Open Reader

Claws Out: Securing and Building with OpenClaw - Nick Taylor, Pomerium

completed 17:11 Jul 11, 2026 Watch on YouTube

Current Status

completed

Video ID

xg1zNlzw7Jk

RAG / Chat

Enabled
Claws Out: Securing and Building with OpenClaw - Nick Taylor, Pomerium
Description

Running OpenClaw without hardening access to it is a bad idea. We'll cover how I secured my OpenClaw, McClaw, contributed trusted-proxy auth mode to the OpenClaw project, and how I use it to build tools. We're going to build something live during the talk using OpenClaw, the same way I built Clawspace, a browser-based file explorer/editor for your OpenClaw workspace. feat(gateway): add trusted-proxy auth modegiithub.com/nickytonline/clawspace, a browser-based file explorer/editor for an OpenClaw workspace.github.com/pomerium/pomerium, an open core Identity-Aware Proxy

Summary

Generated by claude-sonnet-4-5

At-a-Glance

  • Verdict: Skim
  • Core thesis: Adding trusted proxy auth mode to OpenClaw eliminates token management and device pairing friction while improving security posture through identity-aware proxy authentication.
  • Why it matters: Demonstrates a production pattern for securing AI coding agents in enterprise/team environments without sacrificing UX, plus shows live coding workflow for building MCP servers via mobile Discord interface.
  • Best use: Watch if deploying OpenClaw in production behind a reverse proxy (Pomerium, Caddy, etc.) or exploring mobile-first AI development workflows; skip if using local-only token auth.

Executive Summary

Nick Taylor from Pomerium contributed a "trusted proxy auth mode" to OpenClaw in February that eliminates the need for manual token management and device pairing when OpenClaw runs behind an identity-aware proxy (IAP). Prior to this feature, users still had to paste auth tokens for WebSocket connections and pair devices even when already secured by a proxy—creating both security and UX friction. The new mode accepts authentication headers (typically JWTs) from trusted proxies, offloading auth entirely to the proxy layer.

The configuration requires specifying trusted proxy IPs, a user header (JWT), required/optional headers, and optionally allowed users (though IAPs typically handle this via policies). This approach mirrors GCP's IAP pattern: identity provider + policy engine + reverse proxy. Taylor dogfooded OpenClaw to build the feature itself, though he accidentally used GitHub CLI with full permissions and created a premature PR. The feature saw community validation: one user (Sid) fixed a post-merge bug Taylor missed due to testing with already-paired devices.

Taylor's personal workflow centers on building via Discord on mobile, enabled by this proxy mode. He built "ClawSpace" (a workspace file viewer/editor) and demonstrated live-coding an MCP server with ChatGPT UI during the talk. The demo involved building a speaker search tool for the AI Engineer conference, filtering speakers.json data, and adding a "More" button that triggers LLM summarization via MCP's sendMessage function. Hot module reloading (React/Vue) made changes appear instantly in ChatGPT.

The broader implication: trusted proxy auth mode enables secure public exposure of local OpenClaw instances for team/enterprise use, unblocking mobile workflows and MCP app development patterns that require public endpoints. Taylor emphasizes security hygiene (users have deleted emails via exposed instances) but advocates for experimentation and personal tooling in "the age of personal software."

