{"id":"a700e0ec-bcc2-45ea-b4a7-ab955a8788ce","entityType":"agent","slug":"clawhub-leoyeai-myclaw-backup","name":"myclaw-backup","canonicalUrl":"https://www.xpersona.co/agent/clawhub-leoyeai-myclaw-backup","canonicalPath":"/agent/clawhub-leoyeai-myclaw-backup","generatedAt":"2026-10-09T22:08:47.799Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T14:55:38.961Z","emptyReason":null},"description":"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosyst... Skill: myclaw-backup Owner: leoyeai Summary: Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosyst... Tags: backup:1.7.0, latest:2.0.0, migration:1.7.0, myclaw:1.7.0, restore:1.7.0 Version history: v2.0.0 | 2026-03-28T07:13:04.896Z | user Update ecosystem links to myclaw.ai/skills v1.7.0 | 2026-03-03T06:02:50.642Z","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.4K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17173yy3nw4w4agfswx5k0wz583g31t:myclaw-backup","sourceUrl":"https://clawhub.ai/leoyeai/myclaw-backup","homepage":"https://clawhub.ai/leoyeai/skills/myclaw-backup","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/leoyeai/myclaw-backup","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/leoyeai/skills/myclaw-backup","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosyst..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:55:38.961Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:55:38.961Z","emptyReason":null},"stars":null,"forks":null,"downloads":2441,"packageName":null,"latestVersion":"2.0.0","tractionLabel":"2.4K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:55:38.961Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T14:55:38.961Z","lastCrawledAt":"2026-10-09T14:55:38.961Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T14:55:38.961Z","lastVerifiedAt":null,"highlights":[{"version":"2.0.0","createdAt":"2026-03-28T07:13:04.896Z","changelog":"Update ecosystem links to myclaw.ai/skills","fileCount":10,"zipByteSize":22467},{"version":"1.7.0","createdAt":"2026-03-03T06:02:50.642Z","changelog":"Post-restore report: after restore.sh completes, writes .restore-complete.json flag. On next heartbeat Agent detects it, sends restore report to user in their own language (read from USER.md), then deletes the flag (one-shot). Report includes backup name, agent name, restore time, and contents list.","fileCount":9,"zipByteSize":21116},{"version":"1.6.2","createdAt":"2026-03-03T03:57:10.582Z","changelog":"Security: refactor server.js from 474 to 225 lines — token enforcement and localhost-only checks now appear in first 50 lines, visible before any truncation. HTML UI extracted to ui.html. All security gates at top of file.","fileCount":9,"zipByteSize":20358},{"version":"1.6.1","createdAt":"2026-03-03T03:12:19.222Z","changelog":"Security: /restore and /backup endpoints are now localhost-only (remote access can only download/upload, not execute). Web UI hides restore button when accessed remotely. schedule.sh explicitly prints crontab entry before adding. SKILL.md has detailed access control table.","fileCount":8,"zipByteSize":20754},{"version":"1.6.0","createdAt":"2026-03-03T02:06:03.295Z","changelog":"Fix: preserve gateway auth token on restore to new server. Prevents 'gateway token mismatch' error in Control UI / Dashboard after migration. Add --overwrite-gateway-token flag for full disaster recovery.","fileCount":8,"zipByteSize":19605},{"version":"1.5.0","createdAt":"2026-03-02T14:38:45.921Z","changelog":"Backup filename now includes agent name for easy identification (e.g. openclaw-backup_the-doctor_20260302_143000.tar.gz). Agent name read from IDENTITY.md, fallback to hostname.","fileCount":8,"zipByteSize":18551},{"version":"1.4.3","createdAt":"2026-03-02T13:42:27.415Z","changelog":"Add clickable MyClaw.ai link at top of skill page body","fileCount":8,"zipByteSize":18371},{"version":"1.4.2","createdAt":"2026-03-02T13:40:07.686Z","changelog":"Add MyClaw.ai link in skill description","fileCount":8,"zipByteSize":18322}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17173yy3nw4w4agfswx5k0wz583g31t:myclaw-backup","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T22:08:47.796Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-leoyeai-myclaw-backup/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T14:55:38.961Z","emptyReason":null},"readme":"Skill: myclaw-backup\n\nOwner: leoyeai\n\nSummary: Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosyst...\n\nTags: backup:1.7.0, latest:2.0.0, migration:1.7.0, myclaw:1.7.0, restore:1.7.0\n\nVersion history:\n\nv2.0.0 | 2026-03-28T07:13:04.896Z | user\n\nUpdate ecosystem links to myclaw.ai/skills\n\nv1.7.0 | 2026-03-03T06:02:50.642Z | user\n\nPost-restore report: after restore.sh completes, writes .restore-complete.json flag. On next heartbeat Agent detects it, sends restore report to user in their own language (read from USER.md), then deletes the flag (one-shot). Report includes backup name, agent name, restore time, and contents list.\n\nv1.6.2 | 2026-03-03T03:57:10.582Z | user\n\nSecurity: refactor server.js from 474 to 225 lines — token enforcement and localhost-only checks now appear in first 50 lines, visible before any truncation. HTML UI extracted to ui.html. All security gates at top of file.