17 commits2026-03-16: 32 commits2026-03-17: 0 commits2026-03-18: 17 commits2026-03-19: 25 commits2026-03-20: 17 commits2026-03-21: 10 commits2026-03-22: 8 commits2026-03-23: 11 commits2026-03-24: 10 commits2026-03-25: 13 commits2026-03-26: 7 commits2026-03-27: 5 commits2026-03-28: 8 commits2026-03-29: 12 commits2026-03-30: 14 commits2026-03-31: 6 commits2026-04-01: 15 commits2026-04-02: 12 commits2026-04-03: 8 commits2026-04-04: 0 commits2026-04-05: 7 commits2026-04-06: 9 commits2026-04-07: 18 commits2026-04-08: 11 commits2026-04-09: 15 commits2026-04-10: 19 commits2026-04-11: 13 commits2026-04-12: 2 commits2026-04-13: 8 commits2026-04-14: 22 commits2026-04-15: 10 commits2026-04-16: 10 commits2026-04-17: 17 commits2026-04-18: 35 commits2026-04-19: 21 commits2026-04-20: 39 commits2026-04-21: 11 commits2026-04-22: 13 commits2026-04-23: 7 commits2026-04-24: 15 commits2026-04-25: 0 commits2026-04-26: 0 commits2026-04-27: 6 commits2026-04-28: 16 commits2026-04-29: 11 commits2026-04-30: 17 commits2026-05-01: 16 commits2026-05-02: 10 commits2026-05-03: 3 commits2026-05-04: 4 commits2026-05-05: 12 commits2026-05-06: 43 commits2026-05-07: 75 commits2026-05-08: 25 commits2026-05-09: 34 commits2026-05-10: 26 commits2026-05-11: 93 commits2026-05-12: 38 commits2026-05-13: 57 commits2026-05-14: 63 commits2026-05-15: 33 commits2026-05-16: 32 commits2026-05-17: 23 commits2026-05-18: 23 commits2026-05-19: 55 commits2026-05-20: 30 commits2026-05-21: 17 commits2026-05-22: 22 commits2026-05-23: 15 commits2026-05-24: 15 commits2026-05-25: 32 commits2026-05-26: 15 commits2026-05-27: 43 commits2026-05-28: 27 commits2026-05-29: 23 commits2026-05-30: 15 commits2026-05-31: 9 commits2026-06-01: 24 commits2026-06-02: 31 commits2026-06-03: 34 commits2026-06-04: 27 commits2026-06-05: 31 commits2026-06-06: 7 commits2026-06-07: 8 commits2026-06-08: 32 commits2026-06-09: 15 commits2026-06-10: 34 commits2026-06-11: 21 commits2026-06-12: 11 commits2026-06-13: 8 commits2026-06-14: 19 commits2026-06-15: 24 commits2026-06-16: 18 commits2026-06-17: 20 commits2026-06-18: 19 commits2026-06-19: 8 commits2026-06-20: 4 commits2026-06-21: 5 commits2026-06-22: 10 commits2026-06-23: 15 commits2026-06-24: 13 commits2026-06-25: 24 commits2026-06-26: 25 commits2026-06-27: 6 commits2026-06-28: 4 commits2026-06-29: 16 commits2026-06-30: 25 commits2026-07-01: 30 commits2026-07-02: 17 commits2026-07-03: 23 commits2026-07-04: 16 commits2026-07-05: 2 commits2026-07-06: 28 commits2026-07-07: 21 commits2026-07-08: 16 commits2026-07-09: 24 commits2026-07-10: 29 commits2026-07-11: 9 commits2026-07-12: 5 commits2026-07-13: 27 commits2026-07-14: 12 commits2026-07-15: 10 commits2026-07-16: 11 commits2026-07-17: 38 commits2026-07-18: 29 commits2026-07-19: 21 commits2026-07-20: 28 commits2026-07-21: 27 commits2026-07-22: 21 commits2026-07-23: 28 commits2026-07-24: 16 commits2026-07-25: 9 commits2026-07-26: 3 commits2026-07-27: 16 commits2026-07-28: 24 commits2026-07-29: 27 commits2026-07-30: 26 commits2026-07-31: 42 commits2026-08-01: 7 commits2026-08-02: 4 commits2026-08-03: 17 commits2026-08-04: 23 commits2026-08-05: 17 commits2026-08-06: 14 commits2026-08-07: 23 commits2026-08-08: 14 commits2026-08-09: 3 commits2026-08-10: 23 commits2026-08-11: 15 commits2026-08-12: 15 commits2026-08-13: 20 commits2026-08-14: 12 commits2026-08-15: 5 commits2026-08-16: 1 commit2026-08-17: 12 commits2026-08-18: 7 commits2026-08-19: 10 commits2026-08-20: 15 commits2026-08-21: 12 commits2026-08-22: 4 commits2026-08-23: 1 commit2026-08-24: 11 commits2026-08-25: 7 commits2026-08-26: 13 commits2026-08-27: 15 commits2026-08-28: 14 commits2026-08-29: 1 commit2026-08-30: 0 commits2026-08-31: 2 commits2026-09-01: 8 commits2026-09-02: 8 commits2026-09-03: 9 commits2026-09-04: 2 commits2026-09-05: 2 commits2026-09-06: 0 commits2026-09-07: 0 commits2026-09-08: 0 commits2026-09-09: 0 commits2026-09-10: 1 commit2026-09-11: 0 commits2026-09-12: 0 commits2026-09-13: 0 commits2026-09-14: 0 commits2026-09-15: 0 commits2026-09-16: 0 commits2026-09-17: 0 commits2026-09-18: 0 commits2026-09-19: 0 commits2026-09-20: 0 commits2026-09-21: 0 commits2026-09-22: 0 commits2026-09-23: 0 commits2026-09-24: 0 commits2026-09-25: 0 commits2026-09-26: 0 commits
3,609 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    12,634 stars

