OpenClaw Approvals & Permissions: Exec Allowlist CLI
I find it incredibly annoying when I’m in the middle of a workflow and get blocked by execution permissions. It usually happens right when I’m trying to run a script on a remote node or a gateway, and I have to stop everything to figure out which approval or allowlist rule is missing.
Managing OpenClaw approvals and permissions shouldn’t feel like a chore. I want to show you how to use the openclaw approvals command to inspect execution policy, grant a tool through the allowlist, and keep local, gateway, and node hosts aligned from your CLI.
What You’ll Need
Section titled “What You’ll Need”- The OpenClaw CLI installed on your machine.
- A node host that advertises
system.execApprovals.get/set(this includes the macOS app or a headless node host).
Quick Start
Section titled “Quick Start”By default, these commands look at the approvals file on your local disk at ~/.openclaw/exec-approvals.json. You can target gateway or node permissions using the --gateway and --node flags.
1. View current approvals
Section titled “1. View current approvals”First, see what is already allowed. Use the --node flag with an ID, name, or IP to check a specific host.
openclaw approvals getopenclaw approvals get --node <id|name|ip>openclaw approvals get --gateway2. Add a tool to the allowlist
Section titled “2. Add a tool to the allowlist”If you need to permit a specific binary, use the allowlist add helper. You can specify which agent the rule applies to; otherwise, it defaults to "*" for all agents.
openclaw approvals allowlist add "~/Projects/**/bin/rg"openclaw approvals allowlist add --agent main --node <id|name|ip> "/usr/bin/uptime"3. Remove a tool
Section titled “3. Remove a tool”If you no longer need a specific path allowed, removing it is just as simple.
openclaw approvals allowlist remove "~/Projects/**/bin/rg"4. Bulk update from a file
Section titled “4. Bulk update from a file”When you have a long list of approvals, it is easier to manage them in a JSON file and sync them all at once.
openclaw approvals set --file ./exec-approvals.jsonopenclaw approvals set --node <id|name|ip> --file ./exec-approvals.jsonTroubleshooting
Section titled “Troubleshooting”The command isn’t working on my remote node
Make sure the node host is actually advertising the correct capabilities. It must support system.execApprovals.get/set. This is standard for the macOS app and headless node hosts.
I added an approval but it’s not being picked up
Check if you specified a specific agent. If you used --agent main, the approval only applies to that agent. If you want it to apply everywhere, ensure you use the default "*" setting.
I can’t find the local settings file
OpenClaw stores these files per host at ~/.openclaw/exec-approvals.json. You can check that path manually if you need to verify the file exists on the disk.
If you run into other issues, the AI Setup Assistant can help you clear things up.
What’s Next
Section titled “What’s Next”OpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.