\n\nv1.6.1 | 2026-03-03T03:12:19.222Z | user\n\nSecurity: /restore and /backup endpoints are now localhost-only (remote access can only download/upload, not execute). Web UI hides restore button when accessed remotely. schedule.sh explicitly prints crontab entry before adding. SKILL.md has detailed access control table.\n\nv1.6.0 | 2026-03-03T02:06:03.295Z | user\n\nFix: preserve gateway auth token on restore to new server. Prevents 'gateway token mismatch' error in Control UI / Dashboard after migration. Add --overwrite-gateway-token flag for full disaster recovery.\n\nv1.5.0 | 2026-03-02T14:38:45.921Z | user\n\nBackup filename now includes agent name for easy identification (e.g. openclaw-backup_the-doctor_20260302_143000.tar.gz). Agent name read from IDENTITY.md, fallback to hostname.\n\nv1.4.3 | 2026-03-02T13:42:27.415Z | user\n\nAdd clickable MyClaw.ai link at top of skill page body\n\nv1.4.2 | 2026-03-02T13:40:07.686Z | user\n\nAdd MyClaw.ai link in skill description\n\nv1.4.1 | 2026-03-02T13:32:33.789Z | user\n\nOne-click backup & restore for OpenClaw instances. Part of the [MyClaw.ai](https://myclaw.ai) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Backs up workspace, credentials, bot tokens, API keys, agent history. Restore to any new instance with zero re-pairing. | GitHub: https://github.com/LeoYeAI/openclaw-backup\n\nv1.4.0 | 2026-03-02T10:12:57.416Z | user\n\nSecurity fixes: token now mandatory for HTTP server (refuses to start without it), /health returns minimal read-only info only, restore requires explicit dry-run-first + confirm=1 two-step flow, security headers added, declared all dependencies in metadata.\n\nv1.3.0 | 2026-03-02T09:40:31.891Z | user\n\nFull OpenClaw backup & restore: workspace, credentials, agent history, all channel state. Built-in HTTP server for browser download/upload/restore. No re-pairing after migration. Powered by MyClaw.ai\n\nArchive index:\n\nArchive v2.0.0: 10 files, 22467 bytes\n\nFiles: _meta.json (132b), references/what-gets-saved.md (2463b), scripts/backup.sh (8965b), scripts/restore.sh (15742b), scripts/schedule.sh (2023b), scripts/serve.sh (3271b), scripts/server.js (11066b), scripts/ui.html (6928b), skill-card.md (2568b), SKILL.md (7499b)\n\nFile v2.0.0:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\n> **Built on [MyClaw.ai](https://myclaw.ai)** — the AI personal assistant platform that gives every user a full server with complete code control, networking, and tool access. This skill is part of the [MyClaw open skills ecosystem](https://myclaw.ai/skills).\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary & Security Model\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand the security model before use:\n\n### What each script does\n- **backup.sh** — reads `~/.openclaw/` and writes a `chmod 600` archive to disk. No network access.\n- **restore.sh** — overwrites `~/.openclaw/` from an archive. Requires typing `yes` to confirm. Always run `--dry-run` first.\n- **serve.sh / server.js** — starts a local HTTP server. Token is **mandatory** (refuses to start without one). Shell-execution endpoints (`/backup`, `/restore`) are **localhost-only** — remote access can only download and upload files, not trigger execution.\n- **schedule.sh** — modifies your system crontab to run backup.sh on a schedule. Prints the cron entry before adding. Use `--disable` to remove.\n\n### Access control summary\n| Endpoint | Remote (token required) | Localhost only |\n|---|---|---|\n| GET /health | ✅ (no token) | — |\n| GET /backups | ✅ | — |\n| GET /download/:file | ✅ | — |\n| POST /upload | ✅ | — |\n| POST /backup | ❌ | ✅ |\n| POST /restore | ❌ | ✅ |\n\n### Best practices\n- Never start the HTTP server without `--token`\n- Never expose the HTTP server to the public internet without TLS\n- Always run `restore.sh --dry-run` before applying a restore\n- Store backup archives securely — they contain all credentials\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run] [--overwrite-gateway-token]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n> **Gateway token behavior (v1.6+):** By default, `restore.sh` preserves the new server's `gateway.auth.token` after restoring `openclaw.json`. This prevents the `\"gateway token mismatch\"` error in Control UI / Dashboard after migration. Use `--overwrite-gateway-token` only for full disaster recovery on the same server.\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Post-Restore: Automatic Recovery Report\n\nAfter `restore.sh` completes, it writes `workspace/.restore-complete.json`. On the next heartbeat/startup, the Agent should:\n\n1. Check if `workspace/.restore-complete.json` exists\n2. If yes: read it, send a restore report to the user, then **delete the file** (one-shot — never report twice)\n3. **Send the report in the user's primary language** (read from `workspace/USER.md`)\n\n### Report format (adapt language from USER.md)\n```\n✅ [Restore complete — in user's language]\n\n📦 Backup: {backup_name}\n🤖 Agent: {agent_name}\n🕐 Restored at: {restored_at}\n💾 Contents restored: workspace, config, credentials, history, cron...