Skip to main content

v2026.9.2

OpenClaw v2026.9.2 pairs support for OpenAI’s GPT-6 Astra and Meta’s Muse Spark 1.3 with practical reliability improvements. Update reports survive reconnects, eligible interrupted tasks resume after a restart, and completed answers remain available through specific saving failures. Both model additions support text and images for accounts with access. On supported OpenAI API connections, you can correct ongoing work without waiting for Astra to finish its response. The task workspace also lets you put a dashboard, browser, terminal, or file view at the center of a task and keep the conversation beside it. Guided local-model setup chooses a recipe for the computer running OpenClaw and checks that it can use tools, while people sharing a Gateway can connect their own model accounts without changing everyone else’s default. More settings apply without a full restart, keeping unaffected conversations connected.
Upgrade note for shared Gateways: If you run several agents on one Gateway, review their conversation access before upgrading. Omitted settings now let agents with session tools read and search other agents’ conversations, including other users’ transcripts. Explicitly narrow visibility and agent-pair access where needed; mutually untrusted users need separate Gateways. See Security and Privacy for the settings and their limits.
Release scale: 1,245 PRs + 6 direct commits + 232 contributors.

Installation and Onboarding

Setting up a local model now starts with the computer that will run it, and OpenClaw checks that the model can use a tool before making it your default. The rest of setup gets several practical repairs too, from preserving complete workspace instructions after a failed write to choosing the intended agent, opening a hosted dashboard, and recovering shell completion when a profile cannot be changed.
The managed llama.cpp setup now recommends a model using the available memory, supported graphics hardware, and disk space on the computer running OpenClaw. It shows you that computer’s name, the model, and the download size before asking to proceed, which matters when you are opening setup in a browser connected to a different machine. Before changing your default, it checks both a response and a real file-read tool result; a failed or cancelled activation leaves the previous model selected.The local-model recommendations begin with an 8 GiB memory floor for the smallest recipe, with larger choices needing more memory and, in some cases, graphics acceleration. Actual fit and speed still depend on available resources and the workload. CPU-only replies can still take several minutes, and setup now distinguishes a response-check timeout from a tool-use-check timeout with the failed check named in the error.Managed setup also applies lean tools for local models before checking the candidate, reducing the large tool list a smaller model has to process while keeping the agent’s ordinary instructions in normal chats. An explicit opt-out is preserved. On a Gateway with several agents, setting up just one local agent can still change shared lean-tool settings used by other agents, so review those settings after targeted setup.
New workspace instruction and identity files are now made available only after a complete write, so a disk or quota failure during first setup can be resolved and retried without leaving a newly truncated file behind. Existing files are preserved, including readable startup files in an already initialized workspace whose host permissions prevent new writes. Previously truncated files still need repair, and creating missing files requires write access and a filesystem that supports hard links; setup explains when that requirement cannot be met.For multi-agent installations, automatic command review and openclaw setup --baseline now use the configured System Agent’s model, workspace, and session location. When no owner can be determined, baseline setup stops with guidance to configure the System Agent instead of suggesting an unsupported command flag.Before local configuration changes, OpenClaw also checks the installed Gateway’s recorded data and configuration paths, even when the service is stopped. A confirmed mismatch stops the wizard before it writes to the wrong location. If those paths cannot be verified, configuration remains available with a warning and a pointer to openclaw gateway status --deep.
Clean, environment-only agent runs using an OpenAI API key can now start through the built-in OpenClaw runtime when the optional Codex runtime is absent. This removes a setup failure before the agent could answer or begin its task, while explicitly chosen runtimes and existing session pins continue to require their selected runtime.
When Doctor or onboarding cannot update your shell profile, completion setup now provides a command that loads the prepared completions in your current shell instead of sending you back into the same permission failure. Run the complete command it displays; enabling completion for future shells still requires fixing the reported permission or read-only error and retrying installation. PowerShell recovery commands also handle paths containing typographic apostrophes.

The New Web UI

The browser workspace can now take the shape of the work you are doing. Put a dashboard, browser, terminal, or file view in the main area and keep the conversation beside it, then return to that arrangement when you come back. A visual gallery makes saved dashboards easier to find, while mentions, profiles, clearer progress, and more usable conversation history help you stay with the task as it grows or brings in other people.
You can now put the part of a task you are working on in the main view and keep the conversation beside it. Dashboard, Browser, Terminal, Files, Review, and Chat share the same controls, so a dashboard can take the larger space while Chat sits on the left, right, or below it. Swap exchanges the two views, Focus gives the main view the task area, and Restore split brings back the previous arrangement and size.The task layout remembers your choices in that browser, and rearranging or hiding panels preserves live widget inputs, chat drafts, terminals, and Review state. Incoming widgets respect an arrangement you have already saved, while compact Home opens with its conversation and composer visible. Closing a Dashboard view leaves its saved board intact, but reloading the page starts fresh widget views.
When the bundled Control UI skill is available to your agent, type /dashboard with what you want to see to request a board for the current session. Choosing Dashboard in the side panel opens the board directly without adding anything to your message. The dashboard guide includes a one-prompt demonstration, and the command uses the bundled Control UI instructions even when a workspace has another skill with that name. A custom skill named dashboard remains available through $dashboard or /skill dashboard, with its slash alias moved to /dashboard_2.Widgets pinned from an agent’s global session stay with that agent’s board and notify its authorized viewers. Automatically sized HTML widgets keep their content height instead of progressively shrinking, while manual sizes remain yours to set. If creating a visible dashboard session fails, cleanup preserves a newer replacement session and tells you when the original child needs inspection before retrying.
Interactive chat widgets now load their saved document through the authenticated OpenClaw connection, which lets supported widgets work behind login proxies without asking the embedded frame to sign in separately. A failed document load offers Retry, and an HTML download remains available when an image export cannot be produced.Canvas and MCP App previews keep the information that makes them interactive and appear once when live conversation content becomes saved history. Already loaded widgets retain their input during supported panel changes and renewed preview links. Strict previews remain script-free, dashboard permissions stay separate from inline previews, and a full reload creates a fresh view.
When a message needs someone’s attention, type @, choose an eligible teammate, and check the Will notify indication before sending. Simply typing a name does not alert anyone. Human mentions work with durable OpenClaw profiles and bring the message into the recipient’s Inbox without giving them access to a conversation they could not already read.The Mentions Inbox is temporary. Entries last up to seven days, can be removed sooner by capacity limits, and clear when OpenClaw restarts or upgrades. Opening a mention leaves it in the list until you dismiss it. Optional Someone mentions me browser alerts default off and are best effort. The Inbox also keeps automation and model sign-in warnings current through busy periods, and an automation alert’s arrow opens Automations.
A single-owner installation using token or password access can now have a saved name, avatar, profile preferences, and My GitHub connection without setting up a separate sign-in service. These follow the owner profile across its devices. On a Mac, an owner without an uploaded image can use the picture of the Mac account running OpenClaw, while paired browsers and supported Mac SSH connections can display saved profile photos again.For teams, assignment menus include registered people even when they are offline or have not owned a conversation, and grouped session headers bring presence and people cards closer to their work. Participant lists reveal additional names, and person Activity links use readable addresses. Shared token or password holders still share one owner identity, its preferences, and My GitHub connection, so use personal sign-in when each person needs a distinct profile.
Searching Sessions can now find matching active or archived conversations beyond the rows already loaded, with Load more sessions bringing in further matches. It searches conversation details such as names, models, status, and agent identity, while transcript search remains a separate way to search the messages themselves. Counts, grouping, and sorting still describe the loaded rows.Owner choices move into a compact submenu, sharing and owner details sit together in the chat header, and copied session links use the configured public address even through a local SSH tunnel. Unrelated agent activity no longer repeatedly reloads the selected agent’s list, and pinning or renaming another session can continue while a model catalog loads. Opening a chat clears its unread dot immediately, although new activity arriving during the acknowledgement refresh can still briefly be masked.
Opening a long conversation now puts the recent messages you selected ahead of background chats and a restored Home pane, with smaller initial transfers and reusable avatar previews. Valid prefetched history stays available through unrelated sidebar updates, and completed messages avoid repeated redraws while a new reply streams. Older messages remain available by scrolling upward.Large Codex histories use bounded pages and shortened tool-output previews, with full output retained in Codex. Very large individual records and some legacy histories can still exceed the transport limits. On the computer running OpenClaw, cold runtime history checks let unrelated activity continue, and browsing retained archives leaves less message content in memory between requests, at the cost of reading those pages from disk again.
A rejected send can keep its original attachments and Retry action when you leave the conversation, move Home, or reload through a supported recovery path. Recovered documents regain their Open and Download controls, and permitted plain-HTTP installations can use attachment sending and recovery with browser storage available. Recovery keeps the request’s identity so an uncertain send is not automatically repeated.Interrupted personal-account setup can resume with its original session and worktree, while failed cloud starts retain their error and elapsed time when you return. Covered app-triggered reloads protect unsaved starts while the page is responsive and offer an explicit discard action when needed. Incognito starts remain memory-only, and closing the page or choosing to discard unsaved input can still lose them.
Successfully generated images remain visible when a later tool fails, and saved media replies keep one caption after reload. Project screenshots now follow the conversation’s filesystem permissions, so a screenshot the session is allowed to use can also appear in chat. For a blocked image outside those folders, an administrator can inspect its path and choose Allow image for that file alone, with an expiring allowance and current access checks.Media requests reaching the updated server return current file contents, and conditional download resumes for mutable files restart with the current version instead of combining old and new bytes. Attachment lookup does less work in long histories, and verified Tailscale Serve users regain affected previews. An Omitted from history card explains a missing historical image without implying its bytes were recovered, and an old browser cache may still require reopening a fresh media URL.
Tool activity keeps related calls together after reload and shows a short purpose supplied by the acting agent when one is available, with full commands and results underneath. There are no extra model calls just to name those rows, and the description tells you the intended work while the result tells you whether it succeeded. If your configuration contains the retired gateway.controlUi.toolTitles key, remove it even when its value is false. openclaw doctor --fix handles supported configurations, while managed or included configuration files may need changes at their source.The task list keeps active work in creation order and recent completions first, with Refresh and recovery guidance when activity changes during loading. Older checklists stay paused during unrelated work, finished parent conversations stop looking busy while their children continue, and Swarm cards retain completed counts and readable task names. Activity also batches background refreshes, while heavily changing task lists can still require another refresh.
Choosing a command argument now submits the completed command from New Session, and the execution-host picker inserts valid settings while preserving the rest of a chat draft. Sending a message, submitting a chat command, or choosing Scroll to latest brings the newest output into view through composer resizing, while later manual scrolling and keys inside text or media controls remain under your control.Stop remains available for a known running response during reconnection and requests cancellation when the same authorized connection returns. Queued messages can resume when refreshed session state confirms the chat is idle, and accepted messages can stay pending through a temporary history rebuild before execution begins. Work that may already have started is not blindly sent again, and queued messages show a single usable Steer action when steering is available.
The model control can now tell you which fallback model is actually serving the conversation while the open picker keeps your preferred model selected. When the session returns to that preference, the old fallback label clears. Known model names stay visible while switching chats and loading their options, including in locked chats, without enabling controls before their availability is known.Sign-in warnings are easier to distinguish from ordinary model details, provider headings offer a shortcut to Model Setup, and a provider with a usable profile can show Ready despite a failed sibling profile. Session Observer’s model choices also recover after temporary catalog failures and ignore obsolete responses after agent switching. These labels describe the available catalog and session state, rather than verifying a provider credential or identifying a billing account.
The Devices page puts recognizable computers and phones, available resource readings, capabilities, and access details in one inventory. Connected CLI nodes and the Mac shared worker report load, memory, and home-volume disk snapshots, and a successfully saved last reading remains available with its age when a node goes offline. The CLI can show those summaries too. Load averages and used memory describe those measurements, rather than operating-system pressure, and offline values are historical.An Actions menu keeps copying IDs, pairing controls, and available desktops together, while an available Desktop opens in its own window. New Session and Move Session distinguish commands that are missing, waiting for pairing approval, or blocked by policy, so the next step matches the problem. The device guidance covers setup and reapproval, and Connection and System busyness show eligible mounted local disks separately.
GitHub previews keep the exact issue, pull request, or comment destination you opened, even when another link has already filled the preview cache. They use the selected agent’s configured account and explain sign-in, access, rate-limit, or connection failures, while remaining limited to public repositories. PR badges collect later pages of checks before reporting complete results, so a failure beyond the first page does not disappear behind a passing badge. Results beyond the collection limits can leave the badge absent.The Review panel keeps unchanged files out of a session’s changes and reports full addition counts for large new text files even when their previews must stay bounded. GitHub publication controls also retain a retry and its original account across chat navigation and same-chat split panes. That state is held in page memory and clears on reload or relevant connection and access changes. A rejected first account choice can be refreshed before an explicit new Publish, while an uncertain outcome keeps checking the original request.
Side chat has a visible keyboard shortcut, Command-Shift-S on Apple platforms and Ctrl-Shift-S elsewhere, so you can open or close the existing panel without reaching for its tab. Cancelling while conversation context is still loading now retires that request before it can later start a model call or replace a newer answer. The same preparation work is covered by the existing 60-second timeout.
The browser workspace downloads more code and text when the relevant view needs it, and reloads can reuse versioned themes, fonts, icons, and artwork already in the browser cache. Models and Plugins avoid competing initial loads, keeping useful controls visible while supplemental information arrives. Cloudflare Rocket Loader deployments also get the script protection needed for the affected blank-page startup failure.During reconnection, dashboard conversations remain readable, and local panel arrangement controls stay available while server actions wait for the connection. Phones can reach the Server updated recovery action and retry a failed refresh without losing the selected chat. New connections also avoid waiting behind their own presence notification. Operators rebuilding bundled UI assets in place still need to restart OpenClaw to pick up their new identity.
Settings keep long descriptions beside their artwork and place controls deliberately on narrow screens, while notification preference cards align with the rest of the page. Picker selections are easier to see and affected menus respect reduced-motion preferences. Config exposes the selected Form or Raw mode and current section to assistive technology, and obsolete MCP save feedback clears when the settings context changes without cancelling the earlier write.Hebrew and Arabic text with leading direction marks displays in the intended direction, and punctuation remains visible while typing in native fields under CRT and Phosphor themes in Chromium. The first accent swatch shows the inherited color it restores. It is still a reset action, so clicking it can clear a matching explicitly saved profile color and make future color changes follow the inherited setting.
When a saved microphone cannot be opened for a browser Talk call, the error can offer Use System default for this call. You decide whether to retry with that microphone, and your saved choice remains in place for later calls. Permission failures stay visible, and leaving or replacing the call retires the offer so an old button cannot open another microphone.Closing the microphone picker or leaving Appearance also prevents delayed device discovery from requesting camera or microphone access after you have moved on. Deliberately returning to an active picker still allows the normal permission request.
Debug shows when a snapshot is refreshing or waiting for a connection while leaving the last successful readings available. Disabled work lanes with nothing running or queued no longer appear as misleading blocked rows, and Logs keeps its initial load through routine updates without an old connection unexpectedly moving the view.Usage now keeps selected-day totals within the active session filters, while daily charts and daily exports retain those matching sessions across the requested date range. Provider, model, and tool filters select matching whole sessions, so their totals can include other usage within those sessions, and the costs remain estimates rather than provider billing records.
The workspace sidebar makes the existing Discord community easier to find with a dismissible invitation that waits until sidebar interaction finishes before appearing. Joining opens the community in another tab, while closing the card saves a dismissal for that browser origin. If saving fails, the card can still stay dismissed for the current page with a warning.Operators can hide the invitation for the deployment with openclaw config set gateway.controlUi.communityInvite false on the computer serving that UI. Existing pages pick up the change on refresh or reconnect, and re-enabling it keeps saved browser dismissals.
Existing linked Workboard cards continue to appear and update with their conversations. When a task-list continuation expires, Workboard can restart its scan once and use the fresh result to update cards and link started runs. Chat headers and session menus no longer offer Add to Workboard, and this change does not introduce a replacement capture workflow or remove existing cards.
When several people are viewing a terminal, one failed viewer connection no longer holds up output for the healthy viewers that remain. OpenClaw retires that failed delivery once, which also stops the same connection from producing an error for every queued update. This addresses the shared-output stall after a connection fails, without changing terminal permissions or explaining the original disconnect.
A valid diagram should not send you back to rewriting its source because the renderer could not load. Mermaid errors now distinguish unavailable rendering, invalid diagram source, and an image that could not display, with the appropriate reload or correction guidance and the source still readable and copyable.For login-protected reverse proxies, the Mermaid troubleshooting guide explains which static renderer assets need to load without the page’s cookies. Keep authentication on the dashboard and API routes, make only the required asset exception, and reload after correcting it.
Twenty existing non-English locales have updated text for the web workspace’s dashboard controls, mentions and Inbox, connected accounts, device settings, task names, and recovery messages. That includes translated Allow image controls, Mermaid failure guidance, unsaved-start warnings, and update and publication status, so the explanations surrounding these workflows keep up with their controls. Chinese and Japanese text also receives sentence-punctuation corrections.
New Session makes the choice between Current checkout and New worktree explicit, with the starting branch and worktree name in the Checkout control. Device and cloud sessions continue to require a managed worktree, and local sessions can choose Current checkout when a worktree choice is unavailable. Recent Windows folders use readable short names, and the sidebar’s familiar controls and nested-session loading placeholders keep their spacing through supported layouts.The composer no longer shows the naming notice or prepared-name preview below the draft, but background naming still runs. Eligible unsent draft text can go to the selected utility provider before you press Start, as the session naming guide explains. Removing that preview does not change the transmission, and Start does not wait for a name.

