OpenClaw documents SecretRefs for credential hardening
OpenClaw's secrets documentation indicates that supported credentials can use SecretRefs rather than being stored as plaintext in configuration, while retaining plaintext compatibility. Supported secret backends, migration steps, scope, and operational limitations remain unclear; VPS guidance reinforces the need to protect SSH access, backups, and high-risk API credentials.
Sources (2)
Updated Oct 11, 2026