| Webhook endpoints | Unauthorized triggers | Unintended actions |
| AI model access | Prompt injection via untrusted input | Manipulated behavior |
---
Securing API Keys
Use Environment Variables
# Never put keys directly in config.yaml
export OPENCLAW_API_KEY="sk-your-key-here"
export OPENCLAW_TELEGRAM_TOKEN="your-token"
Use a Secrets Manager
secrets:
provider: env # env, vault, aws-ssm, 1password
# provider: vault
# vault_addr: https://vault.example.com
# vault_token: hvs.your-token
Rotate Keys Regularly
# Check when keys were last rotated
openclaw security audit --keys
# Output:
# API Key (OpenAI): Last rotated 45 days ago ⚠ Rotate soon
# Telegram Token: Last rotated 12 days ago ✔
# Webhook Secret: Last rotated 90 days ago ⚠ Rotate now
---
Securing the Agent Process
Run as Non-Root User
# Create a dedicated user
sudo useradd -r -s /bin/false openclaw
sudo chown -R openclaw:openclaw ~/.openclaw
# Run as that user
sudo -u openclaw openclaw start
File Permissions
chmod 600 ~/.openclaw/config.yaml # Owner read/write only
chmod 600 ~/.openclaw/memory.db # Owner read/write only
chmod 700 ~/.openclaw/skills/ # Owner full access only
Firewall Rules
Only expose necessary ports:
# Allow only webhook port from specific IPs
sudo ufw allow from 140.82.112.0/20 to any port 3385 # GitHub webhooks
sudo ufw deny 3385 # Block all other
---
Skill Security
Review Permissions
Before installing any skill, review its permissions:
openclaw skills info suspicious-skill
| Permission | Risk Level | Questions to Ask |
| network | Medium | What URLs does it access? |
| filesystem | High | What files does it read/write? |
| shell | Critical | What commands does it execute? |
| memory | Low | What data does it store? |
Skill Sandboxing
security:
skill_sandbox:
enabled: true
network:
allowed_domains:
- "api.openweathermap.org"
- "api.github.com"
filesystem:
allowed_paths:
- "~/.openclaw/skills/*/data/"
denied_paths:
- "/etc/"
- "/root/"
shell:
allowed: false # Block all shell access
Audit Installed Skills
openclaw security audit --skills
---
Network Security
HTTPS for All External Communication
security:
require_https: true # Block non-HTTPS API calls
tls:
cert: /etc/ssl/certs/openclaw.pem
key: /etc/ssl/private/openclaw.key
Webhook Security
webhooks:
security:
verify_signatures: true
allowed_ips: ["140.82.112.0/20"]
rate_limit: 100
require_https: true
---
Memory Security
Encryption at Rest
memory:
encrypt_at_rest: true
encryption_key_path: ~/.openclaw/memory.key
Sensitive Data Filtering
personalization:
blocklist:
keywords:
- password
- credit card
- social security
- bank account
Regular Audits
# Check what personal data is stored
openclaw memory search "password"
openclaw memory search "key"
openclaw memory search "token"
---
Prompt Injection Protection
If OpenClaw processes untrusted input (e.g., customer support), protect against prompt injection:
security:
prompt_injection:
detection: true
action: block # block, warn, or log
patterns:
- "ignore previous instructions"
- "you are now"
- "disregard all"
---
Security Checklist
- [ ] API keys stored in environment variables, not config files
- [ ] Agent runs as non-root user
- [ ] Config and memory files have restricted permissions (600)
- [ ] Memory encryption enabled
- [ ] Only verified skills installed
- [ ] Skill sandboxing enabled
- [ ] HTTPS required for all external communication
- [ ] Webhook signatures verified
- [ ] Firewall rules restrict unnecessary ports
- [ ] Regular security audits scheduled
- [ ] Log redaction enabled for sensitive data
- [ ] Prompt injection detection enabled (if processing untrusted input)
---
Tips
- Run
openclaw security audit monthly to catch misconfigurations.
- Never commit config.yaml with API keys to version control.
- Use the principle of least privilege — only grant permissions that are needed.
- Monitor logs for suspicious activity — failed auth attempts, unusual commands.
- Keep OpenClaw updated — security patches are included in updates.
---
Troubleshooting
| Problem | Solution |
| Skills blocked by sandbox | Add required domains to allowed list |
| Memory encryption key lost | Data is unrecoverable; back up the key |
| Webhook rejected | Check signature and IP allowlist |