Skip to content

Repository files navigation

1claw OpenClaw Plugin

OpenClaw gateway plugin for 1claw.

Repository: github.com/1clawAI/1claw-openclaw-plugin
npm: @1claw/openclaw-plugin
Docs: OpenClaw Plugins · 1claw

OpenClaw agents need vault access, transaction signing, and sometimes an inspected LLM path. Running a separate MCP process works, but this plugin registers 27+ native tools inside the gateway itself. Secrets are fetched at runtime. Outbound messages get scanned for leaked values. Optional Shroud routing sends LLM traffic through the TEE proxy when the agent has it enabled.

Install one npm package, set ONECLAW_AGENT_API_KEY, restart the gateway. Your agent gets secrets, signing, automations, memory, runtimes, and directory tools without extra wiring. Toggle features (redaction, injection, Shroud, slash commands) in plugins.entries.1claw.config.features.


Features

  • Native agent tools — 27+ tools for secrets, vaults, policies, sharing, signing keys, multi-chain transactions, execution intents, automations, memory, runtimes, and discovery (EVM + Bitcoin, Solana, XRP, Cardano, Tron; optional, configurable)
  • Automations — Create and manage cron-based scheduled tasks via oneclaw_create_automation, oneclaw_list_automations, oneclaw_delete_automation
  • Agent Memory — Store and search persistent vector memory via oneclaw_store_memory, oneclaw_search_memory
  • Runtimes — Deploy and manage agent runtime environments via oneclaw_deploy_runtime, oneclaw_list_runtimes
  • Discovery — Publish agents to the 1Claw directory via oneclaw_publish_agent, oneclaw_search_directory
  • Safe accounts — List/provision counterfactual Safe agent accounts via oneclaw_list_agent_accounts, oneclaw_migrate_agent_to_safe (v0.56.2+, requires @1claw/sdk / MCP parity)
  • Guardrail governance — Agent guardrail widening returns 202 + approval id; execution HITL for bindings when policy matches (v0.56+ platform)
  • Secret redaction — Scan outbound messages and redact leaked secret values (default on)
  • Secret injection — Replace {{1claw:path/to/secret}} placeholders at prompt time (opt-in)
  • Shroud routing — Route LLM traffic through Shroud TEE when the agent has shroud_enabled (opt-in)
  • Key rotation monitor — Background warnings for secrets expiring within 7 days (opt-in)
  • Slash commands/oneclaw, /oneclaw-list, /oneclaw-rotate, /oneclaw-memory (optional)
  • Gateway RPC1claw.status for programmatic health/status
  • Bundled skill — 1claw skill (skills/1claw/SKILL.md) auto-discovered by OpenClaw

All features are toggled via plugins.entries.1claw.config.features. Auth uses config or env vars.

Platform v0.56+ (HITL, HFA, Safe)

Capability Plugin behavior
Graduated HITL oneclaw_submit_transaction / sign tools may return awaiting_approval — poll approvals or use dashboard/mobile inbox.
Human Factor Auth N/A for agent keys; treasury HFA is human-only (@1claw/wallet-react).
Guardrail governance Execution intents honor shadow/enforce; widening guardrails requires human policy_change approval.
Safe foundation Safe account tools when MCP/SDK expose them; on-chain deploy stubs return 501 until Guard audit.

Pin @1claw/openclaw-plugin@0.56.2 with Vault API / MCP 0.56.2 for Safe account tools.


Install

openclaw plugins install @1claw/openclaw-plugin

Or from the repo (e.g. when developing or using as a submodule):

openclaw plugins install -l ./path/to/1claw-openclaw-plugin

Config

Minimal config (config file or env):

{
  plugins: {
    entries: {
      "1claw": {
        enabled: true,
        config: {
          apiKey: "ocv_..."
          // agentId, vaultId, baseUrl, shroudUrl optional
          // features: { tools: true, secretRedaction: true, ... }
        }
      }
    }
  }
}

Env fallback: ONECLAW_AGENT_API_KEY, ONECLAW_AGENT_ID, ONECLAW_VAULT_ID, ONECLAW_BASE_URL, ONECLAW_SHROUD_URL.

Restart the OpenClaw Gateway after changing config.


Tool names

When enabled, tools are registered with a oneclaw_ prefix (e.g. oneclaw_list_secrets, oneclaw_get_secret). Add them to your agent’s tools.allow (e.g. "1claw" or specific names).


Slash commands

Command Description
/oneclaw Connection status, vault info, token TTL, features
/oneclaw-list List secret paths (optional prefix arg)
/oneclaw-rotate Rotate a secret: /oneclaw-rotate <path> <new-value>

Development

npm install
npm run typecheck
  • TypeScript only (no build step required for OpenClaw; jiti loads .ts at runtime).
  • Optional: npm run build to emit dist/ (not required for openclaw plugins install when using source).

As a submodule in 1claw

From the 1claw repo root:

git submodule add https://github.com/1clawAI/1claw-openclaw-plugin.git packages/openclaw-plugin
git submodule update --init --recursive

Clone 1claw with the submodule:

git clone --recurse-submodules https://github.com/1clawAI/1claw.git

License

MIT © 1claw

About

OpenClaw plugin for 1claw — HSM-backed secrets, transaction signing, Shroud TEE

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages