OpenClaw iMessage Setup: Requirements and Options

Text your AI assistant from your iPhone like any other contact. iMessage is OpenClaw's most Apple-specific channel: it needs a Mac, a few macOS permissions, and a decision about "private API" mode. This guide explains every requirement and option before you start, then walks through the setup.

Quick answer

You need a Mac signed in to Messages running the imsg tool, with Full Disk Access and Automation granted to the gateway. Basic texting works as is. Tapbacks, threaded replies, polls and typing indicators need private API mode, which requires turning off System Integrity Protection.

Requirements

What you need for OpenClaw iMessage

RequiredA Mac

iMessage only runs on Apple hardware. There's no way to use it from Windows or Linux alone.

RequiredMessages signed in

The Mac must be signed in to Messages with the Apple Account OpenClaw will use.

RequiredThe imsg tool

OpenClaw talks to Messages through imsg, installed with Homebrew. BlueBubbles is no longer supported.

RequiredTwo permissions

Full Disk Access to read the Messages database, and Automation to send through Messages.

RecommendedAn always-on Mac

Replies and reminders only work while the Mac is awake. A Mac mini is ideal.

RecommendedA dedicated Mac and Apple Account

Keeps the assistant separate from your personal messages. Strongly advised if you use private API mode.

Setup helper

Which iMessage setup fits you?

Where does OpenClaw run?
Which features do you want?
Is this Mac only for OpenClaw?
Recommendation
    Start setup
    Deployment options

    Two ways to run OpenClaw with iMessage

    Simplest

    Gateway on the Mac

    OpenClaw runs on the same Mac that's signed in to Messages. Everything is local, and setup takes about 15 minutes.

    • Fewest moving parts
    • Perfect for a home Mac mini
    • The Mac must stay awake
    Advanced

    Gateway elsewhere, Mac as relay

    OpenClaw runs on a VPS or another computer and reaches imsg on your Mac over SSH, using a small wrapper script.

    • Keep your main gateway on a server
    • The Mac only handles Messages
    • Needs SSH keys set up between them
    Important choice

    Basic mode vs private API mode

    Basic mode works with Apple's normal security left on. Private API mode injects a helper into Messages for the full experience, but it means turning off System Integrity Protection (SIP).

    FeatureBasicPrivate API
    Send and receive textYesYes
    AttachmentsYesYes
    Tapbacks (♥, 👍…)NoYes
    Threaded repliesNoYes
    Message effectsNoYes
    Native pollsNoYes
    Typing indicators and read receiptsNoYes
    Group management actionsNoYes
    SIP must be offNoYes
    Turning off SIP is a real security trade-off

    SIP is a core macOS protection. With it off, malware has more room to do damage, and on Apple silicon Macs you also lose the ability to run iOS apps. The official docs recommend a dedicated Mac for private API mode, not your main computer.

    1
    Step 1

    Prepare the Mac

    1. Sign in to Messages with the Apple Account OpenClaw will use. A separate Apple Account gives your assistant its own number or email.
    2. Install OpenClaw on this Mac if the gateway will run here. See the Mac install guide.
    3. Stop it sleeping in System Settings › Energy if you want replies around the clock.
    2
    Step 2

    Install the imsg tool

    When you choose iMessage in openclaw onboard, setup can offer to install or update imsg with Homebrew for you. To do it yourself:

    Terminal
    brew install imsg

    Install it as the same macOS user that runs the OpenClaw gateway. OpenClaw starts imsg rpc itself, so there's no separate service to run.

    3
    Step 3

    Grant the macOS permissions

    Open System Settings › Privacy & Security and grant both to the app that runs the gateway: the OpenClaw app, Terminal, or your SSH process.

    Full Disk AccessLets OpenClaw read the Messages database so it can see new messages.
    AutomationLets OpenClaw control Messages to send replies.
    4
    Step 4

    Configure the iMessage channel

    Make it yours

    iMessage config builder

    Add the phone numbers (with +country code) and Apple Account emails allowed to message your assistant.

    ~/.openclaw/openclaw.json (JSON5)
    dmPolicyWhat it does
    pairing defaultNew senders get a code to approve
    allowlistOnly handles in allowFrom
    openAnyone (needs allowFrom: ["*"]). Not recommended.
    disabledNo direct messages
    5
    Step 5

    Restart, test and approve

    Terminal
    openclaw gateway restart
    openclaw channels status --probe

    From your iPhone, send a message to the Apple Account signed in on the Mac. With pairing on, approve it:

    Terminal
    openclaw pairing list imessage
    openclaw pairing approve imessage <CODE>

    If the Mac or gateway restarts, OpenClaw replays missed messages automatically, skips stale backlog from Apple's push recovery and avoids handling anything twice.

    Optional

    Enable private API mode

    Only if you want tapbacks, threaded replies, effects, polls and typing indicators, and you're using a dedicated Mac.

    1. Update imsg with Homebrew.
    2. Turn off SIP from macOS Recovery. The steps differ by Mac and macOS version, from Sierra through Tahoe.
    3. Turn off Library Validation (macOS 11 and later) with the Terminal command in the official guide.
    4. Inject the helper: run imsg launch.
    5. Verify: imsg status --json or openclaw channels status --probe.

    Follow the exact Recovery steps for your Mac in the official private API guide. The helper can stop working after Messages restarts or a macOS update. If rich actions stop, run imsg launch again.

    Advanced

    Use iMessage with a gateway on another machine

    Run OpenClaw on a VPS and let your Mac handle Messages. Set up SSH key login from the server to the Mac, then create a wrapper that runs imsg on the Mac:

    ~/bin/imsg-wrapper (on the gateway machine)
    #!/bin/bash
    ssh user@mac-host imsg "$@"
    Terminal
    chmod +x ~/bin/imsg-wrapper

    Point cliPath at the wrapper (enter its full path in the builder above). On the Mac, grant Full Disk Access and Automation to the SSH process that runs imsg.

    Groups

    OpenClaw in iMessage group chats

    • groupPolicy is allowlist by default. The other options are open and disabled.
    • Two checks apply: the sender must be in groupAllowFrom, then the group must match your groups settings. If groupAllowFrom is empty, all group messages are dropped.
    • groups uses each chat's numeric chat_id as the key, or "*" for all.
    • Per-group options include requireMention and a custom systemPrompt, for example a different personality for a family group.
    Troubleshooting

    Fix common iMessage problems

    Doesn't see new messages

    Grant Full Disk Access to the process running the gateway, then restart it.

    Can read but can't send

    Grant Automation permission for Messages. Check Messages is still signed in.

    imsg: command not found

    Install imsg as the same user as the gateway, or set cliPath to its full path.

    Tapbacks or polls stopped working

    The private API helper fell out after a restart or update. Run imsg launch again.

    Group messages ignored

    Add senders to groupAllowFrom. When it's empty, every group message is dropped.

    No replies overnight

    The Mac went to sleep. Turn off automatic sleep in Energy settings.

    More fixes: troubleshooting guide.

    FAQ

    OpenClaw iMessage questions

    Can I use OpenClaw with iMessage without a Mac?

    No. iMessage requires a Mac signed in to Messages. Your gateway can run on another machine, but it must reach imsg on a Mac over SSH.

    What does OpenClaw need to use iMessage?

    A Mac signed in to Messages, the imsg command-line tool, and Full Disk Access and Automation permissions for the process running the gateway.

    Do I have to disable SIP for OpenClaw iMessage?

    Only for private API mode, which adds tapbacks, threaded replies, effects, polls, typing indicators and read receipts. Basic texting and attachments work with SIP on.

    Is it safe to disable SIP?

    It's a real security trade-off. It weakens macOS protections and, on Apple silicon, stops iOS apps from running. Use a dedicated Mac rather than your main computer if you need private API features.

    Does OpenClaw still support BlueBubbles?

    No. BlueBubbles support was removed. OpenClaw now supports iMessage through imsg only, and old channels.bluebubbles settings should move to channels.imessage.

    Can I use iMessage with OpenClaw on a VPS?

    Yes, with a Mac as the Messages host. Create an SSH wrapper script that runs imsg on the Mac and set it as cliPath in your OpenClaw config.

    Keep reading