Changelog 2026
2026
2026-09 (latest)
CLI 0.61.4–0.61.6 (2026-09-15)
0.61.6. The CLI config file, which holds the cloud session token, stayed 0600
only until the next unrelated config write (conf rewrites the file atomically);
it is 0600 for good now. 1claw daemon start --socket-group <group> shares the
daemon socket (0660) with an agent running as its own Unix user, so the agent
reaches policy-gated secrets but not the human's session; login now warns on
a host that has a local vault or daemon.
1claw agent binding proxy <binding> and 1claw daemon proxy <secret> --base-url <url>. A local HTTP front for one execution
binding, for vendor CLIs and SDKs that accept a base-URL override. Each request
becomes POST /v1/agents/{id}/execute for the binding; the vault applies the
host and path allowlists and the agent's policies, injects the credential, and
the upstream response comes back. The tool's own credential is dropped locally
and never forwarded, so a placeholder satisfies its "key must be non-empty"
check. A refusal is a 403; an unreachable vault is a 502 and the tool stops.
Written for the Bankr CLI (BANKR_API_URL), whose bankr login otherwise
leaves the real key in ~/.bankr/config.json where any agent on the host can
read it. The Bankr guide now leads with keeping the
key off the machine. The Shroud bankr provider is documented for what it is:
the LLM chat endpoint only. The daemon form runs the same proxy in front of the
local daemon: policy and injection come from the local vault, and nothing
leaves the machine except the upstream call.
v0.61.9 – v0.61.11 (2026-09-12 → 13)
Control plane. 1claw.co/dashboard now opens on a
live topology map of the org — agents, the policies they hold, the vaults those
grant, the chains they sign on and the systems they call — with a threat
register ranked by blast radius, metrics, a Sankey of who actually read from
which vault, and an SSE signal stream with Last-Event-ID resume. Every agent
carries a continuous 0–100 trust score recomputed every 30 s from policy
denials, threat hits, egress blocks and spend velocity; the engine runs in
recommend-only mode (findings are shadow: true) and never auto-suspends.
Dark mode, touch, keyboard shortcuts (?), search (/), filters, a minimap
for large orgs, and per-org layout persistence. Docs:
Dashboard → Control plane.
API. GET /v1/otel/{stream,topology,threats,summary,metrics,flows} and
GET /v1/otel/agents/{id}/trust — human users only; agents are 403 so a
compromised agent cannot read the org's map. Team orgs can fan the same
signals out to their own collector over OTLP/HTTP JSON
(/v1/org/settings/otel-export). Signal attributes are redacted at the source
before they are buffered.
Platform apps get the same views over their own connections' agents —
GET /v1/platform/connections/{id}/otel/{topology,threats,summary,stream}.
The topology is walked outward from the connection's agents, so a vault shared
with another tenant's agent never reveals that agent. SDK 0.61.12 adds
client.otel (with an async-iterator stream()) and
client.platform.getConnectionOtel*; MCP 0.61.1 adds
platform_get_connection_otel_{summary,threats,topology}.
Also. Deleting an agent now removes its access policies (1,427 orphaned rows from earlier deletions were swept); trust-score history only records a sample when the score moves, and is pruned after 30 days.
v0.61.0 (2026-09-07)
1claw pay. An agent can now pay somebody else's x402 paywall, under a
passkey or a capped spending grant. 1claw pay --agent <id> <url> fetches,
captures the 402, gets it authorized, signs, and retries — Base USDC on the
direct-fetch path.
The CLI holds the network connection and nothing else. It sends the vault the
exact bytes the paywall served; the vault computes the digest, decides what may
be signed, and renders the authorize page from that stored preimage rather than
from anything the client claims about it. The digest binds the transfer
value, not the challenge's maxAmountRequired ceiling, so what a person
approves and what gets signed cannot drift.
--mode is a request. pay_require_passkey defaults to true, and while it is
true every payment needs a human touch — an allowlisted recipient does not
bypass that, it only widens which recipients a grant may cover. auto is never
honoured while a passkey is required; it degrades to the ceremony the agent is
configured for. An unattended agent with no allowlist pays nobody: a null
allowlist is not a wildcard.
Spending grants turn one touch into a cap and a window. The cap is decremented in a single guarded statement, so two concurrent payments cannot both spend the last dollar, and a grant can never exceed the agent's own maximum cap or window.
Limits are charged at signing, not settlement. A signature that was produced
and then lost still consumed authority. Reporting a failure afterwards returns
"limit_released": false — only a vault-verified reconciliation can give
headroom back, and that is not built yet.
When a challenge window closes, the CLI re-fetches the resource rather than re-using the challenge it holds: the stored bytes would reproduce the same closed window, and many challenges carry a single-use nonce. It tries twice, then says so and suggests a grant.
New: PATCH /v1/agents/{id}/pay/settings, POST .../pay/prepare, .../pay/sign,
.../pay/grants, .../pay/{payment_id}/result, GET .../pay/{payment_id},
GET|POST /v1/pay-sessions/{id}, POST /v1/pay-sessions/{id}/authorize,
DELETE /v1/pay-grants/{id}.
Supported: USDC/USDT on Base, Optimism, Avalanche, BNB Chain and Solana — EIP-3009 on the EVM chains, a signed SPL transfer on Solana, chosen by the chain rather than by a flag. Every address and mint verified on-chain; BNB Chain stables are 18 decimals, not 6, and treating them as 6 would understate a payment by 10^12. An unlisted asset is refused rather than guessed at. Signing happens in the vault, not yet in the Shroud TEE. The dashboard authorize page is not built; the endpoint behind it is.
See Paying x402 paywalls.
v0.60.1 (2026-09-07)
Directory job board. Post a task to the agent directory, receive bids from
discoverable agents, award the work. POST /v1/directory/jobs, .../bids,
.../accept/{bid_id}, .../cancel, .../complete. The award returns a handoff
pointing at the bidder's own a2a_url — 1Claw hosts the board, not the runtime.
Job and bid text is written by one party and read by another party's model, so every field is inspected before it is stored. High-confidence injection is refused; anything below that threshold is returned as an untrusted-content envelope rather than a string, server-side, for every client. The SDK types it so passing it into a prompt is a type error. MCP gets read-and-bid tools only. See Directory job board.
Policy presets compile to Cedar (Team+).
POST /v1/agents/{id}/policy-preset/cedar returns the Cedar a preset produces,
validated against the deployed schema. It does not convert the presets' USD
limits into value_gwei — that needs a live price, and a price written into a
policy is wrong the moment it is written. Those limits come back as
residual_guardrails and stay with the guardrail columns.
See Policy presets.
Honcho connector fixed. The preset pointed at a host that does not answer;
it now points at api.honcho.dev. The production suite dials every preset's
base_url, because every static check passed while the host was dead.
Security fixes. Configuring an email or push notification target no longer
suppresses approval notifications — suppression is keyed on the channels that
actually deliver. Notification targets always belong to their creator.
X-Platform-Connection is validated against the caller everywhere it is read.
New-recipient risk elevation is derived server-side instead of read from the
requesting agent's own payload. Connected Account OAuth2 tokens are now attached
to outbound requests. Reports on a listing are one per person and clearable.
v0.60.0 (2026-09-06)
Fleet management — every agent one bootstrap template provisioned, managed as one cohort.
GET /v1/platform/apps/{id}/fleets/{template_id} and /agents;
POST .../bulk-patch, .../rollout, .../pause. CLI
1claw platform fleet status|agents|patch|rollout|pause; SDK
client.platform.getFleet and friends; MCP platform_get_fleet,
platform_list_fleet_agents, platform_plan_fleet_rollout.
Bootstrapping now stamps the fleet and the template version on each agent, so
version_skew answers "how many are behind?" — and spec_hash distinguishes a
version bump that changed nothing from one that did.
Every route here does what it does a thousand times, and nobody reviews it per agent. That is the whole design:
- Guardrails and capability flags are not bulk-patchable. Raising a spend
limit across a fleet is not a deployment operation; it is a thousand separate
decisions that happen to share a form. Enabling
intents_api_enabledfor a cohort is the largest privilege change this API can express. Both stay per-agent. Readbulk_patchable_fieldsoff the fleet summary rather than hard-coding it. - A bad field refuses the whole patch, rather than applying the acceptable parts. A partially-applied bulk patch across a thousand agents is worse than a rejected one.
- Hand edits are skipped, not corrected. An agent changed outside fleet
control is left alone and the field is recorded on it — the standing answer
to "why is this agent behind?".
forceoverrides the skip but still cannot carry a guardrail. - A dry run claims no job, so it never blocks the real rollout behind the
one-rollout-per-template rule.
job_idisnulland the type says so. - MCP is read-only here.
platform_plan_fleet_rolloutalways dry-runs, and sets that itself rather than accepting it as an argument. Bulk-patch and pause are absent: a thousand agents changed from one call is a decision for a human at a terminal.
See Fleet management.
v0.59.18 (2026-09-06)
Four features shipped in this release. Peer memory is below; the other three were omitted from this entry when it was first written, which made them look unreleased to anyone reading the changelog rather than the API.
Learned auto-approval, shadow-first.
GET /v1/org/approval-learning/shadow-report reports which approval patterns
would be automated; POST /v1/org/approval-learning/{profile_id}/promote is
the only write, and it is human-only.
Every decision made through the approvals path has been observed since this shipped, so the shadow window is already accumulating — the report is a read over data that is being collected now, not something that starts when a UI appears. Promotion refuses entirely while the org is in shadow mode.
A promoted rule covers only what was actually approved: it is bounded by the amount band it was earned in, and a run of approvals for a familiar recipient never licenses a new destination. A profile promotes onto the agent whose approvals built it and no other. See Guardrail governance.
Policy presets. Four plain-language presets — read-only-assistant,
small-business-spender, inbox-agent, treasury-operator — that compile to
guardrail columns, access policies and approval rules.
GET /v1/policy-presets, POST /v1/agents/{id}/policy-preset/preview, and
POST /v1/agents/{id}/policy-preset.
Applying a preset that loosens a guardrail returns 202 or 403, never a silent 200: a preset builds the same request a person editing by hand would send and passes it to the same handler, so it is a friendlier interface to the approval flow rather than a way around it. Preview names every field that would widen. See Policy presets.
Trust signals on listed agents. GET /v1/agents/{id}/trust returns badges,
rating and review count for a public listing; POST /v1/agents/{id}/review and
/report are human-only, one per person per agent. The public view carries no
reviewer notes or report reasons — those are queue-internal, and publishing them
would publish accusations about an agent's owner.
See Trust signals.
Peer memory — a shared model of one person across the agents serving them, so each agent does not learn them independently.
POST /v1/peers, GET /v1/peers/{id}, /context, /events,
/predict-approval, /by-connection/{id}, and GET /v1/agents/{id}/peer-context.
SDK client.peers.*; MCP get_peer_context. Bootstrapping a platform
connection provisions its peer with that connection's agents as observers.
A peer is the most sensitive thing an agent can read about someone, and unlike a secret it is derived — nobody deliberately granted it. So:
- Access is by observer list and nothing else. Same organisation, same connection, broad scopes: none of it grants access. A peer with no observers is readable by no agent — if empty meant "everyone", forgetting to set observers would expose a behavioural profile silently and totally.
- Creating a peer is human-only. An agent that could do it could add itself.
- Prediction is not permission.
predict-approvalreturnslikelihood(an observation about a person) andsuggest_auto(a statement about youraction_approval_policy) as separate fields.suggest_autois true only where a rule you already wrote permits this exact case; a confident model never becomes new authority, and ablocked_reasonsays which of your rules prevented it.
Derivation is deliberately narrow: per fingerprint bucket rather than action type, so three approvals of $5 do not become a belief spanning $500; three observations minimum; a mixed history is not a tendency at all; and confidence is capped below certainty, because a 1.0 reads downstream as "no need to check".
Facts outlive their evidence without losing their basis. When events pass the 90-day retention window, each provenance entry becomes a tombstone keeping the kind of event and the decision but not the content — so "why does this system think that about me?" stays answerable. A human correction is never overwritten by re-derivation.
v0.59.17 (2026-09-06)
Declarative charts. One file provisions a whole swarm:
1claw diff -f chart.yaml # what would change
1claw apply -f chart.yaml
POST /v1/org/apply/diff and POST /v1/org/apply, plus per-user usage exports
from v0.59.15's Feature 7 work. Both endpoints are human-only — a chart
provisions agents, vaults and access policies, so an agent that could apply one
could grant itself access to a vault it cannot currently read.
The interesting half is what apply refuses to do:
- It never deletes. A resource removed from the chart is left alone; there
is no
--prune. An apply that silently deletes is an apply nobody runs twice. - It skips anything edited outside the chart, naming the fields that differ. Someone changed it by hand for a reason, and overwriting that because a file says otherwise is how a deployment tool destroys a fix at three in the morning.
- It refuses guardrails. Transaction limits, host allowlists and approval policies route through the guardrail approval flow; a reconciler writing them directly would be a way around it wearing a deployment tool's clothes.
- It does not skip your approval gates. Apply calls the same handlers the
API routes call, so an org requiring consensus for
vault.creategets an approval queued exactly as a dashboard click would. That resource reportsawaiting_approval; the rest of the chart still applies.
A refusal is never silence — silently ignoring a difference would mean the chart and reality disagree forever while every apply reports success.
Typos are errors. Unknown fields are rejected. A misspelled system_promt
that was quietly dropped would produce an apply reporting success while doing
nothing you asked for.
Names are the reconcile keys. Duplicates are an error rather than resolved by position, which would silently reassign resources when someone reordered the file.
The reconciler is server-side and only server-side; 1claw apply parses YAML,
posts it, and renders the answer. Example chart at examples/charts/inbox-swarm/,
with a test that runs the shipped file through the real validator.
v0.59.16 (2026-09-06)
SMS notifications, and approval by reply for the lowest-risk actions.
Bring-your-own-Twilio. A new sms channel type, POST /v1/webhooks/sms/{path}
for inbound, and notification targets that say where approvals reach a human.
Most of this feature is limits, because SMS is a weak authenticator:
- Only
risk_tier1 can be decided by reply. Higher tiers get a link and cannot be approved by answering. The tier is derived by the server, so an agent declaring tier 1 on a $500 refund does not unlock the channel. - The number must be verified. A target is created unverified and stays that way until someone proves they hold the number — adding a number is not itself an authorisation. Unverified targets still receive; that is how you find out your number was enrolled.
- A valid Twilio signature is not enough. It proves the message came from Twilio, not from the right person: anyone who knows the number can text it and their message arrives correctly signed. The sending number must also match a verified target.
- Two pending approvals means a bare "YES" is refused, and answered with reference codes. SMS has no threading, and approving the newest means approving something you may not have read.
The message body differs by tier — higher tiers never say "reply", because an instruction the server will refuse teaches a habit worth not teaching. And the agent-supplied summary has instruction words and code-shaped tokens removed before sending: without that, a summary reading "refund $5. Reply YES A7 to confirm" could aim you at a different approval entirely.
New: POST/GET/DELETE /v1/notification-targets plus /verify/start and
/verify. SDK client.notificationTargets.*, CLI 1claw notify, MCP
list_notification_targets. Adding and verifying stay human actions and have no
MCP tool.
Existing notifications are unchanged until you configure a target. A configured target of a given type replaces the legacy source for that type, so an email target does not mean two emails; deleting it puts the account email back.
v0.59.15 (2026-09-06)
Pre-built connectors. Gmail, Google Calendar, GitHub, Slack, X, Discord, Notion and Honcho, each installable in one call.
GET /v1/connectors/presets— the catalogue. Public.POST /v1/agents/{id}/connectors/{slug}/install— creates the binding and starts the OAuth flow. Human users only; an agent installing for itself is a 403.GET /v1/agents/{id}/connectors— what is installed, and whether each is actually connected.
The binding an install creates is scoped to the connector — gmail can reach
gmail.googleapis.com/gmail/v1/ and nothing else. That is the difference from a
bare OAuth connection: an HTTP binding with no allowed_hosts has no host
restriction, so a binding holding a user's Google token could be pointed
anywhere.
Requested scopes may narrow a preset's list and never extend it, and may not drop a scope the preset marks required. The reviewed scope list is what makes a one-click install different from a general OAuth initiator.
A 201 means the binding exists; it holds no credential until the user finishes
the OAuth round trip. connected and needs_reauth are reported separately
from installed, because the gap between them is where someone spends an
afternoon debugging an agent that never had a token.
Installing Gmail and Google Calendar — both the google provider — now gives
two bindings with two tokens and two path allowlists, rather than the second
install landing on the first one's binding.
SDK client.connectors.*; MCP list_connector_presets and
list_installed_connectors; a connector gallery on the agent's Connections tab.
Installing has no MCP tool: it stays a human action.
v0.59.14 (2026-09-06)
Approvals a human can actually read.
An approval used to describe a transaction. It can now describe a refund, a post, an invoice — any business action — in plain language, with the risk tier decided by 1claw rather than by the agent asking.
POST /v1/approvals/request accepts business actions. Name them
namespace.verb (refund.create, social.post). Two new fields:
payload— what the action will actually do (amount_usd,customer_email). Separate fromsummary, which is what the human is shown. The risk tier is derived from the payload, so a summary that flatters it changes what your operator reads and nothing about how strong the approval must be. The dashboard shows both.declared_risk_tier— advisory. 1claw derives its own floor and takes the higher of the two. You can ask for a stricter review, never a weaker one: an agent declaring tier 1 on a $500 refund gets tier 2, and the response returnsrisk_tier(enforced),declared_risk_tier(asked for) anddeclared_below_floor.risk_tierstill works as the old request-body name.
The response also returns human_summary — the line your operator receives on
SMS, push, or email, rendered from your agent's summary_template.
policy_change, card_order, agent_transaction, agent_execution and
agent_sign_intent return 403 when an agent requests them directly. These
are the approvals 1claw executes when a human approves — and the wording a
human reads has to come from the same place as the side effect that follows.
They are still raised for you automatically by the endpoints that need them.
If you were requesting policy_change to ask for wider access, use
access_request or policy_request instead. Our own documentation showed
policy_change in that example and has been corrected.
New: action_approval_policy on agents. Says which business actions need a
human and above what amount, and carries the summary_template used to render
the sentence:
{
"rules": [{
"action_type": "refund.create",
"mode": "approve",
"require_for_amount_above_usd": "50",
"summary_template": "Refund {{amount_usd}} to {{customer_email}}"
}]
}
Editing it counts as widening a guardrail — raising a threshold takes a human
out of the loop — so it routes through the same approval flow as loosening a
transaction limit. Malformed rules are rejected when you save them rather than
ignored when they are read: a threshold of "fifty" used to be a rule that
silently did nothing.
Consensus approvals keep their summary. POST /v1/pending-approvals and the
platform equivalent now store the summary you send, so the queue an approver
decides from shows it. It was previously included in the webhook and nowhere
else. Sending one is not yet required; submissions without one are accepted and
counted.
Fixed, in the packages
- CLI:
1claw approval listandapproval getthrewTypeError: tier.toLowerCase is not a functionon any real approval —risk_tierwas typed as a string and the API sends a number. The list now leads with the plain-language summary. - MCP:
get_approvalandlist_approvalsreadresource_type,resource_idandmetadata, which the API has never returned, so they showed the action and nothing about what it was for. They now read the real fields and show the summary, tier, and payload.request_approvalno longer tells agents to requestpolicy_change, or that the tier range is 1–5 when the column has always been 1–3. - OpenAPI: the request-side
risk_tierwas documented as 1–5 against a column that has always beenCHECK (risk_tier IN (1, 2, 3)).
v0.59.13 (2026-09-02)
Three endpoints were returning 500 on every call. They are fixed.
POST /v1/secrets/{id}/share— secret sharing failed for every caller. The query behind it named its columns by hand and did not gain two fields the row type had gained, so it failed against the database every time and surfaced as "An unexpected error occurred". If you have integration code that quietly skipped sharing, it will start working.DELETE /v1/org/sub-orgs/{id}— archiving a sub-organization had never once succeeded. Its first statement wrote a column that did not exist, so the transaction rolled back and nothing was archived.POST /v1/vaultsnow answers 409 for a duplicate name and 400 for an empty one or one over 255 characters. All three were 500s. Names are unique per organization, and the name is trimmed before it is stored — the trimmed value is what must be unique.
Browser bridge
POST /v1/agents/{id}/browser/fills requires form_path, field_names,
redirect_chain and current_generation. They were optional and filled in
server-side when absent, which turned three of the policy's own checks off: the
redirect chain was always empty so its check never ran, current_generation
defaulted to generation and was compared against itself, and form_path
defaulted to "", which matches no fingerprint pattern and denied every
binding that carried one.
A request missing any of them is now refused with a 400 naming the fields.
Send current_generation as the generation you observe now — sending the
same value as generation makes the staleness check compare a value to itself.
GET /v1/browser/devicesandDELETE /v1/browser/devices/{id}are documented. Revoked devices are listed rather than hidden, because "was this machine ever paired" is the question asked after a laptop goes missing.- Stock CDP clients connect. Puppeteer, Playwright, and the agent frameworks built on them can now attach to the bridge, open a page and navigate. Previously they were refused on the second method they sent.
- Commands are confined to a client's own targets, not only events: one agent cannot list, attach to, or drive another agent's page.
Runtimes
POST /v1/runtimes/{id}/chatanswers 503 when the runtime's last start failed under 120 seconds ago. Chat starts a stopped runtime, so a client that retries on failure turns each attempt into another deploy. Wait out the cooldown, or call the start endpoint to see the underlying error.
Packages — OpenAPI spec and SDK → 0.59.10. Purely additive: the two browser-device routes, the newly required fill fields, and the 409/503 responses above.
2026-08
v0.59.12 (2026-08-31)
Discoverability — two catalogues that were previously prose only
GET /v1/runtimes/templates— the provisionable runtime template catalogue, withchat_capableper entry. Public, no auth. This path previously collided with/v1/runtimes/{runtime_id}and answered400 UUID parsing failed.GET /v1/automations/step-types— the fullworkflow_specstep vocabulary (14 types), each markedagent_allowedandmoves_funds, plus step caps and the run timeout. Public, no auth.- Unrecognised automation step types are still skipped rather than fatal, but the run output now names the step and lists the known types instead of reporting a bare "unsupported step type".
