Działa na Twoim komputerze · podejmuje działania tylko na Twoje polecenie
Warstwa sterowania
dla agentów AI
- Zobacz każdego agenta.
- Zrozum każde działanie.
- Zatrzymaj to, co nie powinno się wydarzyć.
ClawMetry odczytuje 26 środowisk agentowych, których Twój zespół już używa, od Claude Code i Cursor po Codex i OpenClaw, prosto z plików, które one i tak zapisują. Do agenta nie trzeba nic dodawać.
$ pip install clawmetry && clawmetry
7 dni, wszystkie środowiska, bez karty. Potem $9 lub $19 za węzeł miesięcznie.
“claude_code: 84 tool calls, no file changes, not advancing.” Stop or Pause this agent from the ClawMetry dashboard or device.
Verbatim record, not a mockup. A real detection from the laptop ClawMetry was built on. The steps, the counts and the message are what the daemon wrote to disk.
❯ Supported agent runtimes
Don't see the agent harness you use?
Just share it and we'll add support in ~2 days. Leave your email and we'll ping you the moment it's live, plus 2 months of Pro, on us.
We only use your email to notify you and issue the Pro credit. No lists, no spam.
Zmierzone, jedna instalacja, cztery miesiące
Oznacza agentów, którzy utknęli,
a nie tych, którzy kosztują.
Długa, kosztowna sesja to często Twoja najlepsza praca, więc narzędzie polujące na duże liczby zabiłoby nie to, co trzeba. ClawMetry sprawdza, czy agent w ogóle coś produkuje. Ten sam laptop, cztery miesiące, oba przypadki obok siebie.
Pracuje · nigdy nie oznaczony
$171.58
The most expensive session of the four months. It ran long and cost real money, and it was writing code the whole time. ClawMetry left it alone, which is the correct answer.
Oznaczony · utknął
$175.10
Every one caught for the same reason: tool calls with no file changes, the same failure repeating, or a loop that stopped advancing. Most of them cost less than the session on the left.
Detektory ostrzegają. Nie podejmują działań. Wszystkie siedem tych sesji dobiegło końca. Oznaczenie to powiadomienie, nie wyzwalacz. Nic nie zostaje zatrzymane, dopóki nie zatrzyma tego człowiek albo dopóki sam nie ustawisz limitu wydatków, który agent przekroczy.
165 sessions and $826.47 of agent spend on one developer’s laptop, April to August 2026. One machine, not a customer aggregate. Yours will look different, which is the reason to read your own.
Zobacz w działaniu
Jeden ekran. Wszystko, co dzieje się u Twoich agentów.
Luki widać w tabeli
Co potrafimy, w każdym środowisku.
Każdy dostawca w tej kategorii mówi o zabezpieczeniach. To cała macierz, razem z pustymi polami.
| Środowisko | Obserwacja | Blokada przed uruchomieniem | Przerwanie w trakcie | Koszt w dolarach |
|---|---|---|---|---|
| OpenClaw, NVIDIA NemoClaw, Goosefree forever | ✓ | via proxy | ✓ | ✓ |
| Claude Codethe only pre-execution tool gate | ✓ | ✓ | ✓ | ✓ |
| Codex, OpenCode, Aider | ✓ | via proxy | ✓ | ✓ |
| Cursorone IDE process holds every session | ✓ | – | – | – |
| GitHub Copilotbilled in vendor credits, not USD | ✓ | – | – | – |
| NanoClaw, PicoClaw, Kimi CLIno model id on disk | ✓ | – | – | – |
| Qwen, Hermes, Pi, Deep Agents, n8n, Antigravity, Grok, QM, DeepSeek Harness, Exo |
✓ | via proxy | – | ✓ |
Blokada przed uruchomieniem
Claude Code gets a real pre-execution gate: a PreToolUse hook parks the call before the tool fires. Everything routed through the ClawMetry proxy gets spend refused with a 429 before tokens are spent.
