Database entities cheat sheet
Look up the SQL table and column names stored by OpenClaw Control Plane (OCC).
The tables below are in the occ PostgreSQL schema; use occ."user" when
querying the user table.
The database schema defines
columns and constraints. The
repository-credentials migration
adds the repository binding and session-attempt storage below. The
Drizzle migration-history table,
drizzle.__drizzle_migrations, is excluded. See migration history
for supported database states and platform repositories
for how OCC reads and writes its data.
Platform resources
installation
Stores the single OCC Installation record.
idnamecreated_at
namespaces
Tracks platform Namespaces, their lifecycle status, and any existing Kubernetes namespace they use.
idnameexisting_namespacestatuscreated_atdeleted_at
agents
Stores Agent drafts, their desired runtime state, and the active revision reference.
idnamespace_idnameconfiguration_idbackend_idexecution_modepluginsplugin_approversrepository_bindingsrepository_access(default and explicit per-repository overrides)service_principal_idharness_authharness_auth_secret_idharness_auth_service_account_idharness_auth_credential_source_idactive_revision_iddesired_runtime_statestatuscreated_at
agent_revisions
Stores numbered, immutable snapshots of Agent settings accepted for deployment.
idnamespace_idagent_idrevision_numberbackend_idadmitted_specadmitted_at
workspace_setups
Holds private initial workspace input for one exact Namespace and Agent. Activation
completion clears files; setup identity and completion metadata remain until
Agent deletion. See the workspace setup flow.
idnamespace_idagent_iddefaults_idfilescompleted
configurations
Stores each Agent Configuration’s current generation and Secret bindings; the Driver stores values.
idnamespace_idkindgenerationsecret_bindingscreated_at
presets
Stores reusable Agent launch templates and variable definitions within one Namespace.
idnamespace_idnametemplatecreated_at
secrets
Stores Secret metadata and backend references; Secret values are kept by the selected Driver.
idnamespace_idnamedriver_idbackend_namespace_namebackend_namebackend_keybackend_uidcreated_at
credential_sources
Stores credential sources registered with the selected Credential Gateway; the gateway holds the values.
idnamespace_idnametypeconfigdriver_idstatecreated_at
credential_source_secrets
Links each credential source secret field to the Namespace Secret that supplied it.
namespace_idcredential_source_idfieldsecret_id
service_accounts
Stores Namespace service accounts and any credential Secret references.
idnamespace_idnamecredential
service_account_driver_bindings
Links managed accounts to a Backend, Driver, upstream account, workspace, and any issued credential.
service_account_idnamespace_idbackend_iddriver_idexternal_account_idexternal_credential_idworkspace_id
repository_session_attempts
Retains repository-session identity and cleanup context after AgentRevision deletion.
namespace_idagent_idrevision_idlive_revision_idcleanup_contextrepository_refadmission_idduration_secondsdeadline_wall_msbroker_protocolphasesession_idcreated_atupdated_at
repository_broker_receipts
Retains nonsecret admission fences and broker-confirmed terminal evidence for an exact attempt.
admission_idstategenerationsession_iddeadline_wall_msrevokedexpired
Identity and access
iam_identities
Stores human Principals and service identities, including those owned by an Agent.
idnamespace_idagent_idkindissuersubject
iam_groups
Defines native IAM groups at Installation or Namespace scope.
idnamespace_idname
iam_group_memberships
Links human Principals to their native IAM groups.
namespace_idgroup_idprincipal_id
iam_roles
Defines native IAM roles as sets of actions and resource kinds.
idnamespace_idnamepermissions
iam_access_bindings
Grants a native IAM role to an identity or group, optionally for a specific resource.
idnamespace_ididentity_subject_idgroup_subject_idrole_idresource_kindresource_id
iam_restrictions
Defines native IAM rules that deny actions on a resource kind or specific resource, overriding grants.
idnamespace_idactionresource_kindresource_ideffect
Audit and controller
audit_events
Keeps an append-only record of bootstrap, changes to resources, and authorization denials.
idoccurred_atkindactor_idactionnamespace_idresource_kindresource_idoutcomedetails
controller_work
Queues and tracks controller work for Namespace and Agent lifecycle changes and revision deployments.
idempotency_keynamespace_idagent_idrevision_idactor_idnamespace_targetagent_targetstateavailable_atattempt_countclaim_tokenlease_expires_atcompleted_atreason_coderesult_datacreated_atupdated_at
Browser authentication and service API keys
user
Stores the profiles of people provisioned to sign in.
idnameemailemail_verifiedimagecreated_atupdated_at
session
Stores expiring browser sessions for signed-in users.
idexpires_attokencreated_atupdated_atip_addressuser_agentuser_id
account
Links a user to their sign-in method. Password methods store a password hash; identity-only external methods reject password and provider-token storage. See GitHub sign-in.
idaccount_idprovider_iduser_idaccess_tokenrefresh_tokenid_tokenaccess_token_expires_atrefresh_token_expires_atscopepasswordauthentication_versionidentity_onlycreated_atupdated_at
human_authentication_accounts
Binds each enrolled human user to its existing Installation Principal and current account version. Disabled accounts cannot issue or use profile-bound sessions.
user_idinstallation_idprincipal_idversiondisabledchanged_at
human_authentication_sessions
Binds an ordinary browser session to its admitted account and method versions.
session_iduser_idmethod_idversionmethod_version
human_authentication_recovery
Retains the fixed existing password recovery administrator for an Installation.
installation_iduser_idprincipal_idmethod_id
human_authentication_attempts
Stores one-use external-login attempts with browser binding and a maximum five-minute lifetime. Stores the PKCE verifier, but no authorization code or provider token. Consumed attempts are deleted before exchange.
state_hashbrowser_hashinstallation_idprovider_idcallback_urlcode_verifiercreated_atexpires_at
verification
Stores expiring verification records managed by Better Auth.
ididentifiervalueexpires_atcreated_atupdated_at
apikey
Stores hashed service API keys and their settings for IAM service identities.
idconfig_idnamestartreference_idprefixkeyrefill_intervalrefill_amountlast_refill_atenabledrate_limit_enabledrate_limit_time_windowrate_limit_maxrequest_countremaininglast_requestexpires_atcreated_atupdated_atpermissionsmetadata
