Clawvisor
Source available authorization gateway for AI agents that vaults credentials, limits each agent to the task a person approved, holds out of scope or risky calls for approval, and records every tool call in a replayable audit trail.
Clawvisor is an authorization gateway for AI agents. It sits between an agent and the services it uses, so the agent never holds a real credential: a person approves a task, meaning a declared purpose and the tool calls that purpose needs, and Clawvisor checks every later request against it.
Matching low-risk calls go straight through, with the real credential attached inside the gateway from an encrypted vault; out of scope or high-risk calls are held for a person to approve, and any service or action can be blocked outright. An LLM scores each task for blast radius and checks each request against the approved purpose, and access is revoked when the task ends. Every protected call is recorded with its arguments, the decision and the task and person that authorized it, in a replayable audit trail.
Fourteen adapters cover services such as Gmail, Google Calendar and Drive, GitHub, Slack, Notion, Linear, Stripe and Twilio, and teams can write their own for internal APIs. Agents connect through a skill, plain HTTP or an MCP server with OAuth 2.1. The gateway source is available under the Elastic License 2.0, so teams can self-host it free inside their own network with their own choice of model provider for the checks, or use the managed cloud, which adds longer log retention and org accounts. SAML and OIDC single sign-on ship for Enterprise orgs.
Clawvisor fits developers and teams letting agents act on real accounts who want each task's access scoped, approved and logged. It is a control layer, not an agent builder: it does not run workflows, ground agents in knowledge or give them memory. Its README describes the software as experimental and not audited for security, and no compliance attestation is published.
Vendor details
Canonical URL
https://clawvisor.com/
Category
Agent infrastructure
Subcategory
Authorization gateway for AI agent tool calls
Funding status
Independent. Backed by Y Combinator, per its homepage; round size not disclosed.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Fourteen service adapters (Gmail, Google Calendar, Drive and Contacts, GitHub, iMessage, Slack, Notion, Linear, Stripe, Twilio, Dropbox, Granola and Perplexity) execute the agent's requests with credentials injected from the vault, and customers can write their own adapters against the source; SendGrid, Jira, Salesforce and Airtable are listed as coming soon. Agents connect through a skill or plain HTTP (Claude Code, OpenClaw, any HTTP agent) or through an MCP server with OAuth 2.1 (Claude Desktop, Hermes).
In practice
An agent needs to triage your inbox but should never send mail. You approve a triage task that allows reading only, and Clawvisor lets reads through while any send attempt is held or blocked.
A prompt injection in a document tells your agent to email your customer list elsewhere. The request falls outside the approved purpose and scores high risk, so Clawvisor holds it for a person instead of executing it.
Security asks what your agents did last week. The audit trail shows every call, its arguments, the decision and the task and person that authorized it.
Sources & related URLs
Agentic Index coverage score
6.5 / 14 capabilities · 46%
| Integrations & Tool Calling | Full |
|---|---|
|
Clawvisor executes authenticated actions in outside systems on the agent's behalf. Fourteen service adapters cover Gmail, Google Calendar, Drive and Contacts; messaging through iMessage, Slack and Twilio; work tools in GitHub, Notion, Linear and Granola; and Stripe, Dropbox and Perplexity. Each takes the agent's requested action, attaches the real credential from the vault inside the gateway and returns the result, and customers can write their own adapters against the source for internal APIs. That is read, write and actionable integration, with credentials scoped per task and revoked when it ends. SendGrid, Jira, Salesforce and Airtable are listed as coming soon. SourceClawvisor, clawvisor.com/integrations and /faqread 2026-09-25 |
|
| Workflow Orchestration | Not documented |
|
Authorizing an agent's calls is the job here, not running its work. A task is the authorized unit of work (purpose, allowed tool calls and approver), with a lifecycle of approval, scope expansion and expiry, but the steps, their order and any handoffs between agents belong to the agent itself. That is an authorization lifecycle, not a workflow model. SourceClawvisor, clawvisor.com/faq and the README at github.com/clawvisor/clawvisorread 2026-09-25 |
|
