An API key authorizes requests to a service. OAuth is a browser-based sign-in and consent flow. Available methods depend on the provider and runtime; a consumer subscription does not automatically include API credits.
Connect without leaking credentials
Use onboarding for first setup or openclaw configure for targeted changes. Follow the provider's supported sign-in route. Never send a key, refresh token, or private verification link in ordinary chat, public screenshots, source control, or a support ticket.
Current OpenClaw supports a shared secret store and SecretRefs. The Control UI's Settings → Secrets and masked secret-entry prompts can store values without putting the value in the model conversation. Plain-text messaging apps do not render those secure entry forms.
Inspect health, not secret values
openclaw models status
openclaw secrets auditCredentials are not all stored in openclaw.json. Depending on the integration, they may live in auth profiles, the shared store, environment-backed references, or external secret sources. Protect the state directory and backups too. Secret storage does not itself configure a provider: the correct route must reference the credential.
When authentication fails
- 401: inspect the affected provider and credential source.
- invalid_grant: investigate the OAuth session and use that provider's sign-in flow; generating an unrelated API key is not a universal fix.
- 429 or quota exhausted: check limits and billing before replacing credentials.
After a repair, test one small request. A stored credential or a green inventory row alone does not prove live access.