Cloudflare Access VPS for Openclaw

Wrap your VPS-hosted AI agents in a Cloudflare Zero Trust identity gate to require SSO or MFA before traffic reaches your server.

maverick-software
v1.0.0
Mar 9, 2026
0
938
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install cloudflare-access-vps

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install cloudflare-access-vps using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Cloudflare Access VPS?

The Cloudflare Access VPS skill allows developers to implement a robust security perimeter around their AI agents. By leveraging Cloudflare Zero Trust, this skill ensures that every request to your agent's domain—including webhooks, APIs, and the control UI—is authenticated at the network edge. It serves as an essential component for users of Openclaw Skills who need to protect their cloud deployments from unauthorized access while providing seamless login experiences via Google, GitHub, or Email OTP.

This architecture ensures that unauthenticated traffic never reaches your VPS, significantly reducing the attack surface. It works in tandem with existing Cloudflare Tunnels to provide a secure, encrypted path from the browser to your local OpenClaw instance without exposing open ports to the public internet.

Cloudflare Access VPS Use Cases

  • Securing cloud-deployed AI agents behind a corporate or personal identity provider.
  • Adding Multi-Factor Authentication (MFA) to specific agent subdomains for sensitive tasks.
  • Implementing per-agent access policies to restrict usage to specific email domains or individual users.
  • Enabling programmatic access for native apps or APIs using secure service tokens.
  • Hardening production environments where Openclaw Skills are exposed to the public web.

How Cloudflare Access VPS Works

  1. A user or application attempts to access the agent via its public URL.
  2. Cloudflare Edge intercepts the request and performs an Access policy check.
  3. If the user is unauthenticated, Cloudflare displays a login screen based on your configured Identity Provider.
  4. Upon successful authentication, the request is forwarded through a secure Cloudflare Tunnel to the VPS localhost.
  5. The request hits the OpenClaw agent, which then applies its internal security layers like gateway tokens and device pairing.

Cloudflare Access VPS Setup

Prerequisites

Ensure you have a Cloudflare Tunnel active and your domain managed by Cloudflare DNS.

Implementation Steps

  1. Enable Zero Trust: Navigate to the Cloudflare Dashboard, select Zero Trust, and set up your team domain.
  2. Configure Identity: Go to Settings > Authentication and add a provider like Email OTP or GitHub.
  3. Create Application: Under Access > Applications, add a 'Self-hosted' application and input your agent's subdomain.
  4. Define Policy: Create an 'Allow' rule for your specific email address or domain.
  5. Verify: Test the connection in an incognito window to ensure the identity gate is active for your Openclaw Skills.

Cloudflare Access VPS Data Schema & Taxonomy

Element Description
Application Name The identifier for your agent in the Cloudflare Access dashboard.
Session Duration How long an authentication session remains valid (e.g., 24 hours).
Access Policies The logical rules (Allow/Block) governing who can reach the agent.
Service Tokens Credentials used for non-browser/API access, consisting of a Client ID and Secret.
Identity Providers The external services used for SSO (Google, GitHub, OIDC, etc.).

Cloudflare Access VPS Advanced Features

  • Service Token Support: Use static HTTP headers to allow programmatic or native app access without interactive login.
  • Multi-Agent Isolation: Define unique subdomains and different access policies for each agent in your fleet.
  • Defense-in-Depth: Layer Cloudflare Access with OpenClaw internal gateway tokens for a triple-layered security model.
  • MFA Enforcement: Force the use of hardware keys or TOTP on top of standard SSO providers for high-security Openclaw Skills deployments.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*