We’re rebuilding ClawControl. Sign-ups are paused until v2 launches.

Documentation

Provider auth

Understand the planned provider auth workflow and how it is intended to simplify credential management across runtimes.

Coming SoonAlpha

What provider auth is meant to solve

Today, provider credentials are managed directly in the OpenClaw environment on the runtime host.

Provider auth is intended to make that easier by giving ClawControl a structured way to:

  • store workspace-level provider credentials
  • validate whether those credentials are usable
  • attach them to the right runtime
  • sync the right credentials to the right host

What the future workflow is designed to look like

The planned experience is centered around the Providers area in settings.

At a high level, teams will be able to:

  • add provider credentials for a workspace
  • support different provider auth methods, such as API keys and selected OAuth flows
  • attach a provider credential to a runtime
  • test whether a credential is working
  • retry sync when a runtime needs the credential reapplied

Planned launch support

The current launch catalog in the product contracts includes the following providers and auth modes:

At launch, the only planned OAuth-based provider in the current catalog is OpenAI Codex. The other planned launch providers use API-key authentication.

Why this matters

As teams add more runtimes and more agents, local credential setup becomes harder to manage consistently. Provider auth is meant to reduce that overhead and give operators better visibility into what is connected where.

What will stay the same

Even after provider auth is available, ClawControl will still be coordinating credential usage rather than bundling model access itself.

In practical terms:

  • teams will still use their own AI provider accounts
  • model usage will still depend on those provider accounts
  • ClawControl will help manage the operational side of attaching and syncing credentials

What to do today

Until provider auth is available, manage provider authentication directly in your OpenClaw environment on the runtime host.

For example, the runtime setup flow still depends on the local OpenClaw side having usable auth profiles when agents need provider access.