OpenClawSkills
GitHub
Reference • TutorialHeader.readTime

Configuration Guide

Complete reference for OpenClaw configuration, security models, and workspace structure.

Tutorial.step

Minimal Configuration

OpenClaw uses a JSON file for its core settings. By default, this is located at ~/.openclaw/openclaw.json.

Configuration File

~/.openclaw/openclaw.json
{
  "agents": {
    "defaults": {
      "model": {
        "primary": "anthropic/claude-opus-4-5"
      }
    }
  }
}
Tutorial.step

Model Selection & Authentication

OpenClaw supports a wide variety of AI models. For the best experience, we have specific recommendations.

Recommended Model

Anthropic Pro/Max (100/200) + Opus 4.5 is strongly recommended for its long-context strength and better prompt-injection resistance.

Supported Subscriptions (OAuth)

  • Anthropic (Claude Pro/Max)
  • OpenAI (ChatGPT/Codex)

While any model is supported, Anthropic Pro/Max + Opus 4.5 is strongly recommended. You can configure model failover and auth profile rotation (OAuth vs API keys) with fallbacks.

Model Configuration Capabilities

  • Multiple model providers (Anthropic, OpenAI, Gemini, local models)
  • Model failover for reliability
  • OAuth authentication for subscriptions
  • API key authentication
  • Profile rotation and fallbacks
Tutorial.step

Workspace & Skills

OpenClaw stores all its data in a dedicated workspace directory.

  • Workspace root: ~/.openclaw/workspace (configurable via agents.defaults.workspace)
  • Injected prompt files: AGENTS.md, SOUL.md, TOOLS.md, IDENTITY.md
  • Skills: ~/.openclaw/workspace/skills/<skill>/SKILL.md
  • Memory files: Daily notes formatted in Markdown (e.g. memory/2025-01-01.md) that OpenClaw auto-generates.

Edit Directly

The workspace is just folders and Markdown files on your machine. You can edit them directly, search them with tools like Raycast, or integrate them with Obsidian.
Tutorial.step

Security Model

Important Security Note

OpenClaw connects to real messaging surfaces. Treat inbound DMs as untrusted input.

Default Behavior

  • Default: Tools run on the host for the main session, so the agent has full access when it's just you.
  • Group/channel safety: Set agents.defaults.sandbox.mode: "non-main" to run non-main sessions (groups/channels) inside per-session Docker sandboxes; bash then runs in Docker for those sessions.

Sandbox Configuration

Allowlist

bash, process, read, write, edit, sessions_list, sessions_history, sessions_send, sessions_spawn

Denylist

browser, canvas, nodes, cron, discord, gateway

Run openclaw doctor to surface risky/misconfigured DM policies.

Default DM Access (Security)

Default behavior on Telegram/WhatsApp/Signal/iMessage/Microsoft Teams/Discord/Google Chat/Slack:

  • DM pairing: (dmPolicy="pairing") Unknown senders receive a short pairing code and the bot does not process their message.
  • Approve with: openclaw pairing approve <channel> <code> (then the sender is added to a local allowlist store).
  • Public inbound DMs: Require an explicit opt-in: set dmPolicy="open" and include "*" in the channel allowlist.
Tutorial.step

Gateway Configuration

The Gateway is the control plane for OpenClaw. Key configuration options include:

  • Port: Default is 18789, configurable via gateway.port
  • Bind address: Default is 127.0.0.1 (loopback), configurable via gateway.bind
  • Tailscale: Configure gateway.tailscale.mode for Serve/Funnel access
  • Authentication: Set gateway.auth.mode for password or token auth
Tutorial.step

Agent Configuration

Configure agent behavior and defaults:

  • Model: Set default model via agents.defaults.model.primary
  • Thinking level: Configure thinkingDefault for supported models
  • Verbose mode: Enable verboseDefault for detailed output
  • Session management: Configure session.scope, reset policies, and mainKey