NanoClaw
Status (verified 2026-09-30)
Active, MIT-licensed, ~30.9k GitHub stars / 12.8k forks. Built by brothers Gavriel and Lazer Cohen, who founded NanoCo around it (March 2026). Docker Sandboxes integration announced 2026-03-13. The earlier “500 lines of code” claim is no longer documented by the repo, which now says only “small enough to understand”; treat it as outdated.
Security-focused alternative to openclaw: each agent runs inside an isolated container, built on the Claude Agent SDK (see claude-agent-sdk), by anthropic.
Facts
- Repo: github.com/qwibitai/nanoclaw (maintainer org shows as “nanocoai” on the page). TypeScript/Node.js with Bun for the agent runner.
- Creator Gavriel Cohen wrote it over a weekend after finding security problems in OpenClaw while running an AI marketing startup; it went viral on Hacker News; Andrej Karpathy praised it (TechCrunch). At 2026-03-13: 22k stars, 4.6k forks, 50+ contributors. NanoCo was on a friends-and-family round, planning a commercial product (TechCrunch).
- Latest release seen: v2.4.0 (credential gateways as skills, OneCLI default, Iron Proxy alternative; default Claude model moves to Opus 5.5; new Codex threads use
gpt-6-astra). The release page shows the year as 2025 (clearly a display error; it references 2026 models), so the date is unverified.
Features
- Per-agent isolated Docker container and workspace; SQLite used for inter-process communication instead of shared memory
- Credential gateway: containers never see raw API keys
- Channels: WhatsApp, Telegram, Slack, Discord, Teams, iMessage, Matrix and others (earlier versions were WhatsApp-first)
- Scheduled tasks; per-group model and speed controls
- Skills-based extension: instead of feature PRs, contributors write skills that teach Claude Code to modify your fork (for example
/add-telegram); setup viananoclaw.sh, handing off to Claude Code when judgement is needed - Docker Sandboxes: since 2026-03-13 NanoClaw can run inside Docker’s MicroVM sandboxes with one command (replacing Apple Container as the macOS path in some setups)
Security model
Container (or microVM) isolation is enforced by the OS rather than application-level allowlists like OpenClaw’s. Only explicitly mounted directories are visible; shell commands run in the container.
Limitations
- Smaller ecosystem than OpenClaw; extensions depend on Claude Code
- Requires a container runtime
- Project is young and changes fast (v2 breaking changes around credential gateways)
Pricing
Free/open source (MIT). Costs are API usage plus hardware or VPS.
Comparisons
- vs openclaw: much smaller and container-isolated vs broad features
- vs PicoClaw: security-first vs ultra-minimal embedded
- vs Kimi Claw: self-hosted vs managed
- See openclaw-nanoclaw-picoclaw-comparison
Sources
All accessed 2026-09-30.
- https://github.com/qwibitai/nanoclaw (stars, licence, architecture)
- https://github.com/qwibitai/nanoclaw/releases (v2.4.0)
- https://techcrunch.com/2026/03/13/the-wild-six-weeks-for-nanoclaws-creator-that-led-to-a-deal-with-docker/
- https://www.docker.com/press-release/nanoclaw-partners-with-docker-to-run-ai-agents-safely/ (via search summary)