OpenClaw on GX10: a Personal AI Agent on Your Own Machine
An agent is not a chat that only answers: it has tools. It runs commands, reads files and opens websites. OpenClaw is an open personal agent with one persistent process (the Gateway) that connects a model, chat channels and tools. Here we install it on a server of the NVIDIA GB10 class, reach its dashboard through an SSH tunnel and give it a first task under our approval.
01What you will learn
- What an agent with tools is and how it differs from an ordinary chat.
- What OpenClaw is made of: the Gateway, a model, channels, tools, skills and plugins.
- How to install it and run the Gateway as a service on a GB10-class server.
- How to reach the dashboard from your own computer without opening the machine to the network.
- How to give it a first task and keep it under control with approvals, an audit and a sandbox.
02Before you start
- A machine of the NVIDIA GB10 class (for example ASUS Ascent GX10 or DGX Spark) with DGX OS and terminal access, directly or over SSH. How the machine is prepared is in the n8n on GX10 lesson.
- Node.js 24.16+ or 26.1+ (the documentation recommends 26). Check with
node --version. If it is missing, see the Node.js page in the OpenClaw documentation. - Access to a model: a cloud provider key 🌐 global or a local model through Ollama 🔒 local. The second keeps conversations on the machine but requires choosing a model and enough memory — see Performance and resources of local models.
- One rule up front: an agent with tools has real consequences. Start only with things that cannot do harm — reading, not deleting.
03Steps
-
What OpenClaw is (and is not)
OpenClaw is a personal AI agent. One process — the Gateway — holds the sessions, connects the model to chat channels (Discord, Telegram and others) and gives it tools. The dashboard (Control UI) is a web page of the same process. Do not confuse it with Open WebUI: that is only a chat page for models, without tools. A detailed "which is which" table is in the series cheat sheet.
Part What it is for Gateway The persistent process: sessions, channels, tools, dashboard. Default port 18789 Model A cloud provider or a local one (Ollama). It decides what to do Tools Typed actions the agent can call: running commands ( exec), a browser, web search, messagesSkills SKILL.mdfiles with instructions on how to do a particular jobPlugins Add tools, providers, channels and hooks How one turn works (per the documentation): a message arrives → context and skills are assembled → the model answers or asks for a tool → the tool runs → the result goes back to the model → a final reply comes out. Turns in one session run one at a time so that tools do not collide.
-
Check the machine
bash · on the machineuname -m node --version df -h ~You expect
aarch64and a matching Node.js version (24.16+ or 26.1+). If Node is older, install it by the OpenClaw documentation before you continue. -
Install OpenClaw
The official script is for macOS and Linux. A script piped straight into
bashis convenient but you trust it blindly — so download it, read it, and only then run it.bash · on the machinecurl -fsSL https://openclaw.ai/install.sh -o openclaw-install.sh less openclaw-install.sh # read what it does bash openclaw-install.shThe script starts the first-run wizard by itself. Choose Quick start: if it finds a key or a login for Claude Code or Codex CLI, it uses it and checks with a real request; otherwise it sends you to manual provider setup. Custom setup shows all the steps. A way without installing:
npx openclaw@latest. You can return to the settings later withopenclaw configure.After Quick start the Gateway runs in the foreground of this terminal. Stop it with Ctrl+C and run it as a service:
bashopenclaw gateway install openclaw gateway status openclaw statusOn Linux the service is a systemd user unit. You expect the Gateway on port 18789. ⚠️ Whether it starts by itself after a reboot without you logging in — we have not checked.
-
Open the dashboard from your own computer
By default the Gateway listens only on the machine itself (
loopback). That is right: do not open it to the network. From your computer you reach it through an SSH tunnel — a protected corridor that opens no port anywhere.bash · on your computerssh -L 18789:localhost:18789 <user>@<server-address>Leave the connection open and open
http://localhost:18789in your browser. If you work directly on the machine, runopenclaw dashboard. If the dashboard says the origin is not allowed, see the cheat sheet (keysgateway.publicOriginandgateway.controlUi.allowedOrigins); do not switch on the "dangerous" modes.✅Beyond loopback — only with authenticationIf you ever changegateway.bindto anything other thanloopback, the documentation requires authentication. Treat the dashboard and its addresses as a secret: whoever has them talks to the agent. -
Choose a model
An agent is only as good as the model behind it. Two paths:
- A cloud provider 🌐 global — the easiest; every request and every tool result goes to the provider.
- A local model through Ollama 🔒 local — the data stays on the machine. On GB10 the memory is unified for the processor and the GPU (128 GB), so the model, the system and the containers share it. The Ollama address looks like
http://<address>:<port>without/v1, otherwise tools break — details and sample settings are in the cheat sheet, and how to choose a model is in the performance lesson.
We do not repeat the setup here, so that there is one place for it. ⚠️ We have not measured the speed of a local model on your machine.
-
A first task — read-only
In the dashboard write something harmless and useful: "Look through the file list in the test folder and tell me which are the largest. Do not change or delete anything." Watch which tools the agent asks for and what each returns. That is how you learn how the model "thinks" before you give it anything important.
In the chat, commands such as
/status(session state),/new(archives the session and starts a new one) and/reset(resets it in place) work.✅A human approves every action with a real effectDeleting, sending a message, paying, publishing, changing settings — only after your “yes”. Start with a folder that holds nothing valuable and with read-only rights. -
Security — three moves
bashopenclaw security audit openclaw doctor openclaw logs --follow- Audit:
openclaw security auditafter every larger change; review the result. In detail: OpenClaw security. - Who can write: allow only known people (for Discord — pairing or an allow list).
- Sandbox: according to the documentation tool execution is not sandboxed by default. You switch it on with
agents.defaults.sandbox; the Gateway stays on the machine and only the tools move. The documentation itself says this is not a perfect boundary, but it limits file and process access when the model makes a mistake.
How to make the sandbox tighter — with a separate environment, network policy and keys kept outside it — is the topic of the next lesson: NemoClaw.
- Audit:
04Check
uname -mprintsaarch64andnode --versionprints 24.16+ or 26.1+.openclaw gateway statusshows a running Gateway on port 18789.- The dashboard opens through the tunnel (or with
openclaw dashboardon the machine itself) and the agent replies. - The Gateway is not reachable from the network —
loopbackonly. - The first task was done by reading only; you know which tools the agent used.
openclaw security auditwas run and reviewed.
Test
1. Which process in OpenClaw connects the model to the chat channels and the tools?
2. Which address does the Gateway listen on by default?
3. How do you reach the dashboard of a remote machine without opening the network?
4. What is the default state of the sandbox for tools in OpenClaw?
05What's next
06Sources
- OpenClaw: getting started 🌐 global — Node.js 24.16+/26.1+, install script,
openclaw gateway install, port 18789. - OpenClaw: the agent loop — how one turn is processed.
- OpenClaw: tools, skills and plugins — the difference between the three.
- OpenClaw: sandboxing · Gateway security — off by default; not a perfect boundary.
- openclaw on npm — current release 2026.9.8 as of 03.10.2026.
- ASUS Ascent GX10: tech specs · NVIDIA DGX Spark: hardware — 128 GB unified memory.