\n\n[Channel reconnect instructions in user's language]\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v2.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"2.0.0\",\n  \"publishedAt\": 1774681984896\n}\n\nFile v2.0.0:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nFile v2.0.0:skill-card.md\n\n## Description:\n\nMyClaw Backup helps an OpenClaw user create, schedule, download, upload, and restore backups of OpenClaw configuration, memory, skills, credentials, channel state, and workspace data.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[leoyeai](https://clawhub.ai/user/leoyeai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal OpenClaw users and developers use this skill to protect, migrate, or recover an OpenClaw instance by creating local backup archives, scheduling recurring backups, and restoring from trusted archives.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Backup archives can contain bot tokens, API keys, channel credentials, and session history.\n\nMitigation: Keep archives encrypted or otherwise strongly protected, avoid committing or sharing them, and transfer them only over protected channels.\n\nRisk: Restore and upload paths can affect sensitive OpenClaw state and should not process untrusted archives.\n\nMitigation: Run restores only from trusted archives, use dry-run before applying a restore, and treat the restore and upload web server paths as needing security fixes before remote use.\n\nRisk: The HTTP backup server can expose sensitive backup operations or tokenized URLs if reachable on an unprotected network.\n\nMitigation: Do not expose the HTTP server on a network without TLS, use a strong token, and avoid sharing tokenized URLs.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/leoyeai/skills/myclaw-backup)\n- [Publisher profile](https://clawhub.ai/user/leoyeai)\n- [MyClaw skills ecosystem](https://myclaw.ai/skills)\n- [MyClaw](https://myclaw.ai)\n- [OpenClaw Backup - What Gets Saved](references/what-gets-saved.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell commands, JSON snippets, and operational status text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May create local .tar.gz backup files, restore OpenClaw state, start a token-protected local HTTP backup manager, or modify cron scheduling when the user runs the provided scripts.]\n\n## Skill Version(s):\n\n2.0.0 (source: server release metadata; artifact _meta.json reports 1.7.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.7.0: 9 files, 21116 bytes\n\nFiles: _meta.json (132b), references/what-gets-saved.md (2463b), scripts/backup.sh (8965b), scripts/restore.sh (15742b), scripts/schedule.sh (2023b), scripts/serve.sh (3271b), scripts/server.js (11066b), scripts/ui.html (6928b), SKILL.md (7467b)\n\nFile v1.7.0:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\n> **Built on [MyClaw.ai](https://myclaw.ai)** — the AI personal assistant platform that gives every user a full server with complete code control, networking, and tool access. This skill is part of the MyClaw.ai open skills ecosystem.\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary & Security Model\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand the security model before use:\n\n### What each script does\n- **backup.sh** — reads `~/.openclaw/` and writes a `chmod 600` archive to disk. No network access.\n- **restore.sh** — overwrites `~/.openclaw/` from an archive. Requires typing `yes` to confirm. Always run `--dry-run` first.\n- **serve.sh / server.js** — starts a local HTTP server. Token is **mandatory** (refuses to start without one). Shell-execution endpoints (`/backup`, `/restore`) are **localhost-only** — remote access can only download and upload files, not trigger execution.\n- **schedule.sh** — modifies your system crontab to run backup.sh on a schedule. Prints the cron entry before adding. Use `--disable` to remove.\n\n### Access control summary\n| Endpoint | Remote (token required) | Localhost only |\n|---|---|---|\n| GET /health | ✅ (no token) | — |\n| GET /backups | ✅ | — |\n| GET /download/:file | ✅ | — |\n| POST /upload | ✅ | — |\n| POST /backup | ❌ | ✅ |\n| POST /restore | ❌ | ✅ |\n\n### Best practices\n- Never start the HTTP server without `--token`\n- Never expose the HTTP server to the public internet without TLS\n- Always run `restore.sh --dry-run` before applying a restore\n- Store backup archives securely — they contain all credentials\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run] [--overwrite-gateway-token]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n> **Gateway token behavior (v1.6+):** By default, `restore.sh` preserves the new server's `gateway.auth.token` after restoring `openclaw.json`. This prevents the `\"gateway token mismatch\"` error in Control UI / Dashboard after migration. Use `--overwrite-gateway-token` only for full disaster recovery on the same server.\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Post-Restore: Automatic Recovery Report\n\nAfter `restore.sh` completes, it writes `workspace/.restore-complete.json`. On the next heartbeat/startup, the Agent should:\n\n1. Check if `workspace/.restore-complete.json` exists\n2. If yes: read it, send a restore report to the user, then **delete the file** (one-shot — never report twice)\n3. **Send the report in the user's primary language** (read from `workspace/USER.md`)\n\n### Report format (adapt language from USER.md)\n```\n✅ [Restore complete — in user's language]\n\n📦 Backup: {backup_name}\n🤖 Agent: {agent_name}\n🕐 Restored at: {restored_at}\n💾 Contents restored: workspace, config, credentials, history, cron...\n\n[Channel reconnect instructions in user's language]\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.7.0:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.7.0\",\n  \"publishedAt\": 1772517770642\n}\n\nFile v1.7.0:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nArchive v1.6.2: 9 files, 20358 bytes\n\nFiles: _meta.json (132b), references/what-gets-saved.md (2463b), scripts/backup.sh (8965b), scripts/restore.sh (14470b), scripts/schedule.sh (2023b), scripts/serve.sh (3271b), scripts/server.js (11066b), scripts/ui.html (6928b), SKILL.md (6728b)\n\nFile v1.6.2:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\n> **Built on [MyClaw.ai](https://myclaw.ai)** — the AI personal assistant platform that gives every user a full server with complete code control, networking, and tool access. This skill is part of the MyClaw.ai open skills ecosystem.\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary & Security Model\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand the security model before use:\n\n### What each script does\n- **backup.sh** — reads `~/.openclaw/` and writes a `chmod 600` archive to disk. No network access.\n- **restore.sh** — overwrites `~/.openclaw/` from an archive. Requires typing `yes` to confirm. Always run `--dry-run` first.\n- **serve.sh / server.js** — starts a local HTTP server. Token is **mandatory** (refuses to start without one). Shell-execution endpoints (`/backup`, `/restore`) are **localhost-only** — remote access can only download and upload files, not trigger execution.\n- **schedule.sh** — modifies your system crontab to run backup.sh on a schedule. Prints the cron entry before adding. Use `--disable` to remove.\n\n### Access control summary\n| Endpoint | Remote (token required) | Localhost only |\n|---|---|---|\n| GET /health | ✅ (no token) | — |\n| GET /backups | ✅ | — |\n| GET /download/:file | ✅ | — |\n| POST /upload | ✅ | — |\n| POST /backup | ❌ | ✅ |\n| POST /restore | ❌ | ✅ |\n\n### Best practices\n- Never start the HTTP server without `--token`\n- Never expose the HTTP server to the public internet without TLS\n- Always run `restore.sh --dry-run` before applying a restore\n- Store backup archives securely — they contain all credentials\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run] [--overwrite-gateway-token]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n> **Gateway token behavior (v1.6+):** By default, `restore.sh` preserves the new server's `gateway.auth.token` after restoring `openclaw.json`. This prevents the `\"gateway token mismatch\"` error in Control UI / Dashboard after migration. Use `--overwrite-gateway-token` only for full disaster recovery on the same server.\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.6.2:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.6.2\",\n  \"publishedAt\": 1772510230582\n}\n\nFile v1.6.2:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nArchive v1.6.1: 8 files, 20754 bytes\n\nFiles: _meta.json (132b), references/what-gets-saved.md (2463b), scripts/backup.sh (8965b), scripts/restore.sh (14470b), scripts/schedule.sh (2023b), scripts/serve.sh (3271b), scripts/server.js (21445b), SKILL.md (6728b)\n\nFile v1.6.1:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\n> **Built on [MyClaw.ai](https://myclaw.ai)** — the AI personal assistant platform that gives every user a full server with complete code control, networking, and tool access. This skill is part of the MyClaw.ai open skills ecosystem.\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary & Security Model\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand the security model before use:\n\n### What each script does\n- **backup.sh** — reads `~/.openclaw/` and writes a `chmod 600` archive to disk. No network access.\n- **restore.sh** — overwrites `~/.openclaw/` from an archive. Requires typing `yes` to confirm. Always run `--dry-run` first.\n- **serve.sh / server.js** — starts a local HTTP server. Token is **mandatory** (refuses to start without one). Shell-execution endpoints (`/backup`, `/restore`) are **localhost-only** — remote access can only download and upload files, not trigger execution.\n- **schedule.sh** — modifies your system crontab to run backup.sh on a schedule. Prints the cron entry before adding. Use `--disable` to remove.