OpenClaw EnterpriseDOCSGitHub

Database entities cheat sheet

Look up the SQL table and column names stored by OpenClaw Control Plane (OCC). The tables below are in the occ PostgreSQL schema; use occ."user" when querying the user table.

The database schema defines columns and constraints. The repository-credentials migration adds the repository binding and session-attempt storage below. The Drizzle migration-history table, drizzle.__drizzle_migrations, is excluded. See migration history for supported database states and platform repositories for how OCC reads and writes its data.

Platform resources

installation

Stores the single OCC Installation record.

namespaces

Tracks platform Namespaces, their lifecycle status, and any existing Kubernetes namespace they use.

agents

Stores Agent drafts, their desired runtime state, and the active revision reference.

agent_revisions

Stores numbered, immutable snapshots of Agent settings accepted for deployment.

workspace_setups

Holds private initial workspace input for one exact Namespace and Agent. Activation completion clears files; setup identity and completion metadata remain until Agent deletion. See the workspace setup flow.

configurations

Stores each Agent Configuration’s current generation and Secret bindings; the Driver stores values.

presets

Stores reusable Agent launch templates and variable definitions within one Namespace.

secrets

Stores Secret metadata and backend references; Secret values are kept by the selected Driver.

credential_sources

Stores credential sources registered with the selected Credential Gateway; the gateway holds the values.

credential_source_secrets

Links each credential source secret field to the Namespace Secret that supplied it.

service_accounts

Stores Namespace service accounts and any credential Secret references.

service_account_driver_bindings

Links managed accounts to a Backend, Driver, upstream account, workspace, and any issued credential.

repository_session_attempts

Retains repository-session identity and cleanup context after AgentRevision deletion.

repository_broker_receipts

Retains nonsecret admission fences and broker-confirmed terminal evidence for an exact attempt.

Identity and access

iam_identities

Stores human Principals and service identities, including those owned by an Agent.

iam_groups

Defines native IAM groups at Installation or Namespace scope.

iam_group_memberships

Links human Principals to their native IAM groups.

iam_roles

Defines native IAM roles as sets of actions and resource kinds.

iam_access_bindings

Grants a native IAM role to an identity or group, optionally for a specific resource.

iam_restrictions

Defines native IAM rules that deny actions on a resource kind or specific resource, overriding grants.

Audit and controller

audit_events

Keeps an append-only record of bootstrap, changes to resources, and authorization denials.

controller_work

Queues and tracks controller work for Namespace and Agent lifecycle changes and revision deployments.

Browser authentication and service API keys

user

Stores the profiles of people provisioned to sign in.

session

Stores expiring browser sessions for signed-in users.

account

Links a user to their sign-in method. Password methods store a password hash; identity-only external methods reject password and provider-token storage. See GitHub sign-in.

human_authentication_accounts

Binds each enrolled human user to its existing Installation Principal and current account version. Disabled accounts cannot issue or use profile-bound sessions.

human_authentication_sessions

Binds an ordinary browser session to its admitted account and method versions.

human_authentication_recovery

Retains the fixed existing password recovery administrator for an Installation.

human_authentication_attempts

Stores one-use external-login attempts with browser binding and a maximum five-minute lifetime. Stores the PKCE verifier, but no authorization code or provider token. Consumed attempts are deleted before exchange.

verification

Stores expiring verification records managed by Better Auth.

apikey

Stores hashed service API keys and their settings for IAM service identities.

Search documentation