Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.
Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.

AI Engineer · @aiDotEngineer
This video has no Most replayed graph yet: YouTube shows one only once a video has enough views. These are the moments viewers replayed most in AI Engineer's most watched videos.
Most replayed moment at 18:45
4.8x that video's typical replay level
that they're they're changing they're changing things in the database not yet. You want to run them through the ontology first and make sure that works. Okay. I only got an I've got I've got another I've just a short time. I'm going to try to show you some of the things that um that you can
Said at 18:37
Most replayed moment at 16:13
3.6x that video's typical replay level
method signatures, the program layout and the call stacks. So here's some examples. I don't think you'll be able to read this one, but this is like the level of abstraction we're at. It's how we're actually going to lay this stuff out and how these systems are going to interact. Dylan Mulroy from Cloudflare talks a
Said at 16:06
Most replayed moment at 13:49
2.3x that video's typical replay level
Fable uh and it runs into an unknown, ask it to log it, right? So that um you uh you can see where the deviations happened and then you can sort of figure out why as well, you know? It will usually give you some context about what happened.
Said at 13:43
The graph counts replays. It does not show where viewers stopped watching.
Words
2,865
Runtime
17:11
Speaking pace
167wpm
Reading time
12min
167 words per minute, between the 160 25th percentile and the 181 median of 349 measured videos. That distribution comes from the 349-video hook study.
Opening (first 30 seconds)
[music] >> Yeah. So, like like Phil said, I work at Pomerium and he's not the first person to have trouble pronouncing it. So, I actually convinced the marketing team to uh create Pomeranian stickers. So, if anybody wants Pomeranian stickers, I have a bunch with me. Um bit about me, uh I'm a dev advocate over at Pomerium as Phil said. Um from Canada, uh hailing from Montreal. So, uh if anybody likes poutine and bagels, feel free to chat with me after.
84 words, the words spoken in the first 30 seconds at 167 words per minute.
Free, no signup. See how the first 30 seconds hold attention, with rewrites.
Sentence shape
| Measure | This transcript |
|---|---|
| Sentences | 195 |
| Average words per sentence | 14.7 |
| Longest sentence | 88 words |
| Questions asked | 3 |
| Sentences containing a number | 3 |
Most used terms
Filler phrases
224 in total: uh 106 · like 47 · um 31 · kind of 12 · you know 12 · actually 7 · basically 7 · I mean 1 · literally 1.
A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.
What this transcript is
Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.
[music] >> Yeah. So, like like Phil said, I work at Pomerium and he's not the first person to have trouble pronouncing it. So, I actually convinced the marketing team to uh create Pomeranian stickers. So, if anybody wants Pomeranian stickers, I have a bunch with me. Um bit about me, uh I'm a dev advocate over at Pomerium as Phil said. Um from Canada, uh hailing from Montreal. So, uh if anybody likes poutine and bagels, feel free to chat with me after.
Uh also a GitHub star, Microsoft MVP, and AWS community builder. And these you can pretty much find me everywhere uh at Nikki T online. Um I was pretty happy to see this that there's a a pretty sizable instance on prem of Open Claw. So, I was pretty happy with that. And it looks like that's the operator there. Cool. So, uh I don't know, I came up with a funny title, I guess, but Clawzette. Um we're going to talk about a feature I contributed to the Open Claw project back in February.
And it's about hardening access to the control plane. So, uh I'm assuming everybody here is running an Open Claw or Open Claw curious. Um is anybody running uh a mode called trusted proxy auth mode? You you might not be, but uh okay. You might be on the Who's on the token auth? Okay. Um anyways, so at Pomerium where I work, um you know, I'm always just trying to secure things. That's just part of what I do. And I was able to secure Open Claw, but it meant I still had to add a token uh for the web socket connection.
I had to always pair my device and stuff. And you don't really need that with uh a trusted proxy. Like specifically the one that I work on, which is Open Core, it's called an identity-aware proxy. So, if anybody's ever used GCP, uh there's a IAP in there. It's called an identity-aware proxy, something that came out of Google. Uh essentially, you've got an identity provider, a policy engine, and a reverse proxy. So, those uh it's not the lethal trifecta in the sense that you usually hear, but uh it's a pretty solid security approach for securing internal apps.
So, I was like, of course, I I I kind of got annoyed that I had to add this token still and do the pairing every time. Uh I understood why they were there, but uh I just proposed this issue and then uh at least one other person who uses Caddy uh chimed in and said, "Hey, that's uh sounds like a good idea." And then Peter uh Stipe was like, "Yeah, let's let's work on this." And he laid out like the criteria that he wanted to have for this feature.
