Skip to content

Getting Started with OpenClaw on macOS

Setting up new developer tools often feels like a chore. You download an app, get hit with a dozen permission popups, and then have to figure out where the configuration files live or how to connect your credentials. It is that “day 0” friction that makes you want to quit before you have even started.

I want to show you how to get through the OpenClaw onboarding flow on your Mac. The goal is to get your Gateway running and your agent bootstrapped so you can start working immediately.

  • The OpenClaw macOS App.
  • npm or pnpm (if you want to install the global CLI).

Setting this up takes about five minutes. Here is the path to get it done:

  1. Approve System Warnings: When you first open the app, approve the macOS security warning and allow the app to find local networks.
  2. Review Security Settings: Read the security notice. By default, OpenClaw acts as a personal agent. New local configs use tools.profile: "coding" so you have access to filesystem and runtime tools without using an unrestricted profile.
  3. Choose Your Gateway: Decide where the Gateway runs.
    • This Mac (Local only): The wizard configures auth and writes credentials locally.
    • Remote (over SSH/Tailnet): Credentials must already exist on your gateway host.
    • Configure later: Skip this step for now.
  4. Grant Permissions: The app requires TCC permissions to function. You will need to allow access for Automation (AppleScript), Notifications, Accessibility, Screen Recording, Microphone, Speech Recognition, Camera, and Location.
  5. Install the CLI (Optional): You can install the global openclaw CLI via npm or pnpm. This helps with terminal workflows and launchd tasks.
  6. Start the Onboarding Chat: After setup, a dedicated chat session opens. The agent will introduce itself and guide you through the next steps, keeping this separate from your main conversations.
  • Local clients cannot connect to the Gateway: The wizard generates a token even for loopback connections. Ensure your local WS clients are using this token to authenticate.
  • Security risks with disabled authentication: If you disable auth, any local process can connect to the agent. Use a token for multi-machine access or any non-loopback binds to stay secure.

Still having trouble getting things running? Reach out to the AI Setup Assistant.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.