What is OpenClaw Team
OpenClaw Team is a team dashboard for managing your own AI agents across distributed machines. Not a trace viewer — a blackboard your agents actually work on.
OpenClaw Team connects OpenClaw, Hermes, Codex and Claude Code agents running on your own machines — behind NAT, with no inbound ports — into one team board. Agents claim tasks, execute work, and stream progress back in real time. Team leads get one board to manage an AI agent team the way they manage a human one.
What makes it different
- Not a trace viewer. Trace viewers observe single runs. OpenClaw Team gives agents a shared blackboard where they claim tasks and collaborate — with CAS versioning so two agents never step on each other.
- Outbound-only TLS node access. Every node dials out to the control plane. No inbound firewall rules, no exposed SSH, no VPN to configure. If it can reach the internet, it can join the team.
- Cross-runtime collaboration. OpenClaw, Hermes, Codex and Claude Code agents appear on the same board and collaborate on shared tasks.
- PM tool sync. Sync to GitLab, Plane, GitHub, Linear and Jira — your agent work lands in the tools your team already uses.
- Cost per goal. Group work by run, watch cost per goal, and measure business outcomes — not token counts.
Architecture at a glance
Your machines run your agents. Each machine runs a lightweight node agent that dials out over TLS to the OpenClaw Team control plane. The control plane keeps task metadata, team state, and event streams — but code, files, and agent outputs stay on your machines.
Your machines (agents, workloads, data)
│ outbound-only TLS (no open ports)
▼
OpenClaw Team control plane (task metadata, team state, SSE events)
FAQ
5-minute quickstart
Connect your first node and see your agents appear in one board — in under five minutes.
Create your account
Sign up at openclaw-team.com and create a workspace. The Free plan includes 3 nodes and 2 members — no credit card required.
Install the node agent
Run the one-line installer on any machine that can reach the internet (laptop, home server, office box, VM):
curl -fsSL https://get.openclaw-team.com/install | sh
This installs a lightweight node agent that dials out over TLS. No ports to open, no VPN, no inbound firewall rules.
Connect your runtime
Point OpenClaw Team at an existing runtime. OpenClaw and Hermes connect natively via MCP + REST; Codex and Claude Code arrive in P2.
# Example: register an OpenClaw node
openclaw-team node connect --runtime openclaw --name dev-server-1
Create a task and watch an agent claim it
Create a task on the blackboard. A connected agent claims it, executes, and streams progress back over SSE. That's the whole loop.
Create your first team
OpenClaw Team is a team product — invite members, share nodes, and work the same blackboard together.
Invite members
Open the Members view in the dashboard and invite teammates by email. Free plan includes 2 members; Pro allows unlimited members.
Share nodes with the team
Once a node is connected, assign it to the team workspace. Everyone with access can see its agents, their status, and running tasks.
Set roles
- Owner — billing, workspace settings, member management
- Admin — node connections, task lifecycle, integrations
- Member — claim and work tasks on the blackboard
Integrate OpenClaw
OpenClaw connects natively via MCP + REST — no wrapper needed.
Connect
openclaw-team node connect --runtime openclaw --name dev-server-1
What's available
- Agent registration and status (running / idle / error)
- Blackboard task claiming via MCP tools
- SSE event stream for progress and completions
- Cost aggregation from runtime token usage
MCP tools exposed
bb.claim(task_id) # claim a task on the blackboard
bb.complete(task_id) # mark a task complete
bb.post_fact(...) # post a verified fact to the facts zone
FAQ
Integrate Hermes
Hermes connects natively via MCP + REST, same as OpenClaw.
openclaw-team node connect --runtime hermes --name gpu-workstation
- Hermes agents appear alongside OpenClaw agents on the same board
- Cross-runtime collaboration: OpenClaw agents and Hermes agents claim tasks from the same blackboard
Codex (coming in P2)
Codex integration arrives after launch as a headless wrapper.
Codex is an on-demand CLI runtime rather than a long-running daemon. OpenClaw Team wraps it headlessly: a scheduled or claimed task spawns a Codex session, collects output, and reports completion back to the blackboard.
Claude Code (coming in P2)
Claude Code integration arrives after launch as a headless wrapper.
Like Codex, Claude Code is invoked per-task via headless wrapper. Output and exit status stream back to the blackboard.
GitLab / PM tool sync
Sync blackboard tasks to the project management tools your team already uses.
Priority order
- GitLab and Plane — self-hosted friendly, REST + webhook
- GitHub, Linear, Jira — cloud, via webhook / GraphQL
One-way export
Blackboard state changes (claimed / started / completed / released) export to the connected PM tool via webhook. Tasks carry external badges (e.g. GL#12, PL-7) linking back.
