Skip to content

OpenClaw Approvals & Permissions: Exec Allowlist CLI

I find it incredibly annoying when I’m in the middle of a workflow and get blocked by execution permissions. It usually happens right when I’m trying to run a script on a remote node or a gateway, and I have to stop everything to figure out which approval or allowlist rule is missing.

Managing OpenClaw approvals and permissions shouldn’t feel like a chore. I want to show you how to use the openclaw approvals command to inspect execution policy, grant a tool through the allowlist, and keep local, gateway, and node hosts aligned from your CLI.

  • The OpenClaw CLI installed on your machine.
  • A node host that advertises system.execApprovals.get/set (this includes the macOS app or a headless node host).

By default, these commands look at the approvals file on your local disk at ~/.openclaw/exec-approvals.json. You can target gateway or node permissions using the --gateway and --node flags.

First, see what is already allowed. Use the --node flag with an ID, name, or IP to check a specific host.

Terminal window
openclaw approvals get
openclaw approvals get --node <id|name|ip>
openclaw approvals get --gateway

If you need to permit a specific binary, use the allowlist add helper. You can specify which agent the rule applies to; otherwise, it defaults to "*" for all agents.

Terminal window
openclaw approvals allowlist add "~/Projects/**/bin/rg"
openclaw approvals allowlist add --agent main --node <id|name|ip> "/usr/bin/uptime"

If you no longer need a specific path allowed, removing it is just as simple.

Terminal window
openclaw approvals allowlist remove "~/Projects/**/bin/rg"

When you have a long list of approvals, it is easier to manage them in a JSON file and sync them all at once.

Terminal window
openclaw approvals set --file ./exec-approvals.json
openclaw approvals set --node <id|name|ip> --file ./exec-approvals.json

The command isn’t working on my remote node Make sure the node host is actually advertising the correct capabilities. It must support system.execApprovals.get/set. This is standard for the macOS app and headless node hosts.

I added an approval but it’s not being picked up Check if you specified a specific agent. If you used --agent main, the approval only applies to that agent. If you want it to apply everywhere, ensure you use the default "*" setting.

I can’t find the local settings file OpenClaw stores these files per host at ~/.openclaw/exec-approvals.json. You can check that path manually if you need to verify the file exists on the disk.

If you run into other issues, the AI Setup Assistant can help you clear things up.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.