  • Very active

    3,609 commits in 52 weeks

  • Community-driven

    ~120 contributors

  • Permissive license

    Apache-2.0

  • Continuous integration

    Automated checks passing

  • Repeat trending

    6 trending appearances

What ironclaw does

IronClaw functions as an advanced Agent Operating System that fundamentally prioritizes user privacy, strict security protocols, and high extensibility. It operates as a personal AI assistant uniquely designed to securely handle complex tasks while keeping all user data strictly protected in localized environments. The core architecture is explicitly built to ensure that the assistant remains reliably on the user's side, effectively mitigating the risks of data exposure or unwanted external influence via WASM sandboxing. By providing a highly secure foundational layer, it empowers users to confidently extend the system's capabilities without compromising their personal or professional environment.

IronClaw is aimed directly at privacy advocates, security professionals, and developers who necessitate a strictly secure environment for autonomous agents. It requires a solid understanding of self-hosted software and secure system configuration.

  • Privacy-first architecture: Systematically ensures that all user data and interactions are handled securely and kept strictly private.
  • Agent OS foundation: Delivers a highly robust operating system-level environment explicitly for running complex autonomous tasks.
  • High extensibility: Empowers users to securely add new capabilities and custom tools to their personal AI assistant.
  • Local execution focus: Heavily emphasizes running operations locally to actively minimize reliance on external, potentially insecure APIs.
  • Secure task handling: Employs stringent security measures, including WASM sandboxing, to prevent data leaks during autonomous operations.

Where teams use it

Secure personal assistance

Privacy-conscious users can reliably deploy IronClaw to manage personal schedules and private data without exposing information to corporate clouds.

Confidential data processing

Professionals can confidently use the agent to analyze highly sensitive documents locally, ensuring critical data never leaves their machine.

Custom agent development

Software developers can build directly upon the extensible OS to create highly specialized, secure, and isolated automation tools.

Private communication management

Users can seamlessly integrate the system with messaging platforms to handle communications securely, autonomously, and privately.

Getting started: git clone https://github.com/nearai/ironclaw.git

README

main branch

IronClaw

IronClaw

Your secure personal AI assistant, always on your side

License: MIT OR Apache-2.0 Telegram: @ironclawAI Reddit: r/ironclawAI gitcgr

English | 简体中文 | Русский | 日本語 | 한국어

Quick Start • Philosophy • Features • Installation • Configuration • Security • Architecture


Quick Start

Choose an ironclaw-v* tag from the Releases page, then install it on macOS, Linux, or Windows/WSL. Replace X.Y.Z with the selected version, including any prerelease suffix:

IRONCLAW_RELEASE_TAG=ironclaw-vX.Y.Z
curl --proto '=https' --tlsv1.2 -LsSf \
  "https://github.com/nearai/ironclaw/releases/download/${IRONCLAW_RELEASE_TAG}/ironclaw-installer.sh" | sh

Then run the guided setup:

ironclaw onboard

Choose an LLM provider, enter its API key in the hidden prompt, and accept the default model or enter another one. IronClaw provisions its local configuration, encrypted credential store, and WebUI login token. On macOS and Linux it also installs and starts the background service, then prints a link that opens the WebUI.

