Arrange Chat, Dashboard, and task panels
You can now put the part of a task you are working on in the main view and keep the conversation beside it. Dashboard, Browser, Terminal, Files, Review, and Chat share the same controls, so a dashboard can take the larger space while Chat sits on the left, right, or below it. Swap exchanges the two views, Focus gives the main view the task area, and Restore split brings back the previous arrangement and size.The task layout remembers your choices in that browser, and rearranging or hiding panels preserves live widget inputs, chat drafts, terminals, and Review state. Incoming widgets respect an arrangement you have already saved, while compact Home opens with its conversation and composer visible. Closing a Dashboard view leaves its saved board intact, but reloading the page starts fresh widget views. Find dashboards in a visual gallery
The Dashboard gallery gives saved boards a place you can browse by sight, search by task or author, and sort by title or recent activity, including dashboards beyond the first page of conversations. Supported boards show passive previews of their saved HTML as you scroll, making it easier to recognize the one you want before opening it with its conversation.Open the dashboard to use its controls. Gallery cards leave MCP Apps and non-HTML widgets out of their previews, and their Live badge describes a running session rather than confirming that every displayed value is current. Named dashboard and short session links also avoid the broad session-list searches that added waiting on large installations. Build and open a session dashboard
When the bundled Control UI skill is available to your agent, type /dashboard with what you want to see to request a board for the current session. Choosing Dashboard in the side panel opens the board directly without adding anything to your message. The dashboard guide includes a one-prompt demonstration, and the command uses the bundled Control UI instructions even when a workspace has another skill with that name. A custom skill named dashboard remains available through $dashboard or /skill dashboard, with its slash alias moved to /dashboard_2.Widgets pinned from an agent’s global session stay with that agent’s board and notify its authorized viewers. Automatically sized HTML widgets keep their content height instead of progressively shrinking, while manual sizes remain yours to set. If creating a visible dashboard session fails, cleanup preserves a newer replacement session and tells you when the original child needs inspection before retrying. Use interactive widgets in chat
Mention teammates and find your Inbox
When a message needs someone’s attention, type @, choose an eligible teammate, and check the Will notify indication before sending. Simply typing a name does not alert anyone. Human mentions work with durable OpenClaw profiles and bring the message into the recipient’s Inbox without giving them access to a conversation they could not already read.The Mentions Inbox is temporary. Entries last up to seven days, can be removed sooner by capacity limits, and clear when OpenClaw restarts or upgrades. Opening a mention leaves it in the list until you dismiss it. Optional Someone mentions me browser alerts default off and are best effort. The Inbox also keeps automation and model sign-in warnings current through busy periods, and an automation alert’s arrow opens Automations. Recognize people and assign conversations
A single-owner installation using token or password access can now have a saved name, avatar, profile preferences, and My GitHub connection without setting up a separate sign-in service. These follow the owner profile across its devices. On a Mac, an owner without an uploaded image can use the picture of the Mac account running OpenClaw, while paired browsers and supported Mac SSH connections can display saved profile photos again.For teams, assignment menus include registered people even when they are offline or have not owned a conversation, and grouped session headers bring presence and people cards closer to their work. Participant lists reveal additional names, and person Activity links use readable addresses. Shared token or password holders still share one owner identity, its preferences, and My GitHub connection, so use personal sign-in when each person needs a distinct profile. Find and organize conversations
Searching Sessions can now find matching active or archived conversations beyond the rows already loaded, with Load more sessions bringing in further matches. It searches conversation details such as names, models, status, and agent identity, while transcript search remains a separate way to search the messages themselves. Counts, grouping, and sorting still describe the loaded rows.Owner choices move into a compact submenu, sharing and owner details sit together in the chat header, and copied session links use the configured public address even through a local SSH tunnel. Unrelated agent activity no longer repeatedly reloads the selected agent’s list, and pinning or renaming another session can continue while a model catalog loads. Opening a chat clears its unread dot immediately, although new activity arriving during the acknowledgement refresh can still briefly be masked.
Opening a long conversation now puts the recent messages you selected ahead of background chats and a restored Home pane, with smaller initial transfers and reusable avatar previews. Valid prefetched history stays available through unrelated sidebar updates, and completed messages avoid repeated redraws while a new reply streams. Older messages remain available by scrolling upward.Large Codex histories use bounded pages and shortened tool-output previews, with full output retained in Codex. Very large individual records and some legacy histories can still exceed the transport limits. On the computer running OpenClaw, cold runtime history checks let unrelated activity continue, and browsing retained archives leaves less message content in memory between requests, at the cost of reading those pages from disk again.
Keep drafts and attachments ready to retry
A rejected send can keep its original attachments and Retry action when you leave the conversation, move Home, or reload through a supported recovery path. Recovered documents regain their Open and Download controls, and permitted plain-HTTP installations can use attachment sending and recovery with browser storage available. Recovery keeps the request’s identity so an uncertain send is not automatically repeated.Interrupted personal-account setup can resume with its original session and worktree, while failed cloud starts retain their error and elapsed time when you return. Covered app-triggered reloads protect unsaved starts while the page is responsive and offer an explicit discard action when needed. Incognito starts remain memory-only, and closing the page or choosing to discard unsaved input can still lose them.
Preview images and retrieve current files
Successfully generated images remain visible when a later tool fails, and saved media replies keep one caption after reload. Project screenshots now follow the conversation’s filesystem permissions, so a screenshot the session is allowed to use can also appear in chat. For a blocked image outside those folders, an administrator can inspect its path and choose Allow image for that file alone, with an expiring allowance and current access checks.Media requests reaching the updated server return current file contents, and conditional download resumes for mutable files restart with the current version instead of combining old and new bytes. Attachment lookup does less work in long histories, and verified Tailscale Serve users regain affected previews. An Omitted from history card explains a missing historical image without implying its bytes were recovered, and an old browser cache may still require reopening a fresh media URL.
Follow the work that is running
Tool activity keeps related calls together after reload and shows a short purpose supplied by the acting agent when one is available, with full commands and results underneath. There are no extra model calls just to name those rows, and the description tells you the intended work while the result tells you whether it succeeded. If your configuration contains the retired gateway.controlUi.toolTitles key, remove it even when its value is false. openclaw doctor --fix handles supported configurations, while managed or included configuration files may need changes at their source.The task list keeps active work in creation order and recent completions first, with Refresh and recovery guidance when activity changes during loading. Older checklists stay paused during unrelated work, finished parent conversations stop looking busy while their children continue, and Swarm cards retain completed counts and readable task names. Activity also batches background refreshes, while heavily changing task lists can still require another refresh.
