Mermaid diagrams now render directly inside conversations in the Control UI, Android, iPhone, iPad, and Mac, and Android gains a fuller chat and session experience. Updates preserve more of a working setup and stop before a known problem becomes a broken restart. When an update does fail, OpenClaw gives you a clearer path back to a working installation. Testing also found lower memory use and less repeated work while OpenClaw handled long conversations and large installations.Release scale: 922 pull requests, 6 direct commits, and 241 contributors.
Getting OpenClaw running now takes a shorter path when the machine already has usable AI access, while longer setup paths leave existing choices and files alone when a check fails or a different route is selected. This release also tightens Windows installation, macOS AI setup, shell configuration, Connect handoffs, and managed local-model downloads.
Quick Start to the Web Dashboard
On a fresh local install, the recommended Quick Start path can reuse verified Claude Code or Codex access, or an existing provider key, and open the web dashboard after one choice. The installation and guided setup flow keeps the Gateway in the current terminal until you stop it with Ctrl+C, preserves the configuration afterward, and leaves background service installation as an explicit later step.On a headless machine, the same path provides a one-time authenticated dashboard link and an SSH tunnel template instead of exposing reusable Gateway credentials. Custom setup, remote Gateway onboarding, and non-interactive setup keep their existing paths when Quick Start is not the right fit.
Provider Choices and Setup State
Guided onboarding can once again configure custom and local providers, including endpoints that do not need an API key, and verifies a real response before making the new model active. Failed or cancelled checks leave the previous configuration alone, while setup reruns preserve an existing agent roster and workspace instead of attaching temporary verification work to them.OpenClaw also compares the CLI’s selected state and configuration paths with the local Gateway before guarded setup actions. When a mismatch is proven, it shows both locations and a command that targets the Gateway’s store before credentials are written; offline setup remains available when there is no installed service to compare against.
Windows Installation and CLI Backends
Windows PowerShell 5.1 installation no longer treats harmless npm or Corepack warnings as command failures, and the portable Git bootstrap can complete without an interactive document-parsing step when Git is not already installed. The warnings remain visible, real nonzero exits still fail, and PowerShell 7 keeps its existing download behavior.Eligible npm-installed CLI backends can also be selected by their ordinary command name during Windows onboarding. OpenClaw now follows the platform’s PATHEXT lookup while retaining the neighboring POSIX launcher used by Git Bash, so there is no need to hard-code a .cmd path or delete one of npm’s shims.
AI Setup on macOS
The macOS AI setup sheet now shows the selected provider and the actual installation or verification activity instead of presenting an elapsed-time percentage as progress. Input controls appear when the setup needs an answer, capability consent remains explicit, and late responses from an older attempt no longer replace the current setup state.When someone declines capability review or cancels activation, the app now says that setup was cancelled and offers a clear retry instead of calling it a Gateway failure. Failed or unconfirmed cancellation stays visible, so another connection can be chosen without mistaking the outcome for a completed setup.
Shell Setup and Connect Handoffs
When an npm install fails, the shell installer still shows the useful terminal details and npm’s durable debug log, but no longer points to a temporary installer log that has already been removed. Shell completion installation and reinstall also preserve literal cache paths containing quotes, dollar signs, or backslashes across Bash, zsh, Fish, and the emitted PowerShell command, without replacing unrelated profile commands.The existing openclaw connect command is easier to find in the CLI reference, and its target-file handoff now accepts bounded regular-file inputs without deleting a rejected, unreadable, or oversized file. Successful regular-file and symlink handoffs retain their single-use behavior, while failed inputs stay available for inspection or recovery.
Managed llama.cpp Installation
Managed llama.cpp server installation remains automatic, but downloaded ZIP and TAR archives now pass through the bounded extractor used elsewhere in OpenClaw. Malformed or hostile archives fail without writing outside the installation tree, archive-provided links are skipped, and the required loader aliases are recreated as contained regular files.
The Control UI now gives visual answers, active work, and long-running conversations more room to behave like one workspace. Diagrams render where they are discussed, starting or returning to a session takes less waiting and repeated work, and the interface does a better job of holding what you sent, your reading position, and the agent or session you were actually looking at.
Mermaid Diagrams Inside the Conversation
Completed Mermaid fences now render as diagrams directly in chat, with the exact source, copy, expansion, and zoom controls kept beside the result. The diagram follows the active theme and stays in place while the rest of an answer arrives, so a flowchart or sequence diagram can be read without moving it into another tool.The renderer is lazy-loaded and isolated from the rest of the page, and model-authored output is reduced to passive SVG before display. Incomplete fences remain code, while invalid, oversized, or externally dependent diagrams fall back to readable source with an error instead of being treated as a successful render.
Starting, Switching, and Repairing Sessions
New Session now puts the first prompt and its images on screen as soon as you send them, keeps the draft available if creation fails, and moves into the confirmed conversation without an extra lookup. Chat and New Session also load fewer closed workspace features up front, while larger session lists do less repeated sidebar work when you switch between conversations. Those performance results come from controlled local and synthetic large-roster tests, not a promise that every browser or Gateway will see the same speedup, and the measured warm Chat path included a small composer-readiness regression.Returning to existing work is steadier too. Dashboards and background tasks stay with the selected agent, interrupted or timed-out sessions show a more truthful state, failed cloud or device sessions can be restarted from Chat when a compatible target is available, and Ask OpenClaw keeps the conversation and draft visible while its runtime is repaired. Sidebar groups, hovercards, assignment menus, status icons, and keyboard navigation make large or multi-agent workspaces easier to scan without changing the underlying session, permission, or placement boundaries.
Conversation Order and Reading Position
The chat transcript now holds together more consistently as live events become saved history. Reconnects and refreshes keep one copy of a completed answer, queued prompts stay above the replies they produced, commentary remains distinct from the final answer, and manually taking over the scroll position is less likely to be undone by delayed layout work. Compaction now appears as one calm inline marker that settles into a durable completed state instead of splitting itself across temporary and saved notices.The composer is less fragile around the edges of an active turn. You can begin the next prompt immediately after sending, remove queued input without a false storage warning, keep late dictation after pressing Stop, and reply to attachment-only messages with a useful reference. Sent images remain visible while history takes ownership of them, Office attachment failures no longer wedge later turns through known display blocks, and silent command failures or plugin-delayed final replies still leave timely, visible progress or warning text.
Everyday Workspace Polish
The surfaces around the conversation have had the same attention. Dashboards fill narrow screens, long task progress and Review content use the space available to them, settings show useful loading shapes, and the model picker, agent picker, Side chat, Appearance, Usage, publication controls, and pull request previews are easier to scan. Keyboard menus recover cleanly, scrollbars remain visible beside fades, stale assets are less likely to survive a cache check, and smaller initial Settings data leaves more startup headroom without claiming a measured end-user latency gain.Accessibility and authority state are clearer in several places, including a stable localized name for the composer, reduced-motion loading indicators, properly displayed wildcard tool policies, named approval requesters, optionless credential prompts, and specific recovery guidance for trusted-proxy sign-in failures. One regression remains in the sidebar. Shorter pin and unpin tooltips also became the icon buttons’ accessible names, so assistive-technology users can lose the session-specific context that used to be repeated there.
Updates now make a clearer distinction between work OpenClaw can finish safely and work that needs your attention first. The updater protects more of the setup already on the machine, hands service-owned restarts to a process that can survive them, and leaves recoverable failures with enough context for Doctor or a configured coding agent to take over the investigation.
