Skip to content

How to use OpenClaw Pairing to secure your Gateway

I have often felt the stress of opening up a local service to the internet. You want the convenience of remote access, but you do not want to wake up to a thousand spam messages or unauthorized devices connected to your network. It is about finding that balance between accessibility and keeping the wrong people out.

OpenClaw handles this through “Pairing.” This is an explicit owner approval step. I use it in two scenarios: deciding who can talk to my bot and managing which devices can join my gateway network.

  1. OpenClaw Gateway installed and running.
  2. Access to the CLI on your host machine.
  3. A configured messaging channel (like Telegram or Signal).
  4. The OpenClaw mobile app (if you are pairing a phone).

If your channel uses the pairing policy, unknown senders cannot trigger the bot until you approve them.

  1. Send a message to your bot from an account that is not yet approved.
  2. Run openclaw pairing list telegram (or your specific channel) to see the code.
  3. Use the 8-character uppercase code provided in the list.
  4. Run openclaw pairing approve telegram <CODE> to allow the sender.
Terminal window
openclaw pairing list telegram
openclaw pairing approve telegram <CODE>

Nodes connect as devices with a specific role. I recommend using the Telegram plugin for this because it is the fastest way to handle the setup code.

  1. Message your bot /pair in Telegram to receive the base64-encoded setup code.
  2. Open the OpenClaw iOS app, go to Settings → Gateway, and paste that code.
  3. Message your bot /pair approve in Telegram to finalize the connection.
  4. Run openclaw devices list in your terminal to confirm the device is paired.
Terminal window
openclaw devices list
openclaw devices approve <requestId>

I find it helpful to know where this data is stored. OpenClaw keeps these files sensitive because they gate access to your assistant.

  • DM Pairing: Look in ~/.openclaw/credentials/ for <channel>-pairing.json (pending) and <channel>-allowFrom.json (approved).
  • Node Pairing: Look in ~/.openclaw/devices/ for pending.json and paired.json.
  • The code is not working: Pairing codes expire after 1 hour. If the time limit passes, the bot only sends a new pairing message roughly once per hour per sender. You might need to wait for a new request to trigger.
  • Requests are being ignored: OpenClaw caps pending DM pairing requests at 3 per channel. If you have 3 unapproved requests, the bot ignores additional ones until one expires or you approve it.

If you need help with a specific configuration, check the AI Setup Assistant.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.