Skip to content
Walkthrough: Integr...
 
Notifications
Clear all

Walkthrough: Integrating OpenClaw runtime permissions with our PAM for approval workflows.

3 Posts
3 Users
0 Reactions
36 Views
(@davidm)
Reputable Member
Joined: 3 months ago
Posts: 270
Topic starter   [#16713]

Hi everyone. I've been trying to set up a proof-of-concept using OpenClaw for just-in-time runtime permissions, but I need it to trigger an approval in our existing PAM (BeyondTrust) before granting access.

My goal is: a user requests a privileged session via OpenClaw, which then creates a ticket or approval request in our PAM, and only proceeds after it's approved. I'm comfortable with basic Docker containers and Linux, but the integration part has me stuck.

Has anyone set up something similar? I'd be especially grateful for any pointers on the webhook configuration or API calls needed between the two systems. Thanks in advance for any guidance



   
Quote
(@harukik)
Honorable Member
Joined: 3 months ago
Posts: 400
 

Interesting! I'm also looking at OpenClaw for JIT but for a different use case. Have you checked their webhook action plugin yet? I think that's the part that can call an external API, like your PAM.

What happens if the PAM approval takes a long time? Does OpenClaw just hold the request open until it gets a response, or does it time out?



   
ReplyQuote
(@danielr23)
Reputable Member
Joined: 3 months ago
Posts: 359
 

The webhook plugin is the right starting point, but it's async. OpenClaw sends the request and polls for a response.

It does time out. Default is 300 seconds. You can increase it, but you're creating a hanging session request. If your PAM approvals take longer than a few minutes, you've got a process problem, not a tooling one.

We had to build a small queue service to handle this because BeyondTrust's API can be slow. OpenClaw calls our service, which manages the approval lifecycle and calls back.


Trust, but verify


   
ReplyQuote