OmniPermission is a security-first plugin that places a "Human-in-the-Loop" gatekeeper between the AI and high-risk actions. It pauses sensitive plugin actions (like Slack, Telegram, or GitHub) and sends a Push Notification to your mobile device via OmniPersona for approval.
Run the following commands to download and activate the plugin within your OpenClaw environment:
# Install the plugin
openclaw plugins install omnipermission
# Enable the plugin
openclaw plugins enable omnipermission
# Authorize the plugin to use lifecycle hooks (Necessary)
openclaw config set plugins.allow "[\"omnipermission\"]"Crucial: For the hooks and security authorization to take effect, you must restart the OpenClaw gateway:
openclaw gateway restartThe plugin connects to your mobile app using a secret key.
- Download the app:
- Copy your Key: Find your unique secret key on the Home Page of the OmniPersona mobile app.
- Link it: Run the following command and paste your key when prompted:
openclaw omnipermission set-keyBy default, all tools work without permission. You choose exactly what to control.
Specify which skills/plugins you want to gatekeep. If a skill is on this list, the agent cannot use it without your mobile consent.
openclaw omnipermission blacklist-toolsExample input: slack, telegram, github, message
Check your saved key, your active blacklist, and the current backend environment.
openclaw omnipermission statusWipe the blacklist completely to allow all plugins to run freely.
openclaw omnipermission clear-blacklistIf you are a developer testing new features or using a staging environment, you can toggle the backend target. This setting is stored in the plugin's local state.
Point the plugin to the development backend (backend.dev.ecrop.de):
openclaw omnipermission enable-dev-modeSwitch back to the production backend:
openclaw omnipermission disable-dev-mode- Interception: The plugin monitors the
before_tool_callhook for any skill in your blacklist. - Mobile Alert: The agent's Intent and Parameters are sent to your phone.
- Approval: The agent remains paused until you tap Approve in the OmniPersona app.
OmniPermission does not support every tool, but provides the scaffolding required for adding new tools. In case you want to intercept a specific operation, follow our How to Extend guide.
Additionally, you can find the list of supported tools here.