> ## Documentation Index
> Fetch the complete documentation index at: https://mintlify.com/nearai/ironclaw/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduction to IronClaw

> Your secure personal AI assistant that protects your data and expands its capabilities on the fly

<Frame>
  <img src="https://mintlify.s3.us-west-1.amazonaws.com/nearai-ironclaw/images/ironclaw-hero.png" alt="IronClaw" />
</Frame>

## Your AI Assistant, Always On Your Side

IronClaw is built on a simple principle: **your AI assistant should work for you, not against you**.

In a world where AI systems are increasingly opaque about data handling and aligned with corporate interests, IronClaw takes a different approach — open source, locally-controlled, and security-first.

<CardGroup cols={2}>
  <Card title="Privacy First" icon="shield-check">
    All data stored locally, encrypted, and never leaves your control. No telemetry, no tracking, no data harvesting.
  </Card>

  <Card title="Transparent & Auditable" icon="code">
    Open source from day one. Audit every line of code. No hidden telemetry or black boxes.
  </Card>

  <Card title="Self-Expanding" icon="puzzle-piece">
    Build new tools on the fly without waiting for vendor updates. Dynamic WASM plugins and MCP integration.
  </Card>

  <Card title="Defense in Depth" icon="lock">
    Multiple security layers protect against prompt injection and data exfiltration.
  </Card>
</CardGroup>

## Key Features

### Security First

<AccordionGroup>
  <Accordion title="WASM Sandbox" icon="cube">
    All untrusted tools run in isolated WebAssembly containers with capability-based permissions. Explicit opt-in for HTTP, secrets, and tool invocation. Secrets are injected at the host boundary and never exposed to WASM code.

    ```
    WASM ──► Allowlist ──► Leak Scan ──► Credential ──► Execute ──► Leak Scan ──► WASM
             Validator     (request)     Injector       Request     (response)
    ```
  </Accordion>

  <Accordion title="Credential Protection" icon="key">
    * Secrets encrypted with AES-256-GCM
    * Stored in OS keychain (macOS/Linux) or environment variables
    * Never exposed to tools or LLM context
    * Automatic leak detection in HTTP requests and responses
  </Accordion>

  <Accordion title="Prompt Injection Defense" icon="shield-halved">
    External content passes through multiple security layers:

    * Pattern-based detection of injection attempts
    * Content sanitization and escaping
    * Policy rules with severity levels (Block/Warn/Review/Sanitize)
    * Tool output wrapping for safe LLM context injection
  </Accordion>

  <Accordion title="Endpoint Allowlisting" icon="network-wired">
    HTTP requests only allowed to explicitly approved hosts and paths. Tools declare their required endpoints upfront in capability manifests.
  </Accordion>
</AccordionGroup>

### Always Available

IronClaw runs continuously in the background, accessible through multiple channels:

* **REPL** — Interactive terminal interface for direct conversation
* **HTTP Webhooks** — Trigger tasks via REST API
* **WASM Channels** — Telegram, Slack, Discord, WhatsApp (isolated plugin architecture)
* **Web Gateway** — Browser UI with real-time SSE/WebSocket streaming
* **Routines** — Cron schedules, event triggers, webhook handlers for background automation
* **Heartbeat System** — Proactive background execution for monitoring and maintenance

<Tip>
  All channels support parallel job execution with isolated contexts. No request blocks another.
</Tip>

### Self-Expanding Capabilities

<CardGroup cols={2}>
  <Card title="Dynamic Tool Building" icon="wrench">
    Describe what you need, and IronClaw builds it as a WASM tool. No restart required.
  </Card>

  <Card title="MCP Protocol" icon="plug">
    Connect to Model Context Protocol servers for additional capabilities like file access, web browsing, and more.
  </Card>

  <Card title="Plugin Architecture" icon="boxes-stacked">
    Drop in new WASM tools and channels without restarting the agent. Hot-reload everything.
  </Card>

  <Card title="Docker Sandbox" icon="docker">
    Isolated container execution with per-job tokens and orchestrator/worker pattern for heavy workloads.
  </Card>
</CardGroup>

### Persistent Memory

IronClaw remembers your conversations, preferences, and context:

