Skip to main content

CLI to chat with an ArkClaw EE space's Claw over enterprise SSO — zero permanent AK/SK.

Project description

arkclaw

Chat with your ArkClaw claws (agents) from the terminal — log in with your own SSO identity, no passwords, no permanent keys. Works the same for a human at a prompt and for another agent/script (--json + exit codes).

arkclaw login https://your-space.arkclaw-enterprise-bj.volceapi.com   # browser SSO, once
arkclaw agents                                                        # list the claws you can chat
arkclaw chat ci-xxxxxxxx                                              # talk to one

What it can do

  • Log in as you — browser SSO (PKCE), short-lived token, auto-refresh. No AK/SK, no client secret, nothing permanent on disk but a token in your OS keychain.
  • List your agentsarkclaw agents shows the claws you can chat with.
  • Chat — interactive REPL or one-shot -m, streaming token-by-token, with a live "what's it doing" spinner and tool-event trace.
  • Talk to a specific claw — by id (chat ci-...) or by name (chat 答疑助手).
  • Manage a claw's files — read/write its managed workspace files (AGENTS.md, SOUL.md, MEMORY.md, …) with ls / pull / push.
  • Fan out — send one message to many claws in parallel.
  • Be scripted — every command takes --json (one clean {ok,data,error} envelope on stdout) and returns a typed exit code.

Two transports, picked at login: openclaw (your claws, the default) and a2a (an agent endpoint).


Install

pip install arkclaw-webchat-cli          # provides the `arkclaw` command

From source:

git clone <repo> && cd ee-claw
uv venv && uv pip install -e .

Quick start

# 1. log in to your space (a browser opens; sign in with SSO)
arkclaw login https://your-space.arkclaw-enterprise-bj.volceapi.com

# 2. see which claws you can talk to
arkclaw agents

# 3. chat — interactive…
arkclaw chat ci-xxxxxxxx
#    …or one-shot:
arkclaw chat ci-xxxxxxxx -m "用一句话介绍你自己"

login figures out the rest from the address (your identity pool, region). If your space hasn't published auto-discovery yet, you may need to point it at the STS role once — see Configuration.


Commands

Command What it does
arkclaw login <space-url> Browser SSO login. --transport a2a --endpoint <url> for an agent endpoint. --clawid ci-... sets a default claw (otherwise the last one you opened in the browser). Bare arkclaw login re-logs into the previous space.
arkclaw agents List the claws/agents you can chat with.
arkclaw chat [TARGET] [MSG] Chat. TARGET = a claw id (ci-...), an agent name (from agents), or a profile. With MSG → one-shot; without → interactive REPL. -f attach files, -o write the reply, --session NAME name the conversation, --approve-all auto-approve tool runs.
arkclaw <name> Shortcut: arkclaw 答疑助手arkclaw chat 答疑助手.
arkclaw ls List the claw's managed workspace files.
arkclaw pull <name> [local] Download a managed file to local disk.
arkclaw push <local> [name] Write a local text file into a managed file.
arkclaw fanout "<msg>" --clawid ci-a --clawid ci-b Same message to many claws in parallel.
arkclaw sessions Recent chat sessions on this machine.
arkclaw profile save/use/list Named snapshots of the session config (multi-space / multi-claw).
arkclaw doctor Self-check: login freshness, keychain, pool/STS/endpoint reachability.
arkclaw schema --json Machine-readable command surface (for agents/tooling).
arkclaw claw list/describe/create/delete Fleet management on the control plane.

All commands accept --clawid ci-... (where relevant) to target a specific claw, and --json for machine output.


Chatting

arkclaw chat ci-xxxx                       # REPL with that claw (Ctrl-C: interrupt turn; twice: exit)
arkclaw chat ci-xxxx -m "你好"             # one-shot
arkclaw chat 答疑助手 -m "怎么部署"         # by name (names come from `arkclaw agents`)
echo "$DATA" | arkclaw chat ci-xxxx --json -m "总结" | jq -r .data.reply   # piped, machine
arkclaw chat ci-xxxx -f notes.md -m "review" -o out.md   # attach context, save reply
  • Streaming on both transports; until the first token a spinner shows elapsed time + the running tool.
  • Sessions are server-side--session NAME keeps a named conversation that survives CLI restarts.
  • Tool approvals: in a terminal you're prompted; headless it fails closed (deny) unless --approve-all; a ~/.arkclaw/cmdpolicy.json deny-list always wins.

