Model or dataset
poco-ai/poco-claw avatar
poco-ai/poco-claw

Poco declares version 0.1.0 while its newest release is 0.5.7

A more beautiful and easier-to-use alternative to OpenClaw. It features a nicer Web UI, built-in IM support, a sandboxed runtime and channel-based team collaboration. Under the hood, it is powered by a Claude Code–based agent.

1,353 stars130 forksPythonMIT

At a glance

What is it?
Poco is a self hosted agent platform: a Next.js frontend, a FastAPI backend, a separate executor and an executor manager, all started by one shell script, with tasks running inside container sandboxes. The Python manifest declares an empty dependency list, the compose stack defaults its database to postgres with the password postgres on a published host port, and the memory feature the page leads with sits behind a compose profile that is off by default.
Who is it for?
The architecture is worth reading even if the defaults are not ready to copy. A frontend, a backend, an executor and an executor manager split into four processes, tasks isolated in containers, memory delegated to mem0 rather than hand rolled, and configuration collected in a single env file is a sane shape for this kind of tool.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 11 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 3, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The Python manifest declares an empty dependency list

The project manifest reads `name = "Poco"`, `version = "0.1.0"`, `requires-python = ">=3.12"` and then `dependencies = []`. That last line is the interesting one for a platform whose whole job is orchestrating an agent runtime: the manifest declares nothing to install. The real set is not hidden so much as held elsewhere, because `uv.lock` sits at the top level and the repository is split into three Python roots, `backend/`, `executor/` and `executor_manager/`, with a separate `frontend/` beside them. Both configured type and lint tools target exactly those three directories and both exclude `backend/assets`, so the split is deliberate rather than incidental. The consequence for a reader is that pyproject.toml describes intent, not installation, and the dependency graph has to be read out of the lock file and the Docker images instead. The manifest also gives the project its lineage in one sentence, describing Poco as a cloud based agent execution platform inspired by Anthropic's Cowork that orchestrates agents to do work beyond coding, while the repository description says the same thing differently, as an OpenClaw alternative powered by an agent built on Claude Code.

The Star History badge and the wiki link resolve to a differently named repository

The page carries at least five names for one project. The repository is `poco-ai/poco-claw`, the package calls itself Poco, the page title reads Poco: Your Pocket Coworker, and the repository description frames it as an alternative to OpenClaw. Then two of its own links leave the repository: the Star History badge points at `poco-ai/poco-agent`, and the DeepWiki badge points at `deepwiki.com/poco-ai/poco-agent` as well. The China mirror at the bottom of the page is the one that keeps the current name, at `gitcode.com/poco-ai/poco-claw`, and it credits that mirror with giving mainland China users faster access to the project and its releases. Documentation is split the same way, with a `docs.poco-ai.com` deployment guide linked from the quick start while the repository homepage field points at a Vercel address. The page also ships in two languages, with a Chinese README linked beside the English one, and its badge row names the stack it expects: Docker, Python, Next.js and FastAPI.

Postgres ships the password postgres and publishes 5432 on the host

The first service in the compose file is `postgres:16-alpine` with `restart: unless-stopped`, a named volume, and environment defaults for the database name, the user and the password, all of which fall back to `postgres` unless a `.env` file overrides them. The port mapping is `${POSTGRES_PORT:-5432}:5432`, so the database is published on the host by default, and the healthcheck runs `pg_isready` every five seconds with twenty retries. A second Postgres exists for the memory subsystem, and it is not the official image: it is `ankane/pgvector:v0.5.1`, given a 128MB shared memory size and exposed on `${MEM0_POSTGRES_EXPOSE_PORT:-8432}:5432`, with its own user, password and database defaults that are also all `postgres`. Two databases, two published ports, and default credentials in both, is the first thing to change before the stack is reachable by anything but the host.

The mem0 memory subsystem is behind a compose profile and never starts by default

The page leads its memory bullet with the word mem0, and the compose file has three services for it: `mem0-postgres` built on the pgvector image, `mem0-neo4j` on `neo4j:5.26.4`, and the vector store the README describes as the agent's memory of preferences, project context and past interactions. Both services carry `profiles: ["mem0"]`, which is the compose mechanism for keeping a service off until it is named on the command line. Nothing in the quick start names it. The quick start is one script:

bash
./scripts/quickstart.sh

followed by a browser at `http://localhost:3000`. So the memory feature advertised in the feature list is not part of the default run, and the two databases it needs are two more containers a user has to ask for by hand. The Neo4j defaults are worth reading closely as well: authentication falls back to `neo4j` and `mem0graph`, both the HTTP port 7474 and the bolt port 7687 are published on the host, and the healthcheck tolerates a sixty second start period. The service also loads the `apoc` plugin and sets `NEO4J_apoc_export_file_enabled` to true, and it uses `restart: on-failure` where the main database uses `unless-stopped`, so the memory tier stays down unless it is asked for and does not come back on a clean stop.

