---
title: "Harden an OpenClaw gateway in 6 steps · DotsAgent"
description: "Harden OpenClaw in 6 steps: security audit, a 64-character token, loopback bind, sandboxed tools, exec set to deny, DM pairing and vetted ClawHub skills."
url: https://dotsagent.io/openclaw/hardening
---

OpenClaw guide · 6 steps

# Harden your OpenClaw gateway

Apply the hardened baseline from the OpenClaw docs: loopback and token auth, a sandbox, strict exec approvals and tight control over who can message the agent.

Some defaults are permissive: sandboxing is off and exec.security is full on gateway hosts. Back up ~/.openclaw/openclaw.json before you edit it.

1. Run the security audit The plain audit checks your configuration, --deep adds the extended checks, and --fix applies the fixes it can make on its own. Add --json for output that scripts can parse. Run the audit again after each step below. shell`openclaw security audit openclaw security audit --deep openclaw security audit --fix`
2. Generate a strong token Onboarding already creates a token. If you set your own, use at least 24 characters, because the audit warns on anything shorter. This command prints 64 random hex characters. shell`openssl rand -hex 32`
3. Bind to loopback with token auth In openclaw.json, set gateway.mode to local, gateway.bind to loopback and gateway.auth.mode to token, and put the token from step 2 in gateway.auth.token. Gateway auth fails closed, so requests without a valid token are refused. Do not use lan, custom or auto on a host that faces the internet.
4. Sandbox tools and limit file access Sandboxing is off by default. Turn it on with one of the supported backends (Docker, Podman, SSH, OpenShell or Crabbox) and confirm the result with openclaw sandbox explain. Then set tools.profile to messaging and tools.fs.workspaceOnly to true, and add tool groups you do not use, such as group:automation and group:runtime, to tools.deny.
5. Lock down shell commands Set tools.exec.security to deny so the agent cannot run commands at all. If a workflow needs a few, switch to allowlist and keep tools.exec.ask on always, so each command waits for your approval; askFallback defaults to deny when no one answers. Leave tools.elevated.enabled at false.
6. Control who reaches the agent Keep dmPolicy on pairing, set requireMention to true for groups, and set session.dmScope to per-channel-peer so senders never share a session. Skills run with the agent's privileges and OpenClaw does not block dangerous code at install time, so check each ClawHub skill's audit status before installing it and set security.installPolicy. In February 2026, researchers found hundreds of malicious skills on ClawHub.

The docs treat each gateway as a single trust boundary, not a hostile multi-tenant one. Run separate gateways for separate people or trust domains.

## More OpenClaw guides

[Install OpenClaw](https://dotsagent.io/openclaw/install)

[Run OpenClaw on a VPS](https://dotsagent.io/openclaw/vps)

[Run OpenClaw in Docker](https://dotsagent.io/openclaw/docker)

[Run OpenClaw on a Raspberry Pi](https://dotsagent.io/openclaw/raspberry-pi)

[Connect models to OpenClaw](https://dotsagent.io/openclaw/models)

[Connect OpenClaw to Telegram](https://dotsagent.io/openclaw/telegram)

[Remote access to OpenClaw](https://dotsagent.io/openclaw/remote-access)

## Sources

1. [docs.openclaw.ai](https://docs.openclaw.ai/gateway/security/hardened-baseline)/gateway/security/hardened-baseline
2. [docs.openclaw.ai](https://docs.openclaw.ai/gateway/security/running-the-audit)/gateway/security/running-the-audit
3. [docs.openclaw.ai](https://docs.openclaw.ai/gateway/sandboxing)/gateway/sandboxing
4. [docs.openclaw.ai](https://docs.openclaw.ai/tools/exec-approvals)/tools/exec-approvals
5. [docs.openclaw.ai](https://docs.openclaw.ai/gateway/security/access-control)/gateway/security/access-control
6. [docs.openclaw.ai](https://docs.openclaw.ai/clawhub)/clawhub

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