Use ironclaw status to check the service and print the login link again. Windows users can start the WebUI in the foreground with ironclaw serve. See Installation for Windows installers and source builds.

Philosophy

IronClaw is built on a simple principle: your AI assistant should work for you, not against you.

In a world where AI systems are increasingly opaque about data handling and aligned with corporate interests, IronClaw takes a different approach:

  • Your data stays yours - All information is stored locally, encrypted, and never leaves your control
  • Transparency by design - Open source, auditable, no hidden telemetry or data harvesting
  • Self-expanding capabilities - Build new tools on the fly without waiting for vendor updates
  • Defense in depth - Multiple security layers protect against prompt injection and data exfiltration

IronClaw is the AI assistant you can actually trust with your personal and professional life.

Features

Security First

  • WASM Sandbox - Untrusted tools run in isolated WebAssembly containers with capability-based permissions
  • Credential Protection - Secrets are never exposed to tools; injected at the host boundary with leak detection
  • Prompt Injection Defense - Pattern detection, content sanitization, and policy enforcement
  • Endpoint Allowlisting - HTTP requests only to explicitly approved hosts and paths

Always Available

  • Multi-channel - REPL, HTTP webhooks, WASM channels (Telegram, Slack), and web gateway
  • Docker Sandbox - Isolated container execution with per-job tokens and orchestrator/worker pattern
  • Web Gateway - Browser UI with real-time SSE/WebSocket streaming
  • Routines - Cron schedules, event triggers, webhook handlers for background automation
  • Heartbeat System - Proactive background execution for monitoring and maintenance tasks
  • Parallel Jobs - Handle multiple requests concurrently with isolated contexts
  • Self-repair - Automatic detection and recovery of stuck operations

Self-Expanding

  • Dynamic Tool Building - Describe what you need, and IronClaw builds it as a WASM tool
  • MCP Protocol - Connect to Model Context Protocol servers for additional capabilities
  • Plugin Architecture - Drop in new WASM tools and channels without restarting

Persistent Memory

  • Hybrid Search - Full-text + vector search using Reciprocal Rank Fusion
  • Workspace Filesystem - Flexible path-based storage for notes, logs, and context
  • Identity Files - Maintain consistent personality and preferences across sessions

Installation

The Releases page provides pre-built binaries and installers.

Install via Windows Installer (Windows)

Open the selected ironclaw-v* release, download ironclaw-x86_64-pc-windows-msvc.msi, and run it.

Install via PowerShell script (Windows)
$IronClawReleaseTag = "ironclaw-vX.Y.Z"
irm "https://github.com/nearai/ironclaw/releases/download/$IronClawReleaseTag/ironclaw-installer.ps1" | iex
Install via shell script (macOS, Linux, Windows/WSL)
IRONCLAW_RELEASE_TAG=ironclaw-vX.Y.Z
curl --proto '=https' --tlsv1.2 -LsSf \
  "https://github.com/nearai/ironclaw/releases/download/${IRONCLAW_RELEASE_TAG}/ironclaw-installer.sh" | sh
Build and install from source

Source builds require Rust 1.96+ and Node.js 22+ with Corepack/pnpm.

git clone https://github.com/nearai/ironclaw.git
cd ironclaw
corepack enable pnpm
cargo install --locked --path crates/app/ironclaw_cli

Configuration

ironclaw onboard is the primary configuration path. It writes Reborn state under $HOME/.ironclaw/reborn by default, stores the selected LLM credential in the encrypted local secret store, and preserves existing configuration when it is run again.

Inspect the current setup with:

ironclaw status
ironclaw models status
ironclaw config list

To switch providers after onboarding, select the route and then store its API key using the hidden prompt:

ironclaw models set-provider openai --model gpt-5-mini
ironclaw config set openai.api_key

Additional settings use the same command. For example:

ironclaw config set google.client_id YOUR_CLIENT_ID
ironclaw config set google.client_secret
ironclaw config set google.redirect_uri YOUR_REDIRECT_URI
ironclaw config set webui.token --rotate

Secret values never accept a positional argument; IronClaw prompts for them without echoing the value. Channels such as Slack and Telegram have no configuration-file settings and no CLI enablement key: install the extension and complete its setup on the WebUI Extensions page, which is what makes the route serve.