Key Takeaways

  • Claim: Trusted proxy auth mode removes token management and device pairing when OpenClaw runs behind an identity-aware proxy. | Evidence: Config requires trusted_proxies (IP list), user_header (JWT), and required_header sections instead of token field. Taylor's setup uses Pomerium (identity provider + policy engine + reverse proxy). Prior workflow required pasting tokens into UI query strings and manual device pairing even when proxy-secured. | Caveat: Only works with proxies that inject authentication headers (Pomerium, Caddy with OAuth plugins, not standalone Nginx). Requires public URL exposure, increasing attack surface if misconfigured. At least one community user (via Caddy) validated use case, but adoption appears niche. | Implication: Enterprises running OpenClaw for teams can centralize auth via existing IAP infrastructure (Okta, etc.) and eliminate per-user token sprawl. Mobile workflows become viable since device pairing friction disappears. Security shifts from OpenClaw token management to proxy configuration—a win if proxy is already hardened. | Timestamp: 02:15
  • Claim: OpenClaw's rapid growth (issue #1560 to PR #16000 in two weeks during vacation) creates heavy rebase overhead for contributors. | Evidence: Taylor's initial PR went stale during vacation; project grew from 1500 to nearly 16,000 issues/PRs in two weeks. He had to rebase extensively before merge. Community member Sid fixed a post-merge pairing bug Taylor missed. | Caveat: Growth metric conflates issues + PRs; actual adoption/user count unclear. High activity could also mean low barrier to issue creation or duplicates. Rebase pain is typical for fast-moving OSS but signals process gaps (stale bot threshold, CI/CD friction). | Implication: Contributors should expect frequent rebasing and rapid invalidation of branches. Maintainers may need stricter PR hygiene or auto-rebase tooling. For Ken: OpenClaw velocity indicates strong market pull but potential instability for production deployments pinned to specific commits. | Timestamp: 08:45
  • Claim: Mobile-first AI coding via Discord + OpenClaw + public MCP endpoints enables live development without SSH or local IDE. | Evidence: Taylor built ClawSpace (workspace file viewer/editor) and live-coded an MCP server during talk. Workflow: Discord messages to OpenClaw → code changes in workspace → hot module reload (React/Vue) → instant updates in ChatGPT MCP app UI. Used speaker.json from AI Engineer site to build filterable speaker search with LLM summarization. | Caveat: Requires public URL for MCP (security risk if not gated). Hot reload only works for web tech (React/Vue); non-web projects lose this advantage. Taylor's "phone-pilled" comment suggests novelty factor, but unclear if workflow scales to complex projects (debugging, git conflicts, large refactors). Replit already offers similar mobile dev UX. | Implication: Pattern unlocks rapid prototyping for MCP apps and web tools when traveling/mobile-only. For teams, could enable async code reviews or demos via shared OpenClaw instances. Risk: developers may bypass security controls (VPNs, bastion hosts) for convenience. Ken should explore for lightweight agent tooling but question sustainability for production codebases. | Timestamp: 15:30
  • Claim: MCP apps with UI (via sendMessage function) enable interactive LLM-driven experiences inside ChatGPT. | Evidence: Taylor's demo MCP server included echo and search tools with React/Vue UI. Clicking "More" button triggered sendMessage, which injected a new prompt into ChatGPT to summarize why user should attend a speaker's talk. UI updated live as code changed in OpenClaw workspace. | Caveat: Spec is new (speaker mentions "MCP track tomorrow" at conference, implying early adoption). Unclear how ChatGPT handles rate limits, state management, or complex UI interactions. Template dependency suggests non-trivial setup. Only works for ChatGPT MCP apps, not Claude or other LLM interfaces. | Implication: MCP UI capabilities enable richer agent tooling beyond CLI-style function calls—agents can present filterable data, forms, or trigger follow-up LLM reasoning. For Ken: explore MCP UI for operational dashboards (log viewers, metric explorers) or internal tools where LLM summarization adds value. Watch for vendor lock-in (OpenAI-specific) and stability of spec. | Timestamp: 18:00
  • Claim: Security incidents (exposed OpenClaw instances deleting emails) highlight risks of public endpoints without proper gating. | Evidence: Taylor mentions "a bunch of people have obviously exposed things and they didn't mean to...some people have deleted all their emails." Emphasizes taking security into consideration despite encouraging experimentation. | Caveat: No specifics on attack vectors, whether incidents involved compromised tokens or misconfigured proxies. Unclear if email deletions were accidental (user error via agent) or malicious (external attacker). Taylor's employer (Pomerium) sells security tooling, so framing may emphasize risk to justify product. | Implication: Public OpenClaw endpoints are dangerous without strict auth, rate limiting, and scope controls. For Ken: any agent deployment with write access (email, GitHub, databases) must enforce least-privilege policies and audit logs. Trusted proxy mode reduces token leakage risk but shifts burden to proxy config—misconfigurations (wrong IP allowlist, missing headers) could expose control plane. | Timestamp: 20:15

Detailed Brief

Trusted Proxy Auth Mode: Config and Implementation

  • Claims: New mode eliminates token field in gateway config, replaces with trusted_proxies (IP list) and trusted_proxy section (user_header, required_header, optional allowed_users).; User header is typically a JWT; policies in IAP dictate access rather than allowed_users list.; Can configure via onboarding or TUI post-setup.
  • Evidence: Taylor showed config snippet: mode set to "trusted_proxy," proxy field added, trusted_proxies IP array, user_header set to JWT.; Pomerium IAP combines identity provider + policy engine + reverse proxy (similar to GCP IAP).; Community validation: Caddy user also requested feature, Sid fixed pairing bug post-merge.
  • Caveats: Only works with proxies that inject auth headers (Pomerium, Caddy with OAuth, not vanilla Nginx).; Requires exposing OpenClaw via public URL, increasing attack surface.; Taylor tested with already-paired device, missed bug that Sid caught—suggests edge cases in auth flow.
  • Implications: Enterprises can centralize OpenClaw auth via existing SSO/IAP (Okta, Azure AD) instead of managing per-user tokens.; Mobile workflows become frictionless since device pairing is eliminated.; Security responsibility shifts to proxy config—misconfigurations (wrong trusted IPs, missing required headers) could expose control plane.; For Ken: pattern is sound for team deployments but requires mature proxy setup and monitoring. Consider for internal AI tooling where SSO is already deployed.

