Remote access to OpenClaw
Reach the dashboard of a gateway on another machine with an SSH tunnel or Tailscale, without changing the loopback bind.
Start from a gateway bound to loopback with token auth, as set out in the hardening guide.
Use an SSH tunnel
Run this on the machine you are sitting at. It maps local port 18789 to 127.0.0.1:18789 on the gateway host, so http://127.0.0.1:18789/ opens the remote dashboard. It needs only SSH access and ends when you close the terminal.
shell ssh -N -L 18789:127.0.0.1:18789 user@gateway-hostUse Tailscale Serve
Serve makes the gateway reachable from devices on your tailnet only; the public internet cannot reach it. It suits access from a phone or several machines without keeping an SSH session open.
shell openclaw gateway --tailscale serveTailscale Funnel, public with a password
Funnel publishes the gateway on the public internet, which is why OpenClaw requires password auth for it. Anyone who finds the URL can try that password, so use a long random one, and prefer Serve or SSH unless you truly need public access.
shell openclaw gateway --tailscale funnel --auth password
Funnel is the only one of these three methods that makes the gateway public. Run openclaw security audit --deep after you enable it, and turn it off when you no longer need it.