/.
Host-only bash commands use ! <cmd> (with /bash <cmd> as an alias).
When a conversation is bound to an ACP session, normal text routes to the ACP
harness. Gateway management commands remain local: /acp ... always reaches
the OpenClaw command handler, and /status plus /session stay local whenever
command handling is enabled for the surface.
Three command types
Commands
Standalone
/... messages handled by the Gateway. Must be sent as the
only content in the message.Directives
/think, /fast, /verbose, /trace, /reasoning, /elevated,
/exec, /model, /queue — stripped from the message before the model
sees it. Most persist session settings when sent alone; /exec security
and approval options apply only to their message.Inline shortcuts
/help, /commands, /status, /whoami — run immediately and are
stripped before the model sees the remaining text. Authorized senders only.Directive behavior details
Directive behavior details
- Directives are stripped from the message before the model sees it. Removal leaves the remaining text’s spacing and line endings intact, including code indentation. Only the recognized directive, its arguments, and an adjacent separator (or its own line ending when alone on a line) are removed. Text with no recognized directive is unchanged.
- In directive-only messages (the message is only directives), they
persist to the session and reply with an acknowledgement.
/exec security=... ask=...is the exception: these options apply only to the current message and never change later turns. Include them with the task; use session permission modes for session-wide policy./exec host=... node=...still persists placement. - In normal chat messages with other text, they act as inline hints and
do not persist session settings.
Model selection is the exception: an authorized inline
/modelor configured/<alias>persists the session selection. Owner/admin-aand-gscopes also request an update for the selected default. - Directives only apply for authorized senders. If
commands.allowFromis set, it is the only allowlist used; otherwise authorization comes from channel allowlists, pairing, and always-on access-group enforcement. Unauthorized senders see directives treated as plain text.
Configuration
boolean
default:"true"
Enables parsing
/... in chat messages. On surfaces without native commands
(WhatsApp, WebChat, Signal, iMessage, Google Chat, Microsoft Teams), text
commands work even when set to false.boolean | "auto"
default:"\"auto\""
Registers native commands. Auto: on for Discord/Telegram; off for Slack;
ignored for providers without native support. Override per-channel with
channels.<provider>.commands.native. On Discord, false skips slash-command
registration; previously registered commands may stay visible until removed.boolean | "auto"
default:"\"auto\""
Registers skill commands natively when supported. Auto: on for
Discord/Telegram; off for Slack. Override with
channels.<provider>.commands.nativeSkills.boolean
default:"false"
Enables
! <cmd> to run host shell commands (/bash <cmd> alias). Requires
tools.elevated allowlists.number
default:"2000"
How long bash waits before switching to background mode (
0 backgrounds
immediately).boolean
default:"false"
Enables
/config (reads/writes openclaw.json). Owner-only.boolean
default:"false"
Enables
/mcp (reads/writes OpenClaw-managed MCP config under mcp.servers). Owner-only.boolean
default:"false"
Enables
/plugins (plugin discovery/status plus install + enable/disable). Owner-only for writes.boolean
default:"false"
Enables
/debug (runtime-only config overrides). Owner-only.boolean
default:"true"
Enables
/restart, /update, and external SIGUSR1 restart requests.string[]
Explicit owner allowlist for owner-only command surfaces. Separate from
commands.allowFrom and DM pairing access. CLI pairing approval records the
first owner; Control UI pairing has an explicit owner checkbox. Authorized
non-owners receive a refusal with the exact configuration command for their
sender ID when using an owner-only command such as /restart or /update.
Use channel:id (for example, discord:123456789012345678). If an upgrade
leaves a legacy channel:user:id owner entry, run openclaw doctor --fix;
Doctor rewrites recognized channel entries and reports their list positions.enforceOwnerForCommands policy. This is plugin behavior, not an
openclaw.json setting. A wildcard command allowlist does not bypass it.
object
Per-provider allowlist for command authorization. When configured, it is the
only authorization source for commands and directives. Use
"*" for a
global default; provider-specific keys override it.commands.allowFrom is not configured, command authorization follows
the channel’s allowlists and pairing state. Access-group entries referenced by
channel allowlists are resolved automatically; there is no command-level
access-group toggle.
