1Password CLIの導入と認証を確認し、保存したパスワードやAPIキーをコマンドや設定へ渡します。デスクトップ連携やサービスアカウントにも対応します。
- 1Password CLIを導入したいとき
- APIキーをコマンドに渡したいとき
- CIでサービスアカウント認証を使う
Diagnose OpenClaw Control UI browser and native Android, iOS, or macOS node connection failures across route, auth, pairing, QR/setup-code, and reconnect states.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Goal: fix one exact client against one exact Gateway, then prove that client's fresh connection.
Record the target environment/profile, OpenClaw binary, config/state root, Gateway URL/port, and service before changing anything.
openclaw, proof environment, or similarly named deployment.Identify the target Gateway before changing pairing or auth.
Classify from the request and Gateway log before choosing commands:
client=openclaw-control-ui or mode=webchat.role=node.A phone can be either client. Do not use openclaw qr or openclaw nodes status for a phone browser; those belong to native mobile/node pairing.
Run these through the locked target:
openclaw gateway status --deep
openclaw logs --follow --json
openclaw devices list
openclaw config get gateway.mode
openclaw config get gateway.bind
openclaw config get gateway.remote.url
openclaw config get gateway.auth.mode
openclaw config get gateway.auth.allowTailscale
openclaw config get gateway.tailscale.mode
Have the client retry once while logs are live. Correlate its client ID, mode, platform, address, auth result, device ID, user, and close code. Ignore other paired devices.
Interpret the first failed transition:
token_missing, password_missing, mismatch, or Tailscale identity failure: auth failed before pairing, so an empty pending list is expected.pairing required: route and auth succeeded; approve the exact pending request.authenticated user connected / webchat connected: match the exact client; if followed by 1006, preserve auth/pairing and inspect lifecycle, transport, proxy, or reconnect.1006 without either application-level connected log does not prove auth/pairing; inspect the earlier handshake transition.Choose one topology: same machine, LAN, tailnet, or public reverse proxy. Do not mix them.
gateway.tailscale.mode=off means OpenClaw is not managing Serve/Funnel. It does not prove that Tailscale or an externally managed Serve route is absent.tailscale status --json
tailscale serve status --json
Match the client's URL to the listener/proxy route reaching the locked Gateway.
Restore browser auth before looking for a pairing request:
openclaw dashboard on the Gateway host for a one-time signed handoff. Use --no-open only when the operator can retrieve that host's clipboard, and keep the host browser/clipboard outside agent tooling. Never capture dashboard --json: it can expose the handoff and shared credentials. Never relay, rewrite, or send a loopback handoff URL to a remote phone.gateway.auth.allowTailscale only for that intended trust boundary. Verified Tailscale Control UI auth with browser device identity can skip pairing.After auth succeeds:
pairing required; verified Tailscale identity can skip it.pairing required, re-list devices and approve the exact request ID.1006, preserve auth/pairing and inspect reconnect evidence.Inspect the native route through the locked target without exposing the setup credential:
openclaw qr --json | jq '{gatewayUrl, gatewayUrls, auth, access, accessDowngraded, urlSource}'
For a CLI controlling a remote Gateway, add --remote before --json; it selects gateway.remote.url and remote credentials. If the redaction filter is unavailable, do not run raw QR JSON in agent-visible output.
Verify gatewayUrl and urlSource. The setup code is password-equivalent: have the operator copy it from Control UI → Devices → Pair device, or run openclaw qr --setup-code-only in a terminal outside agent tooling and paste it directly into the official app. Never relay it through agent/chat/tool output. Generate a fresh code after a URL/auth fix or expiry.
If the app reports pairing required:
openclaw devices list
openclaw devices approve --latest # preview only; exits without approval
openclaw devices approve <requestId>
openclaw nodes status
--latest only previews the current request; never treat it as approval. Re-list immediately before the exact-ID command because retries can supersede the request. Never approve by position, age, or similarity.
Before approval, match available request, device/public-key, client, mode/role, platform, address, user, and retry-time facts.
Declare success only after a new attempt made after the final change proves all applicable checks:
openclaw nodes status;A QR/setup code, launched browser, empty pending list, approval, paired-device count, or Tailscale ping proves only one transition.
Report the diagnosis, chosen route/auth lane, exact-client evidence, and any remaining failed transition.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
1Password CLIの導入と認証を確認し、保存したパスワードやAPIキーをコマンドや設定へ渡します。デスクトップ連携やサービスアカウントにも対応します。
OpenClawへの自然な言葉の依頼をClaude Codeなどの外部コーディングエージェントへ振り分け、作業の開始や継続、スレッド内の会話をつなぐスキルです。
Add and live-prove a model provider with non-interactive config one-liners, without exposing credentials.
日本語の概要は準備中です。原文の説明を表示しています。
Requested GitHub PR/issue agent transcripts: redact, trim, preview, and insert safely.
日本語の概要は準備中です。原文の説明を表示しています。
macOSのApple Notesをエージェントから作成・検索・編集・削除し、フォルダ間の移動やHTML・Markdownへの書き出しを行うスキル。
Apple Remindersの予定付きToDoをMacから確認・追加・編集するスキル。リストの管理や完了・削除にも対応し、iPhoneやiPadで見るタスクを整理できます。