Przerwanie w trakcie
A gateway kill for OpenClaw, and SIGSTOP then SIGKILL against the process tree for the CLI runtimes, with a guard so a recycled pid is never the one we hit. macOS and Linux. Windows has no SIGSTOP, so pause and resume do not exist there.
Audyt po fakcie
Every event carries a SHA-256 chain over its immutable fields, per node, with a verifier command. Approval decisions land in an append-only log. Works on every runtime.
Zanim wpuścisz demona na swój laptop
Co robi z komputerem
i co z niego wychodzi.
Zmierzone na tym samym laptopie, nie oszacowane.
Zużycie zasobów
clawmetry uninstallThe query server binds to loopback only, with a one-time 32-hex token and a discovery file at mode 0600. It is why the dashboard can read the store without holding the writer lock.
Co dokładnie wychodzi
Never. These stay in the local file.
The key is generated on the node and never leaves it. Decryption happens in your browser. Compelled by a subpoena, we hand over a blob we cannot open, plus the node id, the version and some counters.
Lokalny plik jest zapisany jawnym tekstem
Everything is sealed in transit and at rest in our cloud, and it is not encrypted on your own disk. The DuckDB file carries default user permissions. Anything running as your user can read it.
Redakcja danych w razie błędu przepuszcza treść
Secrets are fingerprinted at ingest by default, before disk. It is pattern-based, and on an internal error it keeps the original value rather than dropping data. It is tuned for credential shapes, not customer PII.
Podłączony węzeł można zatrzymać zdalnie
If you turn cloud on, Stop, Pause and Resume are reachable from the dashboard and the desk device for any node on the account. That is the feature. Run local-only and no such channel exists.
Starred by the people building AI
Engineers and founders from OpenAI, Google, PostHog and more have starred ClawMetry on GitHub. One of them helped build it.
Trzy miejsca na uruchomienie
Cloud jest opcjonalny.
Zawsze był.
Demon liczy wszystko do pliku DuckDB na Twoim własnym dysku. Gdzie potem mieszka panel, to Twoja decyzja, a stawka jest ta sama niezależnie od wyboru.
01 · Local only
Nic nie wychodzi
Included in the MIT core
The dashboard reads the local file through a loopback query server. There is no account, no sync and no destination to point at.
- Network destinations: none
- Inbound ports opened: 0
- Free forever for OpenClaw, NVIDIA NemoClaw and Goose
02 · Our cloud
Zapieczętowane, zanim wyjdzie
$19 per node, per month
The snapshot is encrypted on the node with a key generated there and never sent. Your browser decrypts it. Subpoena us and we hand over a blob we cannot open.
- AES-256-GCM, key held on the node
- Decryption happens client side
- Stop, Pause and Resume reach any node on the account
03 · Self-hosted
Twoja infrastruktura, dedykowana instancja
$190 per node, per year
One container serves the UI and the ingest API on your own network, with node tokens and admin auth. Licences verify offline against an embedded Ed25519 key you can fingerprint and compare.
- No calls to clawmetry.com beyond an off-by-default version ping
- Same feature set, same runtimes, same rate
- Two months free against the monthly price
Stawka nie zmienia się wraz z modelem wdrożenia. Self-hosted to $19 za węzeł miesięcznie albo $190 za węzeł rocznie, dokładnie tak jak w planie Cloud, bo płacisz za oprogramowanie, a nie za nasze serwery. Zmienia się to, kto trzyma dane i kto uruchamia kontener. Kup klucz self-hosted bez rozmowy z kimkolwiek.
Jedna stawka, jeden licznik
Policz swoją kwotę,
zanim z kimkolwiek porozmawiasz.
7 days, every runtime, no card
$19per node, per month
Pro, billed monthly. Starter is $9 and covers fewer features, not fewer runtimes. Annual is $190 per node, two months free. Free forever for OpenClaw, NVIDIA NemoClaw and Goose.
Start the trial- Every runtime, including Claude Code, Codex and Cursor.
- Cloud or fully self-hosted, at the same rate. Unlimited chat channels.
- Waste flags, error triage, cost optimizer, OTLP export, tool policy.
