* feat(plugins): add experimental FaceTime realtime voice bridge Co-authored-by: Peter Steinberger <steipete@gmail.com> Co-authored-by: Dallin Romney <dallinromney@gmail.com> * test(facetime): align portable release gates * ci: refresh FaceTime PR checks * fix(facetime): retain startup suppression through hangup Begin carrier closure before startup teardown and keep native suppression pending until carrier absence is confirmed. * fix(facetime): retain cancellation until carrier safety is confirmed * fix(facetime): separate carrier closure from startup teardown * test(pr): model authoritative repository identity in sibling fixtures * fix(facetime): retain suppression without carrier proof Do not treat the capture watchdog shutdown as evidence that the native carrier terminated. Keep the call unresolved and process suppression retained until exact termination or stable absence is observed.\n\nCo-authored-by: Codex <noreply@openai.com> * fix(facetime): retain disconnected carrier proof * fix(facetime): stabilize live audio startup and routing * fix(facetime): refresh merged lockfile * refactor(facetime): separate helper result projection * fix(facetime): align published package metadata * fix(facetime): satisfy preflight lint checks * fix(facetime): preserve consult and carrier ownership * test(facetime): declare regression fixture types * test(release): align merged publisher inventory * fix(facetime): retain runtime across safe uninstall * fix(facetime): restore responsive call opening * refactor(facetime): keep greeting policy localized * fix(facetime): accept trusted stock Xcode * fix(facetime): use compiler link drivers * fix(facetime): repair portable lifecycle checks * fix(facetime): normalize installed driver permissions * fix(facetime): preserve consults during caller speech * fix(facetime): make answered-call greeting reliable * fix(facetime): honor explicit agent session owner * fix(facetime): finish voice consults promptly * fix(facetime): preserve repeated voice consults * fix(facetime): settle consult delivery before reporting success * fix(facetime): retain suppression until carrier closure is proven * docs(facetime): refresh merged plugin reference count * fix(facetime): preserve installed driver when backup fails * test(facetime): prove rejected calls cannot start media * fix(facetime): verify unknown SIP status before setup advice * test(facetime): prove caller rejection at authenticated media boundary --------- Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com> Co-authored-by: Dallin Romney <dallinromney@gmail.com>
10 KiB
| summary | read_when | title | |||
|---|---|---|---|---|---|
| Canonical supported vs unsupported SecretRef credential surface |
|
SecretRef credential surface |
This page defines the canonical SecretRef credential surface: which credential fields accept a SecretRef (env/file/exec/store-backed reference) instead of a raw secret value.
Scope:
- In scope: strictly user-supplied credentials that OpenClaw does not mint or rotate.
- Out of scope: runtime-minted or rotating credentials, OAuth refresh material, and session-like artifacts.
The lists below are generated from the source target registry and checked against docs/reference/secretref-user-supplied-credentials-matrix.json in CI; do not hand-edit entries.
Source generation fails if a present channel secret-contract artifact cannot load, rather than publishing an incomplete list. A plugin without that optional artifact contributes no channel targets. This generation check does not change runtime SecretRef owner-isolation behavior.
Supported credentials
openclaw.json targets (secrets configure + secrets apply + secrets audit)
agents
agents.entries.*.memory.search.remote.apiKeyagents.entries.*.tts.personas.*.providers.*.apiKeyagents.entries.*.tts.providers.*.apiKey
channels
channels.buzz.accounts.*.authTagchannels.buzz.accounts.*.privateKeychannels.buzz.authTagchannels.buzz.privateKeychannels.clickclack.accounts.*.tokenchannels.clickclack.tokenchannels.discord.accounts.*.pluralkit.tokenchannels.discord.accounts.*.tokenchannels.discord.accounts.*.voice.realtime.providers.*.apiKeychannels.discord.accounts.*.voice.tts.personas.*.providers.*.apiKeychannels.discord.accounts.*.voice.tts.providers.*.apiKeychannels.discord.pluralkit.tokenchannels.discord.tokenchannels.discord.voice.realtime.providers.*.apiKeychannels.discord.voice.tts.personas.*.providers.*.apiKeychannels.discord.voice.tts.providers.*.apiKeychannels.feishu.accounts.*.appSecretchannels.feishu.accounts.*.encryptKeychannels.feishu.accounts.*.verificationTokenchannels.feishu.appSecretchannels.feishu.encryptKeychannels.feishu.verificationTokenchannels.googlechat.accounts.*.serviceAccountchannels.googlechat.serviceAccountchannels.irc.accounts.*.nickserv.passwordchannels.irc.accounts.*.passwordchannels.irc.nickserv.passwordchannels.irc.passwordchannels.matrix.accessTokenchannels.matrix.accounts.*.accessTokenchannels.matrix.accounts.*.passwordchannels.matrix.passwordchannels.mattermost.accounts.*.botTokenchannels.mattermost.botTokenchannels.msteams.appPasswordchannels.nextcloud-talk.accounts.*.apiPasswordchannels.nextcloud-talk.accounts.*.botSecretchannels.nextcloud-talk.apiPasswordchannels.nextcloud-talk.botSecretchannels.nostr.privateKeychannels.qqbot.accounts.*.clientSecretchannels.qqbot.clientSecretchannels.slack.accounts.*.appTokenchannels.slack.accounts.*.botTokenchannels.slack.accounts.*.relay.authTokenchannels.slack.accounts.*.signingSecretchannels.slack.accounts.*.userTokenchannels.slack.appTokenchannels.slack.botTokenchannels.slack.relay.authTokenchannels.slack.signingSecretchannels.slack.userTokenchannels.sms.accounts.*.authTokenchannels.sms.authTokenchannels.telegram.accounts.*.botTokenchannels.telegram.accounts.*.webhookSecretchannels.telegram.botTokenchannels.telegram.webhookSecretchannels.zalo.accounts.*.botTokenchannels.zalo.accounts.*.webhookSecretchannels.zalo.botTokenchannels.zalo.webhookSecret
cron
cron.webhookToken
gateway
gateway.auth.passwordgateway.auth.tokengateway.remote.passwordgateway.remote.token
memory
memory.search.remote.apiKey
models
models.providers.*.apiKeymodels.providers.*.headers.*models.providers.*.request.auth.tokenmodels.providers.*.request.auth.valuemodels.providers.*.request.headers.*models.providers.*.request.proxy.tls.camodels.providers.*.request.proxy.tls.certmodels.providers.*.request.proxy.tls.keymodels.providers.*.request.proxy.tls.passphrasemodels.providers.*.request.tls.camodels.providers.*.request.tls.certmodels.providers.*.request.tls.keymodels.providers.*.request.tls.passphrase
plugins
plugins.entries.acpx.config.mcpServers.*.env.*plugins.entries.brave.config.webSearch.apiKeyplugins.entries.codex.config.appServer.authTokenplugins.entries.codex.config.appServer.headers.*plugins.entries.comfy.config.headers.*plugins.entries.exa.config.webSearch.apiKeyplugins.entries.facetime.config.realtime.providers.*.apiKeyplugins.entries.firecrawl.config.webFetch.apiKeyplugins.entries.firecrawl.config.webSearch.apiKeyplugins.entries.google-meet.config.realtime.providers.*.apiKeyplugins.entries.google.config.webSearch.apiKeyplugins.entries.google.config.webSearch.headers.*plugins.entries.imap.config.accounts.*.passwordplugins.entries.minimax.config.webSearch.apiKeyplugins.entries.moonshot.config.webSearch.apiKeyplugins.entries.parallel.config.webSearch.apiKeyplugins.entries.perplexity.config.webSearch.apiKeyplugins.entries.tavily.config.webSearch.apiKeyplugins.entries.team-reports.config.discord.tokenplugins.entries.team-reports.config.github.tokenplugins.entries.typesafe.config.apiKeyplugins.entries.voice-call.config.realtime.providers.*.apiKeyplugins.entries.voice-call.config.streaming.providers.*.apiKeyplugins.entries.voice-call.config.tts.providers.*.apiKeyplugins.entries.voice-call.config.twilio.authTokenplugins.entries.webhooks.config.routes.*.secretplugins.entries.xai.config.webSearch.apiKey
skills
skills.entries.*.apiKey
talk
talk.providers.*.apiKeytalk.realtime.providers.*.apiKey
tts
tts.personas.*.providers.*.apiKeytts.providers.*.apiKey
SQLite auth-profile targets (secrets configure + secrets apply + secrets audit)
profiles.*.keyRef(type: "api_key"; unsupported whenauth.profiles.<id>.mode = "oauth")profiles.*.tokenRef(type: "token"; unsupported whenauth.profiles.<id>.mode = "oauth")
Node-host connection targets
gateway.cloudflareAccess.clientIdgateway.cloudflareAccess.clientSecret
These fields live in the node host's canonical nodeHost.config SQLite
machine-state value,
not openclaw.json. They accept the same SecretInput forms and resolve through
the configured SecretRef providers when the node starts. The conventional
CF_ACCESS_CLIENT_ID / CF_ACCESS_CLIENT_SECRET fallback persists env refs for
these fields automatically. They are not targets for secrets configure or
secrets apply.
