1. Front page
  2. Set-up
  3. OpenClaw
Set-up · about 30 minutes

How to install OpenClaw: setup guide with Telegram

Allow about half an hour to go from a bare machine to a self-hosted agent that answers in Telegram and follows rules you wrote yourself.

Step by step

  1. Choose where it will run

    A laptop is fine for trying OpenClaw, but an agent you want reachable at all hours is better off on always-on hardware such as a home server or rented VPS, since it can only answer while its machine is running. Whichever you pick, the gateway port must never face the open internet.

  2. Install OpenClaw

    Use the official installer that matches your system. It detects the operating system, fills in Node where it is absent, sets up OpenClaw and then hands over to onboarding.

    # macOS / Linux / WSL2
    curl -fsSL https://openclaw.ai/install.sh | bash
    
    # Windows (PowerShell)
    iwr -useb https://openclaw.ai/install.ps1 | iex
  3. Onboard and run the gateway as a service

    Onboarding offers Quick start, which reuses any AI access it finds, or Custom setup with every option exposed. Once it is done, end the foreground gateway and register it as a service in the background, which brings it back automatically after a restart.

    openclaw onboard
    # stop the foreground gateway with Ctrl+C, then run it as a service:
    openclaw gateway install
  4. Connect Telegram

    In Telegram, open a chat with @BotFather, double-checking the handle, send /newbot and keep the token you are given. Register Telegram as a channel using that token, and run a status probe to check the connection.

    openclaw channels add --channel telegram --token <bot-token>
    openclaw channels status --probe
  5. Approve pairing

    Send your bot a message. Rather than replying, it gives unfamiliar senders a pairing code, so look through the waiting requests and approve yours before the hour is up.

    openclaw pairing list telegram
    openclaw pairing approve telegram <CODE>
  6. Run the security audit and stay updated

    Let OpenClaw's own security audit check the setup and resolve whatever it raises, then pull updates from the stable channel. Anything released before 2026.4.22 is exposed to known critical vulnerabilities, so make both commands a routine.

    openclaw security audit
    openclaw update --channel stable
  7. Write its standing rules

    Set out your rules in plain language in AGENTS.md in the agent's workspace, and put matching hard limits in ~/.openclaw/openclaw.json, checking key names against the docs for your version. Keep dmPolicy on pairing, and have exec approvals ask every time until you are confident in the setup.

The first week

Treat the first week as a trial run. The gateway should stay on loopback, with access through Tailscale or SSH rather than an exposed port. Leave shell commands on approval, add third-party skills sparingly and only from publishers you know, and watch your model usage daily, because an agent caught in a loop keeps spending tokens. Rerun the security audit after every change to the configuration.

Mistakes to avoid

  • Exposing the gateway to the internet rather than leaving gateway.bind set to loopback.
  • Installing a pile of third-party skills, which deserve the same suspicion as browser extensions.
  • Running an outdated release; every version older than 2026.4.22 carries known critical vulnerabilities.