Configuration writes never restart the service automatically. Run ironclaw service restart after a change that affects the running service, and use ironclaw config set --help for the complete list of supported keys.

Security

IronClaw implements defense in depth to protect your data and prevent misuse.

WASM Sandbox

All untrusted tools run in isolated WebAssembly containers:

  • Capability-based permissions - Explicit opt-in for HTTP, secrets, tool invocation
  • Endpoint allowlisting - HTTP requests only to approved hosts/paths
  • Credential injection - Secrets injected at host boundary, never exposed to WASM code
  • Leak detection - Scans requests and responses for secret exfiltration attempts
  • Rate limiting - Per-tool request limits to prevent abuse
  • Resource limits - Memory, CPU, and execution time constraints
WASM ──► Allowlist ──► Leak Scan ──► Credential ──► Execute ──► Leak Scan ──► WASM
         Validator     (request)     Injector       Request     (response)

Prompt Injection Defense

External content passes through multiple security layers:

  • Pattern-based detection of injection attempts
  • Content sanitization and escaping
  • Policy rules with severity levels (Block/Warn/Review/Sanitize)
  • Tool output wrapping for safe LLM context injection

Data Protection

  • All data stored locally in IronClaw's application state
  • Secrets encrypted with AES-256-GCM
  • No telemetry, analytics, or data sharing
  • Full audit log of all tool executions

Architecture

┌────────────────────────────────────────────────────────────────┐
│                          Channels                              │
│  ┌──────┐  ┌──────┐   ┌─────────────┐  ┌─────────────┐         │
│  │ REPL │  │ HTTP │   │WASM Channels│  │ Web Gateway │         │
│  └──┬───┘  └──┬───┘   └──────┬──────┘  │ (SSE + WS)  │         │
│     │         │              │         └──────┬──────┘         │
│     └─────────┴──────────────┴────────────────┘                │
│                              │                                 │
│                    ┌─────────▼─────────┐                       │
│                    │    Agent Loop     │  Intent routing       │
│                    └────┬──────────┬───┘                       │
│                         │          │                           │
│              ┌──────────▼────┐  ┌──▼───────────────┐           │
│              │  Scheduler    │  │ Routines Engine  │           │
│              │(parallel jobs)│  │(cron, event, wh) │           │
│              └──────┬────────┘  └────────┬─────────┘           │
│                     │                    │                     │
│       ┌─────────────┼────────────────────┘                     │
│       │             │                                          │
│   ┌───▼─────┐  ┌────▼────────────────┐                         │
│   │ Local   │  │    Orchestrator     │                         │
│   │Workers  │  │  ┌───────────────┐  │                         │
│   │(in-proc)│  │  │ Docker Sandbox│  │                         │
│   └───┬─────┘  │  │   Containers  │  │                         │
│       │        │  │ ┌───────────┐ │  │                         │
│       │        │  │ │Worker / CC│ │  │                         │
│       │        │  │ └───────────┘ │  │                         │
│       │        │  └───────────────┘  │                         │
│       │        └─────────┬───────────┘                         │
│       └──────────────────┤                                     │
│                          │                                     │
│              ┌───────────▼──────────┐                          │
│              │    Tool Registry     │                          │
│              │  Built-in, MCP, WASM │                          │
│              └──────────────────────┘                          │
└────────────────────────────────────────────────────────────────┘

Core Components

Component Purpose
Agent Loop Main message handling and job coordination
Router Classifies user intent (command, query, task)
Scheduler Manages parallel job execution with priorities
Worker Executes jobs with LLM reasoning and tool calls
Orchestrator Container lifecycle, LLM proxying, per-job auth
Web Gateway Browser UI with chat, memory, jobs, logs, extensions, routines
Routines Engine Scheduled (cron) and reactive (event, webhook) background tasks
Workspace Persistent memory with hybrid search
Safety Layer Prompt injection defense and content sanitization

Usage

# Check the background service and print the WebUI login link
ironclaw status

# Start an interactive terminal session
ironclaw repl

# Run one turn
ironclaw run --message "hello"

Development

# Format code
cargo fmt

# Lint
cargo clippy --all --benches --tests --examples --all-features

# Run tests
createdb ironclaw_test
cargo test

# Run specific test
cargo test test_name

OpenClaw Heritage

IronClaw is a Rust reimplementation inspired by OpenClaw. See FEATURE_PARITY.md for the complete tracking matrix.

