Skip to main content
The Web Gateway provides a rich browser interface for chatting with your IronClaw agent, browsing workspace files, managing jobs, and monitoring system status.

Features

  • Real-time chat - WebSocket or SSE streaming
  • Workspace browser - View and search memory/daily files
  • Job management - Launch and monitor sandbox jobs
  • Extension management - Install, configure, and authenticate extensions
  • Skill browser - Search and install skills
  • Log viewer - Real-time log streaming with level control
  • OpenAI-compatible API - Use IronClaw as a drop-in replacement for OpenAI API
  • Cost tracking - Token usage and cost estimates
  • Session history - Browse past conversations

Configuration

Set via environment variables or .env file:

Configuration Options

Quick Start

1. Start IronClaw

The gateway starts automatically on http://localhost:3000.

2. Get Auth Token

If no token is configured, IronClaw generates one and prints it:

3. Open Browser

Visit http://localhost:3000 and enter the auth token when prompted.

API Endpoints

Chat

Send Message

Response:

Event Stream (SSE)

Response (Server-Sent Events):

WebSocket

Memory/Workspace

List Files

Response:

Read File

Response:

Search Files

Response:

Jobs

List Jobs

Response:

Get Job Details

Response:

Stop Job

Response:

Extensions

List Installed Extensions

Response:

Install Extension

Authenticate Extension

Skills

Search Skills

Response:

Install Skill

Logs

Stream Logs (SSE)

Response (Server-Sent Events):

Set Log Level

Levels: trace, debug, info, warn, error

Status

System Status

Response:

OpenAI-Compatible API

The gateway provides an OpenAI-compatible endpoint for drop-in replacement:

Chat Completions

Response:

Streaming

Response (SSE):

Use with OpenAI SDK

Authentication

All API endpoints require a bearer token:
Or as a query parameter:
WebSocket connections use the query parameter:

Rate Limiting

The gateway enforces rate limits:
  • Chat messages: 30 per minute
  • API requests: 100 per minute
Exceeding limits returns HTTP 429 (Too Many Requests).

Security

Auto-Generated Tokens

If no GATEWAY_AUTH_TOKEN is set, IronClaw generates a random 32-character token on startup:
This ensures secure defaults even if you forget to set a token. For production use, deploy behind a reverse proxy with TLS:

Source Code

  • Implementation: ~/workspace/source/src/channels/web/mod.rs
  • Server: ~/workspace/source/src/channels/web/server.rs
  • SSE: ~/workspace/source/src/channels/web/sse.rs
  • WebSocket: ~/workspace/source/src/channels/web/ws.rs
  • OpenAI API: ~/workspace/source/src/channels/web/openai_compat.rs

Troubleshooting

Cannot connect to gateway

  • Verify GATEWAY_PORT is correct
  • Check firewall rules allow port 3000
  • Ensure IronClaw is running (ironclaw run)
  • Check logs for “Web Gateway started at…“

401 Unauthorized

  • Verify auth token matches the one printed at startup
  • Check Authorization: Bearer header format
  • For WebSocket, use ?token= query parameter

WebSocket disconnects

  • Check browser console for errors
  • Verify reverse proxy (if any) supports WebSocket upgrades
  • Ensure connection isn’t timing out (send periodic pings)

SSE not receiving events

  • Verify Accept: text/event-stream header
  • Check browser EventSource API support
  • Ensure reverse proxy doesn’t buffer SSE responses

429 Too Many Requests

  • Reduce request frequency
  • Implement exponential backoff
  • Check rate limiter settings in source

Example Integration

React Chat Component