Simple, secure, reliable agents. Self-hosted. Open source. Built with .NET.
See the code
Run your own agent.
Simple, secure, reliable agents.
Website · Documentation · Releases · Discord
Netclaw is an open-source, self-hosted autonomous operations agent that runs anywhere — from a Raspberry Pi to a cloud VM. Built on Akka.NET, the actor framework from Petabridge, it's designed for anyone who wants an AI operations agent with strong safety defaults and as few moving parts as possible.
Your data stays on your infrastructure. Your agent keeps running when a provider changes their pricing. You control what gets approved and what runs autonomously — small models welcome.
Other agents go for feature breadth and release velocity. We went a different route: simplicity (readable code, minimal config footprint), security (approval gates and audience dispositions built in, not bolted on after incidents), and reliability (curated skill feeds managed by your org, not an unaudited public marketplace).
Learn more at netclaw.dev.
Netclaw runs as a daemon plus a thin CLI:
netclawd — the daemon. It hosts LLM sessions, runs tools, and handles
persistence. Start it once and it stays up.netclaw — the CLI. Talk to the daemon, manage config, run commands.
It connects over a local socket.Start the daemon, then use the CLI. Remote devices can pair with the daemon over Tailscale or Cloudflare Tunnel.
samples/Netclaw.Demo.AppHost is a self-contained .NET Aspire demo that
brings up NetClaw + Mattermost + Ollama with seeded credentials in a
single command — no Slack workspace, no API keys, no external accounts.
See samples/Netclaw.Demo.AppHost/README.md.
dotnet run --project samples/Netclaw.Demo.AppHost
Linux (installs CLI + daemon to ~/.netclaw/bin):
curl -sSL https://releases.netclaw.dev/install.sh | bash
# Install only the CLI or only the daemon
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- cli
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- daemon
# Opt into the beta channel (newest prerelease, or latest stable if none)
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- --channel beta
# Pin a specific version (e.g. a prerelease)
NETCLAW_VERSION=0.17.1 curl -sSL https://releases.netclaw.dev/install.sh | bash
# Install without modifying your shell profile
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- --skip-shell
By default, the Unix installer updates the detected Bash, zsh, or fish startup
configuration so new shells include Netclaw on PATH.
macOS (Apple Silicon — M1 or later — installs CLI + daemon to ~/.netclaw/bin):
curl -sSL https://releases.netclaw.dev/install.sh | bash
The cli / daemon / NETCLAW_VERSION options shown above for Linux work the
same way on macOS. Auto-starting the daemon as a background service is not yet
available on macOS (#1015)
— run it manually with netclaw daemon start.
Windows (installs to %LOCALAPPDATA%\Programs\netclaw):
iwr -useb https://releases.netclaw.dev/install.ps1 | iex
The installer adds Netclaw to your User PATH. The -Component cli|daemon,
-Channel beta, -Version, and -SkipShell options work the same way as their
Linux counterparts (download the script and run it with the flag).
Docker (multi-arch: amd64/arm64):
docker run -d --name netclawd \
-p 5199:5199 \
-v ~/.netclaw:/home/netclaw/.netclaw \
-e NETCLAW_Daemon__Host=0.0.0.0 \
-e NETCLAW_Daemon__ExposureMode=reverse-proxy \
-e NETCLAW_Daemon__TrustedProxies__0=172.16.0.0/12 \
ghcr.io/netclaw-dev/netclaw:latest
Use ghcr.io/netclaw-dev/netclaw:beta to track the newest prerelease, or a pinned
tag like :0.19.0-beta.1. :latest only ever points at the latest stable release.
See the Docker deployment guide for volume setup, environment variables, and Docker Compose examples.
Netclaw publishes opt-in beta builds so you can test an upcoming release early.
Stable installs are never affected — the default curl | sh, Docker :latest, and
the GitHub "Latest" release always point at the newest stable. The beta channel
follows the newest prerelease and automatically rolls onto a stable release once it
supersedes the beta.
# Linux / macOS — newest prerelease (falls back to latest stable if none is open)
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- --channel beta
# Windows — download, then run with -Channel beta
iwr -useb https://releases.netclaw.dev/install.ps1 -OutFile install.ps1
./install.ps1 -Channel beta
# Docker — :beta tracks the newest prerelease (:latest stays on stable)
docker pull ghcr.io/netclaw-dev/netclaw:beta
To pin an exact build instead of following the channel, name the version directly:
NETCLAW_VERSION=0.19.0-beta.1 (Linux/macOS), -Version 0.19.0-beta.1 (Windows), or
the :0.19.0-beta.1 image tag (Docker).
For the full installation reference (including building from source), see the installation docs.
Run the guided setup wizard:
netclaw init
Or create the config manually. The daemon reads layered config from
~/.netclaw/config/:
~/.netclaw/config/netclaw.json — base settings (minimal Ollama example):
{
"configVersion": 1,
"Providers": {
"local-ollama": {
"Type": "ollama",
"Endpoint": "http://localhost:11434"
}
},
"Models": {
"Main": { "Provider": "local-ollama", "ModelId": "qwen3:30b" }
}
}
Credentials are stored encrypted in ~/.netclaw/config/secrets.json. Use the
CLI to manage them — never edit that file by hand:
netclaw secrets set Providers.openrouter.ApiKey sk-or-v1-...
netclaw secrets set Slack.BotToken xoxb-...
