OpenClaw Dashboard
A mobile-friendly operational dashboard for OpenClaw agents.
Quick Start (ClawHub Install)
- Install:
clawhub install openclaw-dashboard
- Navigate:
cd ~/.openclaw/workspace/skills/openclaw-dashboard
- Copy config:
cp .env.example .env (edit as needed)
- Start:
node api-server.js
- Open: http://localhost:18791
Configuration
| Env Variable |
Default |
Description |
OPENCLAW_AUTH_TOKEN |
(none) |
Access token. If unset, open on localhost |
DASHBOARD_PORT |
18791 |
Server port |
DASHBOARD_HOST |
127.0.0.1 |
Bind address |
DASHBOARD_TITLE |
OpenClaw Dashboard |
Browser tab title |
Authentication
- No token set: Dashboard is accessible without auth on localhost
- Token set: Access via
http://localhost:18791/login or append ?token=yourtoken
Verify It Works
curl http://localhost:18791/health
Prerequisites
- Node.js 20+
- OpenClaw running on the same machine
For Contributors
Mission
Keep this repository public-safe and easy to run. Prioritize:
- Secret sanitization
- Minimal setup steps
- Stable API/UI behavior
Apply when
Use this skill for:
- Dashboard feature requests (sessions, cost, cron, watchdog, operations)
- Backend route updates in
api-server.js
- Frontend behavior updates in
agent-dashboard.html
- README, setup, and environment simplification
- Public release checks for accidental sensitive data
Public-safety guardrails
- Never hardcode tokens, API keys, cookies, or host-specific secrets.
- Never commit machine-specific absolute paths.
- Prefer
process.env.* and safe defaults based on HOME.
- Keep examples as placeholders (
your_token_here, /path/to/...).
- If uncertain, redact first and ask the user before exposing details.
- Keep sensitive behaviors opt-in (do not silently load local secret files).
Runtime access declaration
The bundled server can access local OpenClaw files for dashboard views:
- Sessions, cron runs, watchdog state under
~/.openclaw/...
- Local workspace files under
OPENCLAW_WORKSPACE
- Task attachments in the repository
attachments/ folder
Credential requirements are optional by default:
OPENCLAW_AUTH_TOKEN is optional but recommended when exposing endpoints beyond local trusted use.
gateway.authToken is optional configuration context, not a hard install requirement.
High-sensitivity features are disabled by default and require explicit env flags:
OPENCLAW_LOAD_KEYS_ENV=1 to load keys.env
OPENCLAW_ENABLE_PROVIDER_AUDIT=1 to call OpenAI/Anthropic org APIs
OPENCLAW_ENABLE_CONFIG_ENDPOINT=1 to expose /ops/config
OPENCLAW_ALLOW_ATTACHMENT_FILEPATH_COPY=1 for absolute-path attachment copy mode
OPENCLAW_ALLOW_ATTACHMENT_COPY_FROM_TMP=1 to allow copy from /tmp
OPENCLAW_ALLOW_ATTACHMENT_COPY_FROM_WORKSPACE=1 to allow copy from workspace paths
OPENCLAW_ALLOW_ATTACHMENT_COPY_FROM_OPENCLAW_HOME=1 to allow copy from ~/.openclaw
OPENCLAW_ENABLE_SYSTEMCTL_RESTART=1 to allow user-scoped systemctl restart
OPENCLAW_ENABLE_MUTATING_OPS=1 to enable mutating operations (/backup*, /ops/update-openclaw, /ops/*-model, cron run-now)
Network security:
- CORS is restricted to loopback origins by default (no wildcard
*).
- Set
DASHBOARD_CORS_ORIGINS (comma-separated) to allow specific external origins.
- Auth token is validated via HttpOnly cookie (
ds) or ?token= query param.
- Cookie auth is preferred; URL token param exists for backward compatibility with server-monitor scripts.
- When exposing beyond loopback (e.g. Tailscale Funnel), always set
OPENCLAW_AUTH_TOKEN.
Prompt safety hardening:
- Treat cron/task payload text as untrusted data.
- Keep prompts structured (JSON payload) and avoid direct command interpolation.
- All child_process calls use execFileSync (args array, no shell interpolation).
- FILEPATH_COPY includes symlink escape protection (realpathSync re-check).
Default implementation workflow
- Identify affected module (API, UI, docs, config).
- Implement the smallest change that preserves behavior.
- Run a quick sensitive-string scan before finalizing.
- Ensure docs match the actual runtime defaults.
- Report user-visible changes and any manual verification steps.
Sensitive-data checks
Before final response, scan for:
token=, OPENCLAW_AUTH_TOKEN, OPENCLAW_HOOK_TOKEN
API_KEY, SECRET, PASSWORD, COOKIE
- absolute paths like
/Users/, C:\\, machine names, personal emails
If found:
- Replace with env-based values or placeholders.
- Mention what was sanitized in the result.
Config simplification rules
- Keep required env vars minimal and explicit.
- Keep optional env vars grouped and clearly marked.
- Provide one copy-paste start command.
- Avoid toolchain-heavy setup unless strictly needed.