Key differences:

  • Rust vs TypeScript - Native performance, memory safety, single binary
  • WASM sandbox vs Docker - Lightweight, capability-based security
  • PostgreSQL vs SQLite - Production-ready persistence
  • Security-first design - Multiple defense layers, credential protection

License

Licensed under either of:

at your option.

View on GitHub

Recent activity

commits and pull requests

Recent open issues

view all

Releases and announcements

48 total
  1. 1.4.0 - 2026-08-27ironclaw-v1.4.0Aug 28, 20261.9K downloads

    ## Release Notes Stable promotion of `1.4.0-rc.1`, covering the 81 commits since `ironclaw-v1.3.0` and the complete release-candidate scope below. ### Added - Durable notification inbox: runs publish authoritative outcomes and actionable gates to a per-user inbox, surfaced by the WebUI notification center, so approvals and auth prompts survive a missed session. - Background subagents: a parent turn can spawn children that run and deliver on their own, with per-child delivery, activation provenance, a derived cap on autonomous wakes, and healing sweeps for orphaned children. - Persistent per-user sandbox containers on the local-Docker profile, reached over Docker Exec so container-local installs and state survive between commands. The Railway preview profile still runs an ephemeral worker per command and keeps only its checkpointed workspace. - Managed per-user sandbox egress proxy, with manifest-declared direct-exec credential bindings that stay behind it so secrets are never handed to sandboxed code. - Run-now for automations, plus exact run capability facts. - Durable backend suggestions generated over the user's own no-approval, read-only tools and gated o

  2. 1.4.0-rc.1 - 2026-08-26ironclaw-v1.4.0-rc.1Aug 27, 2026pre-release340 downloads

    ## Release Notes First release candidate for 1.4.0, covering the 81 commits since `ironclaw-v1.3.0`. ### Added - Durable notification inbox: runs publish authoritative outcomes and actionable gates to a per-user inbox, surfaced by the WebUI notification center, so approvals and auth prompts survive a missed session. - Background subagents: a parent turn can spawn children that run and deliver on their own, with per-child delivery, activation provenance, a derived cap on autonomous wakes, and healing sweeps for orphaned children. - Persistent per-user sandbox containers on the local-Docker profile, reached over Docker Exec so container-local installs and state survive between commands. The Railway preview profile still runs an ephemeral worker per command and keeps only its checkpointed workspace. - Managed per-user sandbox egress proxy, with manifest-declared direct-exec credential bindings that stay behind it so secrets are never handed to sandboxed code. - Run-now for automations, plus exact run capability facts. - Durable backend suggestions generated over the user's own no-approval, read-only tools and gated on connected extensions. - Google Docs semantic

  3. 1.3.0 - 2026-08-19ironclaw-v1.3.0Aug 19, 20261.1K downloads

    ## Release Notes Stable promotion of `1.3.0-rc.2`, including the upgrade and container fixes validated in RC2 and the complete RC1 scope below. ### Fixed in 1.3.0-rc.2 - Upgrades from 1.2 now accept and preserve the released extension `activation_state` field instead of crash-looping during startup. - The canonical Reborn runtime image again supports opt-in, public-key-only worker SSH on port 2222 while running IronClaw as an unprivileged user. ### Added - **Per-user model preferences.** Each user picks their own model from WebUI settings, the CLI, or chat commands, and the choice follows them through channel turns and inbound replay. Admins bound what is selectable with a tenant-scoped model selection policy. - **Structured automations.** A scheduled trigger now carries a validated execution contract — prompt spec, execution policy, required skills — checked by a fail-closed preflight at creation instead of a free-form prompt string, and unattended runs get their own protocol. A deterministic no-result sentinel lets a run that has nothing to report finish silently instead of delivering filler. - **Document editing.** Structural edits to `.docx`, `.xlsx`, a

  4. 1.3.0-rc.2 - 2026-08-18ironclaw-v1.3.0-rc.2Aug 18, 2026pre-release331 downloads

    ## Release Notes ### Fixed in 1.3.0-rc.2 - Upgrades from 1.2 now accept and preserve the released extension `activation_state` field instead of crash-looping during startup. - The canonical Reborn runtime image again supports opt-in, public-key-only worker SSH on port 2222 while running IronClaw as an unprivileged user. ## Install ironclaw 1.3.0-rc.2 ### Install prebuilt binaries via shell script ```sh curl --proto '=https' --tlsv1.2 -LsSf https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.2/ironclaw-installer.sh | sh ``` ### Install prebuilt binaries via powershell script ```sh powershell -ExecutionPolicy Bypass -c "irm https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.2/ironclaw-installer.ps1 | iex" ``` ## Download ironclaw 1.3.0-rc.2 | File | Platform | Checksum | |--------|----------|----------| | [ironclaw-aarch64-apple-darwin.tar.gz](https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.2/ironclaw-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.2/ironclaw-aarch64-apple-darwin.tar.gz.sha256) | | [ironclaw-x86_64-app

