From guided setup to a verifiable run.

Set up Hermes, OpenClaw, or both. Keep keys and configuration local, decide what the agent may do, review meaningful requests, restore changes, and verify the resulting activity.

Get running

Start without configuration work.

Guided setup takes you from nothing installed to a running agent with governed tools in minutes. It handles the terminal commands and hand-edited configuration that normally sit between download and first use.

  1. Choose
  2. Connect
  3. Model
  4. Launch
LaunchZero Choose phase, step 2 of 8, with OpenClaw, Hermes, and both agents selected
Choose OpenClaw, Hermes, or both; when both are selected, the wizard also records which agent is the default.

Choose your agent.

Run Hermes, OpenClaw, or both side by side. One agent is the default for active chat surfaces, and switching the default takes effect immediately.

Add the integrations you need.

Browse and install AgentMail, Gmail, or Outlook during setup, or add them later from the dashboard.

Keep control

Your keys and configuration stay under your control.

Everyday choices remain approachable, advanced control remains available, and a earlier snapshots make configuration changes reversible.

Keep secrets out of plaintext configuration.

LaunchZero connects Hermes and OpenClaw to its encrypted, local-only secret store for you. Keys managed through LaunchZero stay out of plaintext LaunchZero-managed JSON or YAML configuration.

Use a form or edit the source configuration.

Change common Hermes and OpenClaw settings through a simple form. Open the integrated JSON/YAML editor when you need direct, advanced control.

Restore an earlier configuration.

Automatic and manual snapshots keep a version history for each agent. Restore a previous snapshot when a change does not work out.

Set boundaries

Decide what can happen.

A global security posture sets the outer boundary. Per-tool rules, least-privilege access, and the live trust score determine how each request is handled inside it.

Choose a security posture.
Start with Locked down, Balanced, or Permissive, or use Custom. The posture remains the dominant guardrail over individual integration policies.
Set the outcome for each gated tool.
Under the recommended Balanced posture, unknown calls deny and selected writes and sends ask for approval. Effective policy determines the outcome.
  • Allow
  • Require Approval
  • Deny
Use monitored tools for governed access.
Monitored tools provide governed file, command, and network paths. Short-lived, one-shot execution capabilities carry the authority granted to a permitted request.
Grant new folder or host access deliberately.
Monitored file and network tools use workspace and host allowlists. Runtime access grants let you allow a new destination once or add an explicit, scoped durable grant.
Let the trust score change the decision.
Your posture sets the trust thresholds. At or below the low threshold, governed requests escalate to approval. Below critical, monitored writes are denied.

Review and verify

Review the exact request. See what ran.

The approval moment and the resulting Activity record stay connected, so the person who decided and the person who verifies later see the same request.

Proposed

Send the drafted message

Monitored toolgmail · send_message

Recipient, subject, and message stay attached to the request.

Decision gate

Writes and sends need approval

trust score · 82 / 100

  • AllowRuns without review
  • Require ApprovalPauses for your decisionThis request
  • DenyStops before execution

Your decision

Review the exact recipient, subject, and message.

Approve exact action · Deny request

The approval stays bound to this canonical request.

Submit for Execution

The approved request returns to the monitored tool.

Executed

The exact send runs once.

The monitored integration handles this approved request.

Audit receipt

Approved by you · succeeded

Policy, approval, execution, and provenance share one record.

unbroken chain

Review the exact request.

The approval shows the action, risk, request details, agent, trust score, triggering policy rule, requested and expiry times, Approval ID, Correlation ID, and Canonical Hash before you approve or deny.

See what ran.

Activity records Proposed, approved, denied, Executed, failed, and succeeded events. Filter or export the history and verify that its hash chain remains unbroken.

LaunchZero Activity view reporting a verified audit trail and an unbroken chain
Activity keeps policy, approval, token, and execution events together and verifies the resulting hash chain.

Track agent/model spend separately.

Review collected usage and spend estimates without confusing them with product price.

Explore agent spend →

Frequently asked questions

Do I need to use the terminal or edit config files?

No - guided setup gets you from nothing to a running agent with governed tools in minutes and automates the CLI commands and hand-edited JSON/YAML config that running an agent normally requires.

If you want direct control, there is a simple form for the common options and an integrated editor for power users - but everyday setup never touches a terminal.

Which agents does it support?

OpenClaw and Hermes, on Windows, macOS, and Linux. You can run either - or both side by side - each set up and configured automatically. One is the default, and switching takes effect immediately.

Can I undo a configuration change?

Yes. LaunchZero keeps automatic and manual snapshots for each agent's configuration. If a change doesn't work out, restore an earlier snapshot instead of hand-editing the file to undo the mistake.

Where are my API keys stored?

Keys managed through LaunchZero live in its encrypted, local-only secret store rather than plaintext LaunchZero-managed configuration. LaunchZero connects Hermes and OpenClaw to that store for you. Provider credentials remain within the agent's configured trust boundary.

Will it change how I use my agent?

No - it's additive. Once LaunchZero is running you can use your agent's own interface or work with OpenClaw and Hermes inside LaunchZero, switching between them in one place. In either workflow, monitored tools and LaunchZero-managed integrations remain inside the same policy and evidence boundary. It runs natively on Windows, macOS, and Linux.

Is LaunchZero free and open source?

Yes. The complete local-first gateway is free and open source under AGPL-3.0. The core app does not require an account, telemetry, or a paywall.

Set up the agent. Keep the decision.

Free, open source, local-first. Guided setup gets you to Launch in minutes.