All settings can also be overridden via environment variables using the
NETCLAW_ prefix with double-underscore separators for nested keys:
export NETCLAW_Providers__local-ollama__Endpoint=http://localhost:11434
export NETCLAW_Models__Main__ModelId=qwen3:8b
For the full configuration reference, see the configuration docs.
netclaw doctor # Check config schema, provider connectivity, secrets
netclaw doctor --fix # Auto-apply safe fixes
# Start the daemon (background process)
netclaw daemon start
# Check daemon status
netclaw daemon status
# Interactive chat (connects to running daemon)
netclaw chat
# Single-prompt mode (non-interactive)
netclaw chat -p "What's on my calendar today?"
# Stop the daemon
netclaw daemon stop
For the full quickstart walkthrough, see the quickstart guide.
Netclaw connects to your team's existing communication channels:
ghcr.io/netclaw-dev/netclaw)netclaw daemon install creates a user-level serviceNetclaw is default-deny from the ground up. The daemon requires explicit configuration before it will execute tools, connect to channels, or accept remote connections.
Full CLI documentation is available at netclaw.dev/cli.
netclaw init First-run setup wizard
netclaw chat Interactive TUI chat
netclaw chat -p <text> Headless single-prompt mode
netclaw doctor Configuration diagnostics
netclaw daemon start|stop|status Manage the daemon process
netclaw daemon install Install systemd user service (Linux)
netclaw daemon pair Generate a pairing code for remote access
netclaw provider Manage LLM providers
netclaw model Manage model assignments
netclaw mcp Manage MCP server profiles
netclaw skill Manage skills and skill sources
netclaw reminder Manage scheduled reminders
netclaw webhooks Manage inbound webhook routes
netclaw secrets set <k> <v> Manage encrypted secrets
netclaw update Check for and install updates
netclaw version Show CLI version
Visit netclaw.dev/docs for the full documentation, including:
See CONTRIBUTING.md for development workflows, build
instructions, project structure, and contributor tooling.
Netclaw is licensed under the Apache License, Version 2.0.
See LICENSE for the full text.
Built with care by Petabridge. Visit netclaw.dev for documentation, guides, and community resources.
956 followers · starred Jun 2026
1,705 followers · starred May 2026
C#
94.5%
Shell
2.9%
Python
1.4%
Simple, secure, reliable agents. Self-hosted. Open source. Built with .NET.
See the code
Run your own agent.
Simple, secure, reliable agents.
Website · Documentation · Releases · Discord
Netclaw is an open-source, self-hosted autonomous operations agent that runs anywhere — from a Raspberry Pi to a cloud VM. Built on Akka.NET, the actor framework from Petabridge, it's designed for anyone who wants an AI operations agent with strong safety defaults and as few moving parts as possible.
Your data stays on your infrastructure. Your agent keeps running when a provider changes their pricing. You control what gets approved and what runs autonomously — small models welcome.
Other agents go for feature breadth and release velocity. We went a different route: simplicity (readable code, minimal config footprint), security (approval gates and audience dispositions built in, not bolted on after incidents), and reliability (curated skill feeds managed by your org, not an unaudited public marketplace).
Learn more at netclaw.dev.
Netclaw runs as a daemon plus a thin CLI:
netclawd — the daemon. It hosts LLM sessions, runs tools, and handles
persistence. Start it once and it stays up.netclaw — the CLI. Talk to the daemon, manage config, run commands.
It connects over a local socket.Start the daemon, then use the CLI. Remote devices can pair with the daemon over Tailscale or Cloudflare Tunnel.
samples/Netclaw.Demo.AppHost is a self-contained .NET Aspire demo that
brings up NetClaw + Mattermost + Ollama with seeded credentials in a
single command — no Slack workspace, no API keys, no external accounts.
See samples/Netclaw.Demo.AppHost/README.md.
dotnet run --project samples/Netclaw.Demo.AppHost
Linux (installs CLI + daemon to ~/.netclaw/bin):
curl -sSL https://releases.netclaw.dev/install.sh | bash
# Install only the CLI or only the daemon
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- cli
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- daemon
# Opt into the beta channel (newest prerelease, or latest stable if none)
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- --channel beta
# Pin a specific version (e.g. a prerelease)
NETCLAW_VERSION=0.17.1 curl -sSL https://releases.netclaw.dev/install.sh | bash
# Install without modifying your shell profile
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- --skip-shell
By default, the Unix installer updates the detected Bash, zsh, or fish startup
configuration so new shells include Netclaw on PATH.
macOS (Apple Silicon — M1 or later — installs CLI + daemon to ~/.netclaw/bin):
curl -sSL https://releases.netclaw.dev/install.sh | bash
The cli / daemon / NETCLAW_VERSION options shown above for Linux work the
same way on macOS. Auto-starting the daemon as a background service is not yet
available on macOS (#1015)
— run it manually with netclaw daemon start.
