Guide - AI & Automation

How to Self-Host NanoClaw 24/7 on a Dedicated Mac mini

NanoClaw is an open-source (MIT, 30k+ stars) AI assistant that answers you from WhatsApp, Telegram, Discord, Slack, iMessage and more, and runs every agent session in its own Docker container so a prompt-injected agent has nothing to steal and nowhere to go. A dedicated Mac mini gives it an always-on Apple Silicon home with full root, SSH and VNC, from $85/month.

30 min read Updated September 28, 2026

1. Why Run NanoClaw on a Dedicated Mac mini?

NanoClaw only answers while its host is on and connected, the quickstart says so plainly, which rules out a laptop that sleeps. It needs a Mac or Linux machine with at least 4 GB of RAM plus Docker (Docker Desktop on macOS), and its GitHub description positions it as a lightweight alternative to OpenClaw that runs in containers for security. A shared Linux VPS can be cheaper than a Mac mini, so be clear about what you are buying: a dedicated 1:1 physical Apple Silicon Mac that nobody else shares, the only platform where NanoClaw's local iMessage backend works, a real desktop session for Docker Desktop, and a box you can also use for Xcode builds or local models.

Feature Cloud VPS (shared instance) Mac mini (MyRemoteMac)
Monthly cost Varies by size; dedicated instances cost more $85/mo (M4) or $149/mo (M6), flat, 1 Gbps included
Hardware Shared, virtualised CPU and RAM (NanoClaw lists Google Compute Engine VMs as unsupported) Dedicated 1:1 physical Apple Silicon Mac
Container runtime Docker Engine on Linux Docker Desktop for Mac (same per-session Linux containers)
iMessage (local backend) Not possible (macOS only) Supported on a Mac signed in to iMessage
Access SSH Full root, SSH, VNC, WireGuard VPN
Uptime Depends on provider 99.9% SLA

What NanoClaw is: one Node.js host process routes messages from your chat apps to per-session Docker containers, where agents run on Claude Code via Anthropic's Claude Agent SDK. There are no configuration files beyond .env and a SQLite database: you customise it by asking Claude Code to change the code in your own checkout. Version at time of writing: v2.4.0 (September 23, 2026), created by Gavriel Cohen and maintained by NanoCo.

2. Prerequisites

Before you begin, make sure you have the following. Everything below comes from the official NanoClaw README, quickstart and installation pages, plus Docker's and Anthropic's terms for the platform facts:

  • A dedicated Mac mini from MyRemoteMac, M4 from $85/mo (16 GB / 256 GB) or Mac mini M6 from $149/mo. NanoClaw asks for at least 4 GB of RAM (the installer warns below 3,700 MB); every plan clears that by a wide margin.
  • SSH and VNC access (both included with your subscription). VNC is needed once: Docker Desktop is a GUI application and must be launched from the desktop the first time.
  • Docker Desktop for Mac, running whenever NanoClaw starts. Docker's terms: free for personal use, education, non-commercial open source and companies with fewer than 250 employees and less than US$10 million in annual revenue; larger companies and government entities need a paid subscription.
  • Homebrew, git, Node.js 22+ and pnpm 10. git must be present; the installer offers to install Homebrew and installs Node and pnpm itself if they are missing (Node 20 is unsupported since 2.3.0).
  • The Claude Code CLI on the Mac. It is not optional: every /add-<channel> skill, /customize, /debug, /update-nanoclaw and the installer's error recovery run inside Claude Code from the project root.
  • An Anthropic API key (sk-ant-api…) from console.anthropic.com, billed per token. The wizard also offers to sign in with a Claude subscription, but Anthropic's legal terms state that OAuth is intended for ordinary use of Claude Code and native Anthropic apps, and that products built on the Agent SDK should use API key authentication, so for a business or always-on deployment, use a key.
  • A messaging account on Telegram, WhatsApp or Discord to connect your agent (the built-in terminal channel needs nothing).

3. Step 1: Connect via SSH, Install Docker Desktop and Claude Code

First, SSH into your Mac mini with the credentials from your MyRemoteMac dashboard and check the two tools the installer expects to find. The NanoClaw installer will install Homebrew, Node and Docker for you, but pre-installing Docker Desktop lets you start it and verify the daemon before the wizard needs it.

