DocsOpenClaw

OpenClaw

Install the OpenClaw AI assistant from the App Store with your LLM API key, sign in with the gateway token, approve browsers and connect Telegram, Zalo or WhatsApp.

OpenClaw is a self-hosted AI assistant gateway. It connects a large language model (Anthropic, OpenAI, DeepSeek…) to the chat apps you already use, such as Telegram, Zalo and WhatsApp, and gives you a web Control UI to chat, manage sessions, agents and channels. Use it when you want an always-on assistant reachable from your phone's chat apps, with the conversation history kept on your own server.

Requirements

Item Value
Image ghcr.io/openclaw/openclaw:2026.9.8
Memory limit 2048 MB, 1 CPU. The install dialog warns that the app needs about 2 GB of RAM or more.
Free disk to install about 5.8 GB (the image is about 3.3 GB)
Domain a domain or subdomain pointed to the server, for example claw.example.com
LLM API key at least one of Anthropic, OpenAI or DeepSeek. You pay the provider directly.

Docker must be installed (App Store → Install Docker). Customers need a package that allows Docker apps and has 2048 MB of RAM (MB) free for apps; see App limits for customers.

Install

  1. Point the domain's A record to the server.

  2. Open App Store and click Install on the OpenClaw card.

  3. Fill in the dialog. The dialog says "Enter at least one API key (you pay the model provider directly)."

    Field What to enter
    Domain for example claw.example.com
    Owner Administrators only: the hosting account the app belongs to
    Anthropic API key a key from the Anthropic Console (starts with sk-ant-)
    OpenAI API key a key from the OpenAI platform
    DeepSeek API key a key from the DeepSeek platform
    Free SSL (Let's Encrypt) Leave it on

    Fill in one key or several. An install with no key is refused with OpenClaw needs at least one API key. Each value may be up to 512 characters on one line.

  4. Click Install and follow the task log.

ZoPanel passes the keys to the container as ANTHROPIC_API_KEY, OPENAI_API_KEY and DEEPSEEK_API_KEY, and also:

Setting Value
OPENCLAW_GATEWAY_TOKEN a random 32-character token that protects the Control UI, shown under Login details
gateway.bind, gateway.mode lan, local: the gateway listens inside the container; the port is published on 127.0.0.1 only and reached through nginx
gateway.trustedProxies the Docker bridge, so OpenClaw accepts requests from the website's nginx
gateway.controlUi.allowedOrigins https://<your domain> and http://<your domain>

The gateway.* values are written into openclaw.json each time the app starts and when the panel starts. If you change them, ZoPanel puts them back and restarts the app.

The keys cannot be edited from the panel after installation. To use another key later, add it inside OpenClaw (see Choose the model).

Sign in and approve your browser

OpenClaw has no setup lock: it is protected by the gateway token and by browser approval, so the domain is public as soon as it is installed.

  1. Open Websites, choose the domain and go to the Docker tab.
  2. Under Login details, copy OPENCLAW_GATEWAY_TOKEN. Only people who can manage the website see it.
  3. Open https://<your domain>. Paste the token into Gateway secret and click Connect.
  4. OpenClaw asks for this browser to be approved. Go back to the Docker tab: the Browsers card lists it under Waiting for approval with its platform, IP address and time.
  5. Click Approve. The Control UI opens. Click Reject for any request you do not recognise.

Each new browser or device goes through the same approval. Approved ones are listed under Approved. The token is kept only in the current browser tab; after approval the browser uses its own device token.

Important: anyone with the gateway token can request access, and an approved browser can control the assistant and use your API keys. Keep the token secret.

Choose the model

OpenClaw uses the providers whose keys it finds. Check or change the default model in the Control UI under Settings → Models, or with /model in a chat. Set a spending limit in your provider's dashboard: every message, automation and channel uses your key.

The Control UI's operator terminal opens a shell inside the container, where the OpenClaw CLI is available, for example:

openclaw models list
openclaw channels status --probe

If DeepSeek models do not appear, the DeepSeek provider plugin may be missing: openclaw plugins install @openclaw/deepseek-provider.

Connect chat channels

Channels are configured in Settings → Channels (under Connections) or with the CLI in the operator terminal. OpenClaw applies channel changes without a restart.

Telegram

  1. In Telegram, chat with @BotFather, run /newbot and copy the bot token.

  2. Add it in Settings → Channels → Telegram, or run openclaw channels add --channel telegram --token <bot-token>.

  3. Send any message to your bot. By default, unknown senders get a pairing code.

  4. Approve it in the operator terminal (codes expire after one hour):

    openclaw pairing list telegram
    openclaw pairing approve telegram <CODE>
    

Zalo (marked experimental by OpenClaw): create a bot at bot.zaloplatforms.com, set its token in Settings → Channels, then approve the first message's pairing code the same way (openclaw pairing approve zalo <CODE>).

WhatsApp: OpenClaw links as a WhatsApp Web device. Start the login from Settings → Channels → WhatsApp and scan the QR code with WhatsApp on your phone (Linked devices).

Telegram's default long polling only makes outgoing connections, so it works behind ZoPanel without extra settings.

Where your data lives

/var/lib/zopanel-apps/<instance>/state/

<instance> is the domain with dots replaced by hyphens (claw.example.com → claw-example-com). It is mounted at /home/node/.openclaw and holds openclaw.json, channel credentials (bot tokens, the WhatsApp session), paired devices, sessions, memory and the agent workspace. Only root and the container can read it.

Back up

ZoPanel's website backups do not include /var/lib/zopanel-apps; the Backups card on the website's Docker tab backs up the app instead.

To back up OpenClaw, click Back up now on the Backups card of the website's Docker tab. Administrators can also set a Schedule (Off, Every day or Every week; off by default) and how many copies to Keep (1–60, default 7), then click Save. Each backup archives /var/lib/zopanel-apps/<instance>/ into /var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) for the few seconds of the copy, so the copy is consistent. Older copies beyond Keep are removed, and a failed scheduled backup sends administrators the Backup failed alert.

To restore, an administrator clicks Restore next to a backup. OpenClaw is stopped and its data replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too. Customers can click Back up now and see the list; the schedule and restores are done by the provider.

The archives stay on the same server. Copy important ones off it (for example with scp or rclone from /var/backups/zopanel-apps/<instance>/) and store them encrypted, since they contain your API keys, bot tokens and the WhatsApp session. To restore on another server, install OpenClaw on the same domain there, copy the archive into /var/backups/zopanel-apps/<instance>/ on the new server and click Restore on its Backups card. The new install has a new gateway token, shown under Login details.

Update

An administrator clicks Update to latest on the Docker tab. ZoPanel pulls the image this ZoPanel version is pinned to, recreates the container and keeps the state, keys and token. Newer OpenClaw releases arrive with ZoPanel updates. OpenClaw migrates its state on start, so back up first (Back up now). Customers ask their provider.

Network limits

The container is cut off from the server's loopback and private networks, from link-local addresses (including the cloud metadata service) and from other containers. On the server itself it reaches only ports 80, 443, 25, 465, 587 and DNS. It has no access to the Docker socket or to host folders: the container is the assistant's sandbox. For OpenClaw:

  • Model providers must be public APIs. A local model server (Ollama, LM Studio, vLLM) on the same server or on a private network cannot be used.
  • Tools that browse, fetch URLs or run commands reach the public internet only, not the server's databases, Redis, the panel or machines on your private network.
  • The operator terminal is a shell inside this container only.

Troubleshooting

Problem What to do
The Browsers card says the app is not ready yet; try again in a minute OpenClaw is still starting (it can take one to two minutes). Refresh the card.
"No browser is waiting" after you connected Connect again in the Control UI, then refresh the Browsers card.
The Control UI rejects the token Copy it again from Login details, without spaces.
The Control UI refuses the origin Open the app at https://<your domain>, not by IP address.
The bot does not answer in Telegram Approve the pairing code; check openclaw channels status --probe. In groups, mention the bot or turn off its privacy mode in BotFather.
Model errors (401, 429, insufficient credit) Check the key and the balance at the provider.
A connection to localhost or a private IP fails Blocked by design; use a public endpoint.
not enough disk space: this app needs about 5.8 GB free… Free disk space, then install again.
The container restarts under load It reached the 2048 MB limit. Reduce concurrent sessions or tools.

Read Application output on the Docker tab for errors from the app.


← Open WebUI Flowise →