Update Readiness and Restart Handoffs
Before OpenClaw restarts, it now checks the parts of your installation that actually need to be ready for the new version. Missing local-memory setup, unresolved plugin consent, or incomplete approval migration stops the update with a specific repair path, while a migration warning that does not make required state unsafe can leave the Gateway reachable in a clearly degraded state so you can run Doctor instead of watching a supervisor restart it forever.Updates started by an agent on a managed Linux or macOS Gateway can hand the work to a detached helper before the service stops, and Windows agent-initiated restarts use the Gateway-owned restart path rather than dying with the old process tree. That handoff confirms the update was accepted, not that it finished, and npm 12 local archives still need a comma-free path.
Settings and State Through Updates
An update or Doctor repair now does more to preserve the setup you already authored, including configuration includes and environment expressions, agent rosters and workspaces, plugin payloads and policy, credentials, scheduled work, device pairings, and session history. When old and new state disagree, repairs either prove the change is safe or stop before writing, and concurrent Gateway work no longer gets silently replaced by an older Doctor snapshot.The same rule reaches the edges of maintenance. Interactive uninstall keeps local state and workspaces unless you explicitly select them, Windows snapshots work in mixed PowerShell installations, workspace exclusions are applied before backup traversal, and plugin recovery publishes a trusted install record only after it has verified what it is installing.
Doctor Repairs for Older State
Doctor can now resolve more of the old state that used to leave an installation stuck between versions, including empty legacy roots and approval stubs, stale workspace setup files, malformed scheduled jobs, incomplete Skill Workshop proposals, and narrowly safe database, roster, and workspace migrations. Repair stays deliberately conservative. Conflicting or populated state remains available for recovery, invalid cron jobs go to quarantine with their identity and reason, and successful repairs are designed to stay clean on the next pass.When Doctor cannot finish automatically, its diagnostics now point more directly at the thing that needs attention, including retained workspace files, plugin version drift, shared credential health, managed Tailscale ownership, and externally configured paths that a copied-state rehearsal can still reach. Long database maintenance keeps its lease while it works, and managed Tailscale upgrades can reclaim only the ordinary exclusive route that still points to the configured local Gateway.
Investigating a Failed Update
When an interactive update gets far enough to fail operationally, OpenClaw can now carry a bounded, sanitized record of that attempt into its existing triage flow instead of making you reconstruct the failure from scratch. The CLI can offer a configured Claude Code, Codex, OpenCode, or Pi session after updater cleanup, and the Control UI can open Ask OpenClaw with the recorded cause for an investigation-first conversation.That investigation does not get authority to retry the update, repair state, or restart the Gateway on its own, and a successful investigation does not turn the original update into a success. JSON, --yes, background, and managed-service runs remain diagnostic-only, preserving the original exit result while printing the next commands for an operator to use.
Messaging in channels is less about whether a reply was technically sent and more about whether it arrived in the right conversation with its context, controls, and final outcome intact. This release carries that work across approvals, thread routing, rich replies, queues, restarts, voice, and the failure paths that used to leave either the person or the operator guessing.
Approving Delegated Changes from Chat
When a delegated system agent asks to change OpenClaw configuration or plugins, operators can now approve or deny the request from a configured channel and see whether it was applied, denied, cancelled, expired, or could not be applied. The request remains tied to the run that created it, so closing that run also closes its authority to make the change, while Telegram keeps the approval and completion messages in the forum or direct-message topic where the request began.
Reply Context and Agent Identity
Replies now hold onto more of the context that made them meaningful. Microsoft Teams channel threads include their parent and sibling messages even when Teams omits reply metadata, cross-session deliveries are written into the receiving conversation, and LINE tells the answering turn whether a group message actually addressed the bot. Wildcard peer routes no longer change with lookup order, and Slack RPC replies keep the selected agent’s configured name and emoji.
Complete Controls, Cards, and Formatted Replies
Rich replies are less likely to lose the part somebody actually needed. Matrix and Feishu or Lark deliver offered controls, while LINE preserves card text, buttons, questions, and overflow choices when media is unavailable or a generated card is too large for the platform. Long task lists keep their structure across message chunks, and ordinary Markdown examples, citations, image URLs, and labeled links survive parsing without disappearing or triggering the wrong fetch.
Channel Queues Through Restarts
Several channel failures now recover without making a healthy conversation look dead. Telegram can move past a stale session start and acknowledges stored button presses before a busy chat finishes earlier work, while channel routes release cleanly during replacement, Matrix can repair an upgraded sync database with Doctor, and Slack Socket Mode or relay accounts no longer depend on an inactive HTTP-only secret. Failed configured channels remain visible as blocked with a safe recovery hint instead of disappearing from status and health.Older supported Feishu, Telegram, WhatsApp, and Matrix plugins keep dispatching inbound replies after the host updates, installed external channels work with generic message actions and broadcast planning, and narrower Slack lookup problems and Tlon parser stalls are repaired. These are channel-specific repairs rather than a claim that every transport now behaves identically.
Clear Outcomes for Delivery Failures
When delivery cannot finish, the result is now less ambiguous. Rejected webhook uploads across bundled channels receive their complete response before the connection closes, malformed Signal response text fails visibly, and an affected iMessage send explains that its bridge stopped responding and gives the operator the two recovery commands. Context-only prompts no longer hang at completion, while Discord thread replies split after mention expansion and avoid replaying an uncertain or partially accepted webhook delivery as a duplicate bot message.
Stopping Replies and Progress
Stopping or replacing a turn now does a better job of stopping the work and narration attached to it. Active link fetches and processors are cancelled with the reply, obsolete narration cannot update a newer draft, Control UI commentary reconciles as one update, and Slack waits for a complete first preamble while keeping quiet-preview settings quiet. Successful reaction-only and background work also avoid misleading missing-reply fallbacks.Discord follows the same final-outcome discipline in several focused paths. Cancelled voice consults remain quiet, model-picker choices report their real result, and ambient or message-tool-only work does not leak a session-busy warning that its reply policy said to suppress.
Voice Replies and Discord Voice Sessions
Discord voice capture now has one owner per speaker and stops oversized batch utterances with an actionable warning instead of accumulating memory or sending a partial transcript. For inbound WhatsApp voice notes, Codex dynamic replies can once again return voice when automatic inbound TTS is enabled, while later text-only turns remain text and the audio decision stays attached to the reply that received it.
WhatsApp Acknowledgement Migration
Doctor now says when a legacy WhatsApp acknowledgement setting could not survive migration exactly as written. It identifies a shadowed emoji, shows which shared emoji remains active, and warns when the old acknowledgement scope changes or cannot be represented so operators can review messages.ackReactionScope instead of accepting a misleading clean migration.
Memory now keeps rebuildable index work separate from the conversations people need to protect. There is a safe reset path that leaves sessions and transcripts in place, search avoids needless full rebuilds for healthy or ordinarily dirty indexes, legacy retrieval settings survive Doctor upgrades, and long conversations retain capture progress through compaction while closed transcript views release message text they no longer need.
