惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
The GitHub Blog
The GitHub Blog
Vercel News
Vercel News
D
DataBreaches.Net
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
小众软件
小众软件
美团技术团队
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
D
Docker
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
H
Hackread – Cybersecurity News, Data Breaches, AI and More
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
S
SegmentFault 最新的问题
云风的 BLOG
云风的 BLOG
B
Blog
雷峰网
雷峰网
The Cloudflare Blog

Hacker News - Newest: "OpenClaw"

OpenClaw just launched an official app for iPhone, details here - 9to5Mac OpenClaw Launch — Deploy AI Chatbots in Seconds Self-Host OpenClaw AI Agent on VPS: Full Setup Guide GitHub - xltvy/openclaw-memgpt: OpenClaw plugin that gives agents MemGPT-style memory: tiered core/archival/recall storage, self-directed memory operations via tool calls, memory-pressure warnings, and recursive summarisation. Integrates the reference MemGPT implementation via a local sidecar service, preserving the original architecture without reimplementation. Malicious AI 23 ClawHub Plugins Squat Official Org Scopes - Manifold Security what shipping OpenClaw in production taught us — AutoClaw AgentLine — AI Phone API | Phone Numbers, Voice & SMS for AI Agents Make Your OpenClaw Agent Cheaper, and Measure It Yourself GitHub - sammysltd/OpenEmployee: Make your OpenClaw agent employable: deny-by-default governance, budgets, allowlists, approval gates, and a signed audit trail via MakerChecker. Migrate from OpenClaw | Hermes Agent StackOverflow closed my OpenClaw and paperclipAI integration q. as "irrelevant" GitHub - sausin/outpost: Removing AI agents' quiet security problem Potassium — ClawHub Plugins Pi Building Pi, Openclaw's Minimalist Coding Agent | Mario Zechner, Creator of Pi I Spent 4 Hours So You Don’t Have To: Hetzner Metal + NixOS in ~15 Minutes − Irakli's blog GitHub - snuri00/osint-mcp: Self-hosted OSINT toolkit — MCP server, AI REPL, CLI, web app & chat apps (WhatsApp/Telegram/Discord via OpenClaw). Entity, event/news & social/community intelligence. Keyless-first. What a Regex Can't Do GitHub - ai-sns/openclaw-hermes-agent-network: OpenClaw Hermes AI Agent Social Network🦞💬🦞Built on Google 3D Maps and A2A protocol, connects OpenClaw and Hermes agents worldwide in a 3D environment. Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets GitHub - CODEANDTRUST/clawcall: Give your OpenClaw / self-hosted AI agent inbound phone calls - a Twilio-to-gateway voice bridge with working agent tools mid-call (MIT). Build a ZeroCost Web Automation Pipeline with OpenRouter, OpenClaw, and MediaUse Let OpenClaw Run Wild in Simulation, Not on Your Customers | Veris AI GitHub - gpdir16/tabyAgent: A lighter, easier alternative to OpenClaw/Hermes. Runs autonomously inside Docker and chats with you through Telegram. Ask HN: What are the biggest problems you find in OpenClaw/Hermes? Microsoft launches Scout, an OpenClaw-inspired personal assistant GitHub - openclaw/openclaw-windows-node: Windows companion suite for OpenClaw - System Tray app, Shared library, Node, and PowerToys Command Palette extension Microsoft unveils Scout, an autonomous AI agent built on OpenClaw Gavriel Cohen found his own code inside OpenClaw, so he walked away GitHub - hunvreus/heypi: Chat agents for your team, with approvals and sandboxed tools. Slack, Discord, Telegram, webhooks.
GitHub - supersuit-tech/permission-slip
chiedo · 2026-04-23 · via Hacker News - Newest: "OpenClaw"

CI Deploy

Approve what Openclaw does before it does it.

Permission Slip is an open-source approval layer for Openclaw. Every action Openclaw wants to take — sending emails, merging PRs, booking flights — goes through you first. Nothing happens without your say-so.

┌──────────┐         ┌─────────────────┐         ┌──────────────┐
│ Openclaw │ ──────→ │ Permission Slip │ ──────→ │   Gmail,     │
│          │ ←────── │   (approval     │ ←────── │   Stripe,    │
└──────────┘         │    layer)       │         │   GitHub,    │
                     └─────────────────┘         │   Slack…     │
                           │                     └──────────────┘
                           │ push notification
                           ▼
                     ┌───────────┐
                     │  You      │
                     │  (approve │
                     │  / deny)  │
                     └───────────┘

🚀 Try it now

permissionslip.dev — hosted, no setup required.

Get the iPhone app to approve requests on the go.

Or self-host it on Docker, Fly.io, or bare metal. Even runs on a Raspberry Pi 5 in under 30 minutes.


✨ Why Permission Slip?

You want Openclaw to book flights, send emails, and merge PRs. But you can't trust it with full access to your accounts. Your options today:

  • 😬 Give Openclaw your passwords — it can do anything, anytime, with no oversight
  • 😩 Do everything manually — defeats the purpose of having Openclaw
  • 🤞 Hope it asks nicely — it could hallucinate, misunderstand, or get compromised

Permission Slip solves this with a secure proxy + human-in-the-loop approval model. Openclaw submits structured, schema-validated actions — never arbitrary API calls. Nothing executes without your explicit sign-off.


Beta status & how we build

The project is in beta: behavior, APIs, and connectors will keep evolving, and you should expect rough edges.

The architecture and product direction are designed by humans; the codebase is largely written with AI-assisted development (with human review and iteration layered on top). Treat the implementation as fast-moving software, not a formally verified system while it is in beta. If this ever gets more enough use, I'll update some processes, get a formal security review done, etc. Still just exploring at the moment.

Want to run, build, or change the code? Start with the Developer guide — local setup, production builds, testing, and tech stack — then CONTRIBUTING.md for workflow and standards.


🔑 Key Features

  • 🛡️ Action-based security — Openclaw submits structured actions, not raw API calls
  • 🔔 Per-request approval — push notifications with human-readable summaries
  • Standing approvals — pre-authorize trusted, repetitive actions with constraints
  • 🔐 Cryptographic identity — Ed25519 key pairs for tamper-proof request signing
  • 🙈 Zero credential exposure — Openclaw never sees your API keys or passwords
  • 📋 Full audit trail — every request, approval, and execution logged
  • 🔌 OAuth 2.0 connections — Google, Microsoft, Dropbox, and custom providers; PKCE where required; tokens encrypted at rest with automatic refresh
  • 📱 iPhone app — approve on the go from your phone
  • 🏠 Self-hostable — your data, your infrastructure
  • 📦 Single binary deployment — Go server with embedded React frontend

🔌 Connector Health

Connectors are being tested incrementally during the beta; maturity varies by integration.

Connector Status
GitHub 🟡 Early Preview
Google 🟡 Early Preview
Microsoft 🟡 Early Preview
Slack 🟡 Early Preview
🔴 Untested connectors (click to expand)

These connectors are wired up but have not yet been end-to-end verified. If you try one, we'd love a report — see the "connector report" issue template.

Connector Status
Airtable 🔴 Untested
Amadeus 🔴 Untested
Asana 🔴 Untested
AWS 🔴 Untested
Calendly 🔴 Untested
Confluence 🔴 Untested
Datadog 🔴 Untested
Discord 🔴 Untested
DocuSign 🔴 Untested
DoorDash 🔴 Untested
Dropbox 🔴 Untested
Expedia 🔴 Untested
Figma 🔴 Untested
HubSpot 🔴 Untested
Intercom 🔴 Untested
Jira 🔴 Untested
Kroger 🔴 Untested
Linear 🔴 Untested
LinkedIn 🔴 Untested
Make 🔴 Untested
Meta 🔴 Untested
Monday 🔴 Untested
MongoDB 🔴 Untested
MySQL 🔴 Untested
Netlify 🔴 Untested
Notion 🔴 Untested
PagerDuty 🔴 Untested
Plaid 🔴 Untested
Postgres 🔴 Untested
QuickBooks 🔴 Untested
Redis 🔴 Untested
Salesforce 🔴 Untested
SendGrid 🔴 Untested
Shopify 🔴 Untested
Square 🔴 Untested
Stripe 🔴 Untested
Supabase 🔴 Untested
Trello 🔴 Untested
Twilio 🔴 Untested
Vercel 🔴 Untested
Walmart 🔴 Untested
X 🔴 Untested
Zapier 🔴 Untested
Zendesk 🔴 Untested
Zoom 🔴 Untested

Have you tested a connector? Open an issue to let us know!


📚 Documentation

👩‍💻 For developers & contributors

Developer guide — clone the repo, local dev servers, production make build, observability env vars, testing commands, and tech stack overview.

CONTRIBUTING.md — issue workflow, code standards, migrations, and pull request expectations.

📖 Getting Started

🔌 Integrations & Connectors

🔒 Protocol Reference

🚀 Deployment

🧪 Contributing & Testing


🤝 Contributing

Contributions are welcome! For setup and commands, see the Developer guide; for process and standards, see CONTRIBUTING.md. Browse open issues to find something to work on.


📜 License

Permission Slip is licensed under the Apache License 2.0. Built by SuperSuit — questions or feedback welcome at supersuit.tech.


👥 Contributors

Thanks to everyone who has contributed!

Contributors

Made with contrib.rocks.