Updates and Maintenance

Update reports now stay available after a restart, and more settings can change while your Claw keeps working. The maintenance work also preserves working preferences during upgrades, keeps eligible interrupted tasks able to continue, and makes backups, conversation cleanup, and repair diagnostics more useful when an installation needs attention.
An update now leaves a report you can return to after the connection drops and OpenClaw comes back. The update dialog follows the saved attempt, Settings → Updates reopens its latest report, and the CLI and chat use the same recorded steps, outcome, and verification results. Successful updates keep that detail too, so you do not have to reconstruct what happened from a disappearing notification. The update history guide covers openclaw update status and administrator history queries.Configured owners can ask for an update in chat or use /update, with guidance when their account lacks owner access. Chat updates require commands.ownerAllowFrom and the existing commands.restart permission, and reports for existing web conversations can be saved directly into the conversation without an extra model turn. Managed services may miss intermediate notices, and a usable delivery route is still needed for an external chat notice.A saved report describes what OpenClaw recorded. Missing verification stays unverified, and an interrupted CLI update can still leave a running record that locks update and configuration controls. An idle Gateway may also miss a separately started CLI update until it restarts, so a running label alone is not proof that the updater is alive.
Package updates preserve the files another updater is actively preparing and the shared plugin dependencies another installation still needs. Once the replacement Gateway has passed the existing readiness and version checks, the updater keeps that healthy process running instead of interrupting it with a second restart. Supported upgrades from the published v2026.8.2 package also retain the code needed by the older updater to finish replacement and bring its previously active managed service back.Source installations address a different part of the same journey. The repaired updater keeps the code it needs available while generated files are replaced, letting it finish configuration processing and restart the Gateway after a rebuild. Ordinary CLI commands also skip a needless rebuild when only unchanged files’ timestamps differ. An updater already running older code cannot acquire those fixes midway through its own replacement, so the transition installing the repair may still need operator recovery.On Linux without a service manager, the updater can proceed when the selected Gateway is idle and service inspection permits it, explaining why restart was skipped. When upgrading that setup from the published v2026.8.2 CLI, confirm no Gateway is running and use the one-time openclaw update --no-restart path. The update reference explains the service checks and manual restart steps.
Automatic updates now keep enabled skill preferences when a prerequisite happens to be missing from the update environment, and fully repairable older multi-agent configurations retain current choices such as the update channel, port, and original default agent. A failed agent-settings save also keeps the previous complete file readable. Enabled skills still need their prerequisites before they can run, and an explicit standalone Doctor repair can still disable unavailable skills.Remove messages.suppressToolErrors, even if its value is false, or run openclaw doctor --fix to migrate it. The retired setting no longer suppresses the final warning when a tool fails and the run has delivered no reply. Channel settings continue to control mid-turn progress.If an intended owner has lost access to restart or update commands because their saved identity uses an older channel:user:id form, run the same explicit Doctor repair to migrate recognized, unambiguous entries. Upgrading alone does not rewrite those owner entries, and ambiguous identities or default-agent choices still need manual correction.
You can change more of how your Claw works without restarting the whole Gateway. With the default hybrid configuration reload, routine changes to tools, approvals, messaging, speech, browser defaults, retention, and update policy reach the next relevant operation while unaffected conversations stay connected. Logging changes reach already-running channels and plugins, dashboard serving can be switched on or off, and a loaded OpenTelemetry exporter can be replaced on its own when its settings change.Access changes apply at the place they matter. Pending automatic pairing approvals recheck current policy, revoked device commands are cancelled, and rotating a token or password within the same authentication mode reconnects affected shared-credential clients while independently paired clients stay connected. Existing sign-in failures and earned lockouts survive rate-limit changes. Changing the shell affects new terminals, while disabling terminals closes existing sessions and re-enabling allows fresh ones.Changes that replace a channel, browser, or exporter can briefly interrupt that service, and failed service replacement can require Gateway recovery. Working hooks survive a replacement that fails to load, and active channels restore their incoming routes after plugin replacement. Refresh open browser pages for changed interface preferences or terminal policy. Listener and process settings, authentication-mode changes, and dashboard asset roots or base paths still require a full restart.
A Full Access task interrupted by a Gateway restart can inspect its saved conversation and use fresh, currently authorized shell commands or delegated work to continue the original request without asking you to send it again. The restart recovery guide explains how inherited Full Access and explicit session choices apply, while work restricted for safe replay or uncertain delivery keeps its narrower permissions.Queued follow-up replies also retain their original Gateway association after the initiating request ends, and one reply finishing during shutdown no longer removes another unfinished reply’s recovery record. These repairs preserve eligibility to continue work and deliver its result. Interrupted calls and expired process or approval handles are not replayed automatically, and a failed recovery-record write or an uncertain external delivery can still need attention.
Stopping the Gateway now keeps tracked requests, commands, and required cleanup together until they settle, so a finished response does not release services that its remaining work still needs. If required cleanup fails, the process reports an unsuccessful stop instead of starting a replacement inside a runtime that has not finished closing. Commands that time out during startup can return promptly while shutdown continues to track their cleanup separately.Several specific waits are addressed along the way. Committed restarts retire obsolete follow-up retries, suspended Gateways cancel background work that has not started, and bursts of file logs drain in batches. Already-running startup preparation and plugin cleanup are still joined, which can add time to a stop. A stop requested from within Gateway chat reports that it has been scheduled and lets the requesting operation settle, with final termination remaining the responsibility of the serving process or its service manager.
Deployment controllers that pause new work before maintenance can now explicitly hand an unfinished wait over to restart recovery. An administrator arms gateway.suspend.handoff for the exact suspended process, then the controller sends SIGTERM and owns launching the replacement. This gives managed deployments a supported way to interrupt eligible conversation work after their maintenance waiting period, without having two owners trying to restart the same Gateway.The external-app integration guide covers the handoff’s expiry and refusal rules. Arming it alone does not stop the process, and pending final conversation writes can refuse the handoff. Terminal commands and scrollback end with the old process and are not recovered.
Backups now handle managed configuration and credential links such as those used by NixOS and Home Manager, retaining portable links to the content included in the backup. Slow snapshots involving older audit logs can complete without holding the migration lock for the whole copy, and malformed archive headers are rejected before restoration creates its destination.Git backups also preserve text after an embedded NUL character, which could previously truncate a value or collapse distinct record keys. This includes affected iMessage recovery records in global backups. Recreate affected older Git backups from intact source data after updating, even if the old backup passed verification. Updating cannot recover bytes already missing from a backup.
Reaching the active-session limit now archives eligible ordinary conversations so you can search for them and restore them later, while previously archived conversations stop counting against that limit. The interface explains why a conversation was archived, and cleanup previews distinguish archival from removal. Cap-created archives can still be permanently deleted later under disk pressure, and other retention policies continue to apply.Large conversation stores also do less maintenance work on the thread serving interactive Gateway requests. Eligible transcript reclamation and physical disk accounting run in workers, excluded sessions avoid unnecessary metadata reads, and large archive backlogs can progress without overflowing SQLite’s parameter limit. Scan scheduling and old-history inspection use less temporary memory in their affected paths, keeping the same retention decisions and disk totals.
Doctor gives repair instructions for the installation you are actually inspecting. A failed remote connection points you back to that host, its credentials, and its tunnel or network connection, while a source-install dashboard repair command includes the detected checkout path so it can be copied from another directory. Service advice distinguishes installing a missing service, starting an installed one, and explicitly replacing its definition, and explains when Nix, an external supervisor, or the invoking shell prevents installation.Full read-only lint finds expired credentials in the original agent and shared stores and reports their usable paths. Legacy Discord, Matrix, Codex, and Teams checks skip unrelated startup work when it is not needed. Invalid plugin settings now produce a configuration error instead of making the command appear missing, with core shell completion still available while you repair the settings and regenerate plugin completion. Use doctor --lint or bare doctor --json for read-only diagnosis, since ordinary Doctor can migrate state.
Managed Windows Gateways stay alive through startup and can be stopped while startup is still pending, avoiding the case where a command reported a stop and the Gateway appeared afterward. Linux service maintenance correctly reads valid comments and continued lines, preserving runnable service definitions, recovery backups, and operator overrides.Startup also refreshes migrated plugin policy before checking readiness and avoids repeated database scans during migration decisions. Large valid agent configurations with repeated plugin-owned model choices no longer hit the repaired startup bottleneck. These changes let the affected installations reach their normal readiness checks, while genuine configuration changes or failed database checks still prevent startup.
Database compatibility checks used by updates, Doctor, and Gateway maintenance now inspect private copies while preserving the original database files and surrounding SQLite files, including committed changes waiting in a write-ahead log. These checks need temporary space and copying time, and can refuse to finish when a safe copy cannot be prepared.When inspection or verification fails, diagnostics retain useful Node and SQLite error codes. A stable malformed file can report that it is not a database instead of incorrectly appearing to change throughout inspection, and database cleanup releases its original maintenance lock even if the surrounding storage environment has changed. A generic disk I/O error still needs investigation before attributing it to a full disk.
Operators investigating slow requests can now separate the wait before a Gateway handler starts, the handler’s elapsed time, and the first response through the existing diagnostics exporters. The Gateway RPC metrics cover authenticated WebSocket requests, and normal logs also show slow reply-preparation stages separately from waiting for a model or tool. Health observations retain pauses that repeated reads could previously hide, so a later healthy check does not erase the earlier observation from enabled monitoring.During shutdown, count-only reports show remaining tracked work and the transition into server cleanup. The existing OPENCLAW_GATEWAY_RESTART_TRACE=1 option adds entered-phase markers to help locate a wait before that phase finishes. Routine successful continuations move to debug logs, and an unchanged stale-worker assignment stops producing the same disk-space warning every minute.These measurements show observed elapsed phases and completed monitoring windows. They do not identify the responsible function by themselves, and a response accepted for sending is not proof the client received it. Check dropped-observation counters before treating monitoring as complete. If a script calls openclaw logs, omit unset --limit, --max-bytes, and --interval options instead of passing empty values, which now produce an error.
On the computer running OpenClaw, an interactive openclaw triage --run can attempt an installation repair using configured models and their permitted fallbacks. Doctor lint runs before and after the attempt, skips inference when it finds no errors initially, and keeps the result unsuccessful if errors remain afterward. The attempt is limited to one turn, ten minutes overall, five minutes for the turn, and 40 tool calls.Explicit --run permits host commands without further approval prompts during that repair. Filesystem tools enforce the installation or candidate-root boundary, but shell commands follow the repair prompt and have no OS sandbox. Explicit tool denies remain in force, and unsupported execution routes produce guidance for an external handoff. The installation triage guide explains these limits and the checked result.

Messaging

Discord meetings can now leave behind notes you can return to, and Slack conversations give you more useful ways to stop work, follow a reply, or make a decision. The changes also carry through the everyday parts of messaging, from keeping the instructions attached to one message to preserving code, recordings, and generated files as they move through a conversation.
In supported Slack agent sessions, the native Stop button now reaches the work running in the selected conversation, including overlapping replies in group DMs, while session status shows when the agent is working or waiting for an approval. Rename a supported session in Slack and OpenClaw keeps that name through later messages, with delayed controls checked against the conversation they belong to.Existing apps need the two session-event subscriptions described in the Slack setup guide, and native session status requires a reply thread. A completed first reply can still lose its title association after cleanup or restart, and overlapping replies can still interfere with the shared working indicator. Progress cards also keep earlier errors as recovered history after a successful turn, so a finished task does not keep looking failed.
In Slack compact progress mode, the final answer arrives as a new message after any conversation or media that appeared while the agent worked. Temporary progress is removed after Slack confirms delivery, and a failed send leaves the preview available.Slack writes also distinguish an explicit rate-limit rejection from a lost response. A supported rate-limit response can retry up to twice after Slack’s requested wait, including ordinary messages and upload completion. If the outcome is uncertain, OpenClaw reports the failure and avoids automatically repeating text Slack may already have received. That tradeoff means an unaccepted reply can remain missing when its outcome cannot be established.
When a Slack reply would be easier to use as a table or a few choices, the agent now has guidance to offer that format without requiring you to ask for Block Kit. A status request can become an organized report, or a decision can arrive with buttons that let you choose and continue the conversation. This uses the existing Slack renderer and supported controls, with plain text for simple replies and a text fallback for richer ones; the format the agent chooses still depends on the model and request.
You can configure a listen-only bot to take Discord meeting notes when people enter a voice room, then return to the overview, decisions, action items, and speaker-labeled transcript from the Meetings page. Agents can also read permitted saved meetings, so the conversation can continue from what was discussed without you having to paste the notes into a new chat.Occupancy capture is opt-in and needs Discord voice and speech-to-text setup. Tell participants that transcripts will be captured and stored before enabling it, and configure at most one room per account and guild. The bot waits 30 seconds after everyone leaves, and a meeting can reopen with its existing transcript within 10 minutes, including after a restart. Continuous capture remains the default for existing setups and now retains its capture identity through temporary startup failures.People with operator read access share access to meetings across the Gateway, regardless of the selected agent; use separate Gateways when readers need isolation. Model summaries can fall back to heuristic notes, and very long meetings can omit middle sections from the model’s summary input, so use the transcript when a particular detail matters.
In a shared Discord voice room, a delayed request keeps the identity and permissions of the person who spoke it, while spoken answers queue in order instead of replacing one another. One speaker’s failed connection can recover when they speak again without disconnecting everyone else, and OpenAI agent-proxy early wake acknowledgments require the name at the start of the utterance instead of matching an unfinished ordinary word.OpenAI and xAI voice replies also handle interruptions against the answer currently playing when another answer is queued, and later replies can continue after cancellation. The follow-up playback repair keeps a partial audio frame from ending the conversation during a provider pause. Direct voice-model history remains separate for each speaker while agent consultations share the room conversation; a room retains at most eight speaker connections, subject to the provider’s own limits.
Long Discord replies keep their code, Unicode characters, and surrounding quote or list context when they need several messages, and attachment captions avoid extra empty code blocks. Sends and edits also preserve intentional indentation and trailing newlines, while an explicitly empty edit can clear an attachment caption without removing the attachment. Extremely small configured message limits can still constrain formatting, and the existing access checks continue to apply.
With Telegram rich messages enabled, collapsible details keep their headings, code, quotes, tables, and nested sections together through sends and edits. Unsupported markup remains readable as literal text, so examples do not silently lose their wrappers.Telegram progress mode also keeps Claude CLI commentary in one temporary message, shows when context compaction completes or remains incomplete, and gives the final answer priority over pending commentary. Commentary remains temporary even with verbose mode enabled. For installations that depend on a proxy, explicitly configured trusted SOCKS5 routes now carry Bot API requests and incoming attachments through the intended transport, including supported cases where the media destination cannot be resolved locally; the proxy itself must still be locally resolvable and reachable.
You can adjust how long OpenClaw waits to combine a burst of messages without reconnecting Discord, Feishu, iMessage, Mattermost, Microsoft Teams, Signal, Slack, Telegram, or WhatsApp. New work uses the saved delay, while a setting change alone leaves an already pending batch on its existing schedule. Acknowledgement-reaction scope also applies to new turns without reconnecting the supported channels, and work already in progress keeps the policy it started with.Known webhook addresses now ask the sender to retry while a channel or plugin is being replaced. This depends on the sender honoring the retry response; the message has not been accepted or stored at that point. Multi-account IRC setups can also add or edit a non-default named account without disconnecting its siblings, while shared settings, default-account changes, and removals can still restart the channel.
Put a supported text directive before a task and OpenClaw keeps the task, including its formatting, while applying the requested controls. Thinking, verbosity, and authorized tracing can stay with that one message through queueing and model changes, then later messages return to their inherited preferences. A standalone directive still saves a default, and model selection remains persistent. Telegram’s separate handling of multiline commands can still discard later lines before they reach this shared parser.Native verbose menus in Telegram, Slack, and Discord show the current level and let you choose on, off, or full without changing anything merely by opening the menu. Malformed explicit text commands such as /exec gateway now return an argument error instead of becoming an unintended message to the agent. For scripts changing channel accounts, a blank --account is rejected before a change begins; omit the option when you intend the command’s normal default selection.
When Claude Code needs an answer before continuing, its native question can now reach the channel conversation instead of appearing only in the web dashboard. Replying in plain text to that same conversation can answer the waiting question and resume the run, including in installations with several agents. This repairs the existing question workflow, with Telegram directly demonstrated; messages containing media do not use this early plain-text answer path.
Progress mode can stay quiet about routine tool calls while keeping the updates that help you follow the task or need your attention. On the supported Discord, Telegram, Slack, Matrix, Mattermost, and Teams personal-chat presentations, configured commentary, reasoning, and approval or failure notices remain available, and streaming.progress.toolProgress lets you opt into the tool log. Slack compact progress keeps its own presentation and omits plans.Narrated progress also catches up with activity that arrived while an update was being written, including urgent failures after a draft was hidden. When work finishes, a delayed typing or reaction start is followed by cleanup once that request settles, preventing it from bringing back an obsolete working indicator.
A final answer already delivered to the same external conversation can now suppress the extra automatic reply or same-conversation agent announcement, even when another layer rewrites the tool’s visible output. This depends on confirmed final delivery to that destination; a progress update, a dry run, or a message to another conversation does not count as the answer.Conversation resets also preserve the distinction between a status confirmation and an ordinary answer, and resetting an existing but empty conversation no longer creates the malformed history that could block the next reply. Upgraded conversations with an older pending reset wait for an active reply to finish, while a late Stop during finalization leaves an already accepted answer completed. These fixes prevent the affected new failures; they do not reconstruct previously lost or malformed history.
When an agent has already generated images or other files, a later tool error or reasoning-only response no longer decides which of those attachments survive. The media guide explains how generated files remain available alongside the warning, even when the warning mentions only one of them.New M4A and audio WebM uploads stay in the audio workflow, staged recordings can use their original URL to recover the file type, and portrait video frames use display orientation when that information is available. Allowed local macro-enabled Excel workbooks can also be sent as attachments, preserving extension capitalization when staging uses the original extension. This handles the workbook as a file; it does not run or certify its macros, and audio transcription still needs its own setup.Cancelling an attachment-bearing reply now reaches preparation and the outgoing adapters, with Gateway cancellation waiting for abandoned upload cleanup. Cancellation cannot undo a send that has already begun, and the preparation repair does not add a deadline to an unattended transfer that hangs without being cancelled.
Nextcloud Talk recognizes structured help and status commands, including authorized group commands without a bot mention, and an accepted message can recover through the existing queue after a temporary conversation lookup failure. Mattermost recognizes mention-prefixed commands when text commands are enabled and lets them bypass chat batching; later reactions, button clicks, and username checks can also retry a failed lookup instead of inheriting a cached outage. The already failed Mattermost event is not replayed automatically.Tlon summary requests refresh their history after an account restarts, and long IRC replies retain literal code and link destinations across messages. WhatsApp now delivers the final failure explanation instead of discarding it with intermediate error noise. For a confirmed iMessage helper stall, OpenClaw attempts bounded recovery for later actions, which can relaunch Messages.app and delay the original error by up to 30 seconds; the failed action is still reported and is never automatically resent.Direct Matrix encryption setup and encrypted account addition finish their client setup before publishing the enabled settings to a running Gateway. Concurrent account changes prompt a review and rerun instead of being overwritten, although verification can still fail and the encryption choice may still be saved. This change covers those direct commands, with the interactive wizard and separately running encryption processes outside its scope.

Memory

Memory needs to stay useful as conversations grow, daily notes become longer-term knowledge, and you change the way your Claw stores and searches them. This release repairs several places where that continuity could break, from daily memories missing later evidence to recalled context disappearing when a session rotated, while reducing repeated search and indexing work and giving you a clearer view of what is taking up disk space.
Memories first recorded by the daily Dreaming pass can now collect evidence from later recalls and grounded observations, so they can qualify for long-term storage under the existing promotion rules. The original source stays attached, and reinforcement from combined memory and Wiki searches now counts only the memory results actually shown to the model. During consolidation, the model chooses what to add, merge, or supersede, while OpenClaw builds the saved entries from their source evidence and preserves unrelated memories.Active Memory also keeps eligible recalled context and unavailable-memory warnings through session rotation. A completed, grounded recall can still reach the reply when its cleanup crosses the deadline, without turning on transcript exports; failed recalls, failed cleanup, and unavailable results remain excluded from that recovery. Dreaming and Skill Workshop now share visible background capacity in System busyness, with foreground work keeping its own capacity.
Memory searches that return only notes, or no results at all, now skip processing unrelated conversation history. First searches also avoid decoding unrelated saved prompts and reopening an already verified agent database, while indexing large memory files prepares their source text once instead of repeating the same work for each piece. These changes address specific sources of delay as your saved history grows, with the selected search corpus, annotations, and transcript access checks preserved.Preparing memory tools no longer starts the embedding provider before a search is requested, and changing settings after a failed search lets the tool retry with the new configuration immediately. Targeted refreshes read fewer unrelated session records, while an exact lookup for a missing message in an imported CLI conversation now returns empty history instead of substituting recent messages that do not answer the request.
If you use an alternative memory plugin and keep Memory Core enabled for Dreaming, indexing now stays with the plugin you selected. Memory Core can continue contributing Dreaming support without starting unwanted embedding work or lending its private-conversation recall permission to the other plugin. This prevents that unselected component from starting new work; embedding batches already submitted to a provider still need separate handling.Affected plugins that keep their memory managers immutable can now report status, search, read, and finish cleanup normally, so the Memory page can show the actual provider instead of a misleading attention warning. Dreaming schedules also follow frequency changes, disabling, and re-enabling after a plugin reload, without requiring a full restart.
Once your Memory Wiki vault is active, opening an existing visible page by its exact Markdown path reads that page without scanning unrelated pages, so a broken file elsewhere no longer has to block the page you asked for. Local source sync can also reuse an existing compiled Wiki after startup. Fresh CLI processes still validate the saved snapshot, and lookups by a short name, page ID, or missing path can still need a vault scan.Saving a Wiki claim now rejects confidence values outside the supported 0–1 range before changing the page, preventing those new values from distorting later search results. Existing pages remain readable, including older invalid values that this change does not repair.
When a memory database grows, explicit memory status checks now show its file size, transaction log, reusable space, and retained embedding cache, including cache entries left after caching was disabled. Those measurements overlap, so they should not be added together as separate pieces of disk usage. The disk-space recovery guide explains how to use the existing offline compaction command with a verified backup and stopped writers, preserving sessions and allowing you to skip an index reset when you only need to reclaim unused pages.Forgetting a session also protects unrelated saved memory when a staged file rewrite fails, allowing you to fix the storage problem and retry. Doctor imports large legacy memory logs in batches and recognizes configured secret-store credentials without telling you to replace working keys, while file-watcher warnings now point to supported recovery steps for the affected agent.
When OpenClaw shortens a long conversation, tool results discarded while repairing mismatched calls and replies now remain available to the summarizer. The removed-message count and token estimate include them too, closing a specific gap where useful tool output could disappear from both the summary input and its accounting. Ordering after repeated pruning still has a known limitation.

Skills

Skills get practical repairs from creation through installation and remote use. Workshop explains more failed reviews and protects current edits during uncertain restores, while paired and remote workers use the instructions and supporting files prepared for their own turn. Bundled guidance also gives agents a clearer path through dashboard building and delegated work without changing the permissions those tasks require.
Skill Workshop now identifies conflicting support-file locations before saving a proposal, and refuses proposals or evaluations that would silently omit unreadable or excessively nested content. When agents sharing a workspace cannot start a collection review because a provider credential is missing, the error names the affected provider and agent so the operator can fix authentication without guessing at model settings.Restoring an older collection backup also protects later edits and deliberate deletions when the relevant files cannot be verified. Some older backups need manual recovery; keep complete private copies of both the backup and current files while choosing what to restore, and do not change saved hashes or flatten live files to force an automatic restore.
Skills running on paired and remote workers now refer to the instructions, scripts, and resources copied to that worker, including when a skill is selected explicitly. An active turn keeps its prepared instructions, and later edits on the Gateway apply to later turns. Connected nodes also publish a skill’s name, description, and instructions from the same file read, avoiding a mismatch when that file changes during discovery.If an optional discovered skill folder disappears, a worker conversation can continue with the resources that remain available. Explicitly selected or pinned skills, unreadable nested resources, and integrity failures still stop the affected turn. Copied skill files remain temporary inputs, so background commands must not depend on them surviving after the turn ends.A failure to delete disposable skill files no longer changes a successful worker result into a failure or hides the original cancellation or timeout. Cleanup warnings identify files that may remain; wait for the worker or session and its processes to stop before removing them manually. Credential cleanup remains separate and strict. Cloud startup also reports whether a download failed during connection, TLS, the HTTP response, or body transfer, helping operators investigate the relevant part of setup.
The Skills interface now selects the installation recipe advertised for your operating system when a skill leaves recipe IDs implicit. That corrects cases where the button showed one platform’s dependency but selected another platform’s recipe.ClawHub installation also stops with repair or restore guidance when its shared tracking file is damaged, preserving the file and existing skills instead of replacing their update and integrity records. Normal installation and updates can resume after valid tracking is restored. Large archive uploads and library browsing also avoid unnecessary copies of archive content or skill payloads, while keeping their existing results, selected revisions, and permissions.
A bundled Control UI skill now guides agents through building a dashboard in the intended conversation, preserving existing widgets, and checking what actually renders. Follow-up guidance explains supported ways to load external data and troubleshoot blank remote widgets without changing the widget sandbox or automatically configuring hosting.Updated delegation guidance carries the requested outcome through child completion messages, so agents are instructed to continue authorized work after an intermediate review or check and verify the final result. For a request to land a pull request, that includes checking that GitHub reports it as merged. The instructions still allow a specific blocker when the remaining work needs new authority, credentials, or an external decision.Skill authors also get clearer ClawHub publishing guidance, including which personal and organization roles can publish and where the canonical commands live. Code Mode guidance corrects an outdated restriction on completing pending tool calls; these instruction changes do not introduce new runtime permissions or a new publication capability.

Native Apps

Experimental Talk on Watch lets you start a voice conversation directly from your wrist, with the iPhone used for setup rather than relaying the call. The companion messaging path gets its own recovery screen, while iPhone and Android conversations become easier to read, copy, and follow through longer tasks. On Mac, personal browser sign-in brings your own account into shared Gateways, and clearer approval panels make it easier to see what you are allowing. Linux companion work addresses specific AppImage startup failures.
Talk on Watch is a new experimental way to speak with your Claw without the paired iPhone carrying the audio or relaying each message. Enable Standalone Voice under iPhone Settings → Apple Watch, then open Talk on Watch and tap Start. You can choose an agent, read the recent transcript, mute the microphone, and end the call from the Watch; simply opening the screen does not start recording, and each call has its own conversation.Setup requires an administrator connection on the iPhone, a trusted secure Gateway address the Watch can reach independently, and a compatible realtime provider using ICE-lite and UDP. The Watch receives its own limited read and Talk credentials, while permanent provider credentials stay on the Gateway. There is no TURN relay or TCP/WebSocket audio fallback, so a network that blocks the required UDP connection cannot use this path. Talk configuration explains the supported combinations.Keep OpenClaw on screen until the call connects. Network recovery is bounded, and an OpenAI call needs a fresh start when its 30-minute lease expires. Physical Watch microphone and speaker behavior, wrist-down operation, radio handoff, and long-call endurance still need device validation, so treat this as an experimental capability.
The existing iPhone-relayed Watch chat now saves pending messages and completed replies on both devices, allowing a restart or reconnect to recover work without automatically repeating a send whose outcome is uncertain. Queued messages retain their original conversation even if you switch chats on the phone, and a saved reply can still be read after the spoken-reply wait has ended.Update both apps, then use iPhone Settings → Apple Watch → Message Delivery to inspect replies or a Delivery uncertain warning. Check the original conversation before resending uncertain work. Older unsent messages that lack enough delivery information appear as Needs review, and the original 48-hour deadline still applies to new deliveries and their saved replies.
Compatible audio-only clients can now use native GPT-Live with their configured ChatGPT OAuth or Platform credentials while the Gateway handles tools and tasks for the call. The client must explicitly support the Gateway-controlled mode; OpenAI GA Realtime still requires a Platform key for this mode. Status requests, cancellation, redirects, and follow-ups stay with the work started by that call, and saved conversation history is kept separate from what was actually said in the new call.When an answer to a pending question loses its confirmation, OpenClaw reports the uncertainty instead of sending the answer again as another instruction. Check the conversation before retrying. Questions from standalone attached MCP sessions need the Control UI or native question controls, and protected Copilot steering remains unavailable. Talk mode covers these client and authentication boundaries, along with the separate handling of call audio and accepted tasks.
On eligible Android audio setups, Talk can keep listening while it speaks, so an interruption stops queued speech even after the provider has finished generating the reply. This requires active native echo cancellation and Android communication audio; other setups keep taking turns between listening and playback. Thinking, Listening, and Speaking now follow the current response and playback more closely, and new successful spoken answers appear once in Chat while errors and interrupted partial replies stay visible.The native speech loop also sends recognized phrases and resumes listening after the answer, keeps capture running when reply audio is muted, and respects Stop or a switch to push-to-talk. Around that conversation, Disconnect stays disconnected, failed settings loads are shown as errors rather than empty data, and unresolved sends remain visible for recovery. Android guidance explains the native Talk path, while Talk mode covers the audio requirements.
iPhone conversations keep the current reply and working indicator visible as the assistant moves through tool calls, with streaming tables growing without repeatedly shifting earlier text. Opening the keyboard preserves the latest messages when you were already following them, while a deliberate scroll or selected search result keeps your chosen position. Scrolling near the left edge also takes a more clearly horizontal gesture before it opens the sidebar.When you want to reuse part of a reply, Select Text opens an iOS selection sheet so you can copy a passage without taking the whole message. Code blocks gain a raw-code copy button on both iOS and Mac, tall Mermaid previews keep their first and last nodes reachable, and native Swarm progress responds to settings changes without reconnecting or bringing back an older enabled state.
Android task progress now sits in its own attached panel above the message composer, expanding upward while the editor and its controls stay in place. Progress cards show labeled bars alongside their text and links, and the Effort and Permissions sheets keep their choices reachable on smaller screens. Policy default and Default model have distinct labels, so checking permissions is less easily confused with resetting a model choice.Jump to latest lives in the chat header and appears only when newer content is hidden, leaving more room beneath the messages. Opening Dashboard from a conversation now selects that conversation’s board and gives the embedded page a full-size viewport, so it can be read and used after it loads.
Android Stop, Forget, and reconnect now finish against the connection you selected, preventing pending secondary connections or old credential writes from reviving a connection you retired. Changing focus also preserves a handshake that is already underway. Disconnect shows Offline while retaining pairing; forgetting a Gateway removes its local saved connection, but does not revoke pairing on the remote Gateway.In the active iOS app, other enabled Gateways can stay connected while you use the focused one, including through temporary discovery gaps. With Background App Refresh enabled, the iPhone can also request opportunities to update its last-seen status and attempt a reconnect without a push relay. iOS controls that background schedule, and may suspend connections when the app is no longer active.
The Devices page can show memory readings from connected iPhones and iPads, plus memory and available storage from Android phones, when the Gateway supports device resource reporting. The apps send a reading on connection and refresh it while connected, giving you a way to check phone resources from the same place as your other devices.These phone readings include processor count rather than CPU load. iOS omits disk usage, Android storage appears only when it can be sampled, and suspension or a lost connection can pause fresh readings.
The Mac app keeps remote address text in place while you finish typing, and connection failures retain the explanation needed to act on them. An incompatible protocol tells you whether to update the computer running OpenClaw or the Mac app, while conflicting saved device identities show their file paths and IDs. Those conflicts still need deliberate repair; changing a Gateway token is suggested only for a token problem.When you use several Gateways, chat commands, widgets, approvals, settings, and status stay with the window or connection that owns them. Primary dashboards follow a changed Primary, independent saved-profile windows keep their own connection, and older replies cannot replace the selected Gateway’s current settings. Switching Primary clears the old configuration draft, while reconnecting to the same Gateway preserves valid edits. A save already sent can still reach the previous Gateway, so changing selection does not undo an in-flight change.The Tailscale Dashboard link opens the root or configured custom path, heartbeat details follow the active Gateway, and a remembered Usage page stays open during dashboard startup. The Mac remote connection guide covers the connection choices and troubleshooting path.
If your Gateway uses Cloudflare Access, you can enter its address in the Mac app and sign in through your usual browser, then return to its dashboard under your own account without copying a shared token. The website’s Get the apps → Open in Mac app action opens the same connection editor with the address filled in, and the app remembers the selected Gateway after restart.Renewing the same account preserves its browser preferences, chat history, and queued messages. Signing in as someone else closes the previous account’s native chat windows and uses separate history and queues, leaving earlier pending messages with their original account. Removing the saved Gateway clears its credentials and dashboard browser data.This browser handoff currently supports Cloudflare Access, and native device approval remains a separate step unless the Gateway’s existing automatic approval policy allows it. Personal saved Gateways also stay separate from the machine Primary that supplies Mac capabilities and Talk. Eligible Team dashboards can use personal identity for attribution, while shared-token and password connections keep their existing owner flow.
Mac command approvals now put the command and working directory in a resizable panel, with wrapping, scrolling, selectable paths, and Copy for the exact displayed command. Details keeps executable information available without crowding the decision, and remote requests no longer say they will run on the Mac merely because that is where the prompt appeared.Pairing requests identify the device and its requested access, show administrator warnings, and distinguish a capability update from replacing a device token. You can inspect full IDs and versions in Details or use Copy ID. Command-Return approves the displayed request once, while Return alone does not; Not Now or Escape on pairing requests leaves them pending. Always Allow Here remains available only when the command policy permits it.
Dashboard Settings gains a This Mac group for app behavior, device capabilities, permissions, and local Talk and update controls when a supporting Mac app exposes the native bridge. These controls remain owned by the Mac and appear only where that bridge supports them. Voice Wake trigger words belong to the connected Gateway, so their editor also works in an ordinary browser when the Gateway advertises the required methods.Mac AI setup now shows confirmed connection-test rejection reasons and lets you explicitly retry or choose another connection without an old response wiping newer input. Uncertain outcomes keep their verification step, and older Gateways may still require the existing wait. Other daily controls receive focused repairs too, with scheduled-job lists retaining recent edits and deletions, and the browser sidebar resizing and remembering its width even with only one or two tabs.
The Mac app stops checking Tailscale while Connection settings are hidden, retires timers when requests finish, and stops presence sampling after opting out once the required clear succeeds. Its node worker also stays under the app’s process control, so restarting or stopping that worker does not leave it running behind the app.The animated menu-bar icon keeps its existing motion with less CPU work in the measured idle scenarios. This is a focused reduction in background activity and animation cost; battery-life gains and the cleanup of separately detached provider processes are outside these changes.
You can choose Original, Heritage, Clawmark, Origami, Pincer, or Open C in Settings → General → Dock icon, with light and dark previews side by side and the selection saved for each OpenClaw profile. Custom designs change the Dock icon while the app is running; Finder and the Dock after quitting continue to use Original. On macOS 26 and later, Original follows the system’s Icon & widget style setting.
The Linux AppImage packaging now avoids optional media dependencies and bundled Wayland libraries that caused the demonstrated startup failures and blank windows on affected systems. Supported media playback stays bundled, while the graphics connection uses compatible host libraries. Quick Chat also explains when a Gateway needs a missing token or password and directs you to its recovery path without discarding the paired device token.Check the Linux requirements before choosing a system for the companion. The AMD64 AppImage requires glibc 2.35 and GLIBCXX_3.4.30, which standard RHEL 9 and Rocky Linux 9 do not provide; extracting an AppImage bypasses FUSE requirements, not that library floor. The fixes address the reproduced startup failures, with graphics compatibility still depending on the host GPU and compositor.
The existing native-app languages receive updated labels and guidance across phones, watches, and Mac, including chat selection and code-copy actions, model controls, Dock icon choices, and Gateway error titles. Apple translations also cover standalone Watch voice setup and microphone permission, plus Mac browser sign-in and reconnect guidance, so the instructions surrounding those features are available in the supported language catalogs.

Models and Providers

OpenClaw v2026.9.2 adds support for OpenAI’s GPT-6 Astra and Meta’s Muse Spark 1.3 alongside fixes that help conversations continue and active work finish. On its supported API-key path, Astra also lets you send live corrections and keep receiving output while direct tools run. Codex can retain its thread after supported compaction interruptions, long CLI-backed replies avoid being stopped while still producing output, and temporary provider failures get more appropriate recovery and retry guidance. People sharing a Gateway can also choose their own model account for each chat.
OpenClaw v2026.9.2 adds support for OpenAI’s GPT-6 Astra, so accounts with access can choose it for conversations using text and images. You can select openai/gpt-6-astra with an OpenAI API-key profile or an eligible ChatGPT/Codex subscription. Subscription model discovery confirms account access before offering Astra; an unavailable catalog can temporarily leave it out of the picker.On the official OpenAI endpoint with an API key and the built-in OpenClaw runtime, Astra can continue reasoning and responding while direct tools run. A cached WebSocket also lets you send a correction into the active response, including text or images, without waiting for it to finish first. Accepted instructions remain attached to the conversation through continuation and reconnect. SSE keeps ordinary queued delivery, and these built-in-runtime capabilities are separate from native Codex execution.You can change the thinking level before the next turn while retaining a compatible cached prompt prefix. Automatic compaction, automatic truncation, pro mode, and API multi-agent mode do not support that optimization, and a restart or rewritten history starts a fresh request. Finish pending tool results or approvals in a compatible Astra mode before switching. Where runtime capabilities permit it, /think ultra also enables proactive delegation to sub-agents, using max effort in OpenClaw and xhigh in native Codex.Astra’s full context window is 1,050,000 tokens, with up to 128,000 output tokens, while OpenClaw keeps its default active input budget at 272,000. Choosing Off does not disable Astra’s reasoning, and the cost estimate preserves its higher long-context pricing tier.
OpenClaw now supports Meta’s Muse Spark 1.3, with Standard and Contributor choices for accounts that have access. Both accept text and image input and expose reasoning controls, a 1,048,576-token context window, and up to 131,072 output tokens. Select meta/muse-spark-1.3 for Standard or meta/muse-spark-1.3-contributor for Contributor.Fresh Meta setups now choose Standard 1.3, while existing primary-model selections and older catalog choices remain available. Contributor has separate access and data-use terms, so check the provider guide before choosing that version.
People sharing a Gateway can now connect their own supported model accounts in Settings → Profile → Connected accounts, choose a default for new chats, and use Account for this chat to make a separate choice for an existing conversation. Changing the default leaves existing chats alone, and collaborators and forks keep the account already selected for that chat. Model availability, status labels, fallback checks, and retry estimates now follow that personal selection.Personal accounts support Anthropic API keys, OpenAI API keys or browser/device sign-in, and Grok/xAI API keys or device sign-in where those methods are enabled. The Gateway must identify each person first, including for CLI setup; a shared password or device pairing alone does not identify a distinct teammate. Collaborators see a personal-account label without its private email or account details. Shared same-provider fallback can still apply, so selection is not a billing guarantee or isolation from administrators. Claude CLI keeps its required account restriction.Administrators and integrations also gain a Gateway API for inspecting provider accounts and saving or clearing their priority order. Configuration-controlled order remains authoritative, and a successful save can precede the background refresh that applies it.
Model pickers keep the names, reasoning information, and configured choices they already know through more refresh and configuration-reload cases. Native Codex models retain their account-scoped availability, repeated browsing can reuse discovered inventory when a provider is unavailable, and Hugging Face’s bundled models remain selectable before a key is added. A listed model still needs valid credentials, compatible runtime support, and account access before it can answer.Hosted catalog updates can now import eligible tool-capable text models from models.dev for providers that opt in, so adding each supported model no longer needs a separate OpenClaw change. New listings appear after a refreshed catalog has been published and downloaded and the Gateway has restarted. Provider policies and configured allowlists continue to apply.
The local-server guide now uses llmman, the maintained replacement for Inferrs, with corrected startup commands, readiness checks, and troubleshooting for requests that work directly but fail during a larger agent task. Existing Inferrs documentation links redirect to the new guide. Keep its unauthenticated service on loopback or behind trusted access controls.Managed llama.cpp also resolves a selected Hugging Face GGUF file without scanning unrelated files in a large repository, while self-hosted discovery keeps its time budget stable when the computer’s clock changes. These fixes preserve the existing model-address and integrity requirements.
Codex conversations keep the model and account selected for their native thread when you continue them, including imported conversations whose model differs from the agent’s default. Fork from here retains the draft and source thread’s current model on Codex 0.153 or newer, and an empty native tool catalog no longer makes a supervised conversation look corrupt. Separate Ask OpenClaw conversations also keep separate Codex threads.If compaction is interrupted after OpenClaw saves a new session, supported continuation paths can recover its recorded predecessor and keep the existing native thread. That includes ordinary messages, side questions, and same-thread resume, with outdated queued compaction and control commands prevented from changing the successor session. A confirmed deletion of an ordinary managed Codex thread instead creates a fresh native thread in the same OpenClaw session; it cannot restore the deleted native history.Ordinary post-tool summaries stay on the completed work’s prepared model and account. Supervised tool-only runs that cannot safely produce a summary retain their completed work and explain that no final summary was produced, without repeating those actions.
Continuing a long Codex conversation now uses a bounded history renderer that keeps the needed context without first building a much larger temporary string. Resuming large saved records also spends less CPU scanning them, and prompt annotation or confirmed steering avoids rebuilding search information when the searchable content has not changed. These changes reduce specific preparation costs; large-record decoding and parsing can still take time.When browsing native Codex or Claude sessions on connected computers, slow hosts can now add their results after the initial partial list arrives, subject to the viewer’s current access. Internal voice consultations also stop producing false prompt-mirroring warnings when their hidden input was already saved.
Managed Codex now uses version 0.153.4 and resolves the installation owned by its plugin across supported installation layouts, including Windows launchers in paths with spaces. A missing managed package produces repair guidance instead of silently selecting an unrelated older binary. Externally managed runtimes retain the general 0.149.0 minimum, while individual features such as canonical message forks require a newer version.Restricted and message-only turns keep their intended tool limits. If an older administrator-managed Codex policy blocks those turns, the error explains the manual file or MDM migration needed to preserve ChatGPT-only login restrictions. Scheduled runs whose app inventory times out keep their saved access binding and report a timeout suitable for existing retry handling, without executing tools or asking for unnecessary reauthorization. Codex cloud sessions also skip startup of an OpenClaw worker they do not use.
Stopping a newly accepted Codex request now waits for confirmation that the selected turn ended, including side questions, while preserving other conversations on the connection. If conversation-history writes are blocked, cancellation and timeout can still release the turn, and a delayed write cannot later save an obsolete successful answer. Missing cancellation confirmation remains a reported failure.Recognized biological-risk and cyber-policy refusals now explain the refused turn without telling you to start over or automatically trying another model. You can continue the same conversation with a later request; the provider’s safety policy still determines what it accepts.
OpenClaw now talks directly to the Claude Code executable already installed on your computer, preserving existing login and configuration, warm conversations, resumed sessions, approvals, and questions. Script wrappers and command aliases retain their verified launch arguments, and fallback session titles use the first real prompt instead of preceding instruction metadata. Keep Claude Code current.Malformed Claude questions now return the failing field and correction guidance, so a corrected call with a fresh tool-use ID can reach you. Codex and Copilot also show question prompts that could previously remain invisible, including Codex side conversations, while supported credential requests provide a Control UI link for protected entry. A visible prompt can still encounter a separate problem receiving the answer.When Claude deliberately ends a turn without a reply, recognized stop reasons are explained and automatic replay is suppressed. Check any tool effects before retrying manually, because the work may already have changed something even though no final answer arrived.
Supported moves from Opus 5, Sonnet 5, Opus 4.8, or Fable 5 onto Fable 5.1 can retain readable earlier reasoning. Fable 5.1 also keeps the hidden runtime context needed for that continuity in saved transcripts and exports, while leaving it out of visible chat and compaction summaries. Other Anthropic-compatible models return to transient runtime context, avoiding repeated old details on later requests. Switching away and back, changing thinking level, or rewriting the prompt can still invalidate reasoning.Session pruning keeps trimmed tool results trimmed across later requests while preserving the full local history. Direct Anthropic API-key requests in cache-TTL mode use server-side clearing based on token thresholds, rather than the client TTL and hard-clear settings, and protection rules now include historical tools that are no longer available. After restarting a branched conversation, client-side restoration can still pick a sibling branch’s pruning marker and change the context sent to the model.
A model can still be working before it has visible text to send. Anthropic, Google, Mistral, Bedrock, and Ollama now count parsed keepalives, reasoning, and other response events as activity, and active CLI-backed answers retain their existing quiet allowance and time to finish delivery. Truly silent calls and overall run limits still expire.Temporary provider errors receive more appropriate retry handling and advice. ChatGPT SSE preserves the service’s requested retry delay, and eligible Bedrock connection failures before output can continue from completed tool work within the existing recovery limit. A failed unrelated harness plugin no longer blocks healthy models, later requests can recover from a transient catalog mismatch, and beginning provider sign-in leaves serving plugins active. These paths keep their existing safeguards against replaying completed effects.For a new billing failure, the initial wait falls from five hours to ten minutes, although upgrading does not shorten an already-active window or detect a top-up immediately. Explicitly ordered preferred credentials can also be retried on a later real request after their cooldown. Repeated rate-limit failures without a provider reset time can progressively delay those attempts up to 24 hours, so returning from a paid fallback is subject to successful recovery.
OpenAI Responses retains the instruction to finish an answer after compaction through reasoning-only and empty-response retries. If request preparation fails, a later successful request can establish fresh continuation state so subsequent turns stop resending the entire history; that first recovery request still sends the full conversation.Failed requests with unfinished tool calls now retain the provider’s reported usage, served model, and available failure reason when terminal information arrives. Incomplete tools remain blocked, along with later parallel tool completions after the incomplete call. Tiny managed output budgets are raised to the API’s 16-token minimum, and explicitly selected agents can use their allowed API model overrides on multi-agent Gateways without requiring a system agent.
Talk now checks for an unambiguous agent owner before loading providers, and voice-choice discovery can load provider catalogs without starting each full plugin. Compatible video-description services also honor their configured API-key or no-auth mode, with credentials reflected in service errors removed from diagnostics.Ending a Gateway-controlled OpenAI Realtime call now reports a failed provider hangup and retains it for bounded automatic cleanup retries. If those attempts are exhausted, cleanup remains incomplete and the call still reserves capacity; pressing End again is not the retry mechanism. The OpenAI cleanup guidance explains recovery, including that a restart can lose the in-memory cleanup obligation and does not prove the provider call ended.
Copilot now honors direct tools that must run without overlapping other tool calls in the same attempt. They wait for earlier calls to finish and hold later ones until they settle, including failure, while ordinary tools keep their parallel execution. Cancelled queued calls do not begin executing.
An unavailable optional Codex app no longer prevents an unrelated conversation or heartbeat check-in from starting when a successful app snapshot identifies the problem. OpenClaw logs the unavailable apps and continues with the remaining tools, including supported resumed sessions and forks. The unavailable app stays unavailable, and snapshot failures, tool permissions, and scheduled access checks retain their existing restrictions.
Concurrent conversations keep reply text in order while a reader temporarily falls behind, including across tool and final events, within the existing connection limit. A client that permanently stops reading can still be disconnected.Codex turn usage now adds the reported counts from every unique completed response, including responses before a retry or cancellation. Those totals remain separate from the current context window, so a missing final context snapshot stays unavailable instead of showing the cumulative usage as if it were the remaining conversation context.