Resetting and Rebuilding Memory Indexes
Built-in Memory now has an explicit openclaw memory reset path that discards only rebuildable index data for one agent or every configured agent while preserving sessions, transcripts, memory source files, and other durable agent state. It asks before acting, requires --yes in non-interactive use, treats an absent or empty index as a successful no-op, and refuses to race indexing already in progress.Full reindexes are safer around that path. Replacement caches are bounded before publication, failed full rebuilds leave the previously published cache intact, a memory change during automatic maintenance gets one retry against current content, and abandoned workspace locks can recover after process-ID reuse. Recovery messages identify whether an incompatible index belongs to OpenClaw or configuration, warn when an explicit rebuild may contact a paid embedding provider, and retain the unreadable source path; ordinary replies remain available while a legacy index is repaired in the background, and combined memory and wiki searches continue to show the affected agent’s repair instructions.
Search Without Needless Rebuilding
One-shot openclaw memory search commands can reuse a healthy persisted index and exit instead of starting indexing work after they already found the answer. The command still checks its sources, so a real change starts maintenance and becomes searchable rather than leaving the clean state frozen forever.When an index is dirty, ordinary memory-file and session changes can be applied incrementally while searches remain available instead of repeatedly selecting a full rebuild. Workspace discovery also skips symlinked and other non-regular memory entries rather than allowing one linked USER.md to abort indexing for every regular file.
Retrieval Settings and Embedding Providers
Running openclaw doctor --fix on an older configuration no longer silently drops an agent’s knowledge paths or session-memory choices and falls back to global defaults. Custom OpenAI-compatible embedding providers can also resolve a saved API-key or bearer-token profile before indexing or search, while invalid or unavailable bindings stop before a network request rather than selecting a different credential.The packaged local path is less fragile too. The official Linux x64 Docker image now includes the runtime needed for managed llama.cpp embeddings to pass their executable preflight, and malformed Amazon Bedrock embedding responses produce a clear error instead of being accepted through replacement decoding.
Visible Recall Outcomes
On eligible private-chat turns, Active Memory now tells the main model when deep recall was intentionally skipped or unavailable, so an absent lookup is not mistaken for a successful search that found nothing relevant. The note stays bounded and leaves provider errors and sensitive search details out of model context.Memory Core Dreaming also carries an explicitly selected agent through deep consolidation in multi-agent setups, letting recalled facts consolidate under the right owner instead of silently falling back to append-only storage. When no owner is available, that safer append-only fallback remains.
Memory Capture in Long Conversations
LanceDB auto-capture now keeps its place when a long conversation is compacted, avoids embedding facts it has already handled, serializes overlapping capture for the same conversation, and lets in-flight automatic capture finish before the plugin closes. New facts are less likely to disappear behind retained messages after compaction.Large transcript scans can begin processing without first retaining every message payload, while each active chat view owns the recovered full text it needs and releases that text when the view closes. Split panes keep their own valid content, so closing one does not strip the conversation from another that is still open.
Skills are becoming something a team can own without turning the host into a ticket queue. People sharing a Gateway can keep their own libraries, share work deliberately, and carry the exact selected revision into the session that needs it, while overwrites, policy failures, and optional runtime dependencies leave clearer recovery paths.
Personal Skill Libraries for Shared Teams
Signed-in teammates on a shared Gateway can create, import, update, and reuse skills without host access. A library starts private, sharing does not hand over edit rights, and ownership can move to a team when the skill itself becomes shared work, so routine authoring no longer has to pass through an administrator.ZIP imports now reserve room across profiles as well. One person with many unfinished uploads cannot occupy every pending slot, while existing uploads can still finish and linked or merged identities continue to share one allowance. Each session also keeps the immutable skill revision that was selected, including its supporting files and executable permissions, as work moves through local, sandbox, cloud, or node workers.
Skill Editing, Migration, and Runtime Checks
Claude migration can overwrite a generated skill without making local edits disposable. migrate apply claude --overwrite now backs up the whole target skill directory, records the recovery path even if a later write fails, and checks that the command source still exists before changing the target.The surrounding runtime reports and installs are more truthful too. Source-run Gateways can load compiled OpenAI and Memory Core plugins again, context-free harness checks distinguish allowlist, denylist, and disabled-plugin policy from a missing installation, and copied hook packs attempt the optional runtime packages their handlers need.
The native apps take two visible steps forward in this release. Android gets a much fuller everyday workspace for chat, sessions, navigation, and appearance, while Android, iPhone and iPad, and macOS can turn Mermaid source into readable diagrams inside the conversation. Around those larger changes, reconnects hold on to accepted work, voice stays with the turn that started it, and several platform-specific setup and helper paths handle failure more cleanly.
Android’s Fuller Everyday Workspace
The Android app now brings the pieces people reach for during a normal conversation into one more complete native experience. The composer has a full-width writing area with compact actions, model names remain readable, and searchable controls expose models, effort, Fast Mode, and permissions without crowding the transcript. Sessions can be browsed or created from the native catalog, the sidebar can be arranged around the places you use, and theme families and accents stay with the correct profile through offline changes, reconnects, and app recreation.That work also keeps the app usable on narrow screens and with larger text, and it gives an actionable Providers and Models route before sending with an explicitly selected model whose authentication is unavailable. That check still follows the availability reported by the connected Gateway and is scoped to explicitly selected models.
Mermaid Diagrams Across Android, iOS, and macOS
Mermaid diagrams no longer have to be read as raw code in supported native chats. Android and iOS render completed diagrams inline with source, copy, retry, and expanded-preview controls, while macOS brings diagrams to both full chat and Quick Chat and keeps that window open while a larger preview is in use. Each app keeps readable source for streaming, invalid, oversized, or temporarily failed diagrams instead of replacing it with an empty box.Rendering stays local rather than depending on a network diagram service. Android offers a sharp full-screen view with zoom and pan, iOS adds an offline-capable vector preview with zoom, pan, and rotation, and macOS uses compact desktop controls with native Close and Escape behavior. The exact controls follow each platform rather than pretending the three implementations are identical.
Reconnects, Retries, and Queued Messages
Android now keeps the replacement Gateway connection in charge while an older connection finishes shutting down, so retired cleanup is less likely to publish a false offline state or discard an accepted request outcome. Messages acknowledged after reconnect move past Sending, a new conversation remains selected for the next message, later queued sends keep moving, and a queued message you delete stays gone even if an older refresh finishes afterward.The same ownership cleanup reaches other native conversation paths. Apple chat can retry immediately after a session-settings failure, iPhone history refreshes reconcile a streamed reply with its canonical transcript row instead of leaving an older duplicate, and native session progress cards retain the selected agent and workspace context.
Voice Ownership Across Native Apps
Talk and realtime voice now carry the acknowledged agent, run, and reply through the clients involved in the conversation, which keeps a consult on the intended agent, prevents an unrelated newer chat reply from being read back, and makes Stop target the work that actually started. Host cancellation is also reported as cancellation instead of a tool failure while the voice call remains open.On Apple Watch, dictated messages, spoken replies, playback, and retries remain attached to their original chat, and a spoken reply that outlasts the Watch’s wait points the user back to Chat on iPhone. Android offers an explicit voice-note recording path when on-device dictation is unavailable without discarding the draft, while macOS reuses a compatible speech recognizer, keeps the Talk overlay visible through a quick toggle, and packages the resources required by local MLX speech. The recognizer change removes one source of avoidable churn, but it does not establish that the broader open Apple speech-service memory report is fully fixed.
