Features
- Real-time chat - WebSocket or SSE streaming
- Workspace browser - View and search memory/daily files
- Job management - Launch and monitor sandbox jobs
- Extension management - Install, configure, and authenticate extensions
- Skill browser - Search and install skills
- Log viewer - Real-time log streaming with level control
- OpenAI-compatible API - Use IronClaw as a drop-in replacement for OpenAI API
- Cost tracking - Token usage and cost estimates
- Session history - Browse past conversations
Configuration
Set via environment variables or.env file:
Configuration Options
Quick Start
1. Start IronClaw
http://localhost:3000.
2. Get Auth Token
If no token is configured, IronClaw generates one and prints it:3. Open Browser
Visithttp://localhost:3000 and enter the auth token when prompted.
API Endpoints
Chat
Send Message
Event Stream (SSE)
WebSocket
Memory/Workspace
List Files
Read File
Search Files
Jobs
List Jobs
Get Job Details
Stop Job
Extensions
List Installed Extensions
Install Extension
Authenticate Extension
Skills
Search Skills
Install Skill
Logs
Stream Logs (SSE)
Set Log Level
trace, debug, info, warn, error
Status
System Status
OpenAI-Compatible API
The gateway provides an OpenAI-compatible endpoint for drop-in replacement:Chat Completions
Streaming
Use with OpenAI SDK
Authentication
All API endpoints require a bearer token:Rate Limiting
The gateway enforces rate limits:- Chat messages: 30 per minute
- API requests: 100 per minute
Security
Auto-Generated Tokens
If noGATEWAY_AUTH_TOKEN is set, IronClaw generates a random 32-character token on startup:
HTTPS Recommended
For production use, deploy behind a reverse proxy with TLS:Source Code
- Implementation:
~/workspace/source/src/channels/web/mod.rs - Server:
~/workspace/source/src/channels/web/server.rs - SSE:
~/workspace/source/src/channels/web/sse.rs - WebSocket:
~/workspace/source/src/channels/web/ws.rs - OpenAI API:
~/workspace/source/src/channels/web/openai_compat.rs
Troubleshooting
Cannot connect to gateway
- Verify
GATEWAY_PORTis correct - Check firewall rules allow port 3000
- Ensure IronClaw is running (
ironclaw run) - Check logs for “Web Gateway started at…“
401 Unauthorized
- Verify auth token matches the one printed at startup
- Check
Authorization: Bearerheader format - For WebSocket, use
?token=query parameter
WebSocket disconnects
- Check browser console for errors
- Verify reverse proxy (if any) supports WebSocket upgrades
- Ensure connection isn’t timing out (send periodic pings)
SSE not receiving events
- Verify
Accept: text/event-streamheader - Check browser EventSource API support
- Ensure reverse proxy doesn’t buffer SSE responses
429 Too Many Requests
- Reduce request frequency
- Implement exponential backoff
- Check rate limiter settings in source