Connect using OpenClaw mobile clients
Use the OpenClaw mobile app to chat with the agent running on Olares. Pair the phone once, then use the same Gateway address at home and away with LarePass VPN enabled.
Prerequisites
- Complete OpenClaw setup on Olares, including configuring a model for chat.
- Install LarePass on the phone and sign in with the Olares account that owns this OpenClaw instance.
- Upgrade OpenClaw to Chart version 1.0.47 or later.
Important
Keep LarePass VPN enabled on the phone whether you use local Wi-Fi or mobile data. On the local network, LarePass automatically uses an Intranet connection. OpenClaw tokens and setup codes do not replace Olares entrance authentication.
Confirm the Gateway address and Auth Level
- In Olares, open Settings > Applications > OpenClaw.
- Under Entrances, open OpenClaw Gateway and copy its domain. Keep its authentication level set to Internal.
The Gateway entrance is hidden from the Launchpad. Its address differs from OpenClaw CLI, Control UI, and the Olares Desktop address. If you use a cloned app, select that instance's Gateway entrance.
In the examples below, replace efa2f8ec2.yourolaresid.olares.com with that domain. The connection URL is wss://efa2f8ec2.yourolaresid.olares.com, using port 443 and TLS. The internal service port 18789 is not the port to enter when using the Olares entrance.
Install and connect the client
Approve a pending device
Leave the phone on its connection screen with LarePass VPN enabled. In OpenClaw CLI, run:
bashopenclaw devices listIn Pending, identify your phone by its device name and device ID. Review the requested roles and scopes. Use the current Request ID from this list:
bashopenclaw devices approve <requestId>Return to the phone and retry the connection or confirm that you have approved it.
Run
openclaw devices listagain. Mobile apps use bothnodeandoperatorconnections; if another request appears for your phone, review and approve that current request too.
Request IDs can change
If a retry changes the requested role, scopes, or public key, the Gateway can replace a pending request with a new one. The phone may still display an earlier error and Request ID.
For unknown requestId or a mismatch between the phone and CLI, refresh openclaw devices list and use the current request for the verified device. Do not repeatedly approve an old ID or approve an unrelated device. If the phone is already under Paired and there are no pending requests, reconnect; another approval is unnecessary.
Verify local and remote access
Keep the OpenClaw app open in the foreground and check the connection:
bashopenclaw devices list openclaw nodes statusThe device should be paired, and its node should be connected while the app is active.
Send a short chat message and confirm a reply. Pairing alone does not verify the model configuration.
With LarePass VPN still enabled, turn off Wi-Fi and switch the phone to mobile data. Reconnect using the same saved Gateway address, then send another message.
You do not need to change the domain, port, or TLS setting when moving between networks. Mobile operating systems may suspend the app in the background; foreground the app when testing node capabilities.
Troubleshooting
| Symptom | What to check |
|---|---|
Expected HTTP 101 response but was '400 Bad Request' | The WebSocket handshake failed before pairing. First check that LarePass VPN is enabled on this phone, the host is the Gateway entrance, and the port is 443 with TLS. A 400 alone does not identify which proxy returned it. |
| QR advertises loopback, a container IP, or the wrong domain | Generate it again with openclaw qr --url 'wss://efa2f8ec2.yourolaresid.olares.com'. |
| Setup code expired or rejected | Generate a fresh QR code and scan it again. Do not use the pairing credential in the manual token field. |
| Token authentication fails | Retrieve the current token from this OpenClaw instance. Do not use the Olares password or a token from another clone. |
| Pairing command shown on the phone fails | Run openclaw devices list in OpenClaw CLI, identify your phone’s pending request, then run openclaw devices approve <requestId>. The phone may display an older requestId; use the current requestId from CLI. |
pairing required or unknown requestId | Follow Approve a pending device, using the latest request for your phone. |
| Paired in CLI, but the phone still shows an old error | Reconnect with VPN enabled. If necessary, close and reopen the mobile app. |
iOS reports Gateway setup incomplete | Generate a fresh QR/setup code and pair again to obtain both node and operator credentials. |