OpenClaw Maintenance Skill
OpenClaw is a self-hosted, open-source (MIT) gateway that routes AI agents across WhatsApp, Telegram, Discord, Slack, iMessage, Signal, and 15+ other channels simultaneously. It runs on macOS, Linux, or Windows.
Reference Files
| Reference |
Coverage |
| channels.md |
Per-channel setup (WhatsApp, Telegram, Discord, etc.) |
| channel_troubleshooting.md |
Per-channel failure signatures and walkthroughs |
| tools.md |
Tools inventory (profiles, groups, all built-in tools) |
| exec.md |
Exec tool: parameters, config, PATH, security, process tool |
| exec_approvals.md |
Exec approvals: allowlists, safe bins, approval flow |
| browser.md |
Browser tool: profiles, CDP, relay, SSRF, Control API |
| web_tools.md |
Web tools: Brave, Perplexity, Gemini search providers |
| pdf_tool.md |
PDF tool: native/fallback modes, config, page filtering |
| elevated.md |
Elevated mode: /elevated directives, sandbox breakout |
| lobster.md |
Lobster: typed workflow runtime with approvals |
| llm_task.md |
LLM Task: JSON-only LLM step for structured output |
| openprose.md |
OpenProse: multi-agent program runtime |
| plugins.md |
Plugins: official list, config, manifest, CLI, authoring |
| skills.md |
Skills: locations, config, ClawHub, watcher, token impact |
| providers.md |
Model provider setup |
| multi_agent.md |
Multi-agent routing |
| nodes.md |
Nodes (iOS/Android/macOS/headless) |
| security.md |
Security hardening |
| secrets.md |
Secrets management (SecretRef, vault) |
| sandboxing.md |
Sandboxing (Docker isolation) |
| config_reference.md |
Full config field reference |
| gateway_ops.md |
Gateway operations |
| remote_access.md |
Remote access, SSH, Tailscale, web dashboard |
| sessions.md |
Session management, DM isolation, lifecycle, compaction |
| hooks.md |
Hooks: internal event hooks, HTTP webhooks, authoring, CLI |
| automation.md |
Cron jobs, webhooks, Gmail Pub/Sub |
| acp_agents.md |
ACP agents: spawn external AI runtimes (Codex, Claude, etc.) |
| install.md |
Installation, updating, rollback, migration, uninstall |
| web_ui.md |
Web surfaces: Dashboard, Control UI, WebChat |
| slash_commands.md |
Chat slash commands (/new, /model, /acp, etc.) |
| platforms.md |
Platform-specific guides (macOS, iOS, Android, Linux, Windows) |
| diffs_firecrawl.md |
Diffs plugin + Firecrawl anti-bot fallback |
| subagents.md |
Sub-agents: nested spawning, thread binding, announce, tool policy |
| memory.md |
Memory system, vector search, hybrid BM25, compaction, QMD backend |
| architecture.md |
Gateway architecture, wire protocol, pairing, invariants |
| agent_runtime.md |
Agent runtime, bootstrap files, agent loop, hooks, timeouts |
| streaming.md |
Streaming + chunking: block streaming, coalescing, preview modes |
| queue.md |
Command queue: modes (steer/followup/collect), concurrency, per-session |
| model_failover.md |
Model failover, OAuth, auth profiles, cooldowns, billing disables |
| clawhub.md |
ClawHub: public skill registry, CLI commands, publish/install |
| thinking.md |
Thinking levels, verbose directives, reasoning visibility |
| polls.md |
Polls: Telegram, WhatsApp, Discord, MS Teams |
| voice.md |
Talk Mode (voice interaction) + Voice Wake (wake words) |
| presence_discovery.md |
Presence system, discovery (Bonjour/Tailscale), transports |
| gateway_internals.md |
Network model, gateway lock, health checks, doctor, logging, background exec |
| heartbeat.md |
Heartbeat: config, delivery, visibility, HEARTBEAT.md, per-agent |
| bonjour.md |
Bonjour/mDNS: TXT keys, wide-area DNS-SD, debugging, failure modes |
| pairing.md |
Gateway pairing: node approval, CLI, API, auto-approval, storage |
| tui.md |
TUI: keyboard shortcuts, slash commands, pickers, local shell, delivery |
| media.md |
Media: camera capture, images, audio/voice notes, transcription |
| channel_routing.md |
Channel routing, session keys, agent selection, Mattermost, BlueBubbles |
Quick Reference
Key Paths
| Path |
Purpose |
~/.openclaw/openclaw.json |
Main config (JSON5) |
~/.openclaw/.env |