Platform API
PATCH /v1/platform/apps/{id}acceptsredirect_urisfrom aplt_key. Previously no platform-key route could change them, so an app moving domains needed a human operator token.- A refused
PATCHnow names the offending fields rather than only restating which field is permitted, so a reconcile loop can retry without them.
v0.59.8 – v0.59.11 (2026-08-30 → 08-31)
The Vault mints and advertises https://api.1claw.co as its issuer. The
legacy issuer https://api.1claw.xyz is still accepted on validation —
tokens minted before the move stay valid until they expire — but is never
minted. If you pin an expected iss, accept both during the transition.
The OIDC discovery document previously advertised an authorization_endpoint
on the legacy apex, which now 301s; a redirect inside an authorization request
can drop state or code_challenge. It is now on https://1claw.co.
WebAuthn rp_id also moved to 1claw.co. Passkeys enrolled against the old
origin cannot be used on the new one; affected users are re-prompted to enrol.
- Billing — the dashboard metering exemption is now scoped to the three polled endpoints (
GET /v1/runtimes,/v1/runtimes/{id},/v1/automations) in addition to requiring a non-api_keycaller. Session-authenticatedGETs to other routes, including secret reads, are billable and count toward the monthly quota. - Email OTP — the per-address send budget is now scoped to
(address, sender). Previously anyone who knew an address could spend its budget and silently suppress the owner's sign-in code. - Automations — platform-created workflows are validated at create and re-validated at run.
- SMTP execution — a recipient value must be a single mailbox; commas, semicolons and whitespace are rejected, so a list cannot be smuggled past the per-execution recipient cap.
- Packages — OpenAPI spec, SDK, CLI, MCP → 0.59.8;
@1claw/wallet-react→ 0.5.2; Python SDK → 0.59.8. All client defaults moved toapi.1claw.co. docs.1claw.xyznow redirects (308) todocs.1claw.co.
v0.59.5 – v0.59.7 (2026-08-27 → 08-29)
- Content inspection —
POST /v1/shroud/inspect-contentREST parity, webhooks catalog. - Onboarding — golden-path provisioning, runtime log streams, runtime chat history.
- Midnight / NIGHT chain family support behind
ONECLAW_MIDNIGHT_ENABLED(Preprod only). - Auth — email-OTP sign-in promoted on the login page; passkey
rp_idrecorded per credential.
v0.59.4 (2026-08-27)
Platform connection expansion
GET /v1/platform/connections/{id}/portfolio(aliasGET .../balances) — unified balances for connection agents (?chains=,?include_tokens=).POST /v1/platform/connections/{id}/pending-approvals— create consensus/HITL pending approval for connection agent (202).- Connection automations —
GET/POST .../automations,POST .../automations/{aid}/runs/{rid}/cancel(plt_-scoped; not org/v1/automations). - Connection memory —
GET/PUT/DELETE .../memory/{namespace}/{key}(optional?agent_id=). POST /v1/shroud/inspect-content— REST parity with MCPinspect_content(fail-closed threat scan).- Docs sync — webhook events (
pending_approval.created,tx.awaiting_approval,sign.awaiting_approval,automation.run.failed), idempotency matrix,siwe_domain,provisioned_tier/platform_pays.
Packages
- OpenAPI spec, SDK, CLI, MCP, Python SDK → 0.59.4
v0.59.3 (2026-08-27)
Platform connection operations (Fathom parity)
GET /v1/platform/connections/{id}/signing-keys— list agent signing keys (public metadata: chain, address, public_key, curve). Optional?agent_id=. Use instead of org-scopedGET /v1/agents/{id}/signing-keyswith plt_ keys.GET .../signing-keys/{chain}— single-chain lookup with same metadata.PATCH /v1/platform/connections/{id}/agents/{agent_id}— enableintents_api_enabled,execution_intents_enabled, or updatesystem_prompton existing bootstrapped agents without re-bootstrap.- Docs: Platform API overview clarifies
wallet_address(SIWE staker identity) vs agent signing key address (signing-keysendpoints / bootstrapsummary.signing_keys). - Template aliases:
intents: true,intents: { enabled: true },intents_api_enabled: true(and execution equivalents) documented in overview.
Packages
- OpenAPI spec, SDK (
listConnectionSigningKeys,getConnectionSigningKey,patchConnectionAgent), CLI, MCP → 0.59.3 - Python SDK (
oneclaw) → 0.59.3
v0.59.2 (2026-08-27)
Onboarding golden path (MCP stdio)
GET /v1/org/onboarding/status— human-only progress: welcome bundle, agent, policy, sample secret, first read.POST /v1/onboarding/provision— idempotent welcome vault (default),examples/hello, MCP agent,**read/write policy, one-timeocv_key, andmcp_stdio_config(stdionpx @1claw/mcp).- Signup hooks — async welcome bundle after email verify, Google signup, social login, email OTP.
- Agent create —
skip_default_policyonPOST /v1/agents; default onboarding applied on human create and enrollment approve unless skipped. - Dashboard —
/onboarding/connectwizard, connect CTA on dashboard/sidebar/marketing; post-login redirect to connect flow. - CLI —
1claw setupcalls/v1/onboarding/provisioninstead of manual vault/policy steps. - MCP — vault auto-discovery prefers vault named
default;GET /.well-known/oauth-protected-resourceon httpStream (metadata). - Tests —
scripts/test-onboarding-prod.sh; wired intorun-production-tests.shand OpenAPI contract checks.
Packages
- OpenAPI spec, SDK (
client.org.getOnboardingStatus(),.provisionOnboarding()), CLI, MCP → 0.59.2 - MCP registry:
io.github.1clawAI/1claw-mcp@ 0.59.2
v0.59.0 (2026-08-27)
Fathom platform integration (migration 221)
agents.system_prompt— default chat system prompt on create/update and templateagents[].system_promptat bootstrap.- Connection chat —
POST /v1/platform/connections/{id}/agents/{aid}/chatacceptssystem,system_prompt, andmessages[]withrole: system; billing failures return 402 (not 500). - Connection passkey enroll —
POST .../passkeys/enroll/begin|completefor plt_-scoped WebAuthn registration of connected end-users. Withdrawn 2026-08-27 and now always 403. A passkey is exchangeable for a full, non-delegated user session through the public assert flow, so an app able to enrol one held a credential stronger than the delegation boundary it operates under. The user enrols in their own session instead. - Connection runtime GET —
GET /v1/platform/connections/{id}/runtimes/{runtimeId}(plt_ scoped; use instead ofGET /v1/runtimes/{id}). platform_paystier inheritance (migration 220) — Templateplanat bootstrap grants tier to end-user org;GET /v1/platform/connections/{id}returnsprovisioned_tier.- Bootstrap runtime fix —
provision_runtimeuses valid Cloud Run provider and respects tier limits. - OpenAPI —
GET /v1/platform/apps/{id}/usersresponse wraps{ users: [] }; passkey enroll schemas added.
Packages
- OpenAPI spec, SDK, CLI, MCP, Python SDK, Go SDK → 0.59.0
- New SDK/MCP/CLI methods:
getConnectionRuntime,connectionPasskeyEnrollBegin|Complete,system_prompttypes - MCP tools:
platform_get_connection_runtime,platform_connection_passkey_enroll_begin - Prod tests:
scripts/test-platform-expansion-prod.sh(passkey begin, runtime GET, system_prompt chat)
v0.58.2 (2026-08-26)
Platform connection control plane (runtime + chat)
- Bootstrap runtimes: Top-level
runtimes[], nestedagents[].runtime, andprovision_runtime: true(+runtime_preset/runtime_template) now create Cloud Runtimes during bootstrap. Connection detail includesruntime_idsandautomation_ids. GET /v1/platform/apps/{id}/templates/{tid}— plt_ or user JWT; inspect template spec after bootstrap.POST /v1/platform/connections/{id}/runtimes— create runtime in end-user org (fixes plt_ →POST /v1/runtimes404).POST /v1/platform/connections/{id}/agents/{aid}/chat— connection-scoped agent chat (fixes plt_ →POST /v1/agents/{id}/chat403).- Spend-policy PUT replace — second write no longer 500 (unique per-user app policy).
- Connection-scoped control: pending-approval get/decide, mobile approval decide, signing-key deactivate (v0.58.0 continued).
Tests: scripts/test-platform-expansion-prod.sh covers template GET, spend-policy replace, control-plane routes, bootstrap provision_runtime, connection runtime create, connection chat.
v0.58.1 (2026-08-25)
Agent-created automations (chat/runtime)
POST /v1/agents/{agent_id}/automations— agent-token only. Simple manual/webhook workflows with guardrailed steps (log,notify,memory_get,memory_put,wait; max 10 steps, 25 per agent). Optionalauto_triggerfor manual runs. Humans remain onPOST /v1/automations(agents get 403).created_by_typeon automations (human|agent, migration 218). Dashboard shows an Agent-created badge.- Runtime tools:
create_automation,create_test_automation, agent-access tools (request_access,request_approval,request_binding,request_signing_key,request_guardrail_change),forget, capabilities prompt injection across Hermes/OpenClaw/OpenClaude/OpenCode templates. - Vault:
request_timeoutmiddleware, runtime chat cold-start improvements.
Packages
- OpenAPI spec, SDK (
agents.createAutomation()), MCP (create_agent_automation), Python SDK (agents.create_automation()), Go SDK (Agents.CreateAutomation()), CLI (1claw agent automation create) → 0.58.1 - MCP registry:
io.github.1clawAI/1claw-mcp@ 0.58.0 (tool shipped in prior release) - Prod tests:
scripts/test-automations-prod.sh§24 (agent-scoped create + human-route 403)
v0.58.0 (2026-08-24)
Platform API control plane (Fathom bundled release)
- SIWE recovery ids: Accept EIP-191 signatures with recovery byte 27 or 28 (MetaMask/viem) in addition to 0/1.
- App-scoped reads (
plt_):GET /v1/platform/connections/{id}/approvals,.../approvals/{approval_id},.../pending-approvals(includespayload_hash),.../spend-policy. - Spend policy:
GET /v1/platform/apps/{id}/spend-policies/{policy_id};PUT .../connections/{id}/spend-policysupports optionalIdempotency-Key(24h body-hash replay). - App lifecycle:
PATCHslug changes → 400;DELETEsoft-deactivates and returns{ id, slug, deleted_at };GETinactive app → 404; slugs unique per org (migration 216). - Ownership transfer:
POST /v1/platform/apps/{id}/transfer-ownershipwith step-up auth.
Packages
- Vault API 0.58.0 (migrations 216–217)
- OpenAPI spec, SDK, CLI, MCP, Python SDK, Go SDK → 0.58.0 with Platform control-plane parity
- MCP registry:
io.github.1clawAI/1claw-mcp@ 0.58.0 - New MCP tools:
platform_list_connection_approvals,platform_get_connection_approval,platform_list_connection_pending_approvals,platform_get_connection_spend_policy,platform_get_spend_policy,platform_transfer_ownership,platform_delete_app - Prod tests extended:
scripts/test-platform-api.sh,scripts/test-platform-expansion-prod.sh
v0.57.0 (2026-08-24)
Platform API expansion (migration 215)
- SIWE wallet provisioning:
POST /v1/platform/siwe/challenge+ upsert withsubject_token_type: urn:1claw:params:oauth:token-type:siwe,siwe_message,siwe_signature. Atomic DB nonces;siwe_domainon platform apps. - Parameterized bootstrap:
parameterson bootstrap requests;POST .../templates/{id}/previewfor dry-run; params-aware bootstrap idempotency viaIdempotency-Key+ body hash. - Connection polling:
GET /v1/platform/connections/{id}returns claim status,entitlement_status,wallet_address, resource IDs. - Per-connection usage:
GET .../connections/{id}/usage— monthlyinference_spent_usd. - On-chain entitlements: Template
entitlements[];GET/POST .../entitlements+ refresh; background monitor; webhooksplatform.entitlement.granted/revoked. - Inference budgets: Spend policy fields (
inference_allowance_usd,max_request_cost_usd, etc.); JWTinference_budgetclaim; Shroud per-request cap;GET /v1/treasury/wallets/inference-budget. - Claim expiry webhook: Background worker fires
platform.claim.expiredwhen 10-min claim tokens lapse unclaimed.
Packages
- Vault API, OpenAPI spec, SDK, CLI, MCP bumped to 0.57.0
- Python SDK tag 0.57.0 (CI publish)
- MCP registry:
io.github.1clawAI/1claw-mcp@ 0.57.0 - New prod tests:
scripts/test-platform-expansion-prod.sh
v0.56.3 (2026-08-24)
Cumulative gas budget & outbound idempotency
gas_daily_budget_native: Per-chain guardrail field inper_chain_guardrails— UTC-day cumulative EVM gas (sum ofgas_limit × max_fee) enforced alongside per-txmax_fee_per_gas_gwei/max_gas_limit. Tracked inagent_gas_ledger(migration 213).inject_idempotency_key: Binding guardrail — whentrue, Vault injects a deterministicIdempotency-Keyon outbound HTTP/GraphQL execute requests (SHA-256 hex of binding id, HTTP method, path, and JSON body). Wired indomain/execution/http.rsandgraphql.rs.- Expo push on approvals: When
ONECLAW_EXPO_ACCESS_TOKENis set, pending approval/HITL events send best-effort Expo push notifications to registered mobile device tokens (domain/push_notify.rs, wired fromapproval_notify.rs). - Passkey for login 2FA (migration 214): Per-user
require_passkey_for_mfaviaGET/PATCH /v1/auth/settings. When enabled, password/social/email-OTP login returnsmfa_method: "passkey"and completes viaPOST /v1/auth/mfa/passkey/begin+.../completeinstead of TOTP. Disabling requires step-up (X-Auth-Confirm, purposesecurity.mfa_passkey.disable). Dashboard toggle on Settings → Security MFA card.
Packages
- Vault API, OpenAPI spec, SDK bumped to 0.56.3
v0.56.2 (2026-08-24)
Guardrail widening approvals & treasury HFA passkey parity
- Guardrail widening queue: Binding and agent guardrail edits that widen access now require
policy_changeapproval with step-up re-auth (X-Auth-Confirm). PATCH handlers return 202 withpending_approval_iduntil approved. - Treasury HFA passkey parity: Swap operations support passkey tx-assert digests (
treasury_swap_digest); send/swap/export honor Human Factor Auth with passkey-only flows in dashboard and@1claw/wallet-react. - HFA audit events:
human_factor_auth.satisfied/human_factor_auth.deniedemitted on treasury wallet operations.
Phase 5 Safe foundation (counterfactual)
- Agent accounts API:
GET/POST /v1/agents/{id}/accounts,POST .../accounts/migrate,POST .../accounts/{chain}/deprecate-eoa— counterfactual Safe provisioning, EOA→Safe migration wizard, execTransaction signing path. - Module registry:
GET /v1/safe/module-registry/{chain}— pinned Safe v1.4.1 + Zodiac module addresses per chain. - Org allowance sync:
POST /v1/org/safe/sync-allowances— compiles allowance targets from agent guardrails; returns drift report (onchain_sync: counterfactual). - Guard.sol: Foundry scaffold with tests; on-chain deploy/cosign/passkey/timelock/4337 stubs return 501 pending external audit.
- Dashboard: Safe migration wizard at
/agents/[agentId]/migrate-safe.
Tests & tooling
- HFA unit tests (
human_factor_auth.rs); guardrail shadow/revisions/replay checks inscripts/test-guardrails-prod.sh. - CLI:
1claw agent accounts list|migrate|deprecate-eoa,1claw safe module-registry|sync-allowances. - Prod smoke:
scripts/test-safe-prod.sh.
Packages
- Vault API, OpenAPI spec, SDK bumped to 0.56.2
- MCP:
list_agent_accounts,migrate_agent_to_safe,deprecate_agent_eoa,get_safe_module_registry,sync_org_safe_allowances
v0.56.0 (2026-08-24)
Guardrail governance, HFA, Safe foundation (Phases 3–6)
- Convention 6 shadow/enforce on execution guardrails —
enforcement: "log"|"enforce"on bindings and agents; auditguardrail_shadow.would_deny. - Address screening — per-agent
address_screening_policy(mode: off | deny | approve); env deny listONECLAW_SCREENING_DENY_LIST. - Solana simulate_first on non-EVM submit/sign when configured.
- Governance APIs:
GET /v1/org/guardrail-shadow-report,GET /v1/org/guardrail-revisions,POST /v1/agents/{id}/guardrails/replay. - Guardrail revisions recorded on agent/binding guardrail PATCH.
- Org unfreeze T3 step-up; webhook
org.unfrozen. - Execution honeytoken on vault-ref credential loads.
- Shroud tx escalation —
POST /v1/admin/shroud/tx-escalations; Shroud heuristics escalate to HITL. - HFA on treasury send/swap/export; Safe stubs — agent accounts + module registry.
Packages
- Vault API, OpenAPI spec, SDK, CLI, MCP bumped to 0.56.0
- CLI:
1claw guardrails shadow-report|revisions|replay - Dashboard: Settings → Security → Guardrails tab
v0.55.0 (2026-08-24)
Guardrail phases 1.3–2.7 (extended HITL & enforcement)
- Sign HITL: EIP-712 typed data and raw digest signing can route to 202
awaiting_approvalwhentyped_data_policyorraw_signing_policyisapprove. Webhook:sign.awaiting_approval. Approve via/v1/approvals/{id}/decideauto-executes stored sign intent. - Simulation HITL: Tenderly revert can route to tx HITL when
simulation_failure_policyisapprove(instead of 422). - Extended tx guardrails:
tx_block_unlimited_approvals, per-recipient daily limits, new-recipient caps, USD caps (tx_max_value_usd,tx_daily_limit_usd), gas budget checks, in-flight daily budget reservations (tx_budget_reservations). - Signing policies:
raw_signing_policy(allow/deny/approve),personal_sign_policyJSON,allow_erc4337,allow_eip7702. - Execution guardrails (2.4–2.7): binding time windows + source IP (
execution_conditions), outbound secret pattern scan, per-binding concurrency cap. - Org freeze:
POST /v1/org/freezeandPOST /v1/org/unfreeze(owner/admin emergency stop).
Packages
- Vault API, OpenAPI spec, SDK, CLI, MCP bumped to 0.55.0
v0.54.0 (2026-08-24)
Graduated guardrails & HITL (Phase 1–2)
- Transaction HITL:
agents.tx_approval_policyJSON — graduated thresholds (require_above_native,require_for_chains,require_for_new_recipients, unlimited ERC-20 approve detection). Matching txs return 202awaiting_approvalwithapproval_id; humans approve via/v1/approvals/{id}/decideto resume signing. - Execution HITL: Binding
guardrails.approval_policy(mode:off|always|conditional) andallowed_methods. Execute returns 202approval_requiredwhen policy matches; approve auto-runs the intent. dry_runon execute: Validates guardrails and approval policy without side effects (status: dry_run).- Circuit breaker: Repeated guardrail denials can auto-suspend agents (
auto_suspended); org-levelfrozen_at. Webhooks:tx.awaiting_approval,execution.pending,agent.suspended,org.frozen. - Agent API:
tx_approval_policy,typed_data_policy,simulation_failure_policy,auto_suspendedon GET; PATCH supportsclear_auto_suspended(owner/admin). - Production scripts:
scripts/test-guardrail-hitl-prod.sh; extendedscripts/test-execution-guardrails-prod.sh(allowed_methods,dry_run).
Packages
- Vault API, OpenAPI spec, SDK, CLI, MCP bumped to 0.54.0
- MCP:
execute_intentacceptsdry_run; CLI:1claw approval status <id>
v0.53.4 (2026-08-23)
Execution guardrails (Phase 0)
- Machine-readable
guardrail_violationJSON on execute denials (reason_code, optionallimit/current/attempted) - Per-binding guardrails:
max_request_bytes,max_response_bytes,allowed_request_headers, GraphQL depth/mutation/introspection limits, DNS-pinned HTTP/GraphQL clients - Per-binding and per-agent
max_requests_per_minute— denied executions do not count toward RPM GET /v1/approvals/{approval_id}/status— agent-only lightweight approval poll- Production script:
scripts/test-execution-guardrails-prod.sh
Packages
- Vault API, OpenAPI spec, SDK, CLI, MCP (
io.github.1clawAI/1claw-mcp/@1claw/mcp) bumped to 0.53.4 - MCP tool:
get_approval_status - SDK:
client.approvals.getStatus()
v0.53.3 (2026-08-20)
Execution Intents parity
- All ten binding type executors are live on Pro+ (HTTP, GraphQL, Postgres, MySQL, Redis, gRPC, SMTP, Cloud SDK, S3, Custom)
- Production regression script section 30 supports optional
EXEC_*real-service smoke tests - Dashboard Security settings: env policy, credential recovery, and Shamir KEK endpoints wired correctly
1claw.co domain parity
api.1claw.co,mcp.1claw.co,shroud.1claw.co,intents.1claw.co, andrun.1claw.comirror.xyzrouting- Smoke and Shroud prod scripts validate
.cohealth endpoints
Docs & packages
- SDK, CLI, MCP (
io.github.1clawAI/1claw-mcp/@1claw/mcp), OpenAPI spec, Python SDK bumped to 0.53.3 - Marketing copy and agent skills updated for Pro+ binding tier gating
v0.53.2 (2026-08-19)
Release engineering & OpenAPI sync
- OpenAPI
@1claw/openapi-spec0.53.2:ShroudAttestationResponseaddsattestation_level(none|identity|confidential|sev_snp) andconfidential_claims(SEV-SNP tier metadata) - SDK, CLI, MCP, Python SDK, Go SDK, and OpenClaw plugin bumped to 0.53.2
- Production test scripts validate
attestation_levelonGET /v1/shroud/attestation @1claw/wallet-reactv0.5.0 — audit-driven auth/session fixes; parent submodule pointer updated
Shroud & execution
- SEV-SNP attestation verification with measurement match against published image digest
- TEE execution forwarding: Vault
POST /v1/agents/{id}/executewithexecution_mode: "tee"dispatches to Shroud whenONECLAW_SHROUD_EXECUTION_URLis configured - Shroud secrets manifest refresh notifications for faster redaction automata updates
Dashboard & policy UI
- Policy Engine v2 dashboard parity: tx conditions editor, consensus
skip_when/require_when, expression engine fields - Embedded wallet UX improvements and blog post on competitive positioning
Security (2026-08-19 audit)
- HIGH/MEDIUM findings from security audit remediated in vault and dashboard
v0.53.1 (2026-08-19)
Raw Transaction Deep Decode
- Added
raw_transaction(base64) andtron_transaction(JSON) fields to sign and submit endpoints - Pre-built Solana, Bitcoin, and Tron transactions are now deep-decoded for policy enforcement
- Base64 validation and 64KB size cap enforced server-side
Credential Recovery Hardening
- Split approve/execute into two steps with configurable delay window (default 72 hours)
- Added
POST /v1/auth/credential-recovery/requests/{id}/executeendpoint - Admin/owner role verification required for approve and execute actions
- Org-configurable
credential_recovery_delay_hourssetting
Shamir KEK TEE Forwarding
- Reconstruct endpoint now forwards to Shroud TEE for secure key reconstruction
- Returns 501 when Shroud is not configured (deployment without TEE)
- Shroud stub handler at
POST /v1/admin/shamir/reconstruct
Wallet Access Policies
- New CRUD endpoints:
POST/GET/DELETE /v1/treasury/wallets/access-policies - Per-chain, per-agent/user permission policies with conditions (value caps, token allowlists)
OpenAPI Specification
- 15 new endpoint definitions (wallet access, credential recovery, Shamir KEK, execute)
- Full request/response schemas with component definitions
Expression Engine & Chain Decoders
- Expression engine now evaluated in signing path for schema v2 policies
- Solana, Bitcoin, and Tron transaction decoders integrated into policy context builder
- Fail-open fallback when decode fails (graceful degradation)
v0.53.0 — Embedded Wallet Competitive Parity (2026-08-19)
Whole-agent governance hardening for embedded wallet competitive parity with Turnkey-style signing infrastructure.