Apple App Setup, Chat Controls, and Watch Authorization
macOS onboarding now brings failed AI setup, rejected-key details, and the retry action back into view instead of leaving someone stranded between setup and chat. Once inside chat, a cleaner two-row composer keeps context, model, effort, voice, send, attachment, branch, and verbosity controls reachable in narrow windows without duplicating model and usage details in the toolbar.iOS now explains whether a model choice changes the current session, the agent default, or the global default, and it blocks unavailable choices or permanent authentication failures before a live send while still allowing offline queueing and temporary cooldowns. Localization coverage catches more dynamic macOS text and newer Apple controls, while a revoked or replaced Watch connection can no longer receive another command or submit a late result through the retired connection.
Desktop Setup and Remote Work
Fresh Linux desktop installs can again choose a Gateway on another computer before installing a local CLI, while local setup keeps its existing installer path. The desktop companion also receives a compatible local-discovery refresh, with its Windows updater deliberately held on the earlier version until an upstream cleanup conflict is resolved.Remote and supervised work recovers in a few narrower places as well. Paired-node Claude runs can fall back to the node’s native Claude login when forwarded credentials are blank, SSH worker desktops avoid Unix-socket failures caused by long temporary paths, and completed Windows worker turns close their owned state before removing the runtime directory so the slot can be reclaimed normally.
Native Packaging and Background Helpers
Several less visible repairs keep the apps from failing around dependencies and helper processes. iOS development can resolve the available WebRTC 152 package again, Android refreshes camera, image, diagram, local-storage, and math-rendering foundations while preserving its existing database schemas and stored state, and the Licenses screen now includes the missing packaged notices.Background ownership is tighter too. Native Gateway invocations no longer report a timeout after the operation has already settled, private node workers exit after their owned cleanup even when stdin or a plugin child keeps the event loop active, and macOS helper pipes accept short readiness messages while retaining split or final diagnostics from MLX speech, SSH, node workers, computer control, and cookie sync.
Choosing a model should not be an exercise in wondering what else the click changed. Model selection now tells you whether a choice is for this session, one agent, or the global default before it is saved, while provider logins and catalog changes flow into the model list without the ritual Gateway restart. This release also tightens the less visible part of that promise, so a temporary provider failure, a quiet Codex turn, or a disconnected node is much less likely to send work down the wrong route.
Model Selection, Defaults, and Reasoning
The Control UI now gathers the main model, utility model, first fallback, thinking level, and Fast Mode in one autosaving Defaults card, with the scope of a model change shown before you make it. It preserves the rest of an ordered fallback chain when the first choice changes, and refuses to replace a working model when the required harness cannot be activated. The full fallback order still lives in the CLI, and the scope disclosure is currently a Control UI feature rather than a native-app picker feature.Reasoning choices now stay attached to the runtime that actually owns them. Eligible Sol and Terra turns keep Ultra through supported child-session boundaries, configured native Codex models show the effort levels their account advertises, and Luna remains capped at Max. Anthropic Fable 5.1 joins the shared API and Claude CLI catalogs, supported local Ollama routes remain selectable, and status views keep an authored context cap when a model runs through a provider alias.
Provider Accounts and Model Catalogs
Provider state is now much closer to what you actually configured. Model Provider settings stop counting unrelated web-search and extraction credentials as model accounts, externally authenticated OpenAI models remain visible without a second login, and compatible catalog updates survive both credential changes and hot reloads. A new provider login, a settings edit, or a compatible model change can refresh the inventory when it is next requested instead of leaving the old list in place until a restart.The recovery path is less mysterious too. OpenAI relogin can repair stale profile order, Doctor preserves custom-provider environment references instead of turning them into broken stored keys, forced login clears the credential owner it is meant to replace, and a changed provider priority reaches a running Gateway. Google and Vertex configuration can also restore their bundled provider plugin through restrictive allowlists, while read-only catalog work and GitHub Copilot authentication avoid loading discovery or agent-runtime work they cannot use.
Provider Usage and Price Estimates
Provider status now has one genuinely useful addition for xAI users, with OAuth-authenticated SuperGrok accounts able to show usage, reset time, plan, and prepaid balance in the usual status surfaces when xAI supplies them. API-key billing remains a separate bucket. DeepInfra and Anthropic Vertex estimates also follow their current advertised and regional rates more closely, but these are OpenClaw estimates rather than a change to what either provider bills.
Model Retries and Fallbacks
Temporary provider failures now have one bounded retry owner, so a brief outage can recover quietly while a persistent one reaches the normal profile or model fallback path, or gives you an actionable error, within the retry window. A busy session stops after the first model candidate instead of making every fallback look broken, while hard Anthropic and Bedrock refusals stop immediately with revise-and-retry guidance rather than resending the request. Doctor can also remove a stale automatic OpenAI route without disturbing an intentional model choice.The recovery details matter just as much as the retry count. Affected llama.cpp context-limit failures can compact and retry, OpenAI Responses conversations keep compact continuation when tool lists or safely admitted large-integer arguments change, and pre-output transport failures can resume after completed tools without running them again. Provider and context diagnostics now survive more of these paths, while the official failover guide matches the controller that actually owns them.
Codex and Claude CLI Work
Long-running Codex work no longer ends just because its progress is quiet, and finite time limits follow elapsed time without throwing away useful partial output. Idle Codex chats can resume while other chats and catalog reads share the same app server, and prompt-hook changes either take effect safely on the next persistent turn or stop before inference with a recovery path instead of silently keeping stale instructions.Claude CLI setup now works through supported mise and asdf shims, local Claude failures keep bounded credential-redacted diagnostics, and Claude CLI-backed utility models can produce digests, progress, and tool titles through the runtime that owns their authentication. Codex and CLI agents only offer remote shell execution when a connected node can actually run commands, existing broken harnesses explain which plugin needs attention, and the official plugin now aligns managed installs and checks on Codex 0.152.1. Claude Code session catalogs also avoid rescanning an unchanged projects tree on every poll, with the improvement depending on the size of the catalog, disk load, and watcher availability.
Local and Self-Hosted Models
Self-hosted model routes now behave more like services OpenClaw can actually live with. Existing llama.cpp-compatible web apps can fall back to /v1/models when their root models endpoint serves HTML or unusable data, managed diagnostics stop reading oversized response bodies without a bound, and OpenClaw waits for managed local model processes to stop before finishing shutdown. The shutdown proof is scoped to Linux and systemd, and the discovery fallback was exercised at the provider boundary rather than as a complete Unsloth inference run.
Provider-Backed Tools
Provider choice now carries more cleanly into the tools around a conversation. Native Model Studio and Qwen routes honor prompt-cache retention, a selected web-fetch provider no longer trips over credentials for providers it never intended to use, and Local CLI speech generation follows the request timeout. Corrupted Volcengine speech responses fail clearly, while eligible OpenAI OAuth accounts can again transcribe inbound voice notes and configured batch audio without a separate API key. OAuth entitlement and quota are still account-specific, and custom Model Studio proxies remain opt-in for cache markers.
Scheduled work now keeps more of its identity from creation through delivery. An automation can begin with the access somebody already configured, make it through a restart without quietly becoming a different job, and leave a result that is easier to find and understand afterward. Recurring work also gets a deliberate choice about missed jobs, while one-time jobs keep their separate recovery behavior.
