Security

OpenClaw security checklist

Default installs are not production. Run this before the box can read email, CRM, or files. Print this page (Save as PDF) if you want a copy — no fake gated download.

We apply these on Clawesome deployments. The longer narrative version lives in the April 2026 blog post. This page is the working list.

  1. Secrets stay out of git

    API keys, Telegram tokens, and OAuth client secrets in environment variables or a vault — never committed config, never a screenshot in Slack. Rotate anything that has already leaked.

  2. Agents do not share a blast radius

    Separate containers (or equivalent isolation). Inbox should not have a writable path into Research’s memory. Define the channels agents are allowed to use.

  3. Least privilege on tools

    Each job gets the tools it needs. The research agent does not need production file-write. The follow-through agent does not need every CRM admin scope.

  4. Hard token budgets

    A stuck loop will spend. Cap tokens per agent per hour. Alert when the cap trips. “We’ll notice the invoice” is not a control.

  5. Messaging bots are locked to you

    Telegram/WhatsApp tokens restricted to your chat or workspace. Dashboard not on the public internet. SSH by key, not password; root login off.

  6. Skills are reviewed, not starred

    Community skills are untrusted code. Read the repo, pin versions, allowlist what runs. Marketplace install-as-root is how you get a second operator you did not hire.

  7. Firewall the box

    Only 443 and SSH (ideally from your IP or a bastion). OpenClaw admin UI behind VPN or tunnel. Default cloud “open 3000 to the world” is a finding, not a setup.

  8. Backups you have restored once

    Workspace, memory, and config copied off-box on a schedule. An untested backup is a story you tell yourself.

  9. Failure is loud

    Health check on a timer. Telegram (or equivalent) when an agent dies, disk fills, or the model endpoint 401s. Silent failure is how “the AI stopped” becomes a month of missed follow-ups.

If an existing install fails this list, start with Rescue — $200 CAD rather than a full rebuild. If you are still choosing a vendor, read vs Cognio (same category, different SKU) and vs KiloClaw (hosted, not this checklist’s threat model).