New features
- Expression engine — Mini DSL in
tx_conditions.expressionfor signing-time policy evaluation (schema version 2). Fail-closed with step budget and length limits. - Policy schema versioning —
policy_schema_versionon access policies (migration 202). Version 1 = legacy field-matching; version 2 = expression engine support. - TEE attestation endpoint — Public
GET /v1/shroud/attestationon Shroud returns GCE identity token + image hash with verification steps. - Audit chain verification —
GET /v1/audit/verifyreturns org-scoped hash chain integrity result with HMAC-SHA256 scheme metadata. - Multi-chain deep decode — Full Solana, Bitcoin, and Tron transaction parsers feed
TransactionContextfor policy engine evaluation. - Control-plane action kinds —
action_kind_inon consensus triggers for version-agnostic grouping (e.g.signing_key.*,policy.*). - Approval bypass —
approval_idon consensus-gated requests (policy create, agent create, signing key export, treasury send). - Shamir org KEK — Infrastructure for 2-of-3 Shamir KEK custody across HSM providers (migration 203).
- Credential recovery escape hatch — Time-delayed recovery for MFA/passkey consensus gating in solo/small orgs (migration 204).
- Wallet access policies — Role-based wallet permissions schema (migration 205).
allowed_tokensenforcement — Spend policies now enforceallowed_tokensat signing time.
Security docs
- Security overview, trust model comparison, Turnkey migration guide, security whitepaper.
- Policy versioning guide, external security review scope runbook.
Migrations
- 202:
access_policies.policy_schema_version - 203:
organizations.kek_custody,org_kek_shares,org_kek_recovery_codes - 204:
credential_recovery_requests - 205:
wallet_access_policies,users.wallet_roles,agents.wallet_roles
Clients
@1claw/sdk@0.53.0,@1claw/cli@0.53.0,@1claw/mcp@0.53.0,@1claw/openapi-spec@0.53.0- Python SDK
oneclaw@0.53.0, Go SDKv0.53.0 - Vault
0.53.0, Shroud0.8.0
v0.52.0 — Agent Environment Tagging (2026-08-18)
Tag agents with a named environment for policy scoping and automatic env var resolution.
New features
- Agent environment tag —
environment,environment_locked,env_auto_resolve, andper_environment_guardrailson agents. - JWT claim — Agent tokens include
environmentwhen the agent is tagged. - Policy scoping — Access policy
conditions.environment_inrestricts policies to specific environments. - Auto-resolve — When
env_auto_resolveis true,GET /v1/vaults/{id}/env-vars/resolveuses the agent's tag whenenvironmentis omitted. - CLI flags —
--environment,--environment-locked,--env-auto-resolveon create; update supports--per-environment-guardrails. - Dashboard — Environment tag UI on agent create and detail pages.
Bug fixes
consensus_policyunit tests updated forrequire_credential_typesfield.
Migrations
- 201:
agents.environment,environment_locked,env_auto_resolve,per_environment_guardrails
Clients
@1claw/sdk@0.52.0,@1claw/cli@0.52.0,@1claw/mcp@0.52.0,@1claw/openapi-spec@0.52.0- Python SDK
oneclaw@0.52.0, Go SDKv0.52.0
v0.51.0 — Environment Variables (2026-08-18)
First-class per-key environment variables on vaults, bringing Vercel-style env management to 1Claw.
New features
- Per-key env vars — Store
DATABASE_URL,STRIPE_KEY, etc. as individual encrypted entries targeting specific environments (production, preview, development, custom). Replaces theconfig/prod/*path hack. - Named environments — Built-in production/preview/development plus tier-gated custom environments with copy-from support.
- Org shared vars — Organization-level env vars linked to multiple vaults. Vault-level vars with same key+environment always win.
- Resolution endpoint —
GET /v1/vaults/{id}/env-vars/resolvereturns the final KEY=VALUE set with three-tier precedence (shared < vault < branch override). - Sensitive write-only vars — Values non-readable after creation for human callers. Disallowed on Development-only. Org enforcement policy available.
- Cloud Runtime injection — Resolved env vars merged into container environment at start/rebuild. 64KB combined limit. Restart required for changes.
- CLI commands —
env ls,env add,env rm,env environments ls|add|rm,-eflag onpull/push/run. - SDK —
client.envVars.list(),.create(),.get(),.update(),.delete(),.resolve(). - MCP —
resolve_envtool. - Dashboard — Env Variables tab on vault detail, Shared Env Vars settings page, environment management.
Bug fixes
- CLI
env pullnow correctly unwraps the{ secrets: [...] }response wrapper. - CLI
env pushnow sendstypeinstead ofsecret_type(matching the API's serde rename).
Migrations
- 197:
env_varstable - 198:
vault_environmentstable (built-in + custom) - 199:
org_env_varsandorg_env_var_linkstables - 200:
runtimes.environmentcolumn
Clients
@1claw/sdk@0.51.0,@1claw/cli@0.51.0,@1claw/mcp@0.51.0,@1claw/openapi-spec@0.51.0
Auth & dashboard security (2026-08-17)
Human authentication
- Changed: TOTP MFA is available on all tiers (including Free); the Pro+ gate was removed.
- New: Per-user setting
require_passkey_for_vaults(migration 193) — when enabled,GETsecret reads requireX-Passkey-Tokenfrom a user-verified WebAuthn assertion. - New:
GET/PATCH /v1/auth/settings— read/updaterequire_passkey_for_vaults(user-only; enabling requires at least one registered passkey). - New:
POST /v1/auth/passkeys/vault-assert/begin+.../complete— issue a reusable 5-minute vault unlock token after passkey verification. - New: Dashboard passkey suggestion prompt after login for users without a passkey (dismissible, 7-day snooze). Toggle in Settings → Security ("Vault unlock" card).
v0.50.0 — Policy Parity Sprint (2026-08-18)
Consensus precision & approver identity
- New:
threshold_weionConsensusCondition::value_above— arbitrary-precision wei thresholds (preferred over deprecatedthreshold_gwei). - New:
required_roles,per_role_minimums, andrequire_credential_typeson consensusapprovalrequirements — enforce role-based and credential-gated approvals (e.g. require passkey-verified approver). - New:
credential_typeonapproval_signatures(migration 195) — records auth method used at vote time (password,passkey,totp,biometric,api_key).
EIP-712 & EIP-7702 policy conditions
- New:
tx_conditionsfields:eip712_primary_type_in,eip712_verifying_contract_in,eip712_domain_name_in,eip712_domain_chain_id_in— fine-grained typed data signing policies. - New:
eip7702_authorized_addresses_in— restrict EIP-7702 delegate contracts viaauthorization_listin TransactionContext.
Control-plane governance
- New: Org setting
control_plane_consensus_policy_id— gates policy CRUD, signing key export, and member mutations behind consensus (returns 202). - New:
ConsensusCondition::action_in— match control-plane actions (policy.create,policy.update,policy.delete,signing_key.export,member.role_change,member.remove).
Clients
@1claw/sdk@0.50.0,@1claw/cli@0.50.0,@1claw/mcp@0.50.0,@1claw/openapi-spec@0.50.0- Python SDK
oneclaw@0.50.0, Go SDKv0.50.0
v0.49.0 — Policy engine composability & deep inspection (2026-08-17)
Built-in transaction policies
- New:
tx_conditions.match_mode—"all"(default, AND) or"any"(OR) for combining individual condition fields at signing time. - New:
tx_conditions.deep_inspect— when true, conditions are also evaluated against inner calls extracted from wrapper transactions (multicall, SafeexecTransaction, ERC-4337handleOps).
Policy time windows
- New: IANA
timezoneandcron_expron policyconditions.time_window— schedule-aware access control with timezone-aware hour/day checks and cron matching.
Consensus composability
- New:
consensus_trigger.skip_when— array of flat condition sets; when ALL fields in ANY entry match, consensus is bypassed. - New:
consensus_trigger.require_when— consensus is only required when at least one entry matches; if set and none match, consensus is skipped. - New:
consensus_trigger.deep_inspect— evaluate consensus conditions against inner wrapper calls, not just the outer transaction.
Deep decode
- New:
crypto/deep_decode.rs— unwraps multicall, Safe, and ERC-4337 batch transactions to populateinner_callsonTransactionContextfor policy evaluation.
Fixed
- Fixed:
POST /v1/pending-approvals/{id}/executeno longer returns 500 when JSONB key reordering causedpayload_hashmismatch — canonical alphabetical key sorting inpre_sign.rs.
Clients
@1claw/sdk@0.49.0,@1claw/cli@0.49.0,@1claw/mcp@0.49.0,@1claw/openapi-spec@0.49.0- Python SDK
oneclaw@0.49.0, Go SDKv0.49.0 - Integration packages
@1claw/agentkit,@1claw/openclaw-plugin,@workspace/1claw-hermes,1claw-mobileat 0.49.0
v0.48.2 — tx_conditions, consensus tokens & security hardening (2026-08-17)
Built-in transaction policies
- New:
tx_conditionsJSONB onaccess_policies(migration 189) — AND of present fields evaluated at signing time:function_name_in,function_selector_in,erc20_amount_above,value_above(gwei),to_address_in,chain_in,intent_type_in,decode_failed,program_id_in. All tiers. Dashboard:TxConditionsEditoron policy create/edit.
Contract ABI registry
- New:
interface_kindon contract ABIs (migration 190) —evm_abi(default) orsolana_idlfor Anchor IDL decoding. Solana program instructions populatefunction_name,program_id_in, and related TransactionContext fields.
Consensus / pending approvals
- New: Single-use
approval_idbypass token (migration 191) — consumed atomically on execute, submitter-bound (only the original submitter can execute). Works on the EVM submit path after human approval.
Treasury delegation
- Fixed: Per-delegation guardrails (
to_allowlist,allowed_chains,max_value_eth) are now enforced at signing time during treasury-mode Intents API requests — strictest of agent + delegation limits wins.
Security & reliability
- Changed:
ip_filtermiddleware fail-closed on DB errors (500 instead of silent allow). Production requiresONECLAW_PROXY_SECRETfor trusted proxy header validation. - New: Runtime JWT
runtime_idclaim; auth middleware validatesX-1Claw-Runtime-Idmatches the token (prevents cross-runtime replay). - Fixed: OPA WASM evaluation uses wasmtime epoch interruption for reliable timeout enforcement.
- Fixed: Treasury wallet send double-conversion of
value_wei. - Fixed: Agent enrollment anti-spam — bounded cooldown map, sensitive target threshold.
Docs
Clients
@1claw/sdk@0.48.2,@1claw/cli@0.48.2,@1claw/mcp@0.48.2,@1claw/openapi-spec@0.48.2- Python SDK
oneclaw@0.48.2, Go SDKv0.48.2
v0.48.1 — Client package alignment (2026-08-14)
Clients
- Changed: Submodule pointers aligned for npm/PyPI publish — SDK, CLI, MCP, OpenAPI spec, Python SDK (
__version__fix), Go SDK at 0.48.1. - Changed:
@1claw/wallet-react@0.4.2— passkey tx digest binding for treasury send/swap.
v0.48.0 — Cedar/OPA Enforcement v2 (2026-08-14)
Policy backend
- New:
GET/PATCH /v1/org/settings/policy-backend— configure Cedar/OPA backend (builtin,cedar,opa,builtin+cedar,builtin+opa), mode (shadowdefault orenforce), scope actions, and circuit breaker (fail_closeddefault). - New:
GET /v1/org/policy-shadow-report— divergence report when running advanced backends in shadow mode.
Contract ABIs
- New:
POST/GET/DELETE /v1/org/contract-abis,GET /v1/org/contract-abis/{id}— org-scoped ABI registry for transaction decoding in policy evaluation.
Consensus / pending approvals
- New:
consensus_triggeron access policies — structured conditions (value, chain, address, function selector, ERC-20 amount, intent type, always). - New:
POST/GET /v1/pending-approvals, approve/execute/cancel endpoints — multi-party approval workflow; sign/transactions return 202 when consensus matches. - New webhook events:
pending_approval.*,policy_backend.circuit_breaker_*.
Cedar/OPA
- Changed: Cedar and OPA policy responses include dynamic
enforcement_status(shadow,enforce,inactive) from org backend config.
Clients
@1claw/sdk@0.48.0,@1claw/cli@0.48.0,@1claw/mcp@0.48.0,@1claw/openapi-spec@0.48.0- Python SDK
oneclaw@0.48.0, Go SDKv0.48.0
v0.47.3 — Billing quotas: wallets, signatures, Free treasury (2026-08-13)
Quotas
- Changed: Dropped the 0.25% of transaction-value Intents fee. Signature overage is a flat per-signature charge (
proxy_transaction_submitrates: Free $0.225, Pro $0.15, Team $0.075, Business $0.04) via prepaid credits or x402. Included signatures remain free up to the monthly quota. - Changed: Business API calls/month raised to 1,000,000 (was 500,000).
- New: Unified wallet quota covering active treasury wallets, agent signing keys, smart accounts, and agents with an EOA. Free 10, Pro 10,000, Team 250,000, Business 1,000,000, Enterprise unlimited.
- New: Monthly signature quota (Free 100, Pro 20,000, Team 200,000, Business 1,000,000). Over quota is billed, not hard-blocked.
- Changed: Signing POSTs (
POST /v1/agents/{id}/sign,/transactions,/transactions/sign) no longer consume the API Calls meter.
Treasury wallets
- Changed: Treasury wallet generate/import/rotate/send/swap are available on all tiers (no Pro+ gate). Counted against the wallet quota. Dashboard
/treasuryis no longer Pro-walled.
API
- Changed:
GET /v1/billing/subscriptionusagenow includeswallets({ used, limit }) alongsiderequestsandintent_transactions.
Quotas (runtime hours)
- Fixed: Runtime hour caps now match the pricing page: Pro 100h/mo (was 720h), Team 500h/mo (was 7,200h), Business 2,000h/mo (was 18,000h). Enforcement in
tier_limits()was out of sync with customer-facing limits.
Pricing clarity
- Changed: Restored Pro wallet quota to 10,000 and signature quota to 20,000 (reverts interim 100/1,000 limits).
- Changed: Pricing page and docs now distinguish Execution Intents (Pro+, HTTP/GraphQL binding calls, hard monthly execution cap) from Intents API (Business+, on-chain signing, Signatures/mo meter).
Clients
@1claw/sdk@0.47.3,@1claw/cli@0.47.2,@1claw/openapi-spec@0.47.3- Python SDK
oneclaw@0.47.3, Go SDKv0.47.3
v0.47.0 — Key Import, Policy Engine v2, Sub-Orgs & Portfolio (2026-08-13)
Key Import (BYOK)
- New:
POST /v1/agents/{id}/signing-keys/{chain}/import— Import an existing private key as a signing key. Human-only, requiresX-Auth-Confirmpassword re-authentication. Supports hex, base64, and WIF formats. - New:
POST /v1/treasury/wallets/{chain}/import— Import an existing private key as a treasury wallet. Human-only, requiresX-Auth-Confirm.
Policy Engine v2 + Cedar + OPA
- New: Existing access policies now support
effect("allow" or "deny"),priority(higher wins), andattribute_conditionsfields for fine-grained policy evaluation. - New: Cedar policy engine (Team+ tier):
POST/GET /v1/org/cedar-policies(CRUD),POST /v1/org/cedar-policies/test(dry-run evaluation). Declarative authorization via Cedar policy language. - New: OPA policy engine (Business+ tier):
POST/GET /v1/org/opa-policies(CRUD),POST /v1/org/opa-policies/test(dry-run evaluation). Rego-based policy evaluation with custom data documents. - DB: Migration 179 (policy v2 columns: effect, priority, attribute_conditions + secret tags), migration 180 (cedar_policies and opa_policies tables).
Non-EVM Treasury Send
- Updated:
POST /v1/treasury/wallets/{chain}/sendnow supports Bitcoin, Solana, XRP, Cardano, and Tron sends alongside EVM chains. - Updated: Request body extended with
token_mint,memo,destination_tag,fee_rate_sat_per_vbyte,xrpl_tx_json,fee_limit_sun,token_decimals,ttlfor non-EVM chain-specific parameters. - Note:
POST /v1/treasury/wallets/{chain}/swapreturns 400 for non-EVM chains (DEX aggregator is EVM-only).
Sub-Organizations
- New: Hierarchical organization management. Sub-orgs inherit or independently manage billing.
- New endpoints:
POST/GET /v1/org/sub-orgs(create, list),GET/DELETE /v1/org/sub-orgs/{id}(get, archive),POST/DELETE /v1/org/sub-orgs/{id}/permissions(grant, revoke),POST /v1/org/sub-orgs/{id}/users(add user),POST /v1/org/sub-orgs/{id}/wallets/generate(generate wallets). - Platform API:
create_sub_org: boolonupsert_userenables platform apps to create sub-orgs for connected users. - DB: Migration 181.
Portfolio
- New:
GET /v1/portfolio— Unified balance aggregator across all wallet types (treasury wallets, signing keys, smart accounts). Query params:?chains=ethereum,solana,?include_tokens=true. Returns per-wallet balances with USD estimates.
Smart Account Import
- New:
POST /v1/agents/{id}/smart-accounts/import— Import an existing Safe smart account. Accepts{ chain, chain_id, safe_address, verify? }. Optionally verifies on-chain Safe ownership before import.
SDK / CLI / MCP
- SDK:
client.signingKeys.importKey(),client.treasuryWallets.importWallet(),client.cedarPolicies.*(CRUD + test),client.opaPolicies.*(CRUD + test),client.subOrgs.*(full CRUD),client.portfolio.get(),client.agents.importSmartAccount(). Policy types updated witheffect,priority,attribute_conditions. - CLI:
1claw cedar-policy create|list|get|delete|test,1claw opa-policy create|list|get|delete|test,1claw sub-org create|list|get|archive|grant|revoke|add-user|wallets,1claw portfolio,1claw agent keys import,1claw agent smart-account-import,1claw treasury wallet import. - MCP:
import_signing_key,list_cedar_policies,test_cedar_policy,list_opa_policies,test_opa_policy,list_sub_orgs,create_sub_org,get_portfolio,import_smart_accounttools.
Dashboard
- Updated: Policy create/list pages now show effect (allow/deny badge) and priority fields.
- Updated: Create policy form includes effect dropdown and priority input.
Clients
@1claw/sdk@0.47.0,@1claw/cli@0.47.0,@1claw/mcp@0.47.0,@1claw/openapi-spec@0.47.0- Python SDK
oneclaw@0.47.0, Go SDKv0.47.0
v0.46.0 — Agent Delegation Framework (2026-08-12)
Agent-to-Agent Delegation
- New: Human-controlled agent-to-agent delegation framework. Agents cannot delegate to other agents without an explicit
agent_delegationsrecord created by a human. - New: Three delegation modes:
caller(delegate uses own credentials, default/most secure),target(delegate uses target agent's config),both(per-invocation choice). - New: Security guardrails: tool allowlists/blocklists per delegation, daily rate limits (
max_daily_delegations), recursive depth limits (max_depth1–10 viaX-Delegation-Depthheader), expiration, self-delegation blocked (400). - New: Chat enforcement — cross-agent
POST /v1/agents/{id}/chatrequires active, non-expired delegation from caller to target. Delegation engine validates tools, daily limits, and depth. - New:
agents.delegation_enabledBOOLEAN field — agents must have this enabled to participate in delegation.
Endpoints
POST /v1/agents/{id}/delegations— Create delegation (human-only). Body:{ delegate_id, delegation_mode, allowed_tools?, blocked_tools?, max_daily_delegations?, max_depth?, guardrails?, expires_at? }.GET /v1/agents/{id}/delegations— List delegations (human sees all; agent sees own).GET /v1/agents/{id}/delegations/effective— Agent-callable. Returns delegations where calling agent is the delegator (for runtime tool discovery).GET /v1/agents/{id}/delegations/{delegation_id}— Get delegation details.PATCH /v1/agents/{id}/delegations/{delegation_id}— Update delegation (human-only).DELETE /v1/agents/{id}/delegations/{delegation_id}— Revoke delegation (human-only).