Creating Automations with Existing Access
Configured Codex app-server users can create app-backed automations through the authenticated connection they already use, without preparing a second OpenClaw profile or supplying a separate tool allowlist. Reauthenticating the same endpoint keeps the automation usable, while a removed endpoint, changed connection identity, unavailable plugin, or newly disallowed app or tool stops before app work and leaves an actionable recorded failure.Creation now also returns the resolved announcement route or the reason it failed closed before the job is saved, so an operator can fix delivery before trusting it. Integrations that call CronService directly can switch a job between command, script, and agent-turn payloads without inventing omitted optional fields, while malformed environments remain rejected.
One-Time Schedules Through Restarts and Unusual Dates
One-time jobs keep their newer retry time when the Gateway restarts, and an immediate main-session job can still wake its selected agent when periodic heartbeats are disabled. Successful one-shot jobs configured for deletion are removed as expected rather than being left behind in a disabled state.Older schedules are handled more carefully too. Upgrades that have not yet completed the affected legacy migration preserve whether a job was enabled, malformed legacy rows are quarantined without preventing valid jobs from loading, and expanded-year one-time dates honor their selected time zone and display the correct year. The migration repair does not reconstruct enabled state for databases that already passed through the earlier faulty v13 path.
Choosing What Happens to Missed Recurring Jobs
Operators who do not want stale reminders, digests, or model calls after downtime can enable cron.skipMissedJobs: true. On startup, OpenClaw advances overdue recurring schedules to their next future occurrence and saves that decision before normal scheduling resumes. The setting is opt-in, so leaving it unset or false preserves the existing catch-up behavior, and one-time jobs are not skipped.
Heartbeat Routes, Quiet Replies, and Deadlines
Scheduled agent work now keeps model aliases attached to the selected agent, and system-owned heartbeats can reach their configured provider after a clean Gateway restart by using the currently published runtime. Long or unlimited heartbeat runs honor the configured deadline instead of inheriting a fixed ten-minute cutoff, while destination-only wakes retain the rest of the configured heartbeat behavior.The delivery edges are quieter and more accurate as well. An explicit NO_REPLY after successful tool work stays silent, the first-alert explanation appears only on the first alert for an isolated default route, and bounded agents_wait calls keep their requested duration when the system clock moves forward or backward.
Automation Links, History, and Alerts
An Automations link now opens the intended job and highlighted run even when that job sits beyond the loaded page or outside the current agent filter, with a visible lookup error when it is no longer available. Session-restricted operators receive complete pages and accurate totals for the run history they are allowed to see, while large name-sorted job lists avoid repeating the same locale setup for every comparison.Schedule and history durations also keep all meaningful units across locales, and a settled failure alert appears as delivered, not delivered, or genuinely unknown in the live job view. Confirmed non-delivery retains a bounded redacted error and the existing in-app fallback, while immutable run-history entries remain unchanged.
Completed Automation Session Cleanup
Successful isolated jobs now release their run ownership before removing an unused continuation session, avoiding the stale row and misleading competing-work warning that could remain after completion. Generated-media jobs use the same ordering before the final Gateway response, with cleanup kept to the lifecycle that owns the run.
Disabling Managed Scheduled Backups
openclaw backup disable can find the managed backup after its schedule has been renamed or moved beyond the first 200 jobs in a larger automation inventory. It follows the schedule’s stable declaration identity, so an unrelated automation with the same name is left alone.
Browser control is more predictable from the first local screenshot to an attached Chrome tab or a remote desktop. Standalone agents can reach the local browser without borrowing Gateway credentials, selected tabs keep valid commands through ordinary group changes, paired-machine actions report where they ran, and Chrome MCP endpoint checks happen before a connection begins.
Local Browser Runs and Screenshots
Standalone agents with the browser tool enabled now default to the local browser when no Gateway or node route was selected. Viewport, full-page, and element screenshots capture through the page session that owns the current device settings, preserving mobile scale and touch behavior, while an interrupted Chromium capture returns a recovery error instead of leaving later screenshots or resizes stuck.That host-first default is an intentional change for unpinned standalone runs. Anyone who relied on implicit browser-node discovery should select auto or an explicit node, and full-page capture after pinch zoom remains a Chromium edge case. Malformed form-fill requests also stop before changing the page and identify the unsupported field instead of silently accepting only part of the request.
Selected Chrome Tabs and Existing Sessions
Selected-tab automation now keeps newly admitted commands valid while older group lookups finish and while a new tab goes through normal group setup. Genuine access changes still revoke stale work, restored access can recover, and a tab created during a relay disconnect is cleaned up instead of being left behind.Existing-session attachments now use the reviewed Chrome DevTools MCP 1.8.0 release rather than following a moving latest tag. Custom launch commands remain operator-managed, while offline hosts need that exact package cached or an operator-provided executable.
Paired Computers and Remote Desktops
Commands sent to paired nodes now consider only connected machines that can actually execute them. OpenClaw selects a node automatically only when one eligible target remains, asks for an explicit choice when several qualify, and includes the effective node in successful, failed, and timed-out results instead of silently redirecting work to the wrong computer.Computer input is more faithful to what the agent and user can see. Successful typing and key actions on paired macOS Peekaboo nodes report success after the action occurs, screenshot-grounded clicks share one bounded frame across unusual capture shapes, smaller-Mac Settings can resize and scroll, and multiline WebVNC text keeps its line breaks. Windows remote-desktop handoff retains the authenticated TightVNC viewer until its replacement is ready, while large macOS CUA Computer responses use less temporary memory without changing the existing response limit or setup.
Browser Policy and Private Talk Context
Custom Chrome MCP endpoint arguments now pass through the same hostname policy as the endpoint OpenClaw will actually use, before a subprocess or network connection begins. Unsafe, malformed, empty, duplicate, or conflicting arguments fail clearly without echoing credential-bearing URLs, while trusted overrides and host-local attachment continue to work.New Browser Talk conversations also keep the internal consultation question, context, and speaking instructions out of later model turns while preserving genuine speech, assistant results, and lossless exports. Existing unflagged records are not rewritten, and the separate decision about how a consultation answer should be presented remains open.
Search Dates and Presented Browser Output
Brave and Tavily search results now preserve valid absolute publication dates in the existing published field, helping freshness-sensitive work distinguish when a source was published without treating relative ages, fetch times, arbitrary text, or search filters as publication dates.Agents also receive clearer guidance for presenting a widget, dashboard, portal, or separate browser preview. The guidance keeps token-bearing launch links private, uses the presentation surface that is actually available, and says when an interaction was not verified. This changes how existing tools are described and selected, not what they can render or which tools are available.
Plugins now behave more like installed software that stays under the operator’s control. Updates preserve reviewed state, managed provider removals remain removed after restart, channel setup follows the agent that was actually selected, and the integrations around them do a better job of keeping credentials, errors, and cleanup inside the right boundary.
Plugin State Through Installs and Updates
Verified first-party plugins can move through installation, updates, re-enablement, and Doctor repair without stopping for a capability prompt that OpenClaw can already resolve from matching catalog, package, and source identity. That exception remains deliberately narrow, so local artifacts, third-party packages, custom registries, and conflicting or incomplete provenance still require explicit review.Older installs also behave more predictably. Capability acceptance is saved against the replacement artifact during a legacy update, reinstalling a deliberately disabled plugin leaves it disabled until the operator enables it, and registry or inventory reads no longer mistake build-only metadata for a changed plugin. Catalog work does less repeated processing, bundle capabilities remain visible in JSON and verbose inventory, and complete POSIX source builds keep their external plugin dependencies after the checkout moves.
