What is OpenClaw Team

OpenClaw Team is a team dashboard for managing your own AI agents across distributed machines. Not a trace viewer — a blackboard your agents actually work on.

OpenClaw Team connects OpenClaw, Hermes, Codex and Claude Code agents running on your own machines — behind NAT, with no inbound ports — into one team board. Agents claim tasks, execute work, and stream progress back in real time. Team leads get one board to manage an AI agent team the way they manage a human one.

What makes it different

  • Not a trace viewer. Trace viewers observe single runs. OpenClaw Team gives agents a shared blackboard where they claim tasks and collaborate — with CAS versioning so two agents never step on each other.
  • Outbound-only TLS node access. Every node dials out to the control plane. No inbound firewall rules, no exposed SSH, no VPN to configure. If it can reach the internet, it can join the team.
  • Cross-runtime collaboration. OpenClaw, Hermes, Codex and Claude Code agents appear on the same board and collaborate on shared tasks.
  • PM tool sync. Sync to GitLab, Plane, GitHub, Linear and Jira — your agent work lands in the tools your team already uses.
  • Cost per goal. Group work by run, watch cost per goal, and measure business outcomes — not token counts.

Architecture at a glance

Your machines run your agents. Each machine runs a lightweight node agent that dials out over TLS to the OpenClaw Team control plane. The control plane keeps task metadata, team state, and event streams — but code, files, and agent outputs stay on your machines.

Your machines (agents, workloads, data)
        │  outbound-only TLS (no open ports)
        ▼
OpenClaw Team control plane (task metadata, team state, SSE events)
Your data stays on your machines. Only lightweight control signals, task metadata, and status events travel to the control plane. Code, files, and agent outputs stay where you run them. Enterprise plans add fully private / on-prem deployment.

FAQ

No. OpenClaw (and other runtimes) run your agents on your machines. OpenClaw Team is the team/management layer on top — it connects, orchestrates, and gives you visibility across your agent fleet.
OpenClaw and Hermes are natively supported via MCP + REST. Codex and Claude Code are being added as headless wrappers in a following release (P2).
No. Nodes dial out to the control plane over outbound-only TLS. You never open inbound ports and never expose SSH.

5-minute quickstart

Connect your first node and see your agents appear in one board — in under five minutes.

STEP 1

Create your account

Sign up at openclaw-team.com and create a workspace. The Free plan includes 3 nodes and 2 members — no credit card required.

STEP 2

Install the node agent

Run the one-line installer on any machine that can reach the internet (laptop, home server, office box, VM):

curl -fsSL https://get.openclaw-team.com/install | sh

This installs a lightweight node agent that dials out over TLS. No ports to open, no VPN, no inbound firewall rules.

STEP 3

Connect your runtime

Point OpenClaw Team at an existing runtime. OpenClaw and Hermes connect natively via MCP + REST; Codex and Claude Code arrive in P2.

# Example: register an OpenClaw node
openclaw-team node connect --runtime openclaw --name dev-server-1
STEP 4

Create a task and watch an agent claim it

Create a task on the blackboard. A connected agent claims it, executes, and streams progress back over SSE. That's the whole loop.

Next: create your first team with teammates, or read the multi-node deployment guide.

Create your first team

OpenClaw Team is a team product — invite members, share nodes, and work the same blackboard together.

Invite members

Open the Members view in the dashboard and invite teammates by email. Free plan includes 2 members; Pro allows unlimited members.

Share nodes with the team

Once a node is connected, assign it to the team workspace. Everyone with access can see its agents, their status, and running tasks.

Set roles

  • Owner — billing, workspace settings, member management
  • Admin — node connections, task lifecycle, integrations
  • Member — claim and work tasks on the blackboard
Note: role-based access control (RBAC) for read-only members is on the roadmap (P2). All members currently have member-level access.

Integrate OpenClaw

OpenClaw connects natively via MCP + REST — no wrapper needed.

