Safety & Cost Control
Secure your instance and prevent bankruptcy from API costs.
Section A: Security Hardening
SCAM ALERT: No Crypto Token OpenClaw (formerly Moltbot) is a free open-source tool. There is NO official cryptocurrency token. Any 'OpenClaw Token' or 'Clawd Token' you see on social media is a SCAM. Do not connect your wallet.
Close the Exposed Admin Port 8080
Critical: By default, OpenClaw opens an unauthenticated HTTP admin console on port 8080. If exposed to the internet, attackers can steal API keys, exfiltrate data, or use your instance as a backdoor.
For Docker Deployments
Always bind to localhost only in your '<'code'>'docker-compose.yml'<'/code'>':
ports:
- "127.0.0.1:8080:8080" # Safe: localhost only
# NOT: "8080:8080" # Dangerous: exposed to all interfacesFirewall Rules (Linux)
# Block external access to port 8080
sudo ufw deny from any to any port 8080
# Or with iptables
sudo iptables -A INPUT -p tcp --dport 8080 -j DROP
sudo iptables -A INPUT -p tcp -s 127.0.0.1 --dport 8080 -j ACCEPTRun the Security Audit
OpenClaw includes a built-in security scanner:
# Check for common misconfigurations
moltbot security audit
# Auto-fix safe issues
moltbot security audit --fixThe '<'code'>'--fix'<'/code'>' flag will: tighten '<'code'>'groupPolicy="open"'<'/code'>' to '<'code'>'groupPolicy="allowlist"'<'/code'>', and enable sensitive logging redaction.
Encrypting Your config.json Credentials
OpenClaw stores credentials in plaintext under '<'code'>'~/.clawdbot/'<'/code'>'. For production:
Option 1: Use Environment Variables
# .env file (add to .gitignore!)
ANTHROPIC_API_KEY=sk-ant-xxx
OPENAI_API_KEY=sk-xxx
TELEGRAM_BOT_TOKEN=123456:ABC...
# Reference in config or pass to DockerOption 2: File System Encryption
# macOS: Enable FileVault (System Preferences > Security & Privacy)
# Linux: Use encrypted home directory or LUKS
# Or encrypt just the credentials directory:
encfs ~/.clawdbot-encrypted ~/.clawdbotRotate Keys Regularly
If you suspect exposure:
- Revoke/regenerate keys in the provider dashboard (Anthropic, OpenAI, Telegram BotFather)
- Update '<'code'>'~/.clawdbot/credentials/'<'/code'>' or your environment variables
- Restart the gateway: '<'code'>'openclaw gateway restart'<'/code'>'
Section B: Stop the Bleeding (Cost Control)
Real-world warning: Users have reported spending $300+ in just 2 days with default settings. OpenClaw can burn through tokens fast, especially with Claude Opus.
Context Pruning: Use max_tokens
Large context windows = large bills. Configure token limits to prevent runaway costs:
// In your moltbot config or agent settings:
{
"model": {
"max_tokens": 4096, // Limit output tokens
"max_context_tokens": 32000 // Limit context window
}
}Enable Cache Pruning
OpenClaw supports automatic context pruning when cache TTL expires:
// Enable cache-TTL pruning to reduce cache write costs
{
"cache": {
"enabled": true,
"ttl": "5m", // Cache TTL
"prune_on_expire": true // Prune context when cache expires
}
}Heartbeat to Keep Cache Warm
For Anthropic, cache reads are 10x cheaper than input tokens. Set heartbeat interval just under the cache TTL:
// If cache TTL is 1 hour, use 55-minute heartbeat
{
"heartbeat": {
"enabled": true,
"interval": "55m"
}
}Switch to Cheaper Models
Not every task needs Claude Opus. Use tiered models based on task complexity:
| Model | Input/1M | Output/1M | Best For |
|---|---|---|---|
| Claude Haiku 3.5 | $1 | $5 | Simple tasks, quick responses |
| Claude Sonnet 3.5 | $3 | $15 | Balanced performance |
| Claude Opus 3.5 | $5 | $25 | Complex reasoning only |
| Gemini Flash | ~$0.075 | ~$0.30 | Low-priority, high-volume |
| Local (GLM-4) | Free | Free | Offline, sensitive data |
Configure Model Routing
// Route simple tasks to cheaper models
{
"routing": {
"default": "claude-3-5-haiku", // Default to cheapest
"complex": "claude-3-5-sonnet", // Upgrade for complex tasks
"reasoning": "claude-3-5-opus" // Only when needed
}
}Use Anthropic Batch API
For non-urgent tasks, the Batch API offers '<'strong'>'50% discount'<'/strong'>':
