What Are Bind Modes?
The gateway bind mode controls which network interfaces OpenClaw listens on. Choose the wrong mode and your agent is either unreachable or exposed to the internet.
The Five Modes
loopback (Default)
Listens on 127.0.0.1 only. The safest option — only local connections work.
openclaw config set gateway.bind loopback
openclaw gateway restartUse when: single-user setup on the same machine.
lan
Listens on your local network IP (e.g., 192.168.1.50). Other devices on your network can reach it.
openclaw config set gateway.bind lan
openclaw gateway restartUse when: accessing from your phone or another computer on the same network.
tailnet
Listens on your Tailscale IP. Only devices on your tailnet can connect.
openclaw config set gateway.bind tailnet
openclaw gateway restartUse when: you use Tailscale and want secure remote access without exposing to the internet.
auto
OpenClaw picks the best option automatically. It prefers tailnet if available, then lan, then loopback.
openclaw config set gateway.bind auto
openclaw gateway restartUse when: you want reasonable defaults without thinking about it.
custom
Bind to a specific IP or 0.0.0.0 (all interfaces).
openclaw config set gateway.bind 0.0.0.0
openclaw gateway restartUse when: running behind a reverse proxy or in Docker.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Which Mode Should You Pick?
| Scenario | Mode |
|---|---|
| Local dev on laptop | loopback |
| Access from phone on same Wi-Fi | lan |
| Remote access via Tailscale | tailnet |
| Docker container | 0.0.0.0 (custom) |
| Behind Caddy/Nginx | 0.0.0.0 (custom) |
| Not sure | auto |
Check Your Current Bind
openclaw config get gateway.bind
# See what IP the gateway is actually listening on
ss -tlnp | grep 18789Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Security Considerations
- Never bind
0.0.0.0on a public server without a firewall. Anyone on the internet could reach your gateway. - Always set
allowedOriginswhen usinglanor wider modes. - Use a reverse proxy with TLS for production deployments.
Related Posts
- Deploy OpenClaw with Docker Compose for containerized setups
- Securing Your OpenClaw Agent for production hardening
- OpenClaw on Raspberry Pi for low-power deployments
---
Ready to go deeper? Check out our hands-on course: OpenClaw Agent — practical exercises you can follow along on your own machine.
Related guide
Related reading: the Ansible intelligent assistant and MCP server covers this in real-world detail.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Troubleshoot OpenClaw Gateway Errors
Fix OpenClaw gateway errors: 401 unauthorized, connection refused, origin not allowed, and WebSocket failures with resolution guides.
Deploy OpenClaw with Docker Compose
Step-by-step guide to deploy OpenClaw using Docker Compose. Cover networking, volumes, reverse proxy, and Tailscale setups.
OpenClaw Volume Permissions Fix
Fix OpenClaw Docker volume permission errors. Resolve EACCES issues for named volumes and bind mounts with troubleshooting steps.
OpenClaw Heartbeats
Learn how to configure OpenClaw heartbeats for proactive monitoring — email checks, calendar alerts, weather updates, and more.
Understanding OpenClaw's Memory System
Learn how OpenClaw agents maintain memory across sessions using file-based persistence — daily notes, MEMORY.md, and workspace context.
OpenClaw Node Pairing
Pair your phone or IoT devices with OpenClaw for camera access, location tracking, screen recording, and remote commands.
Explore topics
Browse more articles on the topics covered here.