[SPEAKER_00] So, Phil said, I work at Pomerium, and he's not the first person to have trouble pronouncing it, so I actually convinced the marketing team to create Pomeranian stickers, so if anybody wants Pomeranian stickers, I have a bunch with me. A bit about me, I'm a dev advocate over at Pomerium, as Phil said, from Canada, hailing from Montreal, so if anybody likes poutine and bagels, feel free to chat with me after. Also a GitHub star, Microsoft MVP, and AWS Community Builder, and you can find me everywhere at NikkieT online. I was pretty happy to see that there's a sizable instance on-prem of OpenClaw, so I was pretty happy with that, and it looks like that's the operator there. Cool. So, I came up with a funny title, but Claw is out. We're going to talk about a feature I contributed to the OpenClaw project back in February, and it's about hardening access to the control plane. So, I'm assuming everybody here is running an OpenClaw or OpenClaw curious. Is anybody running a mode called trusted proxy auth mode? You might not be, but okay. You might be on the token auth? Okay. Anyways, at Pomerium where I work, I'm always trying to secure things, that's part of what I do, and I was able to secure OpenClaw, but it meant I still had to add a token for the WebSocket connection, I had to always pair my device and stuff. And you don't really need that with a trusted proxy, specifically the one that I work on, which is OpenCore. It's called an identity aware proxy. So, if anybody's ever used GCP, there's an IAP in there, it's called an identity aware proxy, something that came out of Google. Essentially, you've got an identity provider, a policy engine, and a reverse proxy. So, it's not the lethal trifecta in the sense that you usually hear, but it's a solid security approach for securing internal apps. So, I got annoyed that I had to add this token still and do the pairing every time. I understood why they were there, but I proposed this issue, and at least one other person who uses Caddy chimed in and said, hey, that sounds like a good idea. And then Peter Stipeet was like, yeah, let's work on this, and he laid out the criteria that he wanted to have for this feature. So, I went ahead and worked on it. And, prior to trusted proxy auth mode, even if you were secured by a proxy, you still had to paste in that auth token in the UI for the WebSocket connection, and also, it sticks it in the query string, which obviously, this is really more for just local mode. And still having to pair the device, I don't know if people get annoyed by pairing the device, but I'd be on my phone after I just set it up, and then I had to go to the other thing to set it up. So, you still had to do those things, even if it was secured with a proxy. So, it got merged in, and I felt good about it, and it was nice to get some praise from Peter. It was my first contribution to the project, so it was very cool. So, what does it look like exactly in the config? I'm going to show a narrow part of the config here, but you have your gateway, and essentially, you no longer need the token. The mode is obviously different, so it's called trusted proxy, and the proxy now. And then there's some new properties you have to add, so there's trusted proxies, and this is essentially the proxy that is gating access to the control plane, the gateway. It's the IP addresses. It could be one or more. And aside from that, you have to have a trusted proxy section, so you'll have a user header, which is a JWT in my case, and then there's a required header section. There's some optional ones, too. It depends what you want to do. There's allowed users, and in my case, I don't need the allowed users, because the way an identity-aware proxy works is the policies dictate that. But, essentially, that's the big change there, and you can do this through the onboarding, or if you just go back in and configure things through the TUI. And, so that meant no more token for WebSocket connections, and no longer needed a pair of devices. So, not only are you getting better security posture, to me, it's a UX win as well, because I really found doing these two things annoying. Cool. I also want to give a shout-out to a couple contributors. After I contributed this, there was a bug, and Anthony reported it, and then Sid fixed it, and it was definitely something I missed, because I was testing this on my local environment, and I already had something paired, so I didn't run into the issue that Anthony had mentioned. So, it was a small fix, and Sid got that sorted out, but when you miss stuff, people in the community step up, so OSS for the win. The other thing I want to mention, it's not so much about this feature, but when I opened this issue, the number was 1560, and I had a PR initially that was in the 1700s, and I went on vacation, and I said, oh, I'll get back to it when I'm back. And the original PR was closed because it was stale, and literally after two weeks, it went from 1500 to almost 16,000, so that's a testament to how popular the project got, but it also meant I had to rebase quite a bit before it got merged. Anyways, I don't know if anybody else contributes to the project, but there's so many things going on all the time, so there's a lot of rebasing to keep your thing up to date. Cool. So, let's talk about my own OpenClaw. So, this is McClaw, and he's sitting on my desk in Montreal right now. There's some snow still. I use it in Discord. I don't know where people use their OpenClaw. I had it on Telegram initially, but they don't actually have encrypted channels, so all the stuff's unclear, so I work at a security company, and my CEO is like, yeah, don't use that. So, I'm mainly on Discord. I find it handy that way. I have WhatsApp too, but I tend to use Discord more. Some things I want to mention too, when I made the contribution, I actually used OpenClaw to make the contribution, which was fun, but I made the mistake of using the GitHub CLI, and I gave
