Skip to content

OpenClaw Pairing: Secure Device Access

OpenClaw uses pairing codes to control who can talk to your AI. It’s simple: unknown contacts get a code, you approve or ignore them.

No random strangers are going to accidentally (or intentionally) use your AI.


When someone new sends a message to your OpenClaw bot:

  1. They receive a pairing code (8 uppercase characters)
  2. The code expires after 1 hour
  3. You approve it with a CLI command
  4. They’re added to your allowlist — future messages go through automatically

Codes are designed to be human-readable: no confusing characters like 0/O or 1/I.


Controls who can message your bot on each channel.

List pending requests:

Terminal window
openclaw pairing list whatsapp
openclaw pairing list telegram
openclaw pairing list discord

Approve a contact:

Terminal window
openclaw pairing approve whatsapp <CODE>
openclaw pairing approve telegram <CODE>
openclaw pairing approve discord <CODE>

Works for: whatsapp, telegram, discord, signal, imessage, slack

Controls which devices (iOS, Android, macOS, headless) can connect to your gateway.

List pending device requests:

Terminal window
openclaw pairing list nodes

Approve a device:

Terminal window
openclaw pairing approve nodes <CODE>

Pairing data lives in ~/.openclaw/credentials/:

FilePurpose
<channel>-pairing.jsonPending pairing requests
<channel>-allowFrom.jsonApproved allowlist

For example:

  • whatsapp-pairing.json — pending WhatsApp requests
  • telegram-allowFrom.json — approved Telegram contacts

To prevent spam:

  • Max 3 pending requests per channel — additional requests are ignored until one expires or is approved
  • Codes expire after 1 hour — the bot only sends a new code when creating a fresh request
  • One code per sender per hour — no code spam

Your own phone number (the one linked to WhatsApp, etc.) is implicitly trusted. You don’t need to approve yourself.

This means:

  • Messages from your linked device skip pairing
  • selfChatMode in WhatsApp works without approval

Disable pairing entirely (not recommended):

{
"channels": {
"whatsapp": {
"dmPolicy": "allowlist",
"allowFrom": ["*"]
}
}
}

The "*" wildcard allows everyone. Use with caution!

Security deep dive: Official security docs →


First time setup? You’ll need to approve yourself from another device:

  1. Text the bot from your phone
  2. Get the pairing code
  3. On your computer: openclaw pairing approve whatsapp <CODE>

Share the bot with someone:

  1. They text your bot number
  2. They receive a code (tell them to share it with you)
  3. You run: openclaw pairing approve whatsapp <CODE>

Edit the allowlist file directly:

Terminal window
# View current allowlist
cat ~/.openclaw/credentials/whatsapp-allowFrom.json
# Remove a number and save

The code might have expired. Ask them to text the bot again to generate a new code.

Check if the gateway is running:

Terminal window
openclaw gateway status

Still stuck? Our AI Setup Assistant is trained on all OpenClaw documentation.



Need help? Join the OpenClaw Discord or check the official docs.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.