Automations and Scheduling

You can manage existing automations from authenticated admin chat, keep their saved schedules and permissions through edits and copies, and let a self-cleaning job finish its result after removing its own schedule. Background checks retain their conversation context, while delegated tasks gain more specific recovery and stop behavior so you can follow the work through an interruption.
An administrator can now use Control UI chat to manage existing automations across the Gateway, including a reminder created in Telegram. You can ask your Claw to find it, inspect it, change it, run it or remove it, with the same administrative reach as the Automations page.This requires a fresh authenticated Control UI turn with operator.admin permission, and managing someone else’s job preserves its creator and scheduled execution policy. Creating command jobs remains a CLI or Gateway API operation.
Editing an automation now keeps the timing and alert choices you saved, including fractional-second cooldowns and stagger windows. A 90-second interval stays visible as 90 seconds, while alert settings that follow global defaults remain inherited until you deliberately override them. Copies also retain tool restrictions, model fallbacks and context choices, with fresh authorization for the new job.New automations created through Claude Code or Codex can retain the native file and command capabilities authorized in the creating turn. If an older job already has an empty tool-permission list, recreate it or explicitly edit its tools from a fresh authorized turn. Administrator-managed shell restrictions still apply.
A scheduled agent or script that is allowed to remove its own job can now delete the schedule and still finish its final result. Removing the job yourself continues to cancel it, and removing or disabling a job while it checks a condition prevents that pending check from starting the action. Effects already completed are not undone, and work already handed to the main conversation’s heartbeat keeps its own lifecycle.Job management also preserves newer run results and timing when scheduling is disabled, while cleanup can remove expired idle sessions without getting stuck behind a busy one. In experimental Claws, successful installation retries clear old scheduler errors, and unchanged jobs no longer look modified merely because a status response includes extra metadata.
Heartbeat checks and background-command replies keep the room or topic rules that belong to their conversation, including Telegram topics. A command completion also keeps its original destination if the conversation moves elsewhere, and a successful or intentionally quiet heartbeat clears its own pending delivery state so later checks can proceed.Turning off recurring heartbeats no longer drops the spacing and flood limits for event-triggered work, and reloading settings preserves those limits while a turn is running. When OpenClaw refuses a check, its notice explains the reason without requiring verbose mode. Duplicate heartbeat and skill-review monitors can also be reconciled during startup, while large agent fleets avoid repeated heartbeat-summary work in health and status checks.
Delegated work has more ways back to its result when a conversation times out or OpenClaw restarts. Completed child results can wait through a recoverable parent timeout, overlapping groups keep their results until related work finishes, and a failed or decorated waiting message no longer prevents the parent from preparing its final reply.Eligible interrupted subagent tasks can resume after a restart without another prompt, keeping the original task and conversation while showing progress from the replacement run. Already completed tasks recover their saved result and completion time. Restored follow-ups run through a limited queue so a large backlog does not start all at once, which can make that backlog take longer to clear. Resumption notices are separate from final replies and depend on a supported original destination and bounded retries.Recovery also handles a temporary failure to save an already accepted restart attempt, adopting that same execution without another model request while its original recovery owner remains valid. Cancellation, newer work or another restart ends that particular adoption opportunity. When the assistant is simply waiting after an earlier tool error, a deliverable waiting message now shows the current state, while the error remains visible if there is no usable message to replace it.
For ordinary Gateway-owned CLI tasks, cancelling a task now waits for the selected run and its pending approvals to stop before reporting success. The owning Gateway must still be running, and a timeout or missing live owner produces a refusal to confirm cancellation rather than a misleading success.Stopping a group of subagents sends stop requests to siblings without waiting for one sibling’s cleanup, and includes new child branches discovered during the stop. A child launch still being prepared is also rejected if its parent loses authority before acceptance. Once accepted, children keep their independence after ordinary parent completion; a stop acknowledgment does not mean every underlying process has already finished cleaning up.
An eligible automation attached to a persistent session can refresh its pinned dashboard widgets without keeping the browser open. It needs an explicit scheduled tool policy allowing show_widget, and its calls must pin the result; displaying an inline widget or opening it on a device still requires the appropriate client. When you do open Automations, bursts of activity share refresh requests while current status and run history continue to appear.If background image, video or music generation finishes but final delivery fails, the task result can retain output references for recovery through Copy result or openclaw tasks show <lookup>. Those references are bounded and can be truncated or filtered, and the files or URLs must still be accessible. This preserves a way to look for the output without automatically resending or hosting it.

Browser and Computer Use

Desktop work now stays with the machine you selected through approval, reconnects, and taking control, while computer actions account for the screenshot the model actually sees. Browser connections also get clearer startup failures and more careful cleanup, so returning to a task is less likely to mean sorting out a stuck launch button or a tab that another session is still using.
The Desktop panel notices when an approved machine becomes available and keeps your explicit selection when the session moves or refreshes. Opening a popout carries that same desktop and control choice with it, subject to the usual authentication and permissions. You can also take control while Browser or Terminal is launching without leaving its button stuck, and a failed launch shows an error you can act on.For agents using computer control, screenshot-capable CUA sessions can pause and then inspect a fresh image before continuing. Clicks and drags in CUA window images now account for resizing done by OpenClaw, so the delivered image and the requested position agree. Screenshot permission is still required, and a missing usable image prevents pixel-based actions while leaving supported element targeting available. Desktop viewing also handles the repaired clipboard case without dropping the connection, and a stalled receiver pauses further input until it can accept it again.If a paired machine goes offline, Continue on Gateway… lets you resume from the last synced workspace after an explicit data-loss confirmation. Unsynced files and in-flight work may be lost. The old worker loses authority over the session, but physical cleanup remains pending until it can be confirmed, so continuing locally does not mean the offline process has already stopped. The cloud worker recovery guidance explains that choice.
When Desktop disconnects, the browser console keeps the original failure without adding a misleading error from closing an already closed viewer. Desktop stream logs also retain the first known local shutdown trigger separately from the observed connection close code, giving you more useful context when comparing the Gateway and device logs. The intermittent disconnect remains unexplained, and code 1006 on its own does not tell you whether a network, proxy, or local shutdown caused it.
On macOS, authorized Peekaboo computer-control requests can scroll at a screen position or at the pointer without requiring modifier keys or hitting an incorrect stale-snapshot refusal. Background scrolling still needs a window and an element from its current observation, so a background request does not silently become a foreground scroll. The Mac integration also adopts Peekaboo 4.3.0’s native automation and Bridge repairs while retaining the existing computer-control settings and permissions.
Connecting to your existing Chrome session no longer waits for npm’s optional install audit when the default Chrome MCP helper needs to be downloaded. Chrome still needs remote debugging enabled and someone at the computer to approve its connection prompt. Custom launcher arguments retain their existing behavior.If attachment fails, the browser logs retain available startup errors and late shutdown warnings with the existing redaction and size limits. A replacement connection waits for the previous helper and its verified child processes to close, and uncertain cleanup reports an error. Your already-running browser stays open, while cancellation during startup prevents initialization from continuing afterward.
Reading a prose-heavy web page through Readability now spends less work scanning the HTML before extracting the article. The change skips unnecessary passes through ordinary text while keeping the extracted text and Markdown, along with the existing size and nesting limits, intact.

