# How to Configure OpenClaw Windows Node: Step-by-Step Setup for Molty

> Configure your OpenClaw Windows Node with our step-by-step guide. Set up gateway connections, adjust Windows capabilities, and manage Node MCP modes easily.

- Repository: [openclaw/openclaw-windows-node](https://github.com/openclaw/openclaw-windows-node)
- Tags: how-to-guide
- Published: 2026-06-06

---

**You configure OpenClaw Windows Node by running the onboarding wizard to establish a gateway connection, adjusting Windows capabilities, and toggling between Node and MCP modes via the tray application or programmatically through the `GatewayConnectionManager` API.**

OpenClaw Windows Node (codenamed Molty) is a lightweight tray application that connects Windows systems to OpenClaw gateways via WebSocket. This guide explains how to configure openclaw-windows-node using both the graphical interface and the underlying C# API, referencing the actual implementation in the `openclaw/openclaw-windows-node` repository.

## Configuration Architecture Overview

The configuration system resides in three distinct layers. **OpenClaw.Shared** handles low-level transport and device identity, **OpenClaw.Connection** manages connection lifecycle and credential precedence, and **OpenClaw.Tray.WinUI** provides the interface and onboarding wizard.

Persistent storage uses JSON files in `%APPDATA%\OpenClawTray\`. The [`GatewayRegistry.cs`](https://github.com/openclaw/openclaw-windows-node/blob/main/GatewayRegistry.cs) class maintains gateway records in [`gateways.json`](https://github.com/openclaw/openclaw-windows-node/blob/main/gateways.json), while per-gateway identity keys reside in [`device-key-ed25519.json`](https://github.com/openclaw/openclaw-windows-node/blob/main/device-key-ed25519.json) files. The [`GatewayConnectionManager.cs`](https://github.com/openclaw/openclaw-windows-node/blob/main/GatewayConnectionManager.cs) implements the public API that coordinates credential resolution following strict precedence: **device token** → **shared token** → **bootstrap token**.

## Initial Configuration via the Onboarding Wizard

### Installing the Companion

Download the installer from the OpenClaw release page and run it. The installation does not require administrator rights and places the application in the user’s local app data directory.

### First-Launch Setup

When the application launches without an existing gateway configuration, the **Onboarding Wizard** appears automatically. This wizard performs three critical functions:

- Installs an app-owned WSL gateway named `OpenClawGateway` that listens on `ws://localhost:18789`
- Guides you through selecting Windows capabilities (notifications, camera, microphone, screen capture, and optional location)
- Opens `ms-settings:` pages to grant the necessary OS permissions

The wizard stores its state in [`settings.json`](https://github.com/openclaw/openclaw-windows-node/blob/main/settings.json) and reads from [`ONBOARDING_WIZARD.md`](https://github.com/openclaw/openclaw-windows-node/blob/main/ONBOARDING_WIZARD.md) documentation to determine the V2 flow steps.

## Gateway Connection Setup

After the wizard completes, you can connect to gateways through two methods.

**Local WSL Gateway:** The default configuration uses the wizard-created WSL instance. This requires no additional tokens and provides immediate connectivity on the local machine.

**Remote Gateway:** Navigate to the **Connections** tab in the tray UI to add a remote gateway. You may enter a direct URL, supply a shared token, or scan a QR-encoded setup code. The UI delegates to [`SetupCodeDecoder.cs`](https://github.com/openclaw/openclaw-windows-node/blob/main/SetupCodeDecoder.cs) to parse the code, which `GatewayConnectionManager.ApplySetupCodeAsync` then validates and registers.

## Windows Capabilities and Permissions

The Permissions page within the wizard checks five specific Windows capabilities. You must grant access to:

- Notifications
- Camera
- Microphone
- Screen capture
- Location (optional)

The tray application opens the corresponding Windows Settings (`ms-settings:` URIs) to streamline permission grants. These capabilities determine which remote operators can interact with your device.

## Node Mode vs MCP Mode Configuration

OpenClaw Windows Node supports four operational configurations controlled by two boolean settings: `EnableNodeMode` and `EnableMcpServer`.

| `EnableNodeMode` | `EnableMcpServer` | Result |
|------------------|-------------------|--------|
| `false` | `false` | Operator-only tray |
| `false` | `true` | Local MCP only |
| `true` | `false` | Gateway node only |
| `true` | `true` | Both node and MCP |

Access these toggles in the Settings panel. Enabling MCP-only mode bypasses the SSH tunnel manager because no gateway URL is required. Enabling Node mode requires an active gateway connection from the registry.

## Advanced Programmatic Configuration

Developers can embed configuration logic directly using the `IGatewayConnectionManager` API from the `OpenClaw.Connection` project.

### Switching to a Specific Gateway

```csharp
using OpenClaw.Connection;

// Trigger tunnel restart and reconnect operator client
await manager.SwitchGatewayAsync("my-gateway-id");  // ID from gateways.json

```

### Applying a QR Setup Code Programmatically

```csharp
var setupCode = "eyJ1cmwiOiJ3czovL2xvY2Fsc2VydmVyOjE4Nzg5IiwiYm9v..."; 
await manager.ApplySetupCodeAsync(setupCode);

```

This method validates the code, creates or updates the `GatewayRecord`, clears stale device tokens, and initiates a fresh connection—mirroring the UI wizard behavior exactly.

### Enabling MCP-Only Mode via Code

```csharp
var snapshot = manager.CurrentSnapshot;
snapshot.Settings.EnableMcpServer = true;
snapshot.Settings.EnableNodeMode = false;
await manager.ReconnectAsync();

```

The `SshTunnelManager` automatically disables itself when `EnableNodeMode` is false and no gateway is configured.

### Checking Connection State

```csharp
var state = manager.CurrentSnapshot.OverallState; 
Console.WriteLine($"Connection status: {state}");

```

The `OverallState` combines operator and node sub-states (e.g., `Ready`, `Connecting`, `Error`) as defined in the connection architecture documentation.

## Configuration File Reference

| File Path | Purpose |
|-----------|---------|
| `%APPDATA%\OpenClawTray\gateways.json` | Persistent gateway registry managed by [`GatewayRegistry.cs`](https://github.com/openclaw/openclaw-windows-node/blob/main/GatewayRegistry.cs) |
| `%APPDATA%\OpenClawTray\settings.json` | Application settings including mode toggles and legacy token migration |
| `%APPDATA%\OpenClawTray\device-key-ed25519.json` | Per-gateway Ed25519 device identity keys |

Deleting [`settings.json`](https://github.com/openclaw/openclaw-windows-node/blob/main/settings.json) forces a fresh onboarding on next launch. The system performs one-time migration of legacy `Token` and `BootstrapToken` fields into the new registry format automatically.

## Summary

- Install the Molty tray application without admin rights and launch the onboarding wizard.
- Connect to either a local WSL gateway (`ws://localhost:18789`) or a remote gateway using URLs, tokens, or QR codes via `ApplySetupCodeAsync`.
- Grant Windows capabilities (camera, microphone, screen capture) through the permissions UI before enabling remote access.
- Toggle between **Node Mode** and **MCP Mode** in Settings, or programmatically via `manager.CurrentSnapshot.Settings`.
- Configuration persists to `%APPDATA%\OpenClawTray\` and can be reset by deleting [`settings.json`](https://github.com/openclaw/openclaw-windows-node/blob/main/settings.json).

## Frequently Asked Questions

### Do I need administrator rights to install OpenClaw Windows Node?

No. The installer runs in user-space and writes all configuration files to `%APPDATA%\OpenClawTray\`. You only need standard user permissions to install, configure, and run the application.

### Where are gateway credentials stored?

Gateway records reside in `%APPDATA%\OpenClawTray\gateways.json`, maintained by [`GatewayRegistry.cs`](https://github.com/openclaw/openclaw-windows-node/blob/main/GatewayRegistry.cs). Ed25519 device keys are stored in separate [`device-key-ed25519.json`](https://github.com/openclaw/openclaw-windows-node/blob/main/device-key-ed25519.json) files per gateway. The system follows a credential precedence of device token, then shared token, then bootstrap token when authenticating.

### How do I reset the configuration to defaults?

Close the application and delete `%APPDATA%\OpenClawTray\settings.json`. When you relaunch the tray app, the onboarding wizard will trigger automatically because the system detects no usable gateway configuration. You can also delete [`gateways.json`](https://github.com/openclaw/openclaw-windows-node/blob/main/gateways.json) to remove all saved gateway records.

### Can I run the Windows Node without a gateway connection?

Yes. Set `EnableNodeMode` to `false` and `EnableMcpServer` to `true` either in the Settings UI or programmatically via the `IGatewayConnectionManager` API. This MCP-only mode starts the local MCP server without establishing a WebSocket connection to any gateway, bypassing the `SshTunnelManager` entirely.