Session commands /new and /reset (including /reset soft) remain available
to channel-authorized senders on channels that do not enforce owner-only
commands, even when those senders are not in commands.ownerAllowFrom.
An applicable commands.allowFrom policy remains authoritative: a denied
sender or an explicitly empty list cannot fall back to channel admission.
Reset access does not grant other command or owner-only authority. Internal
Gateway callers with explicit scopes still need operator.admin to reset.
When both the request and reply stay in WebChat, rejected /new and /reset
commands show a permission denial. A denied command does not perform the
requested reset or run its follow-up text; normal idle/daily rollover still
applies. Ask your Gateway administrator to reset the session, or send your
message without the command.
Command list
Commands come from three sources:- Core built-ins:
src/auto-reply/commands-registry.shared.ts - Plugin commands: plugin
registerCommand()calls
Core commands
Sessions and runs
Sessions and runs
Explicit
/export-session paths replace existing files inside the
workspace. Omit the path to generate a collision-safe filename.HTML conversation cards omit messages marked hidden. The sidebar’s All
filter includes these records with a [hidden] label for debugging.
Message counts describe the raw archive. The HTML file and its JSONL download
still contain hidden records; hiding a message does not redact the export.Control UI intercepts typed
/new to create and switch to a fresh
dashboard session, except when session.dmScope: "main" is configured
and the current parent is the agent’s main session — in that case /new
resets the main session in place. Typed /reset still runs the Gateway’s
in-place reset. Use /model default when you want to clear a pinned
session model selection.Model and run controls
Model and run controls
verbose / trace / fast / reasoning safety
verbose / trace / fast / reasoning safety
/verboseis for debugging — keep it off in normal use./tracereveals only plugin-owned trace/debug lines; normal verbose chatter stays off./fast auto|on|offpersists a session override; use the Sessions UIinheritoption to clear it./fastis provider-specific: OpenAI/Codex map it toservice_tier=priority; direct Anthropic requests map it toservice_tier=autoorstandard_only./reasoning,/verbose, and/traceare risky in group settings — they may reveal internal reasoning or plugin diagnostics. Keep them off in group chats.
Model switching details
Model switching details
- Prefer choosing the model when creating a session. Changing it in an established session is an advanced operation because model context limits, prompt/tool behavior, and prompt-cache behavior can differ. See Choose a model for a session.
-s changes only this session, -a also updates the agent default, and -g also updates the shared global default. Without a flag, agents.defaults.modelSelectionScope applies when set; omission preserves existing behavior.Configured /<alias> shorthands accept the same trailing scope and --runtime options as /model <alias>.With
modelSelectionScope unset, a direct owner/admin /model <model> also requests an update to the agent’s existing explicit primary, or to the shared global fallback if there is none. Without owner/admin authority, bare commands remain session-only and explicit -a and -g requests are rejected. Selecting the effective configured default clears the session model pin, but agent/global scope still requests the configured-default write. Immutable configuration stays unchanged. Asynchronous write errors do not revert the session selection.- If the agent is idle, the next run uses it right away.
- If a run is active, the switch is marked pending and applied at the next clean retry point.
Discovery and status
Discovery and status
Skills, allowlists, approvals
Skills, allowlists, approvals
Subagents and ACP
Subagents and ACP
Owner-only writes and admin
Owner-only writes and admin
Voice, TTS, channel control
Voice, TTS, channel control
Bundled plugin commands
LINE-only:
/card ... (rich card presets; see LINE)
QQBot-only: /bot-ping, /bot-version, /bot-help, /bot-upgrade, /bot-logs
Skill commands
User-invocable skills are exposed as slash commands:/skill <name> [input]always works as the generic entrypoint.- Skills may register as direct commands using their declared skill name.
