OpenClaw: a gateway at home, a sandbox you switch on
OpenClaw is an open-source gateway. It connects the messaging apps you already use to an agent, on your machine. The site talks about an inbox, a calendar and flights. The documentation talks first about a gateway, pairing, and a sandbox that is off by default.

Original AI-generated illustration · SecuFocus
At a glance
Key points
Take OpenClaw if you want a self-hosted gateway, reachable from a messaging app, with a model you choose. Do not take it as a hosted service, or as a sandbox that is already closed. On a host install, the gateway listens locally. In a container, the documented default opens the bind. The tool sandbox is a setting, not the starting state.
Who it is for
OpenClaw fits if you want to talk to an agent from a messaging app you already have, without handing the gateway to a host run by the project. The documentation aims at people who administer the machine, alone or in a team whose members trust each other. The same software can serve as a personal assistant or as a shared deployment. The configuration changes. The trust boundary does not.
It fits poorly if people who do not trust each other must share the same agent. The security page says so: a group and several users are supported inside one boundary. OpenClaw is not a wall for hostile users on the same gateway. In that case, the documentation asks for a separate gateway, separate credentials, and ideally a separate account or machine.
It also fits poorly if you want a chat in the browser and nothing to install. The documented path installs Node if it is missing, then the gateway. The desktop apps, on macOS, Windows and Linux, do that setup for you. That is not nothing to install. It is a guided installation.
What it is
OpenClaw is a self-hosted gateway. One process connects channels, Discord, Google Chat, iMessage, Matrix, Microsoft Teams, Signal, Slack, Telegram, WhatsApp, Zalo and others, to agents. You run it on your machine or on a server you own. The documentation says there is no hosted service in the middle.
The project is presented as developed by the OpenClaw Foundation, an independent 501(c)(3), under the MIT licence. The homepage says: no subscription, no hosted tier, no token. The documentation adds: no paid tier, and no telemetry by default beyond a version check you can turn off. That version check is a transmission. Turning it off is part of the deployment if you do not want that signal.
The site shows everyday tasks: sorting an inbox, sending a message, keeping a calendar, checking in for a flight. The documentation describes a gateway to tooled agents. What the agent does depends on the tools you enable, and on the accounts you give it. A public marketing line is not the list of tools present at first launch. We did not connect an inbox.
How it is installed
The documented requirement is Node 24.16 or later, or Node 26.1 or later. Node 26 is recommended. If Node is missing, the installer provisions Node 26 on macOS and Node 24 LTS on Linux. pnpm is only needed if you build from source.
The quick path, on macOS, Linux or WSL2, is a script from the site. On Windows, it is a PowerShell command. Both can launch the wizard, or stop before it with an option. A desktop app exists for macOS, Windows and Linux. It can prepare a local gateway, or connect to one that is already there. The site announces, for Linux, an AppImage or a Debian package, on x64.
If you already manage Node, the global npm install is documented, followed by openclaw onboard --install-daemon. On npm 12, and on npm 11.16 or later, the published command explicitly allows the package scripts. Without that, the install can stop before the steps the project expects.
- Pick the desktop app, the script, or npm if Node is already yours.
- Let the wizard set the model provider and the gateway.
- Check that the gateway listens locally, unless you chose a container on purpose.
- Pair unknown senders before you open a group.
- Switch the sandbox on only after you have decided which tools should enter it. It does not switch on by itself.
One gateway, one port
The gateway is a process that stays up. It routes, holds the control plane, and keeps the channel connections. The documented port for a local start is 18789. The same port multiplexes control, OpenAI-format APIs, the interface, and hooks.
On an ordinary host install, the default is local listening. In a detected container, the documented default becomes an open bind, for port forwarding, unless Tailscale forces local listening again. Authentication is required by default: a token, a password, or, behind a proxy, a trusted-proxy mode.
Docker is optional. The page reserves it for an isolated trial, or a machine without a local install. The reference image is ghcr.io/openclaw/openclaw. A Docker Hub mirror exists, openclaw/openclaw. The page asks you to avoid unofficial mirrors. The Docker sandbox for tools does not require the gateway itself to run in a container. Those are two decisions.
Who can write
The announced defaults are conservative, on a host install. An unknown sender in a private message receives a pairing code, instead of having the message processed. Group access is allowlisted, usually behind a mention. The security page says there are exceptions, documented channel by channel. A workspace channel can trust workspace membership. Read the channel page before you open it.
One command says whether you have drifted: openclaw security audit. That is not an outside audit. It is the check the project publishes on its own configuration. Using it before you expose the gateway is the documented step. Skipping it means moving without the dashboard the project provided.
An agent that has the message-sending tool can, by default, write in other conversations and other channels. If you want messages confined to the current channel, you have to configure it. That is not the starting state. Someone who talks to the agent can therefore trigger a message elsewhere, within the reach of that tool.
The sandbox is off
The tool sandbox is off by default. The setting is called agents.defaults.sandbox, with a per-agent variant. When you switch it on, tool execution can enter Docker, Podman, a remote machine over SSH, OpenShell, or a leased machine. The gateway itself stays on the host. Only tool execution moves.
The documentation says this is not a perfect boundary. It limits file and process access when the model does something unwise. A tool denied by policy stays denied: the sandbox does not bring it back. The other way, tools.elevated is an explicit hatch. It runs exec outside the sandbox. An authorized sender can keep that choice for the session. To forbid exec, you need a tool policy, not only a container.
That is the checkable difference with Moltis, without repeating the neighbouring site’s testimonial. Moltis documents an automatic engine choice, with a weak fallback if there is no container. OpenClaw documents a sandbox that is off, which you switch on. Neither page says the other product was measured. Both say isolation is configured.
What leaves, and what stays
The gateway, the sessions and the credentials are on the machine you administer, or on the server you chose. That is not an account with the software’s publisher. The version check, if you do not turn it off, is the signal the documentation separates from telemetry. The rest depends on the channels and the model.
Each question sent to a remote model leaves the machine for that provider. OpenClaw does not become private because the gateway is at home. It is private to the extent that the model is local, or one whose policy you accept, and that the channels you connect are too. An inbox or a calendar given to the agent are real access. The site puts them forward. Giving them means giving them.
Logs and transcripts can contain what the conversations contained. The security page has a section on secrets, storage and logs. Reading it is part of the deployment if several people touch the same machine. A shared gateway folder is not a vault.
What not to ask of it
Do not ask it to be a wall between people who do not trust each other. The documentation refuses that deployment. Split the gateways.
Do not ask it to have already isolated the tools. The sandbox is a setting. A container, if it runs the gateway, also changes the default bind. Mixing the two means believing the service is closed because the word Docker is in the command.
The site displays messages from well-known people. A public message is not a test, and not a list of what the software does at your place. This reading follows the installation, gateway, security, sandbox and Docker pages. It did not install OpenClaw, or connect a messaging app.
The decision
Choose OpenClaw if you want a gateway of your own, channels you already use, and a swappable model. Start with local listening, pairing, and openclaw security audit. Switch the sandbox on if the agent has a terminal. Remove the elevated hatch if that terminal must not be able to leave it.
Look elsewhere if you want a service with no installation, or a wall between users who do not trust each other. Moltis, in the same section, makes a different bet: one binary, and a sandbox chosen immediately if it finds an engine. The linked guide is about what a generative system does with what you give it.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
- OpenClaw documentation ↗docs.openclaw.ai ·
- Sandboxing, OpenClaw ↗docs.openclaw.ai ·
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.