Secret Manager for Openclaw

A secure utility for managing API keys via the system keyring and injecting them into OpenClaw configurations.

jswortz
v1.0.0
Feb 8, 2026
0
2.3k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install secret-manager

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install secret-manager using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Secret Manager?

The Secret Manager skill provides a robust bridge between your system's secure credential storage and your AI agent environment. By leveraging GNOME Keyring and libsecret, it ensures that sensitive tokens for LLMs and integrations are never stored in plain text. This tool is a cornerstone for developers building with Openclaw Skills who prioritize security and automation.

This skill automates the lifecycle of secret management, from secure storage via CLI to the automatic restarting of gateway services. It eliminates the friction of manually updating configuration files while significantly hardening the security posture of your local AI development environment.

Secret Manager Use Cases

  • Storing LLM provider keys like OpenAI or Gemini without exposing them in plain text scripts.
  • Automating the injection of Discord bot tokens into OpenClaw environments.
  • Synchronizing local secrets with a Distrobox-based OpenClaw Gateway service.
  • Managing multiple API credentials for third-party services like Giphy or LinkedIn through a single interface.

How Secret Manager Works

  1. The user provides a key-value pair through the secret-manager CLI tool.
  2. The skill stores the data securely using the system's secret-tool or GNOME Keyring.
  3. Credentials are automatically injected into the auth-profiles.json configuration file.
  4. Environment variables are propagated to the systemd user environment for persistence.
  5. The OpenClaw Gateway service within the Distrobox container is restarted to apply the new credentials immediately.

Secret Manager Setup

Ensure you have the required system dependencies installed for these Openclaw Skills to function:

# Debian/Ubuntu
sudo apt install libsecret-tools

# Fedora
sudo dnf install libsecret

# Arch
sudo pacman -S libsecret

Once dependencies are met, you can use the secret-manager command to begin storing keys.

Secret Manager Data Schema & Taxonomy

The skill interacts with specific files and system components to maintain security and functionality:

Component Path / Detail Purpose
Config Directory ~/.openclaw Primary directory for OpenClaw configurations.
Auth Profiles auth-profiles.json Target file for credential injection.
Secrets File ~/.config/openclaw/secrets.env Optional environment file for sourcing variables.
System Keyring libsecret / GNOME Encrypted storage for raw API tokens.

Secret Manager Advanced Features

  • Interactive prompt mode to prevent API keys from appearing in your shell history.
  • Direct CLI support for automation and batch injection of secrets.
  • Automatic Distrobox container detection and integration.
  • Support for a wide range of predefined service keys including Google Places and LinkedIn authentication.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*