- Native skill-command registration is controlled by
commands.nativeSkillsandchannels.<provider>.commands.nativeSkills. - Names are sanitized to
a-z0-9_(max 32 chars); collisions get numeric suffixes.
Skill command dispatch
Skill command dispatch
By default, skill commands route to the model as a normal request.Skills can declare
command-dispatch: tool to route directly to a tool
(deterministic, no model involvement).Native command arguments
Native command arguments
Discord uses autocomplete for dynamic options and button menus when required
args are omitted. Telegram and Slack show a button menu for commands with
choices. Dynamic choices resolve against the target session model, so model-
specific options like
/think levels follow the session’s /model override./tools: what the agent can use now
/tools answers a runtime question: what this agent can use right now in this
conversation — not a static config catalog.
/loop: recurring conversation work
/loop is owner-only because it uses the cron control-plane tool. /loop 5m check deploy status asks the agent to create a fixed-cadence cron job in the current conversation. Without an interval, /loop watch for new issues creates a self-paced loop that checks more often while active and backs off toward 1 hour while quiet. /loop status lists the conversation’s loop jobs; /loop stop [name] removes them.
/model: model selection
Use -s to change only the current session, -a to also update the agent default, or -g to also update the shared global default. The long forms are --session, --agent, and --global; an explicit scope overrides agents.defaults.modelSelectionScope.
Without a flag or that optional setting, direct owner/admin /model <model> commands keep their existing behavior: change the session and request a best-effort update of the agent’s explicit primary, or the shared global fallback when the agent has none. To make unqualified selections session-only, opt in with:
"agent" and "global"; it does not grant permission to write configured defaults. See Model selection scope.
In text commands, select a model by provider/model or a configured alias.
Numeric selections such as /model 3 are not supported.
/model and /models commands open an interactive
picker. Choose a provider and model from the dropdowns, then select Submit.
Discord follows the direct command behavior, including modelSelectionScope.
Telegram model browsing uses callback buttons; selections always remain session-only.
The picker respects agents.defaults.modelPolicy.allow,
including provider/* entries. Without an explicit allowlist, model entries and
aliases do not restrict selection.
-a updates only the current agent’s configured primary, even when it previously
inherited the global default. -g updates the shared fallback, not every agent’s
explicit primary. Other session pins remain unchanged, but unpinned sessions
and cron jobs that inherit the changed default can use it on their next run.
Selecting the effective configured default clears the session model pin, but
agent/global scope still requests the configured-default write. Use
/model default -s to inherit the configured default without writing it.
Without owner/admin authority, bare commands remain session-only and explicit
-a or -g requests are rejected.
/config: on-disk config writes
Owner-only. Disabled by default — enable with
commands.config: true./config
updates persist across restarts.
/mcp: MCP server config
Owner-only. Disabled by default — enable with
commands.mcp: true./mcp stores config in OpenClaw config, not embedded-agent project settings.
/mcp show redacts credential-bearing fields, recognized credential flag
values, and known secret-shaped arguments. When run from a group, the
configuration is sent to the owner privately; if no private owner route is
available, the command fails closed and asks the owner to retry from a direct
chat.
/debug: runtime-only overrides
Owner-only. Disabled by default — enable with
commands.debug: true.
Overrides apply immediately to new config reads but do not write to disk./plugins: plugin management
Owner-only for writes. Disabled by default — enable with
commands.plugins: true./plugins enable|disable updates plugin config and hot-reloads the Gateway
plugin runtime for new agent turns. /plugins install restarts managed
Gateways automatically because plugin source modules changed. Trusted ClawHub
and official-catalog installs do not need a provenance acknowledgement. Arbitrary npm,
git, archive, npm-pack:, and local path sources show a provenance warning and
require a trailing --force after you review the source. This flag acknowledges
the source and permits replacement of an existing install; it does not bypass
security.installPolicy or installer security checks. ClawHub Review outcomes
are printed informationally; blocked releases remain non-installable.
