6 lessons · 0%Safe Installation and First AgentStart
Course map

Safe Installation and First Agent

0 of 6 complete0 of 6

Course 02 · beginner

Safe Installation and First Agent

Install OpenClaw in a disposable boundary, verify the gateway and provider, then run and remove one approval-gated first agent.

Skip course map

Verifiedon 2026.7.1-2

  • Owner
    academy-editorial
  • Time
    3 hours 30 minutes
  • Freshness SLA
    critical
  • Version scope
    >=2026.7.1-2 <2026.8.0

View this course’s maintenance history

Practical outcome

What this gives you

  1. Choose a platform path and record a reversible installation pre-flight
  2. Verify the CLI, Gateway, provider, and a controlled test task without exposing credentials
  3. Define an approval boundary and remove the first-agent environment safely

Preflight

Before you start

  • Foundations and Architecture

Syllabus

Work through the map

  1. Choose a safe installation path20 min
  2. Install deliberately on macOS, Linux, Windows, WSL, or a VPS20 min
  3. Onboard a provider without leaking its credential20 min
  4. Verify the CLI and Gateway before connecting anything real20 min
  5. Define a first agent that can only propose20 min
  6. Capstone: run, inspect, stop, and remove the first safe agent20 min
  7. Final assessmentAfter coursework
Course details and supporting evidence

What you will build

An intentionally small, local-first agent environment: one trusted operator, one test-only workspace, a provider credential kept out of the workspace, and a task that proposes rather than performs an external action. You will keep a short evidence record and finish by stopping and removing the environment.

Course map

  1. Choose a path and set the stop conditions.
  2. Install without giving the installer more scope than necessary.
  3. Use onboarding to configure a provider without copying a key into notes or source control.
  4. Verify the CLI and Gateway before connecting a real channel.
  5. Define a single-purpose first agent and an explicit approval boundary.
  6. Run, inspect, stop, remove, and document the result.

Before you begin

Use a disposable local account, VM, or VPS test user. Do not point this course at a work mailbox, a production channel, a production repository, or a credential that grants access beyond a throwaway test. If you cannot name the owner, workspace path, approved recipient, and deletion plan, pause before installing.

Safe first-agent boundary

trusted operator -> Gateway + test workspace -> model provider -> proposal for review
                                                          |
                                             approval required before any side effect

Keep the test credential outside the workspace, leave real channels disconnected, and verify that teardown returns the host to its prior state.

Completion evidence

Keep a redacted record containing platform path, installed version, Gateway status result, provider live-check result, one bounded proposal, the approval decision, and teardown result. Do not paste keys, tokens, logs containing secrets, or private endpoints into the record.

Review course maintenance history →