Files
adolf/docs/channels/nextcloud-talk.md
alvis bedb527145
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Vendor OpenClaw source as Adolf fork baseline
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11),
free to diverge. Tree copied sans upstream .git; upstream remote added for
future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19.
Preserves docs/ARCHITECTURE.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
2026-07-05 09:36:54 +00:00

7.7 KiB

summary, read_when, title
summary read_when title
Nextcloud Talk support status, capabilities, and configuration
Working on Nextcloud Talk channel features
Nextcloud Talk

Nextcloud Talk is a downloadable channel plugin (@openclaw/nextcloud-talk) that connects OpenClaw to a self-hosted Nextcloud instance through a Talk webhook bot. Direct messages, rooms, reactions, and markdown messages are supported; media goes out as URLs.

Install

openclaw plugins install @openclaw/nextcloud-talk

Use the bare package spec to follow the current official release tag. Pin an exact version only when you need a reproducible install.

From a local checkout (dev workflows):

openclaw plugins install ./path/to/local/nextcloud-talk-plugin

Restart the gateway after installing. Details: Plugins

Quick setup (beginner)

  1. Install the plugin (above).

  2. On your Nextcloud server, create a bot:

    ./occ talk:bot:install "OpenClaw" "<shared-secret>" "<webhook-url>" --feature webhook --feature response --feature reaction
    

    Keep --feature response: without it, outbound replies fail with 401. Repair an existing bot with ./occ talk:bot:state --feature webhook --feature response --feature reaction <botId> 1.

  3. Enable the bot in the target room settings.

  4. Configure OpenClaw:

    • Config: channels.nextcloud-talk.baseUrl + channels.nextcloud-talk.botSecret
    • Or env: NEXTCLOUD_TALK_BOT_SECRET (default account only)

    CLI setup (--url/--token are aliases for the explicit fields; nc-talk and nc work as channel aliases):

    openclaw channels add --channel nextcloud-talk \
      --url https://cloud.example.com \
      --token "<shared-secret>"
    

    Equivalent explicit fields:

    openclaw channels add --channel nextcloud-talk \
      --base-url https://cloud.example.com \
      --secret "<shared-secret>"
    

    File-backed secret:

    openclaw channels add --channel nextcloud-talk \
      --base-url https://cloud.example.com \
      --secret-file /path/to/nextcloud-talk-secret
    
  5. Restart the gateway (or finish setup).

Minimal config:

{
  channels: {
    "nextcloud-talk": {
      enabled: true,
      baseUrl: "https://cloud.example.com",
      botSecret: "shared-secret",
      dmPolicy: "pairing",
    },
  },
}

Notes

  • Bots cannot initiate DMs. The user must message the bot first.
  • The webhook URL must be reachable from the Nextcloud server; set webhookPublicUrl when the gateway sits behind a proxy. Webhook requests are HMAC-SHA256 signed with the bot secret; invalid signatures are rejected and rate limited.
  • Media uploads are not supported by the bot API; outbound media is appended as an Attachment: <url> line.
  • The webhook payload does not distinguish DMs from rooms; set apiUser + apiPassword to enable room-type lookups (cached about 5 minutes). Without them, every conversation is treated as a room.
  • Outbound requests go through the SSRF guard. For a Nextcloud host on a trusted private/internal network, opt in with channels.nextcloud-talk.network.dangerouslyAllowPrivateNetwork: true.
  • With apiUser/apiPassword and webhookPublicUrl set, openclaw channels status probes the bot and warns when the response feature is missing.

Access control (DMs)

  • Default: channels.nextcloud-talk.dmPolicy = "pairing". Unknown senders get a pairing code.
  • Approve via:
    • openclaw pairing list nextcloud-talk
    • openclaw pairing approve nextcloud-talk <CODE>
  • Public DMs: channels.nextcloud-talk.dmPolicy="open" plus channels.nextcloud-talk.allowFrom=["*"].
  • allowFrom matches Nextcloud user IDs only (lowercased); display names are ignored.