Marketplace, linked, and pinned installs remain shell-only.
/plugins inspect <child> (also show or get) and /plugins inspect all include the shared package install metadata for multi-entry plugins. Inspection returns install: null when package ownership is missing or ambiguous, and preserves its runtime capability report.
When /plugins install or /plugins enable requires capability consent, it
returns the plugin’s declared capabilities and an exact retry command. Review
that reply, then rerun with --accept-capabilities:
--force.
/trace: plugin trace output
/trace reveals session-scoped plugin trace/debug lines without full verbose
mode. It does not replace /debug (runtime overrides) or /verbose (normal
tool output).
/btw: side questions
/btw is a quick side question about the current session context. Alias: /side.
- Uses the current session as background context.
- In Codex harness sessions, runs as an ephemeral Codex side thread.
- Does not change future session context.
- Is not written to transcript history.
/btw and /side open Side chat instead of starting the
detached BTW path. The TUI and
external-channel behavior above is unchanged.
See BTW side questions for the full behavior.
Surface notes
Session scoping per surface
Session scoping per surface
- Text commands: run in the normal chat session (DMs share
main, groups have their own session). - Native Discord commands:
agent:<agentId>:discord:slash:<userId> - Native Slack commands:
agent:<agentId>:slack:slash:<userId>(prefix configurable viachannels.slack.slashCommand.sessionPrefix) - Native Telegram commands:
telegram:slash:<userId>(targets the chat session viaCommandTargetSessionKey) /login codexsends device pairing codes only through private chat or Web UI response paths. Telegram group/topic invocations ask the owner to DM the bot instead./stoptargets the active chat session to abort the current run.
Slack specifics
Slack specifics
channels.slack.slashCommand supports a single /openclaw-style command.
With commands.native: true, create one Slack slash command per built-in
command. Register /agentstatus (not /status) because Slack reserves
/status. Text /status still works in Slack messages.Fast path and inline shortcuts
Fast path and inline shortcuts
- Command-only messages from allowlisted senders are handled immediately (bypass queue + model).
- Inline shortcuts (
/help,/commands,/status,/whoami) also work embedded in normal messages and are stripped before the model sees the remaining text. - In Control UI, every non-skill slash command can be selected in the middle of a draft. The command runs separately, only the command invocation is removed, and the surrounding draft remains unsent.
- In Control UI (WebChat), selecting a skill from slash completion inserts the existing
$skill-namereference into the message (for example,Please use $weather to check Sydney). - Inline command dispatch follows the same connection, permission, and confirmation checks as sending that command by itself. Typing slash-like prose without selecting or submitting the completion does not execute it.
- On external channels, unauthorized text command-only messages are silently ignored; inline
/...tokens are treated as plain text. Native/compactreturns an authorization refusal when a channel-admitted sender cannot use the command. Reset denials show a permission reply only when the request and reply stay in WebChat.
Argument notes
Argument notes
- Commands accept an optional
:between the command and args (/think: high,/send: on). /new <model>accepts a model alias,provider/model, or a provider name (fuzzy match); if no match, the text is treated as the message body./allowlist add|removerequirescommands.config: trueand honors channelconfigWrites.
Provider usage and status
- Provider usage/quota (e.g., “Claude 80% left”) shows in
/statusfor the current model provider when usage tracking is enabled. - Token/cache lines in
/statuscan fall back to the latest transcript usage entry when the live session snapshot is sparse. - Execution vs runtime:
/statusreportsExecutionfor the effective sandbox path andRuntimefor who is running the session:OpenClaw Default,OpenAI Codex, a CLI backend, or an ACP backend. - Per-response tokens/cost: controlled by
/usage off|tokens|full. /model statusis about models/auth/endpoints, not usage.
Related
Skills
How skill slash commands are registered and gated.
Creating skills
Build a skill that registers its own slash command.
BTW
Side questions without changing session context.
Steer
Guide the agent mid-run with
/steer.