Harden your OpenClaw gateway
Apply the hardened baseline from the OpenClaw docs: loopback and token auth, a sandbox, strict exec approvals and tight control over who can message the agent.
Some defaults are permissive: sandboxing is off and exec.security is full on gateway hosts. Back up ~/.openclaw/openclaw.json before you edit it.
Run the security audit
The plain audit checks your configuration, --deep adds the extended checks, and --fix applies the fixes it can make on its own. Add --json for output that scripts can parse. Run the audit again after each step below.
shell openclaw security audit openclaw security audit --deep openclaw security audit --fixGenerate a strong token
Onboarding already creates a token. If you set your own, use at least 24 characters, because the audit warns on anything shorter. This command prints 64 random hex characters.
shell openssl rand -hex 32Bind to loopback with token auth
In openclaw.json, set gateway.mode to local, gateway.bind to loopback and gateway.auth.mode to token, and put the token from step 2 in gateway.auth.token. Gateway auth fails closed, so requests without a valid token are refused. Do not use lan, custom or auto on a host that faces the internet.
Sandbox tools and limit file access
Sandboxing is off by default. Turn it on with one of the supported backends (Docker, Podman, SSH, OpenShell or Crabbox) and confirm the result with openclaw sandbox explain. Then set tools.profile to messaging and tools.fs.workspaceOnly to true, and add tool groups you do not use, such as group:automation and group:runtime, to tools.deny.
Lock down shell commands
Set tools.exec.security to deny so the agent cannot run commands at all. If a workflow needs a few, switch to allowlist and keep tools.exec.ask on always, so each command waits for your approval; askFallback defaults to deny when no one answers. Leave tools.elevated.enabled at false.
Control who reaches the agent
Keep dmPolicy on pairing, set requireMention to true for groups, and set session.dmScope to per-channel-peer so senders never share a session. Skills run with the agent's privileges and OpenClaw does not block dangerous code at install time, so check each ClawHub skill's audit status before installing it and set security.installPolicy. In February 2026, researchers found hundreds of malicious skills on ClawHub.
The docs treat each gateway as a single trust boundary, not a hostile multi-tenant one. Run separate gateways for separate people or trust domains.