SPEAKER_00
where people use their OpenClaw. I had it on Telegram initially, but they don't actually, their channels aren't encrypted, so all the stuff's unclear, so I work at a security company, and my CEO is like, yeah, don't use that. So, anyways, I'm mainly on Discord. I find it handy that way. I have WhatsApp, too, but I tend to use the Discord more. Some things I want to mention, too, is when I made the contribution, I actually used OpenClaw to make the contribution, which was fun, but it also, I made the mistake of using the GitHub CLI, and I gave it full access, so it put up a PR right away even before I was done reviewing things, so I had a little moment, but put it back into draft mode. But aside from that, after the token, trusted proxy mode got merged, I just started working on something. It started getting fun to just build stuff on my phone, so I built out something called ClawSpace, and it doesn't mean you need to use it, it's just the age of personal software. I just had a lot of fun building it. I find it useful, and I thought it was just cool that I could build this out on my phone on Discord. But for me, I find it useful because I don't need to SSH in to see workspace files that I want to actually read or edit, so that's just a little side project I started building. And you can edit files and stuff, too. Cool. So we're going to do a demo here. This is going to be live coding, so YOLO. Okay. So there's an MCP track tomorrow. I've been doing a lot of work in MCPs, so what we're going to do is we're going to build out an MCP, not a full-fledged version of something, but if you've seen the AI engineer website, they have an LMS text on the right, and there's an MCP server, and there's a few other things. So I'm going to go ahead and just add this here. And I'm going to create an app. I'll explain some things here in a second. Okay. And OAuth. Okay. So this is going to create an application in ChatGPT. But basically this is an MCP server that just has UI as well. They'll be talking about this tomorrow. But I have a template that I use for this, so it's not like I'm building this from scratch. But we're just going to register the MCP here. And then I'm just going to start building with OpenClaw. And the thing with the Gentic is you never know when it's done. It's just finishing an OAuth here. Okay. Cool. It's connected. And we can see here it's got two tools. It's got an echo tool, and it's got a search speakers tool. So if we come here, if nobody's ever used MCP apps, basically in ChatGPT, you do this for your app. And I'm going to say, echo hello. And essentially it's going to do the tool call, but because there's UI associated with it, you're going to get some UI in here. And this is just using the standard MCP stuff that's in the spec now. So you can do stuff like change that, make it big and stuff. But what I want to show is when I'm building this with OpenClaw, I can do stuff like this. I can do stuff like that in the echo widget. Now, it's going to take a second, but this is all web tech under the hood. So I don't know if anybody's web devs here. But essentially it's using Vue and React. So there's React refresh and Vue hot module reloading.
SPEAKER_00
McClaw is on the case here. And you can see I'm in ChatGPT. I'm editing live from my workspace, the MCP. And to explain how this is working, we have the trusted proxy auth mode. I happen to use it in this case. So I'm using it as well to secure other things in the workspace. So I have a public URL that I've gated for the MCP. And that's how I'm able to use it in ChatGPT. And I can go ahead and just keep working on it in here. And I don't know how other people work or build with OpenClaw, but this is how I've been doing it. I find it works really well for web dev stuff. So I'm going to say, update the search speakers. So let's just do this in Chat. And I'll say at AIE again. Search speakers. And it's going to give a very minimal UI here because there's not much to it. So I'm going to just tell McClaw to get on the case here. And basically if you go to that top right corner of the AIE website, there's a speaker.json. And this is like all the speakers from the conf. And we're going to use that as the source of users. And then I'm asking it to give the same UI as what you saw in the echo widget. It's going to take a minute here probably because McClaw is covered in snow probably in Montreal. But cool. And so basically once this gets done, we'll be able to filter users and just see who's talking at the conference. And I'm just going to take a sip of water while McClaw is chugging along there. Again, you never know when a Gentic finishes. Okay. It's