Set up the OCC CLI
Use occ to manage OpenClaw Control Plane (OCC) resources from a terminal. You
need your Installation's OCC endpoint and a protected service-key response file.
For all commands and flags, see the CLI command reference.
To deploy through the browser, see Create and deploy Agents in the console.
Connect to your Installation
For a published OCE version, download the binary matching your machine from
the GitHub Releases page.
The assets are named occ-v<version>-<os>-<arch> for macOS (darwin) and Linux,
on amd64 or arm64. Download SHA256SUMS from the same release and compare
the selected binary's SHA-256 before making it executable. For example, with
the GitHub CLI:
export OCE_VERSION='v<release-version>'export OCC_ASSET="occ-${OCE_VERSION}-darwin-arm64" # Choose your OS and CPU.gh release download "$OCE_VERSION" \ --repo openclaw/openclaw-enterprise \ --pattern "$OCC_ASSET" --pattern SHA256SUMSexpected="$(awk -v name="$OCC_ASSET" '$2 == name { print $1 }' SHA256SUMS)"actual="$(shasum -a 256 "$OCC_ASSET" | awk '{ print $1 }')"if [ -n "$expected" ] && [ "$actual" = "$expected" ]; then mkdir -p "$HOME/.local/bin" install -m 755 "$OCC_ASSET" "$HOME/.local/bin/occ" "$HOME/.local/bin/occ" --versionelse printf 'OCC CLI checksum verification failed; binary not installed.\n' >&2fiEnsure $HOME/.local/bin is on PATH. On Linux, use
sha256sum "$OCC_ASSET" in place of shasum -a 256 if shasum is not
installed. The printed CLI version should match the selected release.
To build from a trusted source checkout instead, run this from its root to
install occ on your Go binary path:
go install ./cmd/occEnsure that directory is on PATH. To use the binary inside the checkout
instead, run pnpm cli:build and substitute ./bin/occ for occ below.
occ dev up and occ dev down still require a source checkout even when the
binary came from a GitHub Release.
Set the endpoint and the service-key file supplied by your administrator or created during bootstrap:
export OCC_URL='https://occ.example.com'export OCC_SERVICE_KEY_FILE='/private/path/occ-service-key.json'occ installation getocc namespace listReplace both example values with your own. These commands require an
Installation-scoped key; reading the Installation also requires Installation
read. If your key is Namespace-scoped, use
occ namespace get '<namespace-id>' with the ID supplied by your administrator
instead.
installation get prints the Installation ID and name. namespace list prints
the authorized Namespaces and their STATUS; a Namespace must be ready to
deploy an Agent. Add --output json or --output yaml to print the resource or
list without the HTTP response envelope. Set a Namespace once for subsequent
commands:
export OCC_NAMESPACE='<namespace-id>'Choose your next task
| Task | Guide |
|---|---|
| Create and deploy an Agent | Production Agent deployment, including Configuration, model credentials, and verification |
| Update a Configuration and deploy again | Agent revisions; its CLI examples also require jq |
| Stop or delete an Agent | Agent lifecycle and deletion and cleanup |
| Create or replace integration Secrets | Namespace Secrets and Configuration bindings |
| Use a Credential Gateway | Credential sources, including the current OpenShell limits |
| Grant access to a Namespace resource | Namespace IAM |
| Inspect or upgrade the running fleet | Production image upgrades and the CLI reference |
| Run a local development installation | Local Setup |
Connection and credential boundaries
The key file is the full JSON response from bootstrap or key issuance, not a
file containing only the raw key. Keep it owner-readable; never put the key in
command arguments, logs, or source control. For HTTPS signed by a private
certificate authority, set OCC_CA_BUNDLE to its PEM bundle. See
global options for timeout, origin, and
TLS behavior.
Troubleshoot
invalid service-key file: Check that the JSON contains a nonemptydata.keywith no line break.- HTTP
401: OCC rejected the credential; retrieve or issue the intended key. - HTTP
403: Ask your administrator to check the service principal's permission for the exact operation and Namespace. - Certificate error: Set
OCC_CA_BUNDLEto the correct PEM bundle. The CLI has no insecure TLS mode.
