OpenClawCAUTION
🦞 MCP server for OpenClaw - secure bridge between Claude.ai and your self-hosted OpenClaw assistant with OAuth2 authentication
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/openclaw-mcp) [](https://github.com/freema/openclaw-mcp/actions/workflows/ci.yml) [](https://opensource.org/licenses/MIT) [](https://github.com/freema/openclaw-mcp/pkgs/container/openclaw-mcp) [](https://openclaw-mcp.cloud)
🦞 Model Context Protocol (MCP) server for OpenClaw AI assistant integration.
Demo
Why I Built This
Hey! I created this MCP server because I didn't want to rely solely on messaging channels to communicate with OpenClaw. What really excites me is the ability to connect OpenClaw to the Claude web UI. Essentially, my chat can delegate tasks to my Claw bot, which then handles everything else — like spinning up Claude Code to fix issues for me.
Think of it as an AI assistant orchestrating another AI assistant. Pretty cool, right?
Quick Start
Docker (Recommended)
Pre-built images are published to GitHub Container Registry on every release.
docker pull ghcr.io/freema/openclaw-mcp:latest
Create a docker-compose.yml:
services: mcp-bridge: image: ghcr.io/freema/openclaw-mcp:latest container_name: openclaw-mcp restart: unless-stopped ports: - "3000:3000" environment: - OPENCLAW_URL=http://host.docker.internal
f425c6c037acOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add openclaw-mcp --env OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} --env OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} -- npx -y [email protected]claude mcp add openclaw-mcp:1.5.0 --env OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} --env OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} -- docker run -i --rm ghcr.io/freema/openclaw-mcp:1.5.0:NoneExposed tools (7)
5 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
openclaw_chat | write | Send a message to OpenClaw and get a response |
openclaw_chat_async | write | Send a message to OpenClaw asynchronously. Returns a task_id immediately that can be polled for results. Use this for potentially long-running conversations. |
openclaw_instances | read | List all configured OpenClaw instances. Shows instance names, URLs, and which is the default. Use instance names in other tools to target a specific OpenClaw gateway. |
openclaw_status | read | Get OpenClaw gateway status and health information |
openclaw_task_cancel | read | Cancel a pending task. Only works for tasks that haven |
openclaw_task_list | read | List all tasks. Optionally filter by status, session, or instance. |
openclaw_task_status | read | Check the status of an async task. Returns status, and result if completed. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
OPENCLAW_URL=http://127.0.0.1:18789
OPENCLAW_URL: http://127.0.0.1:18789
'PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjgiIGhlaWdodD0iMTI4IiB2aWV3Qm94PSIwIDAgMTI4IDEyOCIgZmlsbD0ibm9uZSI+PGRlZnM+PGxpbmVhckdyYWRpZW50IGlkPSJiZyIgeDE9IjAlIiB5MT0iMCUiIHgyPSI
import { OpenClawAuthProvider, OpenClawClientsStore } from '../../auth/provider.js';import { taskManager } from '../../../mcp/tasks/manager.js';import { InstanceRegistry } from '../../../openclaw/registry.js';import { taskManager } from '../../../mcp/tasks/manager.js';} from '../../../mcp/tools/tasks.js';
"OPENCLAW_URL": "http://127.0.0.1:18789",
| `OPENCLAW_URL` | OpenClaw gateway URL | `http://127.0.0.1:18789` |
Matching is exact (scheme, host, path). A common mistake is registering `https://claude.ai/oauth/callback`, which does **not** match and makes Claude.ai fail with `Unregistered redirect_uri`. If you a
@modelcontextprotocol/sdk, yargs, @types/node, @types/yargs, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, eslint-config-prettier
| Unauthorized access | High | OAuth2 authentication, API keys |
curl -fsSL https://openclaw.ai/install.sh | bash
Gates applied: no_behavioural_pass.
f425c6c037acfull audit observations/trust-audit/mcp-server/freema__openclaw.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | f425c6c037ac | CAUTION | B | 89 | first audit |
Questions
What is the OpenClaw MCP server?
🦞 MCP server for OpenClaw - secure bridge between Claude.ai and your self-hosted OpenClaw assistant with OAuth2 authentication
What tools does OpenClaw expose?
7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is OpenClaw safe to connect to an agent?
With care. The audit graded it B (89/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does OpenClaw need?
It reads AUTH_ENABLED, MCP_CLIENT_SECRET, OAUTH_ENABLED and OPENCLAW_GATEWAY_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does OpenClaw run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as openclaw-mcp at 1.7.0.
How current is this page?
The grade is for one exact copy of the source (f425c6c037ac), read on 2026-10-06. The repository is watched and re-audited when it changes.