Skip to main content

v2026.8.2

v2026.8.2 adds a Home button to the Control UI that opens your personal Home agent beside whatever you are working on, instead of making you leave it to start another conversation. It also brings a Linux desktop companion, background sessions you can start without switching pages, browser control that can stay available without a running Gateway, four new looks for the Control UI, and a long tail of fixes for replies, voice, updates, and recovery. Release scale: 784 pull requests, 10 direct commits, and 134 contributors.

Installation and Onboarding

Installation and first-run setup now do a better job of preserving the system and model choices people already made. Linux and macOS recovery paths fail more clearly, guided setup keeps the selected agent and model through reconnects, and required runtime plugins can be reviewed, installed, and verified without sending people to Terminal.
Installation now follows the path each system actually began with. Fedora and other affected RPM-based Linux systems can keep their distro-owned Node packages while OpenClaw selects a managed runtime that meets its SQLite requirements, and the shell installer once again exposes the npm errors it needs to recover from supported stale launchers and install directories. On macOS, Install and Relaunch stops after one failed relocation retry and points to the Applications copy instead of looping. Linux Gateway installation also refuses an unsafe sudo-to-root setup before it writes root-owned configuration or credentials, without changing genuine root installs or ordinary sudo lifecycle commands.Updates keep more of the working installation intact. pnpm-owned installs stay with pnpm across the updater handoff, interrupted package lifecycle work can finish before the new package starts, and hardened npm hosts can update without enabling unrelated package scripts. Doctor now migrates a readable active configuration before considering an older last-known-good copy, preserving rejected bytes when fallback recovery is still necessary. ClawDock helpers are retired, so existing users need to remove the helper source line themselves and move to the documented Docker Compose and OpenClaw CLI commands, with their deployment state left in place.
First-run setup now waits for the thing it just configured to become real. Model Setup keeps the chosen model through a reconnect, stays pending until the saved settings are active, and shows the actual recovery reason when the running Gateway is not ready yet. Guided CLI setup asks for an agent only when a step actually belongs to one, keeps that choice through the rest of the flow, and lets people add an agent without copying credentials when that is not what they want.When a model needs a runtime plugin, macOS onboarding and the Control UI can show where the plugin comes from and which capabilities it requests, ask for explicit approval, install it, and verify the model in the same flow. Declining or cancelling leaves the configured model unchanged and stops the attempt. Mac users can also finish ChatGPT Login after a same-route reconnect when the original callback was proven unsent, cancel a stalled provider sign-in, or quit onboarding without a late result taking over a replacement attempt.

