2026-01-01 17:34:46 +01:00
---
2026-01-13 06:16:43 +00:00
summary: "CLI onboarding wizard: guided setup for gateway, workspace, channels, and skills"
2026-01-01 17:34:46 +01:00
read_when:
2026-01-01 21:09:24 +01:00
- Running or configuring the onboarding wizard
- Setting up a new machine
2026-01-01 17:34:46 +01:00
---
# Onboarding Wizard (CLI)
2026-01-07 01:21:36 +01:00
The onboarding wizard is the **recommended** way to set up Clawdbot on macOS,
Linux, or Windows (via WSL2; strongly recommended).
2026-01-13 06:16:43 +00:00
It configures a local Gateway or a remote Gateway connection, plus channels, skills,
2026-01-01 21:09:24 +01:00
and workspace defaults in one guided flow.
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
Primary entrypoint:
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
```bash
2026-01-04 14:32:47 +00:00
clawdbot onboard
2026-01-01 21:09:24 +01:00
```
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
Follow‑ up reconfiguration:
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
```bash
2026-01-04 14:32:47 +00:00
clawdbot configure
2026-01-01 21:09:24 +01:00
```
2026-01-01 18:23:16 +01:00
2026-01-15 04:25:19 +00:00
Recommended: set up a Brave Search API key so the agent can use `web_search`
2026-01-15 05:08:51 +00:00
(`web_fetch` works without a key). Easiest path: `clawdbot configure --section web`
which stores `tools.web.search.apiKey` . Docs: [Web tools ](/tools/web ).
2026-01-15 04:25:19 +00:00
2026-01-08 11:54:40 +01:00
## QuickStart vs Advanced
The wizard starts with **QuickStart** (defaults) vs **Advanced** (full control).
**QuickStart** keeps the defaults:
- Local gateway (loopback)
- Workspace default (or existing workspace)
- Gateway port **18789**
2026-01-11 01:51:07 +01:00
- Gateway auth **Token** (auto‑ generated, even on loopback)
2026-01-08 11:54:40 +01:00
- Tailscale exposure **Off**
2026-01-09 11:06:29 +01:00
- Telegram + WhatsApp DMs default to **allowlist** (you’ ll be prompted for your phone number)
2026-01-08 11:54:40 +01:00
2026-01-13 06:16:43 +00:00
**Advanced** exposes every step (mode, workspace, gateway, channels, daemon, skills).
2026-01-08 11:54:40 +01:00
2026-01-01 21:09:24 +01:00
## What the wizard does
**Local mode (default)** walks you through:
2026-01-22 00:42:04 +00:00
- Model/auth (OpenAI Code (Codex) subscription OAuth, Anthropic API key (recommended) or setup-token (paste), plus MiniMax/GLM/Moonshot/AI Gateway options)
2026-01-01 21:09:24 +01:00
- Workspace location + bootstrap files
- Gateway settings (port/bind/auth/tailscale)
2026-01-23 00:19:23 +00:00
- Providers (Telegram, WhatsApp, Discord, Mattermost (plugin), Signal)
2026-01-07 01:21:36 +01:00
- Daemon install (LaunchAgent / systemd user unit)
2026-01-01 21:09:24 +01:00
- Health check
- Skills (recommended)
**Remote mode** only configures the local client to connect to a Gateway elsewhere.
It does **not** install or change anything on the remote host.
2026-01-07 09:58:54 +01:00
To add more isolated agents (separate workspace + sessions + auth), use:
```bash
clawdbot agents add < name >
```
2026-01-08 07:49:07 +01:00
Tip: `--json` does **not** imply non-interactive mode. Use `--non-interactive` (and `--workspace` ) for scripts.
2026-01-01 21:09:24 +01:00
## Flow details (local)
1) **Existing config detection**
2026-01-04 14:32:47 +00:00
- If `~/.clawdbot/clawdbot.json` exists, choose **Keep / Modify / Reset** .
2026-01-16 06:57:47 +00:00
- Re-running the wizard does **not** wipe anything unless you explicitly choose **Reset**
(or pass `--reset` ).
2026-01-13 01:18:18 +00:00
- If the config is invalid or contains legacy keys, the wizard stops and asks
you to run `clawdbot doctor` before continuing.
2026-01-01 21:09:24 +01:00
- Reset uses `trash` (never `rm` ) and offers scopes:
- Config only
- Config + credentials + sessions
- Full reset (also removes workspace)
2) **Model/Auth**
2026-01-10 17:36:50 +01:00
- **Anthropic API key (recommended)**: uses `ANTHROPIC_API_KEY` if present or prompts for a key, then saves it for daemon use.
