Tool Calls 0
Files (OPFS)
Memory 0
Goals 0
Goals belong to this workspace, not the conversation: they stay after New conversation and reloads.
Event Stream 0
Skills 0
WebMCP Provider
Expose this workspace's memory, goals/tasks, agent status, and messaging as WebMCP tools via
document.modelContext, so an external agent or WebMCP-aware page can discover and drive clawser. Off by default — enabling grants tool access to any page/agent that can call document.modelContext in this tab.
Terminal
~
Dashboard
0
Requests
—
Tokens
0
Errors
—
Avg Latency
Servers
Tool Management
Agents
Channels 0
Tasks 0
Marketplace
Skill sources
Sources are extra places to find skills: a GitHub repo or an index URL you add. The built-in catalog below ships with Clawser and needs no source.
Swarms
Transfers
Devices
Mesh
Peers
Remote
Browser tasks
Configuration
-
History
-
Memory
-
Goals
-
Routines
Checking...
Off by default. When on, tools that pages register on
document.modelContext are offered to the
agent as webmcp_* tools. Their names and descriptions come from those pages, so they are labelled
as such and every call asks first (set a rule on webmcp.* in the MCP gate policy to change that).
The model provider you use will see the names of the sites and tools involved.
Globs match
server.tool. deny always blocks, approve asks first,
allow runs without asking. Otherwise read-only tools run, destructive tools ask
(or are blocked with denyDestructive) and tools that do not say ask unless
unannotated is allow. redact rewrites results.
Drag a panel's header out of the workspace to float it. Hold Shift while dragging a floating panel onto a tile to dock it there. Undo and redo layout changes with Ctrl or Cmd + Alt + Z (add Shift to redo).
Off by default. When on, opening, floating or arranging panels in one tab of this site does the same in your other tabs (the last change wins; pop-out windows stay with their tab).
to
Off by default. Before a write or network tool runs, a small decision model on this machine (Ollama
tev1 / nimble) rates whether the call is safe and what you asked for. Low scores are held for your review; nothing leaves the device. Without a local decision model the calls run as usual.
$0.00 / $5.00
30000
5
6
3
5
Hits: 0 · Misses: 0 · Tokens Saved: 0
Two tiers run code you did not review. Tier 1 (Worker) is for code you or the agent wrote on this device: it stops accidental access to the page and enforces a timeout, but it is not a security boundary (a determined script can still reach the network). Tier 2 (WASM) runs untrusted code (deployed and marketplace skills, Codex blocks) in QuickJS compiled to WebAssembly: no ambient network or storage,
host.call is its only authority, and the limits below are enforced. Threat model per tier
ERR_ANDBOX_FUEL_EXHAUSTED, ERR_ANDBOX_MEMORY_LIMIT or ERR_ANDBOX_DEADLINE; the same program always stops at the same fuel count.
Off by default. While this is off, Clawser contacts no mesh server at all and stays fully on-device; you lose only the ability to discover pods on other origins. Turning it on connects to the relay/signaling URLs above — by default
browsermesh-relay.fly.dev and browsermesh-signaling.fly.dev, operated by the Clawser author. Whoever runs those servers sees your pod's public key (did:key), your IP address, a re-announcement every 15 seconds while a tab is open, and which peers you connect to and when; the relay forwards the peer traffic itself. Point the fields above at your own browsermesh-servers deployment to avoid this.
There is no default STUN server. A STUN request is how your device learns its own public address, so whoever runs the server you enter here sees your IP address on every peer-connection attempt — pick one you trust (or run your own). With no STUN or TURN server configured, Clawser gathers local candidates only: peers on your own network still connect, no third party is contacted, and peers behind different NATs generally cannot connect until you add a STUN or TURN server above.
Off by default. Credits, payments and escrow are backed by a ledger that nothing can fund while this is off, so
escrow_create answers “ledger not enabled”. Turning it on runs a PBFT consensus validator in this tab and keeps the ledger in this browser's IndexedDB (per workspace), so a reload resumes from the last finalized block. Validators are bootstrapped from your mesh access-control admins, so it only agrees with pods you have made admins. Credits are internal metering units, not currency: a new ledger gives each genesis validator 100, and only the ledger owner (the pod that started it) can mint more (credits_grant, or Mesh / Ledger below). With fewer than 4 validators it is tamper-evident but tolerates no faulty validator. Takes effect when the mesh next starts (reload the page or switch workspace).
Mesh is not running
A persistent identity is the same peer after a reload, so the trust, group keys and ledger-validator seat other pods gave it still apply. Its private key never leaves this browser unsealed: your vault encrypts it at rest and it is non-extractable in memory. With the vault locked, or in a disposable session, the tab gets a throwaway identity instead.
Mesh is not running
Credits are internal metering units between your own pods, not currency. Nothing redeems them for money. With fewer than 4 validators the ledger is tamper-evident but tolerates no faulty validator; settlement against real money would be a later, server-side step. Spending credits counts against the autonomy cost ceilings (1 credit = 1 cent).
—
An invite names the ledger's owner, chain and validator keys (public keys only, no secrets). Join a ledger on another device by pasting its invite here; it takes effect when the mesh restarts, and the owner then approves this pod as a validator.
No-cloud blocks model-provider, fetch and signaling traffic to any host that is not on this device. List here the hosts that are yours (your wsh pod, an Ollama on your LAN); a leading dot matches every subdomain. Loopback is always allowed.
Pods that share this secret find each other through the signaling server under keyed aliases; the server sees no pod ID, SDP or candidate. It is a credential: anyone who has it can join your rendezvous. Copy it to your other devices (or pair by QR below). Clearing it makes the next start generate a new one.
Off by default: API keys and channel tokens are saved only in the encrypted vault, and saving one while the vault is locked is refused. Ticking this lets a locked or missing vault fall back to plain
localStorage, which any script running on this origin can read. Secrets already in the vault stay there.
Connect two devices by showing one a code the other scans, then the reply back. The WebRTC offer and answer travel as signed optical artifacts (animated QR); nothing goes to a server. The peer proves its pod ID over the new channel by signing exactly this pairing, and both screens show a safety code to compare. Pairing grants no access. At Relay-blind and above it needs a TURN server, like every connection.
On by default. Each connection negotiates a fresh key (hybrid post-quantum when the peer supports it) before opening a remote shell/exec session, so a relay in the middle cannot read the session. If the peer doesn't support E2E, the connection attempt fails with a clear error instead of silently falling back to plaintext; untick this to connect to a server that cannot do E2E.
On by default. A tool call from a remote wsh peer asks you first, for every tool, including read-only ones. Untick it and remote peers may call read and internal tools without asking; every other tool still asks, even at full autonomy. Takes effect immediately.
Opt-in, off by default. When enabled, this browser subscribes to Web Push and sends the subscription to any relay it's actively reverse-registered with — the relay can then notify you (title/body only, no message contents) about a pending mesh message or due scheduled task instead of silently failing when every tab is closed.
A real Linux guest, emulated in this tab (v86; downloaded the first time you boot it). Unlike the Demo Linux (simulated) runtime listed under Remote, which is only a simulation, this runs actual Linux binaries. Nothing starts until you press Boot.
Not running.