Runtime Tools
- Updated:
delegate_tasktool now enforces delegation authorization — delegation-specific 403 errors returned for unauthorized cross-agent communication. - Updated:
list_my_sub_agentsnow includes delegation status per agent:{ authorized, mode, allowed_tools, remaining_daily }. - New:
get_delegation_statustool — check which agents the caller is authorized to delegate to with tool/limit details.
SDK / CLI / MCP
- SDK:
client.agents.createDelegation(),.listDelegations(),.getDelegation(),.updateDelegation(),.revokeDelegation(),.getEffectiveDelegations(). - MCP:
list_delegations,create_delegation,get_effective_delegationstools. - CLI:
1claw agent delegation create|list|get|update|revoke <agent-id>.
Dashboard
- New: Sub-agent creation wizard at
/agents/sub-agent-wizard— 4-step flow with 6 role presets (Research, Image Gen, Treasury, Comms, Code, Custom). Configures capabilities, sets delegation rules with multi-parent support. - New: Delegations tab on agent detail page — outbound (this agent delegates TO others) and inbound (others delegate TO this agent) tables with create, edit, revoke dialogs.
- New: Sub-Agents card on runtime detail page — "Create Sub-Agent" button, delegation status badges (green "Authorized" / gray "No Delegation"), "Authorize" quick-action.
- New: Sub-agent tag indicators on agents list page, "Create Sub-Agent" button.
Audit
- New audit events:
agent.delegation.created,agent.delegation.updated,agent.delegation.revoked,agent.delegation.invoked,agent.delegation.blocked.
DB
- Migration 176:
agent_delegationstable with partial unique index on(delegator_id, delegate_id) WHERE is_active = true. RLS enabled. - Migration 177:
delegation_eventstable for daily rate limit tracking. agents.delegation_enabledBOOLEAN DEFAULT false.
Tests
scripts/test-sub-agents-prod.sh(~55 assertions) — CRUD, enforcement, depth limits, rate limits, tool blocklists, revocation.scripts/test-delegation-security-prod.sh(~25 security assertions) — bidirectional isolation, expired delegations, self-delegation.
Clients
@1claw/sdk@0.46.0,@1claw/cli@0.46.0,@1claw/mcp@0.46.0updated with delegation types and methods.
v0.45.0 — Hermes-Native Channel Features, Sub-Agent Chat Fix, Image Gen Fallback (2026-08-12)
Added
- Hermes-Native Channel Features: Slash command router (12 commands), voice memo transcription (Telegram/Whisper), cross-platform conversation continuity via
unified_conversation_id, automation→channel delivery, context-aware interruption, platform presence (is_home_platform,/sethome) - Sub-Agent Chat Fix: Agents can now chat with any agent in the same organization (previously restricted to self-only)
- Shroud Image Gen Fallback: DALL-E image generation uses
OPENAI_API_KEYenv var fallback for non-chat endpoints - Runtime API Keys UX: New dashboard component for configuring runtime API keys
Fixed
- LLM Billing Duplicate Fix: Subscription lookup now finds ALL non-cancelled subscriptions, preventing duplicate billing. Dashboard shows improved warning banner.
Changed
- DB migrations 174-175: New columns on
agent_channels(slash_commands_enabled, voice_transcription_enabled, unified_conversation_id, auto_respond_in_progress, is_home_platform) andchannel_messages(is_voice_message, voice_file_id, voice_duration_secs, transcription_status) - New domain modules:
slash_commands.rs,voice_transcription.rs,hermes_migration.rs
v0.46.0 — OAuth2 Refresh Tokens, Platform Marketplace, Security Hardening (2026-08-12)
OAuth2 Authorization Server
- New: Refresh token support —
POST /v1/oauth/tokenreturnsrefresh_tokenwhenoffline_accessscope is requested. Exchange viagrant_type=refresh_token. DB:oauth_refresh_tokenstable (migration 173). - New: Token revocation —
POST /v1/oauth/revokerevokes access or refresh tokens (RFC 7009). - New: Consent revocation —
DELETE /v1/oauth/consent/{app_slug}revokes all consent and tokens for an app (user-only). - New: Scope-filtered UserInfo —
GET /v1/oauth/userinfonow respects granted scopes (e.g.emailscope required for email field). - New:
<SignInWith1Claw />React component in@1claw/wallet-reactfor one-click OAuth integration.
Platform API
- New:
max_connected_usersfield on platform apps — enforced limit on connected users per app. - New: Platform marketplace —
GET /v1/platform/marketplacelists approved apps with category, tags, screenshots. Dashboard at/marketplace. - New: App stats —
GET /v1/platform/apps/{id}/statsreturns connected user count, bootstrap count, active connections. - New: Platform webhook secret rotation —
POST /v1/platform/apps/{id}/rotate-webhook-secretrotates the platform app delivery HMAC secret. - New: 6 platform webhook events:
platform.user.connected,platform.user.disconnected,platform.bootstrap.completed,platform.grant.created,platform.grant.revoked,platform.user.claimed. - New: Platform rate limiting — per-app configurable
max_requests_per_minuteon platform API endpoints. - New: Platform onboarding wizard — step-by-step flow at
/platform/wizardfor creating an app, template, and first user. - Fixed: Multi-agent bootstrap — template specs with multiple agents now correctly provision all agents (was only creating the first).
- New: Delegation scopes for memory/chat —
memory:read,memory:write,chat:read,chat:writeadded to platform delegation scope enforcement.
Runtime Chat
- Fixed: Anthropic tool deduplication — duplicate tool definitions no longer sent to Anthropic models.
- Improved: Graceful LLM fallback — runtime chat falls back to a simpler prompt when the model rejects the request.
- Improved: BYOK UX — LLM API key configuration now shows auto-suggested provider based on key prefix.
LLM Billing
- Fixed: Duplicate subscription detection —
POST /v1/billing/llm-token-billing/subscribedetects and cleans up duplicate Stripe subscriptions. Dashboard shows warning banner when duplicates are detected.
wallet-react (v0.5.0)
- Fixed: 8 auth bugs: token refresh race, social login popup handling, cross-origin message validation, email OTP retry logic, passkey credential caching, session expiry redirect, PKCE state cleanup, consent page deep-link.
- New: Passwordless send via passkey —
sendWithPasskey()method for transaction authorization without password. - Improved: Social login popups — better popup handling for Google/Apple/Discord providers.
- New: CSS theming —
themeprop accepts full CSS custom properties object for deep customization. - New: Toast notifications — built-in toast system for transaction status updates.
- New: Skeleton loading — skeleton UI states for wallet and balance loading.
SDK (v0.46.0)
- New:
auth.generatePKCE()— generates PKCE code verifier and challenge. - New:
auth.buildAuthorizeUrl()— builds OAuth authorize URL with PKCE parameters. - New:
auth.getUserInfo()— fetches UserInfo from OAuth access token. - New:
auth.revokeToken()— revokes an OAuth access or refresh token. - New:
auth.revokeConsent()— revokes OAuth consent for a specific app. - New:
platform.rotateWebhookSecret()— rotates webhook HMAC secret. - New:
platform.getAppStats()— fetches platform app statistics. - New:
platform.marketplace()— lists marketplace apps.
Security
- Fixed (TOCTOU): OAuth authorization code exchange uses atomic
UPDATE ... RETURNINGto prevent time-of-check-to-time-of-use race. - Fixed (Chat authZ):
POST /v1/agents/{id}/chatenforces org membership for users and same-org check for agent callers. - Fixed (Discord replay): Discord OAuth
stateparameter is single-use (consumed on callback) to prevent replay attacks. - Fixed (OAuth atomic): Authorization code creation and consent recording use a database transaction to prevent orphaned codes.
- Fixed (Channel allowlists):
auto_respond_enabledmust be true AND sender must be insender_allowlistfor auto-respond to trigger.
Dashboard
- Fixed: Template spec builder edit round-trip — editing an existing template now correctly loads the current spec.
- Improved: OAuth consent page UX — better error states, scope descriptions, app logo display.
- New: Grant page auth gate —
/connect/{slug}/grantrequires authentication (redirects to login). - Improved: Mobile responsiveness — sidebar, tables, and cards responsive on mobile viewports.
- New: Marketplace page at
/marketplace— browse approved platform apps.
Clients
@1claw/sdk@0.46.0,@1claw/wallet-react@0.5.0,@1claw/mcp@0.46.0,@1claw/openapi-spec@0.46.0updated.
2026-08
v0.45.0 — Runtime Tool Registry, Sub-Agent Framework (2026-08-11)
Runtime Tool Registry
- New: 12 tool modules in
packages/runtime-base/templates/shared/tools/provide runtime agents with structured capabilities:image-gen.js— DALL-E image generation (requiresshroud_enabled)web-search.js— Web search via Brave/Tavily/SerpAPImemory-tools.js— Agent memory CRUD (requiresmemory_enabled)file-handler.js— Image analysis and URL readingcode-exec.js— Sandboxed code executiongoogle-tools.js— Google API integrationsgithub-tools.js— GitHub API toolsslack-tools.js— Slack messagingsocial-tools.js— Social media toolsvault-tools.js— Direct vault secret accessnotify-tools.js— Multi-channel notificationssub-agents.js— Sub-agent framework (see below)
- New: Per-template tool configs — each runtime template (hermes, openclaw, openclaude) has a
tools-config.jsthat enables/disables specific tools based on the template's use case. - Dashboard:
RuntimeToolsCardcomponent on runtime detail page showing enabled/disabled tools per runtime.
Sub-Agent Framework
- New: 4 runtime-level tools for agent-to-agent collaboration:
discover_agents— Search the public agent directory for agents by capabilitydelegate_task— Send a task to another agent via chat and wait for responselist_my_sub_agents— List agents in the same org (org-scoped directory)create_sub_task— Trigger automations on behalf of another agent
- Agent-to-agent communication uses
POST /v1/agents/{id}/chat— agents can now call this endpoint on other agents within the same org. - Dashboard: Sub-Agents tab on runtime detail page.
New Endpoints
GET /v1/agents/org-directory— Authenticated org-scoped agent directory listing. Returns all agents in the caller's org with name, description, capabilities, and status. Used by the sub-agentlist_my_sub_agentstool for agent discovery within an organization.
Shroud
- DALL-E bypass: Image generation requests routed through Shroud now bypass the Stripe AI Gateway. DALL-E has its own billing model and does not need metering through the gateway.
Dashboard
RuntimeToolsCardcomponent on runtime detail page — visual grid of enabled/disabled tools per runtime with tooltips showing requirements (e.g. "Requires shroud_enabled").- Sub-Agents tab on runtime detail page — shows connected agents, delegation history, and task status.
Clients
@1claw/sdk@0.45.0,@1claw/cli@0.45.0,@1claw/mcp@0.45.0,@1claw/openapi-spec@0.45.0updated.
v0.44.0 — Security fixes, platform delegation enforcement, channels, chat (2026-08-11)
OAuth Connected Accounts
- New: Universal OAuth integration for AI agents — connect agents to external services (Google, GitHub, X/Twitter, LinkedIn, Slack, Discord, Notion, Microsoft, Salesforce, HubSpot) via human-approved OAuth flows.
- Provider registry seeded with 10 providers (migration 171). OAuth app credentials encrypted at rest (migration 172).
- Endpoints:
GET /v1/oauth/providers,POST /v1/agents/{id}/oauth/connect,GET .../oauth/connections,POST .../oauth/disconnect/{bindingId}, credential CRUD. - SDK
OAuthConnectResource, MCPlist_oauth_providers/list_oauth_connections, CLI1claw oauth. - Dashboard:
ConnectedAccountsCardon agent detail page (Connections tab).
Security (C-1 Critical + 6 Medium + 8 Low)
- C-1 CRITICAL — Agent memory cross-org isolation (migration 166): Shared memory entries could collide across orgs due to missing
org_idin the unique index. Fixed by addingorg_idto the constraint. - M-2 — Automation runs status CHECK (migration 167): Added
awaiting_approvalto the automation_runs status CHECK constraint. - M-4 — Channel sender allowlist (migration 168): Added
sender_allowlistandauto_respond_enabledcolumns to agent channels for restricting which sender IDs can trigger auto-respond. - M-5 — Telegram dedup (migration 169): Track
last_telegram_update_idper channel to prevent duplicate message processing. - M-6 — Shared memory org validation: Cross-org shared memory access prevented.
- Low: Runtime chat rolling message cap, Cloud Run internal-only ingress, XFF bypass fix, agent token TTL reduced to 2h, step-up unlock prefix hardening, LLM billing gating improvements.
Platform API
- Delegation scope enforcement:
delegation_scopesnow enforced on 4 handler groups: secrets, policies, bindings, and discovery. Missing scope → 403. - Disconnected connection rejection: Operations on disconnected platform connections rejected with 403.
- Bootstrap runtimes & automations: Template
specnow supportsruntimesandautomationsarrays. Bootstrap creates these resources and tracks IDs on the connection (runtime_ids,automation_ids— migration 170). - Dashboard: Platform audit page, key rotation UI, connected apps grant management with expandable panels.
Agent Chat
- New: Chat conversations between humans and agents via Shroud LLM proxy. Persistent conversation history with SSE streaming.
- Endpoints:
POST /v1/agents/{id}/chat,POST .../chat/unlock,GET .../chat/conversations,GET/DELETE .../chat/conversations/{id}. - SDK
client.chat.*, MCPsend_chat_message,list_chat_conversations.
Messaging Channels
- New: Connect agents to Telegram, WhatsApp, and Discord for bi-directional messaging with auto-respond.
- Per-channel sender allowlists, WhatsApp HMAC verification, Telegram dedup.
- Image generation delivery (DALL-E images delivered inline on Telegram and dashboard chat).
- Endpoints: CRUD under
/v1/agents/{id}/channels, webhook endpoints per platform. - MCP
create_channel,list_channels,send_channel_message.
Dashboard
- Fixed: Automations detail page crash.
- Improved: Assist NL mapping, automations wizard/assist UX, runtime chat code formatting.
- Template Spec Builder supports runtime and automation entries.
Clients
@1claw/sdk,@1claw/cli,@1claw/mcp,@1claw/openapi-specupdated.
v0.43.4 — Automations v2: Workflow Engine, SDK ESM fix, Python SDK (2026-08-10)
Automations v2 — Workflow Engine
- New: 7 new step types —
ai_generate(LLM text generation via Shroud),memory_get,memory_put,memory_search(agent memory CRUD),notify(webhook/slack/email notifications),approval_request(human-in-the-loop gate),condition(if/else branching with sub-steps). - New: Template variable syntax —
{{steps.<index_or_name>.<field>}}for referencing previous step outputs,{{webhook_payload.<path>}}for webhook trigger data. Applied recursively before step execution. - New: Conditional execution —
skip_ifandrun_ifstring expressions on any step (operators:==,!=,contains,>,<,>=,<=, truthy). - New: Cancel run endpoint —
POST /v1/automations/{id}/runs/{run_id}/cancel(human-only; cancelsrunningandawaiting_approvalruns). - New: Enriched list API —
GET /v1/automationsreturnslast_run_status,total_runs(30-day),success_rate(percentage), andagent_name. - New: 10 marketing-ready presets —
GET /v1/automations/presets(public): rotate-api-keys-weekly, daily-dca-buy, health-check-alert, database-sync, weekly-content-draft, lead-nurture-email, competitor-watch, sentiment-alert, campaign-report, monitor-balance. - New:
contextJSONB column onautomation_runsfor step output persistence. - DB: Migration 165 (workflow engine v2 —
contextcolumn + index onautomation_runs).
SDK 0.43.4 — ESM fix
- Fixed: ESM module resolution corrected for bundler-free environments (Node.js
--conditions, Deno, Bun). Named exports now work correctly withimport { createClient } from '@1claw/sdk'.
Runtime max_tokens fix
- Fixed:
max_tokensparameter now correctly passed through to LLM providers in runtime chat and automationai_generatesteps.
Python SDK 0.43.4
- New:
oneclawPython SDK updated to 0.43.4 — automation support (client.automations.create/list/trigger), memory CRUD (client.memory.store/search/list), runtime management, and discovery.
Dashboard
- New: Automation create wizard includes preset gallery with one-click deployment.
- New: Enriched automation list shows last run status, success rate, and total runs.
- New: Cancel button on running automation detail page.
- New: Automations Assist page at
/automations/assistwith visual step editor.
Clients
@1claw/sdk@0.43.4,@1claw/cli@0.43.4,@1claw/mcp@0.43.4,@1claw/openapi-spec@0.43.4,oneclaw(Python)0.43.4.
v0.43.3 — Runtime Chat, Assist step editor, log security (2026-08-04)
Added
- Runtime Chat —
POST /v1/runtimes/{id}/chat(SSE); Chat tab next to Shell for hermes/openclaw/openclaude; OpenAI-compatible in-container bridge. - Automations Assist step editor — type-specific editable fields + selectors; Advanced JSON collapsed.
- Logs step-up unlock —
POST /v1/runtimes/{id}/logs/unlock(password or passkey reauth, purposeruntime_logs, 15 min grant).
Security
- Runtime logs exclude/summarize GCP audit payloads and redact JWTs/API keys server-side.
- Agent JWTs mounted via Secret Manager
secretKeyRefso CreateService audit logs do not embed plaintext tokens. - When
agent.shroud_enabled, runtimes enable sidecar/Shroud LLM path; automation swap/submit route signing through Shroud.
Clients
@1claw/openapi-spec/@1claw/sdk/@1claw/cli0.43.3;@1claw/agentkit0.43.2;@1claw/plugin-elizaos0.2.1.
v0.43.2 — Webhook automations, event triggers, runtime logs (2026-08-03)
Added
- Webhook automations —
trigger_type: webhookreturns one-timewebhook_url+whk_token on create. Public trigger:POST /v1/automations/{id}/webhook/{token}. Human-only rotation:POST /v1/automations/{id}/rotate-webhook-token. - Event-trigger wiring — Automations with
trigger_type: eventandevent_filter.event_typefire onsecret.created/updated/rotated/deletedandpolicy.created/updated/deleted. - Automations Assist —
POST /v1/automations/assist/draftand/assist/sessiondocumented in OpenAPI; dashboard Assist flow + OpenClaude runtime template. - Runtime logs API —
GET /v1/runtimes/{id}/logs?tail=Nreturns{ entries: [...] }(replaces legacylines/sincequery params). SDKruntimes.logs(), MCPruntime_logsusetail.
Clients
- OpenAPI 2.31.0 /
@1claw/openapi-spec@0.43.2,@1claw/sdk@0.43.2,@1claw/mcp@0.43.2.
v0.43.1 — Automations workflow_spec + runtime interactive shell (2026-08-03)
Fixed / clarified
- Automations create contract —
POST /v1/automationsrequiresworkflow_spec(+agent_id;cron_exprwhen trigger is cron). Dashboard maps legacyaction_typeUI fields ontoworkflow_spec. API acceptstrigger_type: "schedule"as an alias forcron, and accepts workflow shapes as either a bare step array or{ "steps": [...] }. - Clients synced — OpenAPI 2.30.0 /
@1claw/openapi-spec@0.43.1,@1claw/sdk@0.43.1(runtimes.createShellSession), Go SDK (v0.43.0), Python SDK (oneclaw@0.43.3), CLI@1claw/cli@0.43.1, MCP@1claw/mcp@0.43.1(io.github.1clawAI/1claw-mcp). Updated off the old/v1/agents/{id}/automations+action_typeshapes. CLI README examples use--workflow/--cron. - Runtime interactive shell —
POST /v1/runtimes/{id}/shell/session(+/shell/passkey/begin) documented in OpenAPI. Human-only step-up auth (password, TOTP, passkey, orreauth_token). Dashboard terminal uses binary PTY WebSocket; Vault auto-repairs Cloud Run invoker IAM (non-blocking on Connect to avoid gateway 504). Hermes/runtime images must includeshroud-sidecar— rebuild templates after base updates; enabling shell while running triggers background reconcile / may still need stop/start. - Manual automations — DB allows
trigger_type: "manual"; create no longer 500s for manual workflows. - Prod tests —
scripts/test-automations-prod.shexercisesworkflow_spec+ schedule→cron alias;scripts/test-runtimes-prod.shadds shell session auth/enablement guards.
v0.42.0 — Automations, Runtimes, Agent Memory, Discovery, and Platform enhancements (2026-08-01)
Added
- Agent Memory — Three-tier memory system (scratch, durable, semantic) for AI agents. Scratch is ephemeral and auto-cleared per session; durable persists across sessions; semantic enables vector similarity search via pgvector. All tiers encrypted at rest with envelope encryption. Endpoints:
POST/GET/DELETE /v1/agents/{id}/memory,POST /v1/agents/{id}/memory/search. SDKclient.memory.*, CLI1claw memory, MCP toolsmemory_put/memory_get/memory_list/memory_search/delete_memory. Dashboard: Memory card on agent detail with tier tabs and search UI. - Automations — Cron-scheduled, webhook-triggered, and event-driven automation workflows with multi-step pipelines and AI integration. Visual cron builder in the dashboard. Tier-gated: Free 2, Pro 10, Team 50, Business 200. Endpoints:
POST/GET /v1/automations,GET/PATCH/DELETE /v1/automations/{id},POST /v1/automations/{id}/trigger,GET /v1/automations/{id}/runs. SDKclient.automations.*, CLI1claw automation, MCPlist_automations/trigger_automation. Dashboard pages at/automations,/automations/new,/automations/[id]. - Cloud Runtimes — Deploy AI agents in managed containers with resource presets: small (0.5 vCPU/512MB), medium (1 vCPU/1GB), large (2 vCPU/4GB), large-cc (4 vCPU/8GB confidential compute). Public URL hosting, idle auto-stop, log streaming, health monitoring. Endpoints:
POST/GET /v1/runtimes,GET/PATCH/DELETE /v1/runtimes/{id}, start/stop/logs sub-routes. SDKclient.runtimes.*, CLI1claw runtime, MCPlist_runtimes/manage_runtime/runtime_status/runtime_logs. Dashboard pages at/runtimes,/runtimes/new,/runtimes/[id]. - Agent Discovery — Public agent directory and platform marketplace. Agents can be made discoverable with capability cards showing A2A/MCP URLs, supported protocols, and pricing. Endpoints:
GET /v1/agents/directory,GET /v1/agents/{agent_id}/card,POST /v1/agents/{agent_id}/discovery. SDKclient.discovery.*, CLI1claw directory, MCPsearch_directory. Dashboard:/directorypublic page, discovery card on agent detail. - Platform Delegation — Platform apps can perform CRUD on connected user resources via
X-Platform-Connectionheader. Scoped bydelegation_enabledanddelegation_scopeson platform apps. Operations attributed to the platform app in audit logs. DB: migration 151. - OAuth2 Credential Bindings — Execution Intents bindings support OAuth2 credential type with
authorization_codeandclient_credentialsgrant flows. Automatic token refresh before execution. DB: migration 150. - New agent columns:
llm_default_provider,llm_default_model(migration 143) for agent LLM defaults. - New sidebar entries: Automations, Runtimes, and Directory pages added to dashboard sidebar navigation.