Files

ls / pull / push operate on a claw's managed workspace files — its "brain": AGENTS.md, SOUL.md, MEMORY.md, TOOLS.md, IDENTITY.md, USER.md, HEARTBEAT.md. (This is not a general file store — arbitrary filenames are rejected.)

arkclaw ls                          # list them (defaults to your default claw)
arkclaw pull SOUL.md                # download SOUL.md here
arkclaw pull AGENTS.md ./agents.md  # download to a path
arkclaw push ./agents.md AGENTS.md  # write a managed file
arkclaw ls --clawid ci-other        # a different claw

For agents / automation

  • --json → stdout is exactly one {ok, data, error} document; progress/streaming goes to stderr. Pipe to jq.
  • Exit codes: 0 ok · 1 api · 2 validation · 3 auth · 4 network · 5 internal.
  • Headless never blocks: --json / piped stdin refuse the interactive REPL; tool approvals fail closed.
  • arkclaw schema --json describes every command + option for programmatic discovery.

Identity & security

  • Identity-through, zero permanent secrets. Browser PKCE (S256, public client, loopback) → a short-lived id_token that is your user identity (same as the web app), auto-refreshed. The claw sees you, not a shared key.
  • openclaw path exchanges that token (via a least-privilege STS role that can do exactly GetClawInstanceChatToken) for a one-time ChatToken, then connects over wss. a2a presents the token directly to the agent's gateway.
  • Tokens live in the OS keychain (0600 file fallback). The config file holds only non-secret routing. Every upstream error is redacted (tokens / AK-SK) before display.

Configuration

login resolves config in this order: explicit flag → ARKCLAW_* env → the space's published discovery → derived from the address. You normally only type the address. Until your platform publishes auto-discovery, a deployment may supply these (non-secret) via env:

Env Purpose
ARKCLAW_CLIENT_ID The CLI's public OAuth client id for the pool.
ARKCLAW_ROLE_TRN STS role that mints the ChatToken (openclaw).
ARKCLAW_REGION / ARKCLAW_SPACE_ID Override region / space (usually auto).

Other config: ~/.arkclaw/session.json (routing, 0600), ~/.arkclaw/cmdpolicy.json (tool-approval allow/deny), OS keychain (tokens).

Escape hatch (admin/test): arkclaw login <url> --transport openclaw --static-creds uses VOLCENGINE_ACCESS_KEY/SECRET_KEY from the env instead of SSO — convenient for CI, but it's account-level keys, not identity-through.


Notes

  • ls/pull/push and a bare chat use your default claw (set at login, or the last one you opened in the browser); override with --clawid (or chat ci-...).
  • File commands cover the claw's managed files only; arbitrary file drop isn't exposed by the API.
  • Nothing is hardcoded per space — the CLI reads what the space serves.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

arkclaw_webchat_cli-0.2.0.tar.gz (58.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

arkclaw_webchat_cli-0.2.0-py3-none-any.whl (70.8 kB view details)

Uploaded Python 3

File details

Details for the file arkclaw_webchat_cli-0.2.0.tar.gz.

File metadata

  • Download URL: arkclaw_webchat_cli-0.2.0.tar.gz
  • Upload date:
  • Size: 58.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.9.2

File hashes

Hashes for arkclaw_webchat_cli-0.2.0.tar.gz
Algorithm Hash digest
SHA256 c50fcf41f81fb32b2d4f33e0f81fbbc4de57c8eb713d8a7ac8a7333bce02b6d5
MD5 47735718cb617aecaf04ecd9c01b26b1
BLAKE2b-256 a2f599e9fd6be1cd21d1c93c4e54dffc689ccdf02ddc5b8c25ff7a71729b48ab

See more details on using hashes here.

File details

Details for the file arkclaw_webchat_cli-0.2.0-py3-none-any.whl.

File metadata

File hashes

Hashes for arkclaw_webchat_cli-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 5e90fdaeca6519a86907549883976f5255e5985a91a40ce89baae079cf703e2f
MD5 30e553b817d7842d3b6ae9b4c9a09394
BLAKE2b-256 412444a7624a896049608a2d95a054611e1ba931a139542a074e96a938f8b055

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page