Deploy and manage self-hosted OpenClaw instances across clouds
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
MCP-native infrastructure ops for OpenClaw β with read-only mode, destructive-action confirmation, and audit logs built in.
clawops is a CLI and MCP server for deploying and operating self-hosted OpenClaw instances. Provision on AWS, GCP, Azure, or any Linux VM β then manage day-to-day operations from the terminal, or let Claude Code and Cursor drive them through typed MCP tools with explicit safety controls.
README maintenance. The release-notes section had grown to four versions and was missing
v1.7.2 entirely. It now carries the current line only; CHANGELOG.md remains the
full history.
Requires OpenClaw >= 2026.9.2. This line deploys the 2.0 runtime contract: a writable state
directory holding config, SQLite and plugins; gateway.mode written into the config; no
--allow-unconfigured. A pre-2.0 OpenClaw understands none of it, so doctor, plan, up and
apply refuse anything below the floor. For OpenClaw <= 2026.7.1-2, use
npm install -g @clawops/cli@legacy.
The support range in spec/openclaw-versions.yaml was previously unbounded and read by no code,
so any OpenClaw release was accepted. Moving tags are now resolved to a concrete version before
the range check, and an unresolved tag is refused rather than assumed safe β latest and stable
both point at 2.0 today. The default is now a concrete pin.
clawops doctor --stack <name> reports the version a deployed gateway is actually running, so an
existing deployment that already picked up 2.0 through a moving tag can be identified.
clawops config set now applies. It never has. The config clawops mounted was read by nothing
on either OpenClaw line β models, channels and auth mode were silently discarded. Setting
OPENCLAW_CONFIG_PATH fixes it, with four guards: gateway.port normalisation (with a warning),
an argv --port pin, a parse check, and a post-restart health gate. The MCP gateway restart
tool, which dropped the config mount entirely, now matches the CLI path.
A fresh local deployment starts. OpenClaw refuses a non-loopback bind without auth and always
binds 0.0.0.0 in a container, and the bootstrap never supplied a token β so the gateway exited 78
and systemd restart-looped. A token is now generated once, kept in a 0600 env file, and passed
via --env-file, never on the command line.
Ollama is reachable. localhost inside the container is the container. clawops now passes
--add-host=host.docker.internal:host-gateway and defaults the Ollama address to match.
Packaging. spec/ was missing from the published files, and neither it nor
bootstrap.sh.tmpl resolved from the bundle β so clawops plan and clawops up --provider local
failed from an npm install. Both are now shipped and resolved correctly.
SSH host keys. The verifier read each known_hosts line's key type as the key, so any
standard entry failed permanently with Host denied. Standard entries now parse, including
comma-separated host lists, [host]:port, hashed hostnames, @revoked / @cert-authority
markers, and wildcard and negated patterns.
Behaviour change: a host covered by a wildcard whose key does not match is now refused where it previously connected. Ignoring wildcards meant trust-on-first-use accepted a key your own
known_hostscontradicted. This matches OpenSSH.
pulumi binary required).--json) for scripting and automation.docs/limitations.md for the manual path.~/.clawops/config.json.docs/support-matrix.md.clawops setup is an interactive wizard that gets OpenClaw running in about 2 minutes. It
handles everything in one flow β no config files to write by hand, no commands to memorize.
Step 1 β Choose a deployment target
Pick an existing server you can SSH into (Linux or macOS), or a new cloud VM on AWS, GCP, or Azure. Cloud deployments walk you through authenticating with the provider CLI if you aren't already signed in.
Step 2 β Pick an LLM provider
Choose from Anthropic, OpenAI, Amazon Bedrock, Ollama, or others. The wizard prompts for your
API key and saves it locally (in ~/.clawops/secrets/, chmod 600) β it is never sent anywhere
except to OpenClaw on the target host when the config is applied.
Step 3 β Add chat integrations (optional)
Select any combination of Discord, Telegram, Slack, WhatsApp, or Teams. The wizard collects each integration's bot token the same way as the API key β paste it in, reference an env var, or point to a file.
Step 4 β Wire your AI editor
Select which AI apps should have access to clawops β Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, and Zed are all supported. The wizard writes an MCP server entry into each app's config file using the absolute binary path so the app can launch it independently.
Step 5 β Deploy
The wizard bootstraps OpenClaw on the target host over SSH (installs Docker, pulls the image, starts the container), applies your LLM and integration config, generates a gateway auth token, and prints a direct dashboard URL:
Prerequisites: Node.js β₯ 22, an SSH key, and either an SSH-reachable Linux/macOS host or a
cloud account with CLI credentials configured (aws configure, gcloud auth login, or az login).
For a full narrated walkthrough with example output, see docs/demo-script.md.
If you prefer step-by-step control, or are adding clawops to an already-running deployment:
See docs/examples/local-vm.md for SSH prerequisites, firewall
setup, and troubleshooting.
The setup wizard handles this automatically (Step 4). To wire or re-wire editors at any time:
This opens the same interactive checkbox used in the wizard β select Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, or Zed and clawops writes the MCP entry into each app's config using the correct absolute binary path.
To add the entry manually instead, paste this into your editor's MCP config:
Replace /path/to/clawops with the output of which clawops. Config file locations:
| App | Path |
|---|---|
| Claude Desktop (macOS) | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Claude Desktop (Linux) | ~/.config/Claude/claude_desktop_config.json |
| Claude Code | ~/.claude.json |
| Cursor | ~/.cursor/mcp.json |
| Windsurf | ~/.codeium/windsurf/mcp_config.json |
| VS Code (macOS) | ~/Library/Application Support/Code/User/mcp.json |
| VS Code (Linux) | ~/.config/Code/User/mcp.json |
| Zed | ~/.config/zed/settings.json (key: context_servers) |
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/clawops)<a href="https://allmcps.com/mcp/clawops"><img src="https://allmcps.com/api/badge/clawops?style=directory" alt="Clawops on AllMCPs" /></a>