Uninstalling and Repairing Plugins
Uninstalling a managed provider plugin now means it stays uninstalled after the Gateway restarts, even when an old model, provider, or channel choice still refers to it. Reinstalling later does not silently reactivate it, so the final enable step remains an explicit operator choice.The recovery paths around removal are safer too. Exact orphaned path-source records can be cleaned up through the normal CLI instead of by editing OpenClaw state, another plugin’s channel configuration is preserved during that cleanup, and versionless scoped ClawHub packages produce the expected warning when existing Claws still depend on them. Malformed archive names no longer derail staging, while updated 1Password guidance explains how to recover after Homebrew moves the op executable without pinning another disposable path.
Channel Setup for the Selected Agent
Multi-agent operators can select the intended agent for channel add, channel-specific capabilities, login, logout, remove, and resolve, with that workspace retained while OpenClaw discovers, installs, or reloads the channel plugin. The existing System Agent, sole-agent, and legacy-owner rules still apply when no selector is supplied, while ambiguous or invalid ownership stops before authentication or setup begins.Channel status also stops advertising accounts that were explicitly disabled, and Twitch’s outbound setup error now names the real accessToken setting. The separate Twitch connection-time diagnostic still needs the same wording correction.
Personal GitHub Accounts and Authenticated Dashboards
People sharing a Gateway can connect their own GitHub account from Profile and explicitly choose it for Publish PR without replacing the System account or an agent account. Publication remains bound to the signed-in owner, selected connection, authorized session, and accepted worktree state, and an uncertain publication can be confirmed by that same owner after a restart. This does not replace ordinary shell credentials or turn a personal publication connection into a general GitHub identity for agent commands.Gateway-hosted commands that use a managed GitHub profile stay with the credential selected at process launch. If that profile disappears or loses its token, later commands stop with reconnect guidance instead of falling back to a native account, while already running commands retain their launch credential. Dashboards can read GitHub Actions through a repository-scoped grant and the owning agent’s authenticated access without exposing a token or creating a general authenticated proxy; existing anonymous widgets need to be updated or regenerated, and Publish PR credential checks may remain cached for up to 60 seconds.
WhatsApp, QQ Bot, and Weixin Plugin Updates
Source-built Docker images now include the WhatsApp runtime when it is explicitly selected, rather than accepting the choice and producing an image without the channel. Existing QQ Bot installs recorded under the former @openclaw/qqbot package can move to @tencent-connect/openclaw-qqbot 2.0.3 while preserving channel configuration and credentials, with failed updates leaving the working legacy record in place.Catalog-driven Weixin installs now select the SDK-compatible 2.4.8 package, and affected 2.4.6 operators have explicit update and restart guidance. The evidence verifies package selection, integrity, and compatibility rather than an authenticated Weixin message roundtrip.
Voice Call Setup and Feishu Document Results
Voice Call setup now catches a missing response owner before telephony resources start on a multi-agent installation and points directly to plugins.entries.voice-call.config.agentId. Single-agent and explicitly owned setups keep their existing behavior, while affected multi-agent operators need to rerun setup and restart the Gateway after choosing the owner.Voice Call diagnostic commands now stream large custom logs with backpressure, follow rotation and truncation more carefully, and honor whether SQLite history should start with retained records or only new ones. Feishu document actions also stop counting rejected access grants or image replacements as successes, while retaining a document that was created successfully and continuing with later images after one replacement fails.
Plugin Startup and Shutdown
Optional command implementations for memory-wiki, policy, QA Lab, and Voice Call now load only when their command is selected, while bundled web-search providers keep executable runtime code unloaded until OpenClaw chooses one. Activation planning reuses prepared alias work as well, but those component improvements do not establish a universal or end-to-end Gateway startup speedup.When a plugin does fail, retries preserve the original actionable load error instead of making a rejected module graph appear to recover through a fallback. SQLite-backed plugin state keeps its bounded WAL retry through wall-clock changes, loads that finish after shutdown begins are retired, and interrupted service startup shares one cleanup result so a stop handler is not called twice for the same attempt.
Plugin SDK Compatibility and Session APIs
External plugins built against the 2026.8.1 SDK keep their conversation-binding inspection import, and accepted legacy docks commands remain reachable under Tools after upgrade. Plugin authors also gain a supported facade for the same node CLI helpers OpenClaw uses, while source plugins can load .mtsx and .ctsx configured-state or persisted-auth checkers without falsely reporting that state as absent.Strict single-message and atomic-batch transcript appends can once again omit the documented optional storePath and resolve the selected agent’s configured or default store. Explicit-environment integrations can create and reopen non-main incognito sessions without replacing the process environment, with incognito data remaining memory-only. Corrected migration guidance separates public SDK exports, retained compatibility imports, injected alternatives, and compatibility deadlines without claiming new runtime exports.
OAuth MCP Servers with Strict Request Sizing
OpenClaw can connect to OAuth-enabled Streamable HTTP and SSE MCP servers that reject POST requests without a known size, including through openclaw mcp probe. The initial authenticated request and one token-refresh retry now reuse the same sized payload while changing only the bearer authorization. This does not fix the separate in-Gateway path that can send an unexpanded bearer-token placeholder.
Plugins Hub Accessibility and Polish
ClawHub search now tells screen-reader users when a search finishes and how many results it found, while preserving the visible layout and stale-result protection. Read-only operators see one permissions warning instead of a duplicate page alert, and blocked actions can explain themselves through focus, hover, or tap without attempting a mutation.First-party catalog entries use artwork already bundled with OpenClaw when it is available, avoiding fallback letter tiles and unnecessary remote icon requests when the CDN is blocked, while third-party artwork retains the authenticated proxy path. The Workshop tab also lines up with the shared Plugins content column on wide screens without changing its narrow layout.
OpenClaw can now remember an eligible approval without turning it into blanket permission. Durable MCP grants remain tied to one agent, configured server, and tool, remote Codex placement grants remain tied to the process and placement that earned them, and stricter session or server policy still wins. The same boundary now follows delegated agent creation more carefully, while private diagnostics, saved reasoning, network requests, guest workspaces, and administrative automation each get narrower protections of their own.
Scoped Durable Approvals
Codex now follows the effective session posture when deciding whether an MCP tool needs approval, so a default full-permission session can use an unannotated tool without stopping for a permission card on every call. Stricter postures and explicit server overrides still apply, and Allow Always follows the tool across argument and working-directory changes for the current session. For an eligible MCP tool on an OpenClaw-configured server, that choice can also become a durable grant for the exact agent, server, and tool across later sessions and Gateway restarts; Codex apps, native plugin servers, computer-use servers, explicit prompt mode, and ambiguous matches remain outside it.Remote Codex placement approvals use a narrower lifetime. Allow Always can be reused while the same placement, pairing, environment, workspace, parent approval, and Gateway process remain valid, but a restart, move, re-pairing, authority change, or expiry requires a fresh decision. Approval lifetimes entered through the CLI must now be whole positive days within the existing range, so malformed input leaves the approval pending instead of silently choosing a different duration.