Mobile Development Workflow: Discord + OpenClaw + MCP

  • Claims: Taylor builds primarily via Discord on mobile, using OpenClaw to edit workspace files without SSH.; Built ClawSpace (workspace file viewer/editor) as personal tool to read/edit files directly.; Live demo: created MCP server with ChatGPT UI, filtered conference speakers, added LLM summarization button.; Hot module reloading (React/Vue) enables instant UI updates in ChatGPT as code changes.
  • Evidence: Demo showed adding "More" button to speaker search UI via Discord chat, changes appeared instantly in ChatGPT.; Used speaker.json from AI Engineer website as data source for speaker filtering.; MCP sendMessage function triggers new LLM prompt, returning summary of why to attend speaker's talk.; Taylor mentioned avoiding Telegram (unencrypted channels), using Discord for security compliance.
  • Caveats: Requires public MCP endpoint (security risk if not properly gated).; Hot reload only applicable to web tech (React, Vue); other languages/frameworks lose this advantage.; Unclear if workflow scales to complex projects (debugging, merge conflicts, large refactors).; Replit and other platforms already offer mobile dev environments; novelty may be overstated.; "Phone-pilled" comment suggests enthusiasm but possible recency bias—long-term viability unclear.
  • Implications: Pattern enables rapid prototyping for web-based MCP apps and lightweight tools when mobile-only.; Teams could use shared OpenClaw instances for async code reviews or demos, but governance needed to prevent security bypass.; For Ken: explore for agent tooling MVPs or personal productivity hacks, but question sustainability for production systems. Consider as complement to desktop workflows, not replacement.; MCP UI capabilities (forms, filters, LLM-triggered actions) could power operational dashboards or internal tools where LLM summarization adds value.

Community Dynamics and Project Velocity

  • Claims: OpenClaw grew from issue #1560 to PR #16000 in two weeks during Taylor's vacation.; Initial PR went stale; Taylor had to rebase extensively before merge.; Community member Sid fixed post-merge pairing bug Taylor missed during local testing.; Peter Stipeet (maintainer) laid out feature criteria and provided praise post-merge.
  • Evidence: Taylor mentioned "rebasing quite a bit" due to rapid project growth.; Sid's fix was small but critical for users without already-paired devices.; Taylor used OpenClaw to build the feature itself, accidentally created premature PR via GitHub CLI with full permissions.
  • Caveats: Growth metric (1500 to 16000) conflates issues + PRs; actual user adoption unclear.; High activity could indicate low barrier to issue creation, duplicates, or spam.; Stale bot closing PR during vacation suggests contributor-unfriendly settings or lack of auto-rebase tooling.; No mention of maintainer bandwidth, code review latency, or breaking changes in releases.
  • Implications: Contributors should expect frequent rebasing and rapid branch invalidation—plan shorter PR cycles or stay closely engaged.; Maintainers may need stricter PR hygiene, auto-rebase tooling, or better stale bot thresholds.; For Ken: OpenClaw's velocity signals strong market pull but potential instability for production deployments. Pin to specific commits or releases rather than tracking main. Community-driven bug fixes (Sid's contribution) show healthy OSS dynamics but also reliance on community QA.; Fast-moving projects benefit experimentation but risk technical debt or breaking changes—monitor changelogs closely.

Security Posture and Risk Management

  • Claims: Exposed OpenClaw instances without proper auth have led to incidents (deleted emails mentioned).; Trusted proxy mode reduces token leakage risk by offloading auth to proxy layer.; Taylor emphasizes taking security seriously despite encouraging experimentation.
  • Evidence: Quote: "bunch of people have obviously exposed things...some people have deleted all their emails."; Taylor's employer (Pomerium) sells identity-aware proxy solutions, context for security focus.; Avoided Telegram due to lack of encrypted channels per CEO guidance.
  • Caveats: No details on attack vectors (compromised tokens vs. misconfigured proxies vs. accidental agent actions).; Unclear if email deletions were malicious (external attacker) or accidental (user error via agent).; Taylor's framing may overemphasize risk to justify Pomerium product positioning.
  • Implications: Public OpenClaw endpoints require strict auth, rate limiting, scope controls, and audit logs—treat as production attack surface.; Trusted proxy mode reduces token sprawl but shifts risk to proxy config: wrong IP allowlist, missing required headers, or policy gaps expose control plane.; For Ken: any agent with write access (email, GitHub, databases) must enforce least-privilege policies, approval workflows, and rollback mechanisms. Monitor for accidental destructive actions (bulk deletions, unintended commits).; IAP pattern is sound for team deployments but requires mature ops: monitoring, alerting, regular policy audits. Consider kill switches or read-only modes for high-risk operations.

Notable Concepts & Terms

  • Trusted Proxy Auth Mode: OpenClaw feature allowing authentication via reverse proxy headers (JWTs) instead of manual tokens, eliminating device pairing and token UI friction when secured by IAPs like Pomerium or Caddy.
  • Identity-Aware Proxy (IAP): Security pattern combining identity provider + policy engine + reverse proxy to gate internal apps (originated at Google, available in GCP). Offloads auth/authz from app to proxy layer.
  • ClawSpace: Taylor's personal tool built with OpenClaw to view/edit workspace files without SSH, enabling mobile-first workflows via Discord interface.
  • MCP Apps with UI: Model Context Protocol servers that expose tools with interactive UI (React/Vue) inside ChatGPT. Taylor's demo used sendMessage function to trigger follow-up LLM prompts from UI button clicks.
  • Hot Module Reloading (React/Vue): Development feature allowing live code updates without full page refresh. Taylor leveraged this for instant ChatGPT UI updates as OpenClaw edited workspace files.
  • Phone-pilled: Taylor's term for converting to mobile-first development after initially dismissing it (referencing Replit's mobile coding push). Suggests shift in workflow preferences enabled by OpenClaw + trusted proxy mode.

