Skip to content

Latest commit

Β 

History

3,378 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

ClawBox

ClawBox β€” a private AI assistant appliance built on OpenClaw

ClawBox is a private, always-on AI assistant appliance built on NVIDIA Jetson.
This repository is OpenClaw OS, the operating system that ships on every ClawBox.
Plug in, join its setup hotspot, finish the browser wizard. No cloud required.

Designed, built and shipped from the EU by ID Robots Ltd. β€” the makers of ClawBox, a hardware appliance built on OpenClaw.
Official website: clawbox.com

Website Docs Discord Latest release License

Platform Next.js TypeScript Bun

The ClawBox desktop β€” a Chrome OS-style environment served straight from the device


What is ClawBox?

ClawBox is a dedicated personal AI assistant appliance made by ID Robots Ltd. that runs the OpenClaw AI agent. It is a private AI server for your desk: an NVIDIA Jetson Orin Nano running local AI models at 67 TOPS, with your files, chats and settings stored on the device itself. You buy it once at clawbox.com β€” there is no mandatory subscription.

This repository contains OpenClaw OS, the operating system that ships on every ClawBox. Local-first: with local models nothing leaves the box β€” cloud AI (Claude, GPT, Gemini) is strictly opt-in. On first boot it broadcasts a WiFi access point so you can set it up from any phone; then it joins your network and serves a Chrome OS-style desktop with built-in apps.

Real on-device inference, not a cloud relay. Every ClawBox ships with Gemma 4 preinstalled on its own llama.cpp and runs it on Jetson silicon β€” no API key, no account, works offline. It is not a low-power router that forwards every prompt to someone else's API: on the OpenClaw and dual editions Local-only mode routes every request to the box and switches the cloud providers off, and larger models up to ~8B run locally too.

ℹ️ Genuine ClawBox

ClawBox is designed, manufactured and supported by ID Robots Ltd. (Plovdiv, Bulgaria πŸ‡ͺπŸ‡Ί). The only official channels are:

Unrelated products sold under similar names exist and are not affiliated with ID Robots, this repository, or ClawBox support. If it did not come from clawbox.com, it is not a ClawBox and we cannot support it.

ClawBox is an independent product by ID Robots Ltd. It is not affiliated with, endorsed by, or an official partner of the OpenClaw project.

The OpenClaw AI agent controls the entire device through MCP (Model Context Protocol) tools β€” making ClawBox an OS the AI can operate, not just a UI the user clicks through:

The ClawBox chat panel answering on the desktop, with provider, model and reasoning pills under the message box

A real session on a box: the assistant says what it can do here, with the provider, model and reasoning-effort pills under the composer β€” change any of them mid-conversation, no restart.


✨ New in 4.1

πŸ“± More of the phone for the chat On a phone the chat opens full screen, its header and the composer's options fold away, and the transcript text can be set from 85% to 150%.
πŸ’¬ A conversation that cannot reopen says why Every step of restoring a conversation has a deadline. When the box cannot bring it back, the chat names the reason and offers Try again (and, in the chat panel, Start a new chat).
πŸ—‚οΈ Web apps from before 4.0 find their data A one-time step at boot copies each pre-4.0 web app's saved data into its own sandboxed storage, deleting nothing, and its old storage calls work again.
πŸ”€ Coding Agent PRs merge when green With merging on, a run hands its pull request to GitHub's auto-merge. A hold label or a main base is never merged, and CodeRabbit reviews each PR once, on green code.
πŸ› οΈ Updates and backups hold up OpenClaw 2026.9.4 with an up-front refusal for newer-schema data, plugins left Needs repair retried after the update, and ClawKeep backups that get past the failures seen after 4.0. A box updated from 4.0 no longer starts every local-model reply with a 401.

Full detail, and how to upgrade: RELEASE-NOTES-4.1.0.md.

