Get Started
Run the free policy self-check in about 60 seconds.
Free policy self-check: packaged representative-action check plus best-effort OpenClaw/plugin inspection (no account). This does not install or enable the plugin, and it does not prove a real agent turn was intercepted.
Free local hard gate: install and enable the OpenClaw adapter so that policy is enforced in real sessions (~10–15 min after prerequisites).
Paid: govern supported shell, Git, patch, and deployment actions, check policy, issue a scoped Action Passport, and leave reviewable evidence.
A complete first adapter setup typically takes 10–15 minutes after prerequisites are installed.
Free policy self-check (copy-paste)
npx --yes --package=@dexgate/openclaw-trusted-mode@1.0.18 dexgate-assess
Expect overall status (PASS / FAIL / PARTIAL), packageSelfCheck, environment fields, and canned checks. governed may be true when governed path is configured or connected—not proof of a live Passport decision. When the claim service is reachable, the CLI uploads only the sanitized package self-check and prints a claim URL (open without an account). If upload fails, the CLI saves locally and does not invent a claim link.
Treat package self-check PASS as policy self-check passed, not “local hardening is active on a live agent turn.” Use environment fields for install/enable guidance; the claim does not store those fields.
Status source: compatibility matrix (2026-07-30). To install and enable the free hard gate in real OpenClaw sessions: OpenClaw free quickstart.
Choose your adapter. Run the optional policy self-check first, then install the free local hard gate (~10–15 min). Upgrade when you need shared monitoring of agent requests, Passport-governed allow paths, or security-ready decision records.
Current availability
Free adapters: available now on npm
Paid governed workflows: early-access pilot
Coverage last validated: July 30, 2026
Validated free packages:
@dexgate/openclaw-trusted-mode@1.0.18,
@dexgate/codex-trusted-mode@0.1.16
See the compatibility matrix for coverage, limitations, and current versions.
Feedback: Contact · Founding Customer Pilot · Subscribe.
Platforms: free adapters run on Windows, macOS, and Linux. Paid Dexgate runtime requires one Linux Docker host (agent host can stay on Windows).
How do you want to set up?
Same outcomes—pick the path that fits your workflow. Free adapters need no account; paid pilot needs entitled runtime access.
Choose your adapter
Free vs paid in practice
| Capability | Free local hardening | Paid dexgate governance |
|---|---|---|
| What it is | Local adapter-specific hard gates with conservative read-only defaults; see Compatibility for the exact allowed tool surface. | The Dexgate policy runtime decides before protected execution; scoped Passport evidence + audit. |
| Monitor & record agent requests | No governed action history—only the local free wall on that machine. | Customer runtime dashboard + decision records in the console; see what agents actually request before you expand policy. |
| Evidence | Self-check JSON (package + optional env fields) or local free-mode blocks once the plugin is installed; sample Passport preview only. | Decision records, Passport fields, and console history in the customer workspace. |
| Still blocked free | git push, deploy-class, unrestricted shell — with upgrade CTA. |
Policy may allow with proof, deny, or constrain; exportable for review. |
| When to upgrade | Prove the adapter loads and the free wall works. | Need to see agent requests org-wide, security/audit evidence, multi-env policy, or allow-with-proof. |
| Install surface | Windows / macOS / Linux agent OK. | One Linux Docker host for runtime + agent config. |
Compare paid plans Minimum Production setup Enterprise rollout Setup prompts for your agent