LaunchedEditorial Listing

QwenPaw

AgentScope · QwenPaw: Open-Source Personal AI Assistant with Local Models and Sandboxed Tools

Open QwenPaw

QwenPaw is a free, Apache-2.0 personal AI assistant from the AgentScope team that you run on your own machine, a server, or a one-click cloud deployment. It chats through DingTalk, Feishu (Lark), WeChat, WeCom, QQ, Discord, Telegram, Slack, iMessage, and more, runs scheduled tasks, handles documents and email, and can use small local QwenPaw-Flash models with no API key. It suits technical users, especially those working in Chinese messaging apps, who want a self-hosted agent with sandboxed tool use.

PricingFree
Setupmedium
Runs onSelf-hosted · Desktop · API
APIYes
Open sourceYes
DocsYes
CategoryProductivity
Open SourcePersonal AssistantSelf-HostedMessagingLocal ModelsSandboxMulti-AgentPersistent MemoryMCPScheduled Tasks

Best for

Technical users and small teams who want a self-hosted assistant in DingTalk, Feishu, WeCom, WeChat, or QQ, offline use with small local models, and built-in tool guards with an OS-level shell sandbox

Not ideal for

People who mainly chat in WhatsApp or Signal, anyone who wants a polished, signed consumer app with vendor support, and organizations that need a hardened multi-tenant service

Who it's for

Developers, technical power users, and small trusted teams who want a self-hosted personal agent, particularly in Chinese messaging apps or with offline local models

Capabilities

  • One instance answers across DingTalk, Feishu (Lark), WeCom, personal WeChat, QQ, Yuanbao, XiaoYi, Discord, Telegram, Slack, iMessage (macOS), Mattermost, Matrix, MQTT, and Microsoft Bot Service, plus phone calls via Twilio or SIP
  • QwenPaw-Flash local models (2B, 4B, 9B, with Q4 and Q8 builds) tuned for its agent tasks, downloaded and started from the Console through the built-in llama.cpp provider, which recommends a version for your hardware
  • Also works with Ollama, LM Studio, preset cloud providers (DashScope, ModelScope, OpenAI, Azure OpenAI, Anthropic, Google Gemini, DeepSeek, Kimi, MiniMax, Zhipu, OpenRouter, and others), and custom OpenAI- or Anthropic-compatible endpoints, with per-agent model routing and fallback
  • Five security layers: tool guard with configurable approval levels, file guard for sensitive paths, kernel-level shell sandbox (Seatbelt, Bubblewrap/Landlock, AppContainer), skill scanner, and per-tool access policies that allow, deny, or ask for approval
  • Multiple agents per instance, each with its own workspace, memory, skills, and chat history, plus runtime sub-agents and collaboration skills
  • Self-evolving Markdown memory powered by ReMe, with every turn persisted and older turns indexed for recall
  • Cron jobs and heartbeat check-ins that post results to a chosen chat channel
  • Mail assistant over IMAP/SMTP with thread-aware actions, sender allow and deny lists, and human approval for unknown recipients
  • Skills for PDF, Word, Excel, PowerPoint, browser use, and news, a plugin and app marketplace, and MCP, A2A, and ACP connectors
  • Web Console, terminal UI, REST API, and a beta desktop app (Windows 10+, macOS 14+) that all drive the same agent
  • QwenPaw Hub (v2.2+): a self-hosted multi-user server where each member gets a separate QwenPaw, run as local processes or Docker containers

Limitations

  • No WhatsApp or Signal channel is documented; its strongest channel coverage is in Chinese apps such as DingTalk, Feishu, WeCom, WeChat, and QQ
  • The managed mailbox workflow supports nine personal mail domains (163, 126, yeah.net, QQ, Foxmail, Sina, Aliyun, and Gmail); Outlook and work mail servers are not on the list
  • The built-in QwenPaw Local runtime is still in testing, and the docs recommend Ollama or LM Studio for more stable GPU use; local models need a context length of at least 32K
  • The desktop app is in beta and is not code-signed on Windows or notarized on macOS, so both systems show security warnings on first launch
  • Computer use is a beta plugin available only in the desktop app on Windows and macOS
  • QwenPaw Hub 2.2 is an early release meant only for internal teams whose members trust one another, not for public multi-tenant use
  • Anonymous usage telemetry is accepted automatically when you run qwenpaw init with --defaults
  • Web login for the Console is disabled by default, so you must turn on authentication before exposing an instance beyond localhost
  • Cloud models need your own API key, and quality depends on the model you connect