Connect via SSH

# Connect to your Mac mini
ssh admin@your-server-ip

# Verify you're on Apple Silicon
uname -m
# Expected output: arm64

# git is required (not auto-installed); Homebrew is offered by the installer if missing
git --version
brew --version

Install and Start Docker Desktop for Mac

This is the exact command NanoClaw's own setup/install-docker.sh runs on macOS when docker is missing. Docker Desktop is a desktop application: launch it once from the Mac's desktop over VNC, then confirm from SSH that the daemon answers. If it is not running when NanoClaw starts, the host exits with "FATAL: Container runtime failed to start".

# Install Docker Desktop for Mac (the same Homebrew cask NanoClaw's installer uses)
brew install --cask docker

# Start Docker Desktop, a GUI app: do the first launch from the desktop (VNC)
open -a Docker

# The daemon must answer before NanoClaw can start
docker info

Install Claude Code on the Host

NanoClaw's setup/install-claude.sh runs the same command when claude is missing. You will use Claude Code for every channel, provider and update from now on:

# Official Claude Code installer (the command NanoClaw's setup/install-claude.sh runs)
curl -fsSL https://claude.ai/install.sh | /bin/bash
claude --version

4. Step 2: Install NanoClaw and Configure Your Claude API Key

NanoClaw is not an npm package you install globally: you clone the repository and run a one-shot installer that turns the checkout into your own install. Keep the folder where it is afterwards, the launchd label, the image name and the install slug are derived from its path. Plan 30 to 60 minutes; the wizard is interactive.

Clone and Run the Installer

# Clone the canonical repo (nanocoai: the old qwibitai URL redirects here)
cd ~
git clone https://github.com/nanocoai/nanoclaw.git
cd nanoclaw

# One-shot installer: Node 22 + pnpm + Docker if missing, OneCLI gateway,
# credential registration, sandbox image, launchd service, optional channel
bash nanoclaw.sh

The wizard walks you through the documented choices: Standard setup → Fresh agent → sandbox image: fetch the prebuilt hardened image built by Echo (needs a free NanoClaw sign-in, about 800 MB from a single US region) or build it locally (3–10 minutes, no account, contacts nothing, may be faster from Europe or Asia) → AI runtime: Claude → paste your Anthropic API key (recommended; "Sign in with my Claude subscription" is also offered, see the note in Prerequisites) → Skip for now for the messaging channel. The installer stores your key in the OneCLI Agent Vault, a credential gateway that is mandatory since 2.4.0: agent containers never hold raw API keys.

Scripted Alternative and First Message

If you prefer a non-interactive run, the installation page documents setup-time variables that pre-answer the prompts. Either way, test with the built-in terminal channel from the project folder, the first reply may take a little time while the container starts:

# Scripted setup (documented alternative to the wizard)
pnpm install
pnpm run setup:auto
# Pre-answer prompts with NANOCLAW_AGENT_PROVIDER, NANOCLAW_CHANNELS,
# NANOCLAW_HARDENED_IMAGE, NANOCLAW_SKIP; NANOCLAW_NO_DIAGNOSTICS=1 disables setup diagnostics

# First message through the built-in CLI channel (no credentials needed)
pnpm run chat "hello, who are you?"

# Re-run individual steps later: rebuild the image, reinstall the service, health check
pnpm run setup -- --step container
pnpm run setup -- --step service
pnpm run setup -- --step verify

Choose the Model and Set the Basics in .env

Install-wide settings live in .env at the project root (created with mode 0600 by setup); per-agent-group settings live in the database and are edited with the ncl admin CLI. Since 2.4.0, Claude groups with no model set use Opus 5.5 (claude-opus-5-5, $4 input / $20 output per million tokens); Claude Sonnet 5 costs $2 / $10, so pin it for a personal assistant if cost matters. Other providers are per agent group: /add-codex (OpenAI) and /add-opencode (OpenRouter, OpenAI, Google, DeepSeek). Local models: the README lists /add-ollama-provider, but the providers page on docs.nanoclaw.dev states it is not a supported drop-in switch on current main, treat it as an experiment, not a way to replace Claude.

