OpenClaw EnterpriseDOCSGitHub

ChannelDriver contract

Overview

ChannelDriver validates configured credentials and looks up provider identities for an authorized Namespace edit. OpenClaw Control Plane (OCC) owns caller authorization, Secret access, and the saved Agent or Configuration. The Driver owns the provider request and returns bounded display candidates with stable provider IDs. It does not send messages or grant channel access. The current controller selects the bundled Slack implementation for directory lookup; see Driver selection.

Interface

The shared interface requires a Driver identity and lookupDirectory({ token, kind, query?, cursor?, ids? }). kind selects users or channels. ids resolves saved IDs directly and cannot be combined with a search query or cursor. The method returns workspace identity, candidates, an optional next cursor, and complete. A returned name is a display hint; callers save IDs. A missing selected Driver makes lookup unavailable.

The optional validateCredentials(values, withSecret) method checks configured channel credentials before API provisioning or deployment. withSecret(binding, path, validate) authorizes the exact same-Namespace Secret and supplies its value only inside the SecretDriver callback. Provider calls run before the write transaction. Validation does not pin Secret versions or revalidate queued work.

IAM

OCC admits the caller, checks Agent creation or the exact Agent or Configuration edit, and requires operate on the caller-specified same-Namespace Secret. The Console supplies its selected bot Secret. OCC reads the value through the SecretDriver, then rechecks authority and Secret identity before giving that value to the ChannelDriver in-process. The Driver authenticates to its provider with the token. No Secret value appears in an HTTP response, audit event, or Console script. Provider access does not grant OCC permissions.

Lifecycle

The controller selects one ChannelDriver at startup. Lookups are read-only and make no platform state change. They use the current selected Secret and can be retried after a transient provider failure. Saving a selected ID remains the Agent or Configuration update's responsibility. A later Secret replacement may change the provider workspace. The interface has no cleanup hook.

Limits

Validation does not establish runtime connectivity. Provider pagination can leave a search incomplete; callers must use nextCursor before concluding a name is missing or unique. Exact-ID lookup can leave inaccessible IDs without a label. complete describes provider pagination, not the credential's visibility into every workspace resource.

Troubleshooting

If lookup is denied, check the exact edit permission and Secret operate grant. If the provider rejects the call, check the selected token and its directory scopes. If results are incomplete, load the next page or enter a known exact ID. A successful lookup does not prove the bot can post to a channel.

Implementations

Search documentation