# TrustClaw: a self-hosted personal AI agent that trades local control for a managed sandbox

> TrustClaw is a Vercel-deployable TypeScript agent with pgvector memory, Composio's OAuth tool broker and a Telegram bot. The interesting part is not the feature list, it is the decision to move code execution and credentials off your machine.

**ComposioHQ/trustclaw** — A self-hostable personal AI agent with vector memory, Composio tools, and Telegram.

- Repository: https://github.com/ComposioHQ/trustclaw
- Stars: 901 · Forks: 209
- Language: TypeScript
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/composiohq-trustclaw

## The problem TrustClaw picks: local agents with plaintext keys and a shell on your laptop

Most personal agent projects assume you will run them on the machine you use. That means the agent's credentials sit in a local config file, its tool calls execute in your shell, and a prompt injection arriving through a scraped email has the same filesystem access you do. TrustClaw is written as a direct answer to that. The README frames the comparison in a table: credentials encrypted and managed by Composio rather than plaintext in local config, code execution in a remote sandbox rather than on your machine, integrations through OAuth rather than manual API key setup per app, and a full action log with one-click revocation.

The audience is narrow and identifiable. You want an assistant that runs on a schedule, reads your Gmail or Linear or Calendar, and messages you on Telegram, but you do not want to hand it a shell on the hardware where your SSH keys live. TrustClaw is for that person. It is not for someone who wants the agent to rename files in a local directory, because by design it cannot reach them.

## How a TrustClaw agent run actually flows

The repository diagram shows three entrypoints converging on the same Next.js app: the web dashboard, the Telegram bot, and cron. All three go through a tRPC API and an agent runtime, and the README names the sequence as prepareAgentRun followed by ToolLoopAgent. From there the runtime fans out to four dependencies: Postgres with pgvector, Redis, the Vercel AI Gateway, and Composio.

The split matters. Postgres holds conversation state and the vector memory. Redis is optional and backs resumable streams, streaming state, abort flags and the agent rate limits; the .env.example states that when REDIS_URL is blank, resumable streams are disabled but basic streaming still works. The AI Gateway handles both LLM and embedding calls, which is why the README says no Anthropic or OpenAI API keys are required. Composio is the tool layer, and the README describes 1000+ integrations gated by the user's connected accounts, meaning the agent only sees tools you have already authorized through OAuth.

Memory is where the design gets specific. TrustClaw advertises a three-layer context management scheme: pruning, memory flush, and summarization compaction. The stated goal is conversations that can run indefinitely. That is a claim about context window management rather than about retrieval quality, and the README does not give numbers for either.

## Installing TrustClaw with the CLI and getting to a first Telegram message

The README gives two deployment paths. The Vercel template button is the one-click route; the CLI is the one the README calls out with a single command. The prerequisites are a Vercel account with `npx vercel login` completed once, a GitHub account with `gh auth login` completed once, and a free Composio API key.

```bash
npx @composio/trustclaw deploy
```

The README states the CLI handles the entire flow. Before running it you need two secrets, and the .env.example gives the exact generation command:

```bash
openssl rand -base64 32
```

Run that twice, once for BETTER_AUTH_SECRET and once for CRON_SECRET. The Composio key comes from the developer dashboard linked in the README, and the Composio CLI itself installs with:

```bash
curl -fsSL https://composio.dev/install | bash
```

The remaining variables are DATABASE_URL (Postgres with pgvector enabled, and the README notes Neon's free tier works), COMPOSIO_API_KEY, and optionally TELEGRAM_BOT_TOKEN, TELEGRAM_BOT_USERNAME and TELEGRAM_WEBHOOK_SECRET, which you obtain from @BotFather. The .env.example is explicit that Telegram features are disabled when those are blank. For local development the AI Gateway needs either `vercel link && vercel env pull` for a short-lived OIDC token, or a manually set AI_GATEWAY_API_KEY. On Vercel deployments the README says the gateway authenticates automatically via VERCEL_OIDC_TOKEN.

If you would rather run the stack locally, the package scripts include `pnpm dev` for `next dev --turbo` and `pnpm build`, which runs `prisma generate`, then `prisma db push --accept-data-loss`, then `next build`. Note that `--accept-data-loss` flag before you point it at a database you care about.

## The Vercel Hobby ceiling is the real constraint

This is the part of the README that deserves the most attention, and it is unusually candid. TrustClaw runs on Vercel's free Hobby plan, but two platform limits shape what the agent can do there. Cron jobs can only run once per day, and they fire anywhere within a 60-minute window of the scheduled hour. Any cron expression more frequent than daily fails at deploy time on Hobby. The CLI compensates by auto-adjusting vercel.json to a daily schedule when it detects Hobby.

The second limit is duration: functions are capped at 300 seconds, so long-running agent turns may time out. Upgrading to Vercel Pro changes both, giving per-minute cron precision and up to 800 seconds per function, after which you re-run the CLI or manually set vercel.json back to `* * * * *` and raise maxDuration.

The practical reading is that "works while you sleep" on Hobby means one scheduled run per day, not an hourly watcher. If your recurring task is a morning inbox digest, that is fine. If it is a check every fifteen minutes, TrustClaw on the free tier is the wrong shape, and the README says so rather than hiding it behind a pricing page.