Global env fallback |
~/.openclaw/workspace |
Default agent workspace |
~/.openclaw/agents/<id>/ |
Per-agent state + sessions |
~/.openclaw/skills/ |
Managed/local skills |
~/.openclaw/agents/<id>/qmd/ |
QMD memory backend state |
~/.openclaw/agents/<id>/agent/auth-profiles.json |
Auth profiles + OAuth tokens |
OPENCLAW_CONFIG_PATH |
Override config location |
OPENCLAW_STATE_DIR |
Override state directory |
OPENCLAW_HOME |
Override home directory |
Essential Commands
openclaw status # Overall status
openclaw gateway status # Gateway daemon status
openclaw gateway status --deep # Deep scan including system services
openclaw doctor # Diagnose config/service issues
openclaw doctor --fix # Auto-fix safe issues
openclaw logs --follow # Tail gateway logs
openclaw channels status --probe # Channel health check
openclaw security audit # Security posture check
openclaw security audit --fix # Auto-fix security issues
openclaw update # Self-update
openclaw dashboard # Open Control UI in browser
openclaw tui # Terminal UI (interactive REPL, auto-infers agent from cwd)
openclaw agent # Direct agent interaction via CLI
openclaw health # Health check
openclaw usage # Usage tracking
openclaw config validate # Validate config file
openclaw config file # Print active config path
openclaw sessions cleanup # Session disk cleanup
openclaw agents bindings # Agent-channel bindings
openclaw agents bind # Bind agent to account
openclaw agents unbind # Unbind agent
openclaw update --dry-run # Preview update
openclaw backup create # Create local state archive
openclaw backup verify # Verify backup integrity
openclaw system presence # View connected clients/nodes
openclaw system heartbeat last # Last heartbeat info
openclaw system heartbeat now # Trigger heartbeat immediately
openclaw memory search <query> # CLI memory search
openclaw docs <query> # Search OpenClaw docs
openclaw nodes pending # List pending pairing requests
openclaw nodes approve <id> # Approve node pairing
openclaw health --json # Full health snapshot (JSON)
openclaw message send --media <p> # Send media message
Default Gateway
- Bind:
127.0.0.1:18789 (loopback)
- Dashboard:
http://127.0.0.1:18789/
- Protocol: WebSocket (JSON text frames)
Core Workflow
Diagnosing Issues
Always follow this command ladder:
openclaw status — quick overview
openclaw gateway status — daemon running? RPC probe ok?
openclaw logs --follow — watch for errors
openclaw doctor — config/service diagnostics
openclaw channels status --probe — per-channel health
Starting / Restarting Gateway
# Foreground with verbose logging
openclaw gateway --port 18789 --verbose
# Force-kill existing listener then start
openclaw gateway --force
# Service management (launchd on macOS, systemd on Linux)
openclaw gateway install
openclaw gateway start
openclaw gateway stop
openclaw gateway restart
Configuration
Edit config via any method:
# Interactive wizard
openclaw onboard # Full setup
openclaw configure # Config wizard
# CLI one-liners
openclaw config get <path> # Read value
openclaw config set <path> <value> # Set value (JSON5 or raw string)
openclaw config unset <path> # Remove value
# Direct edit
# Edit ~/.openclaw/openclaw.json (JSON5 format)
# Gateway hot-reloads on save (if gateway.reload.mode != "off")
Minimal config example:
{
agents: { defaults: { workspace: "~/.openclaw/workspace" } },
channels: { whatsapp: { allowFrom: ["+15555550123"] } },
}
Channel Setup
For detailed per-channel setup, see references/channels.md.
For per-channel troubleshooting (failure signatures, setup walkthroughs), see references/channel_troubleshooting.md.
For plugins adding new channels (Matrix, Nostr, MS Teams, etc.), see references/plugins.md.
Quick channel add:
# Interactive wizard
openclaw channels add
# Non-interactive
openclaw channels add --channel telegram --account default --name "My Bot" --token $BOT_TOKEN
openclaw channels login --channel whatsapp # QR pairing for WhatsApp
openclaw channels status --probe # Verify
Model Provider Setup
For detailed provider setup, see references/providers.md.