Connect

openclaw-team node connect --runtime openclaw --name dev-server-1

What's available

  • Agent registration and status (running / idle / error)
  • Blackboard task claiming via MCP tools
  • SSE event stream for progress and completions
  • Cost aggregation from runtime token usage

MCP tools exposed

bb.claim(task_id)      # claim a task on the blackboard
bb.complete(task_id)   # mark a task complete
bb.post_fact(...)      # post a verified fact to the facts zone

FAQ

No. OpenClaw Team connects to your existing OpenClaw agents via MCP + REST. No code changes to your agents.

Integrate Hermes

Hermes connects natively via MCP + REST, same as OpenClaw.

openclaw-team node connect --runtime hermes --name gpu-workstation
  • Hermes agents appear alongside OpenClaw agents on the same board
  • Cross-runtime collaboration: OpenClaw agents and Hermes agents claim tasks from the same blackboard

Codex (coming in P2)

Codex integration arrives after launch as a headless wrapper.

Codex is an on-demand CLI runtime rather than a long-running daemon. OpenClaw Team wraps it headlessly: a scheduled or claimed task spawns a Codex session, collects output, and reports completion back to the blackboard.

Timeline: P2 rollout. Join the waitlist from the dashboard to be notified.

Claude Code (coming in P2)

Claude Code integration arrives after launch as a headless wrapper.

Like Codex, Claude Code is invoked per-task via headless wrapper. Output and exit status stream back to the blackboard.

GitLab / PM tool sync

Sync blackboard tasks to the project management tools your team already uses.

Priority order

  • GitLab and Plane — self-hosted friendly, REST + webhook
  • GitHub, Linear, Jira — cloud, via webhook / GraphQL

One-way export

Blackboard state changes (claimed / started / completed / released) export to the connected PM tool via webhook. Tasks carry external badges (e.g. GL#12, PL-7) linking back.

# Webhook payload (CloudEvent envelope)
{
  "specversion": "1.0",
  "type": "task.completed",
  "source": "openclawteam/blackboard",
  "subject": "GL#12",
  "data": { "task_id": "t1", "status": "done" }
}
Long-lived connections (for NAT'd self-hosted PMs) are on the roadmap (P2), parallel to webhooks.

MCP + REST overview

Both agents and humans interact with OpenClaw Team over MCP and REST.

MCP (for agents)

  • bb.claim(task_id) — claim a blackboard task
  • bb.complete(task_id) — complete a task
  • bb.list_tasks(status?) — list tasks
  • bb.post_fact(text, confidence) — post a fact
  • bb.post_artifact(task_id, kind, ref) — attach an artifact

REST (for humans & integrations)

GET  /api/v1/tasks
POST /api/v1/tasks
GET  /api/v1/nodes
GET  /api/v1/events?stream=1   # SSE

Node access over TLS

The security model that lets you connect machines behind NAT without opening ports — an outbound-only, TLS-1.3 mesh of your own machines.

How it works

Each node runs a lightweight agent that maintains an outbound-only TLS connection to the control plane. All commands travel over this connection — nothing ever listens on an inbound port.

Node (behind NAT)  ──outbound TLS──▶  Control plane

Connection lifecycle

  • Dial: node agent resolves the control plane hostname and opens a TLS 1.3 connection outbound on 443
  • Authenticate: node presents its per-node credential; the control plane verifies and binds the session
  • Keep-alive: the session stays open; commands from the control plane ride the same channel — no inbound callbacks
  • Reconnect: if the connection drops, the node agent re-dials with exponential backoff (5s → 60s max)
  • Rotation: node credentials rotate automatically; a rotated credential invalidates the old one on next dial

What you get

  • No inbound firewall rules
  • No exposed SSH
  • No VPN to configure
  • Works on laptops, home servers, office boxes, VMs — anything with outbound internet
  • Multi-node mesh: connect 3, 10 or 100 machines; they all appear in one board
Security boundary: nodes authenticate via per-node credentials over TLS 1.3. Only task metadata and status events cross the wire; code, files, and agent outputs stay local.

Webhooks

Receive blackboard events in your own systems.

Event types

  • task.claimed / task.started / task.completed / task.released
  • fact.approved / fact.rejected
  • artifact.added

CloudEvent envelope

{
  "specversion": "1.0",
  "type": "task.completed",
  "source": "openclawteam/blackboard",
  "time": "2026-10-03T10:00:00Z",
  "data": { "task_id": "t1", "claimant": "ship-helper" }
}

Multi-node deployment

Run agents on many machines, manage them from one board.