# Install-wide model for every Claude group with no model set
# (aliases sonnet | opus | haiku, or a full id such as claude-sonnet-5)
echo 'NANOCLAW_DEFAULT_MODEL=sonnet' >> .env

# Timezone for scheduled tasks and timestamps (IANA name)
echo 'TZ=Europe/Paris' >> .env

# .env is read only by the host process: restart it after edits
launchctl kickstart -k gui/$(id -u)/com.nanoclaw-v2-<slug>

# Per-group overrides via the ncl admin CLI (symlinked at ~/.local/bin/ncl by setup)
ncl groups config update --id <group-id> --model opus
ncl groups config update --id <group-id> --timezone Europe/Lisbon
# Switch a group to another provider (takes effect on the next container spawn)
ncl groups config update --id <group-id> --provider opencode

5. Step 3: Connect Messaging Channels

Channels are not bundled: each one is installed on demand as a Claude Code skill run from the project root, which adds the adapter to your checkout. Telegram is the fastest to get working, create a bot with @BotFather, paste the token when the skill asks (it is stored as TELEGRAM_BOT_TOKEN in .env), then send the one-time 6-digit pairing code to the bot as a message containing nothing but the digits. Polling mode means no public URL, webhook or open port:

# Step 1: Open Telegram and search for @BotFather
# Step 2: Send /newbot and follow the prompts
# Step 3: Copy the token

# Every channel is a Claude Code skill run from the project root
cd ~/nanoclaw && claude
/add-telegram
# Paste the token when asked (stored as TELEGRAM_BOT_TOKEN in .env).
# The wizard prints a one-time 6-digit pairing code: send exactly those digits to the bot.

# Groups: BotFather -> /mybots -> Bot Settings -> Group Privacy -> Turn off

Connect WhatsApp

The native adapter speaks the WhatsApp Web protocol (Baileys, not Meta's official API): scan the QR code, which rotates about every 60 seconds, or enter the 8-character pairing code under WhatsApp → Linked Devices. In shared-number mode the assistant replies in your own "You" self-chat; for a dedicated number use a separate SIM and set ASSISTANT_HAS_OWN_NUMBER=true. If compliance matters, use /add-whatsapp-cloud (Meta Cloud API) instead:

claude
/add-whatsapp
# Scan the QR (rotates ~60 s) or enter the 8-character code in WhatsApp -> Linked Devices
# Auth state persists in store/auth/: keep that folder private

# Dedicated number (separate SIM) instead of your own chat:
# ASSISTANT_HAS_OWN_NUMBER=true in .env

# Meta's official Cloud API instead of the Web-protocol adapter:
# /add-whatsapp-cloud

Connect Discord, iMessage and the Rest

Discord uses a bot token and a Gateway listener (no public URL). The catalog also covers Slack, Mattermost (new in 2.4.0), Signal, iMessage, Microsoft Teams, Google Chat, Matrix, Webex, WeChat, GitHub, Linear, Delta Chat, Emacs, email via Resend and a real phone number via Dial. The local iMessage backend is the macOS-only feature: the Mac mini must be signed in to iMessage with an Apple ID and the exact node binary needs Full Disk Access (the hosted Photon backend needs neither). Re-running an /add-<channel> skill later refreshes the adapter; /manage-channels wires each conversation to an agent group:

claude
/add-discord
# others: /add-slack /add-imessage /add-signal /add-teams /add-mattermost /add-matrix ...

# Wire conversations to agent groups
/manage-channels

# Silent agent? Check why messages were dropped (no_agent_wired, no_agent_engaged, ...)
ncl dropped-messages list
ncl sessions list

6. Step 4: Run 24/7 with launchd, Then Update Safely

For 24/7 operation NanoClaw must start on boot and restart on failure. The installer already handled this: its service step writes a per-user launchd LaunchAgent named com.nanoclaw-v2-<slug> (slug = first 8 hex characters of the SHA-1 of the project path; older tutorials still show the pre-2.3.0 label com.nanoclaw) with RunAtLoad and KeepAlive, logging to logs/nanoclaw.log and logs/nanoclaw.error.log. The plist sets only PATH and HOME and does not source .env, so restart the host after every .env edit.

