网关
openclaw gateway CLI (`openclaw gateway`) — 运行、查询和发现网关
网关是 OpenClaw 的 WebSocket 服务器(通道、节点、会话、挂钩)。
此页面中的子命令位于 ''openclaw gateway …'' 下。
相关文档:
- ''/网关/发现''
- ''/网关/配置''
运行网关
运行本地网关进程:
openclaw gateway
前台别名:
openclaw gateway run
注意事项:
- 默认情况下,除非在 ''~/.openclaw/openclaw.json'' 中设置 ''~/.openclaw/openclaw.json'',否则网关拒绝启动。使用 ''--allow-unconfigured'' 进行临时/开发运行。
- 未经授权的环回之外的绑定被阻止(安全护栏)。
- ''SIGUSR1'' 在授权时触发进程内重新启动(启用 ''commands.restart'' 或使用网关工具/配置应用/更新)。
- ''SIGINT''/''SIGTERM'' 处理程序停止网关进程,但它们不会恢复任何自定义终端状态。如果使用 TUI 或原始模式输入包装 CLI,请在退出前恢复终端。
### 选项
- ''--port <port>'': WebSocket port (default from config/env; typically ''18789'').
- ''--bind <loopback|lan|tailnet|auto|custom>'': Listener bind mode.
- ''--auth <token|password>'': Auth mode override.
- ''--token <token>'': Token override (also sets ''OPENCLAW_GATEWAY_TOKEN'' for the process).
- ''--password <password>'': Password override (also sets ''OPENCLAW_GATEWAY_PASSWORD'' for the process).
- ''--tailscale <off|serve|funnel>'': Expose gateway via Tailscale.
- ''--tailscale-reset-on-exit'':关闭时重置 Tailscale 服务/漏斗配置。
- ''--allow-unconfigured'':允许网关在配置中没有 ''gateway.mode=local'' 的情况下启动。
- ''--dev'':如果缺少,则创建一个开发配置+工作区(跳过 BOOTSTRAP.md)。
- ''--reset'':重置开发配置+凭据+会话+工作区(需要''--dev'')。
- ''--force'':在开始之前杀死所选端口上的任何现有侦听器。
- ''--verbose'':详细日志。
- ''--claude-cli-logs'':仅在控制台中显示 claude-cli 日志(并启用其 stdout/stderr)。
- ''--ws-log <auto|full|compact>'': websocket log style (default ''auto'').
查询正在运行的网关
所有查询命令都使用 WebSocket RPC。
输出模式:
- 默认值:人类可读(TTY 中彩色)。
- ''--json'':机器可读的 JSON(无样式/微调器)。
- ''--no-color''(或''NO_COLOR=1''):禁用 ANSI,同时保持人性化布局。
共享选项(如果支持):
- ''--url <url>'': Gateway WebSocket URL.
- ''--token <token>'': Gateway token.
- ''--password <password>'': Gateway password.
- ''--timeout <ms>'': Timeout/budget (varies per command).
#
`gateway health`
openclaw gateway health --url ws://127.0.0.1:18789
#
`gateway status`
''gateway status'' 显示网关服务 (launchd/systemd/schtasks) 以及可选的 RPC 探针。
openclaw gateway status openclaw gateway status --json
选项:
- ''--url <url>'': Override probe URL.
- ''--token <token>'': Token auth for probe.
- ''--password <password>'': Password auth for probe.
- ''--timeout <ms>'': Probe timeout (default ''10000'').
- ''--no-probe'':跳过 RPC 探测(仅限服务视图)。
- ''--deep'':也扫描系统级服务。
#
`gateway probe`
''gateway probe'' 是"调试所有内容"命令。它总是探测:
- 您配置的远程网关(如果设置),以及
- 本地主机(环回)即使配置了远程。
openclaw gateway probe openclaw gateway probe --json
##
通过 SSH 远程(Mac 应用程序奇偶校验)
macOS app "Remote via SSH" mode uses local port forwarding, so remote gateway is accessible at ''ws://127.0.0.1:<port>'' (may only bind to loopback).
CLI 等效项:
openclaw gateway probe --ssh user@gateway-host
选项:
- ''--ssh <target>'': ''user@host'' or ''user@host:port'' (port defaults to ''22'').
- ''--ssh-identity <path>'': Identity file.
- ''--ssh-auto'':选择第一个发现的网关主机作为 SSH 目标(仅限 LAN/WAB)。
配置(可选,用作默认值):
- ''gateway.remote.sshTarget''
- ''gateway.remote.sshIdentity''
#
`gateway call <method>`
低级 RPC 助手。
openclaw gateway call status
openclaw gateway call logs.tail --params '{"sinceMs": 60000}'管理网关服务
openclaw gateway install openclaw gateway start openclaw gateway stop openclaw gateway restart openclaw gateway uninstall
- ''gateway install'' 支持 ''--port''、''--runtime''、''--token''、''--force''、''--json''。
- 生命周期命令接受 ''--json'' 进行脚本编写。
发现网关 (Bonjour)
''gateway discover'' 扫描网关信标 (''_openclaw-gw._tcp'')。
- 多播 DNS-SD:''local.''
- 单播 DNS-SD(Wide-Area Bonjour):选择一个域(例如:''openclaw.internal.'')并设置拆分 DNS + DNS 服务器;请参阅 ''/gateway/bonjour''
只有启用了 Bonjour 发现(默认)的网关才会通告信标。
广域发现记录包括 (TXT):
- ''role''(网关角色提示)
- ''transport''(传输提示,例如 ''gateway'')
- ''gatewayPort''(WebSocket 端口,通常为 ''18789'')
- ''sshPort''(SSH 端口;如果不存在,则默认为 ''22'')
- ''tailnetDns''(MagicDNS 主机名,如果可用)
- ''gatewayTls'' / ''gatewayTlsSha256'' (启用 TLS + 证书指纹)
- ''cliPath''(远程安装的可选提示)
##
#
`gateway discover`
openclaw gateway discover
选项:
- ''--timeout <ms>'': Per-command timeout (browse/resolve); default ''2000''.
- ''--json'':机器可读的输出(也禁用样式/微调器)。
示例:
openclaw gateway discover --timeout 4000 openclaw gateway discover --json | jq '.beacons[].wsUrl'