Smartflow for OpenClaw puts a governed gateway between OpenClaw and the model providers it calls. For an individual, Smartflow Halo enforces hard spend caps, keeps provider keys on the machine and records every call. For a company whose people run OpenClaw, Smartflow applies the same controls centrally, with approvals for actions that reach company systems.
What is OpenClaw?
OpenClaw is an open-source personal agent, MIT-licensed and self-hosted. It runs a local gateway, talks to its owner over more than twenty messaging channels, and uses tools: shell execution, files, a browser, web search and scheduled jobs. A heartbeat wakes the agent every thirty minutes by default. The project passed 390,000 GitHub stars in September 2026 and is maintained by the OpenClaw Foundation.
That design makes OpenClaw useful. It also creates three problems a company has to answer before its people run it at work.
What goes wrong?
Spend. Each heartbeat can send the agent's full context to the model. Early users reported overnight bills from heartbeats alone. OpenClaw's token documentation covers usage reporting and has no built-in hard cap.
Actions. The exec tool's security setting defaults to full on gateway hosts, and the sandbox is off by default. An agent that reads a malicious message or web page can act on it with its owner's access.
Supply chain and exposure. In February 2026 researchers found 341 malicious skills in the ClawHub registry delivering credential-stealing malware. At the end of January, Censys counted more than 21,000 OpenClaw instances exposed to the internet. The same week, CVE-2026-25253 allowed one-click remote code execution through the control interface; version 2026.1.29 fixed it. Several employers have since told staff to keep OpenClaw off work machines.
For an individual: Smartflow Halo
Smartflow Halo is a single binary that sits between OpenClaw and the model providers.
- Keys stay on the machine. Register the agent and Halo issues a virtual key mapped to your provider key, which stays in the operating system keychain or an encrypted vault. OpenClaw never holds the real credential, and one agent's key can be revoked without touching the others.
- Hard caps that work offline. A soft cap warns. A hard cap refuses requests. Caps and the kill switch are free, permanently.
- One command. OpenClaw does not read the standard base-URL environment variables.
halo openclaw applyadds Halo as OpenClaw's Anthropic provider. - Nothing goes to APERION. No relay is configured on install, and the dashboard runs on loopback.
- Secrets in tool calls. Halo fronts your MCP servers, resolves secret references only on the copy sent upstream, and scrubs leaked values from results.
For a company: Smartflow
When employees run OpenClaw against company systems, the question moves from cost to authority. Point each instance at the company's Smartflow endpoint with its own virtual key, issued to the employee who runs it. Smartflow then:
- attributes every call to that agent's key;
- redacts personal identifiers before prompts leave your infrastructure;
- allowlists the models and routes each key may use, and applies Shield rules to the agent's tool calls;
- holds tool calls that reach company systems outside policy for approval by a person with approval rights;
- records every call and decision in a hash-chained, time-stamped log that exports to your SIEM.
| Action the agent attempts | Outcome |
|---|---|
| Send email or messages to external recipients from a company account | Held for approval |
| Change a record in a company system through MCP | Held for approval, with step-up |
| Share or export a file outside the company | Held for approval, with step-up |
| Call a model outside the key's allowlist | Refused |
OpenClaw's built-in tools, including shell and browser, run on the host and do not pass through MCP. Govern them with OpenClaw's own settings, below. Smartflow records the model's requests to use them, because those requests arrive in the model's responses.
Harden OpenClaw itself
- Set
tools.exec.securitytoallowlistandtools.exec.asktoon-miss. - Turn on the sandbox for all sessions, or at least for sessions other than the main one.
- Keep the gateway on localhost and direct-message access on
pairing. - Run
openclaw security auditafter every configuration change. - Review every skill before installing it, and keep OpenClaw current.
Should a company allow it?
A company can allow OpenClaw on work machines when three conditions are met: every instance calls models through the company's Smartflow endpoint, every connection to a company system goes through Smartflow's MCP gateway, and the hardening settings above are enforced. Without those, the agent carries an employee's access with no one watching the spend, the actions or the record.
Related: Smartflow for Hermes Agent covers the other widely run self-hosted agent.
Quick answers
Does OpenClaw have a spending limit?
Its documentation covers usage reporting through the /status and /usage commands and does not describe a built-in hard cap. Smartflow Halo adds a soft cap and a hard cap per agent, enforced on the machine, including when it is offline.
Does Halo send my prompts anywhere?
Halo runs on your machine. The exact-match cache and everything on the free tier are local, no relay is configured on install, and nothing goes to APERION. The optional semantic cache is off by default and calls an embedding provider on your own key.
Why does OpenClaw need a provider entry?
OpenClaw reads custom endpoints from its provider configuration and does not document the standard base-URL environment variables. Declare a separate provider that points at Halo or Smartflow. halo openclaw apply writes the Anthropic provider entry for you.
Download the full guide
The PDF adds provider configuration for Halo and for Smartflow, a hardened configuration baseline, a decision map, and a checklist for companies deciding whether to allow OpenClaw on work machines.
Sources
Verified as of September 25, 2026.
- OpenClaw: GitHub repository, release 2026.9.6, documentation on heartbeat, custom providers, security, sandboxing, exec approvals, token use.
- Censys, OpenClaw in the wild, January 31, 2026.
- The Hacker News, CVE-2026-25253 and 341 malicious ClawHub skills, February 2, 2026.
- Slashdot, citing Wired, employer restrictions on OpenClaw, February 19, 2026.
- Notebookcheck, OpenClaw heartbeat costs, February 4, 2026.
Claude, Claude Code and Claude Cowork are products of Anthropic. OpenClaw is maintained by the OpenClaw Foundation. Hermes Agent is a project of Nous Research. APERION is not affiliated with or endorsed by these organizations.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs