Securely Expose Your OpenClaw Gateway with Tailscale
I have often found myself in a situation where I need to access a local dashboard while away from my desk. Setting up traditional port forwarding or managing SSL certificates is usually a headache. It is annoying when you just want to check your services without leaving your local machine wide open to the internet.
I recommend using the Tailscale integration in OpenClaw to solve this. It handles the HTTPS certificates and routing for you, so you can keep your Gateway bound to loopback while still accessing it securely through your tailnet or even the public web.
What You’ll Need
Section titled “What You’ll Need”- Tailscale CLI installed and logged in.
- HTTPS enabled for your tailnet (required for Serve and Funnel).
- MagicDNS enabled and Tailscale v1.38.3+ (required for Funnel).
- The open-source Tailscale app variant if you are on macOS and using Funnel.
Quick Start
Section titled “Quick Start”Setting up Tailscale Serve is the fastest way to get secure, private access to your dashboard. This keeps the Gateway on your private tailnet.
- Verify your environment: Ensure the
tailscalecommand is available in your terminal and you are authenticated. - Update your configuration: Add the Tailscale mode to your
config.json5file.{gateway: {bind: "loopback",tailscale: { mode: "serve" },},} - Launch the Gateway: Run the service using the CLI flag.
Terminal window openclaw gateway --tailscale serve - Access the UI: Open your browser and go to
https://<magicdns>/or your specific base path.
Choosing Your Mode
Section titled “Choosing Your Mode”I suggest picking a mode based on who needs to see the dashboard.
Tailscale Serve (Private)
Section titled “Tailscale Serve (Private)”This is the default recommended path. It uses tailscale serve to provide HTTPS and routing within your tailnet. When gateway.auth.allowTailscale is true, OpenClaw uses tailscale whois to check identity headers. This means you can log in automatically based on your Tailscale identity without typing a password.
Tailscale Funnel (Public)
Section titled “Tailscale Funnel (Public)”If you need to share the dashboard with someone outside your tailnet, use funnel. Because this opens the Gateway to the public internet, OpenClaw requires you to use a shared password.
{ gateway: { bind: "loopback", tailscale: { mode: "funnel" }, auth: { mode: "password", password: "your-secure-password" }, }}Direct Tailnet Bind
Section titled “Direct Tailnet Bind”If you do not want HTTPS or the Serve/Funnel features, you can bind directly to the Tailnet IP. Note that loopback access will be disabled in this mode.
{ gateway: { bind: "tailnet", auth: { mode: "token", token: "your-token" }, }}Troubleshooting
Section titled “Troubleshooting”- Funnel fails to start: OpenClaw will refuse to start Funnel unless your auth mode is set to
password. This prevents accidental public exposure of an unsecured dashboard. - HTTPS errors: Serve and Funnel require HTTPS to be enabled in your Tailscale admin console. The CLI will usually prompt you if this setting is missing.
- macOS Funnel issues: If you are on macOS, Funnel only works with the open-source variant of the Tailscale application.
- Loopback connection refused: If you set
gateway.bindtotailnet, the dashboard will not be accessible at127.0.0.1. You must use the Tailscale IP.
If you hit a wall during setup, check out the AI Setup Assistant for help.
What’s Next
Section titled “What’s Next”OpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.