One line
On the Linux server that runs your gateway. Baton's script does not ask for root; installing OpenClaw or a harness may. Run it again to upgrade. Each step keeps what is already in place.
curl -fsSL https://trybaton.dev/install.sh | bash
The script needs bash. When openclaw is not on PATH, it installs OpenClaw with OpenClaw's own installer, without onboarding. Set BATON_INSTALL_OPENCLAW=0 to stop instead. It downloads the package, checks it against SHA256SUMS, and links the plugin. When OpenClaw asks for a plugin's capabilities to be accepted (2026.9.8 and later), the script accepts Baton's.
When the package includes Baton's setup, the script runs it for the harnesses in BATON_HARNESS: a comma-separated list of openclaw, claude-code, codex, grok and hermes. The default is openclaw, and none skips setup. A harness that is already installed is skipped. When an OpenClaw gateway already runs on the server, Baton uses it. BATON_PER_USER_OPENCLAW=1 installs a separate OpenClaw for the agent user.
Last, it restarts the gateway when this OpenClaw's help lists openclaw gateway restart. If OpenClaw has no gateway service yet, it tells you to run openclaw onboard --install-daemon. If the restart command is not there, it tells you to restart the gateway yourself.
OpenClaw's onboard asks for a model provider. You can skip auth if you only need Baton's UI for now; harness sign-in is separate. Onboard's --install-daemon needs a working systemd user session. If that is unavailable, start the gateway in a shell with openclaw gateway run and leave it running.
Pin this release with BATON_VERSION=0.26.12. The plugin directory defaults to ~/openclaw-plugins. Set BATON_PLUGIN_DIR to use another one.
Requirements
- An OpenClaw gateway you run. The script can install OpenClaw first.
- A Linux server.
- Node 24.16.0 or newer (OpenClaw also accepts 26.1.0+). OpenClaw's installer can install Node when needed; that step may ask for root.
Get the package
Version 0.26.12. Free for up to 3 people. A Pro key lifts that cap. Agents are not people. The cap counts human profiles only.
Download openclaw-baton-0.26.12.tgz
SHA-256 2a5b8a6093c674ff695913fe39dca5dd69ff4c832e5b88e2cfd7b0b6dbe65769
The same file is at /download/baton-latest.tgz. Checksums are in SHA256SUMS.
Use is governed by the Baton license, included in the package as LICENSE, and by the Terms.
Install by hand
Download openclaw-baton-0.26.12.tgz and SHA256SUMS into the same directory. Then:
sha256sum -c --ignore-missing SHA256SUMS mkdir -p ~/openclaw-plugins && tar -xzf openclaw-baton-0.26.12.tgz -C ~/openclaw-plugins openclaw plugins install --link ~/openclaw-plugins/baton
On OpenClaw 2026.9.8 and later, add --accept-capabilities to openclaw plugins install, here and in the upgrade below. Without it OpenClaw does not install the plugin.
Restart the gateway. When openclaw gateway --help lists it, that command is openclaw gateway restart. Then open http://<gateway>/baton/. A fresh local gateway on the default port is http://127.0.0.1:18789/baton/.
To upgrade, extract the new package over the same directory and run the install again with --force:
tar -xzf openclaw-baton-0.26.12.tgz -C ~/openclaw-plugins openclaw plugins install --link ~/openclaw-plugins/baton --force
Connect
Served by the plugin at /baton, Baton opens against this gateway. When the gateway uses token auth (OpenClaw's default), the first visit still asks for the gateway token before the room loads.
The connection status under the Baton logo reads "demo data" until it is connected. Click it and enter the gateway address plus a gateway token. For a local install that is usually ws://127.0.0.1:18789 (or wss://… when TLS is in front). On the gateway host, print the token with openclaw gateway auth-token --show. The token is only used to pair this browser and is never saved. The device token the gateway issues is kept in localStorage.
Agent space, if you want outside harnesses
The package includes setup-agent-space.sh, next to the plugin in ~/openclaw-plugins/baton/. The install script runs it through Baton's setup when a harness you set up needs the agent user and the script runs as root or can use sudo without a password. Otherwise, run it yourself as root on the Baton host:
sudo bash ~/openclaw-plugins/baton/setup-agent-space.sh
It is safe to re-run. It creates:
- The user
baton-agent. Outside agents run as this user. Override withBATON_AGENT_USER. - The group
baton. People, OpenClaw, and agents share project files through it. Override withBATON_GROUP. /srv/projects, ownedroot:baton, group-writable, so new files keep the group. Override withBATON_PROJECTS.
--adopt followed by a repo directory moves that repo into /srv/projects and leaves a link at the old path. --share-clis puts root's claude and codex commands where the agent user can run them. Those copies stay owned by root. Each tool still signs in as the agent user.
To set up more harnesses later, run Baton's setup from the same directory. --dry-run prints the commands without running them:
node ~/openclaw-plugins/baton/baton-setup.js --harness codex,claude-code
Connect an outside agent
In Baton, Agents → Invite agent connects Hermes, Claude Code, Codex, or Grok Build, on this server or over SSH. Hermes can also connect through hermes serve.
Sign-in is the harness's own. Claude Code and Codex use the login already on the server. Grok needs grok login --device-code once, or XAI_API_KEY.
Sessions, approvals, project limits, Pause, Roll back, and Diff go through Baton. How much of each harness's work reaches the gate is listed on the security page. Over WebSocket, Baton cannot install the gate. Start hermes serve with BATON_GATE=1 yourself.
Server id and license key
Members & roles shows the plan, how many people count, and this server's id. The id is created once, in baton/instance.json, under the gateway's state directory. Send that id when you buy a key so the key can be bound to this install. Pro is priced per install.
An admin pastes the key on Members & roles. Baton saves it as baton/license.json (mode 0600) and does not show the key back.
Or set one of these before the gateway starts:
BATON_LICENSE_KEY, thebaton1.…token.BATON_LICENSE_FILE, a file that contains the token.
A saved key wins, so the page can replace what the environment supplied. Choose Remove key to fall back to the environment.
People already on the server are recorded the first time an admin's Baton loads the directory. That list is kept even if it is already over 3, so installing on a server that already has a team does not remove anyone. After that, a new person is admitted only while the license has room.
Nothing is deleted when a key expires, is removed, or fails to verify. The cap falls back to 3. People already admitted keep working. A new person past 3 is refused. An expired key says so, with the date. There is no extra paid window after expiry. The grace is the free cap, with the roster left as it is.
Help
Write to hello@trybaton.dev.