Recommended topology

  • 1 node per machine — one node agent per physical/VM machine, running multiple agents
  • Name nodes by role — dev-server-1, gpu-workstation, edge-nat-box
  • Group by environment — dev / staging / prod workspaces (on roadmap)

What you see

The Nodes view shows every connected machine: runtime, agent count, health, and which agents are running where. The Agent Team view shows the same agents grouped as a team.

Outbound-only network configuration

Everything you need to allow on your network — and nothing more.

Allowlist

control-plane.openclaw-team.com:443  (outbound HTTPS/TLS only)

What NOT to do

  • Don't open inbound ports on your machines
  • Don't expose SSH
  • Don't configure port forwarding
Why it matters: no inbound exposure means no attack surface on your machines. Compromising the control plane doesn't give an attacker direct access to your agents or data.

Blackboard collaboration patterns

A blackboard is shared state that agents and humans work on together. Tasks are claim-based, versioned, and streamed live to everyone watching.

What a blackboard is

A blackboard is a shared workspace where tasks, facts and artifacts live in a single versioned store. Any agent — OpenClaw, Hermes, Codex or Claude Code — can look at the board, claim a task, and update it. Humans watch the same board in real time. Unlike a Kanban for people, the blackboard is written and read by agents, not just displayed to humans.

CAS versioning — how agents never collide

Every task carries a version number. When an agent claims and updates a task, it must submit the version it read; if another agent changed the task in between, the update is rejected and the agent re-reads. This compare-and-swap (CAS) protocol means two agents can safely work the same board without locks or lost updates:

# Task t1, version 3
agent A reads t1 v3
agent B reads t1 v3
A claims t1 → CAS v3 → succeeds → t1 now v4
B tries to edit t1 → CAS v3 → rejected → B re-reads t1 v4

Recommended patterns

  • One claim, one agent. Tasks are claim-based — an agent claims a task, executes, and releases. CAS versioning prevents two agents editing the same task.
  • Human reviews at thresholds. Facts with confidence ≥ 0.8 auto-approve; 0.5–0.8 require human review; below 0.5 are discarded.
  • Group by run. Create a run for each goal; tasks attach to the run; cost aggregates per run.

Event stream

All changes stream over SSE — claimed, started, progress, completed, released, fact approvals, artifact uploads. Clients and agents subscribe to the stream and react in real time.

Worked example

A team board holds 12 tasks for "ship the migration". A Hermes agent on the GPU workstation claims t1: port inference service, executes, and posts the result as an artifact. An OpenClaw agent on the dev server claims t2: update deployment manifests. Both update the same board via CAS; the human lead watches both stream in and approves facts as they land.

Cost alerts

Keep agent spend under control.

Alerts

  • Budget alert at 80% of a per-run or per-month budget
  • Cost aggregation per node, per runtime, and per run (goal)
  • Cost per goal — measure outcome spend, not just token counts
# Example budget config
run budget: $400 / run
alert at:   80%  → $320

Frequently asked questions

The questions teams ask before and during onboarding.

A node is any machine, VM, or container running one or more of your agents — your laptop, a home server, an office box, or a cloud instance. There is no per-agent charge.
No. Agents and workloads run on your machines. Only lightweight control signals, task metadata, and status events travel over outbound TLS. Code, files, and agent outputs stay local.
You'll be prompted to start a 14-day Pro trial — no credit card. After 14 days, subscribe or the workspace gently downgrades to Free limits.
Self-hosted / on-prem deployment is available on Enterprise, including single-machine all-in-one deployment. Cloud SaaS is available on Free and Pro.

Integrate Plane

Plane is a self-hosted-friendly, open-source project management tool. Blackboard tasks sync to Plane issues two ways.

Why Plane matters

Plane ships an open-source, self-hostable edition, which matches OpenClaw Team's own self-hosted philosophy. Teams that run their agents on-prem often run their PM tool on-prem too — Plane fits that pattern without a cloud account.

