DataClaw
ekaya-inc/dataclaw
Localhost MCP server that gives agents such as Hermes and OpenClaw controlled access to a database
DataClaw is a localhost-only server that connects local AI agents to a database, with explicit MCP permissions for each agent on which tools they can run and which queries they can execute. All MCP access is logged in a dashboard.
What DataClaw does
DataClaw is written in Go and runs as a single-user local app. It stores its own metadata in bundled SQLite and serves its browser UI straight from the binary. You create named agents, and each gets its own API key, raw query and raw execute toggles, and an approved-query scope of none, all or selected queries. All MCP access is logged in the dashboard.
By default DataClaw opens two loopback listeners: the admin web UI and API on 127.0.0.1:18790 and MCP on 127.0.0.1:18791/mcp, probing upward if a port is busy. Stored datasource credentials are encrypted with a key file under ~/.dataclaw. Admin sign-in uses the username admin, and the default password is also admin unless DATACLAW_ADMIN_PASSWORD is set, which the README says to do before exposing the admin listener beyond loopback. Installation is a shell script on macOS and Linux, or a zip from GitHub Releases on Windows.
Key features
- Named agents, each with its own API key
- Per-agent raw query and raw execute toggles
- Approved-query scope set to none, all or selected queries
- Dashboard log of all MCP access
- Encrypted storage of datasource credentials
- Admin UI and MCP endpoint on loopback listeners
When to use it
- Letting a Hermes agent run only pre-approved database queries
- Giving several local agents different database permissions
- Reviewing which tools and queries an agent actually ran
Who it is for: Developers who want local AI agents to query a database without handing them unrestricted access.
How it fits with Hermes Agent
The repository description names Hermes and OpenClaw as example agents, which connect over MCP. The README setup text is written around OpenClaw on the same system.
How to install DataClaw
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
curl -fsSL https://dataclaw.sh/install.sh | INSTALL_DIR=$HOME/.local/bin/ sh
dataclawNote: DataClaw accepts the default admin password admin unless DATACLAW_ADMIN_PASSWORD is set, so set a password before exposing the admin listener beyond loopback.
FAQ
What is DataClaw?
DataClaw is a localhost-only server that gives local AI agents controlled MCP access to a database. Each agent gets its own API key and an explicit scope of allowed queries.
Does DataClaw work with Hermes Agent?
Yes. The repository description names Hermes as an example agent, and agents connect to DataClaw over its MCP endpoint at 127.0.0.1:18791/mcp by default.
How do I install DataClaw?
On macOS and Linux, run the install script with curl, optionally setting INSTALL_DIR, then start it with dataclaw. On Windows, download the zip from GitHub Releases and run dataclaw.exe.
Similar mcp & tools for Hermes Agent
All mcp & toolsMCP server with 104 tools for X/Twitter automation, usable from Hermes Agent and other MCP clients
JorG18 AgentCrawlSelf-hosted web scraper that turns pages into Markdown for AI agents via CLI, API or MCP
dominikamann Agent Mail GatewaySelf-hosted email gateway that gives each AI agent its own IMAP/SMTP mailbox with allow lists
JerryLiu369 Agent Web SearchProvider-neutral web search for AI agents as an MCP server, CLI and Python library
rfdiosuao Hermes-Agent-PhoneAndroid app that lets an AI agent control a phone through an HTTP API and accessibility service
Vasallo94 Obsidian MCP ServerMCP server that lets Hermes, Codex and Claude Code read, search and safely edit Obsidian notes
Related guides: What is Hermes Agent? · How to run Hermes Agent securely