Use cases

  • Running a personal assistant inside DingTalk, Feishu, or WeCom that answers questions and manages todos
  • Posting a scheduled news digest or report to several chat channels every morning
  • Triage of a Gmail or QQ Mail inbox, with replies to unknown recipients held for approval
  • Running an assistant fully offline on a laptop with a downloaded QwenPaw-Flash model
  • Giving a small team separate assistants on one shared server with QwenPaw Hub
  • Converting and summarizing PDF, Word, Excel, and PowerPoint files from a chat message

Our take

QwenPaw covers much of the same ground as OpenClaw and Hermes Agent: a self-hosted assistant that lives in chat apps, keeps Markdown memory, runs scheduled jobs, and extends through skills and MCP. Choose it over those two for specific reasons. If your team works in DingTalk, Feishu, WeCom, WeChat, or QQ, it treats those as primary channels. If you want an agent that runs on a laptop with no API key, its own QwenPaw-Flash models and built-in local provider get you there from the Console. If you are wary of letting an agent run shell commands, its sandbox, guards, and approval policies are part of the core rather than optional add-ons. If you live in WhatsApp or Signal, need a signed and supported app, or want to expose it to untrusted users, it is not the right fit yet.

Who should use it

Developers and technical users who chat in DingTalk, Feishu, WeCom, WeChat, or QQ, people who want an assistant that runs offline on small local models, security-conscious users who want sandboxed and approval-gated tool use, and small trusted teams that want separate assistants on one server.

Who should skip it

People who mainly use WhatsApp or Signal, non-technical users who want a signed, supported consumer app, teams whose mail is on Outlook or a company mail server, and anyone planning to offer the Hub to untrusted or public users.

Strengths

  • Ships its own small local models and a built-in runtime, so it can run offline with no API key
  • Tool guard, file guard, skill scanner, and an OS-level shell sandbox are built in rather than add-ons
  • First-class DingTalk, Feishu, WeCom, WeChat, and QQ channels alongside Discord, Telegram, and Slack
  • Free and Apache-2.0 licensed, with Docker images and a REST API
  • Self-hosted multi-user Hub for small teams
  • Frequent releases: 2.0 in July 2026 and 2.2.1 in September 2026

Weaknesses

  • No WhatsApp or Signal channel
  • Managed mail supports only nine personal mail domains
  • Desktop app, built-in local runtime, and computer use are still beta or testing
  • Desktop builds are unsigned, and telemetry is on by default with --defaults
  • Hub is not suitable for public or untrusted multi-tenant use

QwenPaw pricing

Open Source

Free

  • Apache-2.0 license
  • Install with pip, a one-line script, Docker, or the beta desktop app
  • QwenPaw Hub for multi-user self-hosting included
  • Bring your own cloud API key or run local models

Free tier limits: QwenPaw itself has no paid tier. Running QwenPaw-Flash or other local models costs nothing beyond your hardware; cloud models are billed by the provider.

Note: The README also lists cloud deployment options: one-click deployment on the AgentScope Platform (described there as free), ModelScope Studio, and Alibaba Cloud ECS, where you pay for the server.

Technical specs

Modalities

Text, Image, Voice (phone calls via Twilio or SIP)

API pricing

Free self-hosted REST API; model usage is billed by the provider you connect

Available models

QwenPaw-Flash 2B, 4B, and 9B (full, Q8, and Q4 builds)Local models via the built-in llama.cpp runtime, Ollama, or LM StudioDashScope (Qwen), ModelScope, OpenAI, Azure OpenAI, Anthropic, Google Gemini, DeepSeek, Kimi, MiniMax, Zhipu, OpenRouter, SiliconFlow, Volcengine, Xiaomi MiMo, GitHub ModelsCustom OpenAI chat.completions or Anthropic messages compatible endpoints (for example vLLM)

Where QwenPaw excels

An assistant inside a company's DingTalk or Feishu workspace

DingTalk is QwenPaw's recommended channel and Feishu, WeCom, and QQ have dedicated setup guides, so teams on those apps can use the assistant where they already work.

A private assistant on a laptop with no cloud model

The Console recommends a QwenPaw-Flash model for your hardware, downloads it, and starts it through the built-in llama.cpp provider, so conversations stay on the machine.

Daily digests pushed to several channels

Cron jobs and heartbeat check-ins can ask the agent a question on a schedule and send the answer to DingTalk, Telegram, Discord, or other connected channels.

Mailbox triage with a safety net

The mail assistant monitors new mail, applies sender allow and deny rules, and holds messages to unknown recipients for human approval before sending.

QwenPaw vs. competitors

QwenPaw vs. OpenClaw

OpenClaw is a widely used self-hosted assistant built on TypeScript/Node.js with 29 channels including WhatsApp, Signal, and Microsoft Teams, and model access you bring yourself. QwenPaw is a Python alternative that leads with DingTalk, Feishu, WeCom, WeChat, and QQ, ships its own QwenPaw-Flash local models with a built-in runtime, and builds in a tool guard, file guard, and OS-level shell sandbox, where OpenClaw's Docker sandbox is optional. Pick OpenClaw for Western messaging apps and its larger ecosystem, and QwenPaw for Chinese workplace apps, offline small models, or more built-in guardrails.

QwenPaw vs. Hermes Agent

Hermes Agent from Nous Research focuses on compounding memory and skills it writes from experience, with 20+ platforms including WhatsApp and Signal and an OpenAI-compatible API server. QwenPaw also keeps Markdown memory and supports multi-agent work, but adds its own local models, kernel-level sandboxing, and a self-hosted multi-user Hub, with channel coverage centered on Chinese apps. Pick Hermes for long-running memory-driven automation on Western platforms, and QwenPaw for Chinese messaging, offline models, or team hosting.

Frequently asked questions

What is QwenPaw?

QwenPaw is an open-source personal AI assistant from the AgentScope team. You run it on your own computer, a server, or a cloud deployment, and talk to it through a web Console, a terminal UI, a REST API, or chat apps such as DingTalk, Feishu, WeChat, QQ, Discord, Telegram, and Slack. It runs scheduled tasks, works with documents and email, browses the web, and keeps long-term memory as Markdown files.

Is QwenPaw free and open source?

Yes. QwenPaw is released under the Apache License 2.0 and has no paid tier. You pay only for cloud model usage if you connect a cloud provider, or nothing beyond your hardware if you use local models.

Can QwenPaw run without an API key?

Yes. Its built-in QwenPaw Local runtime (based on llama.cpp) can download and run the QwenPaw-Flash 2B, 4B, or 9B models, or other models from ModelScope or Hugging Face, from the Console, and it also works with Ollama and LM Studio. The docs note that QwenPaw Local is still in testing and recommend a context length of at least 32K for local models.

Does QwenPaw only work with Qwen models?

No. Despite the name, it supports many cloud providers, including DashScope (Qwen), OpenAI, Anthropic, Google Gemini, DeepSeek, Kimi, MiniMax, Zhipu, and OpenRouter, plus custom OpenAI- or Anthropic-compatible endpoints and local models.

Which chat apps does QwenPaw support?

The docs cover DingTalk (recommended), Feishu (Lark), WeCom, personal WeChat, QQ, Yuanbao, XiaoYi, Discord, Telegram, Slack, iMessage on macOS, Mattermost, Matrix, MQTT, Microsoft Bot Service, and voice calls via Twilio or SIP. WhatsApp and Signal are not listed.

