Sign inSign up

sbx/picoclaw-mixin:latest

Multi-platform
Manifest digest

sha256:efc966fedcb21a562de4fd188c771268cf0143381428285cadc8113174ae991d

Last pushed

about 21 hours by sbx

Type

Sandbox Kit

Manifest digest

sha256:efc966fedcb21a562de4fd188c771268cf0143381428285cadc8113174ae991d

yaml
schemaVersion: "3"
displayName: PicoClaw (mixin)
description: PicoClaw as a mixin — the pinned, SHA256-verified static binary in an overlay, with the Anthropic credential (API key or claude.ai OAuth), the published gateway and webhook ports, and the hooks that resolve the credential and bring the gateway up. Layer it onto a shell base and run `picoclaw`.
sourceUrl: https://github.com/sipeed/picoclaw
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com
                - claude.ai
                - console.anthropic.com
                - platform.claude.com
                - '*.telegram.org'
                - '*.discord.com'
                - gateway.discord.gg
                - '*.whatsapp.com'
                - '*.whatsapp.net'
                - '*.slack.com'
    - type: com.docker.sandbox/port@1
      config:
        container: 18790
        name: gateway
    - type: com.docker.sandbox/port@1
      config:
        container: 18791
        name: webhook
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
                - domain: claude.ai
                  format: '%s'
                  header: x-api-key
                - domain: console.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        oauth:
            credentialFile:
                path: ~/.picoclaw/auth.json
                structure:
                    credentials:
                        anthropic:
                            access_token: '{{.AccessToken}}'
                            auth_method: oauth
                            provider: anthropic
                            refresh_token: '{{.RefreshToken}}'
            resourceHosts:
                - api.anthropic.com
            sentinels:
                accessToken: sk-ant-oat01-proxy-managed
                refreshToken: sk-ant-ort01-proxy-managed
            tokenEndpoint:
                host: platform.claude.com
                path: /v1/oauth/token
        phase: runtime
        service: anthropic
      description: Anthropic API access (API key or claude.ai OAuth)
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - command:
                - sh
                - /home/agent/.local/bin/picoclaw-anthropic-auth.sh
              description: Resolve the host's Anthropic credential into config.json at sandbox start
              env:
                - PICOCLAW_HOME
                - ANTHROPIC_API_KEY
              user: "1000"
            - background: true
              command: |
                curl -fsS -m 2 http://127.0.0.1:18790/health >/dev/null 2>&1 && exit 0
                mkdir -p /home/agent/.picoclaw
                export HOME=/home/agent
                exec /usr/local/bin/picoclaw gateway > /home/agent/.picoclaw/gateway.log 2>&1
              description: Start the picoclaw gateway in the background (health at :18790/health)
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/picoclaw-mixin/picoclaw-mixin-context.md
args:
    version:
        default: 0.2.9
        description: PicoClaw release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: PICOCLAW_VERSION