  5. 1.3.0-rc.1 - 2026-08-17ironclaw-v1.3.0-rc.1Aug 17, 2026pre-release256 downloads

    ## Release Notes ## Install ironclaw 1.3.0-rc.1 ### Install prebuilt binaries via shell script ```sh curl --proto '=https' --tlsv1.2 -LsSf https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.1/ironclaw-installer.sh | sh ``` ### Install prebuilt binaries via powershell script ```sh powershell -ExecutionPolicy Bypass -c "irm https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.1/ironclaw-installer.ps1 | iex" ``` ## Download ironclaw 1.3.0-rc.1 | File | Platform | Checksum | |--------|----------|----------| | [ironclaw-aarch64-apple-darwin.tar.gz](https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.1/ironclaw-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.1/ironclaw-aarch64-apple-darwin.tar.gz.sha256) | | [ironclaw-x86_64-apple-darwin.tar.gz](https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.1/ironclaw-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/nearai/ironclaw/releases/download/ironclaw-v1.3.0-rc.1/ironclaw-x86_64-apple-darwin.tar.gz.sha256) | | [ironclaw-x86_64-pc-windows-msv

Code frequency

additions and deletions
+1.9M-1.9MWeek of 2026-02-01: +83,379 linesWeek of 2026-02-01: -12,205 linesWeek of 2026-02-08: +50,162 linesWeek of 2026-02-08: -7,677 linesWeek of 2026-02-15: +79,090 linesWeek of 2026-02-15: -19,826 linesWeek of 2026-02-22: +31,958 linesWeek of 2026-02-22: -2,805 linesWeek of 2026-03-01: +50,615 linesWeek of 2026-03-01: -5,908 linesWeek of 2026-03-08: +79,547 linesWeek of 2026-03-08: -22,660 linesWeek of 2026-03-15: +51,812 linesWeek of 2026-03-15: -10,857 linesWeek of 2026-03-22: +32,305 linesWeek of 2026-03-22: -4,836 linesWeek of 2026-03-29: +91,720 linesWeek of 2026-03-29: -10,021 linesWeek of 2026-04-05: +156,436 linesWeek of 2026-04-05: -34,406 linesWeek of 2026-04-12: +59,087 linesWeek of 2026-04-12: -13,333 linesWeek of 2026-04-19: +118,677 linesWeek of 2026-04-19: -42,135 linesWeek of 2026-04-26: +129,929 linesWeek of 2026-04-26: -10,039 linesWeek of 2026-05-03: +170,035 linesWeek of 2026-05-03: -54,336 linesWeek of 2026-05-10: +144,017 linesWeek of 2026-05-10: -37,008 linesWeek of 2026-05-17: +163,858 linesWeek of 2026-05-17: -70,334 linesWeek of 2026-05-24: +246,220 linesWeek of 2026-05-24: -39,915 linesWeek of 2026-05-31: +177,376 linesWeek of 2026-05-31: -31,094 linesWeek of 2026-06-07: +136,676 linesWeek of 2026-06-07: -19,132 linesWeek of 2026-06-14: +114,192 linesWeek of 2026-06-14: -13,575 linesWeek of 2026-06-21: +132,061 linesWeek of 2026-06-21: -46,606 linesWeek of 2026-06-28: +255,380 linesWeek of 2026-06-28: -242,510 linesWeek of 2026-07-05: +436,794 linesWeek of 2026-07-05: -313,539 linesWeek of 2026-07-12: +313,528 linesWeek of 2026-07-12: -205,164 linesWeek of 2026-07-19: +550,101 linesWeek of 2026-07-19: -983,943 linesWeek of 2026-07-26: +287,409 linesWeek of 2026-07-26: -208,214 linesWeek of 2026-08-02: +1,945,891 linesWeek of 2026-08-02: -1,795,251 linesWeek of 2026-08-09: +197,438 linesWeek of 2026-08-09: -69,793 linesWeek of 2026-08-16: +107,729 linesWeek of 2026-08-16: -70,059 linesWeek of 2026-08-23: +62,768 linesWeek of 2026-08-23: -6,947 linesWeek of 2026-08-30: +54,332 linesWeek of 2026-08-30: -12,583 linesWeek of 2026-09-06: +820 linesWeek of 2026-09-06: -39 linesWeek of 2026-09-13: +0 linesWeek of 2026-09-13: -0 linesWeek of 2026-09-20: +0 linesWeek of 2026-09-20: -0 linesFeb 1, 2026Sep 20, 2026
+6.5M lines added, -4.4M removed over the last year.