2026-01-14 20:06:32 +00:00
- **Anthropic OAuth (Claude Code CLI)**: on macOS the wizard checks Keychain item "Claude Code-credentials" (choose "Always Allow" so launchd starts don't block); on Linux/Windows it reuses `~/.claude/.credentials.json` if present.
2026-01-22 00:42:04 +00:00
- **Anthropic token (paste setup-token)**: run `claude setup-token` on any machine, then paste the token (you can name it; blank = default).
2026-01-10 17:36:50 +01:00
- **OpenAI Code (Codex) subscription (Codex CLI)**: if `~/.codex/auth.json` exists, the wizard can reuse it.
- **OpenAI Code (Codex) subscription (OAuth)**: browser flow; paste the `code#state` .
2026-01-09 12:44:23 +00:00
- Sets `agents.defaults.model` to `openai-codex/gpt-5.2` when model is unset or `openai/*` .
- **OpenAI API key**: uses `OPENAI_API_KEY` if present or prompts for a key, then saves it to `~/.clawdbot/.env` so launchd can read it.
2026-01-10 21:37:38 +01:00
- **OpenCode Zen (multi-model proxy)**: prompts for `OPENCODE_API_KEY` (or `OPENCODE_ZEN_API_KEY` , get it at https://opencode.ai/auth).
2026-01-09 12:44:23 +00:00
- **API key**: stores the key for you.
2026-01-16 21:06:21 +00:00
- **Vercel AI Gateway (multi-model proxy)**: prompts for `AI_GATEWAY_API_KEY` .
- More detail: [Vercel AI Gateway ](/providers/vercel-ai-gateway )
- **MiniMax M2.1**: config is auto-written.
2026-01-12 00:57:17 +00:00
- More detail: [MiniMax ](/providers/minimax )
2026-01-13 00:22:03 +00:00
- **Synthetic (Anthropic-compatible)**: prompts for `SYNTHETIC_API_KEY` .
- More detail: [Synthetic ](/providers/synthetic )
2026-01-12 06:47:57 +00:00
- **Moonshot (Kimi K2)**: config is auto-written.
2026-01-17 17:35:40 +00:00
- **Kimi Code**: config is auto-written.
- More detail: [Moonshot AI (Kimi + Kimi Code) ](/providers/moonshot )
2026-01-01 21:09:24 +01:00
- **Skip**: no auth configured yet.
2026-01-09 22:01:57 +01:00
- Pick a default model from detected options (or enter provider/model manually).
2026-01-06 02:48:53 +01:00
- Wizard runs a model check and warns if the configured model is unknown or missing auth.
2026-01-06 21:29:41 +00:00
- OAuth credentials live in `~/.clawdbot/credentials/oauth.json` ; auth profiles live in `~/.clawdbot/agents/<agentId>/agent/auth-profiles.json` (API keys + OAuth).
2026-01-08 09:29:29 +01:00
- More detail: [/concepts/oauth ](/concepts/oauth )
2026-01-01 21:09:24 +01:00
3) **Workspace**
- Default `~/clawd` (configurable).
- Seeds the workspace files needed for the agent bootstrap ritual.
2026-01-10 14:51:21 -06:00
- Full workspace layout + backup guide: [Agent workspace ](/concepts/agent-workspace )
2026-01-01 21:09:24 +01:00
4) **Gateway**
- Port, bind, auth mode, tailscale exposure.
2026-01-11 01:51:07 +01:00
- Auth recommendation: keep **Token** even for loopback so local WS clients must authenticate.
- Disable auth only if you fully trust every local process.
- Non‑ loopback binds still require auth.
2026-01-01 21:09:24 +01:00
2026-01-13 07:15:57 +00:00
5) **Channels**
2026-01-01 21:09:24 +01:00
- WhatsApp: optional QR login.
- Telegram: bot token.
- Discord: bot token.
2026-01-23 00:19:23 +00:00
- Mattermost (plugin): bot token + base URL.
2026-01-01 21:09:24 +01:00
- Signal: optional `signal-cli` install + account config.
2026-01-02 01:19:22 +01:00
- iMessage: local `imsg` CLI path + DB access.
2026-01-13 07:15:57 +00:00
- DM security: default is pairing. First DM sends a code; approve via `clawdbot pairing approve <channel> <code>` or use allowlists.
2026-01-01 21:09:24 +01:00
6) **Daemon install**
2026-01-01 17:34:46 +01:00
- macOS: LaunchAgent
2026-01-05 18:38:30 +01:00
- Requires a logged-in user session; for headless, use a custom LaunchDaemon (not shipped).