Use chat commands and scrolling controls
Choosing a command argument now submits the completed command from New Session, and the execution-host picker inserts valid settings while preserving the rest of a chat draft. Sending a message, submitting a chat command, or choosing Scroll to latest brings the newest output into view through composer resizing, while later manual scrolling and keys inside text or media controls remain under your control.Stop remains available for a known running response during reconnection and requests cancellation when the same authorized connection returns. Queued messages can resume when refreshed session state confirms the chat is idle, and accepted messages can stay pending through a temporary history rebuild before execution begins. Work that may already have started is not blindly sent again, and queued messages show a single usable Steer action when steering is available.
See the selected and serving model
The model control can now tell you which fallback model is actually serving the conversation while the open picker keeps your preferred model selected. When the session returns to that preference, the old fallback label clears. Known model names stay visible while switching chats and loading their options, including in locked chats, without enabling controls before their availability is known.Sign-in warnings are easier to distinguish from ordinary model details, provider headings offer a shortcut to Model Setup, and a provider with a usable profile can show Ready despite a failed sibling profile. Session Observer’s model choices also recover after temporary catalog failures and ignore obsolete responses after agent switching. These labels describe the available catalog and session state, rather than verifying a provider credential or identifying a billing account.
Inspect connected computers and phones
The Devices page puts recognizable computers and phones, available resource readings, capabilities, and access details in one inventory. Connected CLI nodes and the Mac shared worker report load, memory, and home-volume disk snapshots, and a successfully saved last reading remains available with its age when a node goes offline. The CLI can show those summaries too. Load averages and used memory describe those measurements, rather than operating-system pressure, and offline values are historical.An Actions menu keeps copying IDs, pairing controls, and available desktops together, while an available Desktop opens in its own window. New Session and Move Session distinguish commands that are missing, waiting for pairing approval, or blocked by policy, so the next step matches the problem. The device guidance covers setup and reapproval, and Connection and System busyness show eligible mounted local disks separately. Review files and follow GitHub work
GitHub previews keep the exact issue, pull request, or comment destination you opened, even when another link has already filled the preview cache. They use the selected agent’s configured account and explain sign-in, access, rate-limit, or connection failures, while remaining limited to public repositories. PR badges collect later pages of checks before reporting complete results, so a failure beyond the first page does not disappear behind a passing badge. Results beyond the collection limits can leave the badge absent.The Review panel keeps unchanged files out of a session’s changes and reports full addition counts for large new text files even when their previews must stay bounded. GitHub publication controls also retain a retry and its original account across chat navigation and same-chat split panes. That state is held in page memory and clears on reload or relevant connection and access changes. A rejected first account choice can be refreshed before an explicit new Publish, while an uncertain outcome keeps checking the original request.
Side chat has a visible keyboard shortcut, Command-Shift-S on Apple platforms and Ctrl-Shift-S elsewhere, so you can open or close the existing panel without reaching for its tab. Cancelling while conversation context is still loading now retires that request before it can later start a model call or replace a newer answer. The same preparation work is covered by the existing 60-second timeout.
Load and reconnect the browser workspace
The browser workspace downloads more code and text when the relevant view needs it, and reloads can reuse versioned themes, fonts, icons, and artwork already in the browser cache. Models and Plugins avoid competing initial loads, keeping useful controls visible while supplemental information arrives. Cloudflare Rocket Loader deployments also get the script protection needed for the affected blank-page startup failure.During reconnection, dashboard conversations remain readable, and local panel arrangement controls stay available while server actions wait for the connection. Phones can reach the Server updated recovery action and retry a failed refresh without losing the selected chat. New connections also avoid waiting behind their own presence notification. Operators rebuilding bundled UI assets in place still need to restart OpenClaw to pick up their new identity.
Read and navigate settings
Settings keep long descriptions beside their artwork and place controls deliberately on narrow screens, while notification preference cards align with the rest of the page. Picker selections are easier to see and affected menus respect reduced-motion preferences. Config exposes the selected Form or Raw mode and current section to assistive technology, and obsolete MCP save feedback clears when the settings context changes without cancelling the earlier write.Hebrew and Arabic text with leading direction marks displays in the intended direction, and punctuation remains visible while typing in native fields under CRT and Phosphor themes in Chromium. The first accent swatch shows the inherited color it restores. It is still a reset action, so clicking it can clear a matching explicitly saved profile color and make future color changes follow the inherited setting.
Choose a microphone for Talk
When a saved microphone cannot be opened for a browser Talk call, the error can offer Use System default for this call. You decide whether to retry with that microphone, and your saved choice remains in place for later calls. Permission failures stay visible, and leaving or replacing the call retires the offer so an old button cannot open another microphone.Closing the microphone picker or leaving Appearance also prevents delayed device discovery from requesting camera or microphone access after you have moved on. Deliberately returning to an active picker still allows the normal permission request.
Read Logs, Debug, and Usage
Debug shows when a snapshot is refreshing or waiting for a connection while leaving the last successful readings available. Disabled work lanes with nothing running or queued no longer appear as misleading blocked rows, and Logs keeps its initial load through routine updates without an old connection unexpectedly moving the view.Usage now keeps selected-day totals within the active session filters, while daily charts and daily exports retain those matching sessions across the requested date range. Provider, model, and tool filters select matching whole sessions, so their totals can include other usage within those sessions, and the costs remain estimates rather than provider billing records.
Follow linked Workboard cards
Existing linked Workboard cards continue to appear and update with their conversations. When a task-list continuation expires, Workboard can restart its scan once and use the fresh result to update cards and link started runs. Chat headers and session menus no longer offer Add to Workboard, and this change does not introduce a replacement capture workflow or remove existing cards.
Keep shared terminals delivering output
When several people are viewing a terminal, one failed viewer connection no longer holds up output for the healthy viewers that remain. OpenClaw retires that failed delivery once, which also stops the same connection from producing an error for every queued update. This addresses the shared-output stall after a connection fails, without changing terminal permissions or explaining the original disconnect.
