The computer use agent app
that runs everything from your phone.
OpenClaw is the iOS and Android app for managing your AI agents end to end. Monitor sessions live, approve or reject tool calls and handoffs, manage workspaces and bots, and keep a full audit trail — all from your phone. Your data stays on your devices.
Your AI agent dashboard — live, from anywhere.
Sessions, tool calls, tokens, latency — streamed live from your machine to your phone. No polling. No delay. The same AI agent dashboard you'd open on your laptop, now in your pocket. Real-time monitoring without touching your desk.
- Every prompt and every tool call, tagged and timestamped
- Token counts and cost ticking up in real time
- Status flips the moment they happen on your machine
- Replay any session from history, frame by frame
Approve sensitive moves with a swipe.
Tool gates decide what needs human approval — by tool name or pattern, with a risk level and expiry you control. Edit the args before you approve. Reject to stop, or request changes to send feedback and let the agent revise. Audit trail on every action forever.
Tell the agent what's wrong and it revises and resubmits — the decision loop stays open until it's right. And when a WhatsApp or Telegram bot escalates to a human, approve the handoff from your phone too.
Catch the risky moves — even when there's no tool to gate.
Most platforms only allow or block named tools. OpenClaw stacks three layers so a sensitive action gets caught no matter how the agent tries it.
Workspace policies
Allow and deny lists that govern the whole workspace. Start from templates — Safe Agent, Production Guardrails, Read-Only Observer, Communication Safe, Developer Sandbox — or write your own with priorities and rate limits.
Tool gates
Intercept specific MCP tool calls by name or pattern before they reach the server. Each rule carries a risk level, an expiry, and optional auto-approve for trusted roles. The standard human-in-the-loop gate.
Local Guardian
Catches the agent by intent, not by tool name. Even if it never calls an MCP tool — just wants to run a shell command, write a file or deploy — Local Guardian asks you first. 25 templates across files, shell, git, deploy, database, comms, financial and infra.
Tool gates catch named calls. Policies enforce workspace rules. Local Guardian catches everything else — so "approve sensitive actions with a swipe" holds for shell commands, deploys, and emails, not just MCP tools.
Run Claude computer use safely — with a human in the loop.
Claude computer use gives the model direct access to your machine: it reads files, runs commands, edits code, and calls APIs like a developer would. That power needs guardrails. OpenClaw is the mobile control plane for Claude computer use — you see every action the moment it happens, and approve or block the risky ones from your phone before they execute.
- Every Claude tool call streamed to your phone in real time
- Tool gates catch file writes, shell commands and deploys before they run
- Local Guardian blocks dangerous intent — even without a named MCP tool
- Request changes: guide Claude toward a safer approach instead of just blocking
- Full audit trail of every action Claude took on your machine
Works with Claude Code, Claude Desktop, and any MCP-compatible client running on your machine. OpenClaw is model-agnostic — the same guardrail stack applies to GPT, Gemini and open-weight models too.
Don't just block it. Guide the agent to a better version.
Approve or reject are not your only options. Request changes keeps the loop open — tell the agent what's wrong, it revises its approach and resubmits. Every round is logged.
Agent requests approval
Your computer use agent tries a sensitive action — a shell command, a file edit, a deploy. OpenClaw intercepts it and sends a push notification to your phone.
You request changes
Instead of approving or rejecting outright, you send the agent a note: "Don't force-push. Open a PR instead." The approval decision stays open.
Agent revises and resubmits
The agent reads your feedback, adjusts its plan, and resubmits the request. You review the revised action. Repeat until it's right. Every round is logged with timestamps.
The round-trip is especially useful for Claude computer use, where a risky-but-necessary shell command can be rewritten to be safer instead of blocked entirely.
Talk to your agent. Pick up where you left off.
Persistent chat threads let you steer your agent across sessions. Each thread keeps full context — switch tasks on your phone, hand off to your laptop.
- Threads persist across sessions automatically
- Full context injected on resume
- Switch between threads with one tap
Know what your agent is doing — and what it's costing.
From a 60-second glance on your phone to a forensic deep-dive on your laptop. Every prompt, every token, every dollar. Every model. Every tool. Every error.
Decide what your agent can touch — and how it answers.
Plug in MCPs, skills, and functions from the marketplace. Wire up channels: chat, webhook, schedule, push. Push changes to the daemon instantly — no redeploy.
Browse the marketplaceThe AI agent app and control plane — on every surface.
Everything you can do on the desktop AI agent dashboard, you can do on the phone. Pair, monitor, approve, manage tools, view usage. The phone is not a "lite" version — it's the full agent control plane. OpenClaw is the iOS and Android app built for teams who need real control, not just push notifications.
Local AI agent. Your data never leaves your machine.
Your prompts, tool calls, transcripts, audit log — never written to our database. Aerostack is a relay, not a data sink. OpenClaw runs as a local AI agent daemon on your machine; the gateway relays only the events needed to reach your phone. Zero server-side storage, by design.
Aerostack only relays the events needed to sync between your devices. Prompts, transcripts, and audit logs never leave your machine.
Multiple machines
Pair laptops, desktops, servers. All under one agent control plane. Switch between machines in one tap.
Multiple workspaces
Different projects, different clients, different teams. Separate policies, separate audit, separate tool gates.
Push notifications
Approvals, errors, cost spikes, finished tasks. You decide what wakes the phone — no noise, no gaps.
Frequently asked questions
What is a computer use agent?
What can I do from the OpenClaw app?
How does OpenClaw approve tool calls from my phone?
What is the difference between a tool gate and Local Guardian?
What is Local Guardian and what does it protect?
What is the difference between rejecting an action and requesting changes?
Does my agent data leave my machine?
Can my whole team approve agent actions?
Which AI agents and models does OpenClaw support?
Is OpenClaw free and which platforms does it support?
How does OpenClaw work with Claude computer use?
What is an AI agent management platform?
Related features
Pair your machine in 60 seconds.
Free to start. Open-source daemon. No card required.