# Set default model
openclaw models set anthropic/claude-sonnet-4-5
# List available models
openclaw models list --all
# Check auth/token status
openclaw models status --probe
# Add auth interactively
openclaw models auth add
Config example:
{
agents: {
defaults: {
model: {
primary: "anthropic/claude-sonnet-4-5",
fallbacks: ["openai/gpt-5.2"],
},
},
},
}
Multi-Agent Routing
For detailed multi-agent config, see references/multi_agent.md.
openclaw agents add <id> # Create agent
openclaw agents list --bindings # Show agent-channel bindings
openclaw agents delete <id> # Remove agent
Nodes (iOS / Android / macOS / Headless)
For detailed node setup, see references/nodes.md.
openclaw nodes status # List connected nodes
openclaw nodes describe --node <id> # Node capabilities
openclaw devices list # Pending device approvals
openclaw devices approve <requestId> # Approve a device
openclaw node run --host <host> --port 18789 # Start headless node host
Security
For detailed security hardening, see references/security.md.
For secrets management (SecretRef, vault integration), see references/secrets.md.
For sandboxing (Docker isolation for tools), see references/sandboxing.md.
For full config field reference, see references/config_reference.md.
For remote access (SSH, Tailscale, VPN), see references/remote_access.md.
openclaw security audit # Check posture
openclaw security audit --deep # Live gateway probe
openclaw security audit --fix # Auto-fix safe issues
openclaw secrets reload # Re-resolve secret refs
openclaw secrets audit # Scan for plaintext leaks
Update / Uninstall
For detailed installation, updating, rollback, and migration guide, see references/install.md.
# Install (recommended)
curl -fsSL https://openclaw.ai/install.sh | bash
# Update
openclaw update # Self-update command
# Or: npm install -g openclaw@latest
openclaw doctor # Run after update to apply migrations
# Uninstall
openclaw uninstall
Tools Reference
For detailed per-tool documentation, see references/tools.md.
For specific tools, see:
- references/exec.md — Exec tool deep-dive
- references/exec_approvals.md — Exec approvals and allowlists
- references/browser.md — Browser automation deep-dive
- references/web_tools.md — Web search/fetch with multiple providers
- references/lobster.md — Lobster workflow runtime
- references/llm_task.md — LLM Task for structured JSON output
- references/openprose.md — OpenProse multi-agent programs
- references/plugins.md — Plugin system (install, author, distribute)
- references/skills.md — Skills system (load, config, ClawHub)
For ACP agents (Codex, Claude Code, Gemini CLI, etc.), see references/acp_agents.md.
For Diffs plugin and Firecrawl anti-bot fallback, see references/diffs_firecrawl.md.
For chat slash commands (/new, /model, /acp, etc.), see references/slash_commands.md.
For advanced internals and features, see:
- references/thinking.md — Thinking levels (/think, /verbose, /reasoning)
- references/polls.md — Polls (Telegram, WhatsApp, Discord, MS Teams)
- references/voice.md — Talk Mode and Voice Wake
- references/architecture.md — Gateway architecture and wire protocol
- references/agent_runtime.md — Agent runtime and loop details
- references/queue.md — Command queue system
- references/model_failover.md — Model failover and OAuth
- references/clawhub.md — ClawHub skill registry
- references/presence_discovery.md — Presence and discovery
- references/streaming.md — Streaming and chunking
- references/gateway_internals.md — Gateway internals
- references/heartbeat.md — Heartbeat system
- references/bonjour.md — Bonjour/mDNS discovery details
- references/pairing.md — Gateway node pairing
- references/tui.md — Terminal UI (TUI)
- references/media.md — Media (camera, images, audio)
- references/channel_routing.md — Channel routing and session keys
Tool profiles: minimal, coding, messaging, full (default).