Understand diagram loading failures
A valid diagram should not send you back to rewriting its source because the renderer could not load. Mermaid errors now distinguish unavailable rendering, invalid diagram source, and an image that could not display, with the appropriate reload or correction guidance and the source still readable and copyable.For login-protected reverse proxies, the Mermaid troubleshooting guide explains which static renderer assets need to load without the page’s cookies. Keep authentication on the dashboard and API routes, make only the required asset exception, and reload after correcting it. Read current controls in your language
Twenty existing non-English locales have updated text for the web workspace’s dashboard controls, mentions and Inbox, connected accounts, device settings, task names, and recovery messages. That includes translated Allow image controls, Mermaid failure guidance, unsaved-start warnings, and update and publication status, so the explanations surrounding these workflows keep up with their controls. Chinese and Japanese text also receives sentence-punctuation corrections.
Choose a workspace and start a conversation
New Session makes the choice between Current checkout and New worktree explicit, with the starting branch and worktree name in the Checkout control. Device and cloud sessions continue to require a managed worktree, and local sessions can choose Current checkout when a worktree choice is unavailable. Recent Windows folders use readable short names, and the sidebar’s familiar controls and nested-session loading placeholders keep their spacing through supported layouts.The composer no longer shows the naming notice or prepared-name preview below the draft, but background naming still runs. Eligible unsent draft text can go to the selected utility provider before you press Start, as the session naming guide explains. Removing that preview does not change the transmission, and Start does not wait for a name. Expand a table without losing its links
Expanded chat tables keep the same supported file previews and session links as their inline version, including keyboard activation. Following a link dismisses the expanded view so you can use its destination, closing it returns focus to Expand table, and changing conversations no longer leaves a hidden chat’s table over the active one. The table guide also explains the existing, narrower navigation support in Ask OpenClaw.
Follow an update through restart
An update now leaves a report you can return to after the connection drops and OpenClaw comes back. The update dialog follows the saved attempt, Settings → Updates reopens its latest report, and the CLI and chat use the same recorded steps, outcome, and verification results. Successful updates keep that detail too, so you do not have to reconstruct what happened from a disappearing notification. The update history guide covers openclaw update status and administrator history queries.Configured owners can ask for an update in chat or use /update, with guidance when their account lacks owner access. Chat updates require commands.ownerAllowFrom and the existing commands.restart permission, and reports for existing web conversations can be saved directly into the conversation without an extra model turn. Managed services may miss intermediate notices, and a usable delivery route is still needed for an external chat notice.A saved report describes what OpenClaw recorded. Missing verification stays unverified, and an interrupted CLI update can still leave a running record that locks update and configuration controls. An idle Gateway may also miss a separately started CLI update until it restarts, so a running label alone is not proof that the updater is alive. Complete package and source updates
Package updates preserve the files another updater is actively preparing and the shared plugin dependencies another installation still needs. Once the replacement Gateway has passed the existing readiness and version checks, the updater keeps that healthy process running instead of interrupting it with a second restart. Supported upgrades from the published v2026.8.2 package also retain the code needed by the older updater to finish replacement and bring its previously active managed service back.Source installations address a different part of the same journey. The repaired updater keeps the code it needs available while generated files are replaced, letting it finish configuration processing and restart the Gateway after a rebuild. Ordinary CLI commands also skip a needless rebuild when only unchanged files’ timestamps differ. An updater already running older code cannot acquire those fixes midway through its own replacement, so the transition installing the repair may still need operator recovery.On Linux without a service manager, the updater can proceed when the selected Gateway is idle and service inspection permits it, explaining why restart was skipped. When upgrading that setup from the published v2026.8.2 CLI, confirm no Gateway is running and use the one-time openclaw update --no-restart path. The update reference explains the service checks and manual restart steps. Keep working settings during upgrades
Automatic updates now keep enabled skill preferences when a prerequisite happens to be missing from the update environment, and fully repairable older multi-agent configurations retain current choices such as the update channel, port, and original default agent. A failed agent-settings save also keeps the previous complete file readable. Enabled skills still need their prerequisites before they can run, and an explicit standalone Doctor repair can still disable unavailable skills.Remove messages.suppressToolErrors, even if its value is false, or run openclaw doctor --fix to migrate it. The retired setting no longer suppresses the final warning when a tool fails and the run has delivered no reply. Channel settings continue to control mid-turn progress.If an intended owner has lost access to restart or update commands because their saved identity uses an older channel:user:id form, run the same explicit Doctor repair to migrate recognized, unambiguous entries. Upgrading alone does not rewrite those owner entries, and ambiguous identities or default-agent choices still need manual correction.
Apply settings without a full restart
You can change more of how your Claw works without restarting the whole Gateway. With the default hybrid configuration reload, routine changes to tools, approvals, messaging, speech, browser defaults, retention, and update policy reach the next relevant operation while unaffected conversations stay connected. Logging changes reach already-running channels and plugins, dashboard serving can be switched on or off, and a loaded OpenTelemetry exporter can be replaced on its own when its settings change.Access changes apply at the place they matter. Pending automatic pairing approvals recheck current policy, revoked device commands are cancelled, and rotating a token or password within the same authentication mode reconnects affected shared-credential clients while independently paired clients stay connected. Existing sign-in failures and earned lockouts survive rate-limit changes. Changing the shell affects new terminals, while disabling terminals closes existing sessions and re-enabling allows fresh ones.Changes that replace a channel, browser, or exporter can briefly interrupt that service, and failed service replacement can require Gateway recovery. Working hooks survive a replacement that fails to load, and active channels restore their incoming routes after plugin replacement. Refresh open browser pages for changed interface preferences or terminal policy. Listener and process settings, authentication-mode changes, and dashboard asset roots or base paths still require a full restart. Continue eligible work after restart
A Full Access task interrupted by a Gateway restart can inspect its saved conversation and use fresh, currently authorized shell commands or delegated work to continue the original request without asking you to send it again. The restart recovery guide explains how inherited Full Access and explicit session choices apply, while work restricted for safe replay or uncertain delivery keeps its narrower permissions.Queued follow-up replies also retain their original Gateway association after the initiating request ends, and one reply finishing during shutdown no longer removes another unfinished reply’s recovery record. These repairs preserve eligibility to continue work and deliver its result. Interrupted calls and expired process or approval handles are not replayed automatically, and a failed recovery-record write or an uncertain external delivery can still need attention. Stop the Gateway with accurate cleanup status
Stopping the Gateway now keeps tracked requests, commands, and required cleanup together until they settle, so a finished response does not release services that its remaining work still needs. If required cleanup fails, the process reports an unsuccessful stop instead of starting a replacement inside a runtime that has not finished closing. Commands that time out during startup can return promptly while shutdown continues to track their cleanup separately.Several specific waits are addressed along the way. Committed restarts retire obsolete follow-up retries, suspended Gateways cancel background work that has not started, and bursts of file logs drain in batches. Already-running startup preparation and plugin cleanup are still joined, which can add time to a stop. A stop requested from within Gateway chat reports that it has been scheduled and lets the requesting operation settle, with final termination remaining the responsibility of the serving process or its service manager.
