Run agents on hardware you own. Put a node on your tailnet, then pair it — no inbound port, no keys.
HOSTS
{{ fleetTotal }}
ONLINE
{{ fleetOnline }}
vCPU
{{ vcpu }}
MEMORY
{{ ram }}
CONTAINERS
{{ containersRunning }}
Tailscale network
{{ tailnet }} · live device status
connectedmanage →
{{ d.name }}{{ d.os }}{{ d.ip }}{{ d.seen }}
LOCAL HOSTS+ connect a host
{{ h.name }}{{ h.statusLabel }}
{{ h.os }}
CPU{{ h.cpu }}%
RAM{{ h.ram }}%
disk
{{ h.disk }}%
load
{{ h.load }}
ctrs
{{ h.containers }}
{{ h.sshTarget }}copy
waiting for daemon to dial home…
+
Connect a host
Mac · Linux · edge device
CLOUD PROVIDERS
Power the platform from the cloud
Connect a provider and Clawmates provisions agent runners on demand. Each booted VM runs the same daemon, dials home over outbound WSS, and joins your fleet — credentials stay in the secret broker.
1Connect credentials
Scoped IAM role or API token — held by the secret broker, never reaches agent code.
2Provision a runner
We bake clawmates-node into the image; it boots and dials home — no inbound port.
3Agents run sandboxed
§15 network-isolated sandboxes on the cloud host; every egress is a gated door.
PROVIDERS1 connected
{{ p.short }}
{{ p.name }}
{{ p.regions }}
{{ p.offers }}
{{ p.statusLabel }}
aws
Cloud runners● 2 online · 5 agents~$0.44/hr
{{ r.name }}{{ r.region }}
CPU{{ r.cpu }}%
RAM{{ r.ram }}%
{{ r.agents }} agents{{ r.cost }}
ADD TO FLEET← add to fleet← add to fleetCONNECT A PROVIDER← providers
Connect a host
recommended first step
→
Pair a Mac, Linux box, or edge device. The daemon dials home over outbound WSS — no inbound port, no keys.
Tailscale network
connected · {{ tsDeviceCount }} devices
→
Paste your tailnet + API key for live device status across the whole network.
Cloud providers
AWS · GCP · Azure
NEXT
Local & Tailscale first. Cloud provisioning arrives next.
Connect a host
3 steps · ~2 min
123
Install the daemon
We minted a one-time token. Run this on the node you're adding: