Tailscale explains how to run AI agents like OpenClaw more safely using two approaches: routing LLM API calls through Aperture (their AI gateway) to prevent API key leakage and gain cost/usage visibility, and using Tailscale Serve instead of Funnel to keep the agent private to your tailnet. Aperture removes the need to store
Table of contents
Preventing key leaksSeeing tool calls and setting cost quotas: an experimentConnecting to danger (please don’t Funnel your OpenClaw)The first catch out of the cageSort: