OpenClaw
OpenClaw is a personal AI assistant you can talk to on Telegram or WhatsApp. Saka installs it on your server with secure defaults, then gives you a management page with no terminal needed.
Install
Open your server in the panel, press + Pasang aplikasi (Install app), then choose OpenClaw. The fields you fill in:
| Field | Details |
|---|---|
| AI provider | Anthropic (Claude), OpenAI, Google Gemini, OpenRouter, or an OpenAI-compatible endpoint (for example LiteLLM, vLLM). |
| Endpoint address and model name | Only for OpenAI-compatible endpoints. |
| AI API key | Checked with the provider before installation, then stored only on your server, in a file readable only by root. Token costs are paid directly to your AI provider. |
| Telegram bot token (optional) | From @BotFather, command /newbot. You can leave it empty and add it later. This bot belongs to your assistant, not to Saka. |
Create an API key at aistudio.google.com/apikey and copy it in full (it starts with AIza). The key is checked directly with Google before installation. A Google Workspace subscription or a Gemini subscription (the Gemini app) is not an API key and cannot be used; only an API key from Google AI Studio works.
Server requirements: 2 GB of RAM and 8 GB of free disk. Docker is installed automatically if it is not there yet. Installation takes a few minutes. You can close the dialog; the install keeps running and the result is sent to your Telegram.
The setup Saka installs:
- OpenClaw runs in a Docker container with a pinned, tested version.
- The OpenClaw port (18789) is only open on
127.0.0.1and is not exposed to the internet. - The container has no
NET_RAW/NET_ADMINprivileges and runs withno-new-privileges. - Command approval is on and ClawHub is off (see Default security).
- Web search without an extra key is active right away.
The catalog also includes Hermes Agent from Nous Research, an AI assistant that learns from use and talks to you on Telegram. It is installed from the official nousresearch/hermes-agent:latest image and needs 1 GB of RAM and 4 GB of free disk. Its AI providers are the same as OpenClaw's: Anthropic, OpenAI, Google Gemini, OpenRouter, or an OpenAI-compatible endpoint. Hermes replies directly to the Telegram users whose IDs you enter during installation (ask @userinfobot; separate several with commas). The full management page below is only for OpenClaw.
Chat access & approval
A new person who messages your bot is not served right away. They receive an access code (pairing), and their messages are not processed until you approve them.
- Send any message to your bot on Telegram.
- The request appears on the management page within a few seconds, with the sender's name. Match the code with the one from the bot.
- Press Setujui (Approve) only if you know the sender.
The list "Yang bisa mengobrol dengan asisten ini" (Who can chat with this assistant) shows everyone who has been approved. Access can be revoked at any time. The owner cannot be revoked from the panel, so you never lock yourself out of your own assistant.
AI models
- See the main model and the installed models.
- The list of available models is fetched directly from the AI provider using the key on your server (Anthropic, OpenAI, OpenRouter). The key never leaves the server.
- Add a model, make it the main model, or remove a model.
Channels: Telegram and WhatsApp
Telegram
Enter the bot token during installation, or add it later on the Telegram card. Then use the access approval flow.
- Press Tambah WhatsApp (Add WhatsApp). The first time, Saka downloads the WhatsApp plugin and restarts OpenClaw (±2-3 minutes; the Telegram bot pauses briefly).
- A QR code appears in the panel. Scan it from WhatsApp on your phone, just like WhatsApp Web. The QR code refreshes automatically when it expires.
- New senders get an access code; approve them on the access card.
OpenClaw connects to WhatsApp as a linked device (like WhatsApp Web), which is an unofficial route. Meta may restrict or block the number used. Use a separate number, not your main number, and do not use it for bulk or promotional messages.
WhatsApp can be disconnected from the panel and reconnected at any time by scanning the QR code. Discord and Slack are coming later.
Schedules & reminders
Create scheduled tasks for the assistant: once (a specific date and time), daily, weekdays, or weekly (pick the days), with times in WIB (UTC+7). Write what the assistant should do, then choose where the result is sent on Telegram or WhatsApp. Schedules can be turned on or off, run now, or deleted.
You can also create schedules through chat, for example "remind me to take my medicine every day at 8 pm".
Web search
Web search is active from installation, with no extra key. You can switch the provider in the panel: parallel-free (default) or DuckDuckGo, or turn it off. Switching providers for the first time downloads a plugin and restarts OpenClaw.
Skills, persona, memory
- Skills: see OpenClaw's built-in skills, turn them on or off, and enter the keys some skills need.
- Persona: describe in plain language who the assistant is, how it talks, and what it may or may not do. Applies to new conversations (on Telegram, type
/new). - Periodic check-in (heartbeat): how often the assistant checks in on its own (off, 30 minutes, or 1/2/4/12/24 hours), with optional active hours (for example 08:00 to 21:00) in WIB, WITA, WIT (Indonesian time zones), Singapore time, or UTC.
- Memory: read and edit
USER.md, the long-term memoryMEMORY.md, and daily notes. Deleted items are moved to the.sampah-memorifolder on the server instead of disappearing right away. - Usage: token usage is counted by OpenClaw on your server. For actual costs, check your AI provider's dashboard.
Dashboard through a tunnel
The Buka dasbor (Open dashboard) button opens OpenClaw's built-in dashboard on a dedicated subdomain <id>-<aplikasi>-dashboard.saka.work, without opening a port on your server:
- The agent opens an outbound connection to Saka Panel and links it to the OpenClaw port on
127.0.0.1. The agent will only connect to that app port, not to any arbitrary address. - Sign-in uses a one-time ticket (60 seconds) created by the panel. The dashboard subdomain is separate from app.saka.work, so the dashboard's code cannot touch your panel session.
- The dashboard's browser device is approved automatically for 3 minutes after you press the button, so you do not have to deal with device pairing.
Default security
| Setting | Saka default | What it means |
|---|---|---|
| Ask before running commands | On | Before running a command on the server, the assistant sends ✅/❌ buttons to your Telegram. No answer means denied. |
| Skills from the internet (ClawHub) | Off | The assistant cannot download unreviewed third-party skills. Built-in skills can still be used. |
Both can be changed on the Keamanan (Security) card, but we recommend keeping the defaults.
Security check: a button on the same card runs OpenClaw's own security audit (±1-3 minutes) and shows the findings with their severity and suggested fixes. This check needs swap so the assistant does not stall; if there is none yet, fix it first from the Readiness card.
Backups & updates
- Backups: press Buat cadangan (Create backup). A verified backup is stored on your server (
/var/lib/sakapanel/cadangan/), and the last 5 are kept. - Updates: Saka checks for the latest official release (no pre-releases). During an update: a backup is made first, the new image is downloaded, the old version is stopped and kept, and the new version is started. If the new version is not ready, OpenClaw rolls back automatically to the old version.
- Automatic updates (optional): once a day at around 03:00 WIB (UTC+7). Run by the agent itself, so they keep working even if Saka Panel is disconnected. The result is reported to Telegram.
If the app is removed, its container is stopped and its data is moved to /var/lib/sakapanel/aplikasi/.sampah/ on the server, where it can be restored manually.