Skip to content

Remote gateway setup

This content now lives in [Remote Access](/gateway/remote#macos-persistent-ssh-tunnel-via-launchagent). Use that page for the current guide; this page stays as a redirect target.

Running RemoteClaw.app with a Remote Gateway

RemoteClaw.app reaches a remote Gateway over an SSH tunnel: an SSH LocalForward maps a local port to the Gateway WebSocket port on the remote host.

flowchart TB
subgraph Client["Client Machine"]
direction TB
A["RemoteClaw.app"]
B["ws://127.0.0.1:18789\n(local port)"]
T["SSH Tunnel"]
A --> B
B --> T
end
subgraph Remote["Remote Machine"]
direction TB
C["Gateway WebSocket"]
D["ws://127.0.0.1:18789"]
C --> D
end
T --> C

Setup

  1. Add an SSH config entry with LocalForward 18789 127.0.0.1:18789 (see Remote Access for the full config block).
  2. Copy your SSH key to the remote host with ssh-copy-id.
  3. Set gateway.remote.token (or gateway.remote.password) via remoteclaw config set gateway.remote.token "<your-token>".
  4. Start the tunnel: ssh -N remote-gateway &.
  5. Quit and reopen RemoteClaw.app.

For a tunnel that survives reboots and reconnects automatically, use the LaunchAgent setup on the Remote Access page instead of a manual ssh -N.

How it works

ComponentWhat it does
LocalForward 18789 127.0.0.1:18789Forwards local port 18789 to remote port 18789
ssh -NSSH without executing remote commands (port forwarding only)
KeepAliveRestarts the tunnel automatically if it crashes (LaunchAgent)
RunAtLoadStarts the tunnel when the LaunchAgent loads (LaunchAgent)

RemoteClaw.app connects to ws://127.0.0.1:18789 on the client. The tunnel forwards that connection to port 18789 on the remote host running the Gateway.