Tool groups (for allow/deny):
group:runtime — exec, bash, process
group:fs — read, write, edit, apply_patch
group:sessions — sessions_list/history/send/spawn, session_status
group:memory — memory_search, memory_get
group:web — web_search, web_fetch
group:ui — browser, canvas
group:automation — cron, gateway
group:messaging — message
group:nodes — nodes
group:openclaw — all built-in OpenClaw tools (excludes provider plugins)
Common Failure Signatures
| Error |
Cause |
Fix |
refusing to bind gateway ... without auth |
Non-loopback bind without token |
Set gateway.auth.token or gateway.auth.password |
another gateway instance is already listening / EADDRINUSE |
Port conflict |
openclaw gateway --force or change port |
Gateway start blocked: set gateway.mode=local |
Local mode not enabled |
Set gateway.mode="local" |
unauthorized / reconnect loop |
Token/password mismatch |
Check OPENCLAW_GATEWAY_TOKEN or config auth |
device identity required |
Missing device auth |
Ensure client completes connect.challenge flow |
| No replies from bot |
Pairing/allowlist/mention gating |
Check openclaw pairing list, DM policy, mention patterns |
Embedding provider authentication failed (401) |
.env has placeholder API key (e.g. your-jina-api-key-here) |
Replace with real API key in ~/.openclaw/.env, restart Gateway |
config change requires gateway restart (plugins.*) |
Plugin config changes can't hot-reload |
Full openclaw gateway restart or launchctl kickstart -k |
Bootstrap failed: 5: Input/output error |
LaunchAgent plist in stale/stuck state |
openclaw gateway install then launchctl kickstart -k gui/$(id -u)/ai.openclaw.gateway |
Missing env var "X" referenced at config path: ... |
.env missing or variable not defined |
Add variable to ~/.openclaw/.env and restart Gateway |
Environment Variables
| Variable |
Purpose |
OPENCLAW_GATEWAY_TOKEN |
Gateway auth token |
OPENCLAW_GATEWAY_PASSWORD |
Gateway auth password |
OPENCLAW_GATEWAY_PORT |
Override gateway port |
OPENCLAW_CONFIG_PATH |
Override config file path |
OPENCLAW_STATE_DIR |
Override state directory |
OPENCLAW_HOME |
Override home directory |
OPENCLAW_LOAD_SHELL_ENV |
Import shell env (set to 1) |
OPENCLAW_VERBOSE |
Verbose logging |
OPENCLAW_LOG_FILE |
File logging path |
OPENCLAW_LOG_LEVEL |
Log level control |
OPENCLAW_SHELL |
Set by OpenClaw in exec/acp/tui runtimes |
OPENCLAW_THEME |
Terminal theme override (light or dark) |
OPENCLAW_BIND_MOUNT_OPTIONS |
Override bind mount suffix for Podman SELinux (e.g., :z) |
BRAVE_API_KEY |
For web_search tool |
FIRECRAWL_API_KEY |
For Firecrawl anti-bot fallback |
ELEVENLABS_API_KEY |
For Talk Mode TTS |
ELEVENLABS_VOICE_ID |
Default voice for Talk Mode |
CLAWHUB_TOKEN |
ClawHub API token for CI/automation |
CLAWHUB_WORKDIR |
ClawHub working directory override |
CLAWHUB_REGISTRY |
ClawHub registry API URL override |
OLLAMA_API_KEY |
For Ollama embeddings provider |
1---2name: openclaw-guide-maintenance3description: Comprehensive guide for installing, configuring, operating, and troubleshooting OpenClaw — a self-hosted, multi-channel AI agent gateway. Use when the user asks about OpenClaw setup, configuration, channel management (WhatsApp/Telegram/Discord/Slack/iMessage/etc.), model provider setup, Gateway operations, multi-agent routing, security hardening, troubleshooting, or any maintenance task related to their local OpenClaw installation. Also use when encountering errors from `openclaw` CLI commands or the Gateway daemon.4---56# OpenClaw Maintenance Skill78OpenClaw is a self-hosted, open-source (MIT) gateway that routes AI agents across WhatsApp, Telegram, Discord, Slack, iMessage, Signal, and 15+ other channels simultaneously. It runs on macOS, Linux, or Windows.910## Reference Files1112| Reference | Coverage |13|---|---|14| [channels.md](references/channels.md) | Per-channel setup (WhatsApp, Telegram, Discord, etc.) |15| [channel_troubleshooting.md](references/channel_troubleshooting.md) | Per-channel failure signatures and walkthroughs |16| [tools.md](references/tools.md) | Tools inventory (profiles, groups, all built-in tools) |17| [exec.md](references/exec.md) | Exec tool: parameters, config, PATH, security, process tool |18| [exec_approvals.md](references/exec_approvals.md) | Exec approvals: allowlists, safe bins, approval flow |19| [browser.md](references/browser.md) | Browser tool: profiles, CDP, relay, SSRF, Control API |20| [web_tools.md](references/web_tools.md) | Web