1Claw now spans security, payments, identity, discovery, execution and runtime

When we started 1Claw, the problem was narrow and ugly: AI agents were walking around with raw API keys in their environment variables. One prompt injection away from disaster. So we built Vaults, HSM-backed secret storage scoped per agent, with policies deciding who reads what and an audit log catching every access.

Then we kept running into the same question from builders. Fine, my secrets are safe. But my agent still needs to actually do things. Pay for things. Call APIs. Sign transactions. Who approves that?

That question turned into Intents. An agent requests an action, a policy decides, and the action executes without the agent ever holding a raw key. Credentials get injected server-side. If something needs a human, it waits for one.

And because agents talk to LLMs constantly, we built Shroud. It sits between your agent and the model, inspects the traffic, redacts secrets before they reach a prompt or a log, and keeps signing keys inside a TEE. The model never sees what it shouldn't.

That was the foundation. Security, identity, payments. It held up. But agents that live longer than one session need more than a lock on the door.

So over the past few months we shipped three new layers.

Memory

Agents forget everything between runs unless you bolt on a vector DB and hope for the best. Now every 1Claw agent gets three memory tiers out of the box: scratch memory with a TTL for working state, durable key-value storage that persists, and semantic memory with vector search for the fuzzy stuff. Everything is envelope-encrypted at rest and namespaced per agent, so one agent can't read another's memory even inside the same org.

Automations

Cron schedules, webhook triggers, event triggers, and manual runs. Chain up to 14 step types: HTTP calls, AI generation, memory ops, notifications, secret rotation, transaction signing, conditional branching. Describe what you want in plain English and the assist endpoint drafts the workflow for you to review.

The part we care most about is the guardrails. Hard timeouts, concurrency caps, budget limits on AI steps, auto-disable after repeated failures, and human approval gates you can drop into any workflow. Automation without a spending cap is just a faster way to have a bad week.

Every plan includes automations. The free tier gets you 2 automations and 100 runs a month.

Runtimes

You shouldn't need a Kubernetes cluster to run one agent. Pick a preset, point at a Docker image, deploy. Secrets from your vault are injected as environment variables at boot, so nothing lives in your code or config. Every runtime ships with a Shroud sidecar watching LLM traffic. Expose your agent at a public subdomain with API key, JWT, or open auth, or keep it internal.

If you're handling keys that matter, the confidential compute tiers run in AMD SEV-SNP enclaves. Keys never leave the TEE, full stop.

Where this lands

Put it together and 1Claw now covers six things an agent needs: security, identity, payments, discovery, execution and runtime. Vaults and Shroud guard the secrets. Intents handle identity and payments. The agent directory handles discovery, with public A2A and MCP endpoints so agents can find and call each other. Automations handle execution. Runtimes handle, well, runtime.

None of this requires adopting a new framework. We work with OpenClaw, Hermes, CrewAI, LangChain and pretty much anything that speaks MCP. One config block gets your agent 60+ tools covering vault access, payments, memory, automations and runtimes:

{
  "mcpServers": {
    "1claw": {
      "command": "npx",
      "args": ["-y", "@1claw/mcp@latest"],
      "env": { "ONECLAW_AGENT_API_KEY": "<your-key>" }
    }
  }
}

There's also a full SKILL.md and llms.txt at 1claw.xyz/for-ai if you'd rather just hand your assistant the docs and let it wire itself up.

Start free at 1claw.xyz. Docs at docs.1claw.xyz. Come tell us what breaks.