# OpenClaw

> Install the OpenClaw AI assistant from the App Store with your LLM API key, sign in with the gateway token, approve browsers and connect Telegram, Zalo or WhatsApp.

Source: https://zopanel.net/docs/app-openclaw  
Updated: 2026-10-09

OpenClaw is a self-hosted AI assistant gateway. It connects a large language model (Anthropic, OpenAI, DeepSeek…) to the chat apps you already use, such as Telegram, Zalo and WhatsApp, and gives you a web Control UI to chat, manage sessions, agents and channels. Use it when you want an always-on assistant reachable from your phone's chat apps, with the conversation history kept on your own server.

## Requirements

| Item | Value |
| --- | --- |
| Image | `ghcr.io/openclaw/openclaw:2026.9.8` |
| Memory limit | 2048 MB, 1 CPU. The install dialog warns that the app needs about 2 GB of RAM or more. |
| Free disk to install | about 5.8 GB (the image is about 3.3 GB) |
| Domain | a domain or subdomain pointed to the server, for example `claw.example.com` |
| LLM API key | at least one of Anthropic, OpenAI or DeepSeek. You pay the provider directly. |

Docker must be installed (**App Store → Install Docker**). Customers need a package that allows Docker apps and has 2048 MB of **RAM (MB)** free for apps; see [App limits for customers](/docs/apps#app-limits-for-customers).

## Install

1. Point the domain's A record to the server.
2. Open **App Store** and click **Install** on the **OpenClaw** card.
3. Fill in the dialog. The dialog says "Enter at least one API key (you pay the model provider directly)."

   | Field | What to enter |
   | --- | --- |
   | **Domain** | for example `claw.example.com` |
   | **Owner** | Administrators only: the hosting account the app belongs to |
   | **Anthropic API key** | a key from the Anthropic Console (starts with `sk-ant-`) |
   | **OpenAI API key** | a key from the OpenAI platform |
   | **DeepSeek API key** | a key from the DeepSeek platform |
   | **Free SSL (Let's Encrypt)** | Leave it on |

   Fill in one key or several. An install with no key is refused with `OpenClaw needs at least one API key`. Each value may be up to 512 characters on one line.

4. Click **Install** and follow the task log.

ZoPanel passes the keys to the container as `ANTHROPIC_API_KEY`, `OPENAI_API_KEY` and `DEEPSEEK_API_KEY`, and also:

| Setting | Value |
| --- | --- |
| `OPENCLAW_GATEWAY_TOKEN` | a random 32-character token that protects the Control UI, shown under **Login details** |
| `gateway.bind`, `gateway.mode` | `lan`, `local`: the gateway listens inside the container; the port is published on 127.0.0.1 only and reached through nginx |
| `gateway.trustedProxies` | the Docker bridge, so OpenClaw accepts requests from the website's nginx |
| `gateway.controlUi.allowedOrigins` | `https://<your domain>` and `http://<your domain>` |

The `gateway.*` values are written into `openclaw.json` each time the app starts and when the panel starts. If you change them, ZoPanel puts them back and restarts the app.

The keys cannot be edited from the panel after installation. To use another key later, add it inside OpenClaw (see [Choose the model](#choose-the-model)).

## Sign in and approve your browser

OpenClaw has no setup lock: it is protected by the gateway token and by browser approval, so the domain is public as soon as it is installed.

1. Open **Websites**, choose the domain and go to the **Docker** tab.
2. Under **Login details**, copy `OPENCLAW_GATEWAY_TOKEN`. Only people who can manage the website see it.
3. Open `https://<your domain>`. Paste the token into **Gateway secret** and click **Connect**.
4. OpenClaw asks for this browser to be approved. Go back to the **Docker** tab: the **Browsers** card lists it under **Waiting for approval** with its platform, IP address and time.
5. Click **Approve**. The Control UI opens. Click **Reject** for any request you do not recognise.

Each new browser or device goes through the same approval. Approved ones are listed under **Approved**. The token is kept only in the current browser tab; after approval the browser uses its own device token.

**Important:** anyone with the gateway token can request access, and an approved browser can control the assistant and use your API keys. Keep the token secret.

## Choose the model

OpenClaw uses the providers whose keys it finds. Check or change the default model in the Control UI under **Settings → Models**, or with `/model` in a chat. Set a spending limit in your provider's dashboard: every message, automation and channel uses your key.

The Control UI's operator terminal opens a shell inside the container, where the OpenClaw CLI is available, for example:

```bash
openclaw models list
openclaw channels status --probe
```

If DeepSeek models do not appear, the DeepSeek provider plugin may be missing: `openclaw plugins install @openclaw/deepseek-provider`.

## Connect chat channels

Channels are configured in **Settings → Channels** (under **Connections**) or with the CLI in the operator terminal. OpenClaw applies channel changes without a restart.