The New Web UI

The Control UI is easier to use when several conversations are moving at once. A New Session can start in the background, Home can stay beside the work already on screen, messages and drafts keep their place more reliably, long histories do less repeated work, and four opt-in themes make the workspace easier to make your own.
A New Session can now begin in the background while you stay on the setup page and prepare something else, then open from its completion notice when it is ready. Plain folders and fresh repositories remain usable without pretending they support a worktree, project and checkout choices survive temporary discovery failures, and startup progress keeps moving forward instead of hiding newer tool or approval activity. Typing from an unfocused part of New Session also sends the first printable character to the composer.On iPhone, model, effort, permission, context, attachment, skill, connector, and tool controls now live in the composer when the connected Gateway and operator access support them. Queued messages stay bound to the settings that were reviewed before sending, older or stale queue entries stop for review, and Control UI prompts keep one visible identity through preparation, completion, and reload. Selecting text can open an editable side-chat draft without adding the side question to the main history.
Queued, interrupted, and cancelled input now returns to the point where it was accepted instead of dropping below newer replies, and prompts that the Control UI has already handed off stay gone through refreshes, pagination, and remounts. Cross-session messages show which conversation they came from and link back to it, while recovery after a long conversation runs out of room keeps the latest active text request ahead of superseded work.The command surface is simpler around those handoffs too. Manual docking and focus commands are gone without compatibility aliases, and /session unbind is now the supported way to detach a bound conversation without ending its agent session.
Session menus now keep everyday organization, appearance, copying, navigation, and destructive actions in clearer groups, with icon and color editing in one place and supported destinations available without hunting through the interface. Empty group headings can be hidden locally without losing their membership or move targets, nested menus keep their parent row highlighted, and ordinary operational text can be selected and copied again.Beam transcript shares now use shorter readable links while keeping existing catalog links and normal authorization intact. Returning to an existing Control UI tab after an update or abrupt restart also reconnects without making you open another tab, preserving the route and unsent draft you already had open.
Long Control UI conversations now open with up to 800 recent messages and keep older pages capped at 1,000, so more of the current conversation is ready before another history load. The initial render and older-page prepend paths repeat less work while keeping visible content and scroll behavior the same.Importing or returning to a large retained history also requires less local work in the affected paths, while the conversation and its search results remain unchanged.
Usage and status views now carry cumulative output-token totals through tool calls, retries, approvals, reconnects, and the final recap, while selected models report their prepared context windows instead of falling back to a generic number. Cost estimates keep models from different providers apart, preserve explicit custom and zero prices, and avoid applying hosted rates to private endpoints.Settings also preserve separate changes when two OpenClaw processes make their first save at the same time, and the Control UI moves setup bookkeeping out of everyday Appearance settings while leaving consent choices editable.
Each new appearance choice works in light or dark mode and follows your profile, while Manuscript adds the first built-in light-first design and Claw remains the default. An explicitly selected appearance also stays in place while the Gateway reconnects instead of briefly yielding to the browser’s system theme.
The Home agent can now stay docked beside current Control UI work with its normal conversation history, tools, approvals, queue, attachments, and draft-preserving handoff to the full page, so asking for help no longer means leaving the thing you are working on.
Forwarded messages in the Control UI now show which agent sent them through that agent’s avatar or stable initials, including in direct conversations where the identity used to disappear.

Updates and Maintenance

Updates now preserve more of the working installation and leave a clearer recovery path when something goes wrong. Doctor can coordinate supported offline repairs with the managed Gateway, busy systems give status and Control UI requests more room to run, and recovery messages retain useful redacted detail without turning uncertain work into a false success.
Automatic updates now keep their chosen channel and final result across reconnects, reloads, disabled checks, one-off installs, and managed-service handoff. Unattended installation remains limited to managed Gateway services, while a foreground Gateway stays running until you follow the stop, update, and launch path yourself.Restart-enabled updates also refuse to replace files when service ownership cannot be inspected, preserve rollback information when a failed update can be recovered, and stop before claiming success if session migration is incomplete. Installing a newer package no longer migrates shared state before that version actually runs, though databases already changed by an affected package still need a compatible backup restore, and none of these paths turns the whole update into one reversible transaction. Verified legacy migration originals can now be previewed and removed after the selected Gateway is stopped, but that cleanup is explicit and irreversible because it permanently removes the files an older installation could otherwise use for rollback.
Doctor can now take explicit ownership of more offline repair work by stopping the matching managed Gateway, completing supported repairs, checking the result, and restarting the same service. It can recover supported legacy approvals and databases, preserve valid scheduled jobs and current Voice Call settings during migration, and explain which original material remains available when a repair cannot finish.That ownership remains narrow on purpose. Plain diagnostics stay online, an already stopped service stays stopped, and ambiguous or foreign service ownership, unreadable configuration, unrelated database drift, active writers, and incomplete workspace migration remain fail-closed. This is a clearer repair path rather than a promise that every platform or damaged state can be repaired automatically.
Busy Gateways now spend less time repeating work while sessions are renamed, histories are opened, task pages are listed, scheduled work is checked, or several agent turns are running at once. Large session listings retain less memory, unusually branched histories no longer repeat the same ancestry work, and bounded operator requests get a fairer chance to start before returning a retryable overload result.Shutdown also stops admitting outbound retries that have not started yet, leaving them queued for the next process while an already started provider attempt can finish. These improvements are limited to these Gateway paths and do not remove every delay under sustained load.
When recovery needs a person, OpenClaw now does a better job of saying what happened without exposing the thing it is trying to protect. Offline triage can still produce a sanitized archive, embedded triage stays bound to the installation and paths being diagnosed, status and log commands retain the actual redacted failure, and short Control UI errors no longer repeat themselves in empty detail panels.Recovery inside the Control UI is clearer too. A stale unconfirmed browser message can be discarded so later queued input can continue, offline split-pane drafts remain recoverable, and canceling a queued-message edit after reconnect resumes the original queue without replacing the composer draft. Discarding the browser copy cannot prove or reverse work the Gateway may already have accepted, so the interface treats it as local recovery rather than rollback.