Hand maintenance back to an external controller
Deployment controllers that pause new work before maintenance can now explicitly hand an unfinished wait over to restart recovery. An administrator arms gateway.suspend.handoff for the exact suspended process, then the controller sends SIGTERM and owns launching the replacement. This gives managed deployments a supported way to interrupt eligible conversation work after their maintenance waiting period, without having two owners trying to restart the same Gateway.The external-app integration guide covers the handoff’s expiry and refusal rules. Arming it alone does not stop the process, and pending final conversation writes can refuse the handoff. Terminal commands and scrollback end with the old process and are not recovered. Create and restore complete backups
Backups now handle managed configuration and credential links such as those used by NixOS and Home Manager, retaining portable links to the content included in the backup. Slow snapshots involving older audit logs can complete without holding the migration lock for the whole copy, and malformed archive headers are rejected before restoration creates its destination.Git backups also preserve text after an embedded NUL character, which could previously truncate a value or collapse distinct record keys. This includes affected iMessage recovery records in global backups. Recreate affected older Git backups from intact source data after updating, even if the old backup passed verification. Updating cannot recover bytes already missing from a backup. Archive and clean up large conversation stores
Reaching the active-session limit now archives eligible ordinary conversations so you can search for them and restore them later, while previously archived conversations stop counting against that limit. The interface explains why a conversation was archived, and cleanup previews distinguish archival from removal. Cap-created archives can still be permanently deleted later under disk pressure, and other retention policies continue to apply.Large conversation stores also do less maintenance work on the thread serving interactive Gateway requests. Eligible transcript reclamation and physical disk accounting run in workers, excluded sessions avoid unnecessary metadata reads, and large archive backlogs can progress without overflowing SQLite’s parameter limit. Scan scheduling and old-history inspection use less temporary memory in their affected paths, keeping the same retention decisions and disk totals. Get repair advice for the right installation
Doctor gives repair instructions for the installation you are actually inspecting. A failed remote connection points you back to that host, its credentials, and its tunnel or network connection, while a source-install dashboard repair command includes the detected checkout path so it can be copied from another directory. Service advice distinguishes installing a missing service, starting an installed one, and explicitly replacing its definition, and explains when Nix, an external supervisor, or the invoking shell prevents installation.Full read-only lint finds expired credentials in the original agent and shared stores and reports their usable paths. Legacy Discord, Matrix, Codex, and Teams checks skip unrelated startup work when it is not needed. Invalid plugin settings now produce a configuration error instead of making the command appear missing, with core shell completion still available while you repair the settings and regenerate plugin completion. Use doctor --lint or bare doctor --json for read-only diagnosis, since ordinary Doctor can migrate state. Start managed services and migrated installs
Managed Windows Gateways stay alive through startup and can be stopped while startup is still pending, avoiding the case where a command reported a stop and the Gateway appeared afterward. Linux service maintenance correctly reads valid comments and continued lines, preserving runnable service definitions, recovery backups, and operator overrides.Startup also refreshes migrated plugin policy before checking readiness and avoids repeated database scans during migration decisions. Large valid agent configurations with repeated plugin-owned model choices no longer hit the repaired startup bottleneck. These changes let the affected installations reach their normal readiness checks, while genuine configuration changes or failed database checks still prevent startup.
Inspect database compatibility and errors
Database compatibility checks used by updates, Doctor, and Gateway maintenance now inspect private copies while preserving the original database files and surrounding SQLite files, including committed changes waiting in a write-ahead log. These checks need temporary space and copying time, and can refuse to finish when a safe copy cannot be prepared.When inspection or verification fails, diagnostics retain useful Node and SQLite error codes. A stable malformed file can report that it is not a database instead of incorrectly appearing to change throughout inspection, and database cleanup releases its original maintenance lock even if the surrounding storage environment has changed. A generic disk I/O error still needs investigation before attributing it to a full disk.
Measure slow requests and shutdown work
Operators investigating slow requests can now separate the wait before a Gateway handler starts, the handler’s elapsed time, and the first response through the existing diagnostics exporters. The Gateway RPC metrics cover authenticated WebSocket requests, and normal logs also show slow reply-preparation stages separately from waiting for a model or tool. Health observations retain pauses that repeated reads could previously hide, so a later healthy check does not erase the earlier observation from enabled monitoring.During shutdown, count-only reports show remaining tracked work and the transition into server cleanup. The existing OPENCLAW_GATEWAY_RESTART_TRACE=1 option adds entered-phase markers to help locate a wait before that phase finishes. Routine successful continuations move to debug logs, and an unchanged stale-worker assignment stops producing the same disk-space warning every minute.These measurements show observed elapsed phases and completed monitoring windows. They do not identify the responsible function by themselves, and a response accepted for sending is not proof the client received it. Check dropped-observation counters before treating monitoring as complete. If a script calls openclaw logs, omit unset --limit, --max-bytes, and --interval options instead of passing empty values, which now produce an error. Attempt a bounded installation repair
On the computer running OpenClaw, an interactive openclaw triage --run can attempt an installation repair using configured models and their permitted fallbacks. Doctor lint runs before and after the attempt, skips inference when it finds no errors initially, and keeps the result unsuccessful if errors remain afterward. The attempt is limited to one turn, ten minutes overall, five minutes for the turn, and 40 tool calls.Explicit --run permits host commands without further approval prompts during that repair. Filesystem tools enforce the installation or candidate-root boundary, but shell commands follow the repair prompt and have no OS sandbox. Explicit tool denies remain in force, and unsupported execution routes produce guidance for an external handoff. The installation triage guide explains these limits and the checked result.
