Code Pluginsource linkedVerified

ClickClackv2026.9.2

OpenClaw ClickClack channel plugin

@openclaw/clickclack·runtime clickclack·by @openclaw
openclaw plugins install clawhub:@openclaw/clickclack
Latest release: v2026.9.2Download zip

Compatibility

Built With Open Claw Version
2026.9.2
Min Gateway Version
>=2026.6.9
Plugin Api Range
>=2026.9.2
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Credentials
Network access to the configured ClickClack server and credential handling via config, env, token file, or secret references are proportionate for a chat integration; setup-code claiming includes URL validation, HTTPS/loopback restrictions, no redirects, timeouts, and SSRF guard usage.
Install Mechanism
The package metadata declares an OpenClaw channel plugin with dist exports, setup entry, npm/ClawHub install specs, and dependencies on ws and zod; no package lifecycle scripts or unrelated install-time execution were found.
Instruction Scope
Runtime behavior is governed by channel configuration such as baseUrl/apiBaseUrl, workspace, allowFrom, requireMention, allowBots, toolsAllow, commandMenu, agentActivity, and discussions; defaults are functional but broad enough that users should scope senders and discussion settings for shared workspaces.
Persistence & Privilege
The plugin persists bounded discussion binding, generation, revoked-channel, and installation state and registers scoped session-discussion access; the README discloses the SQLite binding state and the code limits side-session tools to the attached main session.
Purpose & Capability
The plugin reads ClickClack bot credentials, connects to a configured ClickClack API/WebSocket endpoint, receives chat messages, sends replies/uploads, can sync command menus, and can optionally create managed discussion channels; these capabilities match the stated channel-plugin purpose.
Assessment
Install only for ClickClack workspaces where you want OpenClaw to read incoming messages and post responses. Use a least-privilege bot token, restrict allowFrom/requireMention in shared spaces, leave agentActivity and discussions disabled unless you want progress/tool traces or managed public discussion channels, and verify any apiBaseUrl points to infrastructure you control.

Verification

Tier
source linked
Scope
artifact only
Summary
Validated package structure and linked the release to source metadata.
Commit
3928bad9badf
Tag
3928bad9badfcb6c7d140530435e806fb8092190
Provenance
No
Scan status
clean

Tags

beta
2026.7.2-beta.7
latest
2026.9.2

ClickClack OpenClaw channel

Official OpenClaw channel plugin for ClickClack.

Install

openclaw plugins install @openclaw/clickclack

Setup

The recommended setup path uses the one-time command generated by ClickClack:

openclaw channels add clickclack --code 'https://clickclack.example.com/#XXXX-XXXX-XXXX'

Split-origin and path-mounted ClickClack deployments generate an exact /api/bot-setup-codes/claim#CODE endpoint. OpenClaw validates the versioned claim response and saves its canonical API base.

For manual token setup:

openclaw channels add clickclack \
  --base-url https://clickclack.example.com \
  --token ccb_... \
  --workspace default
openclaw gateway

Run openclaw onboard for guided setup. The workspace value can be a wsp_... id, slug, or display name.

For the default account only, --use-env reads CLICKCLACK_BOT_TOKEN; config storage is the normal setup path.

Public and private endpoints

baseUrl is the public ClickClack URL used in links that people open. Set the optional apiBaseUrl when the gateway should call ClickClack through a different server-to-server endpoint:

{
  channels: {
    clickclack: {
      baseUrl: "https://clack.openclaw.ai",
      apiBaseUrl: "http://127.0.0.1:8484",
      token: { source: "env", provider: "default", id: "CLICKCLACK_BOT_TOKEN" },
      workspace: "default",
    },
  },
}

This same-host pattern lets the public hostname stay fully protected by an authentication gateway such as Cloudflare Access while the local OpenClaw gateway talks directly to ClickClack. REST requests, setup verification, and the realtime WebSocket use apiBaseUrl; browser-facing discussion links keep using baseUrl. When apiBaseUrl is unset, it defaults to baseUrl.