tools: Brave, Perplexity, Gemini search providers |21| [pdf_tool.md](references/pdf_tool.md) | PDF tool: native/fallback modes, config, page filtering |22| [elevated.md](references/elevated.md) | Elevated mode: /elevated directives, sandbox breakout |23| [lobster.md](references/lobster.md) | Lobster: typed workflow runtime with approvals |24| [llm_task.md](references/llm_task.md) | LLM Task: JSON-only LLM step for structured output |25| [openprose.md](references/openprose.md) | OpenProse: multi-agent program runtime |26| [plugins.md](references/plugins.md) | Plugins: official list, config, manifest, CLI, authoring |27| [skills.md](references/skills.md) | Skills: locations, config, ClawHub, watcher, token impact |28| [providers.md](references/providers.md) | Model provider setup |29| [multi_agent.md](references/multi_agent.md) | Multi-agent routing |30| [nodes.md](references/nodes.md) | Nodes (iOS/Android/macOS/headless) |31| [security.md](references/security.md) | Security hardening |32| [secrets.md](references/secrets.md) | Secrets management (SecretRef, vault) |33| [sandboxing.md](references/sandboxing.md) | Sandboxing (Docker isolation) |34| [config_reference.md](references/config_reference.md) | Full config field reference |35| [gateway_ops.md](references/gateway_ops.md) | Gateway operations |36| [remote_access.md](references/remote_access.md) | Remote access, SSH, Tailscale, web dashboard |37| [sessions.md](references/sessions.md) | Session management, DM isolation, lifecycle, compaction |38| [hooks.md](references/hooks.md) | Hooks: internal event hooks, HTTP webhooks, authoring, CLI |39| [automation.md](references/automation.md) | Cron jobs, webhooks, Gmail Pub/Sub |40| [acp_agents.md](references/acp_agents.md) | ACP agents: spawn external AI runtimes (Codex, Claude, etc.) |41| [install.md](references/install.md) | Installation, updating, rollback, migration, uninstall |42| [web_ui.md](references/web_ui.md) | Web surfaces: Dashboard, Control UI, WebChat |43| [slash_commands.md](references/slash_commands.md) | Chat slash commands (/new, /model, /acp, etc.) |44| [platforms.md](references/platforms.md) | Platform-specific guides (macOS, iOS, Android, Linux, Windows) |45| [diffs_firecrawl.md](references/diffs_firecrawl.md) | Diffs plugin + Firecrawl anti-bot fallback |46| [subagents.md](references/subagents.md) | Sub-agents: nested spawning, thread binding, announce, tool policy |47| [memory.md](references/memory.md) | Memory system, vector search, hybrid BM25, compaction, QMD backend |48| [architecture.md](references/architecture.md) | Gateway architecture, wire protocol, pairing, invariants |49| [agent_runtime.md](references/agent_runtime.md) | Agent runtime, bootstrap files, agent loop, hooks, timeouts |50| [streaming.md](references/streaming.md) | Streaming + chunking: block streaming, coalescing, preview modes |51| [queue.md](references/queue.md) | Command queue: modes (steer/followup/collect), concurrency, per-session |52| [model_failover.md](references/model_failover.md) | Model failover, OAuth, auth profiles, cooldowns, billing disables |53| [clawhub.md](references/clawhub.md) | ClawHub: public skill registry, CLI commands, publish/install |54| [thinking.md](references/thinking.md) | Thinking levels, verbose directives, reasoning visibility |55| [polls.md](references/polls.md) | Polls: Telegram, WhatsApp, Discord, MS Teams |56| [voice.md](references/voice.md) | Talk Mode (voice interaction) + Voice Wake (wake words) |57| [presence_discovery.md](references/presence_discovery.md) | Presence system, discovery (Bonjour/Tailscale), transports |58| [gateway_internals.md](references/gateway_internals.md) | Network model, gateway lock, health checks, doctor, logging, background exec |59| [heartbeat.md](references/heartbeat.md) | Heartbeat: config, delivery, visibility, HEARTBEAT.md, per-agent |60| [bonjour.md](references/bonjour.md) | Bonjour/mDNS: TXT keys, wide-area DNS-SD, debugging, failure modes |61| [pairing.md](references/pairing.md) | Gateway pairing: node approval, CLI, API, auto-approval, storage |62| [tui.md](references/tui.md) | TUI: keyboard shortcuts, slash commands, pickers, local shell, delivery |63| [media.md](references/media.md) | Media: camera capture, images, audio/voice notes, transcription |64| [channel_routing.md](references/channel_routing.md) | Channel routing, session keys, agent selection, Mattermost, BlueBubbles |6566## Quick Reference6768### Key Paths6970| Path | Purpose |71|---|---|72| `~/.openclaw/openclaw.json` | Main config (JSON5) |73| `~/.openclaw/.env` | Global env fallback |74| `~/.openclaw/workspace` | Default agent workspace |75| `~/.openclaw/agents/<id>/` | Per-agent state + sessions |76| `~/.openclaw/skills/` | Managed/local skills |77| `~/.openclaw/agents/<id>/qmd/` | QMD memory backend state |78| `~/.openclaw/agents/<id>/agent/auth-profiles.json` | Auth profiles + OAuth tokens |79| `OPENCLAW_CONFIG_PATH` | Override config location |80| `OPENCLAW_STATE_DIR` | Override state directory |81| `OPENCLAW_HOME` | Override home directory |8283### Essential Commands8485```86openclaw status # Overall status87openclaw gateway status # Gateway daemon status88openclaw gateway status --deep # Deep scan including system services89openclaw doctor # Diagnose config/service issues90openclaw doctor --fix # Auto-fix safe issues91openclaw logs --follow # Tail gateway logs92openclaw channels status --probe # Channel health check93openclaw security audit # Security posture check94openclaw security audit --fix # Auto-fix security issues95openclaw update # Self-update96openclaw dashboard # Open Control UI in browser97openclaw tui # Terminal UI (interactive REPL, auto-infers agent from cwd)98openclaw agent # Direct agent interaction via CLI99openclaw health # Health check100openclaw usage # Usage tracking101openclaw config validate # Validate config file102openclaw config file # Print active config path103openclaw sessions cleanup # Session disk cleanup104openclaw agents bindings # Agent-channel bindings105openclaw agents bind # Bind agent to account106openclaw agents unbind # Unbind agent107openclaw update --dry-run # Preview update108openclaw backup create # Create local state archive109openclaw backup verify # Verify backup integrity110openclaw system presence # View connected clients/nodes111openclaw system heartbeat last # Last heartbeat info112openclaw system heartbeat now # Trigger heartbeat immediately113openclaw memory search <query> # CLI memory search114openclaw docs <query> # Search OpenClaw docs115openclaw nodes pending # List pending pairing requests116openclaw nodes approve <id> # Approve node pairing117openclaw health --json # Full health snapshot (JSON)118openclaw message send --media <p> # Send media message119```120121### Default Gateway122123- Bind: `127.0.0.1:18789` (loopback)124- Dashboard: `http://127.0.0.1:18789/`125- Protocol: WebSocket (JSON text frames)126127## Core Workflow128129### Diagnosing Issues130131Always follow this command ladder:1321331. `openclaw status` — quick overview1342. `openclaw gateway status` — daemon running? RPC probe ok?1353. `openclaw logs --follow` — watch for errors1364. `openclaw doctor` — config/service diagnostics1375. `openclaw channels status --probe` — per-channel health138139### Starting / Restarting Gateway140141```bash142# Foreground with verbose logging143openclaw gateway --port 18789 --verbose144145# Force-kill existing listener then start146openclaw gateway --force147148# Service management (launchd on macOS, systemd on Linux)149openclaw gateway install150openclaw gateway start151openclaw gateway stop152openclaw gateway restart153```154155### Configuration156157Edit config via any method:158159```bash160# Interactive wizard161openclaw onboard # Full setup162openclaw configure # Config wizard163164# CLI one-liners165openclaw config get <path> # Read value166openclaw config set <path> <value> # Set value (JSON5 or raw string)167openclaw config unset <path> # Remove value168169# Direct edit170# Edit ~/.openclaw/openclaw.json (JSON5 format)171# Gateway hot-reloads on save (if gateway.reload.mode != "off")172```173174Minimal config example:175176```json5177{178 agents: { defaults: { workspace: "~/.openclaw/workspace" } },179 channels: { whatsapp: { allowFrom: ["+15555550123"] } },180}181```182183### Channel Setup184185For detailed per-channel setup, see [references/channels.md](references/channels.md).186For per-channel troubleshooting (failure signatures, setup walkthroughs), see [references/channel_troubleshooting.md](references/channel_troubleshooting.md).187For plugins adding new channels (Matrix, Nostr, MS Teams, etc.), see [references/plugins.md](references/plugins.md).188189Quick channel add:190191```bash192# Interactive wizard193openclaw channels add194195# Non-interactive196openclaw channels add --channel telegram --account default --name "My Bot" --token $BOT_TOKEN197openclaw channels login --channel whatsapp # QR pairing for WhatsApp198openclaw channels status --probe # Verify199```200201### Model Provider Setup202203For detailed provider setup, see [references/providers.md](references/providers.md).204205```bash206# Set default model207openclaw models set anthropic/claude-sonnet-4-5208209# List available models210openclaw models list --all211212# Check auth/token status213openclaw models status --probe214215# Add auth interactively216openclaw models auth add217```218219Config example:220221```json5222{223 agents: {224 defaults: {225 model: {226 primary: "anthropic/claude-sonnet-4-5",227 fallbacks: ["openai/gpt-5.2"],228 },229 },230 },231}232```233234### Multi-Agent Routing235236For detailed multi-agent config, see [references/multi_agent.md](references/multi_agent.md).237238```bash239openclaw agents add <id> # Create agent240openclaw agents list --bindings # Show agent-channel bindings241openclaw agents delete <id> # Remove agent242```243244### Nodes (iOS / Android / macOS / Headless)245246For detailed node setup, see [references/nodes.md](references/nodes.md).247248```bash249openclaw nodes status # List connected nodes250openclaw nodes describe --node <id> # Node capabilities251openclaw devices list # Pending device approvals252openclaw devices approve <requestId> # Approve a device253openclaw node run --host <host> --port 18789 # Start headless node host254```255256### Security257258For detailed security hardening, see [references/security.md](references/security.md).259For secrets management (SecretRef, vault integration), see [references/secrets.md](references/secrets.md).260For sandboxing (Docker isolation for tools), see [references/sandboxing.md](references/sandboxing.md).261For full config field reference, see [references/config_reference.md](references/config_reference.md).262For remote access (SSH, Tailscale, VPN), see [references/remote_access.md](references/remote_access.md).263264```bash265openclaw security audit # Check posture266openclaw security audit --deep # Live gateway probe267openclaw security audit --fix # Auto-fix safe issues268openclaw secrets reload # Re-resolve secret refs269openclaw secrets audit # Scan for plaintext leaks270```271272### Update / Uninstall273274For detailed installation, updating, rollback, and migration guide, see [references/install.md](references/install.md).275276```bash277# Install (recommended)278curl -fsSL https://openclaw.ai/install.sh | bash279280# Update281openclaw update # Self-update command282# Or: npm install -g openclaw@latest283openclaw doctor # Run after update to apply migrations284285# Uninstall286openclaw uninstall287```288289## Tools Reference290291For detailed per-tool documentation, see [references/tools.md](references/tools.md).292293For specific tools, see:294- [references/exec.md](references/exec.md) — Exec tool deep-dive295- [references/exec_approvals.md](references/exec_approvals.md) — Exec approvals and allowlists296- [references/browser.md](references/browser.md) — Browser automation deep-dive297- [references/web_tools.md](references/web_tools.md) — Web search/fetch with multiple providers298- [references/lobster.md](references/lobster.md) — Lobster workflow runtime299- [references/llm_task.md](references/llm_task.md) — LLM Task for structured JSON output300- [references/openprose.md](references/openprose.md) — OpenProse multi-agent programs301- [references/plugins.md](references/plugins.md) — Plugin system (install, author, distribute)302- [references/skills.md](references/skills.md) — Skills system (load, config, ClawHub)303304For ACP agents (Codex, Claude Code, Gemini CLI, etc.), see [references/acp_agents.md](references/acp_agents.md).305For Diffs plugin and Firecrawl anti-bot fallback, see [references/diffs_firecrawl.md](references/diffs_firecrawl.md).306For chat slash commands (/new, /model, /acp, etc.), see [references/slash_commands.md](references/slash_commands.md).307308For advanced internals and features, see:309- [references/thinking.md](references/thinking.md) — Thinking levels (/think, /verbose, /reasoning)310- [references/polls.md](references/polls.md) — Polls (Telegram, WhatsApp, Discord, MS Teams)311- [references/voice.md](references/voice.md) — Talk Mode and Voice Wake312- [references/architecture.md](references/architecture.md) — Gateway