Rooms (groups)

  • Default: channels.nextcloud-talk.groupPolicy = "allowlist" (mention-gated).
  • Allowlist rooms with channels.nextcloud-talk.rooms, keyed by room token; "*" sets a wildcard default:
{
  channels: {
    "nextcloud-talk": {
      rooms: {
        "room-token": { requireMention: true },
      },
    },
  },
}
  • Per-room keys: requireMention (default true), enabled (false disables the room), allowFrom (per-room sender allowlist), tools (allow/deny tool overrides), skills (limit loaded skills), systemPrompt.
  • To allow no rooms, keep the allowlist empty or set channels.nextcloud-talk.groupPolicy="disabled".

Capabilities

Feature Status
Direct messages Supported
Rooms Supported
Threads Not supported
Media URL-only
Reactions Supported
Native commands Not supported

Configuration reference (Nextcloud Talk)

Full configuration: Configuration

Provider options:

  • channels.nextcloud-talk.enabled: enable/disable channel startup.
  • channels.nextcloud-talk.baseUrl: Nextcloud instance URL.
  • channels.nextcloud-talk.botSecret: bot shared secret (string or secret reference).
  • channels.nextcloud-talk.botSecretFile: regular-file secret path. Symlinks are rejected.
  • channels.nextcloud-talk.apiUser: API user for room lookups (DM detection) and the status probe.
  • channels.nextcloud-talk.apiPassword: API/app password for room lookups.
  • channels.nextcloud-talk.apiPasswordFile: API password file path.
  • channels.nextcloud-talk.webhookPort: webhook listener port (default: 8788).
  • channels.nextcloud-talk.webhookHost: webhook host (default: 0.0.0.0).
  • channels.nextcloud-talk.webhookPath: webhook path (default: /nextcloud-talk-webhook).
  • channels.nextcloud-talk.webhookPublicUrl: externally reachable webhook URL.
  • channels.nextcloud-talk.dmPolicy: pairing | allowlist | open | disabled (default: pairing). open requires allowFrom=["*"].
  • channels.nextcloud-talk.allowFrom: DM allowlist (user IDs).
  • channels.nextcloud-talk.groupPolicy: allowlist | open | disabled (default: allowlist).
  • channels.nextcloud-talk.groupAllowFrom: room sender allowlist (user IDs); falls back to allowFrom when unset.
  • channels.nextcloud-talk.rooms: per-room settings and allowlist (see above).
  • Static sender access groups can be referenced from allowFrom and groupAllowFrom with accessGroup:<name>.
  • channels.nextcloud-talk.historyLimit: group history limit (0 disables).
  • channels.nextcloud-talk.dmHistoryLimit: DM history limit (0 disables).
  • channels.nextcloud-talk.dms: per-DM overrides keyed by user ID (historyLimit).
  • channels.nextcloud-talk.textChunkLimit: outbound text chunk size in chars (default: 4000).
  • channels.nextcloud-talk.chunkMode: length (default) or newline to split on blank lines (paragraph boundaries) before length chunking.
  • channels.nextcloud-talk.blockStreaming: disable block streaming for this channel.
  • channels.nextcloud-talk.blockStreamingCoalesce: block streaming coalesce tuning.
  • channels.nextcloud-talk.responsePrefix: outbound reply prefix.
  • channels.nextcloud-talk.markdown.tables: markdown table rendering mode (off | bullets | code | block).
  • channels.nextcloud-talk.mediaMaxMb: inbound media cap (MB).
  • channels.nextcloud-talk.network.dangerouslyAllowPrivateNetwork: allow private/internal Nextcloud hosts past the SSRF guard.
  • channels.nextcloud-talk.accounts.<id>: per-account overrides (same keys); defaultAccount picks the default. Env vars NEXTCLOUD_TALK_BOT_SECRET / NEXTCLOUD_TALK_API_PASSWORD apply to the default account only.