Get your API keys out of openclaw.json
OpenClaw keeps your model and tool keys in plain text by default. MoltenRock moves them into an encrypted vault on your Mac and leaves a pointer behind.
The short answer
To secure OpenClaw’s API keys, move them out of openclaw.json and let OpenClaw resolve them from a vault. MoltenRock does this on a Mac: pair OpenClaw, choose the keys to protect, and MoltenRock moves each plaintext key into its Secure Enclave vault and leaves a pointer in the config. You run the one cleanup command it shows, then openclaw secrets reload. Every key OpenClaw resolves is logged.
The problem
openclaw.json is a plaintext key ring
- Plain text on diskModel keys, bot tokens and tool keys sit in one readable file.
- Copies multiplyOpenClaw keeps its own copies and regenerates derived files, so keys reappear.
- Anything can read itAny process, and any other agent in that folder, can open the file.
How MoltenRock handles it
A vault OpenClaw asks by name
- Sealed keysEach key lives in MoltenRock’s Secure Enclave vault, encrypted at rest.
- Pointers, not valuesopenclaw.json keeps a reference; OpenClaw resolves the real value from MoltenRock.
- Every release loggedThe Activity log shows when OpenClaw resolved which key.
- ReversibleLeave anytime: keys are written back.
How it works
Three steps
- 01PairIn MoltenRock: OpenClaw → Add OpenClaw agent → name it → Pair.
- 02Migrate and clean upChoose the keys, then run the one cleanup command MoltenRock shows.
- 03Reload secretsRun openclaw secrets reload. MoltenRock can’t see the gateway, so this step is yours.
Straight answer
Gotchas we’ve seen
Stays on your Mac
- Your keys, sealed in the vault
- A pointer in openclaw.json instead of the value
- A log of every key OpenClaw resolves
Leaves your Mac
- Each key, to OpenClaw, when it resolves it to make a call
- OpenClaw’s own key-database row can shadow the vault until it’s removed (check with openclaw models auth list)
- Nothing to a MoltenRock server; there is none
Questions
What people ask first
A key reappears after I migrated it. Why?
OpenClaw keeps its own copies. The durable removal is OpenClaw’s key-database row; until it’s gone, OpenClaw’s copy shadows the vault.
Is the cleanup risky?
OpenClaw’s cleanup is all-or-nothing: if anything’s wrong it changes nothing, so a failure costs a retry, never a key.
Does this cover email too?
Email uses its own token; pairing OpenClaw never touches your mail. For email, see MoltenMail.
What does it cost?
Free with 3 keys and 1 agent; MoltenRock Pro is unlimited from $9.99 a month.
OpenClaw, without the plaintext.
Free for Mac. No account, no cloud, no telemetry.