Skip to content

v0.2.0

Choose a tag to compare

@contextablemark contextablemark released this 04 Feb 23:45
· 80 commits to main since this release

Added

  • Device pairing authentication - Secure per-device access control
    • HMAC-signed device tokens (no master token exposure)
    • Pairing approval workflow (openclaw pairing approve clawg-ui <code>)
    • New CLI command: openclaw clawg-ui devices - List approved devices

Changed

  • Breaking: Direct bearer token authentication using OPENCLAW_GATEWAY_TOKEN is now deprecated and no longer supported. All clients must use device pairing.

Security

  • Device tokens are HMAC-signed and do not expose the gateway's master secret
  • Pending pairing requests expire after 10 minutes (max 3 per channel)
  • Each device requires explicit approval by the gateway owner