QwenPaw vs OpenClaw: what is the difference?

Both are free, self-hosted assistants that work through chat apps. OpenClaw is a TypeScript/Node.js project with a wider set of Western channels such as WhatsApp and Signal and an optional Docker sandbox. QwenPaw is a Python project with first-class Chinese channels such as DingTalk, WeCom, and QQ, its own QwenPaw-Flash local models with a built-in runtime, and a kernel-level sandbox, tool guard, and file guard built in.

Integrations & fit

DingTalkFeishu (Lark)WeComWeChatQQDiscordTelegramSlackiMessageMatrixMattermostTwilioDashScopeModelScopeOpenAIAnthropicGoogle GeminiDeepSeekOpenRouterOllamaLM StudioHugging FaceMCPDocker
Good fit forSolo / individual, Startup / small team
Pricing modelFree· No cost to start
See pricing on QwenPaw →

Alternatives to consider

About QwenPaw

QwenPaw (short for Qwen Personal Agent Workstation) is a Python application built on the AgentScope framework. You install it with pip, a one-line script, Docker, or a beta desktop app for Windows and macOS, then configure models and channels in a local web Console at port 8088; a full-screen terminal UI and a REST API drive the same agent. One instance can answer in many chat apps at once. DingTalk is the recommended channel, and the docs also cover Feishu (Lark), WeCom, personal WeChat, QQ, Yuanbao, XiaoYi, Discord, Telegram, Slack, iMessage (macOS), Mattermost, Matrix, MQTT, Microsoft Bot Service, and phone calls through Twilio or SIP. Each agent has its own workspace, memory, skills, and chat history, and agents can spawn sub-agents and collaborate. Memory is a ReMe-powered, self-evolving knowledge base of readable Markdown files, with every turn persisted and older turns indexed for recall rather than summarized away. Beyond chat, it runs cron jobs and heartbeat digests, reads and writes PDF and Office files, browses the web, connects MCP servers, manages IMAP/SMTP mailboxes with approval rules, and (in beta, on the desktop app only) operates approved desktop applications. Three things set it apart from other self-hosted assistants. First, it ships its own QwenPaw-Flash models (2B, 4B, and 9B, with 4-bit and 8-bit builds) tuned for its agent tasks, plus a built-in llama.cpp provider that downloads the runtime and a model from the Console, so after setup it can run fully offline with no API key. Second, security is layered and built in: a tool guard checks tool calls before they run, a file guard blocks sensitive paths such as ~/.ssh, shell commands can run in a kernel-level sandbox (Seatbelt, Bubblewrap/Landlock, or AppContainer), and a skill scanner checks skills before activation. Third, version 2.2 added QwenPaw Hub, a self-hosted multi-user server that gives each team member a separate QwenPaw. The tradeoffs: there is no WhatsApp or Signal channel, the managed mail workflow supports only nine personal mail domains (mostly Chinese providers plus Gmail), the built-in local runtime and desktop app are still in testing, Hub is meant only for teams whose members trust one another, Console login is off until you enable it, and anonymous telemetry is on by default when you initialize with defaults.

Updates from QwenPaw

New FeatureQwenPaw 2.2.1: per-agent model routing

Version 2.2.1 lets each agent use its own model routing, provider preferences, and fallback, adds a unified environment-variable settings page, one-click plugin updates, and Creator 1.2 with a blueprint workbench.

LaunchQwenPaw 2.2.0: Hub, Mail, and Data

Version 2.2.0 added QwenPaw Hub for self-hosted multi-user deployments, a mail assistant with sender rules and approval for unknown recipients, the QwenPaw Data analysis app, unified model routing, and one marketplace for apps, plugins, and skills.

New FeatureQwenPaw 2.1.0: browser use and computer use

Version 2.1.0 introduced browser use, computer use, a unified Files workspace, workspace checkpoints, QwenPaw Creator, and integration with Codex and Qoder agents.

Are you the founder? Claim this listing →