✨ New in 4.0

πŸ’» Coding Agent Hand a whole task to a headless Claude Code run on the box. It works in a git worktree copy of your project, opens a pull request with gh, then runs an automatic adversarial review pass over its own diff. Runs keep going in the background and you can steer one mid-flight by sending it a message. Needs a Pro or Max plan.
πŸ”‘ Several Anthropic accounts Settings β†’ Providers β†’ Anthropic accounts holds several Claude Pro/Max sign-ins and API keys in the order you choose. When a coding run hits one account's usage limit it moves to the next and carries on in the same session; if all are limited it waits and resumes at the first reset.
🌐 A hostname that stays A provisioned box runs a named Cloudflare tunnel at <boxHandle>.clawbox.tech β€” the same address every time, instead of a fresh random URL per restart. No Cloudflare account needed; the credential arrives over the portal heartbeat, and a quick *.trycloudflare.com tunnel is still the fallback.
🧠 Memory Shard Your notes, past conversations and folders of your own documents, indexed and searchable by the assistant. Its own desktop app now, on both editions, and the index is built in the ClawBox AI cloud by default. Needs a Pro or Max plan.
πŸ“± Chat that fits a phone A phone opens straight into the chat, with a thumb-sized microphone beside the text box and the provider, model and reasoning pickers folded behind one control so the composer stays one row.
πŸ“Š Progress card in chat A long task reports its steps in the chat as it goes β€” what is done, what is running, and the agent's own note on the current step.
πŸ” Switch model mid-chat Provider, model and reasoning effort are pills under the message box. Picking another applies to the running agent, with nothing restarted.
πŸ–₯️ Local AI is one inventory Settings β†’ Local AI lists every model that can run on the box with Install, Enable and Uninstall on each row. On OpenClaw and dual, Local-only mode routes everything to the box and switches every cloud provider off.

A Coding Agent run on the ClawBox desktop, showing its progress, changed files and the pull request it opened

Settings, Remote Control: the box's persistent clawbox.tech hostname and the tunnel state ClawBox chat on a phone, with the thumb-sized microphone beside the text box

Full detail: RELEASE-NOTES-4.0.0.md.


Key Features

Feature Description
πŸ§™ 5-minute setup Guided wizard: WiFi β†’ updates β†’ password β†’ AI provider β†’ messaging β†’ done
πŸ–₯️ Desktop environment Chrome OS-style desktop with windowed apps, taskbar, system tray and a desktop mascot
πŸ€– AI-controlled OS Up to 78 MCP tools on the OpenClaw edition (67 on Hermes) let the AI agent operate the entire device
πŸ”’ Local-first Your data stays on the box; no telemetry, no data collection. Cloud AI only if you opt in
🧠 Flexible AI ClawBox AI out of the box β€” or Claude / GPT / Gemini with your own key or a subscription you already pay for, OpenRouter, or models that run on the box
πŸ” Switch model mid-chat Provider, model and reasoning effort are pills under the composer, hot-applied with no gateway restart
🧠 Memory Shard Indexes your notes, conversations and your own document folders so the assistant can search them β€” in the ClawBox AI cloud by default on a paid plan, or entirely on the box
🌐 Browser automation AI controls a real browser β€” fills forms, scrapes data, posts content
πŸ’¬ Multi-platform Telegram, Discord, WhatsApp and email β€” all guided in Settings β€” plus the built-in web chat
πŸ—£οΈ Voice in and out Speak to it, and have replies read back; the voice runs in the cloud or on the box
πŸ’» Built-in apps Terminal, Coding Agent, file manager, remote desktop, app store or Hermes Skills, AI chat, Memory Shard, ClawKeep backups
πŸ› οΈ Coding Agent Delegate a whole task to a headless Claude Code run: it works in a copy of your project, opens a pull request and reviews its own diff
🌐 Reachable from anywhere A named Cloudflare tunnel gives the box a persistent <boxHandle>.clawbox.tech address, with a quick tunnel as fallback
πŸ—„οΈ Backups ClawKeep encrypts a snapshot on the device and uploads it to Cloudflare R2 on a daily timer, with restore from the UI
⚑ Always-on 7–15 W power. Runs 24/7 for ~€39/year in electricity
Memory Shard on a ClawBox: the memory index card with file, chunk and source counts, health, and the indexing schedule
Memory Shard β€” your notes, conversations and document folders, indexed and searchable.
Settings β†’ Local AI: one row per model on the box β€” the agent model, the voice, speech to text and memory search
Local AI β€” every model that runs on the box, and what each one is doing right now.
Settings β†’ Appearance: the Mascot Pet picker with the built-in ClawBox crab and the community gallery
Mascot Pet β€” the built-in ClawBox crab, or a companion from the community gallery.

πŸ–₯️ Hardware

The ClawBox device

Component Spec
Processor NVIDIA Jetson Orin Nano 8GB (Super)
AI Performance 67 TOPS
Storage 512GB NVMe SSD
Power 7–15 W typical, USB-C
Size 100 Γ— 79 Γ— 31 mm

Also available: ClawBox Workstation β€” NVIDIA DGX Spark, ~1 PFLOP, runs frontier-scale local models. Details on clawbox.com.



