dotsagent.io
Language:English
OpenClaw guide · 6 steps

Harden your OpenClaw gateway

Apply the hardened baseline from the OpenClaw docs: loopback and token auth, a sandbox, strict exec approvals and tight control over who can message the agent.

Some defaults are permissive: sandboxing is off and exec.security is full on gateway hosts. Back up ~/.openclaw/openclaw.json before you edit it.

  1. Run the security audit

    The plain audit checks your configuration, --deep adds the extended checks, and --fix applies the fixes it can make on its own. Add --json for output that scripts can parse. Run the audit again after each step below.

    shell
    openclaw security audit
    openclaw security audit --deep
    openclaw security audit --fix
  2. Generate a strong token

    Onboarding already creates a token. If you set your own, use at least 24 characters, because the audit warns on anything shorter. This command prints 64 random hex characters.

    shell
    openssl rand -hex 32
  3. Bind to loopback with token auth

    In openclaw.json, set gateway.mode to local, gateway.bind to loopback and gateway.auth.mode to token, and put the token from step 2 in gateway.auth.token. Gateway auth fails closed, so requests without a valid token are refused. Do not use lan, custom or auto on a host that faces the internet.

  4. Sandbox tools and limit file access

    Sandboxing is off by default. Turn it on with one of the supported backends (Docker, Podman, SSH, OpenShell or Crabbox) and confirm the result with openclaw sandbox explain. Then set tools.profile to messaging and tools.fs.workspaceOnly to true, and add tool groups you do not use, such as group:automation and group:runtime, to tools.deny.

  5. Lock down shell commands

    Set tools.exec.security to deny so the agent cannot run commands at all. If a workflow needs a few, switch to allowlist and keep tools.exec.ask on always, so each command waits for your approval; askFallback defaults to deny when no one answers. Leave tools.elevated.enabled at false.

  6. Control who reaches the agent

    Keep dmPolicy on pairing, set requireMention to true for groups, and set session.dmScope to per-channel-peer so senders never share a session. Skills run with the agent's privileges and OpenClaw does not block dangerous code at install time, so check each ClawHub skill's audit status before installing it and set security.installPolicy. In February 2026, researchers found hundreds of malicious skills on ClawHub.

The docs treat each gateway as a single trust boundary, not a hostile multi-tenant one. Run separate gateways for separate people or trust domains.

More OpenClaw guides

Sources

  1. docs.openclaw.ai/gateway/security/hardened-baseline
  2. docs.openclaw.ai/gateway/security/running-the-audit
  3. docs.openclaw.ai/gateway/sandboxing
  4. docs.openclaw.ai/tools/exec-approvals
  5. docs.openclaw.ai/gateway/security/access-control
  6. docs.openclaw.ai/clawhub

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026