| Knowledge Grounding & RAG | Not documented |
|
The product gates the agent's calls and indexes none of the customer's documents for an agent to ground its answers on. Chain-context extraction pulls identifiers from API responses for Clawvisor's own checks, which is not retrieval over the customer's corpus. SourceClawvisor, clawvisor.com/faqread 2026-09-25 |
|
| Human Oversight & Guardrails | Full |
|
A review and approve surface ships with the product. A person approves each task's declared purpose before the agent can act; calls outside that purpose, or that score high for blast radius, are held before they leave the gateway while the agent waits for a decision, and high or critical risk tasks need a confirmation step. Sending an iMessage always requires approval, any service or action can be blocked outright, pending approvals expire after a set timeout, and approvals can be made from the dashboard or a paired mobile device. SourceClawvisor, clawvisor.com/faq and /security, and the README at github.com/clawvisor/clawvisorread 2026-09-25 |
|
| Security, Identity & Governance | Partial |
|
Access controls are in place: SAML and OIDC single sign-on ship for Enterprise orgs, each agent authenticates to the gateway with its own bearer token, management API tokens are scoped, revocable and hashed at rest, and every tool call is limited to the task a person approved, with blocked lists of services and actions (least-privilege tool access). Compliance is missing: no SOC 2, ISO or other attestation is published, the security page asks buyers to verify claims by reading the public source, and the repository README warns that the software is experimental and has not been audited for security. No RBAC or ABAC model is named. SourceClawvisor, clawvisor.com/faq and /security, and the README at github.com/clawvisor/clawvisor (linked from clawvisor.com)read 2026-09-25 |
|
| Observability & Auditability | Full |
|
Every protected tool call is recorded with its action, arguments, policy decision and the task that authorized it, replayable and tied to the person who approved the work, alongside every purpose declaration and credential injection. Activity rolls up by task and approver, so a buyer sees which accounts each agent touched, and the web and terminal dashboards show it live. The managed cloud adds extended log retention on the Pro plan. That is step by step inspection of the agent's own tool calls, with an audit record. SourceClawvisor, clawvisor.com/security, /faq and /pricingread 2026-09-25 |
|
| Memory & State Persistence | Not documented |
|
The state kept is about the agent's authorization, not memory for the agent. Chain-context verification extracts structural facts (IDs, email addresses, phone numbers) from adapter results and feeds them into Clawvisor's own verification prompts for later steps, and standing tasks keep a grant open until revoked. Clawvisor applies both as rules; the agent never reads them as context to decide. No memory layer the agent reads is documented. SourceClawvisor, README at github.com/clawvisor/clawvisor and clawvisor.com/faqread 2026-09-25 |
|
| Deployment & Data Residency | Full |
|
Customers choose between a managed cloud and self hosting inside their own network from the public source (a gateway service plus a datastore for the vault and audit log), with the same purpose verification, risk scoring, vault and audit trail either way; self-hosted, credentials and traffic never leave the customer's network. The repository documents Docker, VPS, container platform and Cloud Run setups. The FAQ lists data residency options as future Enterprise work. SourceClawvisor, clawvisor.com/faq and /pricing, and the README at github.com/clawvisor/clawvisorread 2026-09-25 |
|
| Prebuilt Agents / Templates / Packs | Not documented |
|
No ready-made agents, workflows or templates ship with the product. Its fourteen service adapters are integrations rather than packs, and the installable skill only teaches an agent to route its calls through the gateway. SourceClawvisor, clawvisor.com/integrations and /faqread 2026-09-25 |
|
| Triggers & Channel Coverage | Not documented |
|
Clawvisor does not start agents. The agent calls the gateway; when a held request resolves or a task is approved, denied, expanded or expires, Clawvisor POSTs a callback to a URL the agent supplied. Those callbacks answer the agent's own requests rather than starting new work, so no event, schedule or channel wakes an agent. SourceClawvisor, README at github.com/clawvisor/clawvisorread 2026-09-25 |
|
| Model Flexibility & Routing | Full |
|