πŸ“– Documentation

Full documentation lives at docs.clawbox.com:

Quickstart Β· First Boot Unbox β†’ power β†’ talk, and the setup wizard
What's New What changed on the current release, and where to click
Chat Β· ClawBox AI Β· Memory Shard Β· Local AI Using the box day to day
Editions Β· Switching editions OpenClaw, Hermes and Dual β€” what each is, and how to change a box from one to the other
Technical Reference Quick Reference (one page), then architecture, networking, filesystem, auth, AI providers, updates
Troubleshooting Β· Recovery Symptom-first diagnostic ladders and ordered recovery options
Agent Interface (MCP) The full device-tool catalog and the CLI wrapper
llms.txt Machine-readable docs index β€” point your AI agent here

πŸš€ Quick Start

Requirements

Supported
Device NVIDIA Jetson Orin Nano 8GB (Super)
OS image JetPack 6.2 (Ubuntu 22.04 / L4T R36.x) β€” download

⚠️ JetPack 7.x (Ubuntu 24.04) is not supported yet. NVIDIA's newest images default to JetPack 7 β€” flash JetPack 6.2 instead. On 24.04 the installer fails on Python's externally-managed-environment policy (PEP 668), among other differences. JetPack 6.2 is the platform every shipped ClawBox runs.

Install

The installer expects to run from /home/clawbox/clawbox as the clawbox user's checkout (the same layout shipped devices use):

id -u clawbox >/dev/null 2>&1 || sudo useradd -m -s /bin/bash clawbox
sudo git clone https://github.com/ID-Robots/clawbox.git /home/clawbox/clawbox
sudo chown -R clawbox:clawbox /home/clawbox/clawbox
cd /home/clawbox/clawbox
sudo bash install.sh

The install provisions everything from scratch (20–40 min on a fresh image). When it finishes, connect to the ClawBox-Setup WiFi network (open, no password) and navigate to:

  • http://clawbox.local/
  • http://10.42.0.1/

Install on x86_64

install-x64.sh installs the same web OS on an x86_64 Linux host. It runs a read-only preflight_host check first β€” ports already in use, services it would replace, desktop services it would take over β€” and refuses rather than colliding with them. Run it alone with --preflight to see what it would do.

The web, gateway and terminal ports are selectable with CLAWBOX_PORT, CLAWBOX_GATEWAY_PORT and CLAWBOX_TERMINAL_WS_PORT, and CLAWBOX_SKIP_DESKTOP_SERVICES=1 leaves existing VNC, websockify and browser services untouched.

Update

From the UI: open the System Update app. Over SSH:

sudo bash /home/clawbox/clawbox/install.sh

There is no clawbox command on PATH β€” the CLI wrapper lives in the checkout and runs through Bun (bun run /home/clawbox/clawbox/mcp/clawbox-cli.ts update), and all it does is re-run the installer with sudo. Updates are release-tag based and never touch your data β€” details in Updating ClawBox.


πŸŽ›οΈ Editions

An install is one of three editions, chosen when the device is produced:

Edition Agent Capability store Notes
openclaw OpenClaw gateway App Store The default β€” what every ClawBox was before editions existed
hermes Hermes Agent (Nous Research) Hermes Skills The OpenClaw gateway is not installed; its unit is masked and the openclaw CLI is absent
dual Both, switchable at runtime Both Premium β€” the switcher requires a licence issued by ID Robots

Memory Shard settings on a Hermes-edition ClawBox: the embedding model card with ClawBox AI cloud selected and On this box beside it
Hermes edition β€” Memory Shard indexes through the ClawBox AI cloud by default, with the model on the box one tap away.

Select it when you run the installer:

sudo CLAWBOX_EDITION=hermes bash install.sh

install.sh records the value in the root-owned /etc/clawbox/edition.env. That file is the authority: the web server resolves the edition from it per request, the installer re-reads it on every update, and the MCP server reads it once at startup. It is not a user setting and updates preserve it. On a device, bun run /home/clawbox/clawbox/mcp/clawbox-cli.ts edition prints it.