Operator Notes / Why Ken Should Care

  • Security pattern (IAP + trusted proxy mode) is production-ready for team OpenClaw deployments with existing SSO infrastructure—consider for internal AI tooling to eliminate token management overhead.
  • Mobile MCP development workflow is novel but narrow use case; evaluate for rapid prototyping or lightweight agent tooling, not complex production systems. Hot reload advantage only applies to web tech.
  • OpenClaw's rapid growth (1500 to 16000 issues/PRs in two weeks) signals strong adoption but potential instability—pin production deployments to specific commits/releases and monitor changelogs for breaking changes.
  • MCP UI capabilities (forms, filters, LLM-triggered actions via sendMessage) unlock richer agent experiences beyond CLI function calls—explore for operational dashboards (log viewers, metric explorers) where LLM summarization adds value. Watch for ChatGPT-specific lock-in.
  • Security incidents (deleted emails) highlight need for strict scope controls, audit logs, and least-privilege policies for any agent with write access. Trusted proxy mode reduces token leakage but shifts risk to proxy config—wrong IP allowlist or missing headers expose control plane.
  • Community-driven bug fixes (Sid's pairing fix) show healthy OSS dynamics but reliance on community QA. Fast-moving projects benefit experimentation but risk technical debt—contributors should plan short PR cycles or stay closely engaged to avoid stale closures and heavy rebasing.

Watch Map

  • 00:00: Intro: Nick Taylor from Pomerium, contributor to OpenClaw trusted proxy auth mode feature
  • 02:15: Problem statement: friction of token management and device pairing even when OpenClaw secured by proxy
  • 04:30: Identity-Aware Proxy (IAP) explanation: identity provider + policy engine + reverse proxy pattern from Google
  • 06:00: Config walkthrough: trusted_proxies IPs, user_header JWT, required_header section
  • 08:45: Community validation and bug fix: Sid fixed pairing issue Taylor missed, project growth from 1560 to 16000 in two weeks
  • 10:00: Personal OpenClaw setup: McClaw on Discord (not Telegram due to encryption), ClawSpace tool for workspace file access
  • 12:00: Live demo begins: building MCP server with ChatGPT UI for AI Engineer conference speaker search
  • 15:30: MCP app registration in ChatGPT, echo and search tools demonstration
  • 18:00: Live coding: adding features to speaker search (filtering, LLM summarization via sendMessage button), hot module reload in action
  • 20:15: Security emphasis: incidents of exposed instances deleting emails, importance of proper proxy gating
  • 22:00: Closing: encouragement to experiment with trusted proxy mode, build personal tools, have fun with OpenClaw

Source/Metadata

  • Title: Claws Out: Securing and Building with OpenClaw - Nick Taylor, Pomerium
  • Transcript words: 5331
  • Duration seconds: 1031
  • Timestamp note: Timestamps provided in watch_map are estimated based on 17-minute video duration and content flow; original transcript did not include explicit timestamps for all sections.

