Ironclaw MCP Server
by ironseccoio.github.IronSecCo/ironclawv0.1.535
Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.
context tax
queued
security
queued
cold start
queued
freshness
Active12d ago
Install Ironclaw MCP server
Install in Claude Code
claude mcp add ironclaw -e IRONCLAW_CONTROLPLANE_URL='<ironclaw-controlplane-url>' -e IRONCLAW_API_TOKEN='<ironclaw-api-token>' -- docker run -i --rm -e IRONCLAW_CONTROLPLANE_URL -e IRONCLAW_API_TOKEN ghcr.io/ironsecco/ironclaw-mcp:v0.1.535Install in Cursor
{
"mcpServers": {
"ironclaw": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"IRONCLAW_CONTROLPLANE_URL",
"-e",
"IRONCLAW_API_TOKEN",
"ghcr.io/ironsecco/ironclaw-mcp:v0.1.535"
],
"env": {
"IRONCLAW_CONTROLPLANE_URL": "<ironclaw-controlplane-url>",
"IRONCLAW_API_TOKEN": "<ironclaw-api-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"ironclaw": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"IRONCLAW_CONTROLPLANE_URL",
"-e",
"IRONCLAW_API_TOKEN",
"ghcr.io/ironsecco/ironclaw-mcp:v0.1.535"
],
"env": {
"IRONCLAW_CONTROLPLANE_URL": "<ironclaw-controlplane-url>",
"IRONCLAW_API_TOKEN": "<ironclaw-api-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"ironclaw": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"IRONCLAW_CONTROLPLANE_URL",
"-e",
"IRONCLAW_API_TOKEN",
"ghcr.io/ironsecco/ironclaw-mcp:v0.1.535"
],
"env": {
"IRONCLAW_CONTROLPLANE_URL": "<ironclaw-controlplane-url>",
"IRONCLAW_API_TOKEN": "<ironclaw-api-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"ironclaw": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"IRONCLAW_CONTROLPLANE_URL",
"-e",
"IRONCLAW_API_TOKEN",
"ghcr.io/ironsecco/ironclaw-mcp:v0.1.535"
],
"env": {
"IRONCLAW_CONTROLPLANE_URL": "<ironclaw-controlplane-url>",
"IRONCLAW_API_TOKEN": "<ironclaw-api-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| IRONCLAW_CONTROLPLANE_URL | yes | — | Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed. |
| IRONCLAW_API_TOKEN | yes | yes | Bearer token for the control-plane API (the value the control-plane was started with). |
Freshness
Active — last maintenance signal 12d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-28 · 12d ago · GitHub
Latest release
2026-09-28 · 12d ago · GitHub · v0.1.535
Package published
no data · npm/PyPI
Registry entry updated
2026-09-28 · 12d ago · official registry · v0.1.535
FAQ
›How do I install the Ironclaw MCP server in Claude Code?
Run: claude mcp add ironclaw -e IRONCLAW_CONTROLPLANE_URL='<ironclaw-controlplane-url>' -e IRONCLAW_API_TOKEN='<ironclaw-api-token>' -- docker run -i --rm -e IRONCLAW_CONTROLPLANE_URL -e IRONCLAW_API_TOKEN ghcr.io/ironsecco/ironclaw-mcp:v0.1.535. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Ironclaw require an API key?
Yes. It expects IRONCLAW_CONTROLPLANE_URL, IRONCLAW_API_TOKEN, of which 1 is a secret.
›Can I use Ironclaw as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Ironclaw in the official MCP registry?
Yes, as io.github.IronSecCo/ironclaw.
Alternatives to Ironclaw
Other code execution & sandboxes MCP servers.