How It Works

What happens between your agent, ClawLink and the app on every tool call

ClawLink is one hosted app on claw-link.dev. The same app serves the dashboard, the pairing pages and the connect flows, and it runs every tool call. Pairing, connections and execution use the same data, so they always agree.

One tool call, end to end

Your agent

Calls a ClawLink tool with its device credential.

Check

ClawLink finds your account, your plan and the right connection.

Sign

It adds the app's credential to the request. Your agent never sees it.

Call

The app's API runs the action. ClawLink retries short failures.

Log

The result goes back to your agent and into Logs.

Step by step

Pairing and connect flows start on claw-link.dev

You sign in, approve browser pairing, and connect apps from the dashboard. The provider's sign-in pages send you back here when you finish.

Each connect flow creates or updates one exact connection

Every connect flow is tied to one connection. When it finishes, ClawLink saves that connection with its own stable id, its label, and whether it is the default for that app. You can connect more than one account of the same app.

Your agent authenticates with its ClawLink device credential

Pairing stores one ClawLink credential on your agent's machine. The agent sends it when it lists tools, previews an action or runs one.

ClawLink picks the right connection

ClawLink finds the app and the connection for the request. If you have more than one account for the same app, it uses the default one, unless the request names a specific connection.

The app's credential is used only for the live call

ClawLink makes the provider API call with the stored credential, records the result, and returns the response to your agent.

Security

Tokens stay with ClawLink

For most apps, OAuth tokens are held by Composio, our credential partner. ClawLink keeps only a reference.

Keys are encrypted

An API key you enter is encrypted with AES-256-GCM and decrypted only for the live request.

Your machine holds one credential

Your agent stores only its ClawLink device credential. No provider token reaches it.

Delete one connection at a time

Removing a connection removes only that account, not every account of the app.

Treat the ClawLink device credential on your machine like a password. If you think someone has it, revoke it in Settings > Developer or Devices, and pair again.

See Security for the full picture.

Built-in reliability

  • Retries with backoff. When an app returns a short-lived error, ClawLink tries again, and waits longer between each try.
  • Rate limits. When an app limits requests, ClawLink paces the calls and tells your agent when to try again.
  • Connection-aware routing. With more than one account for an app, ClawLink uses your default connection instead of guessing.

Every call, successful or not, shows in Dashboard > Logs with the app, the action, the status and the latency, so you can see what your agent actually did.

On this page