Stop and follow Slack agent sessions
In supported Slack agent sessions, the native Stop button now reaches the work running in the selected conversation, including overlapping replies in group DMs, while session status shows when the agent is working or waiting for an approval. Rename a supported session in Slack and OpenClaw keeps that name through later messages, with delayed controls checked against the conversation they belong to.Existing apps need the two session-event subscriptions described in the Slack setup guide, and native session status requires a reply thread. A completed first reply can still lose its title association after cleanup or restart, and overlapping replies can still interfere with the shared working indicator. Progress cards also keep earlier errors as recovered history after a successful turn, so a finished task does not keep looking failed. Finish Slack replies without replaying uncertain sends
In Slack compact progress mode, the final answer arrives as a new message after any conversation or media that appeared while the agent worked. Temporary progress is removed after Slack confirms delivery, and a failed send leaves the preview available.Slack writes also distinguish an explicit rate-limit rejection from a lost response. A supported rate-limit response can retry up to twice after Slack’s requested wait, including ordinary messages and upload completion. If the outcome is uncertain, OpenClaw reports the failure and avoids automatically repeating text Slack may already have received. That tradeoff means an unaccepted reply can remain missing when its outcome cannot be established. Use tables and decision buttons in Slack
When a Slack reply would be easier to use as a table or a few choices, the agent now has guidance to offer that format without requiring you to ask for Block Kit. A status request can become an organized report, or a decision can arrive with buttons that let you choose and continue the conversation. This uses the existing Slack renderer and supported controls, with plain text for simple replies and a text fallback for richer ones; the format the agent chooses still depends on the model and request.
Save and revisit Discord meeting notes
You can configure a listen-only bot to take Discord meeting notes when people enter a voice room, then return to the overview, decisions, action items, and speaker-labeled transcript from the Meetings page. Agents can also read permitted saved meetings, so the conversation can continue from what was discussed without you having to paste the notes into a new chat.Occupancy capture is opt-in and needs Discord voice and speech-to-text setup. Tell participants that transcripts will be captured and stored before enabling it, and configure at most one room per account and guild. The bot waits 30 seconds after everyone leaves, and a meeting can reopen with its existing transcript within 10 minutes, including after a restart. Continuous capture remains the default for existing setups and now retains its capture identity through temporary startup failures.People with operator read access share access to meetings across the Gateway, regardless of the selected agent; use separate Gateways when readers need isolation. Model summaries can fall back to heuristic notes, and very long meetings can omit middle sections from the model’s summary input, so use the transcript when a particular detail matters. Keep Discord voice with the speaker
In a shared Discord voice room, a delayed request keeps the identity and permissions of the person who spoke it, while spoken answers queue in order instead of replacing one another. One speaker’s failed connection can recover when they speak again without disconnecting everyone else, and OpenAI agent-proxy early wake acknowledgments require the name at the start of the utterance instead of matching an unfinished ordinary word.OpenAI and xAI voice replies also handle interruptions against the answer currently playing when another answer is queued, and later replies can continue after cancellation. The follow-up playback repair keeps a partial audio frame from ending the conversation during a provider pause. Direct voice-model history remains separate for each speaker while agent consultations share the room conversation; a room retains at most eight speaker connections, subject to the provider’s own limits.
Edit and split Discord messages
Long Discord replies keep their code, Unicode characters, and surrounding quote or list context when they need several messages, and attachment captions avoid extra empty code blocks. Sends and edits also preserve intentional indentation and trailing newlines, while an explicitly empty edit can clear an attachment caption without removing the attachment. Extremely small configured message limits can still constrain formatting, and the existing access checks continue to apply.
Send rich replies through Telegram
With Telegram rich messages enabled, collapsible details keep their headings, code, quotes, tables, and nested sections together through sends and edits. Unsupported markup remains readable as literal text, so examples do not silently lose their wrappers.Telegram progress mode also keeps Claude CLI commentary in one temporary message, shows when context compaction completes or remains incomplete, and gives the final answer priority over pending commentary. Commentary remains temporary even with verbose mode enabled. For installations that depend on a proxy, explicitly configured trusted SOCKS5 routes now carry Bot API requests and incoming attachments through the intended transport, including supported cases where the media destination cannot be resolved locally; the proxy itself must still be locally resolvable and reachable.
Change messaging settings while channels stay connected
You can adjust how long OpenClaw waits to combine a burst of messages without reconnecting Discord, Feishu, iMessage, Mattermost, Microsoft Teams, Signal, Slack, Telegram, or WhatsApp. New work uses the saved delay, while a setting change alone leaves an already pending batch on its existing schedule. Acknowledgement-reaction scope also applies to new turns without reconnecting the supported channels, and work already in progress keeps the policy it started with.Known webhook addresses now ask the sender to retry while a channel or plugin is being replaced. This depends on the sender honoring the retry response; the message has not been accepted or stored at that point. Multi-account IRC setups can also add or edit a non-default named account without disconnecting its siblings, while shared settings, default-account changes, and removals can still restart the channel. Apply controls to one message
Put a supported text directive before a task and OpenClaw keeps the task, including its formatting, while applying the requested controls. Thinking, verbosity, and authorized tracing can stay with that one message through queueing and model changes, then later messages return to their inherited preferences. A standalone directive still saves a default, and model selection remains persistent. Telegram’s separate handling of multiline commands can still discard later lines before they reach this shared parser.Native verbose menus in Telegram, Slack, and Discord show the current level and let you choose on, off, or full without changing anything merely by opening the menu. Malformed explicit text commands such as /exec gateway now return an argument error instead of becoming an unintended message to the agent. For scripts changing channel accounts, a blank --account is rejected before a change begins; omit the option when you intend the command’s normal default selection. Answer a waiting agent question
When Claude Code needs an answer before continuing, its native question can now reach the channel conversation instead of appearing only in the web dashboard. Replying in plain text to that same conversation can answer the waiting question and resume the run, including in installations with several agents. This repairs the existing question workflow, with Telegram directly demonstrated; messages containing media do not use this early plain-text answer path.
