Open-source crypto AML screening desk by the Width DAIA team — KYA address screening, KYT transaction screening, and 24/7 monitoring, powered by the width.info V3 compliance API.
AMLClaw packages the underlying KYA/KYT APIs into payment-industry workflows: deposit/withdrawal screening, continuous monitoring (per-tx KYT on an address's future transfers; counterparty label-change watch that alerts the moment an address gets tagged Sanctions/Freeze), risk alerting and evidence-chain reports.
One API key, professional server-side rulesets, full path evidence.
KYA Screening · KYT Screening · Address Monitoring · TX Monitoring
git clone https://github.com/amlclaw/amlclaw.com.git
cd amlclaw.com
npm install
npm run devOpen http://localhost:3000, go to Settings → API Keys, paste your width.info API key, and start screening.
- Node.js 18+
- Width.info API key — free at width.info/api-keys. Powers all KYA/KYT screening; compliance rulesets run server-side.
- Etherscan / TronGrid API keys (optional) — feed the address-monitoring tx stream. Without your own keys, shared defaults are used and may be rate-limited.
Screen any Ethereum or Tron address against professional compliance rulesets — Sanctions, Terrorism Financing, Cybercrime, Gambling, Public Freezing Actions, and more. Multi-hop fund tracing (0–5 hops each direction) with:
- Risk level (
low / medium / high / critical) — decided by your ruleset, not a fixed score - Address identity checks (is the address itself sanctioned?)
- Exposure breakdown by category and direction
- Per-rule hits with full path evidence and an interactive fund-flow graph
- Advanced settings: hops, node/path caps, min amount, time window, contract penetration
Paste a transaction hash and screen its source of funds (in), destination (out), or both. Each direction uses its own dedicated server-side ruleset (KYT-IN / KYT-OUT builtins by default). Results are Chainalysis-aligned: alert list with exposure types (DIRECT/INDIRECT), recommended actions (block / review / alert / monitor), plus per-hit path evidence.
Add an address and AMLClaw watches its future stablecoin transfers (Ethereum: USDT + USDC; Tron: USDT) via Etherscan/TronGrid on your schedule (hourly to daily). Every new transfer above your minimum amount is automatically KYT-screened — receiving = in, sending = out. High-risk hits fire webhook alerts.
From any KYT result, put the transaction's from or to address under watch. Each cycle re-runs a KYA screen (1-hop, rolling time window since the last run), tracks the risk trend, and alerts the moment the counterparty is tagged Sanctions/Freeze or its risk level escalates.
- Server-side rulesets — no local rule maintenance;
ruleset_id 0= builtin defaults, or reference your own rulesets by id from width.info → Compliance → Rulesets - Explorer-style ledgers — every monitored transaction / scan in a filterable table (by risk level, time range) with per-row evidence; failed screens auto-retry
- Evidence graph — interactive fund-flow visualization (React Flow + dagre), cluster aggregation for same-tag risk sources
- Webhook alerts — real-time notifications on high/critical results and risk escalations
- Screening history — typed KYA/KYT history with one-click recall
- Bilingual (Chinese default / English) with dark/light theme
- No database — file-based storage, backup-friendly, deploy anywhere
- Self-hosted — your data never leaves your server (MIT license)
app/(app)/ # Product pages: dashboard, screening (KYA), kyt, monitoring, tx-monitoring, docs, settings
app/api/ # API routes: screening, kyt, monitors, dashboard, settings
components/ # React components by domain (screening, monitoring, settings, landing, shared)
lib/ # Core logic:
# width-api.ts — width.info V3 client (KYA/KYT sync screening)
# chain-txs.ts — Etherscan/TronGrid tx feeds + cursor management
# scheduler.ts — node-cron monitor execution (global sequential queue)
# monitor-txs.ts — per-monitor tx ledger (capture / screen / retry)
# storage.ts — file-based history + monitors
# settings.ts — settings with key masking
data/ # Runtime data (gitignored: settings.json with API keys, history, monitors)
tests/ # Unit (vitest) + integration tests
npm run dev # Dev server on port 3000
npm run build # Production build
npm run lint # ESLint
npm run test:unit # Unit tests (vitest)
npm test # Integration tests (requires dev server running)docker compose up -dOpen http://localhost:3000. Data is persisted in the ./data directory via volume mount.
- Mount
./datato a persistent volume for data durability - Use a reverse proxy (nginx/Caddy) for HTTPS — the app's local endpoints are open by default, so put it behind your own gateway/auth if exposed
- Add your own Etherscan/TronGrid keys to avoid shared rate limits on monitoring
Chinese (default) and English out of the box, toggled from the sidebar. Translation files in locales/:
locales/zh.json # Chinese (default)
locales/en.json # English
- More chains — as supported by the width.info API
- Batch screening — multi-address KYA submissions
- Report export — Markdown & PDF
- Analytics — trend analysis, risk heatmaps, compliance KPIs
- Case workflow — investigation and disposition on top of screening history
See CONTRIBUTING.md for development setup and PR process.
See SECURITY.md. AMLClaw is self-hosted by design — your data never leaves your server. API keys live only in data/settings.json (gitignored) or environment variables.