2026-01-07 01:21:36 +01:00
- Linux (and Windows via WSL2): systemd user unit
2026-01-05 21:19:49 +00:00
- Wizard attempts to enable lingering via `loginctl enable-linger <user>` so the Gateway stays up after logout.
- May prompt for sudo (writes `/var/lib/systemd/linger` ); it tries without sudo first.
2026-01-13 07:58:47 +00:00
- **Runtime selection:** Node (recommended; required for WhatsApp/Telegram). Bun is **not recommended** .
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
7) **Health check**
2026-01-04 14:32:47 +00:00
- Starts the Gateway (if needed) and runs `clawdbot health` .
2026-01-11 02:42:14 +01:00
- Tip: `clawdbot status --deep` adds gateway health probes to status output (requires a reachable gateway).
2026-01-01 17:34:46 +01:00
2026-01-01 18:23:16 +01:00
8) **Skills (recommended)**
2026-01-01 21:09:24 +01:00
- Reads the available skills and checks requirements.
2026-01-13 07:58:47 +00:00
- Lets you choose a node manager: **npm / pnpm** (bun not recommended).
2026-01-01 21:09:24 +01:00
- Installs optional dependencies (some use Homebrew on macOS).
2026-01-01 17:34:46 +01:00
2026-01-01 18:23:16 +01:00
9) **Finish**
2026-01-01 21:09:24 +01:00
- Summary + next steps, including iOS/Android/macOS apps for extra features.
2026-01-08 00:13:10 +00:00
- If no GUI is detected, the wizard prints SSH port-forward instructions for the Control UI instead of opening a browser.
2026-01-09 07:02:42 +00:00
- If the Control UI assets are missing, the wizard attempts to build them; fallback is `pnpm ui:build` (auto-installs UI deps).
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
## Remote mode
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
Remote mode configures a local client to connect to a Gateway elsewhere.
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
What you’ ll set:
- Remote Gateway URL (`ws://...` )
2026-01-11 01:51:07 +01:00
- Token if the remote Gateway requires auth (recommended)
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
Notes:
- No remote installs or daemon changes are performed.
- If the Gateway is loopback‑ only, use SSH tunneling or a tailnet.
- Discovery hints:
- macOS: Bonjour (`dns-sd` )
- Linux: Avahi (`avahi-browse` )
2026-01-07 09:58:54 +01:00
## Add another agent
Use `clawdbot agents add <name>` to create a separate agent with its own workspace,
sessions, and auth profiles. Running without `--workspace` launches the wizard.
What it sets:
2026-01-09 12:44:23 +00:00
- `agents.list[].name`
- `agents.list[].workspace`
- `agents.list[].agentDir`
2026-01-07 09:58:54 +01:00
Notes:
- Default workspaces follow `~/clawd-<agentId>` .
2026-01-09 12:44:23 +00:00
- Add `bindings` to route inbound messages (the wizard can do this).
- Non-interactive flags: `--model` , `--agent-dir` , `--bind` , `--non-interactive` .
2026-01-07 09:58:54 +01:00
2026-01-01 21:09:24 +01:00
## Non‑ interactive mode
Use `--non-interactive` to automate or script onboarding:
```bash
2026-01-04 14:32:47 +00:00
clawdbot onboard --non-interactive \
2026-01-01 21:09:24 +01:00
--mode local \
--auth-choice apiKey \
--anthropic-api-key "$ANTHROPIC_API_KEY" \
--gateway-port 18789 \
--gateway-bind loopback \
2026-01-06 23:27:58 +01:00
--install-daemon \
--daemon-runtime node \
2026-01-01 21:09:24 +01:00
--skip-skills
2026-01-01 17:34:46 +01:00
```
2026-01-01 21:09:24 +01:00
Add `--json` for a machine‑ readable summary.