So, I went ahead and worked on it. And yeah, again, prior to trusted proxy auth mode, even if you were secured by a proxy, you still had to paste in that auth token in the UI for the web socket connection. And also it sticks it in the query string, which uh obviously like this is really more for just only local mode really. Um and still having to pair the device. Like uh I don't know if people get annoyed by pairing the device, but uh I you know, I I'd just be on a my phone after I just set it up.
And then I was like, "Uh I got to go to the other thing to set it up." So, um basically, you still had to do those things even if it was secured with uh a proxy. So, got merged in and uh I felt pretty good about it. And uh it was nice to get some praise from Peter. It was uh my first contribution to the project. So, it's very cool. So, what does it look like exactly like in the config? Uh I'm just going to show like a kind of narrow part of the config here, but you have your gateway.
And essentially, you no longer need the token like I mentioned. Uh the mode is obviously different, so it's called trusted proxy now. And then there's some new properties you have to add. So, there's trusted proxies. And this is essentially the proxy that is gating access to the control plane, the uh the gateway. Um it's the IP addresses. It could be one or more. And aside from that, you have to have a trusted proxy section.
So, you'll have a user header, which is in in my case uh it's a jot, uh JWT. Um and then there's like a required header section. There's some optional ones, too. It depends what you want to do. There's like allowed users. And in my case, I don't need the allowed users because the way uh identity-aware proxy works is the policies dictate that. Um but essentially, that's kind of the big change there. And you can do this through the onboarding or if you just go back in and uh configure things through the TUI.
And yeah, so that just meant no more token for web socket connections and no longer needed to pair devices. So, not only are you uh getting uh better security posture potentially, uh to me it's like a UX win as well cuz I really found doing these two things annoying. Um Cool. Uh I also just want to give a shout-out to a couple contributors after I contributed this. Um there was a bug and Anthony reported it and then uh Sid fixed it.
And uh it was definitely something I missed because I basically was testing this on my local environment and I already had something paired. So, I didn't run into the issue that uh Anthony had mentioned. So, uh luckily uh it was a small fix and uh Sid got that sorted out. But just uh you know, when you miss stuff, uh people in the community step up. So, OSS for the win. The other thing I want to mention is not so much about this feature, but like when I opened this issue, uh the number of the issue was 1560.
And I had a a PR initially that was like in the 1700s. And I went on vacation and I said, "Oh, I'll get back to it when I'm back." And the original PR was closed cuz it was stale. And like literally after 2 weeks, it went from like 1500 to like almost 16,000. So, uh basically, that's just a testament to how popular the project got. But also meant I had to rebase quite a bit before it got merged. So, anyways, I don't know if anybody else that contributes [clears throat] to the project, but there's so many things going on all the time.
So, there's a lot of uh rebasing to keep your thing up to date. Cool. So, uh let's talk about my own Open Claw. So, this is my claw. And he's sitting on my desk in Montreal right now. There's some snow still. Um I use it in Discord. I don't know where people use their Open Claw. I had it on Telegram initially, but they don't actually uh uh their their uh channels aren't encrypted. So, like all the stuff's in clear. So, I work at a security company and my CEO is like, "Yeah, don't use that." So, anyways, uh I'm mainly on Discord.
I find it use uh handy that way. I have WhatsApp, too, but I tend to use the Discord more. Um Some things I want to mention, too, is when I made the contribution, I actually used Open Claw to make the contribution, which was kind of fun. Um but it also uh I made the mistake of I used the GitHub CLI and I gave it full access. So, it put up a PR right away even before I was like done reviewing things. Uh so, I had a little like, "Ah." But uh put it back in a draft mode.
Um but aside from that, um after the uh token uh trusted proxy mode got merged, I just started working on something. It started getting fun to just build stuff on my phone. So, I built out something called Claw Space. And you know, doesn't doesn't mean you need to use it. It's just, you know, it's the age of personal software. I just had a lot of fun building it. I find it useful. And I thought it was just cool that I could build this out on my phone on Discord.
Um but for me, I find it useful because I don't need to SSH in to see workspace files that I want to actually read or like edit. Uh so, uh that's just a little side project I started building. And you can edit files and stuff, too. Cool. So, we're going to do a demo here. This is going to be uh live coding. So, YOLO. Okay. So, uh there's a MCP track tomorrow. Uh I've been doing a lot of work in MCPs. So, what we're going to do is we are going to build out an MCP, uh not a full-fledged version of something.
But if you've seen the uh AI engineer website, they have like a LMs text on the right. And there's a MCP server and there's a few other things. So, I'm going to go ahead and just add this here. And I'm going to go create an app. I'll explain some things here in a second. Okay. And OAuth. Okay. So, this is going to go create an application in ChatGPT. Uh but basically, this is uh an MCP server that just has UI as well.
They'll they'll be talking about this tomorrow. But uh I have a template that I use for this. So, it's not like I'm building this from scratch. But we're just going to register the MCP here. and then I'm just going to start building with open claw. And the thing with a gentic is you never know when it's done. It's just finishing up a wath here. Okay, cool. It's connected and we can see here it's got two tools. It's got a echo tool and it's got a search speakers tool.