- Cancel any time in Stripe. No contract, no seat count.
Already decided? Buy now and install after. Your key is on the next screen.
Ile Cię to kosztuje
Licz maszyny, na których będzie działał demon, a nie ludzi, którzy będą na to patrzeć.
$551 $6,612 per year · 29 nodes
A node is a machine running the daemon and reporting a heartbeat. The unit of attribution is a machine, so spend maps to a laptop, not to a team. The same number applies self-hosted, so you can price a deployment on your own infrastructure off this figure without asking us. Ephemeral CI runners are not yet specified; the fleet brief carries the rule in writing before you sign.
Dla tych, którzy odpowiadają za ryzyko
Wdrożenie w całej firmie.
Twoi inżynierowie zainstalowali w zeszłym kwartale Claude Code, Cursor, Codex i Copilot. Nikt tego formalnie nie kupił, a wszystkie mają Twoje repozytorium i Twoje klucze.
Nic do instalowania w agencie
Each runtime is read from the session store it already writes. No SDK, no wrapper, no second agent on the laptop, nothing a developer has to opt into or can forget.
A control layer that governs only its own SDK is blind to everything a developer runs outside it.Hosting własny to odpowiedź na SSO
SSO does not exist yet. Single-tenant self-hosted does: one container serves the UI and the ingest API, with node tokens and admin auth, and licences verify offline against an embedded Ed25519 key you can fingerprint and compare.
A self-hosted deployment makes no calls to clawmetry.com beyond an off-by-default version ping.Pasuje do sieci, którą już masz
SIEM and syslog export in CEF or JSON over TCP, UDP or TLS, emitted daemon-side because the cloud never holds plaintext. Corporate TLS interception is supported, with a doctor command that walks DNS, TCP, proxy and TLS in order.
In: your collector feeds us over OTLP. Out: full-event SIEM export. Not yet: correlated spans carrying your trace ids.Wdrożenie na całą flotę jest dziś ręczne
There is no Helm chart, no Terraform provider and no Intune or Jamf package. If a daemon on developer laptops is a non-starter, run the enforcement proxy centrally and govern spend without touching an endpoint.
Auto-update ships on by default. CLAWMETRY_AUTO_UPDATE=0 turns it off. No staged rollout, no version pinning.Pytania, które słyszymy za każdym razem.
Czy możecie zablokować coś przed uruchomieniem, czy tylko poinformować, że się wykonało?
Both, and the split is in the table above. Claude Code gets a genuine pre-execution tool gate, and anything routed through the proxy gets spend refused with a 429 before tokens are spent. For the other runtimes it is detection plus process control: we can see it and end it, we cannot veto the call it already made.
Czy sam zatrzyma moich agentów?
No. Detectors write a warning and stop there. On the reference install every flagged session ran to completion. A run ends only when a person ends it, or when you have set a spend cap yourself and an agent crosses it.
Czy zmienia sposób działania moich agentów?
Read-only by default. Two things you opt into change that: the proxy, a separate process you point one env var at, and approval gates, where ClawMetry adds a gate to the runtime’s own permission system and removes only what it added.
Co się stanie, gdy skończy się mój okres próbny?
The paid runtimes stop being read and the free three keep working. Entitlements are a commercial boundary, not a technical one. We do not hard-block a running fleet on a licence check.
Kto za tym stoi i co się stanie, jeśli znikniecie?
One person, plus contributors. The core is MIT and runs on your machine, so if we vanish your install keeps working and your data stays in a DuckDB file you own. The paid layer is a separate closed package. Ask for the fleet brief and it names the legal entity, the largest deployment we run today, and the reference count, with no rounding.
Czy przejdzie audyt bezpieczeństwa?
For a pilot on non-production machines, usually: MIT source you can audit, local-first storage, single-tenant self-hosted and offline licence verification are the arguments that work. For a regulated production rollout, read the gap list first. SSO, RBAC beyond owner and member, SOC 2, CAIQ and a third-party pen test are all absent, and that is a two-to-four quarter conversation.