Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

OpenClaw Gateway Bind Modes Guide

Learn OpenClaw gateway bind modes: loopback, lan, tailnet, auto, and custom. Pick the right mode for your network setup.

Luca BertonApril 5, 20262 min read

What Are Bind Modes?

The gateway bind mode controls which network interfaces OpenClaw listens on. Choose the wrong mode and your agent is either unreachable or exposed to the internet.

The Five Modes

loopback (Default)

Listens on 127.0.0.1 only. The safest option — only local connections work.

bash
openclaw config set gateway.bind loopback
openclaw gateway restart

Use when: single-user setup on the same machine.

lan

Listens on your local network IP (e.g., 192.168.1.50). Other devices on your network can reach it.

bash
openclaw config set gateway.bind lan
openclaw gateway restart

Use when: accessing from your phone or another computer on the same network.

tailnet

Listens on your Tailscale IP. Only devices on your tailnet can connect.

bash
openclaw config set gateway.bind tailnet
openclaw gateway restart

Use when: you use Tailscale and want secure remote access without exposing to the internet.

auto

OpenClaw picks the best option automatically. It prefers tailnet if available, then lan, then loopback.

bash
openclaw config set gateway.bind auto
openclaw gateway restart

Use when: you want reasonable defaults without thinking about it.

custom

Bind to a specific IP or 0.0.0.0 (all interfaces).

bash
openclaw config set gateway.bind 0.0.0.0
openclaw gateway restart

Use when: running behind a reverse proxy or in Docker.

Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

Which Mode Should You Pick?

ScenarioMode
Local dev on laptoploopback
Access from phone on same Wi-Filan
Remote access via Tailscaletailnet
Docker container0.0.0.0 (custom)
Behind Caddy/Nginx0.0.0.0 (custom)
Not sureauto

Check Your Current Bind

bash
openclaw config get gateway.bind

# See what IP the gateway is actually listening on
ss -tlnp | grep 18789
Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

Security Considerations

  • Never bind 0.0.0.0 on a public server without a firewall. Anyone on the internet could reach your gateway.
  • Always set allowedOrigins when using lan or wider modes.
  • Use a reverse proxy with TLS for production deployments.

---

Ready to go deeper? Check out our hands-on course: OpenClaw Agent — practical exercises you can follow along on your own machine.

Related reading: the Ansible intelligent assistant and MCP server covers this in real-world detail.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.