Transcript

2540 words en Processed in 200.5s

[SPEAKER_00] So, Phil said, I work at Pomerium, and he's not the first person to have trouble pronouncing it, so I actually convinced the marketing team to create Pomeranian stickers, so if anybody wants Pomeranian stickers, I have a bunch with me. A bit about me, I'm a dev advocate over at Pomerium, as Phil said, from Canada, hailing from Montreal, so if anybody likes poutine and bagels, feel free to chat with me after. Also a GitHub star, Microsoft MVP, and AWS Community Builder, and you can find me everywhere at NikkieT online. I was pretty happy to see that there's a sizable instance on-prem of OpenClaw, so I was pretty happy with that, and it looks like that's the operator there. Cool. So, I came up with a funny title, but Claw is out. We're going to talk about a feature I contributed to the OpenClaw project back in February, and it's about hardening access to the control plane. So, I'm assuming everybody here is running an OpenClaw or OpenClaw curious. Is anybody running a mode called trusted proxy auth mode? You might not be, but okay. You might be on the token auth? Okay. Anyways, at Pomerium where I work, I'm always trying to secure things, that's part of what I do, and I was able to secure OpenClaw, but it meant I still had to add a token for the WebSocket connection, I had to always pair my device and stuff. And you don't really need that with a trusted proxy, specifically the one that I work on, which is OpenCore. It's called an identity aware proxy. So, if anybody's ever used GCP, there's an IAP in there, it's called an identity aware proxy, something that came out of Google. Essentially, you've got an identity provider, a policy engine, and a reverse proxy. So, it's not the lethal trifecta in the sense that you usually hear, but it's a solid security approach for securing internal apps. So, I got annoyed that I had to add this token still and do the pairing every time. I understood why they were there, but I proposed this issue, and at least one other person who uses Caddy chimed in and said, hey, that sounds like a good idea. And then Peter Stipeet was like, yeah, let's work on this, and he laid out the criteria that he wanted to have for this feature. So, I went ahead and worked on it. And, prior to trusted proxy auth mode, even if you were secured by a proxy, you still had to paste in that auth token in the UI for the WebSocket connection, and also, it sticks it in the query string, which obviously, this is really more for just local mode. And still having to pair the device, I don't know if people get annoyed by pairing the device, but I'd be on my phone after I just set it up, and then I had to go to the other thing to set it up. So, you still had to do those things, even if it was secured with a proxy. So, it got merged in, and I felt good about it, and it was nice to get some praise from Peter. It was my first contribution to the project, so it was very cool. So, what does it look like exactly in the config? I'm going to show a narrow part of the config here, but you have your gateway, and essentially, you no longer need the token. The mode is obviously different, so it's called trusted proxy, and the proxy now. And then there's some new properties you have to add, so there's trusted proxies, and this is essentially the proxy that is gating access to the control plane, the gateway. It's the IP addresses. It could be one or more. And aside from that, you have to have a trusted proxy section, so you'll have a user header, which is a JWT in my case, and then there's a required header section. There's some optional ones, too. It depends what you want to do. There's allowed users, and in my case, I don't need the allowed users, because the way an identity-aware proxy works is the policies dictate that. But, essentially, that's the big change there, and you can do this through the onboarding, or if you just go back in and configure things through the TUI. And, so that meant no more token for WebSocket connections, and no longer needed a pair of devices. So, not only are you getting better security posture, to me, it's a UX win as well, because I really found doing these two things annoying. Cool. I also want to give a shout-out to a couple contributors. After I contributed this, there was a bug, and Anthony reported it, and then Sid fixed it, and it was definitely something I missed, because I was testing this on my local environment, and I already had something paired, so I didn't run into the issue that Anthony had mentioned. So, it was a small fix, and Sid got that sorted out, but when you miss stuff, people in the community step up, so OSS for the win. The other thing I want to mention, it's not so much about this feature, but when I opened this issue, the number was 1560, and I had a PR initially that was in the 1700s, and I went on vacation, and I said, oh, I'll get back to it when I'm back. And the original PR was closed because it was stale, and literally after two weeks, it went from 1500 to almost 16,000, so that's a testament to how popular the project got, but it also meant I had to rebase quite a bit before it got merged. Anyways, I don't know if anybody else contributes to the project, but there's so many things going on all the time, so there's a lot of rebasing to keep your thing up to date. Cool. So, let's talk about my own OpenClaw. So, this is McClaw, and he's sitting on my desk in Montreal right now. There's some snow still. I use it in Discord. I don't know where people use their OpenClaw. I had it on Telegram initially, but they don't actually have encrypted channels, so all the stuff's unclear, so I work at a security company, and my CEO is like, yeah, don't use that. So, I'm mainly on Discord. I find it handy that way. I have WhatsApp too, but I tend to use Discord more. Some things I want to mention too, when I made the contribution, I actually used OpenClaw to make the contribution, which was fun, but I made the mistake of using the GitHub CLI, and I gave where people use their OpenClaw. I had it on Telegram initially, but they don't actually, their channels aren't encrypted, so all the stuff's unclear, so I work at a security company, and my CEO is like, yeah, don't use that. So, anyways, I'm mainly on Discord. I find it handy that way. I have WhatsApp, too, but I tend to use the Discord more. Some things I want to mention, too, is when I made the contribution, I actually used OpenClaw to make the contribution, which was fun, but it also, I made the mistake of using the GitHub CLI, and I gave it full access, so it put up a PR right away even before I was done reviewing things, so I had a little moment, but put it back into draft mode. But aside from that, after the token, trusted proxy mode got merged, I just started working on something. It started getting fun to just build stuff on my phone, so