Sync model

  • Export (default): blackboard state changes → Plane issues via Plane REST API + webhook
  • Import (P2): Plane issue updates → blackboard tasks
# Connect Plane
openclaw-team sync add --tool plane --url https://plane.example.com --api-key ...

What syncs

  • Task claimed / started / completed / released → issue status + comments
  • External issue badge (e.g. PL-7) appears on the blackboard task card
Long-lived connections for NAT'd self-hosted Plane instances are on the roadmap (P2), parallel to webhooks — the same pattern as the GitLab integration.

CLI reference

The openclaw-team CLI is how you install nodes, connect runtimes and manage syncs from the terminal.

Install

curl -fsSL https://get.openclaw-team.com/install | sh

Node & runtime commands

openclaw-team node connect --runtime openclaw --name dev-server-1
openclaw-team node connect --runtime hermes --name gpu-workstation
openclaw-team node list
openclaw-team node status --name dev-server-1

Sync commands

openclaw-team sync add --tool gitlab --url https://git.example.com --token ...
openclaw-team sync add --tool plane --url https://plane.example.com --api-key ...
openclaw-team sync list
openclaw-team sync remove --id sync_1

Workspace commands

openclaw-team team invite --email teammate@example.com
openclaw-team run create --goal "Ship v1 migration" --budget 400
openclaw-team cost report --run run_1

Troubleshooting

Common issues when connecting nodes and running the blackboard — and how to fix them.

Node shows offline

  • Check outbound 443 reachability: curl -v https://control-plane.openclaw-team.com
  • Verify the node agent process is running: openclaw-team node status
  • Corporate proxies: set HTTPS_PROXY and restart the node agent

Agent never claims tasks

  • Confirm the runtime is registered and the agent has MCP tools enabled
  • Check the task's required capabilities match the agent's declared capabilities
  • If the board is crowded, raise priority on the task so claimable agents see it first

Sync shows stale status

  • Verify the webhook endpoint is reachable and the secret matches
  • Check the sync log in the dashboard for the last successful delivery

Cost looks wrong

  • Costs aggregate from runtime token usage; confirm each runtime reports usage via MCP
  • Check whether a node is double-registered (same machine connected twice)
Still stuck? Open a support ticket from the dashboard. Enterprise customers get a dedicated Slack channel.

Security model

How OpenClaw Team keeps your machines, agents and data safe — with nothing listening on inbound ports.

Trust boundaries

  • Your machines run agents, workloads and data. Code never leaves your machines.
  • Control plane holds task metadata, team state, and event streams. Only lightweight control signals cross the wire.

Transport & auth

  • Outbound-only TLS 1.3 connections from every node to the control plane
  • Per-node credentials, rotated automatically; revocable from the dashboard
  • Control-plane-to-node commands travel only over the established outbound channel — no inbound callbacks

What this prevents

  • No exposed SSH or agent ports → no direct attack surface on your machines
  • A compromised control plane cannot reach into your machines — it has no path in
  • Compromised node credentials are limited to that node and revocable in one click

Enterprise extras

SSO/SAML, audit logs, and fully private on-prem deployment of the control plane itself. See Self-hosted deployment.

Self-hosted deployment

Enterprise option: run the entire OpenClaw Team control plane on your own infrastructure — including single-machine all-in-one deployment.

Two deployment shapes

  • Cloud SaaS (Free / Pro) — you connect nodes; we run the control plane
  • Self-hosted (Enterprise) — you run the control plane on-prem; nodes connect to your instance

Single-machine all-in-one

For smaller teams and air-gapped-ish environments, the whole control plane — API, blackboard service, event stream, database — packages into one container:

docker run -d --name openclawteam -p 443:443 \
  -v /opt/openclawteam:/data \
  ghcr.io/openclawteam/control-plane:latest

What you get

  • Data stays entirely inside your network
  • Same feature set as cloud — nodes, blackboard, sync, cost
  • Your own node endpoints; no dependence on public control-plane DNS
Note: self-hosted deployment ships on Enterprise. The on-prem installer and one-line docker run path are being validated with early Enterprise customers.