When self hosting, the operator picks the model behind Clawvisor's own AI checks (intent verification, task risk scoring and optional chain-context extraction): Anthropic, OpenAI, Google Vertex AI, Groq or a local Ollama model, set in the setup wizard or config. That is admin controlled model choice with the customer's own key. On the managed cloud the model is Clawvisor's choice, and the proxy-lite runtime that presents Anthropic and OpenAI compatible endpoints to agents is labeled preview. SourceClawvisor, clawvisor.com/faq and the README at github.com/clawvisor/clawvisorread 2026-09-25 |
|
| APIs / SDKs / MCP Extensibility | Full |
|
An HTTP API is documented for the platform itself: agents create tasks and send gateway requests with bearer tokens, a management API takes scoped, revocable API tokens so Terraform and CI can drive it, and a CLI manages the server, services and agents. It also serves an MCP server at /mcp with OAuth 2.1 and enumerated tools (fetch_catalog, create_task, get_task, complete_task, expand_task, gateway_request) that create and change its core objects. There is no SDK; agents connect through a skill or plain HTTP. SourceClawvisor, README at github.com/clawvisor/clawvisor (linked from clawvisor.com) and clawvisor.com/faqread 2026-09-25 |
|
| Testing, Debugging & Optimization | Not documented |
|
Evaluation suites exist for Clawvisor's own intent-verification model (179 cases across benign tasks, scope creep and adversarial prompts, 249 across all three checks), with results in the public repo that a customer can rerun. That measures Clawvisor's verifier, not the customer's agent. Nothing documented tests, scores or optimizes the customer's agent. SourceClawvisor, clawvisor.com/faqread 2026-09-25 |
|
| Browser / Computer-use | Not documented |
|
Clawvisor brokers API calls to services such as Gmail, GitHub and Slack and does not operate a browser or a computer; no browser or computer use capability is documented. SourceClawvisor, clawvisor.com and /integrationsread 2026-09-25 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Free 1,000 calls/mo · Pro $150/mo ($120/mo billed annually) · packs $0.025 a call · self-host free
protected calls (each agent request brokered through the gateway)
Included quota
1,000 protected calls a month on Free; 20,000 on Pro
What is public
Free and Pro plan prices, call allowances, pack prices and discounts, and the free self-hosting terms are public; Enterprise and tailored deployments are quoted.
Billing mechanics
Billed on protected calls: every agent request brokered through the gateway counts as one. Free includes 1,000 a month and Pro 20,000; request packs top up either plan, auto-reload can buy them with a monthly cap, and annual Pro billing saves 20%.
Cost watchouts
Self-hosting is free but runs on the operator's own infrastructure and needs an API key for an LLM provider to power purpose verification and risk scoring. The source is available under the Elastic License 2.0, which bars offering it to others as a hosted service. The README calls the software experimental and not audited for security.
Variable cost rationale
Cost scales with protected calls at $0.025 each past the plan allowance, but calls stop at zero unless auto-reload is on, and auto-reload can be capped per month, so spend is bounded.
Additional watchouts
Calls stop when the allowance and packs run out, which protects spend but can stall an agent unless auto-reload is on.
Overage / add-ons
Calls stop at zero until a request pack is bought, or auto-reload buys one; packs are $0.025 a call with up to 30% off on larger packs, and never expire
Sales call required
Mixed (some tiers require a call)
Free / trial
Free cloud plan with 1,000 protected calls a month and no credit card; self-hosting is free with no seat or call limits
Lowest paid plan
Pro, $150 a month or $120 a month billed annually, 20,000 protected calls included
Key ambiguities
Enterprise pricing (SSO, custom retention, tailored deployments) is by quote, and the page does not say what Teams adds beyond volume.
Missing data
Enterprise and Teams pricing.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Clawvisor
The closest documented capability profiles to Clawvisor among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Temporal Cortex8.0 / 14Adds documented Workflow Orchestration and Prebuilt Agents, Templates & Packs, among others
- Arcade7.5 / 14Adds documented Testing, Debugging & Optimization
- Dome Systems6.5 / 14Adds documented Testing, Debugging & OptimizationClawvisor vs Dome Systems →
- Helicone7.5 / 14Adds documented Triggers & Channel Coverage and Testing, Debugging & Optimization
- Portkey7.5 / 14Adds documented Testing, Debugging & Optimization
- AgentOps5.0 / 14Adds documented Testing, Debugging & Optimization
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded