Skip to main content
14-day free trial — no credit card requiredStart trial

Anything to MCP. MCP to anything.

ClawQL is agentic infrastructure for production work in regulated industries. Autonomous event-driven agents. Structured institutional knowledge recall. Hardware-verified trusted execution. A WORM audit trail on every action — before every acknowledgment.

$
npm install -g clawql-mcp

Apache 2.0 core · Event-driven, not prompt-driven · OpenBench mini-firm proven · TEE-ready from day one

ClawQL
The protocol fabric

Any protocol in. Any protocol out. MCP in the middle.

ClawQL Core turns API surfaces into MCP tools — REST · GraphQL · gRPC · WebSocket · MCP · generated CLI · QR stream · WebMCP (preview). mcp-api-adapter exposes any MCP server outward — OpenAPI · GraphQL · Streamable HTTP · gRPC · gen-cli · WebSocket · QR · /mcp-ui. A gRPC service talks to a GraphQL consumer. A QR stream from an air-gapped system becomes agent-callable without a network path across the boundary.

In

ClawQL Core → MCP

REST · GraphQL · gRPC · WebSocket · MCP · generated CLI · QR stream · WebMCP (preview)

Out

mcp-api-adapter → any surface

OpenAPI · GraphQL · Streamable HTTP · gRPC · gen-cli · WebSocket · QR · /mcp-ui

ClawQL Streams

Agents that don't wait for you.

Every other agent platform requires a human to start the session. A stream_subscribe call points at any event source — WebSocket, NATS, webhook, cron, polled API, or QR stream. When an event crosses the significance threshold, an agent session spawns: memory recall, ontology queries, tool execution, optional Ouroboros convergence — then a human reviews via /mcp-ui. The decision lands in the WORM trail. No human starts the session. No developer builds the interface.

OpenBench proof

Memory that closes sets, not approximates them.

Semantic recall returns what looks relevant. Structured ontology recall returns what matches — exactly, with no extras. We rebuilt the Calderwood & Harkness near-miss failure mode as an OpenBench mini-firm harness (B-7), then fixed it structurally with CQE-typed predicates.

OpenBench mini-firm (B-7.1) — same notes, same model, different retrieval mechanism.
ArmScoreMatters foundRetrieval path
ClawQL on3/3 (1.0)5/5structured_predicate
ClawQL off0/30/5could not complete
No memory0/30/5could not complete

OpenBench mini-firm (B-7.1) — same notes, same model, different retrieval mechanism.

How it fits together

Recall → search → execute → ingest.

One closed loop for APIs, memory, and documents. Case studies on docs.clawql.com show the same pattern shipping Cloudflare Workers, recalling Cursor roadmaps from OpenClaw, and filing GitHub issues from vault context — without pasting specs into the chat.

Example case study
  1. 01

    Recall

    Pull prior vault notes and structured ontology matches — institutional context, not a blank session.

  2. 02

    Search

    Rank API operations by intent. Specs stay server-side; agents get operation IDs and parameter hints.

  3. 03

    Execute

    Run validated calls over REST, GraphQL, or gRPC. Lean responses keep results out of your context budget.

  4. 04

    Ingest

    Persist decisions with memory_ingest so the next session — Cursor, OpenClaw, or K8s — continues the trail.

MCP tools

Core discovery and execution — always on.

Memory, documents, automation, and the IDP pipeline opt in when you need them — same surface in Cursor, OpenClaw, or your Kubernetes cluster. Document workflows (Nextcloud → OCR → redaction → Onyx → VDR) live on the IDP page.

Full tool reference

ClawQL Core

Always on — no opt-out

search

Rank thousands of API operations by natural-language intent. Specs stay server-side; agents get operation IDs and parameter hints.

execute

Run one operation with validated args over REST, GraphQL, or gRPC. Lean responses keep tool results out of your context budget.

audit

In-process ring buffer of structured events — append, list, clear. Pair with memory_ingest when you need a durable operator trail.

cache

Ephemeral LRU scratch space for the active session. Use memory_* when data must survive restarts.

Security & TEE

Documented, reproducible — and TEE-ready.

ClawQL documents how container images are scanned, signed, and enforced from CI through Kubernetes admission — plus a 32-module curriculum for agentic AI deployments. ATR scoping limits what each agent can call; Panguard fails closed when scope is unclear.

Golden image pipeline

OSV-Scanner, Trivy, and Syft SBOM gates run before any image publishes. One BuildKit build per image — the exact OCI layout scanned is what Cosign signs and pushes to GHCR. Failed scans block push, sign, and tag promotion.

Pipeline overview

Admission enforcement

The Helm chart defaults Kyverno verifyImages for clawql-mcp and clawql-website. Unsigned or unverified digests are rejected before scheduling — deployed ClawQL images tie back to the signed artifacts from CI.

Defense in depth

Built for agentic AI

32-module security curriculum from supply chain through runtime. MCP gateway ATR scoping limits what agents can do regardless of prompt injection; audit trails, sandbox isolation, and distroless images are documented for self-hosted k3s.

32-module curriculum

Reproduce it yourself

Security documentation is public: golden-image walkthroughs, deliverables matrix, npm supply-chain hardening, and cosign verify instructions. Operators and reviewers can reproduce CI gates — we document limits as clearly as controls.

Full security hub

Build → registry → cluster

LayerWhat happens
GitHub ActionsFailed OSV/Trivy/SBOM or image scan → no push, no sign
GHCR + SigstoreCosign keyless signatures bind to the digest that passed CI
KubernetesKyverno verifyImages rejects unsigned ClawQL images at admission
clawql-tee

Hardware-verified agent execution.

For regulated environments where the operator itself cannot be trusted: clawql-tee is a DO-compatible runtime with AMD SEV-SNP, Intel TDX, and AWS Nitro Enclaves. Hardware attestation gates secrets; the audit trail can leave via QR optical channel — no network path across the boundary.

Questions & Answers

Pricing

Self-host free forever on Apache 2.0, or start a 14-day Developer trial. One MCP endpoint on every tier — same URL when you upgrade. Gateway tiers include vault memory; Teams adds Onyx; IDP tiers (Starter $299+) activate document processing on a dedicated tenant.

Self-hosted

$0

The full Apache 2.0 stack runs on your hardware — Helm chart, GHCR images, no license fee, no feature restrictions. Enable only the plugins you need via CLAWQL_ENABLE_* flags.

  • search, execute, audit, cache (Core — always on)

  • memory_ingest & memory_recall (default on)

  • Full IDP pipeline when you opt in (8 vendors)

  • Apache 2.0 — you pay infra costs only

Gateway + memory · 14-day trial

Developer

$29/mo

MCP gateway + agent memory vault for developers connecting Claude Code, Cursor, or Codex to your APIs. Start with a 14-day free trial, no credit card needed.

  • Unlimited MCP executions

  • Global edge-hosted MCP endpoint

  • Vault storage — no egress penalties on memory recall

  • One MCP endpoint on every tier — same URL when you upgrade

Gateway + memory + search

Teams

$99/mo

Full Onyx semantic search + memory vault + MCP gateway for teams building agent workflows. Add Starter when you need document processing.

  • Unlimited MCP executions

  • Global edge-hosted MCP endpoint

  • Vault storage — no egress penalties on memory recall

  • One MCP endpoint on every tier — same URL when you upgrade

IDP plugin bundle

Starter

$299/mo

Activates the IDP plugin bundle on dedicated tenant infrastructure: Tika, Gotenberg, Stirling, archive layer, classify/extract, Coneshare VDR, sovereign inference. Your MCP endpoint and vault memory stay the same.

  • Unlimited MCP executions

  • Dedicated tenant · full IDP pipeline

  • 5,000 documents/month

  • 5 users · 50 GB storage

Enterprise from $3,500/mo

Large enterprises and regulated industries. Dedicated node, custom fine-tune with retraining, multi-region (EU available), DPA/BAA, dedicated CSM. Sovereign Security Pack included.

Start your 14-day trial or self-host free

Gateway from $29/mo, IDP bundle from $299/mo. Full Apache 2.0 stack, no license fee.