Skip to main content

What is OpenClaw?

OpenClaw is a setup tool that lets Knotie Agency Partners deploy a production-ready AI assistant for their customers — on a VPS they control, routed through the Knotie AI Gateway. Think of it as a “one-click deploy” for an AI agent that:
  • Runs on your customer’s own server (Linux VPS)
  • Is accessible only over a private Tailscale network (no public internet exposure)
  • Comes pre-configured with CRM integrations, calendar sync, and memory
  • Lets the partner earn a margin on every AI call their customer makes

How it works

The partner sets the pricing for their customer — Knotie bills the partner at wholesale rates, and the partner marks up for profit.

Prerequisites

Before running the setup, you need:

Setting up Tailscale

  1. Create a free account at tailscale.com
  2. Go to Settings → Keys and create an auth key
  3. Save the key — you’ll paste it during the setup script

Creating Knotie credentials

  1. In the Partner Portal, go to Settings → API Keys
  2. Create a new key with AI Gateway scope
  3. Go to Settings → MCP Tokens and create a token for the customer
  4. Keep both ready — you’ll need them during setup

Running the setup

Connect to your VPS as root (or with sudo access), then run:
The script will ask for:
  • Customer name — used as the agent’s display name and slug
  • Knotie API Key — your partner API key
  • Model ID — defaults to claude-opus-4-6
  • Tailscale auth key — from your Tailscale admin panel
  • Tailscale hostname — e.g. openclaw-acme-corp
  • Knotie MCP Token — from the Partner Portal

What the script installs

The setup script installs and configures:

Managing deployed agents

Check gateway status

View agent logs

Restart the gateway

Run the health enforcer manually

Access the gateway UI

The gateway is only accessible over Tailscale — not on the public internet. Once Tailscale is connected, access it at:
On first access, you’ll need to approve the device:

Updating the agent

To re-run the setup (e.g., to update the model or MCP token):
The script detects existing installations and skips already-configured steps. To do a full reset and clean uninstall:
This removes OpenClaw, Tailscale, all config, and the memory/workspace directory. A backup archive is saved to /tmp/openclaw-backup-YYYYMMDD-HHMMSS.tar.gz.

Channel Chat (portal-to-agent messaging)

When OpenClaw is deployed via the VPS App Catalog, the setup script also configures a hardened channel endpoint on port 18790. This lets the Knotie Partner Portal send chat messages to the OpenClaw agent over the public internet — authenticated with multiple layers of security.

How it works

The portal never talks directly to the gateway — nginx acts as a security front-end that enforces:
  1. TLS — self-signed 4096-bit RSA certificate, valid for 10 years
  2. Knock header — every request must include X-Knotie-Gateway: <knock-secret>; missing or wrong header returns 444 No Response (nginx drops the connection silently)
  3. Rate limiting — max 10 requests/minute per IP, max 3 concurrent connections per IP
  4. Bearer token — constant-time comparison via timingSafeEqual
  5. HMAC nonce — timestamp + nonce signed with SHA-256, with a ±5 minute replay window

Channel response shape

Successful chat responses return:

Environment variables written during setup

The install script writes a /root/.openclaw/channel.env file with these variables: A systemd drop-in at /root/.config/systemd/user/openclaw-gateway.service.d/knotie-env.conf ensures these variables are loaded into the gateway process on every start. Without this drop-in, process.env.KNOTIE_CHANNEL_TOKEN is undefined inside the channel plugin, causing every chat call to return 503 misconfigured.

Configuration reference

These values are set during install and stored in ~/.openclaw/openclaw.json:

Troubleshooting

Tailscale serve not working
  • Check that Tailscale Serve is enabled in your tailnet: login.tailscale.com/admin/settings
  • Look for: Allow nodes to connect to the Tailnet Service (Serve) and Funnel
  • Re-run the setup script after enabling
Gateway not responding
Agent not using Knotie Gateway The knotie-guard.sh cron runs hourly and will restore the correct config automatically. To manually check:
Only knotie-provider should be present. Channel chat returns 503 misconfigured The gateway process is not seeing the channel environment variables. Check whether the systemd drop-in was written:
If the file is missing, re-run the catalog deploy for OpenClaw. If it exists but the issue persists, reload the service:
nginx not listening on the channel port after deploy If the channel endpoint is unreachable immediately after install, check whether nginx loaded the new config:
A common cause is a limit_conn directive syntax error. The correct form is limit_conn knotie_cn 3 (no zone= prefix). If you see zero size shared memory zone in the error log, run:
Catalog deploy fails immediately with apt lock error When you click Deploy on a freshly provisioned VPS, cloud-init may still be running its own apt-get in the background. The deploy script now waits up to 5 minutes for the lock to release automatically. If you see this error in the deploy log, wait a few minutes and retry the catalog deploy from the portal — no manual intervention is needed. Gateway config shows gateway.token instead of gateway.auth The gateway configuration schema changed in OpenClaw 2026.5.x. The Knotie API key is now stored under gateway.auth.token (not the top-level gateway.token). The install script migrates the config automatically. To verify:
If gateway.auth is missing, re-run the catalog deploy for OpenClaw. Support
Knotie AI Pro Partner Portal — VPS / App Catalog where OpenClaw is deployed