[{"data":1,"prerenderedAt":187},["ShallowReactive",2],{"copy:en:site:":3,"copy:en:openclaw:guide,ui,guides.hardening,guides.install.title,guides.vps.title,guides.docker.title,guides.raspberry-pi.title,guides.models.title,guides.telegram.title,guides.hardening.title,guides.remote-access.title":122,"copy:en:site:common":185},{"common":4,"nav":16,"footer":44,"home":51,"error":115},{"skip":5,"menu":6,"language":7,"sections":8,"footer":9,"tool":10,"home":11,"breadcrumbs":12,"copy":13,"copied":14,"download":15},"Skip to content","Menu","Language","Sections","Footer","tool","Home","Breadcrumbs","Copy","Copied","Download",{"groups":17,"items":25},{"build":18,"connect":19,"instruct":20,"run":21,"web":22,"secure":23,"track":24},"Build","Connect","Instruct","Run","Open your site","Secure","Track",{"models":26,"cost":27,"frameworks":28,"mcp":29,"mcpConfig":30,"mcpClients":31,"agentsMd":32,"files":33,"openclaw":34,"agentReady":35,"llmsTxt":36,"robotsTxt":37,"apiCatalog":38,"bots":39,"security":40,"incidents":41,"checklist":42,"changelog":43},"Models and API prices","Agent cost calculator","Frameworks and SDKs","MCP servers","MCP config generator","MCP clients","AGENTS.md generator","Instruction files","Self-host OpenClaw","Agent-ready websites","llms.txt generator","robots.txt for AI bots","API catalog generator","AI bot directory","Agent security","Incident log","Security checklist","Changelog",{"about":45,"privacy":46,"terms":47,"sitemap":48,"disclaimer":49,"checked":50},"About","Privacy","Terms","Sitemap","Independent reference for people who build AI agents. Not affiliated with any vendor named here.","Facts checked {date}",{"seo":52,"eyebrow":55,"title":56,"lead":57,"ctaMcp":58,"ctaCost":59,"ctaAgents":60,"sheetLabel":61,"sheetTitle":62,"sheet":63,"sheetNote":69,"sectionsTitle":70,"sections":71,"latestTitle":98,"allChanges":99,"rulesTitle":100,"rules":101,"aboutLink":114},{"title":53,"description":54},"DotsAgent: reference and tools for building AI agents","LLM API prices, an agent cost calculator, MCP configs for 13 clients, AGENTS.md and llms.txt generators, and agent security notes. Free, in 18 languages.","For developers building AI agents","The agent builder's desk reference","Prices, protocols, config files and security notes for agent work, each checked against the vendor's own docs. Look a fact up, generate the file you need and get back to your code.","Generate an MCP config","Price an agent task","Write AGENTS.md","Current figures","State of the stack",{"mcp":64,"openclaw":65,"cheapest":66,"models":67,"servers":29,"bots":68},"MCP spec","OpenClaw","Cheapest model, $\u002FM in\u002Fout","Models priced","AI bots tracked","Each figure is checked by hand against vendor docs.","What's on the site",{"models":72,"mcp":76,"instructions":79,"frameworks":82,"openclaw":85,"agentReady":88,"security":91,"changelog":94},{"title":73,"body":74,"unit":75},"Models and prices","Input, output and cached token prices per million, side by side, with a calculator for whole agent runs.","models",{"title":29,"body":77,"unit":78},"A catalogue of Model Context Protocol servers and a config generator that writes the right file for each client.","servers",{"title":33,"body":80,"unit":81},"Write an AGENTS.md and see how CLAUDE.md, .cursor\u002Frules and similar files are read by each tool.","file formats",{"title":28,"body":83,"unit":84},"Compare agent frameworks and vendor SDKs by language, licence, MCP support and multi-agent features.","frameworks",{"title":34,"body":86,"unit":87},"Install, configure and update OpenClaw on your own machine or server, step by step.","current release",{"title":35,"body":89,"unit":90},"Generate llms.txt, robots.txt rules for AI crawlers and an api-catalog, and look up any bot by user agent.","bots listed",{"title":40,"body":92,"unit":93},"The OWASP risks for agents, a log of real incidents and a checklist you can tick off before launch.","incidents logged",{"title":95,"body":96,"unit":97},"API changelog","Dated changes to model APIs, SDKs and protocols, each linked to the vendor's announcement.","entries","Latest changes","All changes","How we keep it accurate",[102,105,108,111],{"title":103,"body":104},"Sourced facts.","Every price, version and flag links to the vendor page it came from, so you can check it yourself.",{"title":106,"body":107},"Dated checks.","Each page shows when its facts were last checked, and stale entries are rechecked or removed.",{"title":109,"body":110},"No paid placement.","Nobody pays to be listed, ranked higher or described