Notes:
- Store refs use names matching
^[A-Z][A-Z0-9_]{0,127}$and resolve only from the Gateway-wide team scope; no other store scope exists. A typical ref is{"source":"store","provider":"default","id":"OPENAI_API_KEY"}. - Auth-profile plan targets require
agentId; plan entries targetprofiles.*.key/profiles.*.tokenand write sibling refs (keyRef/tokenRef). Auth-profile refs are included in runtime resolution and audit coverage. - In
openclaw.json, SecretRefs must use structured objects such as{"source":"env","provider":"default","id":"DISCORD_BOT_TOKEN"}. Legacysecretref-env:<ENV_VAR>marker strings are rejected on SecretRef credential paths; runopenclaw doctor --fixto migrate valid markers. - OAuth policy guard:
auth.profiles.<id>.mode = "oauth"cannot be combined with SecretRef inputs for that profile. Startup/reload and auth-profile resolution fail fast when this policy is violated. - For SecretRef-managed model providers, generated
agents/*/agent/models.jsonentries persist non-secret markers (not resolved secret values) forapiKey/header surfaces. Marker persistence is source-authoritative: OpenClaw writes markers from the active source config snapshot (pre-resolution), not from resolved runtime secret values. - Cold Gateway startup can isolate retryable resolution failures for mapped, non-Gateway owners. Current mapped classes include model providers and skills, media/TTS/cron providers, eligible auth profiles, per-agent memory, sandbox SSH, channel accounts, and manifest-declared plugin routes. Startup keeps each failed owner's explicit refs in the runtime snapshot, reports the owner through status and doctor, and rejects requests for that owner without trying lower-precedence credentials. Reload and config-write preflight use the same owner-aware policy: healthy owners refresh; an eligible failed owner stays stale only when its ref identities, provider definitions, and complete non-secret owner contract are unchanged; a new or changed failure becomes cold. Gateway ingress auth, structurally invalid refs or values, fail-closed owners, and currently unmapped owners remain strict.
- For web search: in explicit provider mode (
tools.web.search.providerset), only the selected provider key is active. In auto mode (tools.web.search.providerunset), only the first provider key that resolves by precedence is active, and non-selected provider refs are treated as inactive until selected. Provider credentials useplugins.entries.<plugin>.config.webSearch.*. - Slack
identity: "user"useschannels.slack.userTokenwithchannels.slack.appTokenfor Socket Mode orchannels.slack.signingSecretfor HTTP mode. The same pairing applies underchannels.slack.accounts.*; no bot token is required for this identity.
Unsupported credentials
These credentials are minted, rotated, session-bearing, or OAuth-durable classes that do not fit read-only external SecretRef resolution:
hooks.tokenhooks.gmail.pushTokenhooks.mappings[].sessionKeyauth-profiles.oauth.*channels.discord.accounts.*.threadBindings.webhookTokenchannels.discord.threadBindings.webhookTokenchannels.whatsapp.accounts.*.creds.jsonchannels.whatsapp.creds.json