ironclaw tool
Manage WASM-based tools that extend IronClaw’s capabilities. Tools are WebAssembly components that provide functions the agent can use during conversations.Subcommands
install- Install a WASM tool from source or .wasm filelist- List installed toolsremove- Remove an installed toolinfo- Show information about a toolauth- Configure OAuth authentication for a toolsetup- Configure required secrets for a tool
ironclaw tool install
Install a WASM tool from a source directory or compiled .wasm file.Syntax
Arguments
<PATH>
Path to:
- Tool source directory (containing
Cargo.toml), or - Compiled
.wasmfile
Flags
--name, -n <NAME>
Tool name (defaults to directory/file name).
--capabilities <PATH>
Path to capabilities JSON file. Auto-detected if not specified:
<name>.capabilities.jsoncapabilities.json
--target, -t <DIR>
Target installation directory.
- Default:
~/.ironclaw/tools/
--release
Build in release mode (default: true).
--skip-build
Skip compilation, use existing .wasm file.
--force, -f
Force overwrite if tool already exists.
Examples
Install from Source Directory
Install from .wasm File
Install with Capabilities
Skip Build (Use Existing)
Output
ironclaw tool list
List all installed tools.Syntax
Flags
--dir, -d <PATH>
Directory to list tools from.
- Default:
~/.ironclaw/tools/
--verbose, -v
Show detailed information.
Examples
Output
Default output:ironclaw tool remove
Remove an installed tool.Syntax
Arguments
<NAME>
Name of the tool to remove.
Flags
--dir, -d <PATH>
Directory to remove tool from.
- Default:
~/.ironclaw/tools/
Examples
Output
ironclaw tool info
Show detailed information about a tool.Syntax
Arguments
<NAME_OR_PATH>
Tool name or path to .wasm file.
Flags
--dir, -d <PATH>
Directory to look for tool.
- Default:
~/.ironclaw/tools/
Examples
Output
ironclaw tool auth
Configure OAuth authentication for a tool.Syntax
Arguments
<NAME>
Name of the tool to authenticate.
Flags
--dir, -d <PATH>
Directory containing the tool.
- Default:
~/.ironclaw/tools/
--user, -u <USER_ID>
User ID for storing the secret.
- Default:
default
Examples
Interactive Flow
The command checks for authentication configuration in the tool’s capabilities file and initiates the appropriate flow:OAuth Flow
Manual Token Entry
Requirements
- Tool must have an
authsection in its capabilities file - Database must be available for storing secrets
SECRETS_MASTER_KEYmust be set
ironclaw tool setup
Configure required secrets for a tool (fromsetup.required_secrets in capabilities).
Syntax
Arguments
<NAME>
Name of the tool to set up.
Flags
--dir, -d <PATH>
Directory containing the tool.
- Default:
~/.ironclaw/tools/
--user, -u <USER_ID>
User ID for storing secrets.
- Default:
default
Examples
Interactive Flow
Capabilities File Format
Tools require a capabilities file defining their permissions:Tool Permissions
Tools have zero permissions by default. The capabilities file grants:- HTTP access - Specific hosts, paths, and methods
- Secrets access - Which secrets the tool can check existence of
- Workspace access - Read access to specific path prefixes
- Tool invocation - Call other tools (with aliases)
Troubleshooting
”No Cargo.toml found”
The path must point to a Rust WASM tool source directory:“No .wasm artifact found”
Build the tool first or remove--skip-build:
“Tool already exists”
Use--force to overwrite: