# ZeroClaw: A Self-Hosted Rust AI Agent Runtime for Any Platform

> ZeroClaw is a single Rust binary that runs an AI agent across 30-plus communication channels, connects to 20-plus LLM providers, and executes tools from shell commands to hardware GPIO, all from one TOML configuration file on your own machine.

**zeroclaw-labs/zeroclaw** — Fast, small, and fully autonomous AI personal assistant infrastructure, any OS, any platform, deploy anywhere, swap anything.

- Repository: https://github.com/zeroclaw-labs/zeroclaw
- Website: https://www.zeroclawlabs.ai/
- Stars: 32,881 · Forks: 4,953
- Language: Rust
- License: Apache-2.0
- Published: 2026-08-04 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/zeroclaw-labs-zeroclaw

## What ZeroClaw Is and Who It Is For

ZeroClaw is an agent runtime distributed as a single Rust binary. It connects to LLM providers, listens on communication channels, and executes tools on the host system, all from one TOML configuration file stored at `~/.zeroclaw/config.toml`. The README summarizes its design philosophy in three lines: you own the agent, you own the data, and you own the machine it runs on.

The target users are developers and system operators who want an always-on AI assistant that is not constrained to a single chat application and that runs on infrastructure they control. The tool runs on Linux, macOS, Windows, FreeBSD, NixOS, and in Docker containers. It also supports hardware-attached platforms: GPIO, I2C, SPI, and USB peripherals on Raspberry Pi, STM32, Arduino, and ESP32 via the `Peripheral` trait.

## How ZeroClaw Works: Channels, Providers, and Tools

ZeroClaw's architecture has three layers: channels (where messages come in), providers (the LLM backends), and tools (what the agent can do).

Channels cover Discord, Telegram, Matrix, email, voice, webhooks, and a local CLI. One configured agent answers across all enabled channels simultaneously, so a message to the agent on Telegram and a message via the CLI reach the same agent loop.

Providers are pluggable. The README lists Anthropic, OpenAI, Ollama, and any OpenAI-compatible endpoint as supported provider types. Provider entries follow a `[providers.models.<type>.<alias>]` TOML schema. The `type` sets the provider family (anthropic, openai, openrouter, etc.) and the `alias` is a local name you choose. Fallback chains and routing keep the agent running when a provider is unavailable.

Tools include shell execution, browser control, HTTP requests, hardware peripherals, and custom MCP server connections. Every tool call generates a cryptographic receipt that logs what was executed, providing an audit trail for all agent actions.

## Installing ZeroClaw and Running Quickstart

On Unix systems, the recommended install is via the project's install script:

```sh
curl -fsSL https://raw.githubusercontent.com/zeroclaw-labs/zeroclaw/master/install.sh | sh
"${CARGO_HOME:-$HOME/.cargo}/bin/zeroclaw" quickstart
```

On Windows, the recommended path uses a prebuilt PowerShell installer documented in the Windows setup guide, which installs the current release without requiring Rust.

After installation, the quickstart command walks through initial configuration:

```bash
zeroclaw quickstart
zeroclaw agent -a <alias>
zeroclaw service install
zeroclaw service start
```

`zeroclaw quickstart` picks a provider and writes a working config. `zeroclaw agent -a <alias>` opens an interactive session using the agent entry named by the alias. `zeroclaw service install` registers the agent as a systemd, launchctl, or Windows Service unit so it runs persistently in the background.

A Docker image is also available at `ghcr.io/zeroclaw-labs/zeroclaw:latest` for container-based deployments. The `docker-compose.yml` in the repository shows the configuration pattern for Docker, using the double-underscore env-var syntax to override TOML config keys.

## TOML Configuration and the Security Model

The configuration file at `~/.zeroclaw/config.toml` requires at minimum four section headers: a provider entry, a model entry under that provider, an agent entry, and a risk profile. The README refers to this as the canonical four-section form.