**Telegram**

1. In Telegram, chat with **@BotFather**, run `/newbot` and copy the bot token.
2. Add it in **Settings → Channels → Telegram**, or run `openclaw channels add --channel telegram --token <bot-token>`.
3. Send any message to your bot. By default, unknown senders get a pairing code.
4. Approve it in the operator terminal (codes expire after one hour):

   ```bash
   openclaw pairing list telegram
   openclaw pairing approve telegram <CODE>
   ```

**Zalo** (marked experimental by OpenClaw): create a bot at [bot.zaloplatforms.com](https://bot.zaloplatforms.com), set its token in **Settings → Channels**, then approve the first message's pairing code the same way (`openclaw pairing approve zalo <CODE>`).

**WhatsApp**: OpenClaw links as a WhatsApp Web device. Start the login from **Settings → Channels → WhatsApp** and scan the QR code with WhatsApp on your phone (**Linked devices**).

Telegram's default long polling only makes outgoing connections, so it works behind ZoPanel without extra settings.

## Where your data lives

```text
/var/lib/zopanel-apps/<instance>/state/
```

`<instance>` is the domain with dots replaced by hyphens (`claw.example.com` → `claw-example-com`). It is mounted at `/home/node/.openclaw` and holds `openclaw.json`, channel credentials (bot tokens, the WhatsApp session), paired devices, sessions, memory and the agent workspace. Only root and the container can read it.

## Back up

ZoPanel's website backups do **not** include `/var/lib/zopanel-apps`; the **Backups** card on the website's **Docker** tab backs up the app instead.

To back up OpenClaw, click **Back up now** on the **Backups** card of the website's **Docker** tab. Administrators can also set a **Schedule** (**Off**, **Every day** or **Every week**; off by default) and how many copies to **Keep** (1–60, default 7), then click **Save**. Each backup archives `/var/lib/zopanel-apps/<instance>/` into `/var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz`, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) for the few seconds of the copy, so the copy is consistent. Older copies beyond **Keep** are removed, and a failed scheduled backup sends administrators the **Backup failed** alert.

To restore, an administrator clicks **Restore** next to a backup. OpenClaw is stopped and its data replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too. Customers can click **Back up now** and see the list; the schedule and restores are done by the provider.

The archives stay on the same server. Copy important ones off it (for example with `scp` or `rclone` from `/var/backups/zopanel-apps/<instance>/`) and store them encrypted, since they contain your API keys, bot tokens and the WhatsApp session. To restore on another server, install OpenClaw on the same domain there, copy the archive into `/var/backups/zopanel-apps/<instance>/` on the new server and click **Restore** on its **Backups** card. The new install has a new gateway token, shown under **Login details**.

## Update

An administrator clicks **Update to latest** on the **Docker** tab. ZoPanel pulls the image this ZoPanel version is pinned to, recreates the container and keeps the state, keys and token. Newer OpenClaw releases arrive with ZoPanel updates. OpenClaw migrates its state on start, so back up first (**Back up now**). Customers ask their provider.

## Network limits

The container is cut off from the server's loopback and private networks, from link-local addresses (including the cloud metadata service) and from other containers. On the server itself it reaches only ports 80, 443, 25, 465, 587 and DNS. It has no access to the Docker socket or to host folders: the container is the assistant's sandbox. For OpenClaw:

- Model providers must be public APIs. A local model server (Ollama, LM Studio, vLLM) on the same server or on a private network cannot be used.
- Tools that browse, fetch URLs or run commands reach the public internet only, not the server's databases, Redis, the panel or machines on your private network.
- The operator terminal is a shell inside this container only.

## Troubleshooting

| Problem | What to do |
| --- | --- |
| The **Browsers** card says `the app is not ready yet; try again in a minute` | OpenClaw is still starting (it can take one to two minutes). Refresh the card. |
| "No browser is waiting" after you connected | Connect again in the Control UI, then refresh the **Browsers** card. |
| The Control UI rejects the token | Copy it again from **Login details**, without spaces. |
| The Control UI refuses the origin | Open the app at `https://<your domain>`, not by IP address. |
| The bot does not answer in Telegram | Approve the pairing code; check `openclaw channels status --probe`. In groups, mention the bot or turn off its privacy mode in BotFather. |
| Model errors (401, 429, insufficient credit) | Check the key and the balance at the provider. |
| A connection to `localhost` or a private IP fails | Blocked by design; use a public endpoint. |
| `not enough disk space: this app needs about 5.8 GB free…` | Free disk space, then install again. |
| The container restarts under load | It reached the 2048 MB limit. Reduce concurrent sessions or tools. |

Read **Application output** on the **Docker** tab for errors from the app.

## Related

- [What each app does](/docs/app-catalog)
- [App Store and S3 storage](/docs/apps)
- [Open WebUI](/docs/app-open-webui)
- [Flowise](/docs/app-flowise)
- Official: [OpenClaw documentation](https://docs.openclaw.ai), [Control UI](https://docs.openclaw.ai/web/control-ui), [Telegram setup](https://docs.openclaw.ai/channels/telegram/setup)
