Security Model
OpenClaw runs with significant system access — file operations, shell commands, web browsing, and messaging. This power requires careful security practices.
API Key Management
Never Hardcode Keys
# Good: Environment variables
export OPENAI_API_KEY="sk-..."
export STRIPE_SECRET_KEY="sk_live_..."
# Bad: In config files committed to git
# apiKey: "sk-..." ← NEVER do thisUse .env Files
# .env (add to .gitignore!)
OPENAI_API_KEY=sk-...
ANTHROPIC_API_KEY=sk-ant-...Rotate Regularly
Set a reminder to rotate API keys quarterly. If a key is ever exposed (e.g., in a chat log), revoke immediately.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Network Security
Firewall Rules
If your agent is internet-facing:
# Only allow SSH and HTTPS
sudo ufw default deny incoming
sudo ufw allow ssh
sudo ufw allow 443/tcp
sudo ufw enableReverse Proxy
Use Caddy or nginx as a reverse proxy with TLS:
# Caddyfile
agent.yourdomain.com {
reverse_proxy localhost:3000
}VPN Access
For maximum security, access your agent only via VPN (WireGuard, Tailscale):
# Tailscale — zero-config VPN
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale upPermission Boundaries
Agent Safety Rules
OpenClaw's AGENTS.md includes safety guidelines:
## Safety
- Don't exfiltrate private data
- Don't run destructive commands without asking
- trash > rm (recoverable beats gone forever)
- When in doubt, askExternal vs Internal Actions
Define clear boundaries: - Free to do: Read files, search web, organize workspace - Ask first: Send emails, post publicly, delete files
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Data Protection
Memory Privacy
MEMORY.md contains personal context. OpenClaw's architecture ensures:
- Memory files stay in the workspace
- They're only loaded in main sessions (not group chats)
- No cloud sync unless you configure it
Backup Your Workspace
# Regular backups
tar -czf agent-backup-$(date +%Y%m%d).tar.gz ~/agent/Audit Logs
Review your agent's daily memory files periodically. They serve as an activity log of what the agent did.
Common Mistakes
- Sharing tokens in chat — your agent might include them in memory
- Running as root — always use a dedicated user account
- Open ports — keep your agent behind a firewall
- No backups — disk failures happen
- Ignoring updates — keep OpenClaw and Node.js updated
---
Ready to go deeper? Check out our hands-on course: OpenClaw Agent — practical exercises you can follow along on your own machine.
Related guide
Related reading: the Ansible intelligent assistant and MCP server covers this in real-world detail.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Troubleshoot OpenClaw Gateway Errors
Fix OpenClaw gateway errors: 401 unauthorized, connection refused, origin not allowed, and WebSocket failures with resolution guides.
Deploy OpenClaw with Docker Compose
Step-by-step guide to deploy OpenClaw using Docker Compose. Cover networking, volumes, reverse proxy, and Tailscale setups.
OpenClaw Gateway Bind Modes Guide
Learn OpenClaw gateway bind modes: loopback, lan, tailnet, auto, and custom. Pick the right mode for your network setup.
SELinux for Apache and PHP-FPM
Configure Apache with PHP-FPM over TCP on RHEL with SELinux enforcing. Diagnose and fix name_connect denials using the correct SELinux boolean and audit tools.
SELinux Booleans Explained
SELinux booleans let you toggle common service behaviors without writing custom policy. Learn getsebool, setsebool, and the most useful httpd booleans.
SELinux Cheat Sheet for RHEL
Quick reference for essential SELinux commands on RHEL 9/10. Modes, contexts, labels, booleans, logs, and troubleshooting in one page.
Explore topics
Browse more articles on the topics covered here.