← Package directory
Available on winget

Install ironclaw

Unleash Your AI Agent, With Peace of Mind

Install with winget
winget install --id NearAI.IronClaw
Upgrade
winget upgrade --id NearAI.IronClaw
Uninstall
winget uninstall --id NearAI.IronClaw

About ironclaw

IronClaw is the secure, open-source alternative to OpenClaw that runs in encrypted enclaves on NEAR AI Cloud. AI agents that actually do things, but your secrets never touch the LLM. Philosophy IronClaw is built on a simple principle: your AI assistant should work for you, not against you. In a world where AI systems are increasingly opaque about data handling and aligned with corporate interests, IronClaw takes a different approach: - Your data stays yours - All information is stored locally, encrypted, and never...

What's new in 0.28.2

Release Notes Fixed - (extensions) restore chat-driven tool_install + fix double-invoke + auto-approve footgun (#3559) Changed - (llm) hide provider-specific auth, model fetch, and embeddings config behind facades (#3416) Tests - (e2e) unxfail two auth-matrix tests now that contracts match (#3589) - (e2e) make Skills lifecycle deterministic (#3309)

Read release notes

Version history

Version Updated Notes
0.28.2 Unknown Release Notes Fixed - (extensions) restore chat-driven tool_install + fix double-invoke + auto-approve footgun (#3559) Changed - (llm) hide provider-specific auth, model fetch, and embeddings config behind facades (#3416...
0.28.1 Unknown Release Notes Added - (channels) add pairing_approve tool for Slack binding via chat (#3396) - (channels) add WeChat registry artifact metadata (#3386) - (common) describe paths and platform helpers in crate description...
0.28.0 Unknown Release Notes Added - (reborn) land the reborn-integration substrate on main, introducing host foundation crates, capability host, runtime dispatcher, process lifecycle, filesystem, secrets, network, and extension manife...
0.27.0 Unknown Release Notes Added - (engine-v2) add canonical capability status vocabulary for the v2 runtime contract (#2825) - (engine-v2) centralize action-vs-capability surface policy across the prompt, runtime, bridge projection,...
0.26.0 Unknown Release Notes Added - (engine-v2) add per-project sandbox with mission lifecycle and cost tracking (#2211) (#2660) - (llm) hot-reload provider chain from settings (#2673) - (bridge) add workspace-backed project registrat...
0.25.0 Unknown Release Notes Added - (tools) production-grade coding tools, file history, and skills (#2025) - add extensible deployment profiles (IRONCLAW_PROFILE) (#2203) - (skills) commitments system — active intake for personal AI...
0.24.0 Unknown Release Notes Added - (gateway) OIDC JWT authentication for reverse-proxy deployments (#1463) - support custom LLM provider configuration via web UI (#1340) - (skills) recursive bundle directory scanning for skill discov...
0.23.0 Unknown Release Notes Added - complete multi-tenant isolation — phases 2–4 (#1614) Fixed - (routines) recover delete name after failed update fallback (#1108) - (mcp) handle 202 Accepted and wire session manager for Streamable H...
0.22.0 Unknown Release Notes Added - (agent) thread per-tool reasoning through provider, session, and all surfaces (#1513) - (cli) show credential auth status in tool info (#1572) - multi-tenant auth with per-user workspace isolation (...
0.21.0 Unknown Release Notes Added - structured fallback deliverables for failed/stuck jobs (#236) - LRU embedding cache for workspace search (#1423) - receive relay events via webhook callbacks (#1254) Fixed - bump Feishu channel vers...
0.20.0 Unknown Release Notes Added - (self-repair) wire stuck_threshold, store, and builder (#712) - (testing) add FaultInjector framework for StubLlm (#1233) - (gateway) unified settings page with subtabs (#1191) - upgrade MiniMax def...
0.19.0 Unknown Release Notes Added - verify telegram owner during hot activation (#1157) - (config) unify config resolution with Settings fallback (Phase 2, #1119) (#1203) - (sandbox) add retry logic for transient container failures (#...
0.18.0 Unknown Release Notes Other - Merge pull request #907 from nearai/staging-promote/b0214fef-22930316561 - promote staging to main (2026-03-10 15:19 UTC) (#865) - Merge pull request #830 from nearai/staging-promote/3a2989d0-228883...
0.17.0 Unknown Release Notes Added - (llm) per-provider unsupported parameter filtering (#749, #728) (#809) - persist user_id in save_job and expose job_id on routine runs (#709) - (ci) chained promotion PRs with multi-agent Claude rev...
0.16.1 Unknown Release Notes Fixed - revert WASM artifact SHA256 checksums to null (#627)
0.16.0 Unknown Release Notes Added - (e2e) extensions tab tests, CI parallelization, and 3 production bug fixes (#584) - WASM extension versioning with WIT compat checks (#592) - Add HMAC-SHA256 webhook signature validation for Slack (...
0.15.0 Unknown Release Notes Added - (oauth) route callbacks through web gateway for hosted instances (#555) - (web) show error details for failed tool calls (#490) - (extensions) improve auth UX and add load-time validation (#536) - a...
0.13.1 Unknown Release Notes Added - add Brave Web Search WASM tool (#474) Fixed - (web) auto-scroll and Enter key completion for slash command autocomplete (#475) - correct download URLs for telegram-mtproto and slack-tool extensions...
0.13.0 Unknown Release Notes Added - (cli) add tool setup command + GitHub setup schema (#438) - add web_fetch built-in tool (#435) - (web) DB-backed Jobs tab + scheduler-dispatched local jobs (#436) - (extensions) add OAuth setup UI f...
0.12.0 Unknown Added - (web) improve WASM channel setup flow (#380) - (web) inline tool activity cards with auto-collapsing (#376) - (web) display logs newest-first in web gateway UI (#369) - (signal) tool approval workflow and status...