OpenClaw Integration
Control Layer for OpenClaw agents — server-managed protection rules, BYOM, blockchain proof.
OpenClaw Integration
Your agent runs 24/7. Do you know what it's doing right now?
agent-shield shows you everything your OpenClaw agent does, blocks dangerous actions before they execute and masks your personal data. Setup takes four steps: install the package, set two environment variables, run the init command, restart your gateway.
How It Works
OpenClaw Agent → Tool Call → agent-shield (MCP) → Palveron Gateway → Policy Check
↓
✅ ALLOW → Execute tool
✏️ MODIFY → Execute with PII masked
🚫 BLOCK → Rejected with reason
⏸️ APPROVAL → Waiting for approvalEvery tool call produces a tamper-evident trace — searchable, filterable, optionally anchored on the Flare blockchain.
Quickstart
1. Install the package
npm install -g @palveron/agent-shield2. Set API key and LLM key
export PALVERON_API_KEY="your-key" # Copied once when the project was created (or rotate it under Settings → API Keys)
export PALVERON_API_URL="https://gateway.palveron.com" # Gateway address (self-hosted: your own gateway URL)
export OPENAI_API_KEY="sk-..." # Your own LLM key (BYOM)Your project API key is shown only once — when the project is created or when you rotate it. It is stored hashed and cannot be displayed again. If you lost it, rotate it under Settings → API Keys to get a fresh key.
3. Activate Shield
palveron shield initThe command validates your API key, registers your agent and activates the protection rules for your project. It reports how many rules are now active; the same list is visible in your dashboard under Policies.
4. Restart Gateway
openclaw gateway restartDone. Your protection rules are active. Open the dashboard tomorrow morning.
BYOM: Bring Your Own Model
You already have an LLM API key. Our 2-pass system (regex + AI) uses your key for the AI analysis. Our LLM cost per user: effectively zero.
| Tier | LLM Key | What happens |
|---|---|---|
| Community | Your own | Full 2-pass engine (regex + AI via your key) |
| Pro | Your own | + Neural Custom Policies |
| Business | Your own | + Team features |
| Enterprise | Your own OR Managed | Managed LLM as a premium option |
Protection Rules (Activated at Setup)
The rule set lives on the Palveron server and is maintained there: no YAML, no config files on your machine. palveron shield init activates the baseline rules for your project and plan and reports the activated count. You can see, adjust and extend every active rule in the dashboard under Policies; palveron shield status lists them from the terminal.
The baseline covers secret exfiltration, dangerous shell commands, destructive actions, package installs and personal data in output. Because the rules live on the server, they can be corrected and extended without a new client release.
MCP Configuration
palveron shield init prints the MCP server entry for your openclaw.json. If you'd like to adjust the configuration manually:
{
"mcpServers": {
"agent-shield": {
"command": "npx",
"args": ["-y", "-p", "@palveron/agent-shield", "palveron", "shield", "mcp"],
"env": {
"PALVERON_API_URL": "https://gateway.palveron.com",
"PALVERON_API_KEY": "your-key"
}
}
}
}MCP Tool
| Tool | Description |
|---|---|
governance_check | Check a tool call against governance policies before it executes. Returns ALLOW, BLOCK, MODIFY or APPROVAL. |
The agent calls governance_check automatically before executing HIGH-RISK actions (shell, file deletes, package installs, sending messages).
