Skip to main content
OPENCLAW · LIVEThe agent surface

Run OpenClaw.Contain the blast radius.

A hijacked agent reaches nothing it shouldn't. OpenClaw runs in a disposable cloud sandbox. It never sees your credentials, cookies, or machine. One click to start. One click to destroy.

no cli. no docker. no api keys.

openclaw.sessionDESTROYED
openclaw.spawn --burn-on-close
agent: claude / scope: legba.app
task: download the statement
status: complete
session destroyed. no trace.
agent templates3 total
  • OpenClawComputer-use agent
    LIVE
  • SWE-AgentSoftware engineering agent
    SOON
  • OpenHandsSoftware development agent
    SOON

[ HOW IT WORKS ]

Three clicks. That's it.

Spawn the sandbox, run the agent, burn it on close. The whole lifecycle takes about as long as opening your IDE.

Pick an agent.

Choose a pre-loaded template. OpenClaw is live now. SWE-Agent and OpenHands are coming next. No install. No config.

Run it contained.

The agent gets full access inside an isolated sandbox. It never sees your credentials, cookies, or machine. A prompt injection has nowhere to go.

Burn it on close.

When you're done, destroy it. One click and the whole environment is gone. No lingering data. No cleanup. No trail.

[ WHY CONTAINMENT ]

Contain the agent.
Not your terminal.

Infra tools sell you scale. Legba contains the agent. One column is the setup you already run. One is the isolated browser for AI agents that Legba ships.

SELF-HOSTEDon your machine
  • Install Docker, Node, and Python dependencies
  • Configure API keys and environment variables
  • Debug port conflicts and permission errors
  • The agent runs against your real filesystem
  • A prompt injection reaches your live credentials
  • Tear down containers and hope nothing persisted
ON LEGBAcontained
  • Click "Launch" and the session is running
  • Pre-configured. Ready to run immediately
  • Every session is isolated in the cloud
  • The agent has zero access to your real machine
  • A hijacked agent reaches nothing it shouldn't
  • Click "Destroy" and it's gone on close

[ OPENCLAW SANDBOX ]

Full system access. Total isolation. Gone on close.

OpenClaw and Legba logos on a dark circuit board background representing AI agent security containment

Access anything.
Expose nothing.

Run Claude computer use safely. The agent gets full system access inside the AI agent sandbox. It can write code, run scripts, and install packages. It cannot touch your machine, your credentials, or your cookies. One click destroys the session. No artifacts. No residue.

  • Full system access inside the sandbox
  • Zero access to your real machine, credentials, or cookies
  • Prompt injection stays contained in the session
  • Destroyed on close. No agent with persistent cookies.

[ PRICING ]

Start free.
Burn every session.

No hidden fees. Every plan runs in full isolation, with one-click teardown and no persistence. See the full OpenClaw pricing breakdown.

Tier 01

Free

Run an agent in a disposable sandbox. See what it can do.

$0
  • 1 session at a time
  • 30-minute session limit
  • OpenClaw template
  • Full isolation
Tier 02MOST POPULAR

Pro

For builders who run agents every day.

$50/mo
  • 3 concurrent sessions
  • 4-hour session limit
  • All agent templates
  • Workspace snapshots
  • Priority environment spin-up

Related surfaces

OpenClaw is one Legba surface, not a disconnected microsite.

OpenClaw is the contained-agent surface inside the larger Legba product family. Use the related pages below to evaluate browser isolation, MSP rollout, and the research behind agent containment.

Containment01

Run Claude computer use safely

A hijacked computer-use agent reaches no credentials, cookies, or files. The disposable sandbox is the boundary.

Explore
Sandbox02

What an AI agent sandbox is, and why isolation matters

Full access inside the sandbox, zero access to your real machine, destroyed on close. The containment layer for autonomous agents.

Explore
Setup03

Give OpenClaw a disposable browser

Add the MCP server, scope a session, run the agent, burn it on close. A short walkthrough with copy-paste config.

Explore
Hosted04

Run OpenClaw in a disposable cloud sandbox

The agent reaches the page, not your credentials, cookies, or machine. Spawn it, run it, burn it on close.

Explore
Comparison05

Legba vs Browser Use for OpenClaw

Compare Browser Use capability with Legba containment. Isolate credentials and bound the blast radius.

Explore
Playbook06

Start with the OpenClaw evaluation guide

Read the practical decision framework for when to run OpenClaw locally, when to contain it, and what to inspect first.

Explore
Core product07

See the Chrome extension and browser-isolation core

OpenClaw runs on the same containment model as the main product. Keep risky web execution off the endpoint by default.

Explore
MSP08

Roll isolated sessions out through MSP workflows

If you manage multiple clients, the MSP page shows how the same isolation layer extends beyond one-off OpenClaw runs.

Explore
Adversary09

Map your external attack surface

Adversary uses the same engine to validate real exposures and return a client-ready report in minutes, not weeks.

Explore
FAQ

Common questions.

What is OpenClaw isolated from?
OpenClaw runs in a disposable cloud sandbox. It is isolated from your machine and credentials. Your cookies stay outside the session. Full system access stays inside the sandbox.
Can the agent reach my files or cookies?
No, it cannot reach your local files. It also cannot touch credentials or cookies. Full system access stays inside the sandbox.
What happens when the run ends?
One click destroys the whole environment. No lingering data remains afterward. There are no artifacts or persistent cookies.
Does it support computer-use agents?
Yes, OpenClaw is live as a computer-use agent. It can write code, run scripts, and install packages inside the sandbox.
Is there a free tier?
The Free plan costs $0. It includes one session at a time. Each session has a 30-minute limit. The OpenClaw template and full isolation are included.

Access anything.
Expose nothing.

Legba is a disposable real browser: it spawns a clean session, does the work, and destroys itself on close.

chromium / real fingerprint · residential ip · burn on close

Real browser. Real IP. Real page. Spawn a session. Do the work. Destroy it. Off your device. Off your stack. Gone on close.