The env example ships two secrets that say change this in production

`.env.example` is organised by purpose rather than by service, and it marks its own required fields. The model configuration is the required part: `ANTHROPIC_API_KEY` with no default, an optional base URL whose comment names the official endpoint and, for compatible services, a provider endpoint such as a proxy or gateway address, a `DEFAULT_MODEL` line commented out with a concrete model id, and a `MODEL_LIST` entry described as a JSON array for the model picker in the interface. Then a section headed SECURITY: CHANGE THESE IN PRODUCTION, holding `BACKEND_SECRET_KEY=change-this-secret-key-in-production` for JWT signing and `INTERNAL_API_TOKEN=change-this-token-in-production` for service to service calls, followed by a note to use a `__Host-` prefixed session cookie name under HTTPS. The placeholders are honest about being placeholders, which puts the burden of changing them on whoever deploys.

A second compose file named for object storage sits at the root with no explanation

The top level holds two compose files, `docker-compose.yml` and `docker-compose.r2.yml`, and the page explains only the first. The name points at R2, which is how the object storage tier is usually referred to, so the file is a variant for a different storage backend rather than a copy. Nothing on the page says when to use it, what changes between the two, or whether the sandboxed tasks write artifacts somewhere different under it. The same gap runs through the rest of the layout: `start-dev.sh` and `stop-dev.sh` sit at the root next to `scripts/`, `docker/`, `docs/` and `specs/`, and four instruction files for tooling and contributors, `CLAUDE.md`, `AGENTS.md`, `COMMIT.md` and `CONTRIBUTING.md`, have no index anywhere. A `.pre-commit-config.yaml` and a `.prettierignore` cover checks for both halves of the codebase, since the frontend is JavaScript and the backend is Python. The deployment guide is the documented place for these questions, hosted at `docs.poco-ai.com`.

The release line stopped in June and the manifest never moved past 0.1.0

Three releases are on record: 0.5.7 dated 2026-06-18, v0.5.6 dated 2026-06-13 and v0.5.5 dated 2026-06-12. Two things are odd about that list. The newest release is titled 0.5.7 while the two before it are titled with the v prefix, so the naming convention changed on the most recent tag. And the last push to the repository is dated 2026-09-22, roughly three months after the newest release, so the commits that follow it have not been packaged. Set against both of those, `version = "0.1.0"` in pyproject.toml is a third number for the same project. The feature list is where the three months of unreleased work would show up, and it is long: channel and direct message collaboration with threads, an artifacts viewer for HTML, PDF, Markdown, images, video, Xmind, Excalidraw and Drawio files, a playback view that replays command output and tool calls, MCP and Skills, a built-in browser, GitHub repository integration, background execution with scheduled triggers, and IM bridges to DingTalk, Feishu and Telegram. For anyone pinning a version, none of the three numbers agrees with the others, and the page marks the hosted offering as coming soon while the self hosted Docker path is the documented one.

Editorial conclusion

The architecture is worth reading even if the defaults are not ready to copy. A frontend, a backend, an executor and an executor manager split into four processes, tasks isolated in containers, memory delegated to mem0 rather than hand rolled, and configuration collected in a single env file is a sane shape for this kind of tool. Three things have to be resolved before any of it faces a network. The compose file ships default database credentials and publishes Postgres, Neo4j HTTP and Neo4j bolt on host ports, the env example ships two secrets as change this placeholders, and the local directory mounting feature hands the sandbox whatever host paths an operator configures. The version numbers are the smaller problem: the manifest says 0.1.0, the newest release says 0.5.7, and the last push is three months past that release.

Frequently asked questions

How do you start a local poco-claw instance?

Run the interactive setup script, ./scripts/quickstart.sh, which generates configuration and starts the services, then open http://localhost:3000. The page points to a deployment guide hosted at docs.poco-ai.com for detailed instructions and troubleshooting.

Does poco-claw need a cloud subscription to work?

No. Self-hosting is described as one-click Docker deployment with a full runtime environment. The only subscription line on the page is the cloud subscription, which is marked as coming soon, so the documented path is the local one.

Which databases does the poco-claw compose stack start?

A postgres:16-alpine service with a named volume, plus a mem0-postgres service on ankane/pgvector:v0.5.1 and neo4j:5.26.4 that both carry profiles: ["mem0"] and therefore stay off unless the profile is requested. Default credentials in the compose file are postgres for the database name, user and password.

Which secrets should be changed before running poco-claw in production?

The env example marks two of them itself: BACKEND_SECRET_KEY, used for backend JWT signing, and INTERNAL_API_TOKEN, used for internal communication between services, both shipped as change-this placeholders. The same section advises a __Host- prefixed session cookie name when serving over HTTPS.

Does poco-claw run agent tasks on the host machine?

The page says all tasks run in an isolated container, so dependencies can be installed, files modified and commands executed without affecting the host. Mounting host directories into the sandbox so the agent can work on real project files is offered as well, and is marked as self-hosted only.

Official sources

  1. License: MIT
  2. poco-ai/poco-claw on GitHub
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/poco-ai-poco-claw.svg)](https://hysenlabs.com/projects/poco-ai-poco-claw)