跳到正文
FunCoding

搜索

搜索文档、文章、Skill 和 MCP

Policy rule reference

Every supported policy.jsonc rule, the OpenClaw state it observes, and when to use it

Every supported rule namespace, field by field. Part of the openclaw policy reference.

Policy rule reference

Every rule below is optional; a check runs only when the rule is present. The observed state is existing OpenClaw config or workspace metadata.

Channels

Policy fieldObserved stateUse when
channels.denyRules[].when.providerchannels.* provider and enabled stateDeny configured channels from a provider such as telegram.
channels.denyRules[].reasonFinding message and repair hint contextExplain why the provider is denied.

MCP servers

Policy fieldObserved stateUse when
mcp.servers.allowmcp.servers.* idsRequire every configured MCP server to be in an allowlist.
mcp.servers.denymcp.servers.* idsDeny specific configured MCP server ids.

Model providers

Policy fieldObserved stateUse when
models.providers.allowmodels.providers.* ids and selected model refsRequire configured providers and selected model refs to use approved providers.
models.providers.denymodels.providers.* ids and selected model refsDeny configured providers and selected model refs by provider id.

Network

Policy fieldObserved stateUse when
network.privateNetwork.allowPrivate-network SSRF escape hatchesSet to false to require private-network access to stay disabled.

Message routing

Policy fieldObserved stateUse when
routing.requireBindingsChannel route bindings, excluding ACP bindingsRequire at least one message-routing binding.
routing.requireConfiguredChannelsBinding channel ids and configured channels.* idsDetect stale or misspelled binding channel ids.
routing.probes[].routeThe public OpenClaw route resolverDescribe a representative inbound route without sending a message.
routing.probes[].expect.agentIdResolved agent idRequire the route to reach the reviewed agent.
routing.probes[].expect.matchedByResolver match kindRequire peer, account, channel, or other reviewed binding specificity.

Check ids must be unique. A route supports channel, optional accountId, peer, parentPeer, guildId, teamId, and memberRoleIds. Peer kinds are direct, group, and channel. matchedBy may contain one or more runtime match kinds, including binding.peer, binding.account, binding.channel, or default.

Routing checks are conformance checks only. They do not change startup, message delivery, binding precedence, or fallback behavior. Findings require operator review because automatically changing a binding could redirect private messages.

Ingress and channel access

Policy fieldObserved stateUse when
ingress.session.requireDmScopesession.dmScopeRequire a reviewed direct-message isolation scope.
ingress.channels.allowDmPolicieschannels.*.dmPolicy and legacy channel DM policy fieldsAllow only reviewed direct-message channel policies.
ingress.channels.denyOpenGroupsChannel, account, and group ingress policyDeny open group ingress for configured channels and accounts.
ingress.channels.requireMentionInGroupsChannel, account, group, guild, and nested mention gate configRequire mention gates when group ingress is open or mention-gated.

Gateway

Policy fieldObserved stateUse when
gateway.exposure.allowNonLoopbackBindgateway.bindSet to false to require loopback Gateway binding.
gateway.exposure.allowTailscaleFunnelTailscale serve/funnel Gateway postureSet to false to deny Tailscale Funnel exposure.
gateway.auth.requireAuthgateway.auth.modeSet to true to reject disabled Gateway auth.
gateway.auth.requireExplicitRateLimitgateway.auth.rateLimitSet to true to require explicit auth rate-limit config.
gateway.controlUi.allowInsecureDevice-identity invariant and origin fallbackSet to false to require device identity and deny Host-header origin fallback.
gateway.remote.allowRemote Gateway mode/configSet to false to deny remote Gateway mode.
gateway.http.denyEndpointsGateway HTTP API endpointsDeny endpoint ids such as chatCompletions or responses.
gateway.http.requireUrlAllowlistsGateway HTTP URL-fetch inputsSet to true to require URL allowlists on URL-fetch inputs.
gateway.nodes.denyCommandsgateway.nodes.commands.denyRequire exact node command ids such as system.run to be denied in OpenClaw config.

gateway.nodes.denyCommands is an exact, case-sensitive policy deny-superset rule. Use it when policy must prove that privileged node commands are explicitly denied by OpenClaw config. A deployment that intentionally allows a privileged node command should update policy.jsonc after review instead of relying on gateway.nodes.commands.allow alone.