Changing the edition of a box you already own is Settings β†’ Harness, which runs the harness_swap root step: it installs the other harness, proves it runs before the edition lock flips, re-provisions the units and carries the ClawBox AI sign-in, the Telegram bot token and Memory Shard's folder list across. It needs the Max plan, an internet connection and ~3 GB free, and the same button swaps back. This is not /setup-api/harness/select, which is the dual SKU's runtime switch between two installed harnesses.

What changes on the hermes edition: the App Store and OpenClaw Control UI apps are hidden, the Skills app takes their place, gateway web paths (/api/*, /chat) return 404 and port 18789 is closed, AI providers are configured through Hermes instead of the gateway, ClawKeep archives the Hermes agent through the backup daemon's own backend rather than the openclaw CLI, and the CLI update path is refused in favour of Settings β†’ System Update. The MCP tool set differs too β€” app_search/app_install, the coding family and coordinate browser control are OpenClaw-only; skill_*, ai_* and memory_shard_search and hermes_plugins_reload are Hermes-only. See mcp/README.md for the authoritative tool matrix.

Hermes scans for its plugins once, when its process starts, and has no runtime reload, so a plugin installed or enabled after boot reached no chat at all β€” new sessions included. The box closes that itself: a watcher in the web server restarts the agent when the declared plugin set changes, POST /setup-api/hermes/plugins/reload (owner cookie or the MCP bearer) is the same thing asked for, and hermes_plugins_reload is what the assistant calls right after hermes plugins install/enable/disable/remove. No sudoers grant is added or needed β€” the restart is the unprivileged hermes dashboard --stop over a process the clawbox user owns, with Restart=always bringing it back, proved by a new main PID and the port answering again. The owner's open chat window drops with it; a desktop notice names the plugin and says to open a new one.

Full documentation: editions Β· switching editions.


How It Works

Layer 1 β€” System bootstrap. install.sh provisions the Jetson from scratch: system packages, Node.js 24 + Bun, the web OS build, the OpenClaw gateway (version-pinned), systemd services, mDNS, and the captive-portal WiFi access point for first-boot setup.

Layer 2 β€” Setup wizard. On first boot (or after factory reset) a guided ~5-minute wizard covers WiFi (with language picker), updates, device password, AI provider (ClawBox AI, an API key, or a subscription sign-in), and Telegram β€” see First Boot.

Layer 3 β€” Desktop environment. A Chrome OS-style desktop served from the device β€” the built-in apps above in draggable windows, with taskbar, system tray, a desktop mascot that opens the chat panel, and a responsive mobile layout. The terminal is xterm.js over a WebSocket PTY; remote desktop is noVNC.

Layer 4 β€” AI agent integration. The agent operates the device through MCP tools β€” shell, files, real-browser control, app installs, system power, preferences, email drafts you approve, picture and audio generation, and a code assistant that builds and deploys desktop webapps. It can also hand a whole coding task to the Coding Agent and steer that run while it works (coding_agent_run, coding_run_message). The clawbox-cli.ts wrapper (run through Bun) exposes the same surface to shell users. Full catalog: Agent Interface.

Layer 5 β€” The cloud your plan covers. On a box linked to ClawBox AI, speech-to-text, spoken replies and memory embeddings default to the service the plan already pays for instead of engines on the device β€” on every edition; the engines stay the fallback and stay selectable, and a choice made by hand is never overwritten. On the edition where ClawBox owns the memory index itself, the index talks to two addresses only, checked per request: the loopback embedder proxy on the device, or this box's own ClawBox AI endpoint. The matrix is in AI Providers.

Layer 6 β€” Reaching the box from outside. Settings β†’ Remote Control starts clawbox-tunnel.service. A provisioned box runs a named Cloudflare tunnel and answers on the same <boxHandle>.clawbox.tech address every time; the credential arrives over the portal heartbeat and is written to data/cloudflared/named-tunnel with mode 0600. With no credential, a refused token, or a named run that dies inside 60 seconds, it falls back to a Cloudflare quick tunnel and a random *.trycloudflare.com URL. data/cloudflared/tunnel.mode records which one is running. On your own network clawbox.local, the bare hostname, a Tailscale .ts.net name or a private LAN IP all work without any tunnel.