- DB migrations: 141 (automations), 142 (automation_runs), 143 (agent LLM defaults), 144 (runtimes), 145 (agent_memory_entries), 146 (agent_memory_vectors), 147 (runtime_hosting), 148 (agent_discovery), 149 (platform_listing), 150 (oauth2_credential_bindings), 151 (platform_delegation_scopes).
Changed
- Dashboard sidebar updated with new navigation items for Automations, Runtimes, and Directory.
- SDK types extended with memory, automation, runtime, and discovery interfaces.
- MCP server tool count increased from 50 to 62 tools.
2026-07
Payment Card Vault — human-in-the-loop approval (2026-07-17)
Card orders require human approval by default
- New:
card_require_approvalon agents (default true). When enabled,POST /v1/agents/{id}/cards/orderreturns 202 withstatus: awaiting_approvalandapproval_id— x402 payment runs only after a human approves. - New:
GET /v1/approvals/quick-decide— public one-click approve/deny from email (SHA-256 hashed, single-use tokens inapproval_quick_tokens; 7-day TTL). Dashboard proxy:GET /api/approvals/quick-decide. - New: Approval notifications — email with Approve/Deny CTAs; push notification dispatch to registered mobile devices.
- New: Auto-execution on
POST /v1/approvals/{id}/decidewhenaction == card_order(approved → pay + Laso; rejected →card.rejectedwebhook). - New: Risk-tier step-up on approve (T2+ requires
X-Auth-Confirmre-auth token; T3 passkey/TOTP). - New: TOTP as re-auth method —
POST /v1/auth/reauth/begin+completewithmethod: "totp". - New: Webhook events
approval.created,approval.decided,card.rejected. - New: Card statuses
awaiting_approval,rejected;approval_idon card responses. - DB: migration 139 (
card_require_approval,approval_quick_tokens, extended status CHECK). - Clients: Dashboard approval detail card-order renderer, guardrails toggle, mobile
card_orderscreen; SDK types updated.
Payment Card Vault — x402 card ordering (Laso) (2026-07-14)
Agents can order prepaid & gift cards, paid with USDC via x402, without ever seeing the PAN
- New:
POST /v1/agents/{id}/cards/order— order a prepaid or gift card. Paid with an outbound x402 payment the Vault constructs and signs (EIP-3009TransferWithAuthorization) using the agent's own Ethereum signing key on Base. Requirescards_enabledand anIdempotency-Keyheader. Available on all tiers (Free: $25/order, 5 cards/month; Pro: 50/month; Team: 200/month; Business+: unlimited). A 3% platform fee per order is debited from prepaid credits. Returns a masked card reference — never a PAN. - New: Card lifecycle endpoints —
GET /v1/cards,GET /v1/cards/{id}(masked to last4),POST /v1/cards/{id}/reveal(humanX-Auth-Confirmre-auth, or per-card agent reveal policy; audit-logged),PATCH /v1/cards/{id}(reveal policy /void_after, human-only),POST /v1/cards/{id}/void(1Claw-level lock, forward-looking only),POST /v1/cards/{id}/refresh(rate-limited → clean 429 +Retry-After),POST /v1/cards/import(human-only, full encrypted storage with one-time-read CVV),POST /v1/cards/gift-cards/search. - New: Ordering guardrails on agents —
cards_enabled,card_max_order_usd,card_daily_limit_usd(enforced atomically over a rolling 24h window),card_payto_allowlist,card_reveal_enabled. These bound the purchase, not how a revealed card is later spent. - New: Outbound x402 client (
crypto/x402_client.rs) validates every 402 challenge before signing —payToallowlist, Base network, exact requested amount, and the pinned Base USDC contract. The stored Laso bearer token is constrained in code to a hardcoded card-endpoint path allowlist (never/withdrawor/send-payment). - New:
card_monitorbackground worker (15s, advisory-lock leader election) — polls the issuer, fillslast4/expiry/balance, stores gift-card redemption payloads as secrets, fires webhooks, auto-voids pastvoid_after, and reconcilesordering-stuck rows asorphaned_payment. - New: Webhook events
card.ordered,card.ready,card.revealed,card.voided,card.depleted,card.orphaned_payment. - Security: PCI-conscious reference mode (only the issuer card id + encrypted refresh token stored; PAN/CVV fetched just-in-time at reveal). Shroud's PII detector now Luhn-validates PANs and detects CVV/expiry patterns, blocking card data in LLM traffic; full-mode PANs are excluded from the admin secrets manifest.
- DB: migration 135 (extends
secret_typewithpayment_card/gift_card), migration 136 (payment_cardstable + agent guardrail columns). - Clients: SDK
client.cards.*, CLI1claw card order|list|get|reveal|void|refresh|import, MCPorder_card/order_gift_card/search_gift_cards/list_cards/get_card_status(reveal omitted from MCP), OpenAPI spec, and a Cards dashboard page + agent "Card Ordering Guardrails" card.
v0.41.2 — Overhead budget and transaction count limits (2026-07-13)
Anti-drain guardrails
- New:
tx_max_per_day(INTEGER) on agents — daily transaction count cap (UTC calendar day). Prevents high-frequency drain attacks. Per-chain override viaper_chain_guardrails.{chain}.max_per_day. - New:
tx_overhead_budget(JSONB) on agents — per-chain daily budget for non-value costs (rent, fees, energy) in native units. Prevents ATA rent drain (Solana), XRP reserve exhaustion, Tron energy drain, and fee storms. Format:{"solana": "0.5", "xrp": "100", "ethereum": "0.01"}. - New:
solana_ata_allowlist(TEXT[]) on agents — restricts which Solana wallet addresses may have Associated Token Accounts created. Prevents ATA rent drain attacks by limiting recipients. - New:
agent_overhead_ledgertable (migration 127) — tracks per-chain overhead costs for budget enforcement. - New:
domain/overhead.rs— per-chain overhead cost estimation module covering EVM (gas), Solana (rent + priority fees), Bitcoin (fee rate), XRP (reserves), Cardano (min-ADA), and Tron (energy). - New: Response fields
tx_count_todayandtx_overhead_today_by_chaininGET /v1/agents/{id}for dashboards and Shroud. - New:
per_chain_guardrailsextended withmax_per_day,overhead_budget, andmax_ata_creates_per_dayfields. - Shroud:
AgentTxGuardrailsmirrors new fields; enforcement parity with Vault API. - Dashboard: Transaction Guardrails card gains Max Transactions Per Day, Overhead Budget (JSON), and Solana ATA Allowlist fields. Summary badges for active limits.
- Clients: SDK (
tx_max_per_day,tx_overhead_budget,solana_ata_allowlist,tx_count_today,tx_overhead_today_by_chain), CLI (--tx-max-per-day,--tx-overhead-budget,--solana-ata-allowlist), Python SDK, Go SDK, Mobile, and OpenAPI spec updated.
v0.41.1 — TEE enforcement toggles (2026-07-13)
Agent-level TEE enforcement (Pro+)
- New:
intents_require_teeboolean on agents — when enabled, transaction sign/submit requests toapi.1claw.coare rejected with 403. Agents must route throughshroud.1claw.cowhere signing happens inside the hardware enclave. - New:
execution_require_teeboolean on agents — when enabled, execute requests toapi.1claw.coare rejected AND all direct secret reads by the agent are blocked. Forces use of Execution Intents bindings through the TEE. - New:
X-1Claw-TEE-OriginHMAC verification module (vault/src/api/middleware/tee_origin.rs) — Shroud sets this header on proxied requests; Vault validates using sharedONECLAW_TEE_ORIGIN_SECRET. - Changed: "Enable Intents API" toggle moved from the Overview tab to the Signing tab on agent detail page.
- Dashboard: Two new TEE enforcement toggles on the Signing tab with Pro+ tier badge, disabled states (dependent on base flags), and confirmation dialog warning about breaking changes.
- Migration 133: Adds
intents_require_tee BOOLEAN DEFAULT falseandexecution_require_tee BOOLEAN DEFAULT falsetoagentstable. - JWT claims:
intents_require_teeandexecution_require_teeincluded in agent JWTs when true. - Clients: SDK, CLI (
--intents-require-tee,--execution-require-tee), Python SDK, Go SDK, and OpenAPI spec updated.
v0.41.0 — Live-pointer credential references for Execution Intents (2026-07-12)
Credential sources
- New:
credential_sourcefield onCreateBindingRequestandUpdateBindingRequest— a tagged union supporting two modes:{ type: "inline", value: {...} }— legacy behavior, credential copied into__agent-keysvault{ type: "vault_ref", vault_id: "...", path: "..." }— live pointer to an existing vault secret. The executor resolves the secret at execution time, so rotations in the source vault are reflected automatically without manual credential rotation.
- New:
BindingResponseincludescredential_source_type("inline" | "vault_ref"),credential_vault_id, andcredential_pathso the UI can display how credentials are sourced. - New: Dashboard binding form has a Manual / From Vault toggle — selecting "From Vault" lets users pick an existing vault secret; the binding references it directly (no duplication).
- New: Validation ensures the referenced vault belongs to the same org and the secret path exists.
- Migration 132: Adds
credential_vault_id UUID(FK to vaults, ON DELETE SET NULL) andcredential_path TEXTcolumns toagent_bindings.
Clients
- SDK:
CredentialSourcetype exported;CreateBindingRequestandUpdateBindingRequestacceptcredential_source. Version bumped to@1claw/sdk@0.41.0. - CLI:
agent binding create --vault-ref <vault-id>:<path>flag. Version bumped to@1claw/cli@0.41.0. - MCP:
create_bindingtool acceptscredential_sourceparameter. Version bumped to@1claw/mcp@0.41.0. - OpenAPI:
CredentialSourceschema added; binding request/response schemas updated. Version bumped to@1claw/openapi-spec@0.41.0. - Python SDK:
CredentialSourcemodel,credential_sourcefield on binding requests. - Go SDK:
CredentialSourcestruct, updated binding request/response types.
Execution Intents 2.0 — executor framework, real GraphQL, guardrail enforcement, credential lifecycle (2026-07-12)
Executor framework
- New: Trait-based executor framework (
domain/execution/) with a sharedExecutionContextthat centralizes SSRF validation, host/path allowlisting, credential loading, and timeout resolution — no executor can accidentally skip a guardrail. Replaces the previous single-file HTTP dispatch. - New: Real GraphQL executor — POSTs
{ query, variables, operationName }, surfaces GraphQLerrors[], and uses introspection for connectivity tests (previously GraphQL was an HTTP alias).
Guardrail enforcement
- New: Per-binding
allowed_pathsis now enforced at execute time (trailing-*wildcard supported); disallowed paths are recorded asdenied. - New: Agent-level
execution_guardrailsare enforced:allowed_hosts(strictest of binding + agent),allowed_binding_types(at execute, not just create),max_duration_ms(applied as the real client timeout), andmax_requests_per_minute(per-agent rate limit). - Changed: Connectivity
testnow runs through the sameExecutionContextasexecute, so SSRF and host-allowlist checks apply to tests too.
Credential lifecycle & custody
- New: Explicit credential rotation endpoint —
POST /v1/agents/{id}/bindings/{binding_id}/rotate-credential. - New:
credential_setboolean on binding responses reports whether a credential is stored, without ever exposing the value. - Fixed: Binding delete now purges the stored credential (no orphaned secrets);
secret_typeunified tocredential.
Execution surface & billing
- New:
execution_surfaceon the execute response truthfully reportsvaultortee(TEE only when a Shroud execution endpoint is configured);ONECLAW_EXECUTION_TEE_REQUIRE_SHROUD=truemakes TEE requests 501 when no enclave endpoint is present, instead of silently running in Vault. - Fixed: Only successful executions count toward the monthly execution quota; the TEE cost premium is charged as a delta over the base rate to avoid double-billing.
Clients & UI
- New: MCP tools
create_binding,test_binding,list_executions, and genericexecute_intent(joiningexecute_httpandlist_bindings). - New: SDK
client.bindings.rotateCredential(); OpenAPI updated with the rotate-credential path,credential_set, andexecution_surface. - New: Dashboard Execution Intents card rebuilt with tabs (Bindings / Execution Log / Playground), inline binding edit +
is_activetoggle, per-binding and per-agent guardrail editors, tier-aware type gating, and write-only credential UX. - New: CLI
@1claw/cli@0.40.1—1claw agent bindingsubcommands (create, list, get, update, delete, test, rotate-credential, execute, executions);--execution-intentsand--execution-guardrailson agent create/update. - New: Python SDK
oneclaw@0.2.1—bindings.rotate_credential(); Go SDKv0.40.1—Bindings.RotateCredential()andcredential_seton binding responses. - New: Audit events for binding create/update/delete/rotate and every execution outcome (
success/error/denied).
Vault 0.39.1 / Shroud 0.37.2 — dRPC managed RPC, Robinhood Chain, security hardening (2026-07-12)
dRPC Managed RPC Endpoints
- New: Automatic dRPC RPC fallback for 25 EVM chains when
DRPC_API_KEYis configured. When a chain has no explicitrpc_urlin the database, the Vault and Shroud dynamically construct a dRPC endpoint URL. Supported chains: Ethereum, Base, Optimism, Arbitrum, Polygon, Avalanche, BSC, zkSync Era, Linea, Scroll, Mantle, Blast, Gnosis, Fantom, Celo, Aurora, Metis, Moonbeam, Cronos, Sepolia, Holesky, Base Sepolia, Optimism Sepolia, Arbitrum Sepolia, Polygon Amoy. - New:
resolve_effective_rpc()shared helper in Vault consolidates RPC resolution: explicit DB URL → dRPC fallback → public testnet fallback. - New: Shroud
ChainRegistryexpanded to 29 EVM chains witheffective_rpc_url()method mirroring Vault's resolution logic. - New: Numeric chain ID → dRPC reverse lookup via
drpc_slug_for_chain_id()— enables dRPC support even when chains are referenced by numeric ID only.
Robinhood Chain Support
- New: Robinhood Chain (mainnet, chain ID 4663) and Robinhood Testnet (chain ID 46630) added to the chain registry.
- New: Native RPC endpoints configured:
https://mainnet.robinhoodchain.com/rpc(mainnet) andhttps://testnet.robinhoodchain.com/rpc(testnet). - New: Known tokens seeded: RBH (mainnet,
0xRBH...), USDC (mainnet), testRBH (testnet). - New:
resolve_chain_id()recognizesrobinhood-chain,robinhood_chain,robinhood,robinhood-testnet,robinhood_testnet. - New:
signing_key_chain_for()mapsrobinhood-chainandrobinhood-testnettoethereum(secp256k1). - New: Database migration
131_add_robinhood_chain.sql.
Security Hardening (July 11-12 Audit)
- Fixed (HIGH): Execution Intents cross-agent confused-deputy — all binding handlers (
list_bindings,get_binding,execute,test_binding,list_execution_events) now enforcecaller.id == agent_idownership check. Previously, an agent with Execution Intents enabled could access another agent's bindings. - Fixed (HIGH): X-Forwarded-For IP spoofing — changed from leftmost to rightmost XFF entry parsing for untrusted requests. GCP's Global Frontend appends the true client IP as the last entry; leftmost parsing was trusting attacker-controlled values.
- Fixed (MEDIUM): Platform-grant scope bypass —
authorize_platform_grantenforced ondelete_secret,get_secret_version,rotate_secret, anddisable_versionhandlers. Previously, platform grants withallowed_pathsrestrictions were not checked on these operations. - Fixed (MEDIUM): Execution events plaintext response bodies — response bodies are now truncated to 4KB, sensitive headers stripped, and sensitive patterns (API keys, tokens) redacted before persisting to
execution_events. Fieldredactions_appliedtracks sanitization. - Fixed (LOW): SSRF trailing-dot bypass —
validate_audience_url()andvalidate_redirect_uri()now strip trailing dots from hostnames before security checks (e.g.,metadata.google.internal.no longer bypasses the blocklist). - Fixed (LOW): Execution event caller misattribution —
insert_execution_eventnow usescaller.idinstead ofagent_idfrom the URL for correct audit attribution.
Intents API Chain Parity
- Improved:
resolve_chain_id()expanded from 10 to 30 chain names/aliases — all dRPC-supported networks are now resolvable by name in transaction requests. - Improved: Shroud
drpc_chain_slug()made case-insensitive for parity with Vault. - Improved: Shroud
seed_defaults()expanded to cover all 29 EVM chains with correct chain IDs, native currencies, and EIP-1559 support flags.
Infrastructure
- New:
DRPC_API_KEYenvironment variable on Vault (Cloud Run) and Shroud (GKE). Configured via Terraform (infra/variables.tf), GitHub Actions secrets, and K8s secrets. - New:
scripts/test-drpc-connectivity.sh— verifies dRPC connectivity across 22 chains viaeth_chainIdcalls. - New: dRPC connectivity test integrated into
run-production-tests.sh(auto-skipped whenDRPC_API_KEYis not set).
API v2.26.0 / SDK 0.40.0 / Vault 0.39.0 / MCP 0.40.0 — Execution Intents (2026-07-10)
Execution Intents (Pro+)
- New: Execution Intents API — agents can make HTTP calls, database queries, and external service interactions through pre-configured bindings. Credentials are stored server-side in the
__agent-keysvault and never exposed to agents. - New: Binding types: HTTP, GraphQL (Pro tier), plus Postgres, MySQL, Redis, gRPC, SMTP, Cloud SDK, S3, Custom (Team+ tier). TEE execution mode available on Business+ for enhanced security.
- New: Per-binding guardrails: host allowlists, timeouts, authentication types (bearer, basic, header, query).
- New: Full execution audit trail via
execution_eventstable with per-event cost tracking. - New: CRUD endpoints under
/v1/agents/{id}/bindings(human-only creation). Execute endpoint:POST /v1/agents/{id}/execute. Test endpoint:POST /v1/agents/{id}/bindings/{binding_id}/test. - New: Agent field
execution_intents_enabled(boolean, default false). JWT claimexecution_intents_enabledgates access; middlewarerequire_execution_intentsenforces it. - New:
execution_guardrailsJSONB on agents — per-agent execution guardrails (allowed hosts, max duration, rate limits). - New: Tier-based billing:
execution_intent(2¢ Pro → 0.5¢ Business) andexecution_intent_tee(10¢ Pro → 2.5¢ Business) per execution. Monthly limits: Pro 1K, Team 10K, Business 50K, Enterprise unlimited.
SDK/CLI/MCP/Dashboard
- SDK:
client.bindings.create(),.list(),.get(),.update(),.delete(),.test(),.execute(),.listExecutions(). - MCP: New
execute_httpandlist_bindingstools. - CLI: Execution intents support via SDK integration.
- Dashboard:
ExecutionIntentsCardon agent detail page — toggle, binding list, create/test/delete.
Migrations
129_execution_intents.sql—agent_bindingsandexecution_eventstables.
Version Bumps
- Vault API: 0.39.0
- SDK: 0.40.0
- MCP: 0.40.0
- CLI: 0.40.0
- OpenAPI: 0.40.0
API v2.25.0 / SDK 0.38.0 / Vault 0.38.0 / MCP 0.38.0 — Token guardrails, known tokens registry, per-chain guardrails (2026-07-05)
Added
- Token allowlist guardrail (
tx_token_allowlist): Controls which token contracts/mints an agent can interact with. Applied totoken_minton non-EVM chains and ERC-20 contract addresses on EVM chains. Checked case-insensitively. - Known tokens only (
tx_known_tokens_only): When enabled, restricts agents to verified tokens in the known tokens registry. Unknown token contracts/mints are rejected with 403. - XRP transaction type allowlist (
xrpl_allowed_tx_types): Controls which XRPL transaction types are allowed when usingxrpl_tx_json. Empty = all supported types. Unsupported types return 403. - Per-chain guardrails (
per_chain_guardrails): Chain-specific overrides formax_value,daily_limit,to_allowlist, andtoken_allowlist. Strictest of global and per-chain values wins. - Per-chain daily spend tracking (
tx_spent_today_by_chain):GET /v1/agents/{id}now returns per-chain daily spend in native units with correct decimals (e.g.{ "ethereum": "0.5", "solana": "2.0" }). The canonical field istx_spent_today/tx_spent_today_by_chain; the deprecatedtx_spent_today_ethalias is still returned for backward compatibility. - Known tokens registry: Public endpoints
GET /v1/tokens(filterable by?chain=) andGET /v1/chains/{chain}/tokensfor listing verified tokens. Admin endpointsPOST /v1/admin/tokensandDELETE /v1/admin/tokens/{id}for registry management. - ERC-20 server-side builder: When
token_mintis provided on EVM chains, the handler generates ERC-20transfer(to, amount)calldata server-side — agents no longer need to construct calldata manually. - Extended token balance:
GET /v1/agents/{id}/signing-keys/{chain}/balancenow accepts optional?tokens=query param (comma-separated contract addresses/mints) to include specific ERC-20/SPL/TRC-20 token balances alongside native balance. - Solana ATA auto-creation: SPL token transfers automatically create the recipient's Associated Token Account if it doesn't exist, adding a
CreateAssociatedTokenAccountinstruction before the transfer. - Cardano native asset transfers: Multi-asset output support with min-ADA enforcement.
token_mintispolicy_id.asset_namehex. - Memo support: Solana (Memo Program v2 instruction appended), XRP (Memos array in
xrpl_tx_json), Tron (extra_datafield). - UTXO locking: Concurrent Bitcoin and Cardano transactions are serialized via the
utxo_lockstable to prevent double-spending the same UTXO. Locks auto-expire after 5 minutes.