more kindly.",{"title":112,"body":113},"Tools run in your browser.","Generators and calculators work locally, and what you type is not sent to a server.","About DotsAgent",{"title":116,"body":117,"home":118,"popular":119,"failed":120,"failedBody":121},"Page not found","This address doesn't match any page. It may have moved, or the link may have a typo.","Go to the home page","Popular tools","Something went wrong","The page failed to load on our side. Try again in a minute, or start from the home page.",{"guide":123,"ui":126,"guides":143},{"eyebrow":124,"moreTitle":125},"OpenClaw guide","More OpenClaw guides",{"crumb":65,"facts":127,"stars":135,"minimum":136,"stepsCount":137,"setting":138,"value":139,"why":140,"settings":141,"sources":142},{"version":128,"lts":129,"license":130,"runtime":131,"minimum":132,"port":133,"config":134},"Latest release","Extended stable","License","Runtime","Minimum host","Default port","Config file","{n} GitHub stars","{cpu} vCPU, {ram} GB RAM, {disk} MB disk","{n} steps","Setting","Value","Why it matters","Settings","Sources",{"hardening":144,"install":171,"vps":173,"docker":175,"raspberry-pi":177,"models":179,"telegram":181,"remote-access":183},{"seo":145,"title":148,"summary":149,"before":150,"steps":151,"after":170},{"title":146,"description":147},"Harden an OpenClaw gateway in 6 steps","Harden OpenClaw in 6 steps: security audit, a 64-character token, loopback bind, sandboxed tools, exec set to deny, DM pairing and vetted ClawHub skills.","Harden your OpenClaw gateway","Apply the hardened baseline from the OpenClaw docs: loopback and token auth, a sandbox, strict exec approvals and tight control over who can message the agent.","Some defaults are permissive: sandboxing is off and exec.security is full on gateway hosts. Back up ~\u002F.openclaw\u002Fopenclaw.json before you edit it.",[152,155,158,161,164,167],{"title":153,"body":154},"Run the security audit","The plain audit checks your configuration, --deep adds the extended checks, and --fix applies the fixes it can make on its own. Add --json for output that scripts can parse. Run the audit again after each step below.",{"title":156,"body":157},"Generate a strong token","Onboarding already creates a token. If you set your own, use at least 24 characters, because the audit warns on anything shorter. This command prints 64 random hex characters.",{"title":159,"body":160},"Bind to loopback with token auth","In openclaw.json, set gateway.mode to local, gateway.bind to loopback and gateway.auth.mode to token, and put the token from step 2 in gateway.auth.token. Gateway auth fails closed, so requests without a valid token are refused. Do not use lan, custom or auto on a host that faces the internet.",{"title":162,"body":163},"Sandbox tools and limit file access","Sandboxing is off by default. Turn it on with one of the supported backends (Docker, Podman, SSH, OpenShell or Crabbox) and confirm the result with openclaw sandbox explain. Then set tools.profile to messaging and tools.fs.workspaceOnly to true, and add tool groups you do not use, such as group:automation and group:runtime, to tools.deny.",{"title":165,"body":166},"Lock down shell commands","Set tools.exec.security to deny so the agent cannot run commands at all. If a workflow needs a few, switch to allowlist and keep tools.exec.ask on always, so each command waits for your approval; askFallback defaults to deny when no one answers. Leave tools.elevated.enabled at false.",{"title":168,"body":169},"Control who reaches the agent","Keep dmPolicy on pairing, set requireMention to true for groups, and set session.dmScope to per-channel-peer so senders never share a session. Skills run with the agent's privileges and OpenClaw does not block dangerous code at install time, so check each ClawHub skill's audit status before installing it and set security.installPolicy. In February 2026, researchers found hundreds of malicious skills on ClawHub.","The docs treat each gateway as a single trust boundary, not a hostile multi-tenant one. Run separate gateways for separate people or trust domains.",{"title":172},"Install OpenClaw",{"title":174},"Run OpenClaw on a VPS",{"title":176},"Run OpenClaw in Docker",{"title":178},"Run OpenClaw on a Raspberry Pi",{"title":180},"Connect models to OpenClaw",{"title":182},"Connect OpenClaw to Telegram",{"title":184},"Remote access to OpenClaw",{"common":186},{"skip":5,"menu":6,"language":7,"sections":8,"footer":9,"tool":10,"home":11,"breadcrumbs":12,"copy":13,"copied":14,"download":15},1790863351013]