deterministically indeterminate. So this should be done in a second. And then what you're going to see is you're going to see this updated. And again, just to reiterate the flow, I'm working in workspace files in my OpenClaw. I'm speaking to it or typing to it in Discord. This is a publicly available site. And I'm able to build it as I'm in my OpenClaw. And I like that workflow. I really don't know how other people work. I mean, obviously I use other tools like Claude and Codex, too. But you can see here, McClaw was able to get the job done. And then I can start filtering. So we could look for drilling down here. Then we can find a speaker. And then we can get a bit more information. And then I could say, let's add another feature here. So let's get McClaw on the case again. So we're going to add a more button here. And there's this send message function that you can use in MCP apps. And this is actually going to, when you click the more button that it's going to generate, this will actually make a call to the LLM and you're going to get a response back. So we'll add this more button. And again, I've been doing web dev for a while. And I always still find it magical when things just automatically update. But I'm going to go ahead and click on here. And you're going to see here that it's thinking now. So it actually made a call, added another prompt to ChatGPT here. And it's going to summarize why it thinks you should check out Alessandro's talk and a bit more about it. Now, I just really find this workflow really
SPEAKER_00
use in MCP apps. And this is actually going to, when you click the more button that it's going to generate, this will actually make a call to the LLM and you're going to get a response back. So we'll add this more button. And again, I've been doing web dev for a while, and I always still find it magical when things just automatically update. But I'm going to go ahead and click on here. And you're going to see here that it's thinking now. So it actually made a call, added another prompt to ChatGPT here. And it's going to summarize why it thinks you should check out Alessandro's talk and a bit more about it. Now, I really find this workflow cool. It's only possible if you use some kind of proxy to do this. You can do this with others like Caddy with OAuth. You could do it with, well, Nginx is deprecated at this point. Well, not deprecated, but at least in Kubernetes land, the ingress controller is. But it's a really nice way to gate stuff that is local, but you can still expose it in a secure way. And it's also just fun to build. I don't know about anybody else, but I've been really enjoying building stuff just chatting. I remember a couple years ago, Replit, who's an AI company that's making it really easy to build stuff. I was thinking, why would I ever want to build on my phone? And I got phone-pilled now, I guess. So, just having fun. I think that's part of the thing with OpenClaw. Also, just use it however you want to. I find that Claw space I created super helpful. Build your own tools and stuff. Definitely take security into consideration. There's a bunch of people that have obviously exposed things and they didn't mean to. Some people have deleted all their emails, et cetera. But I find the trusted proxy auth mode super useful and at least one other person does in that issue. I encourage you to check it out. Just have fun building stuff. And that's pretty much it. My name's Nick Taylor and that's how I build with OpenClaw.
SPEAKER_00
a dev advocate over at Pomerium, as Phil said, from Canada, Hale from Montreal, so if anybody likes poutine and bagels, feel free to chat with me after. Also a GitHub star, Microsoft MVP, and AWS Community Builder, and you can pretty much find me everywhere at NikkieT online. I was pretty happy to see this, that there's a pretty sizable instance on-prem of OpenClaw, so I was pretty happy with that, and it looks like that's the operator there. Cool. So, I don't know, I came up with a funny title, I guess, but Claw is out. We're going to talk about a feature I contributed to the OpenClaw project back in February, and it's about hardening
SPEAKER_00
access to the control plane. So, I'm assuming everybody here is running an OpenClaw or OpenClaw curious. Is anybody running a mode called trusted proxy auth mode? You might not be, but okay. You might be on the, who's on the token auth? Okay. Anyways, so, at Pomerium where I work, you know, I'm always just trying to secure things, that's just part of what I do, and I was able to secure OpenClaw, but it meant I still had to add a token for the WebSocket connection, I had to always pair my device and stuff. And you don't really need that with a trusted proxy, like specifically the one that I work on, which is OpenCore. It's called
SPEAKER_00
an identity aware proxy. So, if anybody's ever used GCP, there's an IAP in there, it's called an identity aware proxy, something that came out of Google. Essentially, you've got an identity provider, a policy engine, and a reverse proxy. So, those, it's not the lethal trifecta in the sense that you usually hear, but it's a pretty solid security approach for securing internal apps. So, I was like, of course, I kind of got annoyed that I had to add this token still, and do the pairing every time. I understood why they were there, but I just proposed this issue, and then, at least