Agent workspace

Policy fieldObserved stateUse when
agents.workspace.allowedAccessagents.defaults.sandbox.workspaceAccess and agents.entries.*.sandbox.workspaceAccessAllow only sandbox workspace access values such as none or ro.
agents.workspace.denyToolsGlobal and per-agent tool deny configRequire mutation tools (exec, process, write, edit, apply_patch) to be denied.

Sandbox posture

Policy fieldObserved stateUse when
sandbox.requireModeagents.defaults.sandbox.mode and per-agent modeAllow only reviewed sandbox modes such as all or non-main.
sandbox.allowBackendsagents.defaults.sandbox.backend and per-agent backendAllow only reviewed sandbox backends such as docker or podman.
sandbox.containers.denyHostNetworkContainer-backed sandbox/browser network modeDeny host network mode.
sandbox.containers.denyContainerNamespaceJoinContainer-backed sandbox/browser network modeDeny joining another container network namespace.
sandbox.containers.requireReadOnlyMountsContainer-backed sandbox/browser mount modeRequire mounts to be read-only.
sandbox.containers.denyContainerRuntimeSocketMountsContainer-backed sandbox/browser mount targetsDeny container runtime socket mounts.
sandbox.containers.denyUnconfinedProfilesContainer security profile postureDeny unconfined container security profiles.
sandbox.browser.requireCdpSourceRangeSandbox browser CDP source rangeRequire browser CDP exposure to declare a source range.

Policy treats missing sandbox.mode as its implicit default off, so sandbox.requireMode reports a fresh or unconfigured sandbox as outside an allowlist such as ["all"].

Data Handling

Policy fieldObserved stateUse when
dataHandling.sensitiveLogging.requireRedactionRuntime invariant oc://openclaw.invariant/logging/redactionSet to true to record the requirement; OpenClaw always satisfies it.
dataHandling.telemetry.denyContentCapturediagnostics.otel.captureContentSet to true to reject telemetry content capture.
dataHandling.retention.requireSessionMaintenancesession.maintenance.modeSet to true to require effective session maintenance mode enforce.
dataHandling.memory.denySessionTranscriptIndexingmemory.search.experimental.sessionMemory, memory.search.rememberAcrossConversations, and per-agent overridesSet to true to reject session transcript indexing into memory.

Secrets

Policy fieldObserved stateUse when
secrets.requireManagedProvidersConfig SecretRefs and secrets.providers.* declarationsSet to true to require SecretRefs to point at declared providers.
secrets.denySourcesSecret provider sources and SecretRef sourcesDeny sources such as exec, file, or another configured source name.
secrets.allowInsecureProvidersInsecure secret-provider posture flagsSet to false to reject providers that opt into insecure posture.

Exec approvals

Exec-approvals checks read the runtime exec_approvals_config singleton row in ~/.openclaw/state/openclaw.sqlite by default, or the same database under $OPENCLAW_STATE_DIR/state when OPENCLAW_STATE_DIR is set. Findings use the stable oc://exec-approvals.json/... URI scheme, which addresses paths within the authoritative JSON document stored in that row. Posture rules under execApprovals.defaults.* or execApprovals.agents.* require readable artifact evidence; a missing or invalid artifact reports as unobservable evidence rather than a best-effort pass. Once readable, omitted fields inherit runtime defaults: missing defaults.security is full, and missing agent security inherits that default. Evidence includes defaults, agents.*, agents.*.allowlist[].pattern, optional argPattern, effective autoAllowSkills posture, and entry source — never socket path/token, commandText, lastUsedCommand, resolved paths, or timestamps.

