OpenClaw security checklist
Default installs are not production. Run this before the box can read email, CRM, or files. Print this page (Save as PDF) if you want a copy — no fake gated download.
We apply these on Clawesome deployments. The longer narrative version lives in the April 2026 blog post. This page is the working list.
-
Secrets stay out of git
API keys, Telegram tokens, and OAuth client secrets in environment variables or a vault — never committed config, never a screenshot in Slack. Rotate anything that has already leaked.
-
Agents do not share a blast radius
Separate containers (or equivalent isolation). Inbox should not have a writable path into Research’s memory. Define the channels agents are allowed to use.
-
Least privilege on tools
Each job gets the tools it needs. The research agent does not need production file-write. The follow-through agent does not need every CRM admin scope.
-
Hard token budgets
A stuck loop will spend. Cap tokens per agent per hour. Alert when the cap trips. “We’ll notice the invoice” is not a control.
-
Messaging bots are locked to you
Telegram/WhatsApp tokens restricted to your chat or workspace. Dashboard not on the public internet. SSH by key, not password; root login off.
-
Skills are reviewed, not starred
Community skills are untrusted code. Read the repo, pin versions, allowlist what runs. Marketplace install-as-root is how you get a second operator you did not hire.
-
Firewall the box
Only 443 and SSH (ideally from your IP or a bastion). OpenClaw admin UI behind VPN or tunnel. Default cloud “open 3000 to the world” is a finding, not a setup.
-
Backups you have restored once
Workspace, memory, and config copied off-box on a schedule. An untested backup is a story you tell yourself.
-
Failure is loud
Health check on a timer. Telegram (or equivalent) when an agent dies, disk fills, or the model endpoint 401s. Silent failure is how “the AI stopped” becomes a month of missed follow-ups.
If an existing install fails this list, start with Rescue — $200 CAD rather than a full rebuild. If you are still choosing a vendor, read vs Cognio (same category, different SKU) and vs KiloClaw (hosted, not this checklist’s threat model).