πŸ—οΈ Architecture

Browser (http://<box-ip>)
  β”‚   inbound firewall: default deny β€” only 22 / 80 / 443 / 18789 / 8090
  β”‚   reachable, and on IPv4 only from private ranges (10/8, 172.16/12,
  β”‚   192.168/16, 169.254/16, 100.64/10 for Tailscale)
  β”‚
  β”œβ”€β”€ Port 80: Next.js (production-server.js)                    ← open on the LAN
  β”‚     β”œβ”€β”€ /setup          β†’ Setup wizard (React SPA)
  β”‚     β”œβ”€β”€ /login          β†’ Authentication
  β”‚     β”œβ”€β”€ /               β†’ Desktop environment (post-setup)
  β”‚     β”œβ”€β”€ /setup-api/*    β†’ 217 API routes (system, files, coding agent, browser, …)
  β”‚     β”œβ”€β”€ /api/*          β†’ Proxy to OpenClaw gateway
  β”‚     └── WebSocket       β†’ Proxy to gateway + terminal PTY + noVNC
  β”‚
  β”œβ”€β”€ Port 3006: Terminal WebSocket PTY server                   ← closed to the LAN;
  β”‚        unauthenticated if reached directly, so it is only served through the
  β”‚        session-gated /terminal-ws proxy on port 80
  β”‚
  β”œβ”€β”€ Port 6080: noVNC WebSocket (remote desktop)                ← closed to the LAN;
  β”‚        reached through the /novnc-ws proxy on port 80
  β”‚
  β”œβ”€β”€ Port 18789: OpenClaw Gateway (token-gated)                 ← open on the LAN;
  β”‚        all user traffic still goes through port 80
  β”‚     β”œβ”€β”€ AI Agent (MCP tools β†’ controls the entire OS)
  β”‚     β”œβ”€β”€ Control UI
  β”‚     β”œβ”€β”€ WebSocket (real-time chat)
  β”‚     └── REST API
  β”‚
  └── Port 18800: Chromium CDP (browser automation)              ← closed to the LAN

Everything not in that allowlist (3006, 18800, 5900/6080 VNC, 11434 Ollama, 8081 the memory embedder, 631 CUPS, …) is unreachable from the network and keeps working over loopback β€” the terminal and noVNC reach your browser through the port-80 proxies. rpcbind (111) is disabled and masked, since nothing on a ClawBox speaks NFS/NIS β€” unless an NFS/NIS package is installed, in which case it is left running and merely firewalled. Also open: 5353/udp mDNS, so clawbox.local keeps resolving, plus DHCP and captive-portal DNS on the setup hotspot's own subnets; on Hermes/dual the dashboard proxy on 8090 is allowed from the same private ranges. Policy lives in scripts/clawbox-firewall.sh, and routing for the hotspot's internet sharing is unchanged.

Node.js runs the production server because Bun doesn't support http.Server upgrade events needed for WebSocket proxying. The deep dive lives in the Architecture reference.

πŸ› οΈ Tech Stack

Layer Technology
Frontend Next.js 16, React 19, Tailwind CSS 4
Language TypeScript 5
Runtime & tooling Node.js 24 (production), Bun (dev/build/packages)
AI Engine OpenClaw or Hermes Agent, via MCP
ClawBox AI DeepSeek V4 Flash by default (deepseek-v4-flash), DeepSeek 4.1 on the Max plan

ClawBox AI plans also cover image generation, cloud voice, voice transcription and memory indexing; the Coding Agent, Memory Shard and persistent <boxHandle>.clawbox.tech links need Pro or Max; the one-click OpenClaw/Hermes switch needs Max. | Local Models | llama.cpp (Gemma 4 E2B ships preinstalled) + Ollama Β· Kokoro TTS Β· faster-whisper STT Β· Qwen3 embeddings | | Coding Agent | Headless Claude Code (claude-ds) in a git worktree, gh for pull requests | | Backups | ClawKeep (Python) β†’ Cloudflare R2 | | Networking | NetworkManager (WiFi AP), Avahi (mDNS), cloudflared (named + quick tunnels) | | Testing | Vitest + Playwright |

Full runtime topology in the Architecture reference.