The security model has three autonomy levels. In supervised mode (the default), medium-risk operations prompt for approval and high-risk operations are blocked. Workspace boundaries, command policies, and OS-level sandboxes (Landlock on Linux, Bubblewrap, Seatbelt on macOS, and Docker) enforce the boundaries. YOLO mode removes these safeguards and is documented explicitly as suitable only for trusted development machines.

Environment variable overrides follow a `ZEROCLAW_<path_with_double_underscores>=<value>` schema that mirrors the TOML path. For example, setting an Anthropic API key uses `ZEROCLAW_providers__models__anthropic__default__api_key=sk-ant-...`. The `.env.example` file in the repository documents this schema with inline comments for each variable category.

## Standard Operating Procedures and ACP Integration

ZeroClaw includes an SOP (Standard Operating Procedure) engine that triggers predefined agent workflows from events. Triggers include MQTT messages, webhooks, cron schedules, and peripheral signals. Each SOP can include approval gates where a human must confirm before the agent proceeds to the next step, and runs are resumable if interrupted.

ACP (Agent Client Protocol) provides IDE and editor integration via JSON-RPC 2.0 over stdio. The `apps/zerocode` workspace member implements this integration. It allows code editors to invoke the agent as a tool-call target, using the same protocol layer as the rest of the channel system.

The HTTP/WebSocket gateway serves a web dashboard for chat, memory browsing, configuration editing, cron management, and tool inspection. This runs locally on the machine and is accessible at `http://localhost:42617` in the Docker compose example.

## ZeroClaw Versus Managed Agent Platforms

Managed agent platforms like those offered by major AI providers run the agent runtime on the provider's infrastructure. This reduces operational overhead but means the provider controls where the agent executes and what data it can access.

ZeroClaw is the opposite: it runs on hardware you control, with provider connections treated as pluggable backends rather than infrastructure owners. The trade-off is that you are responsible for uptime, updates, and security of the host system. The Apache-2.0 license permits commercial use and modification.

For teams that need the agent to access on-premises systems, internal APIs, or air-gapped networks, self-hosted execution is a requirement that managed platforms cannot meet. For individuals or small teams who want a capable AI assistant without managing server infrastructure, a managed platform removes the operational cost. ZeroClaw targets the former case.

## Conclusion

ZeroClaw is a fit for developers who want an AI agent that runs on their own hardware, speaks to multiple chat platforms simultaneously, and can be extended with shell tools, HTTP calls, or hardware peripherals without being locked to a single provider. It is not the right choice for teams that need a managed cloud infrastructure or a polished GUI: the tool is binary-first and configuration-file-driven. Before deploying it, review the security model carefully, since the default supervised mode controls risk but YOLO mode removes those safeguards for dev environments where full autonomy is wanted. The last push was on 2026-09-25 and the current version is v0.8.5.

## FAQ

### What does ZeroClaw do?

ZeroClaw is a self-hosted AI agent runtime that connects to LLM providers, listens on communication channels including Discord, Telegram, Matrix, and CLI, and executes tools from shell commands to hardware GPIO. It runs as a single Rust binary configured by a TOML file.

### How to install ZeroClaw?

On Unix, run the install script with `curl -fsSL https://raw.githubusercontent.com/zeroclaw-labs/zeroclaw/master/install.sh | sh` and then run `zeroclaw quickstart` to configure the first provider and agent. On Windows, use the prebuilt PowerShell installer documented in the Windows setup guide.

### How to install ZeroClaw on Windows?

The README recommends using the Rust-free prebuilt PowerShell installer path described in the Windows setup guide at `docs/book/src/setup/windows.md`. This installs the current release, updates PATH, and runs Quickstart without requiring a Rust toolchain.

### Is ZeroClaw free?

Yes. ZeroClaw is Apache-2.0 licensed, which permits free use, modification, and commercial use. The source code and prebuilt binaries are available on GitHub.

## Sources

- [Official documentation](https://www.zeroclawlabs.ai/)
- [Official README](https://github.com/zeroclaw-labs/zeroclaw#readme)
- [Project repository](https://github.com/zeroclaw-labs/zeroclaw)
- [Release notes](https://github.com/zeroclaw-labs/zeroclaw/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/zeroclaw-labs-zeroclaw