Follow progress and the final reply
Progress mode can stay quiet about routine tool calls while keeping the updates that help you follow the task or need your attention. On the supported Discord, Telegram, Slack, Matrix, Mattermost, and Teams personal-chat presentations, configured commentary, reasoning, and approval or failure notices remain available, and streaming.progress.toolProgress lets you opt into the tool log. Slack compact progress keeps its own presentation and omits plans.Narrated progress also catches up with activity that arrived while an update was being written, including urgent failures after a draft was hidden. When work finishes, a delayed typing or reaction start is followed by cleanup once that request settles, preventing it from bringing back an obsolete working indicator.
Preserve conversation replies and resets
A final answer already delivered to the same external conversation can now suppress the extra automatic reply or same-conversation agent announcement, even when another layer rewrites the tool’s visible output. This depends on confirmed final delivery to that destination; a progress update, a dry run, or a message to another conversation does not count as the answer.Conversation resets also preserve the distinction between a status confirmation and an ordinary answer, and resetting an existing but empty conversation no longer creates the malformed history that could block the next reply. Upgraded conversations with an older pending reset wait for an active reply to finish, while a late Stop during finalization leaves an already accepted answer completed. These fixes prevent the affected new failures; they do not reconstruct previously lost or malformed history.
Keep code, links, and speech examples intact
Code examples need to survive as code, including the spaces and literal characters that make them useful. Shared reply cleanup and Markdown rendering now preserve more of that content through tables, repeated-prose removal, and final message rendering, while one-word Slack or Google Chat link labels remain readable on plain-text delivery paths.Speech directives written inside Markdown code also remain literal examples in final replies and saved history, rather than being removed and treated as instructions to speak. The separate incremental speech cleaner is outside that repair.
Send and recover generated media and documents
Use commands and recover on other channels
Nextcloud Talk recognizes structured help and status commands, including authorized group commands without a bot mention, and an accepted message can recover through the existing queue after a temporary conversation lookup failure. Mattermost recognizes mention-prefixed commands when text commands are enabled and lets them bypass chat batching; later reactions, button clicks, and username checks can also retry a failed lookup instead of inheriting a cached outage. The already failed Mattermost event is not replayed automatically.Tlon summary requests refresh their history after an account restarts, and long IRC replies retain literal code and link destinations across messages. WhatsApp now delivers the final failure explanation instead of discarding it with intermediate error noise. For a confirmed iMessage helper stall, OpenClaw attempts bounded recovery for later actions, which can relaunch Messages.app and delay the original error by up to 30 seconds; the failed action is still reported and is never automatically resent.Direct Matrix encryption setup and encrypted account addition finish their client setup before publishing the enabled settings to a running Gateway. Concurrent account changes prompt a review and rerun instead of being overwritten, although verification can still fail and the encryption choice may still be saved. This change covers those direct commands, with the interactive wizard and separately running encryption processes outside its scope.
Talk directly from Apple Watch
Talk on Watch is a new experimental way to speak with your Claw without the paired iPhone carrying the audio or relaying each message. Enable Standalone Voice under iPhone Settings → Apple Watch, then open Talk on Watch and tap Start. You can choose an agent, read the recent transcript, mute the microphone, and end the call from the Watch; simply opening the screen does not start recording, and each call has its own conversation.Setup requires an administrator connection on the iPhone, a trusted secure Gateway address the Watch can reach independently, and a compatible realtime provider using ICE-lite and UDP. The Watch receives its own limited read and Talk credentials, while permanent provider credentials stay on the Gateway. There is no TURN relay or TCP/WebSocket audio fallback, so a network that blocks the required UDP connection cannot use this path. Talk configuration explains the supported combinations.Keep OpenClaw on screen until the call connects. Network recovery is bounded, and an OpenAI call needs a fresh start when its 30-minute lease expires. Physical Watch microphone and speaker behavior, wrist-down operation, radio handoff, and long-call endurance still need device validation, so treat this as an experimental capability. Recover Watch companion messages
The existing iPhone-relayed Watch chat now saves pending messages and completed replies on both devices, allowing a restart or reconnect to recover work without automatically repeating a send whose outcome is uncertain. Queued messages retain their original conversation even if you switch chats on the phone, and a saved reply can still be read after the spoken-reply wait has ended.Update both apps, then use iPhone Settings → Apple Watch → Message Delivery to inspect replies or a Delivery uncertain warning. Check the original conversation before resending uncertain work. Older unsent messages that lack enough delivery information appear as Needs review, and the original 48-hour deadline still applies to new deliveries and their saved replies. Use native realtime Talk and answer controls
Compatible audio-only clients can now use native GPT-Live with their configured ChatGPT OAuth or Platform credentials while the Gateway handles tools and tasks for the call. The client must explicitly support the Gateway-controlled mode; OpenAI GA Realtime still requires a Platform key for this mode. Status requests, cancellation, redirects, and follow-ups stay with the work started by that call, and saved conversation history is kept separate from what was actually said in the new call.When an answer to a pending question loses its confirmation, OpenClaw reports the uncertainty instead of sending the answer again as another instruction. Check the conversation before retrying. Questions from standalone attached MCP sessions need the Control UI or native question controls, and protected Copilot steering remains unavailable. Talk mode covers these client and authentication boundaries, along with the separate handling of call audio and accepted tasks. Interrupt Android Talk and follow its state
On eligible Android audio setups, Talk can keep listening while it speaks, so an interruption stops queued speech even after the provider has finished generating the reply. This requires active native echo cancellation and Android communication audio; other setups keep taking turns between listening and playback. Thinking, Listening, and Speaking now follow the current response and playback more closely, and new successful spoken answers appear once in Chat while errors and interrupted partial replies stay visible.The native speech loop also sends recognized phrases and resumes listening after the answer, keeps capture running when reply audio is muted, and respects Stop or a switch to push-to-talk. Around that conversation, Disconnect stays disconnected, failed settings loads are shown as errors rather than empty data, and unresolved sends remain visible for recovery. Android guidance explains the native Talk path, while Talk mode covers the audio requirements. Read and copy iPhone conversations
iPhone conversations keep the current reply and working indicator visible as the assistant moves through tool calls, with streaming tables growing without repeatedly shifting earlier text. Opening the keyboard preserves the latest messages when you were already following them, while a deliberate scroll or selected search result keeps your chosen position. Scrolling near the left edge also takes a more clearly horizontal gesture before it opens the sidebar.When you want to reuse part of a reply, Select Text opens an iOS selection sheet so you can copy a passage without taking the whole message. Code blocks gain a raw-code copy button on both iOS and Mac, tall Mermaid previews keep their first and last nodes reachable, and native Swarm progress responds to settings changes without reconnecting or bringing back an older enabled state. Use Android progress and dashboards
Android task progress now sits in its own attached panel above the message composer, expanding upward while the editor and its controls stay in place. Progress cards show labeled bars alongside their text and links, and the Effort and Permissions sheets keep their choices reachable on smaller screens. Policy default and Default model have distinct labels, so checking permissions is less easily confused with resetting a model choice.Jump to latest lives in the chat header and appears only when newer content is hidden, leaving more room beneath the messages. Opening Dashboard from a conversation now selects that conversation’s board and gives the embedded page a full-size viewport, so it can be read and used after it loads.