Plugins and Integrations

Trusted experimental plugins can put custom pages and controls into the web workspace, while MCP tools keep their connections when an unrelated server changes. For work that reaches another machine or another person, cloud coding sessions can push directly to GitHub and shared Beam snapshots can become new conversations with a Team agent.
Feature plugins can give your Claw its own pages, panels, widgets, and session actions, or replace parts of the conversation interface and the whole workspace. An agent can build a plugin archive and propose that exact archive for your review before installation, giving you a way to shape the interface around your work without changing OpenClaw itself.Native interfaces from user-installed plugins are experimental and off by default. Enable Settings → Labs → Custom plugin UI, restart the Gateway, and reload your browser tabs, using the connected Gateway’s own HTTPS or trusted localhost address. Install only code you trust because it runs with your signed-in operator permissions, without a plugin sandbox. Authors should pin and test their OpenClaw host version.Normal layouts currently hide the floating Customize UI entry, limiting access to replacement selection and Reload plugin UI. A full plugin workspace still offers Built-in recovery. Disabling the lab keeps installed plugins and their saved state, and enabled bundled interfaces such as Workboard remain available.
Editing one MCP server no longer needs to disconnect the other tools your agent is using. With Gateway hot reload enabled, unchanged servers keep their connections and cached tools, and an active call to one of those servers can finish while a different server is replaced. Changed or removed servers are revoked immediately, with updated definitions discovered on the next turn and requester sign-in tools refreshed on the next message.OAuth-connected tools also remain available to CLI agents after credentials refresh, and loading a multi-page tool, resource, or prompt list no longer times out just because the computer’s clock jumps forward. In Settings, deleting an MCP server or Cloud Worker profile with list-valued settings, or clearing a worker’s Setup field, no longer fails on those lists.
A coding agent on an OpenClaw cloud worker or paired session host can commit, push, and open a GitHub pull request during its turn, so it can see the result and respond before handing the work back. This needs GitHub CLI on the worker and an available shared Gateway GitHub account with access to the repository. It uses that shared identity, not the paired computer’s personal login.When a replacement worker starts behind the session’s pushed branch, it brings in those commits while preserving local edits and deletions, allowing the agent to continue with an ordinary push. Divergent history still needs attention. File reconciliation back to the Gateway remains separate from Git history, and Codex remote-exec keeps its own publication path. Use a dedicated worker account where required by the setup guide because per-turn credentials do not isolate processes sharing an operating-system account or revoke tokens already held by background processes.Cloud startup now rejects unusable local-only callback addresses before allocating a machine. At the other end of a session, SSH workspace cleanup can finish after the worker’s RPC credential expires, with ownership and SSH checks still enforced. Stop and Move show the current provider cleanup cause and any supplied retry guidance when release remains pending, while local checks of larger returned workspaces do less repeated file work.
A shared Beam snapshot can now become the start of a conversation with a Team agent. Write a message in its composer and OpenClaw copies the retained history into a new session belonging to you, using the source model when it is available and allowed, or explaining the switch to the agent’s configured model.The copy follows the Team agent’s normal permissions and treats imported history as untrusted reference material. It does not resume the source computer, inherit its tools, or synchronize later changes. Shared Beams are visible to Gateway operators with read permission; continuation also requires write or admin permission and access to the chosen agent. Delayed uploads no longer replace a newer snapshot or turn a completed snapshot live again at the same revision, keeping the saved history used for continuation intact.
Reloading or disabling Workboard now stops its retired background services and lets already accepted operations finish before closing their database connection. Saved cards remain available when Workboard reopens, without each reload accumulating another set of open database handles or leaving old polling services writing warnings.Commenting on a blocked card, refreshing its claim, or releasing that claim also reports a successful saved update correctly through the plugin-tools MCP bridge. Custom integrations consuming heartbeat, release, comment, or unblock results should read the returned card under card. The Workboard registration helper again supports integrations that let it create and manage the store.
Logbook now lets accepted captures, activity analysis, and generated standups finish saving before it closes their database during an orderly restart or disable. That also preserves the original analysis error when work fails, instead of covering it with a database-closed error. Shutdown can wait within the host’s existing deadline, and forced termination can still interrupt that work.Questions about a busy day now load only the latest 200 eligible observations already used for the answer context, keeping their chronological order without first loading the whole day’s observations.
Plugin updates give a clearer account of what is installed and what can change. If an official plugin is pinned to an older version, update and dry-run output can show the newer registry release and the explicit command to replace the pin. Existing pins stay in place until you choose otherwise. Repairing missing plugin files and updating a package now use its current contents, including removing settings for children that the replacement package has retired while preserving unrelated disabled plugins.Doctor also separates configuration problems from plugin problems. It keeps the original invalid-setting diagnostic instead of blaming whichever plugin happened to encounter it, and an absent plugin with an exact enabled: false marker no longer attracts contradictory installation advice just because it remains allowed. Real warnings still appear when console logging is set to warn.For valid retired plugins.installs records, openclaw doctor --fix preserves installation details before removing the old setting so service startup can proceed. It can also repair catalog-proven legacy official ClawHub provenance and explain the installation and storage paths behind a trust refusal. Malformed records still need correction, and trust rules remain in force. If an unreadable native service definition blocks an update, follow the service recovery guide, preserving and resupplying any values stored only in that service’s environment.
Plugin tools now keep their supported input preparation and required one-at-a-time execution behavior in later sessions, using the current session’s tool factory. A tool unavailable in that session can be omitted without taking healthy sibling tools with it, and literal names such as constructor work in tool permission rules while existing deny rules continue to apply.For replacement messaging plugins, settings validation, form metadata, and sensitive-field hints follow the plugin actually selected to run. This does not combine every inactive plugin’s redaction hints, and sensitive fields belonging to an unselected schema can still remain visible.Plugin authors should check one registration change before upgrading. A directly registered channel must declare a nonempty capabilities.chatTypes list using supported values. The channel builder still defaults omitted capabilities to direct messages; group, channel, and thread support must be declared explicitly. Narrow SDK compatibility repairs also retain positional text-chunking ranges and legacy provider-wrapper retry inputs. The latter remain deprecated and are ignored by built-in text transports, so new wrappers should omit maxRetries.
Plugin branding now comes from artwork included in the installed package, so displaying its icon does not contact an arbitrary outside image host. Channel gallery rows, details, and setup screens use matching names and locally bundled icons, making the integration you are configuring easier to recognize.Authors must include assets/icon.png to retain custom branding. URL-only packages show a generic fallback until updated, and missing or invalid artwork does not disable the plugin. Empty icon requests also close their file handles correctly instead of accumulating open files on repeated views.
Session-aware command integrations can now receive the current session UUID through the resolve_exec_env hook, letting a plugin pass it to scripts for attribution or callbacks. Exporting an environment variable still requires a plugin that chooses to do so.Configured prompt and model-input hooks also remain active when HTTP scripts or local agent work selects a non-default model, while disabled and excluded plugins stay inactive. Installing an npm hook pack no longer requires changing inherited npm dry-run or download-directory settings; the installer keeps its archive in its own temporary workspace.
A2A tasks that need an execution approval now keep their original task and reply path through the operator’s decision, including peers without an outbound URL. Ordinary text such as “Explain /help please” reaches the agent unchanged.A2A integrations must send plain-text tasks for agent work and use an authorized human command surface for slash commands. Leading-slash requests are rejected, even with permissive command allowlists or a ROLE_USER message value. The routed agent keeps its permitted tools, and approval still belongs to an authorized operator.For IDEs using the Gateway-backed ACP bridge, an externally stopped run can show its carried error cause instead of only an unexplained cancellation. Recording long ACP sessions also avoids repeatedly loading previous message payloads while preserving saved replay. On MCP process tools and Codex’s OpenClaw sandbox process tool, accepted final results clear their matching completion notice so it is not repeated later.
Direct calls to File Transfer directory tools now give the agent usable filenames and distinguish files from directories. A listing can continue after its last displayed entry, and fetched directories show the saved root and relative paths needed to open the files locally. Large fetched trees remain saved even when only part of their manifest fits in the text result; the result explains how to inspect omitted files, and reports when an unrepresentable path prevents text pagination from advancing.Successful individual file fetches also expose both their saved path and a reusable media ID, so an authorized write tool can copy those bytes without guessing at a hidden identifier. Restricted tool sets receive self-contained Bitable and search guidance without being sent to unavailable companion tools. If Bitable creates an application but cannot retrieve its table metadata, the guidance now tells the agent to keep the successfully created application.
Restoring a plugin registry now cancels obsolete cleanup that was still queued, preserving its saved session state and reporting only cleanup changes that actually committed. Choosing cleanup targets also avoids decoding large saved prompts, reducing that particular source of pauses while keeping retained content intact.Looking up or listing saved plugin artifacts reads committed data without creating an absent shared store. Missing storage produces an empty result, while damaged or unsupported storage still reports an error. Cleanup that writes to storage remains a separate operation.
The Lobster setup guide now includes the missing prerequisite. Install the optional official plugin with openclaw plugins install @openclaw/lobster, restart with openclaw gateway restart, then allow its tool. The tool remains unavailable in sandboxed tool contexts. These are corrected setup instructions for the existing integration.

