SkyClaw Adds Encrypted Chat-Based API Key Setup for AI Agents

SkyClaw introduces a method for securely setting up API keys through chat interfaces without exposing them to LLMs or messaging platforms. The system addresses the workflow friction of traditional self-hosted agents that require SSH access, config file edits, and service restarts to change keys.
How It Works
The solution has two security layers:
- Layer 1 — System intercept: Key commands (
/addkey,/keys,/removekey) and encrypted blobs (starting withenc:v1:) are caught inmain.rsbefore messages reach the agent. The Rust process decrypts, validates, and saves to the vault, keeping the LLM completely uninvolved in credential operations. - Layer 2 — OTK encryption: Uses URL fragments (#) that are never sent to servers per RFC 3986. The flow: bot sends
setup.page/#one-time-256bit-key, browser encrypts API key locally using AES-256-GCM with WebCrypto, user pastes encrypted blob back in chat, bot decrypts at system layer and saves, then burns the one-time key.
Security Results
- Messaging platforms see only ciphertext (useless without OTK)
- The LLM sees nothing (intercepted before agent loop)
- GitHub Pages sees only
GET /setup - Works on any platform that sends/receives text
Comparison with Other Projects
The source identifies limitations in current solutions:
- OpenClaw: Uses config files, env vars, CLI wizard, optional external secret managers. GitHub issue #11829 states: "OpenClaw currently has multiple vectors where API keys can leak to the LLM or be exposed in chat." Issue #19137 documents
config.getleaking API keys into session transcript JSONL files. - OpenFang (Rust): Uses env vars referenced in
config.toml(api_key_env = "ANTHROPIC_API_KEY"), CLI init wizard, dashboard UI. Has strong at-rest security withZeroizing<String>and AES-256-GCM credential vault, but no secure key ingestion from chat. - NanoClaw: Uses
ANTHROPIC_API_KEYorCLAUDE_CODE_OAUTH_TOKENenv vars set during/setupskill. In Docker Sandbox mode, proxy-based system substitutes sentinel values, but still no encrypted key transit through messaging. - PicoClaw: Uses
~/.picoclaw/config.jsonwith env var overrides (PICOCLAW_PROVIDERS_*). Issue #972 documents subagent credential leakage when self-healing logic reads config.json and echoes raw API keys into chat logs.
The fundamental problem, as OpenClaw's issue #7916 states: "keys must be in plain text for [the system] to operate." External secret managers defer plaintext exposure to runtime, but no one encrypts the transit.
Technical Details
URL fragments work because per RFC 3986, # and everything after it is never sent to the server in HTTP requests, not included in the Referer header, not logged by CDNs/proxies/web servers, and processed entirely client-side. GitHub Pages receives GET /setup with zero knowledge of the OTK.
The message handler in main.rs has strict priority order: key commands and encrypted blobs are matched first and return immediately, never falling through to the agent. The LLM only receives messages that pass all checks. On the output side, a SecretCensorChannel wraps every outbound message.
📖 Read the full source: r/openclaw
👀 See Also

Indie Developer Unveils 'Ideanator' CLI Tool for Structuring Vague Ideas with Local LLMs
Ideanator is a CLI tool designed by a self-taught 19-year-old developer using local LLMs like Ollama/MLX. It structures vague ideas into well-defined concepts, completely offline.

Claude Code AFK Agent: Run Discord-Backed Autonomous Workers via Teams Plugin
Use the official channels plugin and teams agent with env var CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1 to spawn single workers from Discord. Includes full CLAUDE.md for a lead agent that dispatches, never works, and force-shuts down silent workers after 60 minutes.

AlterSpec v1.0: Runtime Policy Enforcement for AI Agents
AlterSpec v1.0 is an open-source runtime enforcement engine that sits between AI agents and their tools, evaluating actions against YAML-defined policies before execution. It provides allow/deny/review decisions, cryptographic policy signing, and audit logging.

OpenClaw's QMD Memory Search Fast Path Had Silent Bugs
OpenClaw's built-in memory search uses basic keyword matching, but users can switch to QMD for semantic search across workspace markdown files. A fast path through MCPorter was broken with three bugs causing every call to silently fail and fall back to slower CLI execution.