Keep mobile Gateway connections current
Android Stop, Forget, and reconnect now finish against the connection you selected, preventing pending secondary connections or old credential writes from reviving a connection you retired. Changing focus also preserves a handshake that is already underway. Disconnect shows Offline while retaining pairing; forgetting a Gateway removes its local saved connection, but does not revoke pairing on the remote Gateway.In the active iOS app, other enabled Gateways can stay connected while you use the focused one, including through temporary discovery gaps. With Background App Refresh enabled, the iPhone can also request opportunities to update its last-seen status and attempt a reconnect without a push relay. iOS controls that background schedule, and may suspend connections when the app is no longer active. See phone resource readings
The Devices page can show memory readings from connected iPhones and iPads, plus memory and available storage from Android phones, when the Gateway supports device resource reporting. The apps send a reading on connection and refresh it while connected, giving you a way to check phone resources from the same place as your other devices.These phone readings include processor count rather than CPU load. iOS omits disk usage, Android storage appears only when it can be sampled, and suspension or a lost connection can pause fresh readings.
Connect the Mac app to the right Gateway
The Mac app keeps remote address text in place while you finish typing, and connection failures retain the explanation needed to act on them. An incompatible protocol tells you whether to update the computer running OpenClaw or the Mac app, while conflicting saved device identities show their file paths and IDs. Those conflicts still need deliberate repair; changing a Gateway token is suggested only for a token problem.When you use several Gateways, chat commands, widgets, approvals, settings, and status stay with the window or connection that owns them. Primary dashboards follow a changed Primary, independent saved-profile windows keep their own connection, and older replies cannot replace the selected Gateway’s current settings. Switching Primary clears the old configuration draft, while reconnecting to the same Gateway preserves valid edits. A save already sent can still reach the previous Gateway, so changing selection does not undo an in-flight change.The Tailscale Dashboard link opens the root or configured custom path, heartbeat details follow the active Gateway, and a remembered Usage page stays open during dashboard startup. The Mac remote connection guide covers the connection choices and troubleshooting path. Sign in to a personal Gateway from your browser
If your Gateway uses Cloudflare Access, you can enter its address in the Mac app and sign in through your usual browser, then return to its dashboard under your own account without copying a shared token. The website’s Get the apps → Open in Mac app action opens the same connection editor with the address filled in, and the app remembers the selected Gateway after restart.Renewing the same account preserves its browser preferences, chat history, and queued messages. Signing in as someone else closes the previous account’s native chat windows and uses separate history and queues, leaving earlier pending messages with their original account. Removing the saved Gateway clears its credentials and dashboard browser data.This browser handoff currently supports Cloudflare Access, and native device approval remains a separate step unless the Gateway’s existing automatic approval policy allows it. Personal saved Gateways also stay separate from the machine Primary that supplies Mac capabilities and Talk. Eligible Team dashboards can use personal identity for attribution, while shared-token and password connections keep their existing owner flow. Inspect command and pairing approvals
Mac command approvals now put the command and working directory in a resizable panel, with wrapping, scrolling, selectable paths, and Copy for the exact displayed command. Details keeps executable information available without crowding the decision, and remote requests no longer say they will run on the Mac merely because that is where the prompt appeared.Pairing requests identify the device and its requested access, show administrator warnings, and distinguish a capability update from replacing a device token. You can inspect full IDs and versions in Details or use Copy ID. Command-Return approves the displayed request once, while Return alone does not; Not Now or Escape on pairing requests leaves them pending. Always Allow Here remains available only when the command policy permits it.
Use supported Mac controls in Dashboard Settings
Dashboard Settings gains a This Mac group for app behavior, device capabilities, permissions, and local Talk and update controls when a supporting Mac app exposes the native bridge. These controls remain owned by the Mac and appear only where that bridge supports them. Voice Wake trigger words belong to the connected Gateway, so their editor also works in an ordinary browser when the Gateway advertises the required methods.Mac AI setup now shows confirmed connection-test rejection reasons and lets you explicitly retry or choose another connection without an old response wiping newer input. Uncertain outcomes keep their verification step, and older Gateways may still require the existing wait. Other daily controls receive focused repairs too, with scheduled-job lists retaining recent edits and deletions, and the browser sidebar resizing and remembering its width even with only one or two tabs. Reduce idle Mac background work
The Mac app stops checking Tailscale while Connection settings are hidden, retires timers when requests finish, and stops presence sampling after opting out once the required clear succeeds. Its node worker also stays under the app’s process control, so restarting or stopping that worker does not leave it running behind the app.The animated menu-bar icon keeps its existing motion with less CPU work in the measured idle scenarios. This is a focused reduction in background activity and animation cost; battery-life gains and the cleanup of separately detached provider processes are outside these changes.
You can choose Original, Heritage, Clawmark, Origami, Pincer, or Open C in Settings → General → Dock icon, with light and dark previews side by side and the selection saved for each OpenClaw profile. Custom designs change the Dock icon while the app is running; Finder and the Dock after quitting continue to use Original. On macOS 26 and later, Original follows the system’s Icon & widget style setting.
