Now in open beta·Three live integrations·Help us secure our agentic future→
AGENTIC
NAME
SERVICE
Critical Infrastructure for Our Agentic Future
Test Drive

Service Directory

MCP services already onboarded to the ANS dev network.

Live Integrations

Production-ready MCP services with ANS attestation enforcement.

⚙️

Cloudflare MCP

Manage your Cloudflare infrastructure through ANS. Deploy Workers, modify KV namespaces, reconfigure DNS, and execute schema migrations with cryptographic proof of authorization.

Capabilities: Workers deployment, KV get/put/delete, D1 execute, DNS records, Account audit logs
Attestation Rules: Reads = session_only, Deploys = biometric, DNS changes = biometric
Use Case: ANS uses this to govern its own infrastructure. Every deploy, config change, and secret rotation flows through ANS attestation with receipts.
🐙

GitHub MCP

Manage repositories, issues, pull requests, and Actions from your agent. Create branches, review code, merge to main, and trigger CI/CD pipelines with attestation enforcement.

Capabilities: Repos list, Issue CRUD, PR create/review/merge, Actions trigger, Commit browse, Branch create/delete
Attestation Rules: Reading repos = session_only, Creating PRs = passkey, Merging to main = biometric
Use Case: Agents that contribute to repos, automate code reviews, and manage releases without risk of accidental main branch overwrites.
🦅

OpenClaw Agents

ANS permission layer for OpenClaw’s autonomous agents. Skills get attestation requirements. Heartbeat wake signals are scoped to delegation credentials. Agent-to-agent delegation is cryptographically provable.

Capabilities: Skill registration, Heartbeat wake control, Memory scoping, Agent-to-agent delegation, Skill audit logs
Attestation Rules: Skill execution = per-skill, Memory write = device_signature, Agent delegation = passkey
Use Case: OpenClaw agents operate autonomously within user-defined permission boundaries. Heartbeat doesn’t just wake — it validates the agent’s credential first.

OpenClaw Agent Capabilities

How ANS transforms OpenClaw from unrestricted autonomy to governed delegation.

Agent Capability Risk Today With ANS
Heartbeat (30-min wake cycle) No permission gate. Agent wakes, acts, sleeps. Daily reports of agents going out of control. Heartbeat validates delegation credential before wake. Agent receives only scoped permissions. Credential expires after max_auth_duration. Requires fresh handshake to continue.
Skills (autonomous execution) All skills have full system access. Malicious or buggy skills can damage user data, send emails, execute arbitrary code. Each skill is registered with an attestation requirement. Writing files = device_signature, sending emails = passkey, executing code = biometric. User pre-approves or escalates per skill.
Memory (~/.openclaw/workspace/) No access control. Agent reads, writes, and shares memory without restriction. Data exfiltration is silent. Memory access is tiered. Read = session_only. Write = device_signature. Share = biometric. Guardian can block specific memory categories or agents.
Agent-to-Agent (delegation) No trust model. Parent agents have no way to prove they authorized a sub-agent. Sub-agents can exceed parent scope. Delegation credentials are signed proofs of narrowed authority. Each link in the chain restricts scope. Guardian sees the full chain and can revoke any link.

Onboard Your Service

Register an MCP service with ANS in minutes. Set attestation rules, define capability mappings, and get a production-ready integration.

Start with Test Drive Service Onboarding Guide