Files
openclaw/docs/network.md
T
Peter Steinberger ae55a4090c refactor(canvas): make the panel a widget presenter (#126030)
* refactor(canvas): retire legacy host and commands

* refactor(apple): narrow shared Canvas contracts

* refactor(macos): keep Canvas as widget presenter

* refactor(ios): remove Canvas client

* refactor(android): remove Canvas client

* refactor(linux): remove Canvas client

* fix(ci): isolate native locale artifacts

* fix(linux): regenerate companion lockfile

* fix(canvas): refresh native tool display metadata

* test(canvas): align coverage with presenter surface

* test(canvas): remove obsolete asset root seam

* test(canvas): stabilize retirement CI coverage

* refactor(swift): remove orphaned resource wrapper

* test(ios): remove retired canvas layout assertion

* fix(macos): reserve retired canvas command namespace

* refactor(macos): isolate canvas command policy

* fix(canvas): select only eligible macOS panels

* fix(canvas): keep panel selection plugin-owned
2026-08-19 08:21:07 -07:00

2.6 KiB

summary, read_when, title
summary read_when title
Network hub: gateway surfaces, pairing, discovery, and security
You need the network architecture + security overview
You are debugging local vs tailnet access or pairing
You want the canonical list of networking docs
Network

This hub links the core docs for how OpenClaw connects, pairs, and secures devices across localhost, LAN, and tailnet.

Core model

Most operations flow through the Gateway (openclaw gateway), a single long-running process that owns channel connections and the WebSocket control plane.

  • Loopback first: the Gateway WS defaults to ws://127.0.0.1:18789. Non-loopback binds refuse to start without a valid gateway auth path: shared-secret token/password auth, or a correctly configured non-loopback trusted-proxy deployment.
  • One Gateway per host is recommended. For isolation, run multiple gateways with isolated profiles and ports (Multiple Gateways).
  • Hosted widget documents and A2UI renderer assets are served on the same port as the Gateway (/__openclaw__/canvas/, /__openclaw__/a2ui/), protected by Gateway auth when bound beyond loopback.
  • Remote access is typically an SSH tunnel or Tailscale VPN (Remote Access).

Key references:

Pairing + identity

Local trust:

  • Direct local loopback connects (no forwarded/proxy headers) can be auto-approved for pairing to keep same-host UX smooth.
  • OpenClaw also has a narrow backend/container-local self-connect path for trusted shared-secret helper flows.
  • Tailnet and LAN clients, including same-host tailnet binds, still require explicit pairing approval.

Discovery + transports

Nodes + transports

Security