Command menus

ClickClack command menus are enabled by default. At gateway startup, the extension publishes OpenClaw's native commands for composer autocomplete, labeled with the bot's handle. The bot token must include commands:write; current bot:write and bot:admin bundles include it.

Set commandMenu: false on an account to disable menu sync. Sync failures do not prevent the gateway from starting, so older tokens and ClickClack servers continue to work without a menu.

Discussions

ClickClack can create one managed channel for each OpenClaw session:

The account token needs channels:write, which is included in bot:admin but not in the normal bot:write setup token. The ClickClack server must also support and return the managed-channel fields used by this integration.

{
  channels: {
    clickclack: {
      baseUrl: "https://clickclack.example.com",
      token: { source: "env", provider: "default", id: "CLICKCLACK_BOT_TOKEN" },
      workspace: "default",
      discussions: {
        enabled: true,
        workspace: "default",
        controlUrlBase: "https://team.openclaw.ai",
        section: "Sessions",
      },
    },
  },
}

Opening a session discussion creates a public, externally managed channel and stores its binding in the ClickClack plugin's SQLite state. Session label and category changes remain reflected in the channel, but session archive, restore, reset, and deletion never archive or replace it. ClickClack owns channel archive and restore independently. workspace defaults to the account workspace, and section defaults to Sessions. controlUrlBase adds canonical /chat/<agent>/<session-ref> links to the OpenClaw Control UI, preserving base paths. Main sessions use /chat/<agent>.

ClickClack-managed embed URLs explicitly advertise host-theme support. The Control UI uses that provider-owned capability to apply its full palette before the sidebar first paints and to stream live palette changes without rewriting opaque or signed discussion URLs from other providers.

Enable discussions on exactly one ClickClack account. Multiple enabled discussion accounts are rejected because the session discussion provider does not have an account selector.

Messages in the managed channel run in a stable side session under the same agent id as the attached main session. The plugin installs a scoped host grant for sessions_history, session_status, and sessions_send between that side session and its attached main session, so tools.sessions.visibility can be set explicitly to tree for narrower access than the default all. A second host-side policy blocks session discovery and alternate targets; the side-agent prompt is not the authorization boundary. The agent still needs those three tools in its effective tool allowlist.

The binding separates durable room identity from a replaceable exact-session attachment. Resetting a reusable session key keeps the ClickClack channel, history, URL, and ownership reference while rotating the side-session identity and scoped grant. The previous side session cannot access the new main session. Messages arriving through an inactive, disabled, or retargeted managed binding are dropped instead of falling back to the account's normal channel routing. Released bindings leave a durable revoked-channel marker so delayed realtime events remain fail-closed. Remote ownership is keyed by ClickClack server and channel id, so renaming the local account cannot turn a managed channel into an ordinary one.

Managed-channel ownership references include a durable per-installation id, so two OpenClaw gateways using the same ClickClack workspace do not adopt each other's discussion channels. They also include the destination and a durable binding generation, so an account or workspace round trip cannot re-adopt a previous channel. Changing or removing controlUrlBase is reflected on the next lifecycle reconciliation pass.

If a channel-create response is lost, the pending ownership reservation temporarily quarantines otherwise-unbound events in that workspace. The same coarse reconciler then adopts the created channel or clears the ambiguous attempt; a reset cannot duplicate or archive the durable room.

Workspace and account moves release local attachment authority without archiving the old channel. A workspace-scoped replacement token is never tried against the old channel.

The main session gets a read-only discussion tool that pulls the latest channel messages, including recent thread replies. The pull uses bounded history and thread-request budgets; its output says when older active threads may have been omitted. It never posts, archives, renames, or otherwise mutates the discussion.

Docs

See docs/channels/clickclack.md in the OpenClaw repository, or the published docs at https://docs.openclaw.ai/channels/clickclack.