Clawvisor
Clawvisor is the authorization layer for AI agents — a Y Combinator (Spring 2026) security gateway that sits between an AI agent and the tools it acts on (Gmail, Calendar, Drive, Contacts, GitHub, Slack, Notion, Linear, Stripe, Twilio, iMessage). Agents never hold downstream credentials: they declare a task describing their purpose and the service/action pairs they need, the user approves that scope once, and Clawvisor enforces restrictions, task scope, and LLM intent verification on every request before injecting vaulted, short-lived credentials, executing through an adapter, and writing a full audit trail. It ships open-core as a self-hostable Go daemon with a CLI, web dashboard, TUI, and an OAuth 2.1 MCP server, plus an official Claude Code plugin. Agents integrate over a plain HTTP gateway or MCP — no SDK or agent-code changes required.
Clawvisor publishes 5 APIs on the APIs.io network, including Auth API, Catalog API, Gateway API, and 2 more. Tagged areas include AI Agents, Authorization, Security, Identity, and Access Control.
The Clawvisor catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Clawvisor’s developer surface includes documentation, API reference, getting-started guide, support, pricing, signup flow, authentication, and 18 more developer resources.
Kin Score
APIs 5
Individual APIs this provider publishes, each with its own machine-readable definition.
Clawvisor Auth API
Local magic-link session exchange.
Clawvisor Catalog API
Discover the services and actions available to the agent.
Clawvisor Gateway API
Execute authorized actions on downstream services through the gateway.
Clawvisor Tasks API
Declare, approve, expand, and complete task scopes.
Clawvisor Tokens API
Mint and revoke scoped agent tokens (admin-gated).
Arazzo Workflows 2
Multi-step API workflows described with the Arazzo specification.
_Index
ARAZZOClawvisor — approve-scope-and-triage
Declare a read-scoped task, wait for the user to approve it, list and read messages through the gateway under scope, then complete the task. Every operationId is verified agains...
ARAZZOMCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
clawvisor-mcp.yml
MCP SERVEREvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Clawvisor Callbacks Webhooks
ASYNCAPISecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 3
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use