Initializing agent...
Tool Calls 0
Files (OPFS)
Memory 0
Goals 0

Goals belong to this workspace, not the conversation: they stay after New conversation and reloads.

Event Stream 0
Skills 0
WebMCP Provider
Expose this workspace's memory, goals/tasks, agent status, and messaging as WebMCP tools via document.modelContext, so an external agent or WebMCP-aware page can discover and drive clawser. Off by default — enabling grants tool access to any page/agent that can call document.modelContext in this tab.
Terminal
~
Dashboard
0
Requests
—
Tokens
0
Errors
—
Avg Latency
Servers
Tool Management
Agents
Channels 0
Tasks 0
Marketplace
Skill sources

Sources are extra places to find skills: a GitHub repo or an index URL you add. The built-in catalog below ships with Clawser and needs no source.

Swarms
Transfers
Devices
Mesh
Peers
Remote
Browser tasks
Configuration
-
History
-
Memory
-
Goals
-
Jobs
Checking...
Off by default. When on, tools that pages register on document.modelContext are offered to the agent as webmcp_* tools. Their names and descriptions come from those pages, so they are labelled as such and every call asks first (set a rule on webmcp.* in the MCP gate policy to change that). The model provider you use will see the names of the sites and tools involved.
Globs match server.tool. deny always blocks, approve asks first, allow runs without asking. Otherwise read-only tools run, destructive tools ask (or are blocked with denyDestructive) and tools that do not say ask unless unannotated is allow. redact rewrites results.
Drag a panel's header out of the workspace to float it. Hold Shift while dragging a floating panel onto a tile to dock it there. Undo and redo layout changes with Ctrl or Cmd + Alt + Z (add Shift to redo).
Off by default. When on, opening, floating or arranging panels in one tab of this site does the same in your other tabs (the last change wins; pop-out windows stay with their tab).
to
Off by default. Before a write or network tool runs, a small decision model on this machine (Ollama tev1 / nimble) rates whether the call is safe and what you asked for. Low scores are held for your review; nothing leaves the device. Without a local decision model the calls run as usual.
$0.00 / $5.00
30000
5
6
3
5
Hits: 0 · Misses: 0 · Tokens Saved: 0
Two tiers run code you did not review. Tier 1 (Worker) is for code you or the agent wrote on this device: it stops accidental access to the page and enforces a timeout, but it is not a security boundary (a determined script can still reach the network). Tier 2 (WASM) runs untrusted code (deployed and marketplace skills, Codex blocks) in QuickJS compiled to WebAssembly: no ambient network or storage, host.call is its only authority, and the limits below are enforced. Threat model per tier
Applies to sandboxes created after you change it. Exhausting a limit stops the code with ERR_ANDBOX_FUEL_EXHAUSTED, ERR_ANDBOX_MEMORY_LIMIT or ERR_ANDBOX_DEADLINE; the same program always stops at the same fuel count.
Disconnected
Off by default. While this is off, Clawser contacts no mesh server at all and stays fully on-device; you lose only the ability to discover pods on other origins. Turning it on connects to the relay/signaling URLs above — by default browsermesh-relay.fly.dev and browsermesh-signaling.fly.dev, operated by the Clawser author. Whoever runs those servers sees your pod's public key (did:key), your IP address, a re-announcement every 15 seconds while a tab is open, and which peers you connect to and when; the relay forwards the peer traffic itself. Point the fields above at your own browsermesh-servers deployment to avoid this.
There is no default STUN server. A STUN request is how your device learns its own public address, so whoever runs the server you enter here sees your IP address on every peer-connection attempt — pick one you trust (or run your own). With no STUN or TURN server configured, Clawser gathers local candidates only: peers on your own network still connect, no third party is contacted, and peers behind different NATs generally cannot connect until you add a STUN or TURN server above.
Off by default. Credits, payments and escrow are backed by a ledger that nothing can fund while this is off, so escrow_create answers “ledger not enabled”. Turning it on runs a PBFT consensus validator in this tab and keeps the ledger in this browser's IndexedDB (per workspace), so a reload resumes from the last finalized block. Validators are bootstrapped from your mesh access-control admins, so it only agrees with pods you have made admins. Credits are internal metering units, not currency: a new ledger gives each genesis validator 100, and only the ledger owner (the pod that started it) can mint more (credits_grant, or Mesh / Ledger below). With fewer than 4 validators it is tamper-evident but tolerates no faulty validator. Takes effect when the mesh next starts (reload the page or switch workspace).
Mesh is not running
A persistent identity is the same peer after a reload, so the trust, group keys and ledger-validator seat other pods gave it still apply. Its private key never leaves this browser unsealed: your vault encrypts it at rest and it is non-extractable in memory. With the vault locked, or in a disposable session, the tab gets a throwaway identity instead.
Nothing here is a second key. The wsh fingerprint, the podId and the dialback identity are one SHA-256 of the same public key; the ledger address and the QR-pairing signer are the key itself.
Mesh is not running
