How to use OpenClaw Pairing to secure your Gateway
I have often felt the stress of opening up a local service to the internet. You want the convenience of remote access, but you do not want to wake up to a thousand spam messages or unauthorized devices connected to your network. It is about finding that balance between accessibility and keeping the wrong people out.
OpenClaw handles this through “Pairing.” This is an explicit owner approval step. I use it in two scenarios: deciding who can talk to my bot and managing which devices can join my gateway network.
What You’ll Need
Section titled “What You’ll Need”- OpenClaw Gateway installed and running.
- Access to the CLI on your host machine.
- A configured messaging channel (like Telegram or Signal).
- The OpenClaw mobile app (if you are pairing a phone).
Quick Start
Section titled “Quick Start”1. Approve a new DM sender
Section titled “1. Approve a new DM sender”If your channel uses the pairing policy, unknown senders cannot trigger the bot until you approve them.
- Send a message to your bot from an account that is not yet approved.
- Run
openclaw pairing list telegram(or your specific channel) to see the code. - Use the 8-character uppercase code provided in the list.
- Run
openclaw pairing approve telegram <CODE>to allow the sender.
openclaw pairing list telegramopenclaw pairing approve telegram <CODE>2. Pair a Node device (like a phone)
Section titled “2. Pair a Node device (like a phone)”Nodes connect as devices with a specific role. I recommend using the Telegram plugin for this because it is the fastest way to handle the setup code.
- Message your bot
/pairin Telegram to receive the base64-encoded setup code. - Open the OpenClaw iOS app, go to Settings → Gateway, and paste that code.
- Message your bot
/pair approvein Telegram to finalize the connection. - Run
openclaw devices listin your terminal to confirm the device is paired.
openclaw devices listopenclaw devices approve <requestId>Where the state lives
Section titled “Where the state lives”I find it helpful to know where this data is stored. OpenClaw keeps these files sensitive because they gate access to your assistant.
- DM Pairing: Look in
~/.openclaw/credentials/for<channel>-pairing.json(pending) and<channel>-allowFrom.json(approved). - Node Pairing: Look in
~/.openclaw/devices/forpending.jsonandpaired.json.
Troubleshooting
Section titled “Troubleshooting”- The code is not working: Pairing codes expire after 1 hour. If the time limit passes, the bot only sends a new pairing message roughly once per hour per sender. You might need to wait for a new request to trigger.
- Requests are being ignored: OpenClaw caps pending DM pairing requests at 3 per channel. If you have 3 unapproved requests, the bot ignores additional ones until one expires or you approve it.
If you need help with a specific configuration, check the AI Setup Assistant.
What’s Next
Section titled “What’s Next”OpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.