I built out something called ClawSpace, and it doesn't mean you need to use it, it's just the age of personal software. I just had a lot of fun building it. I find it useful, and I thought it was just cool that I could build this out on my phone on Discord. But for me, I find it useful because I don't need to SSH in to see workspace files that I want to actually read or edit, so that's just a little side project I started building. And you can edit files and stuff, too. Cool. So we're going to do a demo here. This is going to be live coding, so YOLO. Okay. So there's an MCP track tomorrow. I've been doing a lot of work in MCPs, so what we're going to do is we're going to build out an MCP, not a full-fledged version of something, but if you've seen the AI engineer website, they have an LMS text on the right, and there's an MCP server, and there's a few other things. So I'm going to go ahead and just add this here. And I'm going to create an app. I'll explain some things here in a second. Okay. And OAuth. Okay. So this is going to create an application in ChatGPT. But basically this is an MCP server that just has UI as well. They'll be talking about this tomorrow. But I have a template that I use for this, so it's not like I'm building this from scratch. But we're just going to register the MCP here. And then I'm just going to start building with OpenClaw. And the thing with the Gentic is you never know when it's done. It's just finishing an OAuth here. Okay. Cool. It's connected. And we can see here it's got two tools. It's got an echo tool, and it's got a search speakers tool. So if we come here, if nobody's ever used MCP apps, basically in ChatGPT, you do this for your app. And I'm going to say, echo hello. And essentially it's going to do the tool call, but because there's UI associated with it, you're going to get some UI in here. And this is just using the standard MCP stuff that's in the spec now. So you can do stuff like change that, make it big and stuff. But what I want to show is when I'm building this with OpenClaw, I can do stuff like this. I can do stuff like that in the echo widget. Now, it's going to take a second, but this is all web tech under the hood. So I don't know if anybody's web devs here. But essentially it's using Vue and React. So there's React refresh and Vue hot module reloading. McClaw is on the case here. And you can see I'm in ChatGPT. I'm editing live from my workspace, the MCP. And to explain how this is working, we have the trusted proxy auth mode. I happen to use it in this case. So I'm using it as well to secure other things in the workspace. So I have a public URL that I've gated for the MCP. And that's how I'm able to use it in ChatGPT. And I can go ahead and just keep working on it in here. And I don't know how other people work or build with OpenClaw, but this is how I've been doing it. I find it works really well for web dev stuff. So I'm going to say, update the search speakers. So let's just do this in Chat. And I'll say at AIE again. Search speakers. And it's going to give a very minimal UI here because there's not much to it. So I'm going to just tell McClaw to get on the case here. And basically if you go to that top right corner of the AIE website, there's a speaker.json. And this is like all the speakers from the conf. And we're going to use that as the source of users. And then I'm asking it to give the same UI as what you saw in the echo widget. It's going to take a minute here probably because McClaw is covered in snow probably in Montreal. But cool. And so basically once this gets done, we'll be able to filter users and just see who's talking at the conference. And I'm just going to take a sip of water while McClaw is chugging along there. Again, you never know when a Gentic finishes. Okay. It's deterministically indeterminate. So this should be done in a second. And then what you're going to see is you're going to see this updated. And again, just to reiterate the flow, I'm working in workspace files in my OpenClaw. I'm speaking to it or typing to it in Discord. This is a publicly available site. And I'm able to build it as I'm in my OpenClaw. And I like that workflow. I really don't know how other people work. I mean, obviously I use other tools like Claude and Codex, too. But you can see here, McClaw was able to get the job done. And then I can start filtering. So we could look for drilling down here. Then we can find a speaker. And then we can get a bit more information. And then I could say, let's add another feature here. So let's get McClaw on the case again. So we're going to add a more button here. And there's this send message function that you can use in MCP apps. And this is actually going to, when you click the more button that it's going to generate, this will actually make a call to the LLM and you're going to get a response back. So we'll add this more button. And again, I've been doing web dev for a while. And I always still find it magical when things just automatically update. But I'm going to go ahead and click on here. And you're going to see here that it's thinking now. So it actually made a call, added another prompt to ChatGPT here. And it's going to summarize why it thinks you should check out Alessandro's talk and a bit more about it. Now, I just really find this workflow really use in MCP apps. And this is actually going to, when you click the more button that it's going to generate, this will actually make a call to the LLM and you're going to get a response back. So we'll add this more button. And again, I've been doing web dev for a while, and I always still find it magical when things just automatically update. But I'm going to go ahead and click on here. And you're going to see here that it's thinking now. So it actually made a call, added another prompt to ChatGPT here. And it's going to summarize why it thinks you should check out Alessandro's talk and a bit more about it. Now, I really find this workflow cool. It's only possible if you use some kind of proxy to do this. You can do this with others like Caddy with OAuth. You could do it with, well, Nginx is deprecated at this point. Well, not deprecated, but at least in Kubernetes land, the ingress controller is. But it's a really nice way to gate stuff that is local, but you can still expose it in a secure way. And it's also just fun to build. I don't know about anybody else, but I've been really enjoying building stuff just chatting. I remember a couple years ago, Replit, who's an AI company that's making it really easy to build stuff. I was thinking, why would I ever want to build on my phone? And I got phone-pilled now, I guess. So, just having fun. I think that's part of the thing with OpenClaw. Also, just use it however you want to. I find that Claw space I created super helpful. Build your own tools and stuff. Definitely take security