Fixed
- Daily spend unit mismatch: Per-chain daily spend now uses correct native-unit decimals instead of ETH-equivalent conversion, which could under-count spend on high-decimal chains.
- XRP guardrail bypass:
xrpl_tx_jsontransactions now enforce all agent guardrails (chains, allowlist, value caps, daily limits) — previously bypassed when using raw XRPL JSON. /signEVM persistence: Transactions submitted via the unifiedPOST /v1/agents/{id}/signendpoint withintent_type: "transaction"are now correctly persisted for audit and daily-limit tracking.
Migrations
124_agent_token_guardrails.sql—tx_token_allowlist,tx_known_tokens_only,xrpl_allowed_tx_types,per_chain_guardrailscolumns onagentstable.125_known_tokens.sql—known_tokenstable with unique index on(chain, contract_address).126_utxo_locks.sql—utxo_lockstable for concurrent UTXO transaction serialization.
SDK/CLI/Dashboard
- SDK:
CreateAgentRequest,UpdateAgentRequest, andAgentResponseinclude all new guardrail fields. Token registry types added. - CLI: New flags
--tx-token-allowlist,--tx-known-tokens-only,--xrpl-allowed-tx-types,--per-chain-guardrailsonagent createandagent update. - Dashboard: Token allowlist editor, known-tokens-only toggle, per-chain guardrails visual editor, and XRPL transaction type multi-select on agent detail page. Token registry hook (
use-token-registry.ts).
Vault 0.37.1 / Shroud 0.37.1 — Official Rust SDKs for Bitcoin & Solana signing (2026-07-04)
- Improved: Bitcoin transaction signing now uses the official
rust-bitcoincrate (v0.32) instead of hand-rolled secp256k1 + BIP-143 logic. All recipient address types are supported: P2PKH, P2SH, P2WPKH, P2WSH, and P2TR (Taproot). Key generation, address derivation, and UTXO-based transaction construction userust-bitcointypes end-to-end, eliminating custom serialization code. - Improved: Solana transaction signing now uses the official
solana-sdkcrate (v4) instead of manual Ed25519 + compact message serialization. PDA derivation usesPubkey::find_program_address(replacing the custom off-curve check withcurve25519-dalek). SPL token transfers use proper Associated Token Account derivation. Key generation, address formatting, and transaction construction are fully type-safe. - Improved: Shroud TEE signing mirrors all changes — both
vaultandshroudnow use identical SDK-backed implementations for Bitcoin and Solana. - Tests: Comprehensive unit tests added for both chains in both
vaultandshroud: key generation determinism, address derivation across networks (mainnet/testnet/signet), signing to all recipient address types, multi-UTXO inputs, dust change handling, invalid address rejection, SPL token transfers, shortvec encoding, and blockhash variation. - Verified end-to-end: Live testnet transactions confirmed on all non-EVM chains — Solana Devnet (sign-only, submit/broadcast, unified sign), Bitcoin Signet (sign-only, submit/broadcast), Tron Shasta (sign-only, submit/broadcast), and Cardano Preprod (sign-only, submit/broadcast).
- Docs: Intents API guide updated with comprehensive testnet reference table including faucet links, external API dependencies, and network-specific address format notes for all 5 non-EVM chains.
API v2.24.0 / SDK 0.37.0 / Vault 0.37.0 / MCP 0.37.0 — Broad XRPL coverage (2026-07-03)
- New: 30+ XRPL transaction types via the
xrpl_tx_jsonfield onSubmitTransactionRequest,SignTransactionRequest, andSignIntentRequest. Pass a raw XRPL transaction JSON object and the server uses thexrpl-rustbinary codec to encode and sign it.Account,Sequence,Fee,LastLedgerSequence, andSigningPubKeyare auto-filled when absent. Supported types: Payment, TrustSet, OfferCreate, OfferCancel, AccountSet, AccountDelete, EscrowCreate/Finish/Cancel, PaymentChannelCreate/Fund/Claim, NFTokenMint/Burn/CreateOffer/AcceptOffer/CancelOffer, AMMCreate/Deposit/Withdraw/Bid/Delete/Vote, SetRegularKey, SignerListSet, DepositPreauth, CheckCreate/Cash/Cancel, TicketCreate, Clawback. - New:
xrpl-rustv1.1.0 crate added to both Vault and Shroud (TEE), replacing the hand-rolled Payment-only STObject serializer. The legacyto/value/destination_tagPayment path is preserved for backward compatibility. - New: Unsupported XRPL transaction types are rejected with a descriptive error listing all supported types.
- SDK:
xrpl_tx_jsonfield added toSubmitTransactionRequest,SignTransactionRequest, andSignIntentRequestin the TypeScript SDK, Python SDK, and Go SDK. - MCP:
submit_transactionandsign_transactiontools acceptxrpl_tx_jsonparameter. - OpenAPI:
xrpl_tx_jsonfield added to all three transaction request schemas. - Tests:
test-nonevm-signing-prod.shextended with TrustSet, AccountSet, unsupported type, and unified/signOfferCreate tests.test-shroud-prod.shgains XRPxrpl_tx_jsonTrustSet dispatch test and XRP Payment dispatch test. - Dashboard: Intents page updated to highlight XRP's 30+ transaction type support.
- Examples:
examples/non-evm-keysupdated with TrustSet example viaxrpl_tx_json.
API v2.23.0 / SDK 0.36.0 / Vault 0.36.0 / MCP 0.36.0 — Non-EVM transaction signing (2026-07-03)
- New: Full on-chain transaction signing + broadcast for Bitcoin, Solana, XRP, Cardano, and Tron through the Intents API (
POST /v1/agents/{id}/transactions,POST .../transactions/sign, unifiedPOST .../signwithintent_type: "transaction"). 1Claw dispatches by chain family, auto-fetches chain data (Bitcoin UTXOs/fee via mempool.space, Solana blockhash, XRP sequence, Cardano protocol params via Blockfrost, Tron ref block via TronGrid), signs in the HSM (or Shroud TEE), and broadcasts. - New: Chain-specific optional fields on transaction requests:
destination_tag(XRP),memo,fee_rate_sat_per_vbyte(Bitcoin),fee_limit_sun(Tron TRC-20),token_mint/token_decimals(Solana SPL + Tron TRC-20),ttl(Cardano).valueis the human-readable major unit (BTC/SOL/XRP/ADA/TRX) as a decimal string. - New: Chain registry migration adds
chain_typecolumn and seeds non-EVM mainnets + testnets (bitcoin-testnet,solana-devnet,xrp-testnet,cardano-preprod,tron-shasta, etc.). - New: Shroud TEE parity — non-EVM signing inside confidential memory with the same family dispatch and guardrails as Vault API.
- Note: Tenderly
simulate_firstand/simulateendpoints remain EVM-only (no-op for non-EVM chains). - Cardano: Requires server-side Blockfrost project id (
BLOCKFROST_PROJECT_ID_PREPROD,BLOCKFROST_PROJECT_ID_MAINNET, or genericBLOCKFROST_PROJECT_ID). - Examples:
examples/non-evm-keysnow includesnpm run sign -- <chain> <to> <amount>for sign + broadcast demos. - Tests: New
scripts/test-nonevm-signing-prod.shwired intorun-production-tests.sh; Shroud prod tests assert non-EVM dispatch. - SDK:
SubmitTransactionRequest/SignTransactionRequestextended with non-EVM fields; OpenAPI spec updated.
API v2.22.0 / SDK 0.35.0 / Vault 0.35.0 — Platform resource grants (2026-07-03)
- New: Platform resource grants — users can grant platform apps access to specific vaults and agents via
POST /v1/platform/connections/{id}/grant. Grants are per-vault with configurableallowed_pathsandpermissions. List active grants viaGET .../grants, revoke individual grants viaDELETE .../grants/{grant_id}. - New: Dashboard grant page at
/connect/{slug}/grant— vault/agent picker with checkboxes for selecting resources to share with a platform app. Linked from OAuth consent and claim flows. - Enhanced: Connected Apps page (
/settings/connected-apps) rewritten — now shows vault/agent counts per app, expandable "Resource Grants" panel with per-grant details, and individual revoke buttons with confirmation dialog. - Fixed:
GET /v1/platform/connected-appsresponse key changed fromconnected_appstoappsto match the SDK and dashboard expectations. - SDK: New methods on
PlatformResource:grantAccess(connectionId, data),listGrants(connectionId),revokeGrant(connectionId, grantId).
2026-06
API v2.20.1 / SDK 0.34.3 / CLI 0.36.4 — OAuth branding + redirect URI validation (2026-06-29)
- New: Platform apps can configure a
logo_urlfor branding on OAuth login and consent pages. When a user visits the "Sign in with 1Claw" flow, the app's logo and name are shown. Set via Dashboard (Platform → app → Settings → App Branding) orPATCH /v1/platform/apps/{id}. - New: Public branding endpoint
GET /v1/platform/apps/by-slug/{slug}/branding— returns{ name, logo_url, slug }without authentication. - New: Dedicated
validate_redirect_uri()function for OAuth redirect URIs allowshttp://localhostandhttp://127.0.0.1per RFC 8252 §7.3 (native/dev clients). Cloud metadata and non-loopback private IPs remain blocked. - Dashboard: Platform app detail page has a "Redirect URIs" editor in the Settings tab. Login and consent pages show app branding (logo + name) when the OAuth
client_idquery parameter is present. - Docs: Updated Platform API guide with redirect URI management instructions and a warning that
client_idmust be the app slug (not UUID).
API v2.20.0 / SDK 0.34.2 / MCP 0.34.3 — raw digest signing + EIP-712 fixes (2026-06-26)
- New: Raw digest signing intent on
POST /v1/agents/{id}/sign—intent_type: "eip712_digest"(alias"digest") signs a client-computed 32-bytehashdirectly and returns a 65-byter‖s‖vsignature that recovers to the agent's EOA. This unblocks ERC-1271 / ERC-7739 nested EIP-712 flows (e.g. Polymarket CLOB orders) where the canonical hash is computed client-side and must match the verifier exactly, which 1Claw's owntyped_datarecomputation would otherwise diverge from. - Security: Raw digest signing is blind signing (no domain/transaction inspection, guardrails bypassed), so it is gated behind a new per-agent
raw_signing_enabledflag — off by default, only a human can enable it (agents cannot self-enable), and every use is audit-logged assigning_key.raw_digest_sign. Surfaced as a toggle (with an explicit warning) on the dashboard agent detail page. - Fixed: EIP-712
uintN/intNencoding fortyped_datanow uses arbitrary-precision integers — decimal strings that happened to be valid hex are no longer misparsed, and values larger thanu128are no longer silently encoded as zero. NegativeintNvalues use correct two's-complement. - New: Platform bootstrap templates accept
provision_eoa: trueper agent — generates a standalone secp256k1 EOA for the agent (returned asagent_evm_addressin the bootstrap summary) so platform-provisioned agents can deploy/operate ERC-4337 smart accounts client-side without a Pro+ treasury-wallet flow. - MCP: New
sign_digesttool wraps theeip712_digestintent. SDK:signIntentacceptsintent_type: "eip712_digest"+hash;AgentResponse/UpdateAgentRequestexposeraw_signing_enabled.
CLI v0.36.2 — fix cloud-mode container startup + start/restart for init --docker (2026-06-25)
- Fixed:
1claw init --docker(cloud mode) started the container but the entrypoint exited immediately withERROR: ONECLAW_AGENT_API_KEY is not set (cloud mode)and looped on restart. The container is designed never to receive the agent API key — the host daemon brokers credentials over the mounted Unix socket — so requiring the key directly was wrong for this flow. The entrypoint now detects the mounted daemon socket and brokers all credentials through it (cloud and local). A directONECLAW_AGENT_API_KEYis only required for standalone deploys with no daemon socket (e.g. Cloud Run via1claw deploy). - New:
1claw containers start <name>and1claw containers restart <name>.startresumes a stopped container; if the container was removed (statusabsent), it is recreated from the saved run spec (re-checking the host port).restartrestarts a running/stopped container or recreates an absent one. Theinitcommand now persists the container's run spec (image, env var names, mounts, labels — never secret values) to~/.config/1claw/containers/{name}.jsonto enable this. - Changed: The chat UI header no longer shows the ambiguous
mode=cloud. It now showsruntime=docker(the container is always Docker) alongsidevault=cloud|local— clarifying that "cloud/local" refers to where the agent's identity and secrets live (a 1Claw cloud account vs an offline local CLI vault), not the runtime./inforeflects the same. - Changed: Base image
org.1claw.base-versionbumped so an existing1claw/agent:stableis rebuilt with the corrected entrypoint and clarified labels automatically on the nextinit.
CLI v0.36.1 — robust port handling for init --docker (2026-06-25)
- Fixed:
1claw init --dockercould fail withBind for 0.0.0.0:3000 failed: port is already allocatedeven though the CLI's pre-check thought the port was free. The free-port check now binds0.0.0.0(matching how Docker publishes ports) instead of127.0.0.1, so ports already held by another container are correctly detected. - New: If the container still fails to start because the port is taken (a TOCTOU race, or a port held only inside the Docker VM), the CLI now automatically retries on the next free port — unless you pinned an explicit
--port, in which case it fails with actionable guidance (1claw containers list,1claw containers stop <name>,docker ps --filter publish=<port>). - Reminder: manage running agent containers with
1claw containers list | info | stop | rm | logs; manage cloud agent identities with1claw agent list | get | update | delete.
CLI v0.36.0 — chat LLM through Shroud (2026-06-25)
- New: In cloud mode, the
1claw init --dockerchat UI is now wired to an LLM through Shroud. Messages route via the host daemon, which injects theX-Shroud-Agent-Keyheader (the container never sees the agent key); Shroud applies the agent's inspection/redaction policy before forwarding to the provider. - New: Three provider-key sources, all keeping the key out of the container: 1Claw LLM Token Billing (Stripe AI Gateway — no key), 1Claw cloud vault (
--llm-api-key, default--llm-key-store cloud, stored atproviders/<provider>/api-keyand auto-fetched by Shroud), and local CLI vault BYOK (--llm-api-key --llm-key-store localor--llm-api-key-secret <name>— the daemon injectsX-Shroud-Api-Key). The provisioned agent now also gets a read policy onproviders/*so cloud-vault keys resolve. - New:
--llm-provider(defaultopenai),--llm-model(default per provider, e.g.gpt-4o-mini),--llm-api-key,--llm-key-store, and--llm-api-key-secretflags oninit --docker. The daemon/proxynow supports injecting multiple secrets into one request. - Fixed: The container chat UI reported
mode=localeven for cloud-provisioned agents —ONECLAW_LOCAL_VAULT=truewas baked into the base image. Mode is now passed at run time; cloud agents correctly reportmode=cloud.--localmode still has no LLM (no cloud agent → no Shroud credential). - Changed: The base image carries an
org.1claw.base-versionlabel;initrebuilds a stale1claw/agent:stableautomatically when bundled assets change. CLI version 0.35.1 → 0.36.0.
CLI v0.35.1 — local vault recovery (2026-06-25)
- New:
1claw local destroy --forceskips the confirmation prompt, and1claw local resetis an alias fordestroy. Neither requires the passphrase — this is the recovery path for a forgotten local-vault passphrase. Destroy now also stops any running daemon still holding the old vault and clears its stale socket/PID. - Improved:
1claw init --docker --localvalidates an existing vault's passphrase before starting the daemon and, on mismatch, fails fast with explicit recovery instructions instead of a generic daemon-startup timeout.1claw daemon startsurfaces the same recovery guidance on "wrong passphrase or corrupted vault file".
CLI v0.35.0 — containerized agent runtime (2026-06-25)
- New:
1claw init --docker— provisions a secure agent runtime inside a Docker container in one command (1Claw MCP server + chat UI on port 3000). The container never receives the agent API key; the host daemon injects credentials over a read-only Unix-socket bind mount. - New: Module system —
--module=ampersend,onchaincomposes container extensions from bundledmodule.yamlmanifests with dependency resolution, conflict detection, and topological layer ordering. Bundled modules:ampersend,onchain,langchain,elizaos,scaffold-agent.--list-modulesprints the catalog. - New:
--localflag runs fully offline (no cloud account); the base image is built from bundled assets when not already present. - New:
1claw containers list|info|stop|rm|logs— manage CLI-created agent containers (state stored in~/.config/1claw/containers/{name}.json). - New:
1claw publish— rebuild from base + modules, build from a customDockerfile, or snapshot a running container (--commit), then tag and push to a registry. - New:
1claw eject— export the generatedDockerfile, module configs, and adocker-compose.yaml(daemon socket pre-wired) for manual control. - New:
1claw deploy --google-cloud— generate Terraform (main.tf,variables.tf,outputs.tf) for Cloud Run with Secret Manager key injection;--applyrunsterraform apply. - Changed: CLI version bumped from 0.34.7 to 0.35.0. Added
yamldependency for module manifest parsing.
CLI v0.34.7 — LLM proxy, treasury proposals, unified signing (2026-06-22)
- New:
1claw proxy— local OpenAI-compatible proxy that routes LLM traffic through Shroud with full inspection, secret redaction, and optional LLM Token Billing. Auto-detects provider from model name. IDE setup snippets printed on startup. - New:
1claw treasury proposal create|list|get|sign|execute|cancel— full multisig proposal lifecycle from CLI. - New:
1claw agent sign— unified signing command for EIP-191, EIP-712, and all EIP-2718 transaction types (0–4). - New:
1claw webhook create|list|get|update|delete— manage webhook endpoints from CLI. - New:
1claw platform reissue-claim— reissue expired claim URLs without re-provisioning. - New:
1claw treasury sendand1claw treasury swap— send native/ERC-20 tokens and swap via 0x from CLI. - New:
1claw treasury balance— query native + ERC-20 token balances. - New: DPoP support —
ONECLAW_DPOP=trueenv var enables RFC 9449 proof-of-possession. Keypair persisted at~/.config/1claw/dpop-key.json. - Updated: MCP tools expanded to 37 tools (added platform_reissue_claim, platform_rotate_key, list_approvals, get_approval, request_approval, treasury_propose, treasury_sign_proposal, treasury_list_proposals, sign_digest).
- Updated: MCP auth simplified —
ONECLAW_AGENT_API_KEYalone is sufficient (agent ID and vault auto-discovered via prefix lookup). - Changed: CLI version bumped from 0.34.2 to 0.34.7. SDK 0.34.1. MCP 0.34.1.
Local Vault & Daemon (v0.34.2 — 2026-06-22)
Local encrypted vault:
1claw local init— create an AES-256-GCM encrypted vault with passphrase-derived key (PBKDF2, 100k iterations)1claw local add/get/rm/list/status/destroy— full secret lifecycle without cloud connectivity1claw local import <file>— import from.envfiles into the local vault1claw local export— export as.envformat1claw local sync— push local secrets to cloud vault;--pullto pull from cloud- File permissions hardened to 0600; safe to back up (encrypted at rest)
Local daemon & secret proxy:
1claw daemon start— starts a Unix socket daemon that holds decrypted secrets in memory1claw daemon policy add <secret> --hosts <hosts>— per-secret host allowlist (fail-closed: no policy = no injection)1claw daemon policy list/remove— manage policies- Secret proxy:
POST /proxyon the daemon socket injects secrets into HTTP requests per policy rules — the AI model never sees the raw secret value 1claw daemon status/stop— lifecycle management
MCP local mode:
1claw setup --local— configures AI clients to use the daemon instead of the cloud API- MCP server (
ONECLAW_LOCAL_VAULT=true) connects to daemon over Unix socket proxy_requestMCP tool: AI model specifies secret name + URL, daemon injects credential per policylist_secretstool shows secret names (never values) from the local vault
CLI DX & Homebrew (v0.34.1 — 2026-06-22)
New CLI commands:
1claw setup— auto-detect and configure AI clients (Claude Desktop, Cursor, VS Code, Zed, Windsurf, Claude Code) to use the 1Claw MCP server for runtime secret access1claw import <file>— parse.envfiles and import secrets into a vault (supports--prefix,--dry-run,--force)env cache/env cache-clear/env cache-status— encrypted local secret cache for offlineenv run(AES-256-GCM,~/.config/1claw/env-cache.enc)env run --no-cache— bypass local cache and always fetch from API
Homebrew tap:
brew install 1clawAI/tap/oneclaw— install CLI via Homebrewbrew install 1clawAI/tap/1claw-mcp— install MCP server via Homebrew- Automated formula updates on npm publish via
repository_dispatch
Version alignment:
- CLI bumped to 0.34.7 (latest)
- SDK at 0.34.1
- MCP at 0.34.1
- OpenAPI spec info.version bumped to 2.19.0
Security Hardening (v0.34.1 — 2026-06-21)
Fixed
- H-1/H-2 (HIGH):
create_sharenow enforces vault-binding, scope access, and policy-engine read permission checks before sharing. Cross-org share recipients are validated to prevent cross-tenant secret egress. - H-3 (HIGH): Treasury wallet swap path now enforces full spend policy (per-tx cap, daily limits, denylist, 10,000-ETH sanity cap) and records swaps to the daily send ledger.
- H1-R (HIGH): CAE (Continuous Access Evaluation) now properly revokes agent tokens on critical risk verdicts via
revoke_all_for_agent, ensuring stolen agent JWTs are actually rejected by auth middleware. - L-4: Single
delete_agentendpoint now enforcesplatform_lockedguard (parity with batch-delete). - L-5: Batch-delete hardening — sanitized error messages (no raw DB errors), collapsed not-found/access-denied responses to prevent cross-tenant existence oracle.
- L-1/L-2: Nightly cleanup job now sweeps expired
revoked_tokens,agent_active_tokens, anddpop_noncestables to prevent unbounded growth.