Policy fieldObserved stateUse when
execApprovals.requireFileActive runtime exec_approvals_config rowSet to true to require the approvals document to exist and parse.
execApprovals.defaults.allowSecuritydefaults.security, defaulting to fullAllow only approved default approval security modes.
execApprovals.agents.allowSecurityagents.*.security, inheriting defaultsAllow only approved per-agent effective approval security modes.
execApprovals.agents.allowAutoAllowSkillsdefaults.autoAllowSkills and agents.*.autoAllowSkills, inheriting runtime defaultsSet to false to require strict manual allowlists without implicit skill CLI approval.
execApprovals.agents.allowlist.expectedAggregate agents.*.allowlist[] pattern and optional argPattern entriesRequire the approvals allowlist to match the reviewed pattern set.

Example: require the approvals artifact, deny permissive defaults, and allow only reviewed exec approval posture for selected agents.

{
  "execApprovals": {
    "requireFile": true,
    "defaults": {
      // Security modes: "deny", "allowlist", or "full".
      // This default permits only the locked-down deny posture.
      "allowSecurity": ["deny"],
    },
  },
  "scopes": {
    "restricted-shell": {
      "agentIds": ["family-agent", "groups-agent"],
      "execApprovals": {
        "agents": {
          // Selected agents may use reviewed allowlist posture, but not "full".
          "allowSecurity": ["allowlist"],
          // false means skill CLIs must appear in the reviewed allowlist instead of
          // being implicitly approved by autoAllowSkills.
          "allowAutoAllowSkills": false,
          "allowlist": {
            "expected": [
              // Simple entry: exact reviewed executable pattern with no argPattern.
              "travel-hub",
              // Constrained entry: pattern plus reviewed argument regex.
              { "pattern": "calendar-cli", "argPattern": "^sync\\b" },
              "/bin/date",
            ],
          },
        },
      },
    },
  },
}

Auth profiles

Policy fieldObserved stateUse when
auth.profiles.requireMetadataauth.profiles.* provider and mode metadataRequire metadata keys such as provider and mode on config auth profiles.
auth.profiles.allowModesauth.profiles.*.modeAllow only supported auth profile modes such as api_key, aws-sdk, oauth, or token.

Tool metadata

Policy fieldObserved stateUse when
tools.requireMetadataGoverned AGENTS.md tool declarationsRequire governed tools to declare metadata keys such as risk, sensitivity, or owner.

Tool posture

Policy fieldObserved stateUse when
tools.profiles.allowtools.profile and agents.entries.*.tools.profileAllow only tool profile ids such as minimal, messaging, or coding.
tools.fs.requireWorkspaceOnlytools.fs.workspaceOnly and per-agent tools.fs overridesSet to true to require workspace-only filesystem tool posture.
tools.exec.allowSecuritytools.exec.security and per-agent exec securityAllow only exec security modes such as deny or allowlist.
tools.exec.requireAsktools.exec.ask and per-agent exec ask modeRequire approval posture such as always.
tools.exec.allowHoststools.exec.host and per-agent exec host routingAllow only exec host routing modes such as sandbox.
tools.elevated.allowtools.elevated.enabled and per-agent elevated postureSet to false to require elevated tool mode to stay disabled.
tools.alsoAllow.expectedtools.alsoAllow and per-agent tools.alsoAllowRequire exact alsoAllow entries and report missing or unexpected additive tool grants.
tools.denyToolstools.deny and agents.entries.*.tools.denyRequire configured tool deny lists to include tool ids or groups such as group:runtime and group:fs.

Tool requirements use the same group membership, aliases, and * matching as core tool policy. For example, group:fs includes ls, group:runtime includes secrets, cron resolves to automations, and the image-understanding tool is view_image. A required deny list must cover every tool in a required group; an empty list covers nothing, and denying write does not deny apply_patch.