SPEAKER_00
one other person who uses caddy chimed in and said, hey, that sounds like a good idea. And then, Peter, Stipeet was like, yeah, let's work on this, and he laid out the criteria that he wanted to have for this feature. So, I went ahead and worked on it. And, yeah, again, prior to trusted proxy auth mode, even if you were secured by a proxy, you still had to paste in that auth token in the UI for the WebSocket connection, and also, it sticks it in the query string, which obviously, like, this is really more for just only local mode, really. And still having to pair the device, like, I don't know if people get annoyed
SPEAKER_00
by pairing the device, but I'd just be on my phone after I just set it up, and then I was like, I got to go to the other thing to set it up. So, basically, you still had to do those things, even if it was secured with a proxy. So, got merged in, and I felt pretty good about it, and it was nice to get some praise from Peter. It was my first contribution to the project, so it was very cool. So, what does it look like exactly, like, in the config? I'm just going to show, like, a kind of narrow part of the config here, but you have your gateway, and essentially, you no longer need the token, like I mentioned. The mode is obviously different, so it's called trusted proxy, and
SPEAKER_00
the proxy now. And then there's some new properties you have to add, so there's trusted proxies, and this is essentially the proxy that is gating access to the control plane, the gateway. It's the IP addresses. It could be one or more. And aside from that, you have to have a trusted proxy section, so you'll have a user header, which is, in my case, it's a JWT, and then there's, like, a required header section. There's some optional ones, too. It depends what you want to do. There's, like, allowed users, and in my case, I don't need the allowed users, because the way an identity-ware proxy works is the policies dictate that. But, essentially,
SPEAKER_00
that's kind of the big change there, and you can do this through the onboarding, or if you just go back in and configure things through the TUI. And, yeah, so that just meant no more token for WebSocket connections, and no longer needed a pair of devices. So, not only are you getting better security posture, potentially, to me, it's like a UX win, as well, because I really found doing these two things annoying. Cool. I also just want to give a shout-out to a couple contributors. After I contributed this, there was a bug, and Anthony reported it, and then Sid fixed it, and it was definitely something I missed, because I
SPEAKER_00
basically was testing this on my local environment, and I already had something paired, so I didn't run into the issue that Anthony had mentioned. So, luckily, it was a small fix, and Sid got that sorted out, but just, you know, when you miss stuff, people in the community step up, so OSS for the win. The other thing I want to mention, it's not so much about this feature, but, like, when I opened this issue, the number of the issue was 1560, and I had a PR initially that was, like, in the 1700s, and I went on vacation, and I said, oh, I'll get back to it when I'm back. And the original PR was closed because it was stale, and, like, literally after two weeks, it went
SPEAKER_00
from, like, 1500 to, like, almost 16,000, so basically that's just a testament to how popular the project got, but it also meant I had to rebase quite a bit before it got merged, so, anyways, I don't know if anybody else that contributes to the project, but there's so many things going on all the time, so there's a lot of rebasing to keep your thing up to today. Cool. So, let's talk about my own OpenClaw. So, this is McClaw, and he's sitting on my desk in Montreal right now. There's some snow still. I use it in Discord. I don't know where people use their OpenClaw. I had it on Telegram initially, but they don't actually,
SPEAKER_00
their channels aren't encrypted, so, like, all the stuff's unclear, so I work at a security company, and my CEO is like, yeah, don't use that. So, anyways, I'm mainly on Discord. I find it handy that way. I have WhatsApp, too, but I tend to use the Discord more. Some things I want to mention, too, is when I made the contribution, I actually used OpenClaw to make the contribution, which was kind of fun, but it also, I made the mistake of, I used the GitHub CLI, and I gave it full access, so it put up a PR right away even before I was, like, done reviewing things, so I had a little, like, ah, but put it back into draft mode. But aside from that, after
SPEAKER_00
the token, trusted proxy mode got merged, I just started working on something. It started getting fun to just build stuff on my phone, so I built out something called ClawSpace, and, you know, it doesn't mean you need to use it, it's just, you know, it's the age of personal software. I just had a lot of fun building it. I find it useful, and I thought it was just cool that I could build this out on my phone on Discord. But for me, I find it useful because I don't need to SSH in to see workspace files that I want to actually read or, like, edit, so that's just a little side project I started building. And you can edit files and stuff, too. Cool.
