OpenClaw on AI Coach

How to get an assistant running, how to run it day to day, and a standalone OpenClaw reference for when you are working on the instance itself.

Part 3 is not about AI Coach. It is a plain OpenClaw cheatsheet, useful whether you bought anything from us or not. Parts 1 and 2 are the AI Coach side. If you are here to fix an instance, skip to it.

1. Run your Assistant agent with AI Coach

An Assistant is one OpenClaw instance that is yours alone: its own container, its own state, its own channel accounts. Nobody else's assistant shares it, because OpenClaw's trust boundary is the Gateway process itself.

Two ways in

Managed, from $29/mo

We provision the instance, apply the guardrails, meter the model spend and monitor it. A delivery partner sets it up with you. This is most people.

Bring your own

You already run OpenClaw and want AI Coach to hold the order, the credentials and the handover around it. You keep the box and everything on it.

Ordering a managed one

Go to /openclaw/order. Three things decide what you pay:

ChoiceWhat it means
Plan How many cells and channels, how fast we answer, and whether you get a hardened runtime and version pinning.
Payment In full, a 25% booking deposit, or a free first month. The balance on a deposit is taken only when you confirm handover, and never if you do not.
Intake What you want it to watch and what it may act on. This seeds its memory as facts it cannot overwrite, and your partner works from it.

Be specific in the intake. The more precisely you describe what you want watched, the less of the first call is spent working it out.

Bringing your own

Install OpenClaw (part 3 has the commands), then send AI Coach three values:

  • • The Gateway URL it answers on
  • • OPENCLAW_GATEWAY_TOKEN
  • • OPENCLAW_GATEWAY_PASSWORD

Both secrets are encrypted here and revealed one at a time, to you and to your partner, with every read logged and visible to you.

Connecting does not reconfigure your instance. A self-installed assistant gets no guardrail profile, no metered model gateway and therefore no spend cap, no patching, and no SLA. Those belong to instances AI Coach provisioned. What you get is the order, the credential handling, a delivery partner and the record.

What happens next

  1. 1 Ordered. Payment clears. You get a receipt saying what was taken and what is still conditional.
  2. 2 Partner assigned. We email a delivery partner with your spec and copy you in. Reply-all and you are talking to them directly.
  3. 3 Instance deployed. AI Coach builds the cell, applies the guardrails, and checks it answers before telling anyone.
  4. 4 Onboarding. Your partner pairs channels, installs skills, connects servers and seeds memory with you.
  5. 5 You confirm. Only when it does what you asked. That starts your plan and your support cover.

Track it on your assistant page. Nothing recurring is billed until the last step.

Confirming handover

Your partner marks the work delivered; that asks you a question rather than announcing an answer. Check it does what you asked, then confirm. Confirming starts your monthly plan, starts your support cover, starts the SLA clock, and settles any remaining balance on the card you booked with.

If it is not right, do not confirm. Email your partner and say what is missing. If they go quiet, tell us: we reassign the order or refund the booking.

2. Manage your Assistant with AI Coach

Everything below lives on /account/assistant.

What it may do without you

Three tiers. Every assistant is handed over on Draft, and only you can raise it.

Observe

Reads, summarises, watches, answers. Nothing leaves your account. Most of the value is here and it cannot cause an incident.

Draft — where you start

Writes the email, the reply, the post, then holds it for your tap. The default for anything leaving your account.

Act

Sends, books, pays, deletes. Granted one tool at a time, revocable, always logged. Worth leaving off until you have watched it work for a few weeks.

What it may spend

The plan fee covers the cell and the support. Model usage is separate, metered against your wallet at cost plus a disclosed markup. A monthly cap is on by default and enforced in the control plane, not inside the assistant, so a compromised or looping agent cannot exceed it.

Reaching the cap stops model spend. It does not stop your plan fee, and it does not delete anything.

Credentials

You get two, revealed one at a time on your account page:

CredentialForWho else has it
Gateway passwordSigning in to the Control UIYour partner
Gateway tokenThe CLI and API, for pushing config changesYour partner
Heartbeat / model keyMonitoring and metered spendAI Coach only

Every reveal is recorded. Expand Who has seen this login to see every read including ours. Change the password on first sign-in.

Asking for something

Raise a request from your assistant page. Where it goes depends on what it is about:

  • • Setup and configuration go to your delivery partner. Pairing a channel, adding a skill, changing what it watches.
  • • Billing, access and incidents come to AI Coach. Your partner cannot act on those.

The form tells you where it is going before you write it. Everything stays on the record, both sides can read the thread, and you get an email when it is answered.

Support windows

Hosting your assistant means we are technically able to reach it. That is true of every managed host and most do not mention it. What we commit to instead:

  • • Access needs a window you open, with a reason and a scope.
  • • Every window expires on its own, at most 72 hours. There is no open-ended option.
  • • You can see whether it was actually used, and close it at any moment.
  • • Your partner can ask for one. Only you can open it.

Billing

/account/billing shows what you were charged, what recurs, and what has not been charged yet, alongside your wallet usage. Invoices and your card live in the Stripe portal, linked from the same page.

Updates

ChangeNoticeOpt out
Critical security patchWithin 24hNone
Minor version48 hoursDefer once
Major version14 days30 days, then required
Upstream abandons the project60 daysFull export

If it goes quiet

Your cell reports in every five minutes. If it stops for an hour we email you before you notice, and the incident lands on your timeline. You should hear it from us rather than from your assistant not replying. If you notice first, raise an incident request.

3. OpenClaw setup, config and operation cheatsheet

Nothing in this section is about AI Coach. It is a plain OpenClaw reference for working on an instance, whoever runs it. Checked against the CLI and configuration references in September 2026; the project releases often, so verify at docs.openclaw.ai if a flag is rejected.

Install

npm install -g openclaw
openclaw --version

Docker

docker run -d --name openclaw \
  -p 127.0.0.1:18789:18789 \
  -v ~/openclaw-data:/data \
  -e OPENCLAW_CONFIG_PATH=/data/openclaw.json \
  -e OPENCLAW_STATE_DIR=/data/state \
  -e OPENCLAW_GATEWAY_TOKEN="$(openssl rand -hex 32)" \
  ghcr.io/openclaw/openclaw:2026.9.1

Onboard

A fresh install has no model provider, no gateway auth and no workspace until this runs.

openclaw onboard                    # guided
openclaw setup --baseline           # config + workspace, no wizard
openclaw configure --section model  # change one part later

Non-interactive

Both flags are required. --accept-risk acknowledges that an agent with system access is a serious thing; the CLI refuses without it.

openclaw onboard \
  --non-interactive --accept-risk --skip-health \
  --mode local --gateway-bind loopback \
  --secret-input-mode ref \
  --auth-choice apiKey --anthropic-api-key "$ANTHROPIC_API_KEY" \
  --json

Onboard flags worth knowing

FlagDoes
--secret-input-mode refStores credentials as environment references, not plaintext. The config stops being a file full of working keys.
--gateway-bind loopbackLocalhost only. Use with a reverse proxy.
--install-daemonManage a local Gateway as a service. Omit if pointing at a remote one.
--skip-healthConfiguration only. Absence of a gateway is informational, not fatal.
--skip-bootstrapNo default workspace files, for pre-seeded automation.
--jsonMachine-readable output. Does not imply non-interactive.

A custom or proxied provider

openclaw onboard --non-interactive --accept-risk --skip-health \
  --mode local --auth-choice custom-api-key \
  --custom-provider-id my-gateway \
  --custom-base-url "https://llm.example.com/v1" \
  --custom-model-id "claude-sonnet-4-6" \
  --custom-api-key "$CUSTOM_API_KEY" \
  --custom-compatibility anthropic \
  --gateway-bind loopback

Config and environment

One JSON5 file, plus environment variables. The file defaults to ~/.openclaw/openclaw.json.

openclaw config get                      # everything
openclaw config get gateway.auth         # one subtree
openclaw config set gateway.port 18789
openclaw config patch '{"gateway":{"bind":"loopback"}}'
VariableMeaning
OPENCLAW_CONFIG_PATHConfig file location. Default ~/.openclaw/openclaw.json.
OPENCLAW_STATE_DIRState directory: sessions, memory, the SQLite store.
OPENCLAW_GATEWAY_TOKENShared secret for CLI and API.
OPENCLAW_GATEWAY_PASSWORDShared secret for signing in.
ANTHROPIC_API_KEYAnthropic. Also OPENAI_API_KEY, XAI_API_KEY, OPENCODE_API_KEY.
--profile <name>Flag, not a variable. Uses an alternate state directory.
Do not move credentials by copying files. Copying auth-profiles.json or replacing the SQLite databases between installs is explicitly unsupported and will leave you with an instance that half works. Re-run configure on the target instead.

Gateway

openclaw gateway install    # run it as a service
openclaw gateway start
openclaw gateway stop
openclaw gateway restart
openclaw gateway status

Default port is 18789. Resolution order is flag, then environment, then config, then the default.

Bind modes: loopback (default), lan, tailnet, custom. Behind a reverse proxy, set gateway.auth.mode to trusted-proxy.

It refuses to start on a non-loopback bind with no auth. That is deliberate and it is doing you a favour: it makes accidentally publishing your agent to the network a startup failure rather than a silent exposure.

Models

openclaw models auth list
openclaw models auth add
openclaw models auth login          # prints a URL, paste the token back
openclaw models list
openclaw models set <model-id>
openclaw models status              # add --agent <id> for one agent

Channels and plugins

Two commands, not one: a plugin needs explicit consent before it can be installed.

openclaw plugins install telegram --accept-capabilities
openclaw channels add --channel telegram --token "$BOT_TOKEN"
openclaw channels list
WhatsApp. Automating a personal account breaches Meta's terms. Numbers get restricted with no pattern anyone has found. Telegram, Slack, Discord or a WhatsApp Business API number carry no such risk.

Agents and profiles

openclaw agents add work \
  --workspace ~/.openclaw/workspace-work \
  --model openai/gpt-5.6-sol \
  --bind whatsapp:biz \
  --non-interactive --json

Separate installs side by side on one machine:

OPENCLAW_CONFIG_PATH=~/.openclaw/a.json \
OPENCLAW_STATE_DIR=~/.openclaw-a \
  openclaw gateway start

openclaw --dev ...        # isolates state in ~/.openclaw-dev

Profiles are process isolation, not tenant isolation. Two people who do not trust each other need two complete instances, because an authenticated operator inside a Gateway holds a trusted role over everything in it.

Health and updates

openclaw status --json      # machine-readable health
openclaw doctor             # diagnose and repair state
openclaw update             # rolls back if the post-update doctor fails

update checks readiness before restarting, preserves configuration and secret references across a failed upgrade, and hands failures to a triage agent. Global flags worth remembering: --json, --log-level, --profile, --dev, --no-color.

Troubleshooting

SymptomUsually
Refuses to bindNon-loopback bind with no auth. Set a token, or bind loopback and proxy.
Port in useA previous instance is still running, or something else holds 18789.
Onboarded but no modelWith ref mode the key is a reference: the Gateway process needs that variable too. Check models status.
Channel stopped replyingThe session expired or the account was restricted. Re-pair it.
Broken after an updateopenclaw doctor, then the sanitized failure context the updater kept.
Anything elseopenclaw doctor first. It repairs most legacy state problems.

Hardening, whoever runs it

# Take the shell away from anything reachable from a message.
openclaw config set agents.defaults.tools.deny '["exec","shell","bash"]'

# Hold outbound actions for approval rather than sending them.
openclaw config set agents.defaults.approvals.outbound required

Then, outside OpenClaw: default-deny outbound networking restricted to the services you approved, and patch quickly. In July 2026 a researcher chained three OpenClaw flaws from one WhatsApp message to credential theft, a sandbox escape and code execution on the host. All were patched; the shape of the risk is permanent.

Want the managed version?

Isolated, hardened, patched, monitored, and set up with you by a delivery partner. Model spend metered against your wallet with a cap, rather than an unbounded API key.

See what it costs →

OpenClaw is open-source software published by third parties under the MIT licence, and its name and logo are their trademarks. AI Coach is not affiliated with OpenClaw AI and provides hosting, setup and support services only.