Messaging

Voice, media, and channel conversations now do a better job of reaching a clear ending and staying with the person and chat that started them. Spoken replies survive more delivery handoffs, calls and Browser Talk keep turns in order, attachments and plain text retain their intended shape, and account-specific failures no longer have to take every healthy channel down with them.
Browser Talk now waits for microphone permission before opening its connection and explains what it is waiting for instead of appearing stuck. Once the conversation begins, spoken questions and answers stay in order when transcription arrives late, a transcription failure can be shown without closing the call, and interrupting a Google Live response no longer ends the next turn by mistake.Default sessions also keep the configured agent, transcript, and consultation together, generated consultation instructions no longer appear as a second message from the user, and later spoken requests can continue after the first exchange.
Spoken replies now make it through more of the places where successful synthesis could previously disappear or be mistaken for an unfinished answer. Private Discord and Telegram replies can deliver one permitted built-in TTS voice note while keeping private final text hidden, long replies leave internal reasoning and known tool-status text out of the audio, and delivered speech can finish the turn without a misleading warning or an unnecessary second request.Speech created during Code Mode, Tool Search, or Codex work also has a clearer path into the final reply, while audio that finishes only after the request has timed out stays withheld.
Voice Call now drops an obsolete automatic answer when the caller starts speaking again, and an old call stream can no longer disrupt the current reply. Late provider updates stay attached to the original call with its transcript, duration, and agent, while a failed first save no longer dials or consumes the only call slot, so restoring storage access is enough to try again.
Images already visible in a Control UI conversation now remain in place through a hard refresh instead of flashing out and shifting the thread while history reloads, while removed or inaccessible images still disappear. Empty local text files show that there was no text to extract without hiding later attachment explanations, and text files with quoted or escaped character-set labels decode as their intended text instead of replacement characters.Affected AVI video and ASF or WMA audio also return to their existing playback-conversion paths instead of falling back as unsupported.
Plain-text replies now keep visible code in the right place when surrounding formatting contains hidden code-like text, and paragraph or section formatting keeps its intended breaks instead of running adjacent text together. That makes affected default Telegram and direct text or media replies easier to read without changing their rich-message path.
When a turn has already finished its tool work, OpenClaw now makes another attempt to produce the final answer and, if the model still gives it nothing usable, leaves one clear fallback without rerunning completed actions. Accepted channel turns that fail before an answer also end with one compact error instead of a progress marker followed by silence.In Discord and Slack, long turns are calmer too, with one stable acknowledgement, useful milestones, and prompt approvals or failures instead of a running list of every tool action.
iMessage direct replies and actions such as polls now stay with the conversation that requested them when the service setting is unset, while a redacted display value is no longer retried as though it were a real destination. In multi-bot Discord rooms, the opt-in other-mention filter also keeps OpenClaw out of replies aimed at another bot unless someone explicitly mentions it.Telegram keeps rich-button labels in reply context and keeps its model picker usable after a configuration reload, while long WhatsApp replies keep their formatting and quote context across split messages. Slack Enterprise Grid plugin approvals now stay with the intended workspace from the direct message through the approval click.
LINE now stays quiet when another connected service controls the chat, and a bot joining a group or room responds only where it is allowed to serve. Shared group rules also carry into named groups and rooms unless that conversation has its own setting.The conversation itself carries more of what the person sent and what the operator configured. Inline emoji no longer collapse into bare parentheses, multi-part replies follow the selected agent’s pacing, and configured users, groups, and rooms are available when choosing where to send a message.
One unavailable or disabled channel account no longer has to hide the health and status of every other channel, and recovery now explains whether an account start was handed off, left busy, or skipped. When repeated startup failures put OpenClaw into safe mode, an operator can manually restart a configured account without first running an undocumented repair step.That separation carries through the rest of the channel’s work. Matrix can finish room activity while an account stops or restarts, Doctor preserves the supported QQBot multi-account layout, and SMS work stops when its credential disappears or is replaced. Messages and actions from an installed channel plugin also stay with the plugin the operator selected.