SPEAKER_00
So we're going to do a demo here. This is going to be live coding, so YOLO. Okay. So there's an MCP track tomorrow. I've been doing a lot of work in MCPs, so what we're going to do is we're going to build out an MCP, not a full-fledged version of something, but if you've seen the AI engineer website, they have, like, an LMS text on the right, and there's an MCP server, and there's a few other things. So I'm going to go ahead and just add this here. And I'm going to go create an app. I'll explain some things here in a second. Okay. And OAuth. Okay. So this is going to go create an application in ChatGPT. But
SPEAKER_00
basically this is an MCP server that just has UI as well. They'll be talking about this tomorrow. But I have a template that I use for this, so it's not like I'm building this from scratch. But we're just going to register the MCP here. And then I'm just going to start building with OpenClaw. And the thing with the Gentic is you never know when it's done. It's just finishing a OAuth here. Okay. Cool. It's connected. And we can see here it's got two tools. It's got an echo tool, and it's got a search speakers tool. So if we come here, if nobody's ever used MCP apps, basically in ChatGPT, you do this for your app. And I'm going to say, like,
SPEAKER_00
echo hello. And essentially it's going to do the tool call, but because there's UI associated to it, you're going to get some UI in here. And this is just using the standard MCP stuff that's in the spec now. So you can do stuff like change that, make it big and stuff. But what I want to show is, like, when I'm building this with OpenClaw, I can do stuff like this. I can do stuff like that in the echo widget. Now, it's going to take a second, but this is all web tech under the hood. So I don't know if anybody's web devs here. But essentially it's using V and React. So there's React refresh and V hot module reloading.
SPEAKER_00
McClaw is on the case here. And you can see I'm in ChatGPT. I'm editing live from my workspace, the MCP. And to explain how this is working, we have the trusted proxy auth mode. I happen to use it in this case. So I'm using it as well to secure other things in the workspace. So I have a public URL that I've gated for the MCP. And that's how I'm able to use it in ChatGPT. And I can go ahead and just keep working on it in here. And I don't know how other people work or build with OpenClaw, but this is kind of how I've been doing it. I find it works really well for web dev stuff. So I'm going to go, say, update the search speakers. So let's just
SPEAKER_00
do this in Chat. And I'll say at AIE again. Search speakers. And it's going to give a very minimal UI here because there's not much into it. So I'm going to just tell McClaw to get on the case here. And basically if you go to that top right corner of the AIE website, there's a speaker.json. And this is like all the speakers from the conf. And we're going to use that as like the source of users. And then I'm asking it to kind of give the same UI as what you kind of saw in the echo widget. It's going to take a minute here probably because McClaw is covered in snow probably in Montreal. But cool. And so basically once this gets done, we'll be able to filter users
SPEAKER_00
and just kind of see who's talking at the conference. And I'm just going to take a sip of water while McClaw is chugging along there. Again, you never know when a Gentic finishes. Okay. It's deterministically an indeterminate. So this should be done in a second. And then what you're going to see is you're going to see this updated. And again, just to reiterate the flow, I'm working in workspace files in my open claw. I'm speaking to it or typing to it in Discord. This is a publicly available site. And I'm able to build it as I'm in my open claw. And I like that workflow. I really
SPEAKER_00
don't know how other people work. I mean, obviously I use other tools like Claude and Codex, too. But you can see here, McClaw was able to get the job done. And then I can start filtering. So we could look for drilling down here. Then we can find a speaker. And then we can get a bit more information. And then I could say, let's add another feature here. So let's get McClaw in the case again. So we're going to add a more button here. And there's this send message function that you can use in MCP apps. And this is actually going to, when you click the more button that it's going to
SPEAKER_00
generate, this will actually make a call to the LLM and you're going to get a response back. So we'll add this more button. And again, like, I've been doing web dev for a while. And I always still find it magical when things just automatically update. But I'm going to go ahead and click on here. And you're going to see here that it's thinking now. So it actually made a call, added another prompt to ChatGPT here. And it's going to kind of summarize why it thinks you should check out Alessandro's talk and a bit more about it. Now, I just really find this workflow really cool. It's only possible if you use some kind of proxy to do this. You can do this with others
SPEAKER_00
like Caddy with OAuth. You could do it with, well, Nginx is kind of deprecated at this point. Well, not deprecated, but at least in Kubernetes land, the ingress controller is. But it's just a really nice way to gate stuff that is local, but you can still expose it in a secure way. And it's also just fun to build. Like, I don't know about anybody else, but I've been really enjoying building stuff just chatting. I remember a couple years ago, Replit, who's an AI company that's, you know, making it really easy to build stuff. I was like, why would I ever want to build on my phone? And I
SPEAKER_00
kind of got phone-pilled now, I guess. So, just having fun. I think that's part of the thing with OpenClaw. Also, just use it however you want to. I find that Claw space I created super helpful. Build your own tools and stuff. Definitely take security into consideration. There's a bunch of people that have obviously, you know, exposed things and they didn't mean to. Like, you know, some people have deleted all their emails, et cetera. But, I don't know. I find the trusted proxy auth mode super useful and at least one other person does in that issue. I encourage you to check it out. Just have fun building stuff. And, yeah, that's pretty much it. My name's Nick
SPEAKER_00
Taylor and that's how I build with OpenClaw.