πŸ“ Project Structure

β”œβ”€β”€ bench/                  Model benchmark harness (suite, runner, pricing)
β”œβ”€β”€ clawkeep/               Backup agent (Python) + its systemd units
β”œβ”€β”€ config/                 Systemd services, captive-portal DNS
β”œβ”€β”€ docs/                   Internal specs, benchmarks and handoff notes
β”œβ”€β”€ docs-site/              docs.clawbox.com source (Mintlify)
β”œβ”€β”€ e2e/                    Playwright end-to-end specs
β”œβ”€β”€ e2e-install/            Full-install end-to-end suite (Docker)
β”œβ”€β”€ mcp/                    MCP server + CLI (AI agent interface to the OS)
β”œβ”€β”€ public/                 Static assets (icons, wallpapers, manifest)
β”œβ”€β”€ scripts/                WiFi AP, terminal server, voice/TTS, tunnels, firewall, Jetson tuning
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ app/                Next.js App Router (pages + 217 API routes)
β”‚   β”‚   └── setup-api/      WiFi, AI models, local AI, memory, coding agent, pets,
β”‚   β”‚                       channels, files, browser, portal/tunnel, update, system
β”‚   β”œβ”€β”€ components/         Setup wizard, desktop environment, built-in apps
β”‚   β”œβ”€β”€ hooks/              Window manager, local model management
β”‚   β”œβ”€β”€ lib/                Config, network, auth, OAuth, i18n, updater, chat, harness,
β”‚   β”‚                       coding agent, named tunnel, memory shard, code-projects
β”‚   β”œβ”€β”€ tests/              Unit, component and API route tests
β”‚   └── middleware.ts       Captive portal detection + session auth
β”œβ”€β”€ production-server.js    Node.js HTTP + WebSocket proxy wrapper
β”œβ”€β”€ install-x64.sh          x86_64 installer (host preflight, configurable ports)
└── install.sh              Full system installer (idempotent)

πŸ§ͺ Development

bun install
bun run dev              # Port 3000
bun run dev:privileged   # Port 80 (requires root)
bun run build
bun run lint
bun run test             # Unit + component tests (Vitest)
bun run test:e2e         # End-to-end tests (Playwright)
bun run check:mcp-tools  # Assert the MCP tool matrix matches mcp/README.md

Environment Variables

Variable Default Description
PORT 80 Web server port
GATEWAY_PORT 18789 OpenClaw gateway port
TERMINAL_WS_PORT 3006 Terminal WebSocket PTY port
NOVNC_WS_PORT 6080 noVNC WebSocket port (remote desktop)
NETWORK_INTERFACE wlP1p1s0 WiFi interface for AP
CANONICAL_ORIGIN http://clawbox.local Default redirect origin
ALLOWED_HOSTS clawbox.local,10.42.0.1,10.43.0.1,localhost Trusted hostnames
SESSION_SECRET Auto-generated Session cookie signing key, persisted in data/.session-secret
CLAWBOX_MCP_TOKEN Auto-generated Bearer token the MCP server uses on /setup-api, persisted in data/.mcp-token
OLLAMA_HOST http://127.0.0.1:11434 Ollama server URL
LLAMACPP_MODEL gemma4-e2b-it-q4_0 Bundled local model served by llama.cpp
CLAWBOX_ROOT /home/clawbox/clawbox Project root directory
CLAWBOX_CONTROL_UI_ORIGINS_FILE /home/clawbox/clawbox/data/control-ui-origins.json Extra trusted control UI origins (see below)

Additional options (OAuth client IDs, ClawBox AI, llama.cpp tuning) live in .env.example.

Trusted control UI origins

This is only for genuine cross-origin/custom-origin deployments β€” for example, a reverse proxy that serves the Control UI from a different hostname or port. Same-origin access via the box's own hostname β€” bare (http://clawbox/) or <hostname>.local β€” a Tailscale .ts.net name, or a private LAN IP already works out of the box (see ALLOWED_HOSTS above and the hostname/IP handling in src/lib/gateway-proxy.ts) and normally needs no entry here.

To trust an additional origin, put a JSON array of exact http/https origins in data/control-ui-origins.json (or the path set by CLAWBOX_CONTROL_UI_ORIGINS_FILE):

["https://control.example.com", "http://192.0.2.10:8080"]

Entries are validated strictly β€” no wildcards, credentials, paths, query strings, or fragments β€” and normalized (lowercased scheme/host, default ports dropped). Invalid entries are dropped with a warning; a missing file is normal and adds nothing. Matching is exact: a configured origin does not grant trust to the same hostname on a different scheme or port. See scripts/gateway_origins.py (loaded by gateway-pre-start.sh into the gateway's own allowedOrigins) and src/lib/control-ui-origins.ts (used by the Next.js proxy's redirect-origin reflection).