into consideration. There's a bunch of people that have obviously exposed things and they didn't mean to. Some people have deleted all their emails, et cetera. But I find the trusted proxy auth mode super useful and at least one other person does in that issue. I encourage you to check it out. Just have fun building stuff. And that's pretty much it. My name's Nick Taylor and that's how I build with OpenClaw. a dev advocate over at Pomerium, as Phil said, from Canada, Hale from Montreal, so if anybody likes poutine and bagels, feel free to chat with me after. Also a GitHub star, Microsoft MVP, and AWS Community Builder, and you can pretty much find me everywhere at NikkieT online. I was pretty happy to see this, that there's a pretty sizable instance on-prem of OpenClaw, so I was pretty happy with that, and it looks like that's the operator there. Cool. So, I don't know, I came up with a funny title, I guess, but Claw is out. We're going to talk about a feature I contributed to the OpenClaw project back in February, and it's about hardening access to the control plane. So, I'm assuming everybody here is running an OpenClaw or OpenClaw curious. Is anybody running a mode called trusted proxy auth mode? You might not be, but okay. You might be on the, who's on the token auth? Okay. Anyways, so, at Pomerium where I work, you know, I'm always just trying to secure things, that's just part of what I do, and I was able to secure OpenClaw, but it meant I still had to add a token for the WebSocket connection, I had to always pair my device and stuff. And you don't really need that with a trusted proxy, like specifically the one that I work on, which is OpenCore. It's called an identity aware proxy. So, if anybody's ever used GCP, there's an IAP in there, it's called an identity aware proxy, something that came out of Google. Essentially, you've got an identity provider, a policy engine, and a reverse proxy. So, those, it's not the lethal trifecta in the sense that you usually hear, but it's a pretty solid security approach for securing internal apps. So, I was like, of course, I kind of got annoyed that I had to add this token still, and do the pairing every time. I understood why they were there, but I just proposed this issue, and then, at least one other person who uses caddy chimed in and said, hey, that sounds like a good idea. And then, Peter, Stipeet was like, yeah, let's work on this, and he laid out the criteria that he wanted to have for this feature. So, I went ahead and worked on it. And, yeah, again, prior to trusted proxy auth mode, even if you were secured by a proxy, you still had to paste in that auth token in the UI for the WebSocket connection, and also, it sticks it in the query string, which obviously, like, this is really more for just only local mode, really. And still having to pair the device, like, I don't know if people get annoyed by pairing the device, but I'd just be on my phone after I just set it up, and then I was like, I got to go to the other thing to set it up. So, basically, you still had to do those things, even if it was secured with a proxy. So, got merged in, and I felt pretty good about it, and it was nice to get some praise from Peter. It was my first contribution to the project, so it was very cool. So, what does it look like exactly, like, in the config? I'm just going to show, like, a kind of narrow part of the config here, but you have your gateway, and essentially, you no longer need the token, like I mentioned. The mode is obviously different, so it's called trusted proxy, and the proxy now. And then there's some new properties you have to add, so there's trusted proxies, and this is essentially the proxy that is gating access to the control plane, the gateway. It's the IP addresses. It could be one or more. And aside from that, you have to have a trusted proxy section, so you'll have a user header, which is, in my case, it's a JWT, and then there's, like, a required header section. There's some optional ones, too. It depends what you want to do. There's, like, allowed users, and in my case, I don't need the allowed users, because the way an identity-ware proxy works is the policies dictate that. But, essentially, that's kind of the big change there, and you can do this through the onboarding, or if you just go back in and configure things through the TUI. And, yeah, so that just meant no more token for WebSocket connections, and no longer needed a pair of devices. So, not only are you getting better security posture, potentially, to me, it's like a UX win, as well, because I really found doing these two things annoying. Cool. I also just want to give a shout-out to a couple contributors. After I contributed this, there was a bug, and Anthony reported it, and then Sid fixed it, and it was definitely something I missed, because I basically was testing this on my local environment, and I already had something paired, so I didn't run into the issue that Anthony had mentioned. So, luckily, it was a small fix, and Sid got that sorted out, but just, you know, when you miss stuff, people in the community step up, so OSS for the win. The other thing I want to mention, it's not so much about this feature, but, like, when I opened this issue, the number of the issue was 1560, and I had a PR initially that was, like, in the 1700s, and I went on vacation, and I said, oh, I'll get back to it when I'm back. And the original PR was closed because it was stale, and, like, literally after two weeks, it went from, like, 1500 to, like, almost 16,000, so basically that's just a testament to how popular the project got, but it also meant I had to rebase quite a bit before it got merged, so, anyways, I don't know if anybody else that contributes to the project, but there's so many things going on all the time, so there's a lot of rebasing to keep your thing up to today. Cool. So, let's talk about my own OpenClaw. So, this is McClaw, and he's sitting on my desk in Montreal right now. There's some snow still. I use it in Discord. I don't know where people use their OpenClaw. I had it on Telegram initially, but they don't actually, their channels aren't encrypted, so, like, all the stuff's unclear, so I work at a security company, and my CEO is like, yeah, don't use that. So, anyways, I'm mainly on Discord. I find it handy that way. I have WhatsApp, too, but I tend to use the Discord more. Some things I want to mention, too, is when I made the contribution, I actually used OpenClaw to make the contribution, which was kind of fun, but it also, I made the mistake of, I used the GitHub CLI, and I gave it full access, so it put up a PR right away even before I was, like, done reviewing things, so I had a little, like, ah, but put it back into draft mode. But aside from that, after the token, trusted proxy mode got merged, I just started working on something. It started getting