Verify and Manage the Service

# Is the LaunchAgent loaded? Find your label (com.nanoclaw-v2-<slug>)
launchctl list | grep nanoclaw
ls ~/Library/LaunchAgents/ | grep nanoclaw

# Health: host + connected adapters (ncl status is new in 2.4.0)
ncl status
pnpm run setup -- --step verify
docker ps --filter label=nanoclaw-install

# Live logs
tail -f logs/nanoclaw.log logs/nanoclaw.error.log

# Restart (also after every .env edit) / stop / start / reinstall the service
launchctl kickstart -k gui/$(id -u)/com.nanoclaw-v2-<slug>
launchctl unload ~/Library/LaunchAgents/com.nanoclaw-v2-<slug>.plist
launchctl load ~/Library/LaunchAgents/com.nanoclaw-v2-<slug>.plist
pnpm run setup -- --step service   # regenerates the plist (wipes manual edits)

Survive a Reboot on a Headless Mac mini

This part is our operations recommendation, assembled from Apple's and Docker's documentation, NanoClaw's docs do not cover headless Macs. The LaunchAgent lives in your user session and Docker Desktop is a GUI app, so after a reboot nothing runs until someone logs in. Enable Automatic login for the same user account that ran bash nanoclaw.sh, the LaunchAgent and Docker Desktop's start-at-sign-in setting are both per-user, so auto-logging-in another account would leave the service unloaded and Docker stopped (Apple: Automatic login is not available while FileVault is on). Remember that anyone who restarts the Mac lands in that session, which is acceptable only on a dedicated Mac mini reachable solely over SSH, VNC and WireGuard; if you prefer a non-admin account for it, install NanoClaw under that account, knowing that installing Homebrew and running sudo pmset still need an administrator (Docker Desktop itself runs as an unprivileged user and only asks for privileged access for specific features). Then turn on Docker Desktop's "Start Docker Desktop when you sign in to your computer" setting, and disable sleep:

# 1. System Settings > Users & Groups > Automatic login = the user that ran bash nanoclaw.sh
#    (over VNC; not available with FileVault on; LaunchAgent + Docker Desktop are per-user)
# 2. Docker Desktop > Settings > General > "Start Docker Desktop when you sign in to your computer"

# 3. Keep the Mac awake (same as in our OpenClaw guide)
sudo pmset -a sleep 0 disksleep 0 standby 0 powernap 0

# 4. Reboot-test, then log back in over SSH and check
sudo reboot
docker info
launchctl list | grep nanoclaw

Update NanoClaw (Never git pull)

The upgrading page is explicit: "Do not update with a raw git pull." NanoClaw records each sanctioned upgrade in data/upgrade-state.json and a startup tripwire refuses to start on a mismatch. The only supported path is /update-nanoclaw in Claude Code: it creates a backup branch and tag, stages upstream in a separate worktree, validates (install, build, tests), stops the service and containers, snapshots .env, data, groups and store, cuts over, restarts and health-checks. It is blocked on a dirty working tree or when NanoClaw is not running under launchd. Before moving to 2.4.0, pin your model if you do not want unset Claude groups to switch to Opus 5.5:

# Optional: pin the model BEFORE upgrading (2.4.0 default for unset Claude groups is Opus 5.5)
echo 'NANOCLAW_DEFAULT_MODEL=sonnet' >> .env

# The only supported update path: inside Claude Code, from the project root
cd ~/nanoclaw && claude
/update-nanoclaw
# Refresh installed channel/provider skills only:
/update-skills

# After resolving merge conflicts, or to roll back after cutover:
pnpm exec tsx scripts/update-nanoclaw.ts resume --id "$id"
pnpm exec tsx scripts/update-nanoclaw.ts rollback --id "$id"

# Remove this checkout only (service, containers, image, data; .env backed up to .env.bak)
bash nanoclaw.sh --uninstall --dry-run
bash nanoclaw.sh --uninstall

7. Security Hardening (Least Privilege)

NanoClaw's threat model is "assume the agent gets prompt-injected, then make sure a compromised agent has nothing to steal and nowhere to go." Out of the box each session runs in its own container as the unprivileged node user with --cap-drop=ALL, --security-opt no-new-privileges, --init, a pids limit and setuid bits stripped; there is no host home, no .ssh, no Docker socket, and the OneCLI gateway rewrites auth headers in flight so containers never see your API key. Approval cards (packages, MCP servers, sub-agents, new chat registration) need an admin answer and auto-deny when unanswered, keep them. The safest documented configuration adds the following, and never disables approvals or the gateway:

  • Unknown senders: set --unknown-sender-policy strict (dropped silently) or request_approval on every messaging group strangers can reach.
  • Mounts: leave the allowlist (~/.config/nanoclaw/mount-allowlist.json) absent or minimal, without it all additional mounts are blocked, and .ssh.gnupg.aws.kube.docker, credentials.env and .netrc are blocked patterns anyway. Mounts are read-only unless explicitly allowed.
  • Isolation: "when in doubt, start more isolated." A family chat and a client channel should not be one agent; an agent with a mounted repo and deploy credentials must not share an agent group with one that talks to strangers. Separate sessions are not a confidentiality boundary inside a group.
  • Limits and egress: set CONTAINER_CPU_LIMIT and CONTAINER_MEMORY_LIMIT, and enable NANOCLAW_EGRESS_LOCKDOWN=true (all traffic through the gateway, containers on an internal network) once your tools work through the proxy, it is off by default because it breaks non-proxy-aware tools.
  • Secrets on disk: .env is created with mode 0600 and holds channel tokens only; agent API keys live in the vault. Keep store/auth/ (WhatsApp session) private too, our recommendation, not a NanoClaw claim. Setup sends diagnostics unless NANOCLAW_NO_DIAGNOSTICS=1.
# Unknown senders: drop silently (or route to an approval card) on every reachable group
ncl messaging-groups list
ncl messaging-groups update --id <mg-id> --unknown-sender-policy strict
# or: --unknown-sender-policy request_approval

# Opt-in per-container caps (passed to docker create --cpus / --memory)
echo 'CONTAINER_CPU_LIMIT=2' >> .env
echo 'CONTAINER_MEMORY_LIMIT=8g' >> .env

# Once every tool works through the OneCLI proxy: no direct internet route for containers
echo 'NANOCLAW_EGRESS_LOCKDOWN=true' >> .env
launchctl kickstart -k gui/$(id -u)/com.nanoclaw-v2-<slug>

# Mounts are deny-by-default and read-only unless the allowlist root sets allowReadWrite
ncl groups config add-mount --id <group-id> --host /path/on/mac --container /path/in/container

# Secrets on disk: .env must stay 0600 (setup creates it that way)
ls -l .env

Residual risks the sandbox does not cover: a compromised agent can still message any destination it is wired to, read or destroy its own workspace and memory, spend the credentials it was granted and poison the group's memory, so scope every agent group narrowly.

8. Troubleshooting Common Issues

"FATAL: Container runtime failed to start"

Docker Desktop was not running when the host started, the classic after a reboot without a logged-in session. Check the daemon, start Docker Desktop, then restart NanoClaw:

# Is the Docker daemon up?
docker info

# Not running? Start Docker Desktop (first launch must be from the desktop over VNC)
open -a Docker

# Then restart NanoClaw and watch the logs
launchctl kickstart -k gui/$(id -u)/com.nanoclaw-v2-<slug>
tail -f logs/nanoclaw.error.log

"NanoClaw stopped: update did not go through the supported path"

Someone ran git pull (or otherwise changed the checkout) and data/upgrade-state.json no longer matches. Go back through the supported update, or resume/roll back a staged one:

# Never `git pull`. Run the supported update from the project root:
cd ~/nanoclaw && claude
/update-nanoclaw

# A staged update stuck in conflict, or a bad cutover?
pnpm exec tsx scripts/update-nanoclaw.ts resume --id "$id"
pnpm exec tsx scripts/update-nanoclaw.ts rollback --id "$id"

# The update is blocked on a dirty working tree, detached HEAD or a host not under launchd
git status

The agent never answers in a chat

Usually a wiring or trigger issue rather than a crash: the agent only responds when its trigger (@Andy by default, from ASSISTANT_NAME; the WhatsApp wizard's default is Nano) matches, and the chat must be wired to an agent group. List dropped messages and sessions:

# Why were messages dropped? (no_agent_wired, no_agent_engaged, ...)
ncl dropped-messages list
ncl sessions list

# Wire the chat to an agent group
claude
/manage-channels

# Telegram: pending pairing codes live here; the message must contain only the 6 digits
cat data/telegram-pairings.json

Host refuses to start after a hand-merged update (no credential gateway)

Since 2.4.0 the host refuses to start without a registered credential gateway. Forks merged by hand must register OneCLI (or Iron Proxy) and check NANOCLAW_GATEWAY_PROVIDER in .env; OpenCode installs must also re-run /add-opencode, rebuild the image and restart their groups (commands from the 2.4 release note):