Memory

Memory and large retained histories now avoid more unnecessary work without changing the information available to the paths that need it. Memory Wiki rejects invalid operations before changing a page, local scans stop importing generated copies of their own vault content, and several long-session paths hold less transient data while they prepare context or inspect history.
Memory Wiki now rejects unknown operations before changing or synchronizing a page, and local scans stop importing generated copies of its own vault pages again. Canceled Memory requests return the original cancellation error, while the optional database-backed memory plugin starts with less memory and keeps the same three tools.Long native Codex conversations and detached Skill Workshop reviews also prepare the context they need without loading as much history that the model will never see. Resuming, listing, cleaning up, and checking large session stores does less unnecessary work while keeping the full history available to the paths that need it.

Skills

Skills added after OpenClaw starts are easier to pick up on the next turn, including new project and workspace skill directories that no longer require a Gateway restart. Skill metadata remains strict but more readable, and malformed Skill Workshop proposals can be rejected or quarantined without trusting or applying them.
Skills added after OpenClaw starts are easier to bring into the next turn. A new project or workspace .agents/skills directory is detected without restarting the Gateway, Windows path casing no longer changes which source a skill belongs to, and colon-rich plain text in the approved description, read_when, and summary fields remains readable without relaxing structured metadata.Skill Workshop can also reject or quarantine a malformed proposal without trusting its draft, while actions that would revise, evaluate, or apply that content still fail closed. That makes disposal possible when a proposal is missing, altered, oversized, or linked somewhere unsafe without turning the recovery path into permission to use it.

Native Apps

Linux users now have a desktop companion for x86-64 systems, available as a .deb or AppImage, that connects to a local or remote Gateway and puts Quick Chat in the system tray or behind an X11 keyboard shortcut. Native Codex sessions can also be continued, opened, viewed, or archived with less unrelated discovery work, and compatible conversations survive app-server restarts more reliably.
Known local Codex sessions in a large home can now be continued, opened in a terminal, viewed, or archived without scanning unrelated rollout history first, and compatible conversations can return to the same thread after the app server restarts. A fresh Codex thread also carries forward facts preserved only in a saved compaction or branch summary, while token counts and the effective context window recover after /new instead of looking like a fresh zero.

Models and Providers

Model and speech-provider setup now stays more closely aligned with the provider, login, voice, and transport that actually own the request. Catalog failures retain the last healthy information, pinned models use their intended retry budget, configured private speech endpoints stay scoped to their origin, and automatic language detection no longer inserts an English instruction when no language was chosen.
Voice and transcription settings now reach the service they were meant for more consistently. OpenRouter and DeepInfra speech honor the configured voice, Voice Call and Talk can find eligible configured providers, Talk clients can use advertised transcription models, and TTS personas can use credentials stored through SecretRefs without borrowing another provider’s key.For multilingual voice notes, leaving the language unset now uses automatic language detection without inserting an English instruction into the transcript. xAI transcription can accept silence as an empty result and continue to a configured fallback, while private or self-hosted xAI setups can use their configured address for voice discovery and buffered speech.
The model list and the request it starts now agree more often about which provider and login own the work. Authenticated Claude CLI models found in the full catalog can be selected before the first turn, native Claude login remains in charge when an unrelated Anthropic credential is stored, and simple completions retain the provider transport chosen during preparation instead of borrowing a different connection at dispatch.When a provider fails, OpenClaw keeps more of the useful context needed to recover. Chat, the terminal UI, and Gateway history can use guidance for the provider that actually handled the run, malformed catalog responses no longer replace the last healthy OpenRouter capability data, and pinned models use their full same-model retry and profile-rotation budget without quietly switching models. Chutes and Cerebras catalog estimates can refresh without overwriting operator-set rates, but catalog entries and estimated prices are not proof of account entitlement, paid inference, or a provider invoice.

