How to install OpenClaw and connect Telegram
About thirty minutes from nothing to an agent you can message in Telegram. Commands are copied from the official docs; check them against your version.
What you need
- A computer or VPS with macOS, Linux, WSL2 or Windows
- Node 24.16+ or Node 26 (the installer can add it)
- An API key or subscription for a model, or a local model
- A Telegram account
Steps
- 1
Pick where it runs
Your own laptop is fine for trying it. For an always-on agent use a small VPS or home server. Do not expose the gateway port to the internet.
- 2
Install OpenClaw
Run the official installer. It detects your OS, installs Node if needed, installs OpenClaw and starts onboarding.
# macOS / Linux / WSL2 curl -fsSL https://openclaw.ai/install.sh | bash # Windows (PowerShell) iwr -useb https://openclaw.ai/install.ps1 | iex
- 3
Run onboarding and install the service
Choose Quick start to reuse detected AI access, or Custom setup for the full flow. Then install the gateway as a background service so it survives reboots.
openclaw onboard # after quick start, stop the foreground gateway (Ctrl+C) and install the service openclaw gateway install
- 4
Create a Telegram bot and add it
In Telegram, message @BotFather (check the handle exactly), run /newbot and copy the token. Add it to OpenClaw and check the channel status.
openclaw channels add --channel telegram --token <bot-token> openclaw channels status --probe
- 5
Approve your own account
Send any message to your bot. Unknown senders get a pairing code instead of an answer; approve yours within an hour.
openclaw pairing list telegram openclaw pairing approve telegram <CODE>
- 6
Lock it down
Run the built-in security audit and keep the gateway updated. Versions before 2026.4.22 have known critical flaws.
openclaw security audit openclaw update --channel stable
Tips from experience
- Keep gateway.bind on loopback and reach it over SSH or Tailscale, never an open port.
- Leave dmPolicy on pairing so strangers who find your bot cannot use it.
- Treat third-party skills like browser extensions: install few, from sources you trust.
- Set exec approvals to always ask until you trust your setup.