\n\n### Access control summary\n| Endpoint | Remote (token required) | Localhost only |\n|---|---|---|\n| GET /health | ✅ (no token) | — |\n| GET /backups | ✅ | — |\n| GET /download/:file | ✅ | — |\n| POST /upload | ✅ | — |\n| POST /backup | ❌ | ✅ |\n| POST /restore | ❌ | ✅ |\n\n### Best practices\n- Never start the HTTP server without `--token`\n- Never expose the HTTP server to the public internet without TLS\n- Always run `restore.sh --dry-run` before applying a restore\n- Store backup archives securely — they contain all credentials\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run] [--overwrite-gateway-token]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n> **Gateway token behavior (v1.6+):** By default, `restore.sh` preserves the new server's `gateway.auth.token` after restoring `openclaw.json`. This prevents the `\"gateway token mismatch\"` error in Control UI / Dashboard after migration. Use `--overwrite-gateway-token` only for full disaster recovery on the same server.\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.6.1:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.6.1\",\n  \"publishedAt\": 1772507539222\n}\n\nFile v1.6.1:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nArchive v1.6.0: 8 files, 19605 bytes\n\nFiles: references/what-gets-saved.md (2463b), scripts/backup.sh (8965b), scripts/restore.sh (14470b), scripts/schedule.sh (1737b), scripts/serve.sh (3271b), scripts/server.js (19271b), SKILL.md (5850b), _meta.json (132b)\n\nFile v1.6.0:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\n> **Built on [MyClaw.ai](https://myclaw.ai)** — the AI personal assistant platform that gives every user a full server with complete code control, networking, and tool access. This skill is part of the MyClaw.ai open skills ecosystem.\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand what it does before use:\n\n- **backup.sh** reads and archives the entire `~/.openclaw/` directory (excluding logs/media)\n- **restore.sh** overwrites `~/.openclaw/` — always run `--dry-run` first, confirm output, then apply\n- **serve.sh** opens a TCP port — **always set `--token`**, never expose to public internet without it\n- Backup archives are `chmod 600`; treat them like passwords\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run] [--overwrite-gateway-token]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n> **Gateway token behavior (v1.6+):** By default, `restore.sh` preserves the new server's `gateway.auth.token` after restoring `openclaw.json`. This prevents the `\"gateway token mismatch\"` error in Control UI / Dashboard after migration. Use `--overwrite-gateway-token` only for full disaster recovery on the same server.\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.6.0:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.6.0\",\n  \"publishedAt\": 1772503563295\n}\n\nFile v1.6.0:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nArchive v1.5.0: 8 files, 18551 bytes\n\nFiles: references/what-gets-saved.md (2463b), scripts/backup.sh (8965b), scripts/restore.sh (11047b), scripts/schedule.sh (1737b), scripts/serve.sh (3271b), scripts/server.js (19271b), SKILL.md (5499b), _meta.json (132b)\n\nFile v1.5.0:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\n> **Built on [MyClaw.ai](https://myclaw.ai)** — the AI personal assistant platform that gives every user a full server with complete code control, networking, and tool access. This skill is part of the MyClaw.ai open skills ecosystem.\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand what it does before use:\n\n- **backup.sh** reads and archives the entire `~/.openclaw/` directory (excluding logs/media)\n- **restore.sh** overwrites `~/.openclaw/` — always run `--dry-run` first, confirm output, then apply\n- **serve.sh** opens a TCP port — **always set `--token`**, never expose to public internet without it\n- Backup archives are `chmod 600`; treat them like passwords\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.5.0:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.5.0\",\n  \"publishedAt\": 1772462325921\n}\n\nFile v1.5.0:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nArchive v1.4.3: 8 files, 18371 bytes\n\nFiles: references/what-gets-saved.md (2463b), scripts/backup.sh (8527b), scripts/restore.sh (10986b), scripts/schedule.sh (1737b), scripts/serve.sh (3271b), scripts/server.js (19271b), SKILL.md (5499b), _meta.json (132b)\n\nFile v1.4.3:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\n> **Built on [MyClaw.ai](https://myclaw.ai)** — the AI personal assistant platform that gives every user a full server with complete code control, networking, and tool access. This skill is part of the MyClaw.ai open skills ecosystem.\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand what it does before use:\n\n- **backup.sh** reads and archives the entire `~/.openclaw/` directory (excluding logs/media)\n- **restore.sh** overwrites `~/.openclaw/` — always run `--dry-run` first, confirm output, then apply\n- **serve.sh** opens a TCP port — **always set `--token`**, never expose to public internet without it\n- Backup archives are `chmod 600`; treat them like passwords\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.4.3:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.4.3\",\n  \"publishedAt\": 1772458947415\n}\n\nFile v1.4.3:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nArchive v1.4.2: 8 files, 18322 bytes\n\nFiles: references/what-gets-saved.md (2463b), scripts/backup.sh (8527b), scripts/restore.sh (10986b), scripts/schedule.sh (1737b), scripts/serve.sh (3271b), scripts/server.js (19271b), SKILL.md (5261b), _meta.json (132b)\n\nFile v1.4.2:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand what it does before use:\n\n- **backup.sh** reads and archives the entire `~/.openclaw/` directory (excluding logs/media)\n- **restore.sh** overwrites `~/.openclaw/` — always run `--dry-run` first, confirm output, then apply\n- **serve.sh** opens a TCP port — **always set `--token`**, never expose to public internet without it\n- Backup archives are `chmod 600`; treat them like passwords\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.4.2:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.4.2\",\n  \"publishedAt\": 1772458807686\n}\n\nFile v1.4.2:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nArchive v1.4.1: 8 files, 18231 bytes\n\nFiles: references/what-gets-saved.md (2463b), scripts/backup.sh (8527b), scripts/restore.sh (10986b), scripts/schedule.sh (1737b), scripts/serve.sh (3271b), scripts/server.js (19271b), SKILL.md (5094b), _meta.json (132b)\n\nFile v1.4.1:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand what it does before use:\n\n- **backup.sh** reads and archives the entire `~/.openclaw/` directory (excluding logs/media)\n- **restore.sh** overwrites `~/.openclaw/` — always run `--dry-run` first, confirm output, then apply\n- **serve.sh** opens a TCP port — **always set `--token`**, never expose to public internet without it\n- Backup archives are `chmod 600`; treat them like passwords\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.4.1:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.4.1\",\n  \"publishedAt\": 1772458353789\n}\n\nFile v1.4.1:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```\n\nArchive v1.4.0: 8 files, 18232 bytes\n\nFiles: references/what-gets-saved.md (2463b), scripts/backup.sh (8527b), scripts/restore.sh (10986b), scripts/schedule.sh (1737b), scripts/serve.sh (3271b), scripts/server.js (19271b), SKILL.md (5094b), _meta.json (132b)\n\nFile v1.4.0:SKILL.md\n\n---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand what it does before use:\n\n- **backup.sh** reads and archives the entire `~/.openclaw/` directory (excluding logs/media)\n- **restore.sh** overwrites `~/.openclaw/` — always run `--dry-run` first, confirm output, then apply\n- **serve.sh** opens a TCP port — **always set `--token`**, never expose to public internet without it\n- Backup archives are `chmod 600`; treat them like passwords\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, `python3`, `openclaw` CLI (all standard on OpenClaw instances).\n\nCheck: `which node rsync tar python3 openclaw`\n\n## Scripts\n\n| Script | Purpose |\n|---|---|\n| `scripts/backup.sh [output-dir]` | Create backup (default: `/tmp/openclaw-backups/`) |\n| `scripts/restore.sh <archive> [--dry-run]` | Restore — **always dry-run first** |\n| `scripts/serve.sh start --token TOKEN [--port 7373]` | Start HTTP server — **token required** |\n| `scripts/serve.sh stop\\|status` | Stop/check server |\n| `scripts/schedule.sh [--interval daily\\|weekly\\|hourly]` | System cron scheduling |\n\n## What Gets Backed Up\n\nSee `references/what-gets-saved.md` for full details.\n\n**Includes:** workspace (MEMORY.md, skills, agent files), openclaw.json (bot tokens + API keys), credentials, channel pairing state, agent config + session history, devices, identity, cron jobs, guardian scripts.\n\n**Excludes:** logs, binary media, node_modules, canvas system files.\n\n## Common Workflows\n\n### Create backup\n\n```bash\nbash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)\n```\n\n### Restore — always dry-run first\n\n```bash\n# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n```\n\nThe restore script saves a pre-restore snapshot before overwriting anything.\n\n### HTTP server — token is mandatory\n\n```bash\n# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>\n```\n\n**Never share the URL on a public network without a reverse proxy + TLS.**\n\nThe Web UI provides: create backup, download `.tar.gz`, upload, dry-run preview, restore.\n\n**HTTP API (all require token except /health):**\n- `GET  /health`              — Health check (unauthenticated, read-only)\n- `GET  /backups`             — List backups\n- `POST /backup`              — Create backup\n- `GET  /download/:filename`  — Download archive\n- `POST /upload`              — Upload archive (multipart, field: `backup`)\n- `POST /restore/:filename`   — Restore; add `?dry_run=1` to preview\n\n### Migrate to a new instance\n\n**Old machine:**\n```bash\nbash scripts/serve.sh start --token MYTOKEN --port 7373\n```\n\n**New machine (after installing OpenClaw):**\n```bash\n# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed\n```\n\n### Schedule daily auto-backup (OpenClaw cron)\n\n```json\n{\n  \"name\": \"daily-openclaw-backup\",\n  \"schedule\": { \"kind\": \"cron\", \"expr\": \"0 3 * * *\", \"tz\": \"UTC\" },\n  \"payload\": {\n    \"kind\": \"agentTurn\",\n    \"message\": \"Run a backup using the myclaw-backup skill. Output dir: /tmp/openclaw-backups\",\n    \"timeoutSeconds\": 120\n  },\n  \"sessionTarget\": \"isolated\"\n}\n```\n\n## Future: MyClaw Cloud Backup\n\nThe HTTP API is designed to be compatible with a future MyClaw cloud backup service. When available, replace the local server URL with the MyClaw API endpoint — the upload/download/restore flow stays identical.