# Register the gateway (OneCLI is the default; Iron Proxy is the alternative)
claude
/add-onecli
# or: /add-iron-proxy

# Check the provider recorded in .env (onecli | iron-proxy)
grep NANOCLAW_GATEWAY_PROVIDER .env

# OpenCode installs: re-run /add-opencode, then rebuild the image, restart the host and the groups
./container/build.sh build
launchctl kickstart -k gui/$(id -u)/com.nanoclaw-v2-<slug>
ncl groups restart --id <group-id>

Nothing runs after the Mac mini reboots

The LaunchAgent and Docker Desktop both live in the user session. Check that the service is registered, that Automatic login is on for the user that ran the installer and that Docker Desktop starts at sign-in, then reboot-test:

# Is the LaunchAgent registered?
launchctl list | grep nanoclaw

# Not listed? Reinstall it (regenerates the plist)
pnpm run setup -- --step service

# Docker not up after login? Enable "Start Docker Desktop when you sign in" (Settings > General)
docker info

# Then reboot-test again
sudo reboot

9. Cost Analysis vs. Cloud VPS

NanoClaw itself is free (MIT). You pay for the host and for model usage on your Anthropic API key, identical on any host, because NanoClaw does not run local models in a supported way. The Mac mini is a dedicated physical machine, so the fair comparison is a dedicated or AI-tier cloud instance, not the cheapest shared VPS:

Use Case AI Calls/Month Cloud VPS Cost MyRemoteMac Cost Monthly Savings
Personal assistant, one channel ~500 calls $120/mo (dedicated AI-tier instance) $85/mo (Mac mini M4) $35/mo
Small team, several channels + scheduled tasks ~5,000 calls $200/mo $85/mo (Mac mini M4) $115/mo
Several agent groups with concurrent containers 10,000+ calls $350+/mo $149/mo (Mac mini M6) $201+/mo

Assumptions: VPS prices are the same ranges used across our guides for dedicated AI-tier instances and are not quotes from a specific provider; a shared 4 GB Linux VPS would be cheaper than any Mac mini plan. MyRemoteMac prices are the current monthly rates in USD, excluding tax, 1 Gbps included. Model usage is extra on both sides: Opus 5.5 is $4 / $20 per million input / output tokens and Sonnet 5 is $2 / $10 (platform.claude.com, September 2026). NanoClaw publishes no RAM or CPU footprint figures for the host, the Docker Desktop VM or the per-session containers, so plan advice stays qualitative.

Which plan: the 16 GB Mac mini M4 at $85/month is a comfortable host for a personal assistant or a small team bot, NanoClaw's own minimum is 4 GB. Pick the Mac mini M6 when you run several agent groups with concurrent containers alongside the Docker Desktop VM, or when the Mac also builds iOS apps. To keep the token bill predictable, set NANOCLAW_DEFAULT_MODEL=sonnet and reserve Opus for a group that needs it.

10. NanoClaw vs. OpenClaw

NanoClaw positions itself explicitly against OpenClaw: its README claims OpenClaw has nearly half a million lines of code, 53 config files and 70+ dependencies with security at the application level (allowlists, pairing codes) rather than OS-level isolation, figures from NanoClaw's README, not independently measured. From our OpenClaw guide, the practical differences on a Mac mini are these. OpenClaw is a global npm install (Node 26.1+ recommended), one Gateway process, a JSON5 config file, channels bundled, no Docker. NanoClaw is git clone + bash nanoclaw.sh, Node 22+ and pnpm 10, requires Docker Desktop, Homebrew and Claude Code on the host, has no config files (customisation is code in your own checkout), runs each session in a Linux container with cap-drop and no-new-privileges, blocks mounts by default and keeps API keys out of the sandbox through a credential gateway; channels are installed on demand as skills and updates go only through /update-nanoclaw. In short: NanoClaw is safer by construction but heavier to run (a Docker Desktop VM always on, a GUI login session, Docker's licence rule for large companies, a 30–60 minute interactive setup and a fork you maintain); OpenClaw is lighter to install and configure but relies on application-level permission checks. Both default to Claude; NanoClaw adds Codex and OpenCode per agent group. The Mac mini cost is identical for both.

