Secret Manager
A secure way to manage API keys for OpenClaw using the system keyring.
- macOS: Uses Keychain Access via
securitycommand - Linux: Uses GNOME Keyring via
secret-tool(libsecret)
This skill provides a secret-manager CLI that:
- Stores API keys securely in the OS keyring.
- Injects them into your
auth-profiles.json. - (Linux only) Propagates them to
systemduser environment. - (Linux only) Restarts the OpenClaw Gateway service inside your Distrobox container.
Installation
macOS (no extra dependencies)
macOS Keychain is built-in. No installation needed.
Linux
Ensure you have the dependencies:
- Debian/Ubuntu:
sudo apt install libsecret-tools - Fedora:
sudo dnf install libsecret - Arch:
sudo pacman -S libsecret
Copy the script to your path or run it directly.
macOS Usage
# Store a key
security add-generic-password -a "openclaw" -s "OPENAI_API_KEY" -w "sk-xxx" -U
# Retrieve a key
security find-generic-password -a "openclaw" -s "OPENAI_API_KEY" -w
# Delete a key
security delete-generic-password -a "openclaw" -s "OPENAI_API_KEY"
# List all OpenClaw keys
security dump-keychain | grep -A5 "openclaw"
Configuration
The script uses default paths that work for most OpenClaw installations, but you can override them with environment variables:
| Variable | Description | Default |
|---|---|---|
OPENCLAW_CONTAINER |
Name of the Distrobox container (Linux only) | clawdbot |
OPENCLAW_HOME |
Path to OpenClaw config directory | ~/.openclaw |
SECRETS_ENV_FILE |
Path to an optional .env file to source | ~/.config/openclaw/secrets.env |
KEYRING_BACKEND |
Force backend: keychain (macOS) or libsecret (Linux) |
auto-detect |
Usage
List all configured keys:
secret-manager list
Set a key (interactive prompt):
secret-manager OPENAI_API_KEY
# (Paste key when prompted)
Set a key (direct):
secret-manager DISCORD_BOT_TOKEN "my-token-value"
Supported Keys:
OPENAI_API_KEYGEMINI_API_KEYDISCORD_BOT_TOKENGATEWAY_AUTH_TOKENOLLAMA_API_KEYGIPHY_API_KEYGOOGLE_PLACES_API_KEYLINKEDIN_LI_ATLINKEDIN_JSESSIONID