\n\nFile v1.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"1.4.0\",\n  \"publishedAt\": 1772446377416\n}\n\nFile v1.4.0:references/what-gets-saved.md\n\n# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```","readmeExcerpt":"Skill: myclaw-backup Owner: leoyeai Summary: Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosyst... Tags: backup:1.7.0, latest:2.0.0, migration:1.7.0, myclaw:1.7.0, restore:1.7.0 Version history: v2.0.0 | 2026-03-28T07:13:04.896Z | user Update ecosystem links to myclaw.ai/skills v1.7.0 | 2026-03-03T06:02:50.642Z ","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"bash scripts/backup.sh /tmp/openclaw-backups\n# → /tmp/openclaw-backups/openclaw-backup_TIMESTAMP.tar.gz (chmod 600)"},{"language":"bash","snippet":"# Step 1: preview what will change\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Step 2: review the output, then apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz"},{"language":"bash","snippet":"# Token is required — server refuses to start without one\nbash scripts/serve.sh start --token $(openssl rand -hex 16) --port 7373\n# → http://localhost:7373/?token=<generated-token>"},{"language":"bash","snippet":"bash scripts/serve.sh start --token MYTOKEN --port 7373"},{"language":"bash","snippet":"curl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\""},{"language":"bash","snippet":"# Download\ncurl -O \"http://OLD_IP:7373/download/openclaw-backup_TIMESTAMP.tar.gz?token=MYTOKEN\"\n\n# Always dry-run first\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz --dry-run\n\n# Apply\nbash scripts/restore.sh openclaw-backup_TIMESTAMP.tar.gz\n# All channels reconnect automatically — no re-pairing needed"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: myclaw-backup\ndescription: \"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosystem — the AI personal assistant platform that gives every user a full server with complete code control. Use when the user wants to create a snapshot of their OpenClaw instance, schedule periodic backups, restore from a backup, migrate to a new server, download a backup file locally, upload a backup file from another machine, or protect against data loss. Includes a built-in HTTP server for browser-based download/upload/restore without needing cloud storage. TRUST BOUNDARY: This skill archives and restores highly sensitive data including bot tokens, API keys, and channel credentials. Only install if you trust the operator. Always use --dry-run before restore. Never start the HTTP server without a --token.\"\nmetadata:\n  openclaw:\n    requires:\n      bins: [\"node\", \"rsync\", \"tar\", \"python3\", \"openclaw\"]\n    trust: high\n    permissions:\n      - read: ~/.openclaw\n      - write: ~/.openclaw\n      - network: listen\n---\n\n# MyClaw Backup\n\n> **Built on [MyClaw.ai](https://myclaw.ai)** — the AI personal assistant platform that gives every user a full server with complete code control, networking, and tool access. This skill is part of the [MyClaw open skills ecosystem](https://myclaw.ai/skills).\n\nBacks up all critical OpenClaw data to a single `.tar.gz` archive and restores it to any OpenClaw instance. Includes a built-in HTTP server for browser-based backup management.\n\n## ⚠️ Trust Boundary & Security Model\n\nThis skill handles **highly sensitive data**: bot tokens, API keys, channel credentials, session history. Understand the security model before use:\n\n### What each script does\n- **backup.sh** — reads `~/.openclaw/` and writes a `chmod 600` archive to disk. No network access.\n- **restore.sh** — overwrites `~/.openclaw/` from an archive. Requires typing `yes` to confirm. Always run `--dry-run` first.\n- **serve.sh / server.js** — starts a local HTTP server. Token is **mandatory** (refuses to start without one). Shell-execution endpoints (`/backup`, `/restore`) are **localhost-only** — remote access can only download and upload files, not trigger execution.\n- **schedule.sh** — modifies your system crontab to run backup.sh on a schedule. Prints the cron entry before adding. Use `--disable` to remove.\n\n### Access control summary\n| Endpoint | Remote (token required) | Localhost only |\n|---|---|---|\n| GET /health | ✅ (no token) | — |\n| GET /backups | ✅ | — |\n| GET /download/:file | ✅ | — |\n| POST /upload | ✅ | — |\n| POST /backup | ❌ | ✅ |\n| POST /restore | ❌ | ✅ |\n\n### Best practices\n- Never start the HTTP server without `--token`\n- Never expose the HTTP server to the public internet without TLS\n- Always run `restore.sh --dry-run` before applying a restore\n- Store backup archives securely — they contain all credentials\n\n## Dependencies\n\nRequires: `node`, `rsync`, `tar`, "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7fymx2je994eh44j51che37s824w29\",\n  \"slug\": \"myclaw-backup\",\n  \"version\": \"2.0.0\",\n  \"publishedAt\": 1774681984896\n}"},{"path":"references/what-gets-saved.md","content":"# OpenClaw Backup — What Gets Saved\n\n## Backed Up ✅\n\n| Component | Path | Why |\n|---|---|---|\n| **Workspace** | `~/.openclaw/workspace/` | Agent memory, MEMORY.md, skills, USER.md, SOUL.md, all custom files |\n| **Gateway