Commits per week

last 52 weeks
3420Week of 2025-09-27: 0 commitsWeek of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 0 commitsWeek of 2026-02-01: 79 commitsWeek of 2026-02-08: 35 commitsWeek of 2026-02-15: 94 commitsWeek of 2026-02-22: 48 commitsWeek of 2026-03-01: 98 commitsWeek of 2026-03-08: 188 commitsWeek of 2026-03-15: 118 commitsWeek of 2026-03-22: 62 commitsWeek of 2026-03-29: 67 commitsWeek of 2026-04-05: 92 commitsWeek of 2026-04-12: 104 commitsWeek of 2026-04-19: 106 commitsWeek of 2026-04-26: 76 commitsWeek of 2026-05-03: 196 commitsWeek of 2026-05-10: 342 commitsWeek of 2026-05-17: 185 commitsWeek of 2026-05-24: 170 commitsWeek of 2026-05-31: 163 commitsWeek of 2026-06-07: 129 commitsWeek of 2026-06-14: 112 commitsWeek of 2026-06-21: 98 commitsWeek of 2026-06-28: 131 commitsWeek of 2026-07-05: 129 commitsWeek of 2026-07-12: 132 commitsWeek of 2026-07-19: 150 commitsWeek of 2026-07-26: 145 commitsWeek of 2026-08-02: 112 commitsWeek of 2026-08-09: 93 commitsWeek of 2026-08-16: 61 commitsWeek of 2026-08-23: 62 commitsWeek of 2026-08-30: 31 commitsWeek of 2026-09-06: 1 commitsWeek of 2026-09-13: 0 commitsWeek of 2026-09-20: 0 commitsSep 27, 2025Sep 20, 2026
3.6K commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 33 commitsSun 1:00 — 10 commitsSun 2:00 — 6 commitsSun 3:00 — 3 commitsSun 4:00 — 4 commitsSun 5:00 — 8 commitsSun 6:00 — 1 commitsSun 7:00 — 3 commitsSun 8:00 — 5 commitsSun 9:00 — 6 commitsSun 10:00 — 6 commitsSun 11:00 — 2 commitsSun 12:00 — 9 commitsSun 13:00 — 16 commitsSun 14:00 — 15 commitsSun 15:00 — 10 commitsSun 16:00 — 12 commitsSun 17:00 — 9 commitsSun 18:00 — 6 commitsSun 19:00 — 9 commitsSun 20:00 — 19 commitsSun 21:00 — 20 commitsSun 22:00 — 34 commitsSun 23:00 — 22 commitsMon 0:00 — 21 commitsMon 1:00 — 7 commitsMon 2:00 — 7 commitsMon 3:00 — 4 commitsMon 4:00 — 10 commitsMon 5:00 — 2 commitsMon 6:00 — 6 commitsMon 7:00 — 7 commitsMon 8:00 — 19 commitsMon 9:00 — 21 commitsMon 10:00 — 30 commitsMon 11:00 — 33 commitsMon 12:00 — 50 commitsMon 13:00 — 30 commitsMon 14:00 — 36 commitsMon 15:00 — 42 commitsMon 16:00 — 49 commitsMon 17:00 — 43 commitsMon 18:00 — 28 commitsMon 19:00 — 24 commitsMon 20:00 — 22 commitsMon 21:00 — 46 commitsMon 22:00 — 40 commitsMon 23:00 — 41 commitsTue 0:00 — 33 commitsTue 1:00 — 14 commitsTue 2:00 — 11 commitsTue 3:00 — 7 commitsTue 4:00 — 5 commitsTue 5:00 — 6 commitsTue 6:00 — 3 commitsTue 7:00 — 5 commitsTue 8:00 — 8 commitsTue 9:00 — 18 commitsTue 10:00 — 20 commitsTue 11:00 — 27 commitsTue 12:00 — 28 commitsTue 13:00 — 37 commitsTue 14:00 — 41 commitsTue 15:00 — 42 commitsTue 16:00 — 54 commitsTue 17:00 — 19 commitsTue 18:00 — 24 commitsTue 19:00 — 23 commitsTue 20:00 — 20 commitsTue 21:00 — 37 commitsTue 22:00 — 27 commitsTue 23:00 — 28 commitsWed 0:00 — 23 commitsWed 1:00 — 11 commitsWed 2:00 — 17 commitsWed 3:00 — 13 commitsWed 4:00 — 7 commitsWed 5:00 — 4 commitsWed 