Windows (installs to %LOCALAPPDATA%\Programs\netclaw):
iwr -useb https://releases.netclaw.dev/install.ps1 | iex
The installer adds Netclaw to your User PATH. The -Component cli|daemon,
-Channel beta, -Version, and -SkipShell options work the same way as their
Linux counterparts (download the script and run it with the flag).
Docker (multi-arch: amd64/arm64):
docker run -d --name netclawd \
-p 5199:5199 \
-v ~/.netclaw:/home/netclaw/.netclaw \
-e NETCLAW_Daemon__Host=0.0.0.0 \
-e NETCLAW_Daemon__ExposureMode=reverse-proxy \
-e NETCLAW_Daemon__TrustedProxies__0=172.16.0.0/12 \
ghcr.io/netclaw-dev/netclaw:latest
Use ghcr.io/netclaw-dev/netclaw:beta to track the newest prerelease, or a pinned
tag like :0.19.0-beta.1. :latest only ever points at the latest stable release.
See the Docker deployment guide for volume setup, environment variables, and Docker Compose examples.
Netclaw publishes opt-in beta builds so you can test an upcoming release early.
Stable installs are never affected — the default curl | sh, Docker :latest, and
the GitHub "Latest" release always point at the newest stable. The beta channel
follows the newest prerelease and automatically rolls onto a stable release once it
supersedes the beta.
# Linux / macOS — newest prerelease (falls back to latest stable if none is open)
curl -sSL https://releases.netclaw.dev/install.sh | bash -s -- --channel beta
# Windows — download, then run with -Channel beta
iwr -useb https://releases.netclaw.dev/install.ps1 -OutFile install.ps1
./install.ps1 -Channel beta
# Docker — :beta tracks the newest prerelease (:latest stays on stable)
docker pull ghcr.io/netclaw-dev/netclaw:beta
To pin an exact build instead of following the channel, name the version directly:
NETCLAW_VERSION=0.19.0-beta.1 (Linux/macOS), -Version 0.19.0-beta.1 (Windows), or
the :0.19.0-beta.1 image tag (Docker).
For the full installation reference (including building from source), see the installation docs.
Run the guided setup wizard:
netclaw init
Or create the config manually. The daemon reads layered config from
~/.netclaw/config/:
~/.netclaw/config/netclaw.json — base settings (minimal Ollama example):
{
"configVersion": 1,
"Providers": {
"local-ollama": {
"Type": "ollama",
"Endpoint": "http://localhost:11434"
}
},
"Models": {
"Main": { "Provider": "local-ollama", "ModelId": "qwen3:30b" }
}
}
Credentials are stored encrypted in ~/.netclaw/config/secrets.json. Use the
CLI to manage them — never edit that file by hand:
netclaw secrets set Providers.openrouter.ApiKey sk-or-v1-...
netclaw secrets set Slack.BotToken xoxb-...
All settings can also be overridden via environment variables using the
NETCLAW_ prefix with double-underscore separators for nested keys:
export NETCLAW_Providers__local-ollama__Endpoint=http://localhost:11434
export NETCLAW_Models__Main__ModelId=qwen3:8b
For the full configuration reference, see the configuration docs.
netclaw doctor # Check config schema, provider connectivity, secrets
netclaw doctor --fix # Auto-apply safe fixes
# Start the daemon (background process)
netclaw daemon start
# Check daemon status
netclaw daemon status
# Interactive chat (connects to running daemon)
netclaw chat
# Single-prompt mode (non-interactive)
netclaw chat -p "What's on my calendar today?"
# Stop the daemon
netclaw daemon stop
For the full quickstart walkthrough, see the quickstart guide.
Netclaw connects to your team's existing communication channels:
ghcr.io/netclaw-dev/netclaw)netclaw daemon install creates a user-level serviceNetclaw is default-deny from the ground up. The daemon requires explicit configuration before it will execute tools, connect to channels, or accept remote connections.
Full CLI documentation is available at netclaw.dev/cli.
netclaw init First-run setup wizard
netclaw chat Interactive TUI chat
netclaw chat -p <text> Headless single-prompt mode
netclaw doctor Configuration diagnostics
netclaw daemon start|stop|status Manage the daemon process
netclaw daemon install Install systemd user service (Linux)
netclaw daemon pair Generate a pairing code for remote access
netclaw provider Manage LLM providers
netclaw model Manage model assignments
netclaw mcp Manage MCP server profiles
netclaw skill Manage skills and skill sources
netclaw reminder Manage scheduled reminders
netclaw webhooks Manage inbound webhook routes
netclaw secrets set <k> <v> Manage encrypted secrets
netclaw update Check for and install updates
netclaw version Show CLI version
Visit netclaw.dev/docs for the full documentation, including:
See CONTRIBUTING.md for development workflows, build
instructions, project structure, and contributor tooling.
Netclaw is licensed under the Apache License, Version 2.0.
See LICENSE for the full text.
Built with care by Petabridge. Visit netclaw.dev for documentation, guides, and community resources.
956 followers · starred Jun 2026
1,705 followers · starred May 2026
C#
94.5%
Shell
2.9%
Python
1.4%