Security

How ClawLink keeps your credentials and data secure

ClawLink keeps provider credentials off your machine and out of your code. Connect flows and tool calls run in ClawLink's hosted infrastructure. Your agent keeps only its own ClawLink device credential.

OAuth tokens held by Composio

Most apps connect through Composio, our credential partner. ClawLink stores only a reference.

Keys encrypted with AES-256-GCM

Keys you enter are encrypted at rest and decrypted only in memory, for the live request.

HTTPS everywhere

Agent to ClawLink, and ClawLink to every app. Never plain HTTP.

One credential on your machine

Your agent holds a ClawLink device credential, never a Google or Stripe token.

Credential storage

Most integrations connect through a hosted OAuth flow run by Composio, our credential infrastructure partner. Composio holds your provider OAuth tokens. ClawLink stores only a reference to your connected account, not the tokens. Composio publishes its compliance posture in its trust center.

When ClawLink holds a credential directly, such as an API key you enter during setup, it encrypts it with AES-256-GCM before it writes it to the database. The key is never stored or logged in plain text, and it is decrypted only in memory when your request runs. Encryption keys can be rotated without downtime.

For the full picture, see the Security Overview and the Trust Center. If your security team needs more detail, email [email protected].

Your machine stays clean

ClawLink makes the provider calls from its hosted infrastructure, so you do not put third-party API keys in .env files or source code. Connect your apps once in the dashboard, and ClawLink handles the provider side.

How your agent authenticates

The recommended setup is browser pairing. Pairing creates a ClawLink credential in the format cllk_live_... and stores it on the agent's machine. For OpenClaw, that is ~/.openclaw/openclaw.json.

This credential authenticates your agent to ClawLink. It is not a provider credential like your Google or Stripe token.

The ClawLink credential on your machine gives access to your connected apps through your account. Never share it or commit it to source control. If you think someone has it, revoke it at once in Dashboard > Devices or Settings > Developer, and pair again.

API key good practice

  • Prefer browser pairing to manual keys.
  • Use manual keys only for agents that cannot run the login command, or for the Developer API.
  • Use one key per device or workflow.
  • Revoke keys you no longer need.

If a credential is exposed

Find it in the dashboard

A paired device is in Dashboard > Devices. A manual key is in Settings > Developer.

Revoke it

It stops working at once.

Set up the affected agent again

Pair the device again, or create a new key and paste it into the agent's settings.

Any agent still using a revoked credential stops working until you pair it again or give it a new key.

Account security

Settings > Security opens your account screen for password, email, connected sign-in methods, and any extra protection your sign-in method supports.

Reporting security issues

Send security reports to [email protected]. Include the steps to reproduce, the affected endpoints, and any account or request details that help.

On this page