2026-01-01 17:34:46 +01:00
2026-01-08 14:44:40 +01:00
Gemini example:
```bash
clawdbot onboard --non-interactive \
--mode local \
--auth-choice gemini-api-key \
--gemini-api-key "$GEMINI_API_KEY" \
--gateway-port 18789 \
--gateway-bind loopback
```
2026-01-10 16:32:21 +01:00
Z.AI example:
```bash
clawdbot onboard --non-interactive \
--mode local \
--auth-choice zai-api-key \
--zai-api-key "$ZAI_API_KEY" \
--gateway-port 18789 \
--gateway-bind loopback
2026-01-16 21:06:21 +00:00
```
2026-01-16 14:40:56 +01:00
Vercel AI Gateway example:
```bash
clawdbot onboard --non-interactive \
--mode local \
--auth-choice ai-gateway-api-key \
--ai-gateway-api-key "$AI_GATEWAY_API_KEY" \
--gateway-port 18789 \
--gateway-bind loopback
```
2026-01-10 16:32:21 +01:00
2026-01-12 06:47:57 +00:00
Moonshot example:
```bash
clawdbot onboard --non-interactive \
--mode local \
--auth-choice moonshot-api-key \
--moonshot-api-key "$MOONSHOT_API_KEY" \
--gateway-port 18789 \
--gateway-bind loopback
```
2026-01-13 00:22:03 +00:00
Synthetic example:
```bash
clawdbot onboard --non-interactive \
--mode local \
--auth-choice synthetic-api-key \
--synthetic-api-key "$SYNTHETIC_API_KEY" \
--gateway-port 18789 \
--gateway-bind loopback
```
2026-01-10 01:07:56 +01:00
OpenCode Zen example:
```bash
clawdbot onboard --non-interactive \
--mode local \
--auth-choice opencode-zen \
2026-01-10 21:37:38 +01:00
--opencode-zen-api-key "$OPENCODE_API_KEY" \
2026-01-10 01:07:56 +01:00
--gateway-port 18789 \
--gateway-bind loopback
```
2026-01-07 09:58:54 +01:00
Add agent (non‑ interactive) example:
```bash
2026-01-08 07:49:07 +01:00
clawdbot agents add work \
--workspace ~/clawd-work \
--model openai/gpt-5.2 \
--bind whatsapp:biz \
--non-interactive \
--json
2026-01-07 09:58:54 +01:00
```
2026-01-03 16:04:19 +01:00
## Gateway wizard RPC
The Gateway exposes the wizard flow over RPC (`wizard.start` , `wizard.next` , `wizard.cancel` , `wizard.status` ).
Clients (macOS app, Control UI) can render steps without re‑ implementing onboarding logic.
2026-01-01 21:09:24 +01:00
## Signal setup (signal-cli)
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
The wizard can install `signal-cli` from GitHub releases:
- Downloads the appropriate release asset.
2026-01-04 14:32:47 +00:00
- Stores it under `~/.clawdbot/tools/signal-cli/<version>/` .
2026-01-13 06:16:43 +00:00
- Writes `channels.signal.cliPath` to your config.
2026-01-01 17:34:46 +01:00
2026-01-01 21:09:24 +01:00
Notes:
- JVM builds require **Java 21** .
- Native builds are used when available.
2026-01-07 01:21:36 +01:00
- Windows uses WSL2; signal-cli install follows the Linux flow inside WSL.
2026-01-01 21:09:24 +01:00
## What the wizard writes
2026-01-04 14:32:47 +00:00
Typical fields in `~/.clawdbot/clawdbot.json` :
2026-01-09 12:44:23 +00:00
- `agents.defaults.workspace`
- `agents.defaults.model` / `models.providers` (if Minimax chosen)
2026-01-01 21:09:24 +01:00
- `gateway.*` (mode, bind, auth, tailscale)
2026-01-13 06:16:43 +00:00
- `channels.telegram.botToken` , `channels.discord.token` , `channels.signal.*` , `channels.imessage.*`
2026-01-18 00:41:57 +00:00
- Channel allowlists (Slack/Discord/Matrix/Microsoft Teams) when you opt in during the prompts (names resolve to IDs when possible).
2026-01-01 21:09:24 +01:00
- `skills.install.nodeManager`
- `wizard.lastRunAt`
- `wizard.lastRunVersion`
- `wizard.lastRunCommit`
- `wizard.lastRunCommand`
- `wizard.lastRunMode`
2026-01-09 12:44:23 +00:00
`clawdbot agents add` writes `agents.list[]` and optional `bindings` .
2026-01-07 09:58:54 +01:00
2026-01-06 21:29:41 +00:00
WhatsApp credentials go under `~/.clawdbot/credentials/whatsapp/<accountId>/` .
Sessions are stored under `~/.clawdbot/agents/<agentId>/sessions/` .
2026-01-01 21:09:24 +01:00
2026-01-15 05:03:56 +00:00
Some channels are delivered as plugins. When you pick one during onboarding, the wizard
will prompt to install it (npm or a local path) before it can be configured.
2026-01-01 21:09:24 +01:00
## Related docs
2026-01-10 14:51:21 -06:00
- macOS app onboarding: [Onboarding ](/start/onboarding )
- Config reference: [Gateway configuration ](/gateway/configuration )
2026-01-13 06:16:43 +00:00
- Providers: [WhatsApp ](/channels/whatsapp ), [Telegram ](/channels/telegram ), [Discord ](/channels/discord ), [Signal ](/channels/signal ), [iMessage ](/channels/imessage )
2026-01-10 14:51:21 -06:00
- Skills: [Skills ](/tools/skills ), [Skills config ](/tools/skills-config )