So if we come here if nobody's ever used MCP apps basically in chat GPT do this for your app and I'm going to say like echo hello. And essentially it's going to do the tool call but because there is UI associated to it, you're going to get some UI in here. And this is just using the standard MCP stuff that's in the spec now. Um so you can do stuff like change that, make it big and stuff. But what I want to show is like when I'm building this with open claw, I can do stuff like this.
I can say like uh ba ba ba change echo message to AIEU in the echo widget. Now it's going to take a second but um this is all web tech under the hood so I don't know if anybody's web devs here but essentially it's using V and react so there's react refresh and V hot module reloading. McClaw is on the case here and you can see I'm in chat GPT I'm editing live from my workspace the MCP and and to explain how this is working, uh we have the trusted proxy off mode.
Uh I happen to be using pomerium in this case so I'm using it as well to secure other things in the workspace so I have a public URL that I've gated for the MCP and that's how I'm able to use it in chat GPT. And I can go ahead and just keep working on it in here and I don't know how other people work or build with uh open claw but this is kind of how I've been doing it. I find it works really well for web dev stuff. So I'm going to go say update the search speaker so let's just do this in new chat.
And I'll say at AIE again search speakers. And it's going to give uh a very minimal UI here cuz there's not much into it. Uh so I'm going to just tell McClaw to get on the case here. And basically if you go to that top right corner of the AIE uh website, there's uh speaker.json and this is like all the speakers from the conf and we're going to use that as like the source of users and then I'm asking it to kind of give the same UI as what you kind of saw in the echo widget.
Uh it's going to take a minute here probably cuz uh McClaw is covered in snow probably in Montreal but uh cool. And so basically once this gets done uh we'll be able to filter users and just kind of you know see who's talking um at the conference and I'm just going to take a sip of water while McClaw is chugging along there. Again, you never know when a gentic finishes. Okay, it's deterministic and it's deterministically an indeterminate.
So it should be done in a second and then what you're going to see is you're going to see this updated and again just to reiterate the flow I'm I'm working in workspace files in my open claw. I'm speaking to it or typing to it in discord. Uh this is a publicly available site uh and I'm able to build it as I'm in my open claw and I like that workflow. I really don't know how other people work. I mean obviously I use other tools like Claude and and Codex too.
Uh but you can see here um McClaw was able to get the job done and then I can start filtering so we could look for drilling down here then we can find a speaker and then we can get a bit more information and then like I could say let's add another feature here so let's get McClaw on the case again. So we're going to add a more button here and there's this send message function that you can use in MCP apps and this is actually going to uh when you click the but the more button that it's going to generate, this will actually make a call to the LLM to and you're going to get a response back.
Uh so we'll give this a second. Uh ba da ba da ba. Cool. So I added this more button in uh again like I've been doing web dev for a while and I I always still find it magical when things just automatically update but I'm going to go ahead and click on here and you're going to see here that it's thinking now so it actually made a call uh added another uh prompt to chat GPT here and it's going to kind of summarize why it thinks you should check out Alessandro's talk and a bit more about it.
Now I just really find this workflow really cool. It's only possible if you use some kind of proxy to do this. Uh you can do this with others like uh caddy with oauth. You could do it with uh well engine X is kind of deprecated at this point. We're not deprecated but uh at least in Kubernetes land the ingress controller is. Um but it's just a really nice way to gate stuff that is local but you can still expose it in a secure way.
Um and it's also just fun built. Like I don't know about anybody else but I've been really enjoying building stuff just chatting. Uh I remember a couple years ago uh replit um who's who's a AI company that's you know making it really easy to build stuff. I was like why would I ever want to build on my phone and uh I kind of got uh phone killed now I guess so. Um just fun you know just having fun. I think that's part of the thing with open claw.
Also just like use it however you want to. Like I I find that claw space I created super helpful. Uh you know build your own tools and stuff. Um definitely take security into consideration. Uh you know there's a bunch of people that have obviously you know exposed things and they didn't mean to. Like you know some people have deleted all their emails etc. Um but I don't know. I I find the trusted proxy off mode super useful and at least one other person does in the in the in that issue.
Um I encourage you to check it out. Uh just have fun building stuff and that's uh pretty much it. My name is Nick Taylor and that's how I build with open claw. >> [applause] [music]
The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.
Free tools for your own script. No signup, no login.
Paste your draft and see where viewers are likely to drop off, with a rewrite for each weak line.
Paste the first 30 seconds of your own draft for a hook score and rewrites.
Check your draft against YouTube's advertiser-friendly guidelines before you record it.
Read this channel's public videos and transcripts, and download a writing brief for it.