## Rate limiting, fail mode, and the public-internet warning

TrustClaw ships Redis-backed per-user rate limiting on the chat, cron and Telegram entrypoints, enabled by default. The knobs are RATE_LIMIT_CHAT_PER_MINUTE, RATE_LIMIT_CHAT_PER_DAY, RATE_LIMIT_CRON_PER_DAY, RATE_LIMIT_TELEGRAM_PER_MINUTE and RATE_LIMIT_FAIL_MODE, with RATE_LIMIT_ENABLED=false to bypass all agent entrypoint limits. The defaults documented in .env.example are 20 chat messages per minute, 500 chat messages per day, 100 cron runs per day, and 20 Telegram messages per minute per user.

RATE_LIMIT_FAIL_MODE defaults to open in development and closed otherwise. That is the correct default, but it creates a dependency: in production, if Redis is unreachable and fail mode is closed, agent entrypoints stop working. The README's instruction for production is to configure REDIS_URL or explicitly set RATE_LIMIT_FAIL_MODE=open or RATE_LIMIT_ENABLED=false. Choosing either of those two overrides means giving up the limit that protects you.

The README also carries a warning worth repeating: if you put an instance on the public internet for strangers to sign up to, add at least a monthly per-user message or tool-call cap enforced server-side, plus billing or invite-only access. TrustClaw has username and password login via Better Auth, but the README does not describe an invite system or a billing integration, so that gap is yours to close.

## TrustClaw versus OpenClaw and other local-first agents

The README positions TrustClaw as built on the ideas behind OpenClaw but rebuilt from scratch for security, and the search data around this project shows people comparing the two directly. The difference is architectural rather than feature-level. A local-first agent like OpenClaw runs on your hardware, which means it can read and write local files, run shell commands, and work without a cloud account. TrustClaw gives that up. Its README states plainly that there is no long-lived shell access and no code running on your machine, so a destructive prompt injection cannot delete your laptop's files because the agent has no shell there.

The cost of that trade is real. A remote sandbox is gone when the task is done, per the README, so anything the agent produces has to come back through a tool integration or a message. Local file manipulation, running a build, editing a document on disk: none of that is in scope. You also inherit Vercel's cron and function-duration limits, and you depend on Composio for both OAuth brokering and tool coverage. If Composio does not have an integration for the service you need, TrustClaw does not have it either.

The counterargument for choosing TrustClaw is credential handling. Comparing a system that brokers OAuth for every tool against one where you paste API keys into a config file is not a close call for an agent that reads your email on a schedule.

## Licence, maintenance and what upgrading costs you

TrustClaw is MIT licensed, stated in both the README and package.json, with Composio listed as the author. MIT means you can fork, modify and self-host without a copyleft obligation; it says nothing about the terms of the services the project depends on, and those are separate agreements. Composio, Vercel, Neon, Upstash and any LLM routed through the AI Gateway each carry their own pricing and acceptable-use terms. The repository's own LICENSE file is the authoritative text, and nothing here is legal advice.

The repository is not archived, and the last push was on 2026-07-10. There are no retrieved releases, and package.json still carries version 0.1.0, so the project is pre-1.0 and versioned accordingly. Upgrading means tracking a moving main branch rather than pinning releases, and the build script's `prisma db push --accept-data-loss` is the part to watch: it applies schema changes directly, and the flag name tells you what happens to data that does not fit the new schema. If you self-host, back up Postgres before running a build against a database with real conversations in it.

## Conclusion

Adopt TrustClaw if you want a personal agent whose tool calls run in a remote sandbox and whose credentials live with Composio rather than in a local config file, and if a daily cron cadence on Vercel Hobby is acceptable. Do not adopt it if you need per-minute scheduled runs without paying for Vercel Pro, or if you want the agent to touch files on your own machine, which its security model deliberately prevents. Verify first that your Postgres provider has pgvector enabled, that you have generated BETTER_AUTH_SECRET and CRON_SECRET with openssl rand -base64 32, and that you understand the RATE_LIMIT_FAIL_MODE default before exposing a signup page to strangers.

## FAQ

### How does TrustClaw compare with OpenClaw?

The README says TrustClaw is built on the ideas behind OpenClaw but rebuilt from scratch for security. The concrete differences it lists are OAuth-brokered credentials managed by Composio instead of plaintext local config, remote sandbox execution instead of running code on your machine, and a full action log with one-click revocation.

### Do I need Anthropic or OpenAI API keys to run TrustClaw?

No. The README states that LLM and embedding calls route through Vercel AI Gateway and that no Anthropic or OpenAI API keys are required. For local development you either run `vercel link && vercel env pull` to get a short-lived OIDC token or set AI_GATEWAY_API_KEY manually.

### Can TrustClaw run tasks on a schedule?

Yes, the README lists cron-scheduled agent runs for recurring tasks and shows cron as one of the three entrypoints in the architecture diagram. On Vercel's free Hobby plan, however, cron jobs can only run once per day and any more frequent expression fails at deploy time.

### What database does TrustClaw need for its memory?

Postgres with the pgvector extension enabled, according to the .env.example, which notes that Neon's free tier works. The README describes long-term memory as backed by Postgres plus pgvector.

## Sources

- [ComposioHQ/trustclaw on GitHub](https://github.com/ComposioHQ/trustclaw)
- [Issues](https://github.com/ComposioHQ/trustclaw/issues)
- [License: MIT](https://github.com/ComposioHQ/trustclaw/blob/main/LICENSE)
- [README](https://github.com/ComposioHQ/trustclaw/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/composiohq-trustclaw