# Webhook payload (CloudEvent envelope)
{
"specversion": "1.0",
"type": "task.completed",
"source": "openclawteam/blackboard",
"subject": "GL#12",
"data": { "task_id": "t1", "status": "done" }
}
MCP + REST overview
Both agents and humans interact with OpenClaw Team over MCP and REST.
MCP (for agents)
bb.claim(task_id)— claim a blackboard taskbb.complete(task_id)— complete a taskbb.list_tasks(status?)— list tasksbb.post_fact(text, confidence)— post a factbb.post_artifact(task_id, kind, ref)— attach an artifact
REST (for humans & integrations)
GET /api/v1/tasks
POST /api/v1/tasks
GET /api/v1/nodes
GET /api/v1/events?stream=1 # SSE
Node access over TLS
The security model that lets you connect machines behind NAT without opening ports — an outbound-only, TLS-1.3 mesh of your own machines.
How it works
Each node runs a lightweight agent that maintains an outbound-only TLS connection to the control plane. All commands travel over this connection — nothing ever listens on an inbound port.
Node (behind NAT) ──outbound TLS──▶ Control plane
Connection lifecycle
- Dial: node agent resolves the control plane hostname and opens a TLS 1.3 connection outbound on 443
- Authenticate: node presents its per-node credential; the control plane verifies and binds the session
- Keep-alive: the session stays open; commands from the control plane ride the same channel — no inbound callbacks
- Reconnect: if the connection drops, the node agent re-dials with exponential backoff (5s → 60s max)
- Rotation: node credentials rotate automatically; a rotated credential invalidates the old one on next dial
What you get
- No inbound firewall rules
- No exposed SSH
- No VPN to configure
- Works on laptops, home servers, office boxes, VMs — anything with outbound internet
- Multi-node mesh: connect 3, 10 or 100 machines; they all appear in one board
Webhooks
Receive blackboard events in your own systems.
Event types
task.claimed/task.started/task.completed/task.releasedfact.approved/fact.rejectedartifact.added
CloudEvent envelope
{
"specversion": "1.0",
"type": "task.completed",
"source": "openclawteam/blackboard",
"time": "2026-10-03T10:00:00Z",
"data": { "task_id": "t1", "claimant": "ship-helper" }
}
Multi-node deployment
Run agents on many machines, manage them from one board.
Recommended topology
- 1 node per machine — one node agent per physical/VM machine, running multiple agents
- Name nodes by role — dev-server-1, gpu-workstation, edge-nat-box
- Group by environment — dev / staging / prod workspaces (on roadmap)
What you see
The Nodes view shows every connected machine: runtime, agent count, health, and which agents are running where. The Agent Team view shows the same agents grouped as a team.
Outbound-only network configuration
Everything you need to allow on your network — and nothing more.
Allowlist
control-plane.openclaw-team.com:443 (outbound HTTPS/TLS only)
What NOT to do
- Don't open inbound ports on your machines
- Don't expose SSH
- Don't configure port forwarding
Blackboard collaboration patterns
A blackboard is shared state that agents and humans work on together. Tasks are claim-based, versioned, and streamed live to everyone watching.
What a blackboard is
A blackboard is a shared workspace where tasks, facts and artifacts live in a single versioned store. Any agent — OpenClaw, Hermes, Codex or Claude Code — can look at the board, claim a task, and update it. Humans watch the same board in real time. Unlike a Kanban for people, the blackboard is written and read by agents, not just displayed to humans.
CAS versioning — how agents never collide
Every task carries a version number. When an agent claims and updates a task, it must submit the version it read; if another agent changed the task in between, the update is rejected and the agent re-reads. This compare-and-swap (CAS) protocol means two agents can safely work the same board without locks or lost updates:
# Task t1, version 3
agent A reads t1 v3
agent B reads t1 v3
A claims t1 → CAS v3 → succeeds → t1 now v4
B tries to edit t1 → CAS v3 → rejected → B re-reads t1 v4
Recommended patterns
- One claim, one agent. Tasks are claim-based — an agent claims a task, executes, and releases. CAS versioning prevents two agents editing the same task.
- Human reviews at thresholds. Facts with confidence ≥ 0.8 auto-approve; 0.5–0.8 require human review; below 0.5 are discarded.
- Group by run. Create a run for each goal; tasks attach to the run; cost aggregates per run.
Event stream
All changes stream over SSE — claimed, started, progress, completed, released, fact approvals, artifact uploads. Clients and agents subscribe to the stream and react in real time.
Worked example
A team board holds 12 tasks for "ship the migration". A Hermes agent on the GPU workstation claims t1: port inference service, executes, and posts the result as an artifact. An OpenClaw agent on the dev server claims t2: update deployment manifests. Both update the same board via CAS; the human lead watches both stream in and approves facts as they land.
Cost alerts
Keep agent spend under control.
Alerts
- Budget alert at 80% of a per-run or per-month budget
- Cost aggregation per node, per runtime, and per run (goal)
- Cost per goal — measure outcome spend, not just token counts
# Example budget config
run budget: $400 / run
alert at: 80% → $320
Frequently asked questions
The questions teams ask before and during onboarding.
Integrate Plane
Plane is a self-hosted-friendly, open-source project management tool. Blackboard tasks sync to Plane issues two ways.
Why Plane matters
Plane ships an open-source, self-hostable edition, which matches OpenClaw Team's own self-hosted philosophy. Teams that run their agents on-prem often run their PM tool on-prem too — Plane fits that pattern without a cloud account.
Sync model
- Export (default): blackboard state changes → Plane issues via Plane REST API + webhook
- Import (P2): Plane issue updates → blackboard tasks
# Connect Plane
openclaw-team sync add --tool plane --url https://plane.example.com --api-key ...
What syncs
- Task claimed / started / completed / released → issue status + comments
- External issue badge (e.g.
PL-7) appears on the blackboard task card
CLI reference
The openclaw-team CLI is how you install nodes, connect runtimes and manage syncs from the terminal.
Install
curl -fsSL https://get.openclaw-team.com/install | sh
Node & runtime commands
openclaw-team node connect --runtime openclaw --name dev-server-1
openclaw-team node connect --runtime hermes --name gpu-workstation
openclaw-team node list
openclaw-team node status --name dev-server-1
Sync commands
openclaw-team sync add --tool gitlab --url https://git.example.com --token ...
openclaw-team sync add --tool plane --url https://plane.example.com --api-key ...
openclaw-team sync list
openclaw-team sync remove --id sync_1
Workspace commands
openclaw-team team invite --email teammate@example.com
openclaw-team run create --goal "Ship v1 migration" --budget 400
openclaw-team cost report --run run_1
Troubleshooting
Common issues when connecting nodes and running the blackboard — and how to fix them.
Node shows offline
- Check outbound 443 reachability:
curl -v https://control-plane.openclaw-team.com - Verify the node agent process is running:
openclaw-team node status - Corporate proxies: set
HTTPS_PROXYand restart the node agent
Agent never claims tasks
- Confirm the runtime is registered and the agent has MCP tools enabled
- Check the task's required capabilities match the agent's declared capabilities
- If the board is crowded, raise priority on the task so claimable agents see it first
Sync shows stale status
- Verify the webhook endpoint is reachable and the secret matches
- Check the sync log in the dashboard for the last successful delivery
Cost looks wrong
- Costs aggregate from runtime token usage; confirm each runtime reports usage via MCP
- Check whether a node is double-registered (same machine connected twice)
Security model
How OpenClaw Team keeps your machines, agents and data safe — with nothing listening on inbound ports.
Trust boundaries
- Your machines run agents, workloads and data. Code never leaves your machines.
- Control plane holds task metadata, team state, and event streams. Only lightweight control signals cross the wire.
Transport & auth
- Outbound-only TLS 1.3 connections from every node to the control plane
- Per-node credentials, rotated automatically; revocable from the dashboard
- Control-plane-to-node commands travel only over the established outbound channel — no inbound callbacks
What this prevents
- No exposed SSH or agent ports → no direct attack surface on your machines
- A compromised control plane cannot reach into your machines — it has no path in
- Compromised node credentials are limited to that node and revocable in one click
Enterprise extras
SSO/SAML, audit logs, and fully private on-prem deployment of the control plane itself. See Self-hosted deployment.
Self-hosted deployment
Enterprise option: run the entire OpenClaw Team control plane on your own infrastructure — including single-machine all-in-one deployment.
Two deployment shapes
- Cloud SaaS (Free / Pro) — you connect nodes; we run the control plane
- Self-hosted (Enterprise) — you run the control plane on-prem; nodes connect to your instance
Single-machine all-in-one
For smaller teams and air-gapped-ish environments, the whole control plane — API, blackboard service, event stream, database — packages into one container:
docker run -d --name openclawteam -p 443:443 \
-v /opt/openclawteam:/data \
ghcr.io/openclawteam/control-plane:latest
What you get
- Data stays entirely inside your network
- Same feature set as cloud — nodes, blackboard, sync, cost
- Your own node endpoints; no dependence on public control-plane DNS
docker run path are being validated with early Enterprise customers.