fun to just build stuff on my phone, so I built out something called ClawSpace, and, you know, it doesn't mean you need to use it, it's just, you know, it's the age of personal software. I just had a lot of fun building it. I find it useful, and I thought it was just cool that I could build this out on my phone on Discord. But for me, I find it useful because I don't need to SSH in to see workspace files that I want to actually read or, like, edit, so that's just a little side project I started building. And you can edit files and stuff, too. Cool. So we're going to do a demo here. This is going to be live coding, so YOLO. Okay. So there's an MCP track tomorrow. I've been doing a lot of work in MCPs, so what we're going to do is we're going to build out an MCP, not a full-fledged version of something, but if you've seen the AI engineer website, they have, like, an LMS text on the right, and there's an MCP server, and there's a few other things. So I'm going to go ahead and just add this here. And I'm going to go create an app. I'll explain some things here in a second. Okay. And OAuth. Okay. So this is going to go create an application in ChatGPT. But basically this is an MCP server that just has UI as well. They'll be talking about this tomorrow. But I have a template that I use for this, so it's not like I'm building this from scratch. But we're just going to register the MCP here. And then I'm just going to start building with OpenClaw. And the thing with the Gentic is you never know when it's done. It's just finishing a OAuth here. Okay. Cool. It's connected. And we can see here it's got two tools. It's got an echo tool, and it's got a search speakers tool. So if we come here, if nobody's ever used MCP apps, basically in ChatGPT, you do this for your app. And I'm going to say, like, echo hello. And essentially it's going to do the tool call, but because there's UI associated to it, you're going to get some UI in here. And this is just using the standard MCP stuff that's in the spec now. So you can do stuff like change that, make it big and stuff. But what I want to show is, like, when I'm building this with OpenClaw, I can do stuff like this. I can do stuff like that in the echo widget. Now, it's going to take a second, but this is all web tech under the hood. So I don't know if anybody's web devs here. But essentially it's using V and React. So there's React refresh and V hot module reloading. McClaw is on the case here. And you can see I'm in ChatGPT. I'm editing live from my workspace, the MCP. And to explain how this is working, we have the trusted proxy auth mode. I happen to use it in this case. So I'm using it as well to secure other things in the workspace. So I have a public URL that I've gated for the MCP. And that's how I'm able to use it in ChatGPT. And I can go ahead and just keep working on it in here. And I don't know how other people work or build with OpenClaw, but this is kind of how I've been doing it. I find it works really well for web dev stuff. So I'm going to go, say, update the search speakers. So let's just do this in Chat. And I'll say at AIE again. Search speakers. And it's going to give a very minimal UI here because there's not much into it. So I'm going to just tell McClaw to get on the case here. And basically if you go to that top right corner of the AIE website, there's a speaker.json. And this is like all the speakers from the conf. And we're going to use that as like the source of users. And then I'm asking it to kind of give the same UI as what you kind of saw in the echo widget. It's going to take a minute here probably because McClaw is covered in snow probably in Montreal. But cool. And so basically once this gets done, we'll be able to filter users and just kind of see who's talking at the conference. And I'm just going to take a sip of water while McClaw is chugging along there. Again, you never know when a Gentic finishes. Okay. It's deterministically an indeterminate. So this should be done in a second. And then what you're going to see is you're going to see this updated. And again, just to reiterate the flow, I'm working in workspace files in my open claw. I'm speaking to it or typing to it in Discord. This is a publicly available site. And I'm able to build it as I'm in my open claw. And I like that workflow. I really don't know how other people work. I mean, obviously I use other tools like Claude and Codex, too. But you can see here, McClaw was able to get the job done. And then I can start filtering. So we could look for drilling down here. Then we can find a speaker. And then we can get a bit more information. And then I could say, let's add another feature here. So let's get McClaw in the case again. So we're going to add a more button here. And there's this send message function that you can use in MCP apps. And this is actually going to, when you click the more button that it's going to generate, this will actually make a call to the LLM and you're going to get a response back. So we'll add this more button. And again, like, I've been doing web dev for a while. And I always still find it magical when things just automatically update. But I'm going to go ahead and click on here. And you're going to see here that it's thinking now. So it actually made a call, added another prompt to ChatGPT here. And it's going to kind of summarize why it thinks you should check out Alessandro's talk and a bit more about it. Now, I just really find this workflow really cool. It's only possible if you use some kind of proxy to do this. You can do this with others like Caddy with OAuth. You could do it with, well, Nginx is kind of deprecated at this point. Well, not deprecated, but at least in Kubernetes land, the ingress controller is. But it's just a really nice way to gate stuff that is local, but you can still expose it in a secure way. And it's also just fun to build. Like, I don't know about anybody else, but I've been really enjoying building stuff just chatting. I remember a couple years ago, Replit, who's an AI company that's, you know, making it really easy to build stuff. I was like, why would I ever want to build on my phone? And I kind of got phone-pilled now, I guess. So, just having fun. I think that's part of the thing with OpenClaw. Also, just use it however you want to. I find that Claw space I created super helpful. Build your own tools and stuff. Definitely take security into consideration. There's a bunch of people that have obviously, you know, exposed things and they didn't mean to. Like, you know, some people have deleted all their emails, et cetera. But, I don't know. I find the trusted proxy auth mode super useful and at least one other person does in that issue. I encourage you to check it out. Just have fun building stuff. And, yeah, that's pretty much it. My name's Nick Taylor and that's how I build with OpenClaw.