Credits are internal metering units between your own pods, not currency. Nothing redeems them for money. With fewer than 4 validators the ledger is tamper-evident but tolerates no faulty validator; settlement against real money would be a later, server-side step. Spending credits counts against the autonomy cost ceilings (1 credit = 1 cent).
—
        An invite names the ledger's owner, chain and validator keys (public keys only, no secrets). Join a ledger on another device by pasting its invite here; it takes effect when the mesh restarts, and the owner then approves this pod as a validator.
        Published and fetched shares are kept in this browser's storage. Publishing or fetching past the quota fails; unpinned fetched copies are evicted first, least recently used.
        Off by default. A public share is served to any peer connected to you over the mesh that asks for it by CID, with no per-peer grant. Shares published as “granted” are only ever served to peers you grant. Turning this off stops serving public shares immediately. Shares travel only between clawser pods over the mesh; nothing is announced to IPFS, BitTorrent or any tracker unless you configure one below and ask for it.
        One trustless gateway per line (https; plain http only for a gateway on this machine). Privacy: a gateway you list sees the CID you ask for and your IP address. Fetched content is checked against its CID in this browser, so a gateway can refuse or stall but cannot hand you altered bytes. Used only by share_fetch / the Shares panel for a CID or ipfs:// link that no peer on the mesh has; refused at the No-cloud and Stealth privacy levels. This tab reads from IPFS only; pinning to IPFS needs a host you own over wsh.
        One WSS tracker per line (wss://; plain ws:// only for a tracker on this machine). Used by share_publish {torrent: true} / the Shares panel to seed a share as a torrent, and by share_fetch for a magnet: link; a magnet’s own trackers and web seeds are never contacted. A tab has no DHT, TCP or uTP, so only other browser peers (and hybrid hosts you run) can connect. Privacy: a tracker and every peer it introduces see the torrent’s info hash and your IP address. Refused at the No-cloud and Stealth privacy levels. Each tracker contact is counted in Settings → Privacy. WebRTC to those peers uses only the STUN/TURN server you set under Mesh / Relay (none by default, so only directly reachable peers connect).
          No-cloud blocks model-provider, fetch and signaling traffic to any host that is not on this device. List here the hosts that are yours (your wsh pod, an Ollama on your LAN); a leading dot matches every subdomain. Loopback is always allowed.
          Pods that share this secret find each other through the signaling server under keyed aliases; the server sees no pod ID, SDP or candidate. It is a credential: anyone who has it can join your rendezvous. Copy it to your other devices (or pair by QR below). Clearing it makes the next start generate a new one.
          Off by default: API keys and channel tokens are saved only in the encrypted vault, and saving one while the vault is locked is refused. Ticking this lets a locked or missing vault fall back to plain localStorage, which any script running on this origin can read. Secrets already in the vault stay there.
          Connect two devices by showing one a code the other scans, then the reply back. The WebRTC offer and answer travel as signed optical artifacts (animated QR); nothing goes to a server. The peer proves its pod ID over the new channel by signing exactly this pairing, and both screens show a safety code to compare. Pairing grants no access. At Relay-blind and above it needs a TURN server, like every connection.
          Counts destination hostnames only (never paths or contents) for the fetch tool, the built-in model-provider calls and the first-hop URL of any page the agent asks the browser extension to open (not that page’s own requests, redirects or later clicks). It does not yet cover WebSocket/wsh/relay/signaling connections, WebRTC (STUN/TURN/peers), MCP servers, channels or CDN module loads. It records; at the No-cloud and Stealth privacy levels it also blocks what it covers.
          On by default. Each connection negotiates a fresh key (hybrid post-quantum when the peer supports it) before opening a remote shell/exec session, so a relay in the middle cannot read the session. If the peer doesn't support E2E, the connection attempt fails with a clear error instead of silently falling back to plaintext; untick this to connect to a server that cannot do E2E.
          On by default. A tool call from a remote wsh peer asks you first, for every tool, including read-only ones. Untick it and remote peers may call read and internal tools without asking; every other tool still asks, even at full autonomy. Takes effect immediately.
          Opt-in, off by default. When enabled, this browser subscribes to Web Push and sends the subscription to any relay it's actively reverse-registered with — the relay can then notify you (title/body only, no message contents) about a pending mesh message or due scheduled task instead of silently failing when every tab is closed.
          A real Linux guest, emulated in this tab (v86; downloaded the first time you boot it). Unlike the Demo Linux (simulated) runtime listed under Remote, which is only a simulation, this runs actual Linux binaries. Nothing starts until you press Boot.
          Not running.