CLI Commands
The package installs a single binary, palveron. Shield commands live under the shield subcommand:
palveron shield init # Set up shield + register agent
palveron shield status # 24h statistics + active rules
palveron shield test # Run test governance checks
palveron shield mcp # Start the governance MCP server (stdio)
palveron help # Show helpEnvironment Variables
| Variable | Description |
|---|---|
PALVERON_API_KEY | Your project API key (required) |
PALVERON_API_URL | Gateway URL (required): https://gateway.palveron.com for the hosted gateway |
OPENAI_API_KEY | Your LLM key for BYOM 2-pass analysis |
AGENT_SHIELD_API_KEY | Alternative name for the API key |
AGENT_SHIELD_API_URL | Alternative name for the API URL |
Risk Classification
Every tool call is checked and traced: there is no skip tier. The classification decides what happens if the gateway is unreachable:
| Risk | Example Tools | On gateway outage |
|---|---|---|
| HIGH | exec, shell, delete_file, write_file, git_push, install_package, navigate | Fail-closed: the action is blocked |
| MEDIUM | read_file, list_directory, git_status, memory_write, and any unknown tool | Fail-open: the action proceeds |
Blockchain Proof
Set up a Flare wallet in the dashboard for cryptographic on-chain proof of governance decisions:
| Tier | Wallet Mode | Gas Fees |
|---|---|---|
| Community | Own wallet (CUSTOMER_OWNED) | You pay (minimal per-transaction cost) |
| Pro/Business | Managed OR own | We pay (Managed) |
| Enterprise | Managed OR own | Included |
Without a wallet: every record carries a checksum that makes a later change detectable. Anchoring makes that evidence presentable to third parties; without it, it stays local.
Viewing Traces
Every governance check produces a trace in the dashboard:
- Filter by
framework: openclawfor all OpenClaw checks - Filter by tool name (e.g.
toolName: exec) - Timeline view: every tool call, every minute, searchable
- Inspect PII findings, policy matches and blockchain status
- Export as CSV or include in EU AI Act Evidence Packages
On-Premise
{
"mcpServers": {
"agent-shield": {
"command": "npx",
"args": ["-y", "-p", "@palveron/agent-shield", "palveron", "shield", "mcp"],
"env": {
"PALVERON_API_URL": "https://gateway.internal.yourcompany.com:8080",
"PALVERON_API_KEY": "your-key"
}
}
}
}Troubleshooting
Every check is blocked, but only when the agent runs inside OpenClaw
If governance_check always blocks with reason gateway_tls_untrusted (or an
older agent-shield shows the opaque gateway_unavailable_failclosed) only when
run inside OpenClaw, while a direct run works, an antivirus or firewall is
performing HTTPS inspection. It re-signs traffic with its own root CA, which
the OS trusts but Node does not (UNABLE_TO_VERIFY_LEAF_SIGNATURE).
Fix (Node ≥ 22): start the MCP server so Node trusts the OS certificate store
— use command: node with --use-system-ca as the first argument, pointing at
the installed package's binary (find its directory with npm root -g):
{
"mcpServers": {
"agent-shield": {
"command": "node",
"args": ["--use-system-ca", "/path/to/node_modules/@palveron/agent-shield/bin/palveron.mjs", "shield", "mcp"]
}
}
}Node < 22: set NODE_EXTRA_CA_CERTS to the inspecting CA file instead.
Never set
NODE_TLS_REJECT_UNAUTHORIZED=0— that disables certificate verification entirely.--use-system-cakeeps verification on and simply trusts the legitimate OS-store CA.
For email sending, the same AV interception affects SMTP — but with port-specific behavior and an in-code trust option. See OpenClaw Mailer (SMTP-specific TLS, port 587 + MAILER_CA_CERT).
Hermes
Hermes (the open-source agent by Nous Research) is a second target environment. Its documentation describes two connection points that match the paths on this page: configurable model endpoints, which is where a governance gateway address can be entered, and MCP servers with tool filtering, which is where a governance_check server can be registered. We have not yet verified this setup against the Palveron gateway; a tested guide will follow that verification.
Next Steps
- Create your own policies for your team's workflow
- Set up approval workflows for high-risk operations
- Configure blockchain attestation for regulated environments
- Compliance Hub for EU AI Act, DORA and other frameworks
Microsoft Agent Governance Toolkit
Bridge between Palveron and Microsoft AGT — central policies, sub-millisecond local enforcement, unified audit trails.
OpenClaw Mailer
Governed email sending for OpenClaw agents — fail-closed recipient allowlist, one TLS trust model with agent-shield, port 587 + MAILER_CA_CERT behind AV interception.