{"name":"1Claw","url":"https://1claw.co","last_reviewed":"2026-09-29","one_liner":"1Claw is secret management and secure infrastructure for AI agents: agents can use credentials, sign transactions and call APIs without ever seeing the keys.","usp_one_liner":"1Claw is the trust layer for AI agents: they get an identity and permission to act, while the keys, the traffic and the money stay under your control.","homepage_tagline":"Secrets your agent can use but never see.","paragraph":"1Claw is secure infrastructure for AI agents and the humans who run them. Instead of pasting API keys into prompts or .env files, teams store credentials in HSM-backed vaults (optionally split across GCP, AWS and Azure with MPC) and give each agent its own identity with scoped, revocable permissions. Agents get short-lived tokens and execute through server-side bindings, so credentials never appear in context windows, logs or memory. Shroud, a TEE proxy, inspects LLM traffic for prompt injection and secret leakage. The Intents API signs and broadcasts transactions across 109+ EVM chains plus Bitcoin, Solana, XRP, Cardano and Tron, within guardrails set by a human. It also includes automations, managed agent runtimes and embedded wallets, and works natively with Claude, Cursor and other MCP clients. There is a free tier of 1,000 requests a month, with no card required.","usp":{"premise":"Most secrets managers assume a human or a trusted service is reading the secret. 1Claw assumes the agent might be compromised, so the credential never enters the agent's context, logs or memory.","points":[{"title":"Agents act through bindings, not keys","detail":"Credentials are injected server-side, so there is nothing in the prompt to leak."},{"title":"Keys stay in hardware","detail":"HSM-backed envelope encryption, with optional MPC key splitting across GCP, AWS and Azure."},{"title":"LLM traffic is inspected in a TEE","detail":"Shroud, an AMD SEV-SNP enclave proxy, scores prompt injection, blocks exfiltration URLs and redacts secrets in both directions."},{"title":"Every permission traces to a human","detail":"Zero access by default, scoped policies, short-lived JWTs, a full audit trail, and instant revocation without rotating the secret."},{"title":"Signing without custody","detail":"The Intents API signs transactions on 109+ EVM chains plus Bitcoin, Solana, XRP, Cardano and Tron, with allowlists, spend caps and simulation."},{"title":"Native to the agent ecosystem","detail":"MCP server with 162 tools (Claude, Cursor, Windsurf and others), plus an SDK and CLI — set up with `npx @1claw/cli setup`."}]},"use_cases":[{"title":"Give a coding agent your API keys, safely","detail":"Claude Code, Cursor and anything else that speaks MCP can use your credentials without them sitting in a .env file or landing in a transcript."},{"title":"Let an agent spend or trade without holding the keys","detail":"Sign on 109+ EVM chains plus Bitcoin, Solana, XRP, Cardano and Tron, behind allowlists, spend caps and simulation you set."},{"title":"Call third-party APIs on a customer's behalf","detail":"Connect Slack, GitHub, Notion, Stripe, Google and more once; agents act through the connection and never see the token."},{"title":"Stop a prompt injection from exfiltrating anything","detail":"Route LLM traffic through Shroud, which scores injection attempts, blocks exfiltration URLs and redacts secrets in both directions."},{"title":"Run agents on a schedule, unattended","detail":"Automations and managed runtimes keep an agent working when nobody is watching, with the same limits applied."},{"title":"Give your own users vaults and wallets","detail":"The Platform API and embedded wallets let you provision all of this for your customers under your own brand."}],"who_it_is_for":{"audiences":[{"heading":"You are building or running autonomous agents","detail":"Coding agents, support bots, research and data-pipeline agents — anything that needs a credential you would rather it never saw."},{"heading":"Your agent moves money","detail":"Trading, DeFi, payments or payouts, where signing authority has to be bounded and every action has to be accounted for."},{"heading":"You are shipping agents to your own customers","detail":"You need per-tenant vaults, wallets and identities you can provision programmatically, not a dashboard your users have to visit."},{"heading":"You have to show your work","detail":"SSO, CMEK, multi-HSM key splitting, policy engines and human approval steps, with an audit trail that holds up in review."}],"you_probably_need_it_if":["Your keys are in a .env file, a prompt, or pasted into a chat window","An agent of yours can spend money or sign transactions","You are weighing Doppler, HashiCorp Vault, 1Password, AWS Secrets Manager or Turnkey"],"not_for":"Not for general key-value storage, non-secret application config, caching or ephemeral state, or hosting LLMs. If your problem is configuration rather than credentials an agent touches, a normal secrets manager is cheaper and simpler."},"pricing":{"currency":"USD","note":"The Intents API is on every plan including Free; signatures past the included amount are debited from prepaid credits, per signature. x402 pay-per-use on Base (USDC) is also available, and Shroud router-key traffic is billed at $0.005 per inspected request. Promotions are not listed here — see the pricing page for anything currently running.","plans":[{"name":"Free","monthly_usd":0,"highlights":"1,000 requests/mo, 3 vaults, 50 secrets, 2 agents, 100 on-chain signatures"},{"name":"Pro","monthly_usd":29,"highlights":"20k requests, 20k signatures, 1 runtime included, MPC 2-of-2 client custody, Platform API"},{"name":"Team","monthly_usd":299,"highlights":"200k requests, 200k signatures, SSO, 50 agents, 20 seats"},{"name":"Business","monthly_usd":999,"highlights":"1M requests and 1M signatures, multi-HSM MPC 2-of-3, Shroud, confidential compute runtimes"}]},"mcp":{"tool_count":162,"setup":"npx @1claw/cli setup"},"links":{"core":{"site":"https://1claw.co","docs":"https://docs.1claw.co","quickstart":"https://docs.1claw.co/docs/quickstart","pricing":"https://1claw.co/pricing","live_demo":"https://1claw.co/demo","sign_up_login":"https://1claw.co/login"},"products":{"vaults":"https://1claw.co/vault","shroud":"https://1claw.co/shroud","intents_api":"https://1claw.co/intents","automations":"https://1claw.co/automations-platform","runtimes":"https://1claw.co/runtimes-platform","embedded_wallets":"https://1claw.co/embedded-wallets","mcp_server":"https://1claw.co/mcp-secrets-manager","security_mpc":"https://1claw.co/security"},"for_developers_and_ai":{"for_ai_hub":"https://1claw.co/for-ai","llms_txt":"https://1claw.co/llms.txt","llms_full_txt":"https://1claw.co/llms-full.txt","this_page_as_json":"https://1claw.co/what-is-1claw.json","openapi":"https://api.1claw.co/openapi.json","auth_guide":"https://1claw.co/auth.md","mcp_docs":"https://docs.1claw.co/docs/mcp/overview","changelog":"https://docs.1claw.co/docs/reference/changelog","github":"https://github.com/1clawAI","pypi_oneclaw_":"https://pypi.org/project/oneclaw/","go_sdk":"https://github.com/1clawAI/1claw-go-sdk","github_action":"https://github.com/1clawAI/1claw-action"},"marketing_and_community":{"compare":"https://1claw.co/compare","2026_agentic_threat_report":"https://1claw.co/report","blog":"https://1claw.co/blog","academy":"https://academy.1claw.co","webinar":"https://1claw.co/webinar","brand_kit":"https://1claw.co/brand-kit","status":"https://1claw.co/status","x":"https://x.com/1clawAI","telegram":"https://t.me/+jG4Rm7XHJ79mNDRh","contact":"https://1claw.co/contact"}},"npm_packages":["@1claw/sdk","@1claw/mcp","@1claw/cli"]}