Manage OpenClaw Plugins: Install, Update, and Configure
Managing gateway extensions can be a real headache when you’re just trying to get your environment set up. You want a way to handle plugins, hook packs, and bundles without fighting manual configuration files every five minutes.
The openclaw plugins command is your go-to tool for managing Gateway plugins, hook packs, and compatible bundles. If you’re looking for more context, check out these resources:
- Plugin system: Plugins
- Bundle compatibility: Plugin bundles
- Plugin manifest + schema: Plugin manifest
- Security hardening: Security
Commands
Section titled “Commands”Here is the quick list of commands you’ll use most often:
openclaw plugins listopenclaw plugins install <path-or-spec>openclaw plugins inspect <id>openclaw plugins enable <id>openclaw plugins disable <id>openclaw plugins uninstall <id>openclaw plugins doctoropenclaw plugins update <id>openclaw plugins update --allopenclaw plugins marketplace list <marketplace>OpenClaw comes with some bundled plugins, but they start disabled. You can use plugins enable to activate them when you’re ready.
For native OpenClaw plugins, you need to include an openclaw.plugin.json file with an inline JSON Schema in the configSchema field (even if it’s empty). If you’re using compatible bundles, they use their own bundle manifests instead.
When you run plugins list, you’ll see either Format: openclaw or Format: bundle. If you use the verbose list or info output, you’ll also see the bundle subtype—like codex, claude, and cursor—along with any detected bundle capabilities.
Install
Section titled “Install”Installing plugins is straightforward. You can pull from ClawHub, npm, or local paths:
openclaw plugins install <package> # ClawHub first, then npmopenclaw plugins install clawhub:<package> # ClawHub onlyopenclaw plugins install <package> --pin # pin versionopenclaw plugins install <package> --dangerously-force-unsafe-installopenclaw plugins install <path> # local pathopenclaw plugins install <plugin>@<marketplace> # marketplaceopenclaw plugins install <plugin> --marketplace <name> # marketplace (explicit)OpenClaw checks bare package names against ClawHub first, then falls back to npm. A quick security tip: treat plugin installs like running code. I recommend using pinned versions to keep things predictable.
If you run into false positives with the built-in dangerous-code scanner, you can use the --dangerously-force-unsafe-install flag. This is a break-glass option that lets the install continue even with critical findings. Just keep in mind it won’t bypass before_install hook policy blocks or actual scan failures.
This flag specifically applies to openclaw plugins install. For gateway-backed skill dependency
openclaw plugins install clawhub:openclaw-codex-app-serveropenclaw plugins install clawhub:openclaw-codex-app-server@1.2.3openclaw plugins install openclaw-codex-app-serveropenclaw plugins marketplace list <marketplace-name>openclaw plugins install <plugin-name>@<marketplace-name>openclaw plugins install <plugin-name> --marketplace <marketplace-name>openclaw plugins install <plugin-name> --marketplace <owner/repo>openclaw plugins install <plugin-name> --marketplace ./my-marketplaceopenclaw plugins install -l ./my-pluginopenclaw plugins uninstall <id>openclaw plugins uninstall <id> --dry-runopenclaw plugins uninstall <id> --keep-filesopenclaw plugins update <id-or-npm-spec>openclaw plugins update --allopenclaw plugins update <id-or-npm-spec> --dry-runopenclaw plugins update @openclaw/voice-call@betaopenclaw plugins inspect <id>openclaw plugins inspect <id> --jsonOpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.