惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
Recent Announcements
Recent Announcements
Last Week in AI
Last Week in AI
博客园 - Franky
Microsoft Security Blog
Microsoft Security Blog
Hugging Face - Blog
Hugging Face - Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Vercel News
Vercel News
MyScale Blog
MyScale Blog
大猫的无限游戏
大猫的无限游戏
罗磊的独立博客
H
Help Net Security
月光博客
月光博客
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
GbyAI
GbyAI
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
feat: add proxy validation command · openclaw/openclaw@4e...
jesse-merhi · 2026-05-01 · via Recent Commits to openclaw:main

@@ -1,32 +1,58 @@

11

---

2-

summary: "CLI reference for `openclaw proxy`, the local debug proxy and capture inspector"

2+

summary: "CLI reference for `openclaw proxy`, including operator-managed proxy validation and the local debug proxy capture inspector"

33

read_when:

4+

- You need to validate operator-managed proxy routing before deployment

45

- You need to capture OpenClaw transport traffic locally for debugging

56

- You want to inspect debug proxy sessions, blobs, or built-in query presets

67

title: "Proxy"

78

---

89910

# `openclaw proxy`

101111-

Run the local explicit debug proxy and inspect captured traffic.

12+

Validate operator-managed proxy routing, or run the local explicit debug proxy

13+

and inspect captured traffic.

121413-

This is a debugging command for transport-level investigation. It can start a

14-

local proxy, run a child command with capture enabled, list capture sessions,

15-

query common traffic patterns, read captured blobs, and purge local capture

16-

data.

15+

Use `validate` to preflight an operator-managed forward proxy before enabling

16+

OpenClaw proxy routing. The other commands are debugging tools for

17+

transport-level investigation: they can start a local proxy, run a child command

18+

with capture enabled, list capture sessions, query common traffic patterns, read

19+

captured blobs, and purge local capture data.

17201821

## Commands

19222023

```bash

2124

openclaw proxy start [--host <host>] [--port <port>]

2225

openclaw proxy run [--host <host>] [--port <port>] -- <cmd...>

26+

openclaw proxy validate [--json] [--proxy-url <url>] [--allowed-url <url>] [--denied-url <url>] [--timeout-ms <ms>]

2327

openclaw proxy coverage

2428

openclaw proxy sessions [--limit <count>]

2529

openclaw proxy query --preset <name> [--session <id>]

2630

openclaw proxy blob --id <blobId>

2731

openclaw proxy purge

2832

```

293334+

## Validate

35+36+

`openclaw proxy validate` checks the effective operator-managed proxy URL from

37+

`--proxy-url`, config, or `OPENCLAW_PROXY_URL`. It reports a config problem when

38+

no proxy is enabled and configured; use `--proxy-url` for a one-off preflight

39+

before changing config. By default it verifies that a public destination succeeds

40+

through the proxy and that the proxy cannot reach a temporary loopback canary.

41+

Custom denied destinations are fail-closed: HTTP responses and ambiguous

42+

transport failures both fail unless you can verify a deployment-specific denial

43+

signal separately.

44+45+

Options:

46+47+

- `--json`: print machine-readable JSON.

48+

- `--proxy-url <url>`: validate this proxy URL instead of config or env.

49+

- `--allowed-url <url>`: add a destination expected to succeed through the proxy. Repeat to check multiple destinations.

50+

- `--denied-url <url>`: add a destination expected to be blocked by the proxy. Repeat to check multiple destinations.

51+

- `--timeout-ms <ms>`: per-request timeout in milliseconds.

52+53+

See [Network Proxy](/security/network-proxy) for deployment guidance and denial

54+

semantics.

55+3056

## Query presets

31573258

`openclaw proxy query --preset <name>` accepts:

@@ -42,9 +68,11 @@ openclaw proxy purge

42684369

- `start` defaults to `127.0.0.1` unless `--host` is set.

4470

- `run` starts a local debug proxy and then runs the command after `--`.

71+

- `validate` exits with code 1 when proxy config or destination checks fail.

4572

- Captures are local debugging data; use `openclaw proxy purge` when finished.

46734774

## Related

48754976

- [CLI reference](/cli)

77+

- [Network Proxy](/security/network-proxy)

5078

- [Trusted proxy auth](/gateway/trusted-proxy-auth)