[ WHAT IS 1CLAW ]
Your agents get to act. The keys, the traffic and the money stay yours.
1Claw is secret management and secure infrastructure for AI agents: agents can use credentials, sign transactions and call APIs without ever seeing the keys.
1,000 requests a month, no card required.
[ WHAT YOU CAN DO ]
What people actually use it for
If the thing you are trying to do is on this list, you are in the right place.
Give a coding agent your API keys, safely
Claude Code, Cursor and anything else that speaks MCP can use your credentials without them sitting in a .env file or landing in a transcript.
Let an agent spend or trade without holding the keys
Sign on 109+ EVM chains plus Bitcoin, Solana, XRP, Cardano and Tron, behind allowlists, spend caps and simulation you set.
Call third-party APIs on a customer's behalf
Connect Slack, GitHub, Notion, Stripe, Google and more once; agents act through the connection and never see the token.
Stop a prompt injection from exfiltrating anything
Route LLM traffic through Shroud, which scores injection attempts, blocks exfiltration URLs and redacts secrets in both directions.
Run agents on a schedule, unattended
Automations and managed runtimes keep an agent working when nobody is watching, with the same limits applied.
Give your own users vaults and wallets
The Platform API and embedded wallets let you provision all of this for your customers under your own brand.
[ HOW IT WORKS ]
The agent never holds the credential
Most secrets managers assume a human or a trusted service is reading the secret. 1Claw assumes the agent might be compromised, so the credential never enters the agent's context, logs or memory.
Agents act through bindings, not keys
Credentials are injected server-side, so there is nothing in the prompt to leak.
Keys stay in hardware
HSM-backed envelope encryption, with optional MPC key splitting across GCP, AWS and Azure.
LLM traffic is inspected in a TEE
Shroud, an AMD SEV-SNP enclave proxy, scores prompt injection, blocks exfiltration URLs and redacts secrets in both directions.
Every permission traces to a human
Zero access by default, scoped policies, short-lived JWTs, a full audit trail, and instant revocation without rotating the secret.
Signing without custody
The Intents API signs transactions on 109+ EVM chains plus Bitcoin, Solana, XRP, Cardano and Tron, with allowlists, spend caps and simulation.
Native to the agent ecosystem
MCP server with 162 tools (Claude, Cursor, Windsurf and others), plus an SDK and CLI — set up with `npx @1claw/cli setup`.
The long version
1Claw is secure infrastructure for AI agents and the humans who run them. Instead of pasting API keys into prompts or .env files, teams store credentials in HSM-backed vaults (optionally split across GCP, AWS and Azure with MPC) and give each agent its own identity with scoped, revocable permissions. Agents get short-lived tokens and execute through server-side bindings, so credentials never appear in context windows, logs or memory. Shroud, a TEE proxy, inspects LLM traffic for prompt injection and secret leakage. The Intents API signs and broadcasts transactions across 109+ EVM chains plus Bitcoin, Solana, XRP, Cardano and Tron, within guardrails set by a human. It also includes automations, managed agent runtimes and embedded wallets, and works natively with Claude, Cursor and other MCP clients. There is a free tier of 1,000 requests a month, with no card required.
[ IS THIS FOR YOU ]
Where it earns its place
And where it does not — the last section is there to save you the trial.
You are building or running autonomous agents
Coding agents, support bots, research and data-pipeline agents — anything that needs a credential you would rather it never saw.
Your agent moves money
Trading, DeFi, payments or payouts, where signing authority has to be bounded and every action has to be accounted for.
You are shipping agents to your own customers
You need per-tenant vaults, wallets and identities you can provision programmatically, not a dashboard your users have to visit.
You have to show your work
SSO, CMEK, multi-HSM key splitting, policy engines and human approval steps, with an audit trail that holds up in review.
You probably need this if
- Your keys are in a .env file, a prompt, or pasted into a chat window
- An agent of yours can spend money or sign transactions
- You are weighing Doppler, HashiCorp Vault, 1Password, AWS Secrets Manager or Turnkey
When not to use 1Claw
Not for general key-value storage, non-secret application config, caching or ephemeral state, or hosting LLMs. If your problem is configuration rather than credentials an agent touches, a normal secrets manager is cheaper and simpler.
[ PRICING ]
What it costs
List prices. Anything currently on promotion is on the pricing page, which states live terms.
| Plan | Price | What you get |
|---|---|---|
| Free | $0 | 1,000 requests/mo, 3 vaults, 50 secrets, 2 agents, 100 on-chain signatures |
| Pro | $29/mo | 20k requests, 20k signatures, 1 runtime included, MPC 2-of-2 client custody, Platform API |
| Team | $299/mo | 200k requests, 200k signatures, SSO, 50 agents, 20 seats |
| Business | $999/mo | 1M requests and 1M signatures, multi-HSM MPC 2-of-3, Shroud, confidential compute runtimes |
The Intents API is on every plan including Free; signatures past the included amount are debited from prepaid credits, per signature. x402 pay-per-use on Base (USDC) is also available, and Shroud router-key traffic is billed at $0.005 per inspected request. Promotions are not listed here — see the pricing page for anything currently running.
Full comparison[ WHERE TO START ]
Everything, in one place
Including this page as JSON, if you would rather hand it to an agent than read it.
For developers and AI
npm: @1claw/sdk · @1claw/mcp · @1claw/cli
Reviewed 2026-09-29 · what-is-1claw.json