6:00 — 6 commitsWed 7:00 — 10 commitsWed 8:00 — 13 commitsWed 9:00 — 18 commitsWed 10:00 — 21 commitsWed 11:00 — 40 commitsWed 12:00 — 37 commitsWed 13:00 — 46 commitsWed 14:00 — 36 commitsWed 15:00 — 46 commitsWed 16:00 — 48 commitsWed 17:00 — 35 commitsWed 18:00 — 34 commitsWed 19:00 — 27 commitsWed 20:00 — 21 commitsWed 21:00 — 25 commitsWed 22:00 — 44 commitsWed 23:00 — 30 commitsThu 0:00 — 35 commitsThu 1:00 — 15 commitsThu 2:00 — 14 commitsThu 3:00 — 10 commitsThu 4:00 — 6 commitsThu 5:00 — 4 commitsThu 6:00 — 7 commitsThu 7:00 — 11 commitsThu 8:00 — 16 commitsThu 9:00 — 19 commitsThu 10:00 — 19 commitsThu 11:00 — 36 commitsThu 12:00 — 39 commitsThu 13:00 — 40 commitsThu 14:00 — 56 commitsThu 15:00 — 39 commitsThu 16:00 — 31 commitsThu 17:00 — 37 commitsThu 18:00 — 33 commitsThu 19:00 — 24 commitsThu 20:00 — 28 commitsThu 21:00 — 45 commitsThu 22:00 — 44 commitsThu 23:00 — 54 commitsFri 0:00 — 31 commitsFri 1:00 — 12 commitsFri 2:00 — 15 commitsFri 3:00 — 5 commitsFri 4:00 — 8 commitsFri 5:00 — 6 commitsFri 6:00 — 7 commitsFri 7:00 — 4 commitsFri 8:00 — 14 commitsFri 9:00 — 14 commitsFri 10:00 — 28 commitsFri 11:00 — 43 commitsFri 12:00 — 36 commitsFri 13:00 — 34 commitsFri 14:00 — 37 commitsFri 15:00 — 43 commitsFri 16:00 — 39 commitsFri 17:00 — 50 commitsFri 18:00 — 30 commitsFri 19:00 — 18 commitsFri 20:00 — 25 commitsFri 21:00 — 19 commitsFri 22:00 — 17 commitsFri 23:00 — 32 commitsSat 0:00 — 32 commitsSat 1:00 — 22 commitsSat 2:00 — 7 commitsSat 3:00 — 5 commitsSat 4:00 — 8 commitsSat 5:00 — 4 commitsSat 6:00 — 6 commitsSat 7:00 — 6 commitsSat 8:00 — 10 commitsSat 9:00 — 8 commitsSat 10:00 — 9 commitsSat 11:00 — 19 commitsSat 12:00 — 15 commitsSat 13:00 — 16 commitsSat 14:00 — 14 commitsSat 15:00 — 15 commitsSat 16:00 — 15 commitsSat 17:00 — 10 commitsSat 18:00 — 17 commitsSat 19:00 — 17 commitsSat 20:00 — 14 commitsSat 21:00 — 14 commitsSat 22:00 — 32 commitsSat 23:00 — 34 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Mar 9, 2026daily#12+197
Mar 8, 2026daily#19+247
Mar 7, 2026daily#9+368
Mar 6, 2026daily#10+302
Feb 16, 2026daily#17+162
Feb 14, 2026daily#24+139
  • openclaw/openclaw

    The AI that really does things. Any OS. Any Platform. The lobster way. 🦞

    391.3K stars · TypeScript

  • ultraworkers/claw-code

    An agent-managed museum exhibit, built in Rust with Gajae-Code / LazyCodex — developed and maintained with no human intervention.

    195.2K stars · Rust

  • farion1231/cc-switch

    A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

    140K stars · Rust

  • openai/codex

    Lightweight coding agent that runs in your terminal

    127.8K stars · Rust

  • Graphify-Labs/graphify

    Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing, every edge explained, no vector store.

    123.7K stars · Python

  • denoland/deno

    A modern runtime for JavaScript and TypeScript.

    108.6K stars · Rust