Skip to main content

ironclaw tool

Manage WASM-based tools that extend IronClaw’s capabilities. Tools are WebAssembly components that provide functions the agent can use during conversations.

Subcommands

  • install - Install a WASM tool from source or .wasm file
  • list - List installed tools
  • remove - Remove an installed tool
  • info - Show information about a tool
  • auth - Configure OAuth authentication for a tool
  • setup - Configure required secrets for a tool

ironclaw tool install

Install a WASM tool from a source directory or compiled .wasm file.

Syntax

Arguments

<PATH> Path to:
  • Tool source directory (containing Cargo.toml), or
  • Compiled .wasm file

Flags

--name, -n <NAME> Tool name (defaults to directory/file name). --capabilities <PATH> Path to capabilities JSON file. Auto-detected if not specified:
  • <name>.capabilities.json
  • capabilities.json
--target, -t <DIR> Target installation directory.
  • Default: ~/.ironclaw/tools/
--release Build in release mode (default: true). --skip-build Skip compilation, use existing .wasm file. --force, -f Force overwrite if tool already exists.

Examples

Install from Source Directory

Install from .wasm File

Install with Capabilities

Skip Build (Use Existing)

Output


ironclaw tool list

List all installed tools.

Syntax

Flags

--dir, -d <PATH> Directory to list tools from.
  • Default: ~/.ironclaw/tools/
--verbose, -v Show detailed information.

Examples

Output

Default output:
Verbose output:

ironclaw tool remove

Remove an installed tool.

Syntax

Arguments

<NAME> Name of the tool to remove.

Flags

--dir, -d <PATH> Directory to remove tool from.
  • Default: ~/.ironclaw/tools/

Examples

Output


ironclaw tool info

Show detailed information about a tool.

Syntax

Arguments

<NAME_OR_PATH> Tool name or path to .wasm file.

Flags

--dir, -d <PATH> Directory to look for tool.
  • Default: ~/.ironclaw/tools/

Examples

Output


ironclaw tool auth

Configure OAuth authentication for a tool.

Syntax

Arguments

<NAME> Name of the tool to authenticate.

Flags

--dir, -d <PATH> Directory containing the tool.
  • Default: ~/.ironclaw/tools/
--user, -u <USER_ID> User ID for storing the secret.
  • Default: default

Examples

Interactive Flow

The command checks for authentication configuration in the tool’s capabilities file and initiates the appropriate flow:

OAuth Flow

Manual Token Entry

Requirements

  • Tool must have an auth section in its capabilities file
  • Database must be available for storing secrets
  • SECRETS_MASTER_KEY must be set

ironclaw tool setup

Configure required secrets for a tool (from setup.required_secrets in capabilities).

Syntax

Arguments

<NAME> Name of the tool to set up.

Flags

--dir, -d <PATH> Directory containing the tool.
  • Default: ~/.ironclaw/tools/
--user, -u <USER_ID> User ID for storing secrets.
  • Default: default

Examples

Interactive Flow

Capabilities File Format

Tools require a capabilities file defining their permissions:

Tool Permissions

Tools have zero permissions by default. The capabilities file grants:
  • HTTP access - Specific hosts, paths, and methods
  • Secrets access - Which secrets the tool can check existence of
  • Workspace access - Read access to specific path prefixes
  • Tool invocation - Call other tools (with aliases)

Troubleshooting

”No Cargo.toml found”

The path must point to a Rust WASM tool source directory:

“No .wasm artifact found”

Build the tool first or remove --skip-build:

“Tool already exists”

Use --force to overwrite:

“Invalid capabilities file”

Validate your JSON:

“SECRETS_MASTER_KEY not set”

Run onboarding or set the key manually:
  • mcp - Manage MCP servers (alternative to WASM tools)
  • onboard - Initial setup including secrets key