// Enable batch processing for background tasks
{
"batch": {
"enabled": true,
"queue_threshold": 10, // Batch when 10+ messages queued
"max_wait": "30s" // Or after 30 seconds
}
}Set Up Cost Alerts
Monitor spending before it gets out of control:
Anthropic Console
- Go to '<'a href="https://console.anthropic.com" target="_blank" rel="noopener noreferrer"'>'console.anthropic.com'<'/a'>'
- Navigate to Usage & Limits
- Set a monthly spending limit
- Enable email alerts at 50%, 80%, 100% thresholds
OpenAI Dashboard
- Go to '<'a href="https://platform.openai.com" target="_blank" rel="noopener noreferrer"'>'platform.openai.com'<'/a'>'
- Settings → Limits
- Set hard usage cap
Section C: What to decide first on call
If you are putting OpenClaw into a real production workflow, do not stop at generic advice like keep it safe and control cost. On call, first decide whether the current issue is exposure, credential risk, or spend runaway.
- If port 8080 is still exposed publicly, treat it as the highest-priority risk. Close the exposure before debugging features.
- If API spend is rising while the service still appears usable, treat it as a stop-loss case. Route to cheaper models, cap tokens, and add budget guardrails first.
- If you suspect credential leakage, do not restart services just to hide symptoms. Rotate keys first and preserve access and billing evidence.
Section D: Pick the stop-loss path after search
If you arrived from searches like OpenClaw cost spike, exposed 8080, or leaked API key, use these three routes before reading the full checklist.
- Public 8080 or unauthenticated admin surface: treat it as a safety FIX and close the entry point first.
- Unexpected billing climb: treat it as a cost FIX, downgrade models, cap tokens, and enable budget limits.
- Credential, log, or session exposure: treat it as a credential FIX, rotate keys, and preserve evidence.
Section D: What to verify before calling it closed
- Public traffic can no longer reach unauthenticated admin surfaces or the 8080 entry point.
- Critical credentials have been rotated and old keys are confirmed inactive.
- Model routing, max token limits, budget caps, or alerts are active rather than parked in a TODO.
- The incident record keeps the exposure surface, spend curve, remediation steps, and follow-up guardrails.
Section E: Exact safety and cost searches this page should answer
Use this section when the query is already high intent and the reader needs a decision path, not a general platform overview.
OpenClaw exposed 8080 port what to do— close public access first, then verify the admin surface is not reachable without authentication.OpenClaw API cost spike stop loss— cap spend, downgrade routing, reduce max tokens, and add billing alerts before feature debugging.OpenClaw leaked API key rotate credentials— rotate keys immediately, invalidate old credentials, and keep the evidence needed for incident review.
Section C: If you arrived from the homepage, migration guide, or release note
GA4 for 2026-05-12 shows /zh/safety-and-cost among the stronger Chinese entrances. Split safety/cost intent from installation, migration, release evaluation, and CLI regression before treating every symptom as the same path.
- OpenClaw is not installed cleanly yet: finish install and local validation first, then return here to set port, credential, and budget guardrails. Read the Mac install guide
- You just migrated from Moltbot: confirm old commands, directories, and environment variables are cleaned up, otherwise safety and cost settings may land in the wrong path. Read the 1-minute migration guide
- You are evaluating 2026.3.13: use this page as part of the production-readiness checklist before choosing a team baseline. Read the 2026.3.13 release note
- The CLI already hangs for 20-40 seconds: separate performance regression from context/model cost runaway; command-path latency belongs in the dedicated triage page. Read the CLI regression triage
This routing turns the safety/cost entry from a risk note into a higher-intent next-step hub.
OC NEWS