Risk Engine + DPoP Token Binding (v0.34.0 — 2026-06-11)
Added
- Risk Engine Phase 1: Geo-velocity (impossible travel detection), first-seen ASN/country drift, honeytoken canary secrets
- Risk Engine Phase 2: DPoP token binding (RFC 9449), Continuous Access Evaluation (auto-revoke on critical)
- Dashboard:
/securitypage with risk events feed and severity filtering - Dashboard:
/security/honeytokenspage for canary secret management - Dashboard: DPoP enforcement toggle in Security settings (off/warn/required)
- SDK:
client.riskresource for risk events, verdicts, and honeytokens - SDK/MCP/CLI:
DPoPManagerfor proof-of-possession token binding - API:
GET/POST/DELETE /v1/risk/honeytokens,GET /v1/risk/events,GET /v1/risk/verdicts - MaxMind GeoLite2 IP enrichment (City + ASN) for risk scoring
- Auth verdict gate: blocks login/token-exchange on high/critical risk score
- Honeytoken detection: silent critical verdict on canary secret read
Security
- Stolen JWTs are now non-replayable when DPoP is enabled (bound to client keypair)
- Critical risk verdicts immediately revoke all active sessions for the principal
- Impossible travel detection catches session replay from different geography
- ASN/country baseline drift flags credential stuffing from unfamiliar sources
Migrations
118_risk_engine_phase1.sql— risk_events, risk_verdicts, principal_baselines, honeytokens119_dpop_and_cae.sql— jwt_bound_keys, dpop_nonces
Embedded Wallets: Email OTP, OAuth2, Spend Policies (v0.33.0)
- New: Email OTP login — Passwordless authentication for embedded wallet end-users via 6-digit email codes.
POST /v1/auth/email-otp/send(rate-limited, 5-min expiry) andPOST /v1/auth/email-otp/verify(returns JWT + auto-provisions treasury wallets on first login). Migration 113. - New: Sign in with 1Claw — Full OAuth2 authorization code flow with PKCE; 1Claw acts as an OIDC provider for third-party apps. Endpoints:
POST /v1/oauth/authorize(code grant),POST /v1/oauth/token(code exchange),GET /v1/oauth/userinfo. Dashboard consent page at/oauth/authorize. OIDC discovery updated to advertiseauthorization_endpoint,userinfo_endpoint, and PKCE (S256). Platform apps configureredirect_urisfor OAuth client registration. Migration 114. - New: Wallet spend policies — Per-app default and per-user override policies for treasury wallet sends and swaps. Controls: recipient
to_allowlist,max_value_ethper-tx cap,daily_limit_eth,allowed_chains. Endpoints:POST/GET/PATCH/DELETE /v1/platform/apps/{app_id}/spend-policies. Enforced server-side before signing treasury wallet transactions. Migration 115. - New: Embedded Wallets marketing page — Landing page at
/embedded-walletsshowcasing the platform for developers (feature grid, code snippets, integration steps). - New: OAuth consent page — User consent UI at
/oauth/authorizefor third-party app authorization with scope display and approve/deny. - SDK: Added
sendEmailOtp(),verifyEmailOtp(),exchangeOAuthCode(), spend policy CRUD methods (createSpendPolicy,listSpendPolicies,updateSpendPolicy,deleteSpendPolicy). - wallet-react: Added
sendEmailOtp()andverifyEmailOtp()methods for passwordless login in the React widget. - OpenAPI spec: Documented all new endpoints (email OTP, OAuth2 authorization/token/userinfo, spend policies).
- Docs: 2-minute embedded wallets quickstart guide at
docs/guides/embedded-wallets-quickstart. - Changed: OIDC discovery (
/.well-known/openid-configuration) now advertisesauthorization_endpoint,userinfo_endpoint, and PKCE support (code_challenge_methods_supported: ["S256"]).
Bankr Dynamic Key Vending (Secret Engine)
- New: First-class "dynamic secrets" engine for Bankr. Store a long-lived partner key (
bk_ptr_) in the secure zone; programmatically issue/revoke short-livedbk_usr_wallet API keys for agents — scoped, TTL-bound, and automatically cleaned up. - Endpoints:
POST /v1/agents/{id}/bankr-keys/lease,GET /v1/agents/{id}/bankr-keys,DELETE /v1/agents/{id}/bankr-keys/{lease_id}. - Lifecycle: Leases auto-revoke on agent deletion/deactivation. Nightly sweep cleans expired leases via Bankr DELETE.
- Shroud integration: When
X-Shroud-Provider: bankr, Shroud auto-resolves the latest leased key for the agent. Falls back to staticproviders/bankr/api-key. - SDK:
client.agents.leaseBankrKey(),.listBankrKeys(),.revokeBankrKey(). - MCP:
lease_bankr_keytool. - CLI:
1claw agent bankr-key lease|list|revoke. - Dashboard: Bankr Keys card on agent detail page (lease, list, revoke inline).
- Config:
BANKR_PARTNER_KEY,BANKR_DEFAULT_WALLET_ID,BANKR_DEFAULT_LEASE_TTL_SECS. - Security (v0.32.2): Leasing is deny-by-default — agents require explicit policy on
agents/{id}/bankr/*. Agent lease responses and MCPlease_bankr_keyoutput omitbk_usr_keys (Shroud resolves server-side). Agent default TTL 15 min; recommend 5–15 min with revoke-after-task.
Shroud: Bankr LLM Gateway upstream
- New: Shroud provider
bankr— route agent LLM traffic through Bankr LLM Gateway (https://llm.bankr.bot) withX-Shroud-Provider: bankr. Storebk_keys atproviders/bankr/api-key. Empty model allowlist (Bankr catalog is authoritative). - Docs: Shroud supported models, Shroud guide, Ecosystem.
Security audit fixes — social login, treasury, webhooks, internal ledger (v0.24.1, SDK/OpenAPI 0.31.0)
- Fixed (CRITICAL): Social login Google/Apple tokens now validate OAuth audience and issuer (shared
oauth_tokensmodule). Discord uses server-side authorization code exchange withoauth_redirect_uri(no raw access tokens in production). - Fixed (CRITICAL): Removed email-based auto-linking on social login — existing email returns 409; users must sign in with their existing method first.
- Fixed (HIGH): Internal transfers require account ownership (
from_account.user_id == caller.id). - Fixed (HIGH): Internal transfers support
Idempotency-Keyreplay protection (migration 110). - Fixed (HIGH): Fiat webhooks in production require verified MoonPay signature (unsigned JSON rejected).
- Fixed (HIGH): Agents cannot supply client
users/...signing paths; treasurymode=treasuryonly. - Fixed (HIGH): Webhook
PATCHURL updates run SSRF validation (validate_audience_url). - Fixed (HIGH): Passkey
tx-assert/completevalidates origin; sign-count clone detection; optional tx_digest binding viaX-Passkey-Tx-Digest. - Fixed (MEDIUM): Treasury send sanity cap (10k ETH); proposal
signer_addressmust match registered signer;auto_credit_account_idownership check; internal transfer asset allowlist; ledgertotalis real count. - Changed: Vault 0.24.1.
@1claw/sdk,@1claw/cli,@1claw/mcp,@1claw/openapi-spec0.31.0 (OpenAPI 2.17.0).
CDP parity Phases 2–4: deposits, fiat ramps, social login, internal ledger, embedded wallet (v0.24.0)
- New: Deposit destinations —
POST/GET/PATCH /v1/deposit-destinationsfor unique inbound payment addresses per chain.deposit_destinationsanddeposit_eventstables (migration 106). Webhook eventdeposit_destination.created. - New: Fiat on/off ramps —
POST /v1/fiat/onramp/session(Coinbase Onramp or MoonPay widget URL),POST /v1/fiat/offramp/initiate,POST /v1/fiat/webhooks(partner completion). Config:COINBASE_ONRAMP_APP_ID,MOONPAY_API_KEY,MOONPAY_SECRET_KEY. - New: Social login —
POST /v1/auth/social-login(public) accepts Google/Apple/Discordid_token, verifies JWKS, upserts user, auto-provisions Ethereum treasury wallet on signup. Migration 108 (users.social_provider,users.social_subject). - New: Passkey transaction authorization —
POST /v1/auth/passkeys/tx-assert/beginand.../completereturn a short-livedpasskey_tokenusable asX-Passkey-Tokenon treasury send (alternative toX-Auth-Confirmpassword). - New: Internal accounts & ledger —
POST/GET /v1/internal-accounts,POST /v1/internal-transfers,GET /v1/internal-accounts/{id}/ledger. Double-entry bookkeeping withSELECT FOR UPDATEbalance checks (migration 107). Webhookinternal_transfer.completed. - New:
@1claw/wallet-reactv0.2.0 —<OneclawEmbeddedWallet />with social login UI, Send/Swap/Receive/Buy views, passkey and fiat client methods. - New: SDK resources —
client.depositDestinations,client.internalAccounts,client.fiat. - New: Dashboard hooks —
use-deposit-destinations,use-internal-accounts,use-fiat. - Changed: Vault version bumped to 0.24.0. SDK/CLI/OpenAPI spec bumped to 0.30.0.
CDP parity Phase 1: live webhooks, gasless treasury sends, wallet-react swap (v0.23.0)
- New: Webhook delivery wired end-to-end —
dispatch_event()calls in treasury_wallets, policies, signing_keys, transactions, and treasury_proposals handlers. Background workerprocess_pending_deliveriesruns every 5s. Events:wallet.transfer.sent,wallet.transfer.received,proposal.created/signed/executed/cancelled,agent.transaction.broadcast/signed,signing_key.rotated,policy.created/updated/deleted. - New: Gasless treasury wallet sends —
POST /v1/treasury/wallets/{chain}/sendacceptsgasless: trueto wrap the send as an ERC-4337 UserOperation with Pimlico paymaster sponsorship. Response includesuser_op_hash. RequiresPIMLICO_API_KEY. - New:
@1claw/wallet-reactv0.1.0 — addedswap()client method,SwapParams/SwapResulttypes, swap exposed in context.<OneclawTreasuryWidget />rebuilt with three views: Send, Swap, and Receive. - New: Dashboard treasury
WalletChainCard— inline balance with 30s auto-refresh, Send dialog (with gasless option), Swap dialog per chain. New hooks:useTreasuryWalletBalance,useSendFromWallet,useSwapFromWallet. - Changed: Vault version bumped to 0.23.0.
2026-05
Security audit fixes (v0.22.1, 2026-05-30)
- Fixed (CRITICAL): Treasury signing authorization bypass — agents signing via Intents API in
mode: "treasury"now require an activetreasury_delegationsentry withmodeset todelegatedorboth. Previously, any agent with Intents API enabled could sign using treasury wallet keys without delegation verification. - Fixed (H1): Delegation guardrails enforcement — per-delegation
guardrailsJSONB fields (to_allowlist,max_value_eth,allowed_chains) are now enforced during treasury-mode signing in the Intents API. Previously, delegation guardrails were stored but not checked, allowing agents to bypass spend caps and address restrictions on delegated treasury transactions. - Fixed (H2): Webhook SSRF protection — webhook delivery dispatcher now validates destination URLs via
validate_audience_url()(blocks private CIDRs, cloud metadata,.internalhosts, localhost) and disables HTTP redirect following to prevent SSRF via registered webhook endpoints. - Fixed (H3): Account lockout on treasury send/swap — failed password re-authentication on
POST /v1/treasury/wallets/{chain}/sendandPOST /v1/treasury/wallets/{chain}/swapnow incrementsfailed_login_attemptsand triggers account lockout at 10 failures (matches existing behavior on export). Previously, send/swap brute-force did not trigger lockout. - Fixed (M1): Treasury proposal
sign_proposalauthorization —POST /v1/treasury/{id}/proposals/{pid}/signnow verifies the caller is either a treasury signer or the proposal creator. Previously, any org member could submit signatures. - Fixed (M2): Delegation mode filter for Intents API — only delegations with
modeset todelegatedorbothare accepted for direct signing viaPOST /v1/agents/{id}/transactionswithtreasury_id. Owner-mode-only delegations are rejected (they must propose via the multisig pipeline). - Changed:
@1claw/wallet-reactconverted to a public git submodule (github.com/1clawAI/wallet-react, MIT license). - Changed: Vault version bumped to 0.22.1.
Treasury wallet operations, webhooks, and gasless transactions (v0.22.0)
- New:
GET /v1/treasury/wallets/{chain}/balance— query native token and ERC-20 token balances for a treasury wallet via RPC. Accepts optional?tokens=0x...query param for ERC-20 addresses. - New:
POST /v1/treasury/wallets/{chain}/send— send native token or ERC-20 transfers from a treasury wallet. Human-only, requires password re-authentication viaX-Auth-Confirmheader. Audit-logged astreasury_wallet.send. - New:
POST /v1/treasury/wallets/{chain}/swap— DEX token swaps via 0x aggregator. Human-only withX-Auth-Confirmre-auth. Returns transaction hash and swap details. RequiresZERO_X_API_KEYenv var. - New: Webhook system — register HTTP endpoints to receive real-time event notifications. Full CRUD:
POST /v1/webhooks(create, returns signing secret),GET /v1/webhooks(list),GET /v1/webhooks/{id}(get),PATCH /v1/webhooks/{id}(update),DELETE /v1/webhooks/{id}(delete). 12 event types:secret.created,secret.updated,secret.deleted,secret.accessed,agent.created,agent.deleted,policy.created,policy.updated,policy.deleted,transaction.submitted,transaction.signed,share.created. Deliveries use HMAC-SHA256 signatures (X-1Claw-Signatureheader) with 5 retries and exponential backoff. Database migration 105. - New:
GET /v1/agents/{id}/signing-keys/{chain}/balance— agents can query the native token balance of their signing key address. - New:
gasless: trueflag onPOST /v1/agents/{id}/transactions— enables gas sponsorship via Pimlico paymaster for ERC-4337 smart account transactions. When set, the handler requests sponsorship before signing the UserOperation. - New:
@1claw/wallet-react— embeddable React component package for Platform API apps. Components:<OneclawWalletProvider>,<OneclawTreasuryWidget>. Hooks:useOneclawWallet(). Supports wallet listing, balance display, and send operations. - New:
crypto/dex.rsmodule — 0x DEX aggregator client for swap quotes. - New:
domain/webhook_dispatcher.rs— background webhook delivery with retry logic. - Changed: Vault version bumped to 0.22.0. SDK/CLI/MCP/OpenAPI all bumped to 0.28.0.
API key expiration and platform key rotation (v0.21.2)
- New: All three API key types (
1ck_human,ocv_agent,plt_platform) now support optional expiration viaapi_key_expires_at. Expired keys are rejected at authentication time with 401. - New:
POST /v1/platform/apps/{id}/rotate-key— rotate a platform app's API key with an optional new expiration date. Returns the newplt_key (one-time). - New: Agent create/update accepts
api_key_expires_at(ISO 8601 datetime). Enforced duringPOST /v1/auth/agent-tokenexchange. - New: Platform app create/update accepts
api_key_expires_at. Enforced in auth middleware forplt_Bearer tokens. - New: Dashboard UI —
KeyExpiryPickercomponent on agent create, platform app create, and API keys settings. Agent cards show expiry badges. Platform detail shows key expiration. - New: CLI flags —
--api-key-expires-atonagent create,agent update,platform create,platform update. Newplatform rotate-key <appId>command. - New: MCP tool —
platform_rotate_keywith optionalapi_key_expires_at. - New: Database migration 098 (
agents.api_key_expires_at,platform_apps.api_key_expires_at,platform_apps.api_key_rotated_at). - New:
POST /v1/platform/connections/{id}/reissue-claim— reissue an expired claim URL for an existing connection without re-provisioning resources. - Changed: OpenAPI spec v2.15.0. SDK/CLI/MCP all bumped to 0.27.0.
WebAuthn passkeys, email change, and agent approvals (v0.21.1)
- New: WebAuthn/FIDO2 passkey authentication — passwordless login and passkey management. Server-side P-256 ECDSA verification (
p256crate) with CBOR attestation parsing (ciboriumcrate). - New: Passkey endpoints (public):
POST /v1/auth/passkeys/assert/begin(start login),POST /v1/auth/passkeys/assert/complete(complete login → JWT). - New: Passkey endpoints (authenticated):
POST /v1/auth/passkeys/register/begin,POST /v1/auth/passkeys/register/complete,GET /v1/auth/passkeys(list),DELETE /v1/auth/passkeys/{id}(delete). - New: Dashboard login page "Sign in with passkey" button. Settings → Security page has passkey management (register, list, delete).
- New:
POST /v1/auth/set-password— allows platform-provisioned users (OIDC/Google, no existing password) to set their first password. Enables email/password login alongside existing auth methods. - New: Email change flow —
POST /v1/auth/change-email(sends 6-digit verification code to new email),POST /v1/auth/verify-email-change(completes change). One pending request per user, 15-minute expiry. Dashboard: Account settings email change dialog. - New:
POST /v1/approvals/request— agent-initiated approval requests for policy changes. Directed to the agent's creator (human). Dashboard approval inbox at/approvalsand detail at/approvals/[id]. - New: Auto-execution of approved policy changes — when
POST /v1/approvals/{id}/decideapproves apolicy_changeaction, the policy described in the approvalsummaryis automatically created/updated. - New: Database migration 097 (
email_change_requeststable). - New: Dashboard hooks:
use-approvals.ts(useApprovals, useApproval, useDecideApproval),use-passkeys.ts(usePasskeys, usePasskeySignIn, useRegisterPasskey, useDeletePasskey). - New:
lib/passkeys.ts— WebAuthn browser helpers (base64url encode/decode, credential creation/request options builders, attestation/assertion serialization).
Mobile companion app & approval queue (v0.21.0)
- New: Mobile companion app for iOS and Android (Expo/React Native, beta). Passkey authentication, biometric unlock, and push notifications.
- New: Device registration API —
POST/GET/DELETE /v1/auth/devicesfor mobile device lifecycle, step-up challenge (POST .../challenge), WebAuthn attestation (POST .../attest), and push token registration (POST .../push-token). - New: Approval queue —
GET /v1/approvals(list with status filter),GET /v1/approvals/:id(details),POST /v1/approvals/:id/decide(approve/reject). Risk-tiered step-up authentication: routine actions require biometrics, critical/irreversible actions require passkey attestation. - New: CLI commands —
1claw device list,1claw device revoke,1claw approval list,1claw approval get,1claw approval decide. - New: MCP tools —
list_approvals,get_approvalfor agent visibility into pending approvals. - New: SDK resources —
client.devices(list, revoke),client.approvals(list, get, decide),client.passkeys. - New: OpenAPI spec v2.14.0 — 6 device endpoints, 3 approval endpoints, 11 new schemas, Approvals tag.
- New: Database migrations (092–096):
user_devices,device_challenges,step_up_tokens,user_passkeys,approvalstables. - Changed: Vault version bumped from 0.20.2 to 0.21.0. CLI 0.23.0. MCP 0.24.0. SDK types regenerated.
Security hardening round 3 (v0.20.2, 2026-05-14)
- Fixed (H-NEW-OIDC-SSRF): SSRF via Platform App
oidc_jwks_url—validate_audience_url()wired into platform app create/update and insideresolve_oidc_subject()defense-in-depth. Prevents attacker-controlled JWKS URLs from reaching internal services. - Fixed (H-NEW-DEK-REWRAP-RACE): Nightly DEK re-wrap race condition — added optimistic concurrency guard
WHERE wrapped_dek = $oldto UPDATE; skips onrows_affected == 0to prevent races between concurrent re-wrap and secret-write operations. - Fixed (M-NEW-IPV6-MAPPED): IPv4-mapped IPv6 bypass —
is_private_or_reserved()now checksto_ipv4_mapped(), ULAfc00::/7, and link-localfe80::/10to prevent IPv6 representation bypasses of private CIDR blocklists in audience/URL validation. - Fixed (M-NEW-BUNDLER-OPEN): Bundler proxy unauthenticated —
/api/bundlerroute now requires session cookie + per-IP rate limiting (20/min). - Fixed (M-NEW-DEMO-UNAUTH): Demo vault/intents routes unauthenticated —
/api/demo/vaultand/api/demo/intentsnow require session cookie + per-IP rate limiting (10/min). - Fixed (M-NEW-EXPORT-NO-LOCKOUT): Treasury wallet export no lockout — failed re-auth password now increments
failed_login_attempts, triggers account lockout at 10 failures; successful re-auth resets the counter. - Fixed (M-NEW-SIGNKEY-AGENT-UUID): Signing key path UUID binding —
validate_signing_key_pathnow takescaller_agent_idand enforces UUID match onagents/{uuid}/paths, preventing cross-agent key path traversal. - Fixed (M-NEW-PLT-AUD-DISABLED): Platform audience not enforced —
oidc_audiencecolumn added toplatform_apps(migration 089). When set, enforced during JWT validation inresolve_oidc_subject(). - Fixed (L-NEW-FORWARDED-FOR): All demo/bundler routes now use
x-vercel-forwarded-forinstead ofx-forwarded-forfor reliable IP extraction on Vercel. - Fixed (L-NEW-DEMO-AUTH-WEAK): Accepted risk — any non-empty session cookie passes auth check on demo routes, but combined with rate limiting this is acceptable for demo functionality.
- Changed: Vault version bumped from 0.20.1 to 0.20.2.
Platform API (v0.20.0)
- New: Platform API for developers building applications on top of 1Claw. Platform apps can provision users, vaults, agents, and policies on behalf of their end-users.
- New:
plt_prefixed API keys for platform app authentication. Resolved by auth middleware toCallerIdentitywithprincipal_type: "platform". - New: Bootstrap templates — declarative JSON specs that scaffold vault + agent + policies in a single API call (
POST /v1/platform/connections/{id}/bootstrap). - New: OIDC user provisioning —
POST /v1/platform/users/upsertaccepts asubject_token(JWT verified against the platform app's JWKS) or email to create-or-find end-users. - New: Connected apps management — end-users can view and disconnect platform apps via
GET/DELETE /v1/platform/connected-apps. - New: Claim tokens (
ct_prefix) — one-time 10-minute tokens for end-users to claim bootstrapped resources. - New:
platform_lockedflag on vaults and agents — prevents platform operators from accessing end-user secret values (custody guarantee). - New: Three billing models:
platform_pays(default),user_pays,hybrid. Per-resource payer override viavaults.billed_to_typeandbilled_to_id. - New: Three auth modes:
silent(no user interaction),user_signin(user must sign in),configurable(per-connection). - New: Database tables:
platform_apps,platform_templates,platform_user_connections,platform_user_grants,platform_claim_tokens(migrations 081–085). New columns onvaults,agents,access_policies,users,usage_events(migration 086). - New: Dashboard pages at
/platform— app management, template editor, connected users, bootstrap flow. - New: SDK —
client.platform.createApp(),.upsertUser(),.bootstrapUser(),.listConnectedApps(). - New: Platform audit events (
platform.*actions) with dedicated query endpoint.
