1claw-crewai-tools
CrewAI agents need credentials and signing keys, but crew configs are not a safe place to store them. Hard-coded API keys end up in git. Shared .env files break when you spin up parallel agents with different permissions.
1claw-crewai-tools wraps the 1Claw API as CrewAI-compatible tools. Each tool fetches secrets at runtime, signs transactions server-side, and writes to encrypted agent memory. Access is policy-scoped: your agent only sees vault paths a human explicitly granted.
Drop in get_all_tools(client) and your crew gets 11 tools (vault, memory, signing, automations) with one OneclawClient initialized from ONECLAW_AGENT_API_KEY.
Install
pip install 1claw-crewai-tools
PyPI package:
1claw-crewai-tools· Python import:oneclaw_crewai
Quick Start
All tools at once (recommended)
import os
from crewai import Agent, Crew, Process, Task
from oneclaw_crewai import OneclawClient, get_all_tools
client = OneclawClient(
api_key=os.environ["ONECLAW_AGENT_API_KEY"],
# agent_id and vault_id are auto-resolved from the API key
)
tools = get_all_tools(client) # 11 tools
researcher = Agent(
role="Blockchain Researcher",
goal="Check wallet balances and sign transactions",
backstory="You use 1Claw tools for all credential and signing operations.",
tools=tools,
)
task = Task(
description="Check the Ethereum balance, then sign the message 'hello world'.",
expected_output="Balance and signature details.",
agent=researcher,
)
crew = Crew(agents=[researcher], tasks=[task], process=Process.sequential)
crew.kickoff()
Single tool (backward-compatible)
from oneclaw_crewai import OneclawVaultTool
vault_tool = OneclawVaultTool(
agent_id=os.environ["ONECLAW_AGENT_ID"],
api_key=os.environ["ONECLAW_AGENT_API_KEY"],
vault_id=os.environ["ONECLAW_VAULT_ID"],
)
agent = Agent(
role="Engineer",
goal="Build features using vault-stored API keys",
backstory="You use tools instead of pasted secrets.",
tools=[vault_tool],
)
Available Tools
| Tool | Name | Description |
|---|---|---|
OneclawVaultTool |
oneclaw_vault |
Fetch a decrypted secret by path |
OneclawPutSecretTool |
oneclaw_put_secret |
Store or update a secret |
OneclawListSecretsTool |
oneclaw_list_secrets |
List secrets (paths, not values) |
OneclawRotateSecretTool |
oneclaw_rotate_secret |
Server-side secret rotation |
OneclawMemoryPutTool |
oneclaw_memory_put |
Store a value in encrypted memory |
OneclawMemoryGetTool |
oneclaw_memory_get |
Retrieve a value from memory |
OneclawMemorySearchTool |
oneclaw_memory_search |
Semantic search over memory |
OneclawSignMessageTool |
oneclaw_sign_message |
EIP-191 message signing |
OneclawSubmitTransactionTool |
oneclaw_submit_transaction |
Sign and broadcast transactions |
OneclawGetBalanceTool |
oneclaw_get_balance |
Check signing key balances |
OneclawTriggerAutomationTool |
oneclaw_trigger_automation |
Trigger automation workflows |
Multi-Agent Crew Example
from crewai import Agent, Crew, Process, Task
from oneclaw_crewai import OneclawClient, get_all_tools
client = OneclawClient(api_key=os.environ["ONECLAW_AGENT_API_KEY"])
tools = get_all_tools(client)
# Agent 1: Manages secrets and credentials
secrets_agent = Agent(
role="Secrets Manager",
goal="Manage and rotate API credentials securely",
backstory="You handle all credential lifecycle operations.",
tools=tools,
)
# Agent 2: Handles blockchain operations
blockchain_agent = Agent(
role="Blockchain Operator",
goal="Execute blockchain transactions safely",
backstory="You check balances and sign transactions using 1Claw.",
tools=tools,
)
# Agent 3: Remembers context across sessions
memory_agent = Agent(
role="Knowledge Manager",
goal="Store and recall important information",
backstory="You use encrypted memory for persistent knowledge.",
tools=tools,
)
rotate_task = Task(
description="Rotate the secret at 'api-keys/external-service'.",
expected_output="Confirmation of rotation with new version number.",
agent=secrets_agent,
)
balance_task = Task(
description="Check the Ethereum signing key balance.",
expected_output="Native balance in ETH.",
agent=blockchain_agent,
)
remember_task = Task(
description="Store today's rotation status in memory under key 'last-rotation'.",
expected_output="Confirmation that the value was stored.",
agent=memory_agent,
)
crew = Crew(
agents=[secrets_agent, blockchain_agent, memory_agent],
tasks=[rotate_task, balance_task, remember_task],
process=Process.sequential,
)
crew.kickoff()
Authentication
The OneclawClient supports two auth patterns:
Key-only (recommended) — agent ID and vault ID auto-resolved:
client = OneclawClient(api_key="ocv_...")
Explicit IDs — for backward compatibility or multi-vault setups:
client = OneclawClient(
api_key="ocv_...",
agent_id="<agent-uuid>",
vault_id="<vault-uuid>",
)
Platform v0.56+ (HITL, HFA, Safe, guardrail governance)
Tools call 1Claw API v0.56+. Server-side behavior (no Python package API changes):
- Graduated HITL —
OneclawSubmitTransactionToolmay receive202 awaiting_approvalfor human review. - Guardrail governance — Agent execution and widening guardrail edits may require approval; configure via dashboard/CLI.
- Safe foundation — Counterfactual Safe accounts via Vault agent accounts API.
- Multichain signing — EVM, BTC, SOL, XRP, ADA, TRX unchanged; Vault uses
rust-bitcoin,solana-sdkv4,xrpl-rust1.1.0.
Testing
Unit tests (offline, no credentials needed)
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
pytest -v
ruff check src tests
All network calls are mocked with respx; no 1Claw account required.
Security
- Tool output can contain plaintext credentials. Never
print()or log return values. - All tools set
cache_functionto always returnFalse— no framework-level caching. - CrewAI's
verbose=Trueprints tool output to stdout — useverbose=Falsein production. - Private signing keys never leave the HSM — signing happens server-side.
Links
License
MIT — see LICENSE.
Release files for 1claw-crewai-tools 0.3.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| 1claw_crewai_tools-0.3.2.tar.gz | 14.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| 1claw_crewai_tools-0.3.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 27.4 kB
Release files / 1claw_crewai_tools-0.3.2.tar.gz
| Download URL | 1claw_crewai_tools-0.3.2.tar.gz |
|---|---|
| Size | 14.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c3bfb8cd8759fa7e5e61711eb69f05203caf66d17e801ad9454c8055d48abd81
|
|
BLAKE2b-256 checksum How to use checksums |
de6117d631c2e06176de587df00b735bbe37bc609d1a0b2ba44ac459fd5dec7c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 24, 2026.
Transparency logRelease files / 1claw_crewai_tools-0.3.2-py3-none-any.whl
| Download URL | 1claw_crewai_tools-0.3.2-py3-none-any.whl |
|---|---|
| Size | 12.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
450aacff39f5390346fdd7470300c9c6ab503056e2e59a90569d310539e3d1a7
|
|
BLAKE2b-256 checksum How to use checksums |
219b405e9ff80f535b1394d612129903d4f39b6973340597f15d7702b8a533e5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 24, 2026.
Transparency log