* **Hybrid Search** — Full-text + vector search using Reciprocal Rank Fusion
* **Workspace Filesystem** — Flexible path-based storage for notes, logs, and context
* **Identity Files** — Maintain consistent personality and preferences across sessions (`IDENTITY.md`, `SOUL.md`)
* **PostgreSQL or libSQL** — Production-ready persistence with pgvector for semantic search

<Note>
  Your workspace is stored in a local database. Enable embeddings during setup for semantic search across all your notes and conversations.
</Note>

## Architecture at a Glance

```
┌────────────────────────────────────────────────────────────────┐
│                          Channels                              │
│  ┌──────┐  ┌──────┐   ┌─────────────┐  ┌─────────────┐         │
│  │ REPL │  │ HTTP │   │WASM Channels│  │ Web Gateway │         │
│  └──┬───┘  └──┬───┘   └──────┬──────┘  │ (SSE + WS)  │         │
│     │         │              │         └──────┬──────┘         │
│     └─────────┴──────────────┴────────────────┘                │
│                              │                                 │
│                    ┌─────────▼─────────┐                       │
│                    │    Agent Loop     │  Intent routing       │
│                    └────┬──────────┬───┘                       │
│                         │          │                           │
│              ┌──────────▼────┐  ┌──▼───────────────┐           │
│              │  Scheduler    │  │ Routines Engine  │           │
│              │(parallel jobs)│  │(cron, event, wh) │           │
│              └──────┬────────┘  └────────┬─────────┘           │
│                     │                    │                     │
│       ┌─────────────┼────────────────────┘                     │
│       │             │                                          │
│   ┌───▼─────┐  ┌────▼────────────────┐                         │
│   │ Local   │  │    Orchestrator     │                         │
│   │Workers  │  │  ┌───────────────┐  │                         │
│   │(in-proc)│  │  │ Docker Sandbox│  │                         │
│   └───┬─────┘  │  │   Containers  │  │                         │
│       │        │  │ ┌───────────┐ │  │                         │
│       │        │  │ │Worker / CC│ │  │                         │
│       │        │  │ └───────────┘ │  │                         │
│       │        │  └───────────────┘  │                         │
│       │        └─────────┬───────────┘                         │
│       └──────────────────┤                                     │
│                          │                                     │
│              ┌───────────▼──────────┐                          │
│              │    Tool Registry     │                          │
│              │  Built-in, MCP, WASM │                          │
│              └──────────────────────┘                          │
└────────────────────────────────────────────────────────────────┘
```

| Component | Purpose |
| - | - |
| **Agent Loop** | Main message handling and job coordination |
| **Router** | Classifies user intent (command, query, task) |
| **Scheduler** | Manages parallel job execution with priorities |
| **Worker** | Executes jobs with LLM reasoning and tool calls |
| **Orchestrator** | Container lifecycle, LLM proxying, per-job auth |
| **Web Gateway** | Browser UI with chat, memory, jobs, logs, extensions, routines |
| **Routines Engine** | Scheduled (cron) and reactive (event, webhook) background tasks |
| **Workspace** | Persistent memory with hybrid search |
| **Safety Layer** | Prompt injection defense and content sanitization |

## Why IronClaw?

<Tip>
  IronClaw is a Rust reimplementation inspired by [OpenClaw](https://github.com/openclaw/openclaw), bringing native performance, memory safety, and enhanced security.
</Tip>

**Key differences from OpenClaw:**

* **Rust vs TypeScript** — Native performance, memory safety, single binary
* **WASM sandbox vs Docker** — Lightweight, capability-based security for tools
* **PostgreSQL vs SQLite** — Production-ready persistence with vector search
* **Security-first design** — Multiple defense layers, credential protection, prompt injection defense

## Next Steps

<CardGroup cols={2}>
  <Card title="Installation" icon="download" href="/installation">
    Install IronClaw on your system
  </Card>

  <Card title="Quick Start" icon="rocket" href="/quickstart">
    Get up and running in 5 minutes
  </Card>

  <Card title="Configuration" icon="gear" href="/configuration">
    Configure LLM providers, channels, and more
  </Card>

  <Card title="CLI Reference" icon="terminal" href="/cli/overview">
    Explore all available commands
  </Card>
</CardGroup>
