Back to vendors
C

Clawvisor

Visit site
Entry priceFree 1,000 calls/mo · Pro $150/mo ($120/mo billed annually) · packs $0.025 a call · self-host freeFull pricing detail

Source available authorization gateway for AI agents that vaults credentials, limits each agent to the task a person approved, holds out of scope or risky calls for approval, and records every tool call in a replayable audit trail.

Clawvisor is an authorization gateway for AI agents. It sits between an agent and the services it uses, so the agent never holds a real credential: a person approves a task, meaning a declared purpose and the tool calls that purpose needs, and Clawvisor checks every later request against it.

Matching low-risk calls go straight through, with the real credential attached inside the gateway from an encrypted vault; out of scope or high-risk calls are held for a person to approve, and any service or action can be blocked outright. An LLM scores each task for blast radius and checks each request against the approved purpose, and access is revoked when the task ends. Every protected call is recorded with its arguments, the decision and the task and person that authorized it, in a replayable audit trail.

Fourteen adapters cover services such as Gmail, Google Calendar and Drive, GitHub, Slack, Notion, Linear, Stripe and Twilio, and teams can write their own for internal APIs. Agents connect through a skill, plain HTTP or an MCP server with OAuth 2.1. The gateway source is available under the Elastic License 2.0, so teams can self-host it free inside their own network with their own choice of model provider for the checks, or use the managed cloud, which adds longer log retention and org accounts. SAML and OIDC single sign-on ship for Enterprise orgs.

Clawvisor fits developers and teams letting agents act on real accounts who want each task's access scoped, approved and logged. It is a control layer, not an agent builder: it does not run workflows, ground agents in knowledge or give them memory. Its README describes the software as experimental and not audited for security, and no compliance attestation is published.

Vendor details

Canonical URL

https://clawvisor.com/

Category

Agent infrastructure

Subcategory

Authorization gateway for AI agent tool calls

Funding status

Independent. Backed by Y Combinator, per its homepage; round size not disclosed.

Company status

independent

Use cases & customers

Primary use cases

Agent credential vaultingPurpose based authorization for agentsHuman approval and guardrails for agent tool callsAudit and spend attribution for agents

Target customers

Developers building AI agentsTeams deploying agents against real dataEnterprises needing agent governance

Deployment options

SaaSSelf-hostedOn-premises

Integrations

Fourteen service adapters (Gmail, Google Calendar, Drive and Contacts, GitHub, iMessage, Slack, Notion, Linear, Stripe, Twilio, Dropbox, Granola and Perplexity) execute the agent's requests with credentials injected from the vault, and customers can write their own adapters against the source; SendGrid, Jira, Salesforce and Airtable are listed as coming soon. Agents connect through a skill or plain HTTP (Claude Code, OpenClaw, any HTTP agent) or through an MCP server with OAuth 2.1 (Claude Desktop, Hermes).

In practice

An agent needs to triage your inbox but should never send mail. You approve a triage task that allows reading only, and Clawvisor lets reads through while any send attempt is held or blocked.

A prompt injection in a document tells your agent to email your customer list elsewhere. The request falls outside the approved purpose and scores high risk, so Clawvisor holds it for a person instead of executing it.

Security asks what your agents did last week. The audit trail shows every call, its arguments, the decision and the task and person that authorized it.

Agentic Index coverage score

6.5 / 14 capabilities · 46%

Integrations & Tool Calling Full

Clawvisor executes authenticated actions in outside systems on the agent's behalf. Fourteen service adapters cover Gmail, Google Calendar, Drive and Contacts; messaging through iMessage, Slack and Twilio; work tools in GitHub, Notion, Linear and Granola; and Stripe, Dropbox and Perplexity.

Each takes the agent's requested action, attaches the real credential from the vault inside the gateway and returns the result, and customers can write their own adapters against the source for internal APIs. That is read, write and actionable integration, with credentials scoped per task and revoked when it ends. SendGrid, Jira, Salesforce and Airtable are listed as coming soon.

SourceClawvisor, clawvisor.com/integrations and /faqread 2026-09-25

Workflow Orchestration Not documented

Authorizing an agent's calls is the job here, not running its work. A task is the authorized unit of work (purpose, allowed tool calls and approver), with a lifecycle of approval, scope expansion and expiry, but the steps, their order and any handoffs between agents belong to the agent itself. That is an authorization lifecycle, not a workflow model.