Security and Privacy

If you run several agents on one Gateway, review their conversation access before upgrading. Where the settings were previously omitted, agents with session tools now gain access to other agents’ conversations, including other users’ transcripts. Choose narrower session visibility, restrict the participating agents, or disable ordinary cross-agent access if that sharing is not what you intend. Alongside this change, approvals follow current permissions through more of a task, switching Gateways retires the previous Gateway’s automatic skill trust, and conversation cleanup preserves data belonging to other agents.
Agents can now cooperate across one Gateway without first enabling two settings. Omitted tools.sessions.visibility changes from agent to all, and omitted tools.agentToAgent.enabled changes from false to true, allowing agents with the relevant tools to list, read, search, message, and inspect other agents’ sessions. Existing explicit restrictions still apply, but leaving these settings unset on an older installation now permits broader access on upgrade.The session visibility settings let you set tools.sessions.visibility to agent for the current agent’s conversations or self for only the current conversation. agent can still include other users’ conversations under that agent. To keep selected agents working together, set an explicit tools.agentToAgent.allow list that includes both the requesting and receiving agents, or set tools.agentToAgent.enabled to false to block ordinary cross-agent access. An omitted or empty allowlist permits all agent pairs when access is enabled, and deleting an agent can empty that list, so check it again after removal.There are important boundaries to those choices. Under tree or all, requester-owned native subagent and ACP child sessions remain reachable even when agent-to-agent access is disabled. tree also lets the canonical main session reach all same-agent conversations, while self stays limited to its current conversation. Sandboxing restricts what the sandboxed caller can reach; it does not hide its transcripts from another permitted caller. Incognito sessions remain hidden from these tools, and memory_search remains agent-scoped while sessions_search searches transcripts within the permitted scope.Run openclaw security audit to identify agents that retain unrestricted cross-agent session-tool access and see narrowing guidance. These are controls within one trusted Gateway, not isolation from its administrators. Mutually untrusted users need separate Gateways and credentials, ideally under separate OS users or on separate hosts.
When you ask an agent to change an OpenClaw setting, effective Full Access can now carry that permitted change through without a redundant approval card, including when Full Access comes from the configured default. Restricted runs still need approval, and operation restrictions, tool policy, and live permission checks continue to apply. In Guarded mode, the requesting tool waits for the actual result of Allow, Deny, expiry, or failure, so dismissing a card no longer leaves the agent reporting that it is waiting for a change that already finished. Stop cancels the pending request, and a late approval cannot revive it.Codex connected-app actions in ask mode also request approval within the current native thread, including resumed conversations and side questions, without rewriting saved app preferences. If an ordinary app-inventory check times out, chat can continue with those app tools disabled; their availability is separate from permission to use them, and scheduled work retains its stricter authority checks. Native administrative requirements still apply. Managed ACP sessions using the optional plugin-tools bridge now hide denied plugin tools and reject direct calls to them.For updates requested through an external chat channel, OpenClaw checks the requester’s current owner access again after service shutdown and immediately before starting the updater. Revocation at that point prevents the launch and restores the stopped service. It does not cancel an updater that has already started.
The shared Gateway owner profile now stays separate from personal profiles and their GitHub connections. Shared-token or password access cannot absorb a person’s identity through an owner-profile merge, and adding the first personal identity no longer imposes multi-person catalog restrictions on an otherwise solo Gateway. If an unreleased build left a malformed owner profile, openclaw doctor --fix followed by reconnecting repairs supported cases while preserving the person’s data. GitHub-backed Cloudflare Access sign-ins also reuse verified public profile metadata and respect quota retry deadlines, while current identity bindings and permissions remain checked.On a Mac, the local node now reuses credentials belonging to the selected Gateway, and switching Gateways retires the previous Gateway’s automatic skill permissions. The Exec Approvals pane refreshes its trusted commands and agent choices while keeping unfinished allowlist edits. Older Mac credentials with unknown Gateway ownership may require pairing again through the existing Approve on gateway prompt. On Windows, an approved device can move among the CLI, TUI, and Node Host without another approval solely for equivalent platform metadata; genuine identity and permission changes still go through their checks.Device token rotation and revocation now complete for authorized callers and return the final result before self-management disconnects the client. Self-rotation can return the replacement token, but CLI output does not automatically save it for the next connection. Shared-secret callers and callers rotating another device receive metadata without the replacement bearer token. Removing a paired device also runs its worker cleanup if the requesting connection loses authorization after removal is committed.
On shared installations with operator roles, knowing another person’s draft session key no longer lets a view, suggest, or write caller read its details or messages. Transcript reads check access again after loading, so revocation or replacement of the conversation during the read prevents disclosure; creators and administrators retain access. Managed image, thumbnail, and artifact downloads also follow the current conversation history, closing access when a reset or branch change removes the attachment from that history, even if an old archive still contains it.Deleting a conversation now retains current and historical data if the original caller loses authority before the deletion commits. Deleting one agent’s global session also preserves other agents’ saved plugin state and timestamps. Selected-agent global-session reads, delivery, boards, run lookup, search checks, and GitHub publication keep the explicitly selected agent, although retained-global links and unscoped session-list ownership still have separate unresolved cases.Agent and experimental Claw removal refuses to proceed while a database is actively in use and preserves directories containing another agent’s registered data. If session cleanup or transcript archiving fails after configuration removal, the result reports partial cleanup instead of completion. Correct the reported error, preview and retry removal, and finish cleanup before recreating the agent. Conversation deletion can still wait on native cleanup or database settlement, so these permission checks do not establish a total deletion timeout.
Local utilities used to inspect busy ports, identify processes, and clear a port now receive a limited operating-system environment instead of inheriting unrelated provider credentials, application tokens, proxy settings, and runtime overrides. This is scoped to those diagnostic helpers. Redacted logs and sanitized tool results also keep valid JSON fields that could previously disappear, including literal __proto__ fields, while still hiding nested secrets.Doctor recovery reports keep report-bearing links out of terminal and JSON output and preserve the approved report when a GitHub submission has an uncertain outcome. A later run checks for the same report instead of automatically posting again, and declining consent keeps reporting local. Sanitized report bodies can still appear in JSON. Once a submission receipt is claimed, its version-4 recovery manifest cannot be read by older Doctor writers that only understand versions 1–3, even if the claim is later cleared.Remote workers now reclaim abandoned private skill copies before preparing their next turn, including a turn that selects no skills. Cleanup failures stop preparation for retry, and disconnected workers have no cleanup deadline. Private credential-file writes also retain automatic repair of overly permissive OpenClaw directories with the filesystem-library update, while transcript repair preserves directory permissions and file-transfer refusals retain destination details where available.
Installing an npm plugin with an expected integrity checksum now stops with a clear error if the registry omits the checksum needed to verify it. Those registries must supply integrity metadata for pinned installs to succeed; unpinned installations and the existing consent flow for a present but mismatched checksum keep their behavior.Crafted SVG site icons that could freeze conversations and web requests are now rejected without triggering that validation freeze, and valid self-closing SVG roots pass the repaired check. HTTP-client dependencies also receive security updates, while proxy exception matching handles a single trailing DNS dot consistently in either the destination or NO_PROXY entry. Requests that bypass the proxy retain the normal direct-connection DNS checks.

Quality-of-Life Improvements

Swarm is now available to eligible agents without a separate enablement step, so your Claw can divide a job among helpers and collect their answers using the tools you already allow. Code Mode can also keep working after a tool error, inspecting what happened and completing the remaining changes in the same conversation. Around that work, conversations are easier to organize, long histories interfere less with other activity, and command results give you more useful information when something stops or fails.
Swarm lets an agent coordinate several helpers and collect their results, and eligible agents now have it available by default. It remains experimental and follows your existing tool permissions and limits, with an explicit opt-out in Settings → Agents & Tools → Labs → Swarm. OpenClaw Code Mode remains a separate opt-in.Larger Swarm jobs in Code Mode now queue calls when the bridge is full, allowing accepted work to advance as space opens without manually splitting the job into batches. Stopping the run prevents its remaining queued calls from launching, and pauses within the same process preserve the original arguments. Result collection also preserves the text or structured format requested when each helper started, while agents sharing global sessions can use the same group name without sharing one another’s concurrency allowance or retention schedule.Existing Codex chats keep the tools they started with. Use /new or /reset in an ordinary unlocked chat to get the current tools; keep a supervised chat intact and start a separate ordinary session from the global New Session page with a concrete Codex-backed model. Saved Codex scripts that call tools.openclaw__agents_wait must change to tools.agents_wait.
A failed tool call no longer puts Code Mode into a separate read-only recovery mode. Your agent can read the error, inspect the current files or settings, and make the remaining changes without restarting the conversation or being limited to one further edit. Failed programs are not automatically replayed, and because an earlier call may have partly succeeded, the agent needs to check what already happened before repeating an action. Normal permissions and approvals still apply to every later call.The compact tool reference now includes whole-number requirements and numeric ranges, including the reminder that file-read offsets start at one. Large results and diagnostics also take less work to fit within the existing output limits, and obsolete tool resources can be released after refreshes and reloads while descriptions for tools still in use stay current.
Preparing a long saved conversation now happens in background workers so that reading its history does not hold up unrelated Gateway activity. Context loading also batches message reads, startup can check for existing messages without decoding their full contents, and resuming an older view of a conversation uses fewer database statements when saving the next message. These changes reduce interference and unnecessary work while preserving the selected conversation branch; the amount of history still matters, and the work does not have a fixed memory cost.Branching keeps your current conversation in place until the new branch has saved, preserves current session details, and prevents an older run from writing after another run takes over. Shared databases also retain the correct agent ownership in session views and save the activity records needed to inspect non-default agents. Incognito history follows the active branch again while remaining in memory, and stopped history workers release their database leases when cleanup succeeds. A cleanup failure stays visible with restart guidance before deletion.Stopping or timing out compaction now prevents further preparation once cancellation is observed, including after a session handoff, and native CLI cancellation is reported as compaction aborted. An operation already in progress may still need to settle before cleanup completes.
Command results give your agent more useful clues about what happened. A foreground command that exits unsuccessfully without printing anything now explicitly says (no output) beside its exit code, and background process lists distinguish an overall timeout from a command that stopped producing output. Polling a completed job clears its pending completion notice only after confirmed chat delivery or successful saving of the tool result, keeping that notice available when delivery or persistence fails.For people working in the terminal, a URL used as an initial message can appear before or after the destination session URL, as shown in the TUI guide, and unusually long wrapped table cells no longer hit the repaired argument-limit crashes. There are two small scripting changes to account for. Stopping openclaw sessions tail --follow now returns 130 for Ctrl-C or 143 for termination instead of success, and diagnostics exports reject empty --log-lines or --log-bytes values. Omit those flags when you want their defaults.
Checking usage and costs no longer loads large saved skill or system prompts just to prepare the metrics, avoiding the associated history-processing stalls while leaving full context available where it is needed. Turn completion and usage displays also skip fallback price lookups when recorded costs already suffice, or when only token counts are being shown. The pricing calculation and displayed costs are unchanged, and estimated costs remain estimates.When a run fails without enough information to classify the cause, the message now says the agent run failed and keeps the available model context instead of blaming the provider. Recognized provider errors retain their specific guidance, so the wording reflects what OpenClaw actually knows without claiming to diagnose or repair an unknown failure.

Other Bug Fixes

A task can finish its file changes and still lose the answer at the last step, or a conversation repair can fail while the chat is still open. These fixes keep completed work available through specific saving and provider failures, preserve the last committed conversation when a repair fails, and bring command startup under the same timeout and cancellation controls as the work that follows.
When a file already contains the change you asked for, the agent now treats that as a successful step and continues to the rest of the task, including its final answer. Local CLI agents also keep access to their embedded Gateway tools after starting a run.Completed work has two more paths back to a useful response. If a temporary provider failure interrupts the final summary after all tools have finished, eligible runs can try a summary without executing those tools again. When a CLI-backed turn has already returned its answer, a later session-saving failure preserves that answer and its usage information instead of automatically repeating the action. Remote computer cleanup failures likewise retain the captured result and the earlier error or interruption, so the cleanup problem remains visible. Resolve that problem and check what the tools already did before retrying work whose outcome is uncertain.
A failed conversation repair now leaves both the active chat and its saved history at their last committed state, allowing the same repair to be retried once the problem is resolved. When an authorized rewrite succeeds, the message already accepted for the current turn stays in the active conversation exactly once, including through repeated rewrites and later replay.History-index rebuilds also wait for writes they have already accepted before reporting that they have finished, while keeping the database resources needed to complete them. Alongside those changes, stored messages avoid false “edited” errors caused by serialization, and damaged session metadata follows the full reader’s parsing rules when it is used for listings and cleanup decisions.
Command timeouts and cancellation now apply while a process is still starting, including service-managed commands waiting for credentials, so those startup waits can return a timeout or cancellation result. The first cancellation reason stays attached to the run even if a timeout fires afterward.Cancelling a request also releases runtime state that nobody else needs and skips obsolete workspace preparation that has not started yet. Other callers can keep using shared preparation, and finished or combined queued chats release their unused cancellation listeners. Work already performing discovery is not forcibly interrupted by this cleanup, and stopping startup does not guarantee that every descendant of an interactive terminal process has been removed.
If a paired computer will not reconnect, Continue on Gateway… can now move its session back to the computer running OpenClaw so you can resume from the last synced workspace. This is an explicit recovery choice that discards changes still held only on the offline device, so use it when waiting for that device to return is no longer the right option.The cloud-session recovery guide explains what remains on the Gateway. Physical cleanup can still be pending after the session becomes available again, and moving the session does not confirm that an old process on the disconnected computer has stopped.
Agents can read from the beginning of a blank line without receiving a false end-of-line error, including when an ordinary Markdown or memory file starts that way. Operators can also delete an agent with file cleanup, recreate the same ID, and create new sessions without restarting the Gateway.Several narrower changes remove work that no longer needs to be retained. Code Mode can release completed calls’ inputs while slower calls continue, compute workers no longer require the parent process to hold their input copies throughout execution, and session-list refreshes can let go of obsolete cached pages. Long-conversation preparation avoids repeated validation and unnecessary copies, while voice processing skips debug-capture filesystem checks when capture is disabled. These changes reduce specific processing and retention costs; total history loading can still be dominated by database reads.
If final filtering removes everything from a reply, OpenClaw now reports a failure instead of leaving the conversation looking successful with nothing to read, including when a fallback model also produces no visible answer. Deliberate silence and valid delivery or continuation paths keep their existing behavior.On Apple clients, Talk relay playback now follows the audio player’s actual completion. The speaking state, playback acknowledgments, and microphone echo suppression stay active until queued audio finishes, while pause, interruption, and cancellation can still stop playback earlier.

Maintainer and Internal Changes

These 514 maintainer-only changes cover repository upkeep, release verification, test infrastructure, and internal code cleanup. The collapsed change list below preserves the complete maintenance record.
Release checks now bind more of their evidence to the exact package candidate and preserve the boundaries around older releases, prepared test workspaces, and reviewed exceptions. Dependency audits retry temporary advisory-service failures within a bounded deadline. Under the final policy, incomplete advisory coverage still blocks ordinary CI.Test cleanup, fixture isolation, and clearer failure reports make repository checks easier to diagnose. CI changes reduce repeated preparation and combine compatible jobs while retaining their checks. Internal refactors reduce repeated work in parsing, rendering, and database access without establishing a general user-facing speedup. The paired Vitest benchmark supports comparison of candidate versions; it does not establish acceptance of a Vitest upgrade.Contributors running declaration builds must use dependencies owned by the selected checkout. Shared external toolchains are rejected, so affected setups may need a standalone checkout with its own pnpm install.