architecture and wire protocol313- [references/agent_runtime.md](references/agent_runtime.md) — Agent runtime and loop details314- [references/queue.md](references/queue.md) — Command queue system315- [references/model_failover.md](references/model_failover.md) — Model failover and OAuth316- [references/clawhub.md](references/clawhub.md) — ClawHub skill registry317- [references/presence_discovery.md](references/presence_discovery.md) — Presence and discovery318- [references/streaming.md](references/streaming.md) — Streaming and chunking319- [references/gateway_internals.md](references/gateway_internals.md) — Gateway internals320- [references/heartbeat.md](references/heartbeat.md) — Heartbeat system321- [references/bonjour.md](references/bonjour.md) — Bonjour/mDNS discovery details322- [references/pairing.md](references/pairing.md) — Gateway node pairing323- [references/tui.md](references/tui.md) — Terminal UI (TUI)324- [references/media.md](references/media.md) — Media (camera, images, audio)325- [references/channel_routing.md](references/channel_routing.md) — Channel routing and session keys326327**Tool profiles**: `minimal`, `coding`, `messaging`, `full` (default).328329**Tool groups** (for allow/deny):330- `group:runtime` — exec, bash, process331- `group:fs` — read, write, edit, apply_patch332- `group:sessions` — sessions_list/history/send/spawn, session_status333- `group:memory` — memory_search, memory_get334- `group:web` — web_search, web_fetch335- `group:ui` — browser, canvas336- `group:automation` — cron, gateway337- `group:messaging` — message338- `group:nodes` — nodes339- `group:openclaw` — all built-in OpenClaw tools (excludes provider plugins)340341## Common Failure Signatures342343| Error | Cause | Fix |344|---|---|---|345| `refusing to bind gateway ... without auth` | Non-loopback bind without token | Set `gateway.auth.token` or `gateway.auth.password` |346| `another gateway instance is already listening` / `EADDRINUSE` | Port conflict | `openclaw gateway --force` or change port |347| `Gateway start blocked: set gateway.mode=local` | Local mode not enabled | Set `gateway.mode="local"` |348| `unauthorized` / reconnect loop | Token/password mismatch | Check `OPENCLAW_GATEWAY_TOKEN` or config auth |349| `device identity required` | Missing device auth | Ensure client completes connect.challenge flow |350| No replies from bot | Pairing/allowlist/mention gating | Check `openclaw pairing list`, DM policy, mention patterns |351| `Embedding provider authentication failed (401)` | `.env` has placeholder API key (e.g. `your-jina-api-key-here`) | Replace with real API key in `~/.openclaw/.env`, restart Gateway |352| `config change requires gateway restart (plugins.*)` | Plugin config changes can't hot-reload | Full `openclaw gateway restart` or `launchctl kickstart -k` |353| `Bootstrap failed: 5: Input/output error` | LaunchAgent plist in stale/stuck state | `openclaw gateway install` then `launchctl kickstart -k gui/$(id -u)/ai.openclaw.gateway` |354| `Missing env var "X" referenced at config path: ...` | `.env` missing or variable not defined | Add variable to `~/.openclaw/.env` and restart Gateway |355356## Environment Variables357358| Variable | Purpose |359|---|---|360| `OPENCLAW_GATEWAY_TOKEN` | Gateway auth token |361| `OPENCLAW_GATEWAY_PASSWORD` | Gateway auth password |362| `OPENCLAW_GATEWAY_PORT` | Override gateway port |363| `OPENCLAW_CONFIG_PATH` | Override config file path |364| `OPENCLAW_STATE_DIR` | Override state directory |365| `OPENCLAW_HOME` | Override home directory |366| `OPENCLAW_LOAD_SHELL_ENV` | Import shell env (set to `1`) |367| `OPENCLAW_VERBOSE` | Verbose logging |368| `OPENCLAW_LOG_FILE` | File logging path |369| `OPENCLAW_LOG_LEVEL` | Log level control |370| `OPENCLAW_SHELL` | Set by OpenClaw in exec/acp/tui runtimes |371| `OPENCLAW_THEME` | Terminal theme override (`light` or `dark`) |372| `OPENCLAW_BIND_MOUNT_OPTIONS` | Override bind mount suffix for Podman SELinux (e.g., `:z`) |373| `BRAVE_API_KEY` | For web_search tool |374| `FIRECRAWL_API_KEY` | For Firecrawl anti-bot fallback |375| `ELEVENLABS_API_KEY` | For Talk Mode TTS |376| `ELEVENLABS_VOICE_ID` | Default voice for Talk Mode |377| `CLAWHUB_TOKEN` | ClawHub API token for CI/automation |378| `CLAWHUB_WORKDIR` | ClawHub working directory override |379| `CLAWHUB_REGISTRY` | ClawHub registry API URL override |380| `OLLAMA_API_KEY` | For Ollama embeddings provider |