AI coding tools
OpenClaw Operating Card
Operate OpenClaw as a self-hosted agent gateway with explicit channels, tools, sandboxing, credentials, health checks, and rollback.
- Format
- Reference
- Level
- Intermediate
- Audience
- Practitioner, Developer, Operator
- Owner
- Project42 Editorial
- Review cadence
- Every 30 days
- Prerequisites
- A supported Node.js and operating-system path; An approved model-provider credential; A host and channel security boundary
Treat the gateway as an operational service
OpenClaw is a self-hosted gateway that connects agent runtimes, tools, skills, plugins, and communication channels. Choose it when you are prepared to operate identities, credentials, host access, sessions, updates, and channel policy as a service.
The model sees only capabilities that survive the configured profile, allow and deny policy, sandbox, provider restrictions, channel permissions, and installed plugins. Review every layer instead of relying on one allowlist.
Install deliberately and verify the gateway boundary
Confirm current platform requirements, review installer behavior, pin an update channel where required, and run documented health checks. Bind interfaces and channel identities according to the intended threat model.
Enable only required tools, skills, plugins, and channels. Keep provider and channel credentials external to prompts and repositories, and maintain an export, update, rollback, and uninstall plan.
Task: [one agent or gateway outcome]
Scope: [host, workspace, channels, and sessions]
Permissions: [tools, plugins, sandbox, network, and identities]
Credentials: [approved secret stores and rotation owners]
Health checks: [version, doctor, gateway, and channel tests]
Verification: [observable result and audit evidence]
Recovery: [disable route/tool, restore config, rotate, rollback]Expected evidence and verification
Expected evidence includes version and installation path, effective config, enabled capabilities, identity and channel map, health results, and a tested user-boundary outcome without secret values.
If behavior or access is unexpected, disable the affected channel or tool, preserve logs safely, rotate exposed credentials, restore the last reviewed configuration, and rerun health and end-to-end checks.