Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
144 lines
4.4 KiB
Markdown
144 lines
4.4 KiB
Markdown
---
|
|
name: node-connect
|
|
description: "Diagnose OpenClaw Android, iOS, or macOS node pairing, QR/setup code, route, auth, and connection failures."
|
|
---
|
|
|
|
# Node Connect
|
|
|
|
Goal: find the one real route from node -> gateway, verify OpenClaw is advertising that route, then fix pairing/auth.
|
|
|
|
## Topology first
|
|
|
|
Decide which case you are in before proposing fixes:
|
|
|
|
- same machine / emulator / USB tunnel
|
|
- same LAN / local Wi-Fi
|
|
- same Tailscale tailnet
|
|
- public URL / reverse proxy
|
|
|
|
Do not mix them.
|
|
|
|
- Local Wi-Fi problem: do not switch to Tailscale unless remote access is actually needed.
|
|
- VPS / remote gateway problem: do not keep debugging `localhost` or LAN IPs.
|
|
|
|
## If ambiguous, ask first
|
|
|
|
If the setup is unclear or the failure report is vague, ask short clarifying questions before diagnosing.
|
|
|
|
Ask for:
|
|
|
|
- which route they intend: same machine, same LAN, Tailscale tailnet, or public URL
|
|
- whether they used QR/setup code or manual host/port
|
|
- the exact app text/status/error, quoted exactly if possible
|
|
- whether `openclaw devices list` shows a pending pairing request
|
|
|
|
Do not guess from `can't connect`.
|
|
|
|
## Canonical checks
|
|
|
|
Prefer `openclaw qr --json`. It uses the same setup-code payload Android scans.
|
|
|
|
```bash
|
|
openclaw config get gateway.mode
|
|
openclaw config get gateway.bind
|
|
openclaw config get gateway.tailscale.mode
|
|
openclaw config get gateway.remote.url
|
|
openclaw config get gateway.auth.mode
|
|
openclaw config get gateway.auth.allowTailscale
|
|
openclaw config get plugins.entries.device-pair.config.publicUrl
|
|
openclaw qr --json
|
|
openclaw devices list
|
|
openclaw nodes status
|
|
```
|
|
|
|
If this OpenClaw instance is pointed at a remote gateway, also run:
|
|
|
|
```bash
|
|
openclaw qr --remote --json
|
|
```
|
|
|
|
If Tailscale is part of the story:
|
|
|
|
```bash
|
|
tailscale status --json
|
|
```
|
|
|
|
## Read the result, not guesses
|
|
|
|
`openclaw qr --json` success means:
|
|
|
|
- `gatewayUrl`: this is the actual endpoint the app should use.
|
|
- `urlSource`: this tells you which config path won.
|
|
|
|
Common good sources:
|
|
|
|
- `gateway.bind=lan`: same Wi-Fi / LAN only
|
|
- `gateway.bind=tailnet`: direct tailnet access
|
|
- `gateway.tailscale.mode=serve` or `gateway.tailscale.mode=funnel`: Tailscale route
|
|
- `plugins.entries.device-pair.config.publicUrl`: explicit public/reverse-proxy route
|
|
- `gateway.remote.url`: remote gateway route
|
|
|
|
## Root-cause map
|
|
|
|
If `openclaw qr --json` says `Gateway is only bound to loopback`:
|
|
|
|
- remote node cannot connect yet
|
|
- fix the route, then generate a fresh setup code
|
|
- `gateway.bind=auto` is not enough if the effective QR route is still loopback
|
|
- same LAN: use `gateway.bind=lan`
|
|
- same tailnet: prefer `gateway.tailscale.mode=serve` or use `gateway.bind=tailnet`
|
|
- public internet: set a real `plugins.entries.device-pair.config.publicUrl` or `gateway.remote.url`
|
|
|
|
If `gateway.bind=tailnet set, but no tailnet IP was found`:
|
|
|
|
- gateway host is not actually on Tailscale
|
|
|
|
If `qr --remote requires gateway.remote.url`:
|
|
|
|
- remote-mode config is incomplete
|
|
|
|
If the app says `pairing required`:
|
|
|
|
- network route and auth worked
|
|
- approve the pending device
|
|
|
|
```bash
|
|
openclaw devices list
|
|
openclaw devices approve --latest # preview only; copy the requestId from output
|
|
openclaw devices approve <requestId>
|
|
```
|
|
|
|
If the app says `bootstrap token invalid or expired`:
|
|
|
|
- old setup code
|
|
- generate a fresh one and rescan
|
|
- do this after any URL/auth fix too
|
|
|
|
If the app says `unauthorized`:
|
|
|
|
- wrong token/password, or wrong Tailscale expectation
|
|
- for Tailscale Serve, `gateway.auth.allowTailscale` must match the intended flow
|
|
- otherwise use explicit token/password
|
|
|
|
## Fast heuristics
|
|
|
|
- Same Wi-Fi setup + gateway advertises `127.0.0.1`, `localhost`, or loopback-only config: wrong.
|
|
- Remote setup + setup/manual uses private LAN IP: wrong.
|
|
- Tailnet setup + gateway advertises LAN IP instead of MagicDNS / tailnet route: wrong.
|
|
- Public URL set but QR still advertises something else: inspect `urlSource`; config is not what you think.
|
|
- `openclaw devices list` shows pending requests: stop changing network config and approve first.
|
|
|
|
## Fix style
|
|
|
|
Reply with one concrete diagnosis and one route.
|
|
|
|
If there is not enough signal yet, ask for setup + exact app text instead of guessing.
|
|
|
|
Good:
|
|
|
|
- `The gateway is still loopback-only, so a node on another network can never reach it. Enable Tailscale Serve, restart the gateway, run openclaw qr again, rescan, then approve the pending device pairing.`
|
|
|
|
Bad:
|
|
|
|
- `Maybe LAN, maybe Tailscale, maybe port forwarding, maybe public URL.`
|