Already on OpenClaw? NanoClaw ships /migrate-from-openclaw, a guided Claude Code conversation that maps OpenClaw agents to agent groups, chats to wired messaging groups, IDENTITY.md/SOUL.md to instructions.prepend.md plus memory/, skills to container/skills, channel tokens to .env, API keys to the OneCLI vault, cron jobs to ncl tasks, MCP servers to per-group config and allowlists to unknown_sender_policy and roles. WhatsApp must be re-authenticated; human delay and TTS have no v2 equivalent. Starting from scratch instead? Read our OpenClaw on a Mac mini guide and our Hermes Agent guide before choosing.

11. FAQ

Is NanoClaw free to use?

Yes. NanoClaw is MIT-licensed with 30k+ GitHub stars, created by Gavriel Cohen and maintained by NanoCo. You pay for the Mac mini (from $85/month for the M4, $149/month for the M6 at MyRemoteMac) and for Claude usage on your Anthropic API key. Docker Desktop is free for personal use and for companies under 250 employees and US$10 million in revenue; larger companies and government entities need a paid Docker subscription.

Do I really need Docker Desktop on a Mac mini?

Yes. On macOS NanoClaw requires Docker Desktop, which its installer adds with brew install --cask docker; Docker is the shipped runtime (NANOCLAW_RUNTIME_DRIVER=docker, behind a selectable driver seam since 2.3.0). Apple's own container tool is not a supported runtime today, the v2 /add-apple-container work is an open draft pull request. Every agent session runs in its own Linux container, which is the whole point of NanoClaw's security model.

Can I use my Claude subscription instead of an API key?

NanoClaw's wizard offers "Sign in with my Claude subscription" and accepts an OAuth token. Anthropic's legal terms, however, state that OAuth authentication is intended exclusively for subscribers' ordinary use of Claude Code and native Anthropic applications, that developers building on the Agent SDK should use API key authentication, and that Anthropic may enforce this without notice. For a business or always-on deployment, use an API key from the Console, and never store or share your Claude.ai credentials.

Which Mac mini plan should I pick for NanoClaw?

NanoClaw asks for at least 4 GB of RAM and publishes no footprint figures beyond that, so the advice is qualitative: the 16 GB Mac mini M4 at $85/month comfortably hosts a personal assistant or a small team bot with a couple of channels. Choose the Mac mini M6 from $149/month when several agent groups run containers at the same time alongside the Docker Desktop VM, or when the same Mac also runs Xcode builds or other workloads.

Does NanoClaw survive a reboot of the Mac mini?

Yes, provided a user session comes back: the installer registers a per-user LaunchAgent (com.nanoclaw-v2-<slug>, KeepAlive) and Docker Desktop is a GUI app, so on a headless Mac mini enable Automatic login for the same user account that ran bash nanoclaw.sh (both are per-user; not available with FileVault on), turn on Docker Desktop's start-at-sign-in setting and disable sleep with pmset. Verify with launchctl list | grep nanoclaw and docker info after a test reboot. This headless recipe is our recommendation; NanoClaw's docs only say to keep the computer on and connected.

Can I migrate my existing OpenClaw setup to NanoClaw?

Yes. Run /migrate-from-openclaw in Claude Code from the NanoClaw project root: it maps OpenClaw agents to agent groups, chats to messaging groups, IDENTITY.md and SOUL.md to instructions.prepend.md and memory/, skills to container/skills (same format), channel tokens to .env, API keys to the OneCLI vault, cron jobs to ncl tasks and allowlists to sender policies. WhatsApp is deliberately not migrated, you scan the QR again, and human delay and TTS have no v2 equivalent.

12. Sources and Further Reading

Every command, path, variable and requirement in this guide was checked on September 28, 2026 against the official NanoClaw repository (nanocoai/nanoclaw, v2.4.0 released September 23, 2026, the old qwibitai URL redirects there) and docs.nanoclaw.dev, plus Docker's, Anthropic's and Apple's documentation for the platform facts. Version pins such as the Claude Code build inside agents drift with every release, so consult these pages for current values:

Related Guides

Ready to Run NanoClaw 24/7?

Deploy a dedicated Mac mini as your sandboxed AI assistant host. Mac mini M4 from $85/month, Mac mini M6 from $149/month.

Looking for more detail?

Browse the full documentation for step-by-step setup, configuration references, and troubleshooting.

Open the documentation →