Security hardening round 2 (2026-05)
- New: Nonce-based Content Security Policy (CSP) — dashboard uses per-request nonces instead of
'unsafe-inline'for script tags. - New: DEK re-wrap nightly job — automatically re-wraps data encryption keys using the latest KEK version, ensuring old key versions can be safely destroyed.
- Improved: OIDC federation audience URL validation now blocks cloud metadata endpoints (169.254.x.x, link-local) and private CIDR ranges.
- Improved: CORS explicit header allowlist — only documented request headers are accepted; unknown custom headers are rejected.
- Improved: MCP secret cache TTL and rate limiting — secrets fetched via the MCP server are no longer persisted beyond the session; rate limits added to prevent abuse.
- Improved: x402 payment proof cleanup — expired proofs are purged during the nightly credit expiry job.
- Improved: HTTP timeouts on all outbound RPC clients (KMS, Tenderly, chain RPC) to prevent hung connections.
- Improved: Demo Shroud endpoint rate limiting — prevents abuse of the public demo page.
- Improved: Platform handler audit events now include
request_idfor full request tracing. - Fixed: Platform
upsert_usernow enforces org match — prevents cross-org user binding. - Changed: KEK rotation period updated from 90 days to 365 days (NIST SP 800-57). Nightly KMS cleanup job destroys old key versions (keeps 2 most recent).
- Changed: MCP exfiltration protection default changed from
warntoblock.
Signing key auto-resolution and chain mapping (v0.19.2)
- Improved: Default
signing_key_pathnow auto-resolves: if the agent has a per-chain signing key provisioned (viaPOST /v1/agents/:id/signing-keys), the handler usesagents/{id}/chains/{chain}/private_key; otherwise falls back tokeys/{chain}-signer. - Improved: Network names (e.g.
sepolia,base,arbitrum) now map to canonical signing key chains (e.g.ethereum) viasigning_key_chain_for(), so agents only need one Ethereum signing key regardless of which EVM network they transact on. - Improved:
validate_signing_key_pathnow also allowsagents/{id}/chains/*paths (previously restricted tokeys/*,wallets/*,agents/{id}/keys/*). - Improved: Shroud default signing key path is now chain-aware (dynamically resolved to
keys/{chain}-signerinstead of hardcodedkeys/default-signer).
Native multi-chain treasury wallets (v0.19)
- New: HSM-backed treasury wallet generation for human users across 6 chains: Ethereum (secp256k1), Bitcoin (secp256k1), Solana (Ed25519), XRP (Ed25519), Cardano (Ed25519), Tron (secp256k1).
- New:
POST /v1/treasury/wallets/generate— generate wallets for specified chains (or all supported chains). Private keys stored in per-org__treasury-keysvault with auto-configured MPC custody. - New:
GET /v1/treasury/wallets— list all active wallets for the calling user. - New:
GET /v1/treasury/wallets/{chain}— get wallet for a specific chain. - New:
POST /v1/treasury/wallets/{chain}/export— export private key (audit-logged). - New:
POST /v1/treasury/wallets/{chain}/rotate— rotate wallet keypair. - New:
DELETE /v1/treasury/wallets/{chain}— deactivate wallet. - New: MPC custody auto-configured per billing tier: XOR 2-of-2 for Pro/Team, Shamir 2-of-3 multi-HSM for Business/Enterprise.
- New: Dashboard wizard UI with QR codes for public addresses and key export.
- New: SDK —
client.treasury.generateWallets(),.listWallets(),.getWallet(),.exportWallet(),.rotateWallet(),.deactivateWallet(). - New: CLI —
1claw treasury generate,list,get,export,rotate,deactivate. - Changed: Treasury page no longer requires beta access — requires Pro+ subscription.
- Removed: Coinbase CDP embedded wallets replaced by native wallet generation.
Multi-chain signing keys (v0.18)
- New: Per-agent, per-chain signing keys for 6 blockchains: Ethereum (secp256k1), Bitcoin (secp256k1), Solana (Ed25519), XRP (Ed25519), Cardano (Ed25519), Tron (secp256k1).
- New:
POST /v1/agents/{id}/signing-keys— provision an HSM-backed key for a chain. Returns public key and derived address. Private key stored in__agent-keysvault. - New:
POST /v1/agents/{id}/signing-keys/{chain}/rotate— rotate a chain's key (deactivates old version, creates new). - New:
DELETE /v1/agents/{id}/signing-keys/{chain}— deactivate a chain's key. - New: Crypto modules —
bitcoin.rs(secp256k1, P2WPKH bech32),solana.rs(Ed25519, Base58),xrp.rs(Ed25519, Base58Check),cardano.rs(Ed25519, bech32 enterprise),tron.rs(secp256k1, Base58Check). - New: Dashboard — "Signing Keys" card on agent detail page with public keys, addresses, key version, and "Add Key" dialog.
- New: SDK —
client.signingKeys.create(),.list(),.rotate(),.deactivate(). - New: CLI —
1claw agent signing-keys list,create --chain,rotate,delete. - New: MCP tools —
provision_signing_key,list_signing_keys.
Extended signing intents (v0.18)
- New: Unified
POST /v1/agents/{id}/signendpoint supporting three intent types:personal_sign(EIP-191): Sign arbitrary messages. Requiresmessage_signing_enabledon agent.typed_data(EIP-712): Sign structured typed data (e.g. ERC-20 Permit). Enforces domain allowlist and deny-by-default for dangerous types (Permit, Permit2, etc.).transaction: All EIP-2718 types — legacy (type 0), EIP-2930 access list (type 1), EIP-1559 (type 2), EIP-4844 blob (type 3), EIP-7702 (type 4).
- New: Agent guardrail fields —
message_signing_enabled(boolean),eip712_default_policy("deny"/"allow"),eip712_domain_allowlist(JSON array),signing_chains(text array). - New: SDK —
client.agents.sign(agentId, { intent_type, chain, ... }). - New: CLI —
1claw agent sign. - New: MCP tools —
sign_message(EIP-191),sign_typed_data(EIP-712). - New: Multi-chain keys example, EVM signing example, Agentic TX example, Non-EVM keys example.
Scaling & performance (v0.17)
- New: DEK cache — 60s TTL, 1000-entry DashMap, cuts KMS unwrap calls ~80%.
- New: Usage metering batching — in-memory buffer, batch INSERT every 5s/100 events.
- New: Distributed rate limiting — two-layer: in-memory L1 + optional Redis L2.
- New: Shroud nonce manager — DB-backed via Vault's
POST /v1/admin/nonces/reserve. - New: Cron job leader election via
pg_try_advisory_lock. - New: Quota header caching — DashMap 30s TTL per org.
- New: Manifest endpoint ETag/304 +
?since=incremental query. - New: Daily spend partial composite index on
transactionstable.
2026-04
Agent self-enrollment: link-only and approval_url
- Updated:
POST /v1/agents/enroll—human_emailis optional. With email, a pending enrollment is created and Allow/Deny links are sent; the JSON response may includeapproval_urlas a fallback if email is delayed. Name only creates a link-only pending enrollment; the response includesapproval_urlfor the human to open while signed in to approve into their org. - Updated: Database migration allows nullable org/user/email on
pending_agent_enrollmentsfor link-only rows; global cap on link-only pendings viaONECLAW_MAX_LINK_ONLY_PENDING_ENROLLMENTS(default 100). - Updated: CLI
agent enroll—--emailis optional; printsapproval_urlwhen returned. - Docs: Quickstart for agents, Agent self-onboarding, Give an agent access, OpenClaw.
MPC Secret Storage
- New: Multi-Party Computation (MPC) secret storage — split secret DEKs across multiple HSM providers so no single provider holds the complete key. Three custody modes:
2of2_client_custody(XOR split, client holds one share),2of3_multi_hsm(Shamir 2-of-3 across GCP KMS + AWS KMS + Azure Key Vault, fully server-side),2of3_client_custody(Shamir 2-of-3 with client share). - New:
POST /v1/vaults/{id}/mpc— enable MPC on a vault (user-only, Business/Enterprise tiers). - New:
client_sharereturned inSecretCreatedResponsefor client custody modes. Must be stored securely — only returned once. Required viaX-Client-Shareheader on read. - New: Crypto modules —
mpc_provider.rs(orchestrates split/reconstruct),shamir.rs(Shamir secret sharing over GF(256)),xor_split.rs(XOR 2-of-2),hsm_aws.rs(AWS KMS CryptoProvider),hsm_azure.rs(Azure Key Vault CryptoProvider). - New: Database tables
vault_mpc_keksandsecret_dek_shares(migration 063). - New: MPC guide in documentation.
GDPR Data Export
- New:
POST /v1/auth/export-data— authenticated endpoint that returns a JSON archive of the calling user's personal data (profile, org membership, vaults, agents, policies, audit events, shares, billing). For GDPR data portability compliance. - Updated:
DELETE /v1/auth/mealready handles account deletion with cascade cleanup (right-to-erasure). - Updated: Compliance documentation now covers GDPR support.
Security hardening (2026-04-15)
- New: Agent token auto-revocation on policy changes — when an access policy targeting an agent is created, updated, or deleted, all of that agent's active JWTs are automatically revoked via the
agent_active_tokenstable (migration 066). The agent must re-exchange credentials to get a fresh token with updated scopes. Eliminates stale-scope window. - New: KMS key rotation — GCP KMS vault KEKs are now created with a 90-day automatic rotation schedule and
next_rotation_time. Existing ciphertext remains decryptable (KMS retains all versions). - New: KMS CRC32C verification — all
wrap_dek,unwrap_dek, andsignKMS operations now send CRC32C of input data and verify response CRC32C. Detects in-transit corruption or tampering. Addedcrc32candprost-typescrates. - New: Audit insert hardening — migration 067 creates a restricted
vault_appdatabase role (noBYPASSRLS) and aSECURITY DEFINERfunctioninsert_audit_event. DirectINSERTonaudit_eventsis revoked fromvault_app, preventing log fabrication from compromised connections. - Fixed: Shroud user-supplied
blocked_patternscompiled viaRegexBuilderwith 256KiB size limit (ReDoS protection). - Fixed: x402 facilitator verify now passes actual atomic USDC amounts. Settlement moved before broadcast in
submit_transaction.
2026-03
Live demo
- New: Interactive demo page at 1claw.co/demo — three panels (Vault secret retrieval, Shroud prompt injection + secret redaction, Intents TEE transaction signing) with preset buttons, no signup required.
Onboarding wizard improvements
- Updated: Agent wizard is now 4 steps: register → save credentials → grant vault access (creates read policy) → connection snippets. Ensures agents don't start with zero access.
- Updated: Vault wizard is now 4 steps: create vault → store secret → grant agent access (creates read policy) → next steps.
- New:
.envimport on vault detail page — paste a.envfile to bulk-create secrets with configurable path prefix.
Google OAuth JWKS
- Updated:
POST /v1/auth/googlenow verifies the Google ID token locally via Google's JWKS (RS256 signature, audience, issuer, expiry). Replaces the previous tokeninfo endpoint call. More reliable (no URL length limits).
SSO (WorkOS)
- New: WorkOS SAML/OIDC SSO —
GET /v1/auth/sso/authorize, callback handler, "Sign in with SSO" button on login page.
Security fixes (2026-03-16 audit)
- Fixed (C-3): Dashboard auth bypass —
PUBLIC_PAGESprefix match for"/"matched all paths. Now uses exact match. - Fixed (C-4): MFA token replay — MFA challenge tokens are now single-use (jti revoked after verification).
- Fixed (C-5): Cross-vault IDOR — agent JWTs with empty
vault_idsno longer grant unrestricted access; vault IDs are derived from access policies. - Fixed (H-19): Ed25519 SPKI DER parsing uses proper ASN.1 validation instead of a heuristic.
- New:
signing_key_pathvalidation restricts Intents API key paths tokeys/*,wallets/*,agents/{id}/keys/*, oragents/{id}/chains/*. - New: Shroud strips sensitive headers (authorization, cookies, IP headers) before forwarding to upstream LLM providers.
x402 marketplace compatibility
- Updated: 402 Payment Required response body now aligns with docs.g402.ai and x402scan:
x402Version,accepts[]withmaxAmountRequired(atomic units),resource(full URL),payTo,maxTimeoutSeconds,asset,description,mimeType. Enables registration on x402 marketplaces. - Updated: On paid routes, x402 middleware runs before auth so unauthenticated requests receive 402 (with payment details) instead of 401. Scanners and buyers can discover and pay without a token.
- New: Optional
x402.asset(DB/API) andX402_ASSETenv — default is Base USDC. Used in 402accepts[].asset. - Updated: SDK
PaymentAcceptand auto-pay logic support the new 402 shape;maxAmountRequired(atomic) with fallback to legacyprice(USD). CustomX402Signerimplementations should usemaxAmountRequiredandasset. - Updated: Dashboard proxy passes discovery paths (
/openapi.json,/.well-known/x402) through without/v1prefix so vault discovery routes are reachable at api.1claw.co.
2026-02
Tenderly Transaction Simulation
- New:
POST /v1/agents/:agent_id/transactions/simulate— pre-flight simulation of EVM transactions via Tenderly. Returns balance changes, gas estimates, decoded errors, and a Tenderly dashboard deep-link. No signing or broadcasting occurs. - New:
POST /v1/agents/:agent_id/transactions/simulate-bundle— simulate multiple sequential transactions (e.g. approve + swap). - New:
simulate_firstflag onPOST /v1/agents/:agent_id/transactions— runs a Tenderly simulation before signing. If the simulation reverts, returns HTTP 422 and does not sign. Org admins can enforce this as mandatory via theintents_api.require_simulationsetting. - New: EIP-1559 (Type 2) transaction signing — set
max_fee_per_gasandmax_priority_fee_per_gasinstead of legacygas_price. - New: Automatic nonce resolution via
eth_getTransactionCountRPC whennonceis omitted. - New: Address derivation from private key (secp256k1) — the simulation endpoint resolves the
fromaddress without exposing the key. - New:
simulate_transactionMCP tool andsimulate_firstargument on thesubmit_transactionMCP tool (defaults totrue). - New:
simulateTransaction()andsimulateBundle()methods in the TypeScript SDK. - New: Dashboard Transaction Builder on the agent detail page — simulate, review balance changes, then confirm and send.
- New: Transaction history table on the agent detail page with simulation status badges and tx hash copy.
Transaction replay protection & response hardening
- New:
Idempotency-Keyheader onPOST /v1/agents/:agent_id/transactions— duplicate requests with the same key within 24 hours return the cached response (200) instead of signing and broadcasting again. In-progress duplicates return 409 Conflict. - New: Server-side nonce serialization — when
nonceis omitted, the server atomically reserves the next nonce per agent+chain+address viaSELECT FOR UPDATElocking, preventing nonce collisions between concurrent requests. - New:
signed_txredacted by default — GET transaction endpoints omit the raw signed transaction hex. Pass?include_signed_tx=trueto include it. The initial POST submission always returns it. - New:
transaction_idempotencyandnonce_trackerdatabase tables (migrations 034, 035). - New: Nightly cleanup of expired idempotency keys (>48h) in the existing credit expiry background job.
- Updated: SDK
submitTransaction()auto-generates anIdempotency-Keyheader (UUID). Callers can override viaoptions.idempotencyKey. - Updated: MCP
submit_transactiontool auto-generates anIdempotency-Keyheader. - Updated: OpenAPI spec documents
Idempotency-Keyheader andinclude_signed_txquery parameter.
Admin user management
- New:
DELETE /v1/admin/users/:user_id— platform admins can delete users. Cascades: delete share links created by the user, clearagents.created_by, then delete the user (device_auth_codes and user_api_keys CASCADE in DB). Cannot delete self or the last owner of the platform org. - New:
scripts/cleanup-test-users.sh— removes test users by display name. Auth viaONECLAW_TOKENorADMIN_EMAIL+ADMIN_PASSWORD. Use--dry-runto list only.
Security audit hardening
- New: Per-agent transaction guardrails —
tx_allowed_chains,tx_to_allowlist,tx_max_value_eth,tx_daily_limit_ethenforced before signing. - New: Audit hash chain — each event stores
prev_event_idand SHA-256integrity_hashfor tamper detection. - New: x402 payment replay protection — payment proofs deduplicated via SHA-256 before facilitator verification.
- New: Authorization enforcement on
delete_secret,list_secrets, andlist_versions(policy check, not just org membership). - Improved: CORS defaults to
https://1claw.coin production (no more permissiveAnyfallback). - Improved: CSP removes
unsafe-inlineandunsafe-evalfromscript-src. - Improved: Global rate limiting middleware applied to all API routes.
- Improved: Dependency overrides for
minimatch,ajv,honoto address known CVEs.
Dashboard UX — CopyableId
- New: One-click copy for every UUID, path, and identifier across the dashboard. Vault IDs, agent IDs, principal IDs, audit actor/resource IDs, API key prefixes, secret paths, and user/org IDs in the sidebar — all clickable with tooltip confirmation.
Quota exemption for platform admin orgs
- New:
CallerIdentity.quota_exemptflag resolved at authentication time. Platform admin org (and its agents) bypasses all billing checks. Cleaner than per-route overrides — single source of truth in auth middleware.
Policy UI improvements
- New: Vault selector dropdown on Create Access Policy page — pick any vault, not just the one in the URL.
- New: Agent principal picker — select from existing agents or type a custom agent ID.
- New: Edit policy dialog — update permissions, conditions (JSON), and expiry on existing policies.
- New: Delete policy from the policies list page.
Agent integration guide
- New: Agent detail page in the dashboard now includes a tabbed integration guide with copy-paste code snippets for TypeScript SDK, Python, curl, and MCP configuration.
PolyForm Noncommercial License
- All repositories now include the PolyForm Noncommercial License 1.0.0.
Organization migration
- All repositories moved to the 1clawAI GitHub organization.
Email notifications
- New: Transactional emails via Resend for account and security events.
- Welcome email on signup (email/password and Google OAuth).
- Share invite email when a secret is shared by email.
- Share access notification to the creator when a shared secret is accessed.
- Password change confirmation email.
- API key creation notification email.
- Emails are fire-and-forget (non-blocking) and silently skipped when no
RESEND_API_KEYis configured.
Sharing & invite-by-email
- New:
external_emailshare type — share secrets with users who don't have accounts yet. - New: Claim-on-login — pending email shares are automatically claimed when the recipient signs up or logs in.
- New: Share access notifications — creators are emailed each time a shared secret is accessed.
- New:
POST /v1/auth/signup— self-service account registration via email/password.
SDK rewrite (@1claw/sdk v0.2.0)
- New: Full API parity — typed methods for all 42+ REST API endpoints.
- Resource modules:
vault,secrets,access,agents,sharing,auth,apiKeys,billing,audit,org. createClient()factory with auto-authentication (API key or agent credentials).{ data, error, meta }response envelope on every method.- Typed error hierarchy:
AuthError,PaymentRequiredError,NotFoundError,RateLimitError, etc. - x402 auto-payment support with configurable
maxAutoPayUsd. - MCP tool layer:
McpHandlerandgetMcpToolDefinitions()for AI agent frameworks. auth.signup()for programmatic account creation.sharing.create()with email support for invite-by-email.
Examples repository
- New:
examples/basic/— TypeScript scripts for vault CRUD, secrets, billing, signup, and email sharing. - New:
examples/nextjs-agent-secret/— Next.js 14 app with Claude AI agent accessing vault secrets.
MCP server (@1claw/mcp)
- New: MCP server for AI agent access to secrets via the Model Context Protocol.
- 7 tools:
list_secrets,get_secret,put_secret,delete_secret,describe_secret,rotate_and_store,get_env_bundle. - Browsable
vault://secretsresource. - Dual transport: Local stdio mode (Claude Desktop, Cursor) and hosted HTTP streaming mode (
mcp.1claw.co). - Per-session authentication in hosted mode — each connection gets its own vault client.
- Auto-deploy to Cloud Run via GitHub Actions.
Billing & usage tracking
- New: Usage tracking middleware records every authenticated API request.
- New: Free tier — 1,000 requests/month per organization.
- New: x402 Payment Required responses when free tier is exhausted, with on-chain payment on Base (EIP-155:8453).
- New: Billing API —
GET /v1/billing/usage(summary) andGET /v1/billing/history(event log). - Unified billing across dashboard, SDK, and MCP — all count against the same quota.
Vault API
- Added
POST /v1/agents/:agent_id/rotate-keyendpoint for agent key rotation. - Added
GET /v1/billing/usageandGET /v1/billing/historyendpoints. - Usage middleware tracks method, endpoint, principal, status code, and price per request.
- x402 middleware enforces free tier limits and returns payment-required responses.
Infrastructure
- Cloud Run deployment for MCP server (
oneclaw-mcp). - Terraform resources for MCP service and domain mapping.
- GitHub Actions workflow for MCP auto-deploy.
- CI pipeline expanded: MCP type check, build, Docker image build and Trivy scan.
Documentation
- New: Full MCP documentation section (overview, setup, tool reference, security, deployment).
- New: Billing & usage guide.
- New: Deploying updates guide.
- Updated intro, MCP integration guide, and changelog.
- Updated
llms.txtandllms-full.txtwith MCP and billing content.
Initial release (2026-02 early)
- Vault API: vaults, secrets (CRUD + versioning), policies, agents, sharing, audit log, org management.
- Human auth: email/password, Google OAuth, personal API keys (
1ck_). - Agent auth: agent API keys (
ocv_) exchanged for short-lived JWTs. - Envelope encryption with Cloud KMS (or SoftHSM for local dev).
- Dashboard: Next.js with full secret management UI.
- TypeScript SDK (
@1claw/sdk). - Docusaurus docs site.
- Terraform infrastructure (Supabase, GCP, Vercel).