Delegated Agent Authority
Delegated agent creation now keeps checking the authority of the run that requested it through workspace, identity, session, and configuration writes. If that run ends while creation is still being prepared, OpenClaw stops before starting the next persistent effect instead of finishing later and reporting success for a request that is no longer authorized. Users can check openclaw agents list and retry from an active run.The boundary is forward-looking rather than destructive. A filesystem write that already started may finish, a fully published agent remains available, and its required bookkeeping can complete rather than leaving partial state behind.
Guest Coding Inside Private Workspaces
Sandbox-required guests can once again write files, patch code, run project-local commands, and delegate work inside a private workspace with workspaceAccess set to none. The shared agent workspace and host credentials remain outside that boundary, managed skill overlays remain read-only, an explicit ro workspace remains read-only, and networking stays off unless an operator enables it.Existing containers are recreated once to adopt the new mount format. Public cloning and dependency downloads still need operator-enabled networking, and arbitrary shell enforcement on a remote host still depends on that remote operator’s filesystem policy.
Private Data in Diagnostics
Doctor now compares the selected state directory only with the effective account’s default, avoiding sibling home-directory paths and unrelated backup warnings on shared systems. If a targeted session import or restore cannot archive a transcript, its durable migration record keeps useful failure details and the original recovery source while masking secret-shaped values; iOS agent deep links omit the complete incoming URL from diagnostics, and configuration responses redact credentials, SecretRef identifiers, and internal plugin metadata from pre-migration snapshots.These protections are scoped to the named Doctor, iOS, and configuration-response paths. Snapshot redaction does not change stored configuration or migration inputs, and it does not repair the separate startup or runtime corruption symptoms that were not reproduced by the configuration fix.
Saved Codex Reasoning
Newly recorded Codex dashboard turns now keep reasoning as typed thinking instead of mirroring it into ordinary answer text. Saved reasoning appears under Worked only when the session explicitly uses /reasoning on and the local View → Reasoning control is enabled, while off and stream keep it hidden after reload without hiding the final answer.Previously malformed transcript rows are not rewritten. This change is also limited to saved Codex reasoning in the Control UI and does not resolve separate provider or channel-streaming leakage reports.
Network Destinations and Azure BYOK Requests
Operators can now deny selected destinations across browser access, guarded web fetches, and automation webhooks without maintaining a complete allowlist. Exact hostnames and wildcard subdomains are rejected before DNS resolution and before allow or private-network exceptions, while an absent or empty blocklist leaves existing behavior unchanged. This is a destination policy rather than a complete browser egress firewall, a wildcard does not cover its apex host, and supported Chrome MCP endpoints supplied only through mcpArgs remain outside the shipped hostname check.Azure OpenAI BYOK traffic through the Copilot extension also gains a separate request boundary. Each local proxy receives a fresh credential, verifies it before accepting request-body data, and removes it before forwarding upstream, while configured provider headers and the existing non-Azure nonce path remain intact. The Azure path relies on header forwarding verified for the shipped Copilot SDK version.
Scoped Sign-In and Device Tokens
GitHub-backed Cloudflare Access and Tailscale sign-in can use the Gateway’s existing GitHub credential for public profile verification, reducing failures caused by the anonymous API quota. Named operator roles are still admitted only after identity is verified, and an unavailable verification service now produces an accurate retryable error instead of opening a session with no usable scope.Authorized operators can also rotate or revoke approved scoped node tokens through openclaw devices. The operation cannot add a role or widen the approved scope baseline, under-scoped callers remain blocked, and operator-token operations with broader stored scopes may still require a broader authenticated connection.
Configuration and Secrets Automation
Automation can now guard one direct config set operation with an expectation that the current value is absent or exactly matches supplied JSON. A mismatch writes nothing, reveals neither value, and leaves the existing final snapshot guard in place for later races. The expectation does not apply to batch or dry-run mode, redirected SecretRef writes, or roster updates.Secrets commands using --json now return one parseable document on success or failure across reload, audit, configure, apply, and store list or get operations. Human-readable output and documented exit codes remain unchanged, and this is an output-contract repair rather than a change to secret contents, storage, or security policy.
OpenClaw spends less time repeating work you never asked it to do. Long conversations and concurrent replies use less CPU and memory in the measured workloads, large installations give health checks and session views more room to respond, and routine starts, commands, files, worktrees, logs, and remote checks shed a long tail of avoidable overhead.
Long Conversations and Concurrent Replies
Large conversations no longer drag as much unrelated history through every nearby task. Resets read only the navigation data they need, session inspection walks backward without copying the history, and ordinary turns avoid several unnecessary session reads, which leaves more room for the conversation itself.The streaming path also does less work as replies grow. Concurrent long replies reuse their prepared text instead of repeatedly rebuilding it, producing substantially lower CPU and memory use in the tested workloads while preserving tool ordering, corrections, reply targeting, and final media. These measurements cover the built-in runtime on defined local workloads rather than model-provider latency.
Code Mode with Less Repeated Work
Repeated Code Mode work can reuse bounded warm workers and look up only the requested session, cutting preparation and CPU work once those workers are warm. Snapshot buffers also move between tool calls without another storage-format copy. The warm pools can retain materially more process memory, so this improves the measured Code Mode workloads without establishing a general Gateway capacity or throughput gain.
Large Installation Health and Session Views
Gateways with large agent rosters now reuse prepared roster, model, and workspace facts during one startup batch, which lets real HTTP health checks answer again instead of leaving a listening socket that never becomes useful. Other fleet startup costs can still produce noticeable post-listen delays, but the repeated discovery work covered here is gone.Installations with large saved-session histories also keep less conversation data in memory and do far less work to count or list sessions, while read-only diagnostics stay out of SQLite’s writer lifecycle. Retained Control UI assets use less memory on constrained ARM64 hosts as well, improving headroom in the tested 768 MiB and 1 GiB setups, though 512 MiB without swap can still fail when status work overlaps startup.
Startup and Command Overhead
Common startup paths now load less optional code and reuse more work they have already verified. Gateway readiness avoids repeated Doctor and plugin-metadata preparation, ordinary shell commands defer model review and follow-up delivery until those paths are actually needed, and concurrent first turns share one workspace Git setup. Approval, elevation, cancellation, and delivery rules stay where they were.Everyday command feedback is less surprising too. A temporary login-shell failure can recover on a later lookup without restarting the Gateway, /agents takes one coherent view of the subagent registry, automatic TTS leaves routine command output as text, zsh completion keeps examples literal, and strict-JSON errors point to the safer file-backed patch workflow.
Managed Worktrees on Other Storage
Managed worktrees can now live on another chosen disk or folder without moving the rest of OpenClaw’s state, and existing worktrees keep using the locations already recorded for them. This release first raised the shared checkout target to 100, then removed the hard admission ceiling entirely, so sufficient disk space governs new worktrees and restores while 100 remains the automatic cleanup target. Manual and protected worktrees keep their existing safeguards.
Project Directories for Local Agents
Local agents can work directly in an existing project directory while their instructions and memory remain in OpenClaw’s managed workspace. Existing setups keep their old behavior unless a separate directory is configured, session-created and paired-agent directories still take precedence, and the split-directory option is limited to unsandboxed runs.
Conversation Branches and Session Continuity
Supervised Codex Chats can use Fork from here on newer canonical messages, retain the native conversation history through a Gateway restart, and open the chosen input as an unsent draft without changing the source conversation. Descendant forks and paginated /btw side questions retain that native lineage as well.Underneath that workflow, nested session writes remain ordered, malformed cyclic ancestry returns bounded context instead of hanging, and a stale local CLI recovery attempt can no longer replace a newer session. Older canonical messages without recorded native provenance remain outside the new fork path.
