Why a Reverse Proxy?
Running OpenClaw directly on port 18789 works for local use. For remote access you want HTTPS, a clean domain, and proper WebSocket handling. Caddy does all of this with minimal config.
Prerequisites
- A domain pointing to your server (e.g.,
openclaw.yourdomain.com) - Caddy installed (
sudo apt install caddyon Debian/Ubuntu) - OpenClaw running and bound to
127.0.0.1:18789
Minimal Caddyfile
openclaw.yourdomain.com {
reverse_proxy localhost:18789
}That is the entire config. Caddy automatically: - Obtains a TLS certificate from Let's Encrypt - Redirects HTTP to HTTPS - Proxies WebSocket connections
Reload Caddy:
sudo systemctl reload caddyMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Configure OpenClaw allowedOrigins
Tell OpenClaw to accept requests from your domain:
openclaw config set gateway.controlui.allowedOrigins '["https://openclaw.yourdomain.com"]'
openclaw gateway restartDocker Setup
If both Caddy and OpenClaw run in Docker, use a shared network:
version: "3.8"
services:
openclaw:
image: openclaw/openclaw:latest
environment:
- OPENCLAW_GATEWAY_BIND=0.0.0.0
- OPENCLAW_GATEWAY_CONTROLUI_ALLOWEDORIGINS=["https://openclaw.yourdomain.com"]
networks:
- web
caddy:
image: caddy:latest
ports:
- "80:80"
- "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile
- caddy_data:/data
networks:
- web
networks:
web:
volumes:
caddy_data:Caddyfile for Docker:
openclaw.yourdomain.com {
reverse_proxy openclaw:18789
}Note: use the service name openclaw instead of localhost.
Verify
# Check TLS certificate
curl -I https://openclaw.yourdomain.com
# Test API
curl -H "x-api-key: YOUR_TOKEN" https://openclaw.yourdomain.com/v1/modelsGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Nginx Alternative
If you prefer Nginx:
server {
listen 443 ssl;
server_name openclaw.yourdomain.com;
ssl_certificate /etc/letsencrypt/live/openclaw.yourdomain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/openclaw.yourdomain.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:18789;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}The Upgrade and Connection headers are required for WebSocket connections.
Troubleshooting
- 502 Bad Gateway: OpenClaw is not running or bound to the wrong interface. Check
ss -tlnp | grep 18789. - WebSocket errors: Missing
proxy_set_header Upgradein Nginx config. Caddy handles this automatically. - Certificate errors: DNS not pointing to your server yet. Check with
dig openclaw.yourdomain.com.
Related Posts
- Deploy OpenClaw with Docker Compose for the base Docker setup
- OpenClaw Gateway Bind Modes to understand network binding
- Securing Your OpenClaw Agent for additional hardening
---
Ready to go deeper? Check out our hands-on course: OpenClaw Agent — practical exercises you can follow along on your own machine.
Related
For a production-focused walkthrough, see Luca Berton's guide on OpenClaw-driven CVE remediation with Ansible.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
OpenClaw Volume Permissions Fix
Fix OpenClaw Docker volume permission errors. Resolve EACCES issues for named volumes and bind mounts with troubleshooting steps.
Troubleshoot OpenClaw Gateway Errors
Fix OpenClaw gateway errors: 401 unauthorized, connection refused, origin not allowed, and WebSocket failures with resolution guides.
OpenClaw + Tailscale Remote Access
Access OpenClaw securely from anywhere using Tailscale. Zero port forwarding, zero firewall rules, encrypted connections.
OpenClaw Cron Jobs: Scheduled AI Tasks
Schedule recurring tasks with OpenClaw cron — from daily summaries to weekly reports. Complete setup guide with practical examples.
OpenClaw for DevOps
Use OpenClaw as your DevOps assistant — monitoring servers, managing deployments, checking logs, and automating infrastructure tasks.
OpenClaw Discord Bot Setup
Set up an OpenClaw AI agent as a Discord bot. Learn how to create the bot, configure permissions, and get your agent responding in channels.
Explore topics
Browse more articles on the topics covered here.