SourceClawvisor, clawvisor.com/faq and the README at github.com/clawvisor/clawvisorread 2026-09-25

Knowledge Grounding & RAG Not documented

The product gates the agent's calls and indexes none of the customer's documents for an agent to ground its answers on. Chain-context extraction pulls identifiers from API responses for Clawvisor's own checks, which is not retrieval over the customer's corpus.

SourceClawvisor, clawvisor.com/faqread 2026-09-25

Human Oversight & Guardrails Full

A review and approve surface ships with the product. A person approves each task's declared purpose before the agent can act; calls outside that purpose, or that score high for blast radius, are held before they leave the gateway while the agent waits for a decision, and high or critical risk tasks need a confirmation step. Sending an iMessage always requires approval, any service or action can be blocked outright, pending approvals expire after a set timeout, and approvals can be made from the dashboard or a paired mobile device.

SourceClawvisor, clawvisor.com/faq and /security, and the README at github.com/clawvisor/clawvisorread 2026-09-25

Security, Identity & Governance Partial

Access controls are in place: SAML and OIDC single sign-on ship for Enterprise orgs, each agent authenticates to the gateway with its own bearer token, management API tokens are scoped, revocable and hashed at rest, and every tool call is limited to the task a person approved, with blocked lists of services and actions (least-privilege tool access).

Compliance is missing: no SOC 2, ISO or other attestation is published, the security page asks buyers to verify claims by reading the public source, and the repository README warns that the software is experimental and has not been audited for security. No RBAC or ABAC model is named.

SourceClawvisor, clawvisor.com/faq and /security, and the README at github.com/clawvisor/clawvisor (linked from clawvisor.com)read 2026-09-25

Observability & Auditability Full

Every protected tool call is recorded with its action, arguments, policy decision and the task that authorized it, replayable and tied to the person who approved the work, alongside every purpose declaration and credential injection. Activity rolls up by task and approver, so a buyer sees which accounts each agent touched, and the web and terminal dashboards show it live. The managed cloud adds extended log retention on the Pro plan. That is step by step inspection of the agent's own tool calls, with an audit record.

SourceClawvisor, clawvisor.com/security, /faq and /pricingread 2026-09-25

Memory & State Persistence Not documented

The state kept is about the agent's authorization, not memory for the agent. Chain-context verification extracts structural facts (IDs, email addresses, phone numbers) from adapter results and feeds them into Clawvisor's own verification prompts for later steps, and standing tasks keep a grant open until revoked. Clawvisor applies both as rules; the agent never reads them as context to decide. No memory layer the agent reads is documented.

SourceClawvisor, README at github.com/clawvisor/clawvisor and clawvisor.com/faqread 2026-09-25

Deployment & Data Residency Full

Customers choose between a managed cloud and self hosting inside their own network from the public source (a gateway service plus a datastore for the vault and audit log), with the same purpose verification, risk scoring, vault and audit trail either way; self-hosted, credentials and traffic never leave the customer's network. The repository documents Docker, VPS, container platform and Cloud Run setups. The FAQ lists data residency options as future Enterprise work.

SourceClawvisor, clawvisor.com/faq and /pricing, and the README at github.com/clawvisor/clawvisorread 2026-09-25

Prebuilt Agents / Templates / Packs Not documented

No ready-made agents, workflows or templates ship with the product. Its fourteen service adapters are integrations rather than packs, and the installable skill only teaches an agent to route its calls through the gateway.

SourceClawvisor, clawvisor.com/integrations and /faqread 2026-09-25

Triggers & Channel Coverage Not documented

Clawvisor does not start agents. The agent calls the gateway; when a held request resolves or a task is approved, denied, expanded or expires, Clawvisor POSTs a callback to a URL the agent supplied. Those callbacks answer the agent's own requests rather than starting new work, so no event, schedule or channel wakes an agent.

SourceClawvisor, README at github.com/clawvisor/clawvisorread 2026-09-25

Model Flexibility & Routing Full

When self hosting, the operator picks the model behind Clawvisor's own AI checks (intent verification, task risk scoring and optional chain-context extraction): Anthropic, OpenAI, Google Vertex AI, Groq or a local Ollama model, set in the setup wizard or config. That is admin controlled model choice with the customer's own key. On the managed cloud the model is Clawvisor's choice, and the proxy-lite runtime that presents Anthropic and OpenAI compatible endpoints to agents is labeled preview.