Large Files, Terminal Output, and Logs
Large downloads, generated media, multipart uploads, and command results now avoid several full-size temporary copies while preserving the same bytes, limits, timeouts, and error details. Terminal replay evicts old buffered output in one pass, and very long styled or Unicode lines reach their existing width limit with much less temporary work.Logging follows the same theme. Text loggers reuse stable formatting, JSON console output skips work it does not need, completed payloads are released as slow writes finish, and console.trace() keeps one readable redacted stack instead of producing a duplicate error record.
Remote Gateway Timing and Cleanup
Remote Gateway and paired-node operations now hold their timing and cleanup boundaries through clock changes, suspend, cancellation, and concurrent shutdown. Node wake retries use elapsed time, stale presence expires in the intended order, and an SSH-backed probe does not call itself stopped until its child process and forwarded port are gone. Remote health output also uses the Gateway’s own ages, avoiding misleading status when the two machines’ clocks disagree.
Background Work and Conversation Concurrency
Removed or replaced sessions no longer leave an obsolete observer scheduling utility-model work that cannot be saved. A subagent settlement wake that reaches its deadline also cancels the exact accepted run and releases the requester’s single-concurrency lane, letting later messages continue instead of piling up behind stale retries. That cancellation is scoped to settlement wakes and the shared direct-announcement deadline path.
Documentation for Existing Paths
Several places where the product already had a working route but the documentation did not make it obvious are now clearer. Supported /login aliases, SecretRef defaults, TaskFlow audit warnings, uv-managed Python execution, and dead-letter recovery commands are documented where people look for them, retired pages lead to current migration guidance, and the Lite Mode Showcase link reaches the actual skill. Translation handling is less likely to strand localized pages on protected placeholders, while the expanded v2026.8.2 page is easier to navigate by topic and remains historical documentation.
The smaller fixes in this release are easier to understand when they stay attached to the place you actually notice them. Sessions now keep interrupted requests and finished child work attached to the right run, attachments hold on to their real text and type, command-line tools stop on ambiguous targets, and status, logs, remote connections, and channel-specific edges report what actually happened instead of quietly substituting a plausible answer.
Interrupted Sessions and Child Work
Interrupted work now keeps its shape through restart and cleanup. A user message interrupted by a Gateway restart remains in later model context, cloud-session cleanup failures stay visible and retryable without discarding accepted workspace changes, and retried agent or CLI commands remain attached to the process tree that actually owns their cancellation, output, and diagnostics.Child work also settles more cleanly. Completion-required CLI-backed results resume after the parent yields without replaying an already delivered result, a successful child with no final message can finish quietly, and a rejected requester wake no longer retries forever. Catalog-backed sessions retain the runtime they were created with, ordinary wait deadlines are no longer mislabeled as Gateway shutdown, and simultaneous session starts avoid repeating the same Git preparation work.
Agent Runs and Tool Results
Long-running work gives the agent more useful signals before it goes off course. A background command tells Code Mode how to poll for its eventual output, early tool-loop warnings reach the model before the blocking threshold, completed fallback reports stop delegated work from launching again on the covered CLI path, and cleanup can finish even when plugin setup fails.The result is easier to trust as well. Chat /bash replies show the real exit code or signal, successful PDF and image analysis remains available to Code Mode and Tool Search, nested calls retire stale terminal summaries after the accepted result settles, and explicit multi-agent fleets use the selected agent for status and diagnostics instead of requiring an unrelated System Agent owner.
Attachments and Conversation Media
Attachments now arrive with their identity intact across several awkward boundaries. Paths ending in dot segments fall back to a usable name, long UTF-8 text remains recognizable when a character crosses the inspection boundary, streamed files keep a type and extension that match the saved bytes, and inferred legacy text keeps accents, currency symbols, and other non-ASCII characters. Rejected URL downloads also release their transport promptly, while repeatedly changing one conversation avatar no longer pushes other current avatars out of the cache.
CLI Automation and Target Selection
Command-line automation now fails without guessing. MCP read commands return the normal JSON failure document on early errors, agent exec preserves the original run failure and exit code when cleanup also fails, and Windows command lookup ignores empty PATHEXT entries instead of treating an extensionless file as runnable.Explicitly blank session, store, and dead-letter account selectors now stop before OpenClaw can fall back to a default target. Omitting those selectors still keeps the existing default behavior, so scripts can choose between a deliberate default and an explicit target without an empty variable quietly changing what the command touches.
Status, Logs, and Diagnostics
Status and logs now make a problem visible without overstating what is healthy. Detailed status reports show inbound queue pressure and dead letters even when channel connectivity looks fine, usage requests reject unsupported fixed offsets instead of returning totals for the wrong day, and Telegram and TUI status retain known context usage after tool-only turns.The same principle carries through troubleshooting. Rolling log tails read the file OpenClaw is currently writing, session-observer warnings show a redacted cause instead of an empty object, failover counters agree across console and structured logs, and failed search or Git snapshot diagnostics explain what was lost while keeping sensitive values out of persisted output. Plugin validation reports every genuinely missing field in one pass, tool-policy warnings stop recommending grants that an active deny would block, and native PR quota failures once again include safe manual retry guidance for both observed GraphQL variants while failed SSH tunnel startup cleans up its readiness work.
Connected Device and Remote Gateway State
Remote and connected setups now hold on to the state they actually observed. SSH tunnel startup keeps its configured listener timeout even if the system clock changes, node age filters use the Gateway’s latest recorded connection time, and the Devices roster keeps the genuine Gateway visible while remaining bounded under peer pressure and hostname collisions. At the HTTP edge, clients that explicitly reject HTML receive the existing startup or not-found response instead of an unwanted app shell, while ordinary browser navigation keeps working as before.
Channel Commands and Relay Ordering
Two narrower channel fixes remove behavior that depended on the wrong condition. Native /compact now gives an explicit authorization refusal without starting compaction work when the sender is not allowed to use it, while Buzz applies stable event ordering when profile or room updates share a timestamp instead of letting arrival order decide which state wins.
This release includes 415 maintainer-only units covering the machinery behind how OpenClaw is tested, reviewed, built, translated, packaged, and released. They tighten the evidence we rely on, remove duplicated internal work, and keep tooling failures from looking like successful validation, but they do not add a separate user workflow and should not be read as public product claims.
CI and test reliability
CI and focused test work now exposes skipped, crashed, mistimed, or incompletely cleaned validation more clearly, while reusing safe fixtures and build inputs to shorten maintainer feedback without changing product behavior.
Release and package tooling
Release preparation retains stronger artifact identity, retry, review, and publication boundaries, while removing repeated builds from the protected path where the frozen evidence supports reuse.
Documentation and localization
Documentation and generated localization work keeps maintainer guidance, release history, translation inputs, and native locale generation aligned with the code they describe.
Internal refactors and performance
Behavior-preserving refactors consolidate duplicated ownership and trim repeated parsing, copying, allocation, and setup across the runtime and repository.
QA and maintainer workflow fixes
The remaining maintainer fixes repair local previews, QA simulators, merge helpers, packaging checks, and other contributor workflows without turning those changes into public product claims.