OpenClaw EnterpriseDOCSGitHub

Set up the OCC CLI

Use occ to manage OpenClaw Control Plane (OCC) resources from a terminal. You need your Installation's OCC endpoint and a protected service-key response file. For all commands and flags, see the CLI command reference. To deploy through the browser, see Create and deploy Agents in the console.

Connect to your Installation

For a published OCE version, download the binary matching your machine from the GitHub Releases page. The assets are named occ-v<version>-<os>-<arch> for macOS (darwin) and Linux, on amd64 or arm64. Download SHA256SUMS from the same release and compare the selected binary's SHA-256 before making it executable. For example, with the GitHub CLI:

bash
export OCE_VERSION='v<release-version>'export OCC_ASSET="occ-${OCE_VERSION}-darwin-arm64" # Choose your OS and CPU.gh release download "$OCE_VERSION" \  --repo openclaw/openclaw-enterprise \  --pattern "$OCC_ASSET" --pattern SHA256SUMSexpected="$(awk -v name="$OCC_ASSET" '$2 == name { print $1 }' SHA256SUMS)"actual="$(shasum -a 256 "$OCC_ASSET" | awk '{ print $1 }')"if [ -n "$expected" ] && [ "$actual" = "$expected" ]; then  mkdir -p "$HOME/.local/bin"  install -m 755 "$OCC_ASSET" "$HOME/.local/bin/occ"  "$HOME/.local/bin/occ" --versionelse  printf 'OCC CLI checksum verification failed; binary not installed.\n' >&2fi

Ensure $HOME/.local/bin is on PATH. On Linux, use sha256sum "$OCC_ASSET" in place of shasum -a 256 if shasum is not installed. The printed CLI version should match the selected release.

To build from a trusted source checkout instead, run this from its root to install occ on your Go binary path:

bash
go install ./cmd/occ

Ensure that directory is on PATH. To use the binary inside the checkout instead, run pnpm cli:build and substitute ./bin/occ for occ below. occ dev up and occ dev down still require a source checkout even when the binary came from a GitHub Release.

Set the endpoint and the service-key file supplied by your administrator or created during bootstrap:

bash
export OCC_URL='https://occ.example.com'export OCC_SERVICE_KEY_FILE='/private/path/occ-service-key.json'occ installation getocc namespace list

Replace both example values with your own. These commands require an Installation-scoped key; reading the Installation also requires Installation read. If your key is Namespace-scoped, use occ namespace get '<namespace-id>' with the ID supplied by your administrator instead.

installation get prints the Installation ID and name. namespace list prints the authorized Namespaces and their STATUS; a Namespace must be ready to deploy an Agent. Add --output json or --output yaml to print the resource or list without the HTTP response envelope. Set a Namespace once for subsequent commands:

bash
export OCC_NAMESPACE='<namespace-id>'

Choose your next task

Task Guide
Create and deploy an Agent Production Agent deployment, including Configuration, model credentials, and verification
Update a Configuration and deploy again Agent revisions; its CLI examples also require jq
Stop or delete an Agent Agent lifecycle and deletion and cleanup
Create or replace integration Secrets Namespace Secrets and Configuration bindings
Use a Credential Gateway Credential sources, including the current OpenShell limits
Grant access to a Namespace resource Namespace IAM
Inspect or upgrade the running fleet Production image upgrades and the CLI reference
Run a local development installation Local Setup

Connection and credential boundaries

The key file is the full JSON response from bootstrap or key issuance, not a file containing only the raw key. Keep it owner-readable; never put the key in command arguments, logs, or source control. For HTTPS signed by a private certificate authority, set OCC_CA_BUNDLE to its PEM bundle. See global options for timeout, origin, and TLS behavior.

Troubleshoot

Search documentation