config** | `~/.openclaw/openclaw.json` | Models, channels config, **bot tokens**, **API keys**, plugins |\n| **Credentials** | `~/.openclaw/credentials/` | Channel pairing state (telegram-allowFrom, telegram-pairing, etc.) |\n| **Channel state** | `~/.openclaw/telegram/` etc. | Update offsets, session data — allows resume without re-pairing |\n| **Agent config** | `~/.openclaw/agents/main/agent/` | Model provider config (apiKey, baseUrl, custom models) |\n| **Session history** | `~/.openclaw/agents/main/sessions/` | Full conversation history (.jsonl) |\n| **Devices** | `~/.openclaw/devices/` | Paired nodes/phones (paired.json) |\n| **System skills** | `~/.openclaw/skills/` | Installed skills (find-skills, etc.) |\n| **Cron jobs** | `~/.openclaw/cron/` | Scheduled tasks |\n| **Identity** | `~/.openclaw/identity/` | Device identity files |\n| **Scripts** | `guardian.sh`, `gw-watchdog.sh`, `start-gateway.sh` | Auto-restart and guardian logic |\n\n## NOT Backed Up ❌ (by design)\n\n| Component | Reason |\n|---|---|\n| `openclaw.log` | Runtime log, not needed for restore |\n| Media files (images/audio/video) | Too large, easily regenerated |\n| `node_modules/` | Reinstall with npm |\n| `.git/` | Source control managed separately |\n| Binary assets (png/jpg/mp4/gif/webp) | Size; regenerate as needed |\n| `subagents/runs.json` | Ephemeral sub-agent run state, not needed |\n| `canvas/index.html` | Static system file, reinstalled with OpenClaw |\n\n## Security Note\n\nThe backup archive contains **bot tokens, API keys, and session credentials**.\n\n- Archive is created with `chmod 600` (owner read/write only)\n- Store backups in a secure location\n- Never commit the `.tar.gz` to a public git repo\n- Transfer via scp/sftp, not plain HTTP\n\n## Post-Restore\n\nAfter restore, all channels reconnect automatically — **no re-pairing needed**.\n\nIf Telegram is silent after 30 seconds, send `/start` to your bot to re-trigger the connection.\n\n### Restore to a New Instance\n\n```bash\n# On the NEW machine (after installing OpenClaw):\nchmod +x restore.sh\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz --dry-run   # preview first\n./restore.sh /path/to/openclaw-backup_TIMESTAMP.tar.gz             # apply\n# That's it — no re-pairing needed.\n```"},{"path":"skill-card.md","content":"## Description:\n\nMyClaw Backup helps an OpenClaw user create, schedule, download, upload, and restore backups of OpenClaw configuration, memory, skills, credentials, channel state, and workspace data.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[leoyeai](https://clawhub.ai/user/leoyeai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal OpenClaw users and developers use this skill to protect, migrate, or recover an OpenClaw instance by creating local backup archives, scheduling recurring backups, and restoring from trusted archives.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Backup archives can contain bot tokens, API keys, channel credentials, and session history.\n\nMitigation: Keep archives encrypted or otherwise strongly protected, avoid committing or sharing them, and transfer them only over protected channels.\n\nRisk: Restore and upload paths can affect sensitive OpenClaw state and should not process untrusted archives.\n\nMitigation: Run restores only from trusted archives, use dry-run before applying a restore, and treat the restore and upload web server paths as needing security fixes before remote use.\n\nRisk: The HTTP backup server can expose sensitive backup operations or tokenized URLs if reachable on an unprotected network.\n\nMitigation: Do not expose the HTTP server on a network without TLS, use a strong token, and avoid sharing tokenized URLs.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/leoyeai/skills/myclaw-backup)\n- [Publisher profile](https://clawhub.ai/user/leoyeai)\n- [MyClaw skills ecosystem](https://myclaw.ai/skills)\n- [MyClaw](https://myclaw.ai)\n- [OpenClaw Backup - What Gets Saved](references/what-gets-saved.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell commands, JSON snippets, and operational status text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May create local .tar.gz backup files, restore OpenClaw state, start a token-protected local HTTP backup manager, or modify cron scheduling when the user runs the provided scripts.]\n\n## Skill Version(s):\n\n2.0.0 (source: server release metadata; artifact _meta.json reports 1.7.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosyst... Skill: myclaw-backup Owner: leoyeai Summary: Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data. Part of the MyClaw.ai (https://myclaw.ai/skills) open skills ecosyst... Tags: backup:1.7.0, latest:2.0.0, migration:1.7.0, myclaw:1.7.0, restore:1.7.0 Version history: v2.0.0 | 2026-03-28T07:13:04.896Z | user Update ecosystem links to myclaw.ai/skills v1.7.0 | 2026-03-03T06:02:50.642Z","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1593,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:55:38.961Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:55:38.961Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:08:47.799Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}