🀝 Contributing

Pull requests are welcome:

  • Target the beta branch β€” it's the integration branch; main carries tagged releases.
  • Every PR runs CI (unit tests + e2e + a full-install e2e) and an automated CodeRabbit review.
  • Keep PRs focused β€” one issue or feature per PR.
  • 🌍 The UI ships in 10 languages β€” a new string goes into every locale. The catalogues are split by area: src/lib/translations.ts, src/lib/desktop-translations*.ts, src/lib/clawkeep-translations.ts and src/lib/edition-translations/. A parity test fails if a locale is missing a key.

❓ Frequently asked questions

Who makes ClawBox? ClawBox is made by ID Robots Ltd., a robotics and AI company based in Plovdiv, Bulgaria (EU). ID Robots designs the hardware, builds OpenClaw OS (this repository), and provides all official support and warranty. Official site: clawbox.com.

What is the difference between ClawBox and OpenClaw? OpenClaw is the open-source AI agent. ClawBox is the dedicated hardware appliance that runs it 24/7, preconfigured, with OpenClaw OS on top β€” desktop environment, setup wizard, built-in apps, backups and updates. OpenClaw is the software; ClawBox is the box built for it by ID Robots.

Does ClawBox need a subscription? No. The hardware is a one-time purchase (€749). Optional ClawBox AI plans (Pro / Max) add higher usage limits, ClawKeep backups, Remote Desktop, Memory Shard, the Coding Agent and priority support β€” and you can instead bring your own Claude, GPT, Gemini or OpenRouter key, sign in with a subscription you already pay for, or run entirely on local models with no external account at all.

Does ClawBox work without internet? Yes, for local models. Gemma 4 E2B (gemma4-e2b-it-q4_0, a 3.1 GB Q4_0 build) ships preinstalled on the box's own llama.cpp, and on the OpenClaw and dual editions Local-only mode routes every request to it with the cloud providers switched off. Internet is needed only for updates, messaging integrations, browser automation, and optional cloud AI providers.

Which AI model answers by default? On ClawBox AI it is DeepSeek V4 Flash (deepseek-v4-flash), with a 1M-token context window. The Max plan uses DeepSeek 4.1. You can instead use your own Anthropic, OpenAI, Google or OpenRouter key, sign in with a Claude Pro/Max, ChatGPT Plus/Pro or Google One AI Premium subscription you already pay for, or stay entirely on the box.

What is the Coding Agent? A headless Claude Code run you hand a whole task to. It works in a git worktree copy of your project (<project>/.clawbox/worktrees/<runId>) so it never edits your checkout under you, opens a pull request with gh, and then runs an automatic review pass that adversarially reviews its own diff. Runs continue in the background, several can run at once, and you can send a message to one mid-flight to steer it. It needs a Pro or Max plan. Each run keeps its screenshots, test output and a report.md in its own evidence folder.

How do I reach my box from outside my network? Turn on Settings β†’ Remote Control. A provisioned box gets a persistent <boxHandle>.clawbox.tech address over a named Cloudflare tunnel, so it is the same URL every time. No Cloudflare account is needed. If the named credential is missing or refused, the box falls back to a quick tunnel with a random *.trycloudflare.com URL.

Where do I buy a ClawBox? Only from clawbox.com. ID Robots ships to 108 countries via DHL Express. Products sold elsewhere under a similar name are not ClawBox and are not covered by our warranty or support.

Can I run OpenClaw OS on my own Jetson? Yes β€” this repository is source-available and installs on an NVIDIA Jetson Orin Nano 8GB running JetPack 6.2. See Quick Start. Buying a ClawBox gets you the assembled, tested device with case, NVMe storage, warranty and support.


πŸ“„ License

ClawBox is released under the ClawBox Source Available License v1.0. Free to use, modify, and redistribute for personal, non-commercial purposes. Commercial use requires a separate license from IDRobots Ltd. β€” contact yanko@idrobots.com.


clawbox.com Β· docs.clawbox.com Β· Discord Β· yanko@idrobots.com

ClawBoxβ„’ β€” a private AI assistant appliance that runs OpenClaw. Designed, built and supported by ID Robots Ltd., Plovdiv, Bulgaria πŸ‡ͺπŸ‡Ί
Personal AI server Β· Local AI assistant hardware Β· NVIDIA Jetson Orin Nano Β· Edge AI appliance Β· Self-hosted AI Β· Powered by OpenClaw

About

🦞 ClawBox β€” Your private AI assistant on NVIDIA Jetson. Setup wizard, dashboard, and 580+ skills. Plug in, scan QR, done.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

30 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages