跳到正文
FunCoding

搜索

搜索文档、文章、Skill 和 MCP

Feishu access control

Feishu DM policy, group policy, mention gating, and how to find chat and user IDs

Who can talk to the Feishu bot, the group configuration examples that express those rules, and how to look up the IDs they need.

Access control

Direct messages

Configure channels.feishu.dmPolicy (default: pairing) to control who can DM the bot:

ValueBehavior
"pairing"Unknown users receive a pairing code; approve via CLI
"allowlist"Only users listed in allowFrom can chat
"open"Public DMs; config validation requires allowFrom to include "*". Non-wildcard entries still narrow access

Approve a pairing request:

openclaw pairing list feishu
openclaw pairing approve feishu <CODE>

Group chats

Group policy (channels.feishu.groupPolicy, default: allowlist):

ValueBehavior
"open"Respond to all messages in groups
"allowlist"Only respond to groups in groupAllowFrom or explicitly configured under groups.<chat_id>
"disabled"Disable all group messages; explicit groups.<chat_id> entries do not override this

Mention requirement (channels.feishu.requireMention):

  • Default: @mention required, except when the effective group policy is "open"; there it defaults to false so messages that cannot carry mentions (for example images) still reach the agent.
  • Set true or false explicitly to override; per-group override: channels.feishu.groups.<chat_id>.requireMention.
  • Broadcast-only @all and @_all are not treated as bot mentions. A message that mentions both @all and the bot directly still counts as a bot mention.

Mentions of other people stay readable in the text sent to the agent, including when consecutive messages are combined.

Mentions in bot-started threads

Set requireMentionInBotThreads: false to accept messages without an @mention in threads or topics whose root message was sent by this bot. Set it to true to require an @mention in those threads, even when requireMention is false. Omitting the setting preserves the existing mention behavior.

{
  channels: {
    feishu: {
      requireMention: true,
      requireMentionInBotThreads: false,
    },
  },
}

Configure the setting at channels.feishu, under accounts.<id>, or under groups.<chat_id>. The selected group entry takes precedence over the account setting, which takes precedence over the top-level setting. groups["*"] supplies the group entry when no exact group entry exists, matching requireMention.

This applies only to actual threads and topics owned by the current bot. Ordinary quoted replies, threads started by someone else, and roots that cannot be read or verified keep the regular mention policy. Group access, sender allowlists, and bot-message restrictions still apply. Receiving unmentioned group messages also requires the app's im:message.group_msg scope and group message event delivery; this setting does not change which events Feishu sends.

Group configuration examples

Allow all groups, no @mention required

{
  channels: {
    feishu: {
      groupPolicy: "open", // requireMention defaults to false under "open"
    },
  },
}

Allow all groups, still require @mention

{
  channels: {
    feishu: {
      groupPolicy: "open",
      requireMention: true,
    },
  },
}

Allow specific groups only

{
  channels: {
    feishu: {
      groupPolicy: "allowlist",
      // Group IDs look like: oc_xxx
      groupAllowFrom: ["oc_xxx", "oc_yyy"],
    },
  },
}

In allowlist mode, you can also admit a group by adding an explicit groups.<chat_id> entry. Explicit entries do not override groupPolicy: "disabled". Wildcard defaults under groups.* configure matching groups, but they do not admit groups by themselves.

{
  channels: {
    feishu: {
      groupPolicy: "allowlist",
      groups: {
        oc_xxx: {
          requireMention: false,
        },
      },
    },
  },
}

Restrict senders within a group

{
  channels: {
    feishu: {
      groupPolicy: "allowlist",
      groupAllowFrom: ["oc_xxx"],
      groups: {
        oc_xxx: {
          // User open_ids look like: ou_xxx
          allowFrom: ["ou_user1", "ou_user2"],
        },
      },
    },
  },
}

channels.feishu.groupSenderAllowFrom sets the same sender allowlist for all groups; a per-group allowFrom takes precedence.

Bot-authored messages

Feishu ignores messages authored by other bots by default. To allow bot-to-bot group conversations, grant the app the im:message.group_at_msg.include_bot:readonly and im:message:readonly scopes, then set allowBots:

{
  channels: {
    feishu: {
      allowBots: true,
    },
  },
}

Feishu only delivers bot-authored group events when another bot mentions this bot. Existing group policy, sender allowlists, and mention requirements still apply. OpenClaw drops self-authored messages, mentions the peer bot on every text or card reply, and applies the shared channels.defaults.botLoopProtection guard.

Get group/user IDs

Group IDs (chat_id, format: oc_xxx)

Open the group in Feishu/Lark, click the menu icon in the top-right corner, and go to Settings. The group ID (chat_id) is listed on the settings page.

Get Group ID

User IDs (open_id, format: ou_xxx)

Start the gateway, send a DM to the bot, then check the logs:

openclaw logs --follow

Look for open_id in the log output. You can also check pending pairing requests:

openclaw pairing list feishu