Automations and Scheduling

Longer-running work is easier to steer without losing track of who owns it. Supported active tasks can accept permission changes, human approvals and corrections move ahead of agent-to-agent traffic, Stop catches more selected child work, and scheduled jobs report the outcome that actually settled instead of treating dispatch alone as success.
Supported native and Codex work can now take a permission change from the Control UI while it is active. The interface shows that the change is being applied, closes old approvals, and keeps the conversation in place instead of making you manually stop and continue the task.Human approvals and corrections also move ahead of agent-to-agent traffic in busy sessions, while Stop catches the selected running and waiting helper-agent work beneath the task you chose. Finished helper work that cannot deliver its result leaves one recoverable follow-up alert, and messages sent between sessions say whether they were queued or added to work already in progress.
When several agents share one OpenClaw installation, replies, commands, tasks, plugins, media, and connected conversations now stay with the agent that owns them more consistently. The same ownership follows work into shortened conversations, detached reviews, and coding tools, so one agent is less likely to answer with another agent’s context or permissions.Unattended work can now find and organize other sessions owned by the same agent without extra setup, and connected coding sessions keep same-named work separate when different agents resume, control, cancel, or clean it up.
Automation results now line up more closely with the work that actually finished. Scripts waiting for a scheduled run receive the complete machine-readable result before the command exits, jobs that wake an agent record the result of the work rather than treating the wake-up itself as success, and screen readers and tooltips name the scheduled job behind each row action.

Browser and Computer Use

Browser control can stay available through a paired local relay on supported macOS and Linux builds even when the Gateway is not running, while managed pages expose useful controls sooner. Cloud and remote work can reuse prepared projects, stop and clean up more deliberately, recover edits after a restart, and report failed sandbox or worker stages more clearly.
When an agent edits or searches a workspace, more of what was actually on disk now survives the trip. Patches preserve untouched content and line endings, formatting-only edits are no longer silently discarded, search results keep readable context from files that previously looked garbled and from unusual filenames, and local names beginning with @ stay literal when that file or directory exists.Normal replies also respect how much tool progress each agent is set to show, and ordinary requests are less likely to be diverted into an irrelevant answer about the current model.
On supported macOS and Linux extension builds, a paired Chrome extension can wake an authenticated local relay even when the Gateway is not running, and the Gateway can join that relay later without taking the browser session away from other authenticated clients. This is not yet established for Chrome Web Store v2.2.0, Windows still requires manual relay setup, and commands through the browser CLI still need a running Gateway.Once connected, managed Chromium can return actionable page controls without spending the whole request waiting, and browser automation keeps more nested workers and frames attached while a page is running.
Cloud sessions can prepare a Git project and runtime once, then let later sessions reuse verified pieces while still receiving current edits, attachments, and fresh enrollment. The first session still does the preparation and capture work, so the improvement is less repeated setup for later sessions rather than a promised startup time.Crabbox project snapshots now wait for the prepared image to settle before a worker enrolls, keeping failed or uncertain capture in recovery instead of letting work continue against an image that may not be ready.
Stop now closes queued and new work earlier, interrupts supported provisioning, waits for the resources it owns to finish cleanup before reporting success, and can resume accepted cleanup after a Gateway restart.An initial message that never reached the worker stays marked as not sent for a deliberate retry, while repeated Stop requests share the same cleanup instead of starting competing teardown work.
Cloud sessions can recover legitimate workspace edits after a Gateway restart, and stale results now settle into a recoverable outcome or a clear failure instead of leaving the session stuck waiting to finish. Archive, delete, and recovery actions can also complete without getting trapped behind an earlier worker move.Accepted browser follow-ups survive a restart or reload, and delivery receipts can confirm input that the Gateway already consumed. Input whose delivery remains uncertain is held for an explicit resend instead of being replayed automatically, while cloud execution errors keep the original failure visible and report workspace-recovery trouble separately when remote edits may not have returned.
Remote sandboxes running on supported Python 3.9 environments now preserve complete file and attachment bytes, while guarded HTTP 308 redirects from Codex sandbox requests keep their request body and the existing destination checks.When optional container hosting or Crabbox bootstrap fails, operators also get a redacted error that identifies the failed stage instead of a worker that looks ready or a generic aborted message.

Plugins and Integrations

Plugins now load and update more reliably across common package layouts while preserving explicit pins and capability review. Doctor and the registry give more useful repair guidance without guessing, and Beam transcript sharing keeps conversation order, publisher identity, and receiver changes clearer.
Packaged TypeScript plugins now choose a runnable compiled entry more consistently across common build layouts, and file-URL entry points can load and refresh through the native loader, including the Windows path that previously failed. Exact beta updates keep eligible official plugins aligned with the beta core that was actually installed, while explicit selectors and third-party pins stay in place and a missing matching artifact remains a visible warning rather than proof of alignment.A managed update waiting for capability review keeps the previous plugin and stops before restarting, while npm failures that produced no output now identify the timeout, signal, or exit that ended the command. Published Plugin SDK imports and older command categories also remain compatible across the upgrade, without bringing retired docking features back.
Plugin repair is more useful when it refuses to guess. Doctor and the registry CLI now show which persisted plugin records differ, verify a manual refresh before reporting success, and only suggest an exact npm repair target that exists. A verified stale linked-plugin record can also be removed after the healthy configured-path replacement is confirmed, without weakening uninstall ownership checks.Two trust boundaries remain important. Migrated compatibility allowlists preserve bundled providers and explicit denies, but the landed repair retains an automated-review concern around mixed eligibility and scoped environment propagation. A bundled plugin selected through a configured path also keeps its bundled behavior across built and unbuilt states, but ignored dist or node_modules descendants beneath a bundled tree may still inherit bundled trust, so this release does not establish that nested path boundary as safe.
Shared Beam transcripts now keep questions before their answers and show the verified person who published the snapshot instead of borrowing the viewer’s identity.Automatic shares keep the conversation readable while leaving out reasoning and tool details, masking known credentials, and showing when part of the transcript was left out. Changing the receiver starts fresh delivery to the new destination without carrying unfinished updates across, and readable links can use the session title while old links still open the same transcript.

Security and Privacy

Several lower-level safeguards now fail earlier and reveal less. Oversized MCP responses and events are bounded before parsing, routine diagnostics keep ClawDock credentials out, long-secret redaction stays safe within its supported size, and optional image components move to patched dependency versions without making them mandatory.
Gateway integrations now reject an oversized MCP HTTP response or individual SSE event before parsing it, while healthy long-lived streams can continue beyond that amount in total. ClawDock inspection keeps credential values and prefixes out of ordinary diagnostics, and redaction handles accepted long secrets without crashing.Optional image decoding now uses patched Sharp 0.35.4 and libheif 1.23.2 components without making Sharp mandatory. A standalone @openclaw/memory-lancedb installation can still resolve an older Sharp through its optional Transformers path, so the dependency repair should not be read as universal coverage. Bun 1.4 Gateway connections also use the installed npm WebSocket receiver.

Maintainer and Internal Changes

Another 382 changes in v2026.8.2 primarily affect the people who build, test, document, and release OpenClaw rather than the everyday product experience. They cover CI and test maintenance, internal refactors, release and package validation, generated metadata, documentation upkeep, and other behind-the-scenes work, so they stay out of the release story above while remaining part of the complete record.
This completes the accounting for all 794 analyzed PRs and commits in v2026.8.2. The collapsed list below contains the 382 maintainer-only changes that do not belong in the user-facing product sections.