Authenticate
KClaw opens a unique browser URL and waits for you to approve the CLI with Google Sign-In.
Documentation / Overview
KClaw is the technical platform that packages, distributes, and manages the agent profiles, templates, skills, integrations, and runtime lifecycle used by the KORIKA Claw ecosystem.
Credentials, memories, sessions, logs, and other user state are never copied into a KClaw template.
KClaw requires Node.js 20 or newer. Remote templates require Git. Install a recent Hermes CLI, an OpenClaw CLI with experimental Claws support, or both.
curl -fsSL https://klausul.gits.app/install.sh | shThe installer verifies the bundle checksum and installs the KClaw CLI under ~/.local/bin.
$ kclaw --version
$ kclaw hermes status
$ kclaw openclaw statusRun an install, update, use, or remove command without --target to choose Hermes or OpenClaw in an interactive wizard. Scripts and other non-interactive callers must specify the target.
$ kclaw template install ./my-agent
$ kclaw template install ./my-agent --target hermes
$ kclaw template install ./my-agent --target openclawKClaw delegates to Hermes' native profile-distribution commands. Install and update also apply the bundled Hermes security guard. Hermes-only options include --alias, --force, and --force-config.
KClaw initializes an isolated named profile with openclaw --profile NAME setup --baseline, then previews and applies the template's native Claw package inside it. The exact plan is bound by OpenClaw's planIntegrity; KClaw displays it and asks before applying. Use --yes only for a plan already reviewed in non-interactive operation.
CLAW.md. The Python security guard is Hermes-specific and is not installed into OpenClaw.Sign in once, browse the templates assigned to your account, and install by catalogue ID.
$ kclaw login
$ kclaw template list
$ kclaw template install research-agentKClaw opens a unique browser URL and waits for you to approve the CLI with Google Sign-In.
List your catalogue or use a template ID you already know.
Select Hermes or OpenClaw, then review the native profile plan.
$ kclaw template upload ./my-agent
$ kclaw template add shared-research-agent
$ kclaw template remove-from-catalog shared-research-agentUploads are limited to 10 MiB and are scanned for secrets, state databases, symlinks, and unsupported files.
$ kclaw admin assign aiis-2026-assistant user@example.com
$ kclaw admin revoke aiis-2026-assistant user@example.comExclusive templates are hidden from discovery and can only be assigned by an administrator configured on the backend.
Creating, inspecting, and installing local templates does not require a KClaw account.
$ kclaw template create ./my-agent --description "My coding agent"
$ kclaw template inspect ./my-agent
$ kclaw template install ./my-agent --name my-agentYou can also inspect and install directly from Git:
$ kclaw template inspect github:owner/my-agent
$ kclaw template install github:owner/my-agent --target openclaw$ kclaw template use my-agent --target openclaw
$ kclaw template update my-agent --target openclaw
$ kclaw template remove my-agent --target openclawHermes updates preserve config.yaml by default. OpenClaw updates refresh the recorded local, Git, or catalogue source and apply its native Claw update plan. OpenClaw removal preserves the named profile and user-owned state.
A template contains a native Hermes distribution. To support OpenClaw too, include its native package metadata and Claw manifest alongside the shared persona and capability files.
my-agent/
├── distribution.yaml Hermes
├── package.json OpenClaw package
├── CLAW.md OpenClaw manifest
├── SOUL.md
├── config.yaml
├── skills/
│ └── research/SKILL.md
├── mcp.json
└── cron/
name: my-agent
version: 1.0.0
description: A focused research assistant
hermes_requires: ">=0.2"
distribution_owned:
- SOUL.md
- config.yaml
- skills/
- mcp.json
- cron/
---
schemaVersion: 1
agent:
id: my-agent
workspace:
bootstrapFiles:
SOUL.md: { source: SOUL.md }
files:
- source: skills/research/SKILL.md
path: skills/research/SKILL.md
packages: []
mcpServers: {}
cronJobs: []
---
kclaw template create generates both manifests. List every bundled skill asset under workspace.files, translate servers and schedules to mcpServers and cronJobs, and place OpenClaw-specific tool or memory policy in profiles/openclaw.yml.
.env, auth.json, memories, sessions, logs, and databases.kclaw login [--api-url URL]Connect the CLI to your cloud account.
kclaw auth statusShow the currently authenticated account.
kclaw hermes statusCheck whether Hermes is available.
kclaw openclaw statusCheck whether OpenClaw is available.
kclaw logoutRemove the saved cloud login.
kclaw admin assign <template-id> <user-email>Assign an exclusive template to a user who has signed in.
kclaw admin revoke <template-id> <user-email>Revoke an exclusive template assignment.
kclaw template create <directory> [--name NAME] [--description TEXT]Create a valid template scaffold.
kclaw template upload <directory>Validate, upload, and add a template to your catalogue.
kclaw template listList templates in your cloud catalogue.
kclaw template inspect <source>Preview a local or remote template without installing it.
kclaw template install <source> [--target hermes|openclaw] [--name NAME] [--alias] [--force] [--yes]Choose a runtime and install its native profile package.
kclaw template update <profile> [--target hermes|openclaw] [--force-config] [--yes]Preview and update through the selected runtime.
kclaw template use <profile> [--target hermes|openclaw]Open or switch to the selected runtime profile.
kclaw template remove <profile> [--target hermes|openclaw] [--yes]Remove managed template state through the selected runtime.
The hosted service at https://klausul.gits.app uses an OAuth 2.0 device flow, Google Sign-In for browser approval, and an authenticated template catalogue.
/oauth/device/codeStart device authorization.
/oauth/tokenPoll for authorization and obtain an access token.
/v1/meVerify the authenticated account.
/v1/templatesUpload and validate a template bundle.
/v1/catalog/templatesList the authenticated user's catalogue.
/v1/catalog/templates/:idResolve an installable Git source.
/v1/admin/catalog/assignmentsList exclusive templates, users, and assignments.
/v1/admin/catalog/templates/:id/users/:emailAssign an exclusive template.
Send access tokens as Authorization: Bearer <token>. HTTP 401 tells the CLI to request a new login.