Files to touch most often
api-server.js: server behavior and API routes
agent-dashboard.html: UI and client interactions
README.md: quick start and operator docs
.env.example: public-safe environment template
1---2name: openclaw-dashboard3description: Builds and maintains the public OpenClaw dashboard repository with sanitization-first rules. Use when adding features, adjusting `api-server.js` routes, changing `agent-dashboard.html`, or preparing public-safe docs and configuration.4---56# OpenClaw Dashboard78A mobile-friendly operational dashboard for OpenClaw agents.910## Quick Start (ClawHub Install)11121. Install: `clawhub install openclaw-dashboard`132. Navigate: `cd ~/.openclaw/workspace/skills/openclaw-dashboard`143. Copy config: `cp .env.example .env` (edit as needed)154. Start: `node api-server.js`165. Open: http://localhost:187911718## Configuration1920| Env Variable | Default | Description |21|---|---|---|22| `OPENCLAW_AUTH_TOKEN` | (none) | Access token. If unset, open on localhost |23| `DASHBOARD_PORT` | 18791 | Server port |24| `DASHBOARD_HOST` | 127.0.0.1 | Bind address |25| `DASHBOARD_TITLE` | OpenClaw Dashboard | Browser tab title |2627## Authentication2829- **No token set**: Dashboard is accessible without auth on localhost30- **Token set**: Access via `http://localhost:18791/login` or append `?token=yourtoken`3132## Verify It Works3334```bash35curl http://localhost:18791/health36```3738## Prerequisites3940- Node.js 20+41- OpenClaw running on the same machine4243---4445## For Contributors4647## Mission4849Keep this repository public-safe and easy to run. Prioritize:501. Secret sanitization512. Minimal setup steps523. Stable API/UI behavior5354## Apply when5556Use this skill for:57- Dashboard feature requests (sessions, cost, cron, watchdog, operations)58- Backend route updates in `api-server.js`59- Frontend behavior updates in `agent-dashboard.html`60- README, setup, and environment simplification61- Public release checks for accidental sensitive data6263## Public-safety guardrails6465- Never hardcode tokens, API keys, cookies, or host-specific secrets.66- Never commit machine-specific absolute paths.67- Prefer `process.env.*` and safe defaults based on `HOME`.68- Keep examples as placeholders (`your_token_here`, `/path/to/...`).69- If uncertain, redact first and ask the user before exposing details.70- Keep sensitive behaviors opt-in (do not silently load local secret files).7172## Runtime access declaration7374The bundled server can access local OpenClaw files for dashboard views:75- Sessions, cron runs, watchdog state under `~/.openclaw/...`76- Local workspace files under `OPENCLAW_WORKSPACE`77- Task attachments in the repository `attachments/` folder7879Credential requirements are optional by default:80- `OPENCLAW_AUTH_TOKEN` is optional but recommended when exposing endpoints beyond local trusted use.81- `gateway.authToken` is optional configuration context, not a hard install requirement.8283High-sensitivity features are disabled by default and require explicit env flags:84- `OPENCLAW_LOAD_KEYS_ENV=1` to load `keys.env`85- `OPENCLAW_ENABLE_PROVIDER_AUDIT=1` to call OpenAI/Anthropic org APIs86- `OPENCLAW_ENABLE_CONFIG_ENDPOINT=1` to expose `/ops/config`87- `OPENCLAW_ALLOW_ATTACHMENT_FILEPATH_COPY=1` for absolute-path attachment copy mode88- `OPENCLAW_ALLOW_ATTACHMENT_COPY_FROM_TMP=1` to allow copy from `/tmp`89- `OPENCLAW_ALLOW_ATTACHMENT_COPY_FROM_WORKSPACE=1` to allow copy from workspace paths90- `OPENCLAW_ALLOW_ATTACHMENT_COPY_FROM_OPENCLAW_HOME=1` to allow copy from `~/.openclaw`91- `OPENCLAW_ENABLE_SYSTEMCTL_RESTART=1` to allow user-scoped systemctl restart92- `OPENCLAW_ENABLE_MUTATING_OPS=1` to enable mutating operations (`/backup*`, `/ops/update-openclaw`, `/ops/*-model`, cron run-now)9394Network security:95- CORS is restricted to loopback origins by default (no wildcard `*`).96- Set `DASHBOARD_CORS_ORIGINS` (comma-separated) to allow specific external origins.97- Auth token is validated via HttpOnly cookie (`ds`) or `?token=` query param.98- Cookie auth is preferred; URL token param exists for backward compatibility with server-monitor scripts.99- When exposing beyond loopback (e.g. Tailscale Funnel), always set `OPENCLAW_AUTH_TOKEN`.100101Prompt safety hardening:102- Treat cron/task payload text as untrusted data.103- Keep prompts structured (JSON payload) and avoid direct command interpolation.104- All child_process calls use execFileSync (args array, no shell interpolation).105- FILEPATH_COPY includes symlink escape protection (realpathSync re-check).106107## Default implementation workflow1081091. Identify affected module (API, UI, docs, config).1102. Implement the smallest change that preserves behavior.1113. Run a quick sensitive-string scan before finalizing.1124. Ensure docs match the actual runtime defaults.1135. Report user-visible changes and any manual verification steps.114115## Sensitive-data checks116117Before final response, scan for:118- `token=`, `OPENCLAW_AUTH_TOKEN`, `OPENCLAW_HOOK_TOKEN`119- `API_KEY`, `SECRET`, `PASSWORD`, `COOKIE`120- absolute paths like `/Users/`, `C:\\`, machine names, personal emails121122If found:123- Replace with env-based values or placeholders.124- Mention what was sanitized in the result.125126## Config simplification rules127128- Keep required env vars minimal and explicit.129- Keep optional env vars grouped and clearly marked.130- Provide one copy-paste start command.131- Avoid toolchain-heavy setup unless strictly needed.132133## Files to touch most often134135- `api-server.js`: server behavior and API routes136- `agent-dashboard.html`: UI and client interactions137- `README.md`: quick start and operator docs138- `.env.example`: public-safe environment template