SourceClawvisor, clawvisor.com/faq and the README at github.com/clawvisor/clawvisorread 2026-09-25

APIs / SDKs / MCP Extensibility Full

An HTTP API is documented for the platform itself: agents create tasks and send gateway requests with bearer tokens, a management API takes scoped, revocable API tokens so Terraform and CI can drive it, and a CLI manages the server, services and agents. It also serves an MCP server at /mcp with OAuth 2.1 and enumerated tools (fetch_catalog, create_task, get_task, complete_task, expand_task, gateway_request) that create and change its core objects. There is no SDK; agents connect through a skill or plain HTTP.

SourceClawvisor, README at github.com/clawvisor/clawvisor (linked from clawvisor.com) and clawvisor.com/faqread 2026-09-25

Testing, Debugging & Optimization Not documented

Evaluation suites exist for Clawvisor's own intent-verification model (179 cases across benign tasks, scope creep and adversarial prompts, 249 across all three checks), with results in the public repo that a customer can rerun. That measures Clawvisor's verifier, not the customer's agent. Nothing documented tests, scores or optimizes the customer's agent.

SourceClawvisor, clawvisor.com/faqread 2026-09-25

Browser / Computer-use Not documented

Clawvisor brokers API calls to services such as Gmail, GitHub and Slack and does not operate a browser or a computer; no browser or computer use capability is documented.

SourceClawvisor, clawvisor.com and /integrationsread 2026-09-25

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Free 1,000 calls/mo · Pro $150/mo ($120/mo billed annually) · packs $0.025 a call · self-host free

protected calls (each agent request brokered through the gateway)

Free tier

Included quota

1,000 protected calls a month on Free; 20,000 on Pro

What is public

Free and Pro plan prices, call allowances, pack prices and discounts, and the free self-hosting terms are public; Enterprise and tailored deployments are quoted.

Billing mechanics

Billed on protected calls: every agent request brokered through the gateway counts as one. Free includes 1,000 a month and Pro 20,000; request packs top up either plan, auto-reload can buy them with a monthly cap, and annual Pro billing saves 20%.

Cost watchouts

Self-hosting is free but runs on the operator's own infrastructure and needs an API key for an LLM provider to power purpose verification and risk scoring. The source is available under the Elastic License 2.0, which bars offering it to others as a hosted service. The README calls the software experimental and not audited for security.

Variable cost rationale

Cost scales with protected calls at $0.025 each past the plan allowance, but calls stop at zero unless auto-reload is on, and auto-reload can be capped per month, so spend is bounded.

Additional watchouts

Calls stop when the allowance and packs run out, which protects spend but can stall an agent unless auto-reload is on.

Overage / add-ons

Calls stop at zero until a request pack is bought, or auto-reload buys one; packs are $0.025 a call with up to 30% off on larger packs, and never expire

Sales call required

Mixed (some tiers require a call)

Free / trial

Free cloud plan with 1,000 protected calls a month and no credit card; self-hosting is free with no seat or call limits

Lowest paid plan

Pro, $150 a month or $120 a month billed annually, 20,000 protected calls included

Key ambiguities

Enterprise pricing (SSO, custom retention, tailored deployments) is by quote, and the page does not say what Teams adds beyond volume.

Missing data

Enterprise and Teams pricing.

Agentic Index verified 2026-09-25

Alternatives to Clawvisor

The closest documented capability profiles to Clawvisor among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Temporal Cortex8.0 / 14Adds documented Workflow Orchestration and Prebuilt Agents, Templates & Packs, among others
  • Arcade7.5 / 14Adds documented Testing, Debugging & Optimization
  • Dome Systems6.5 / 14Adds documented Testing, Debugging & OptimizationClawvisor vs Dome Systems →
  • Helicone7.5 / 14Adds documented Triggers & Channel Coverage and Testing, Debugging & Optimization
  • Portkey7.5 / 14Adds documented Testing, Debugging & Optimization
  • AgentOps5.0 / 14Adds documented Testing, Debugging & Optimization

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.