The Linux AppImage packaging now avoids optional media dependencies and bundled Wayland libraries that caused the demonstrated startup failures and blank windows on affected systems. Supported media playback stays bundled, while the graphics connection uses compatible host libraries. Quick Chat also explains when a Gateway needs a missing token or password and directs you to its recovery path without discarding the paired device token.Check the Linux requirements before choosing a system for the companion. The AMD64 AppImage requires glibc 2.35 and GLIBCXX_3.4.30, which standard RHEL 9 and Rocky Linux 9 do not provide; extracting an AppImage bypasses FUSE requirements, not that library floor. The fixes address the reproduced startup failures, with graphics compatibility still depending on the host GPU and compositor. Read native controls in your language
The existing native-app languages receive updated labels and guidance across phones, watches, and Mac, including chat selection and code-copy actions, model controls, Dock icon choices, and Gateway error titles. Apple translations also cover standalone Watch voice setup and microphone permission, plus Mac browser sign-in and reconnect guidance, so the instructions surrounding those features are available in the supported language catalogs.
Use OpenAI's GPT-6 Astra and steer active work
OpenClaw v2026.9.2 adds support for OpenAI’s GPT-6 Astra, so accounts with access can choose it for conversations using text and images. You can select openai/gpt-6-astra with an OpenAI API-key profile or an eligible ChatGPT/Codex subscription. Subscription model discovery confirms account access before offering Astra; an unavailable catalog can temporarily leave it out of the picker.On the official OpenAI endpoint with an API key and the built-in OpenClaw runtime, Astra can continue reasoning and responding while direct tools run. A cached WebSocket also lets you send a correction into the active response, including text or images, without waiting for it to finish first. Accepted instructions remain attached to the conversation through continuation and reconnect. SSE keeps ordinary queued delivery, and these built-in-runtime capabilities are separate from native Codex execution.You can change the thinking level before the next turn while retaining a compatible cached prompt prefix. Automatic compaction, automatic truncation, pro mode, and API multi-agent mode do not support that optimization, and a restart or rewritten history starts a fresh request. Finish pending tool results or approvals in a compatible Astra mode before switching. Where runtime capabilities permit it, /think ultra also enables proactive delegation to sub-agents, using max effort in OpenClaw and xhigh in native Codex.Astra’s full context window is 1,050,000 tokens, with up to 128,000 output tokens, while OpenClaw keeps its default active input budget at 272,000. Choosing Off does not disable Astra’s reasoning, and the cost estimate preserves its higher long-context pricing tier. Select Meta Muse Spark 1.3
Choose your own account for a chat
People sharing a Gateway can now connect their own supported model accounts in Settings → Profile → Connected accounts, choose a default for new chats, and use Account for this chat to make a separate choice for an existing conversation. Changing the default leaves existing chats alone, and collaborators and forks keep the account already selected for that chat. Model availability, status labels, fallback checks, and retry estimates now follow that personal selection.Personal accounts support Anthropic API keys, OpenAI API keys or browser/device sign-in, and Grok/xAI API keys or device sign-in where those methods are enabled. The Gateway must identify each person first, including for CLI setup; a shared password or device pairing alone does not identify a distinct teammate. Collaborators see a personal-account label without its private email or account details. Shared same-provider fallback can still apply, so selection is not a billing guarantee or isolation from administrators. Claude CLI keeps its required account restriction.Administrators and integrations also gain a Gateway API for inspecting provider accounts and saving or clearing their priority order. Configuration-controlled order remains authoritative, and a successful save can precede the background refresh that applies it. Find available models after refresh
Model pickers keep the names, reasoning information, and configured choices they already know through more refresh and configuration-reload cases. Native Codex models retain their account-scoped availability, repeated browsing can reuse discovered inventory when a provider is unavailable, and Hugging Face’s bundled models remain selectable before a key is added. A listed model still needs valid credentials, compatible runtime support, and account access before it can answer.Hosted catalog updates can now import eligible tool-capable text models from models.dev for providers that opt in, so adding each supported model no longer needs a separate OpenClaw change. New listings appear after a refreshed catalog has been published and downloaded and the Gateway has restarted. Provider policies and configured allowlists continue to apply. Connect and discover local model services
The local-server guide now uses llmman, the maintained replacement for Inferrs, with corrected startup commands, readiness checks, and troubleshooting for requests that work directly but fail during a larger agent task. Existing Inferrs documentation links redirect to the new guide. Keep its unauthenticated service on loopback or behind trusted access controls.Managed llama.cpp also resolves a selected Hugging Face GGUF file without scanning unrelated files in a large repository, while self-hosted discovery keeps its time budget stable when the computer’s clock changes. These fixes preserve the existing model-address and integrity requirements. Continue and branch Codex conversations
Codex conversations keep the model and account selected for their native thread when you continue them, including imported conversations whose model differs from the agent’s default. Fork from here retains the draft and source thread’s current model on Codex 0.153 or newer, and an empty native tool catalog no longer makes a supervised conversation look corrupt. Separate Ask OpenClaw conversations also keep separate Codex threads.If compaction is interrupted after OpenClaw saves a new session, supported continuation paths can recover its recorded predecessor and keep the existing native thread. That includes ordinary messages, side questions, and same-thread resume, with outdated queued compaction and control commands prevented from changing the successor session. A confirmed deletion of an ordinary managed Codex thread instead creates a fresh native thread in the same OpenClaw session; it cannot restore the deleted native history.Ordinary post-tool summaries stay on the completed work’s prepared model and account. Supervised tool-only runs that cannot safely produce a summary retain their completed work and explain that no final summary was produced, without repeating those actions.
Open large Codex histories
Continuing a long Codex conversation now uses a bounded history renderer that keeps the needed context without first building a much larger temporary string. Resuming large saved records also spends less CPU scanning them, and prompt annotation or confirmed steering avoids rebuilding search information when the searchable content has not changed. These changes reduce specific preparation costs; large-record decoding and parsing can still take time.When browsing native Codex or Claude sessions on connected computers, slow hosts can now add their results after the initial partial list arrives, subject to the viewer’s current access. Internal voice consultations also stop producing false prompt-mirroring warnings when their hidden input was already saved.
Launch the intended Codex runtime
Managed Codex now uses version 0.153.4 and resolves the installation owned by its plugin across supported installation layouts, including Windows launchers in paths with spaces. A missing managed package produces repair guidance instead of silently selecting an unrelated older binary. Externally managed runtimes retain the general 0.149.0 minimum, while individual features such as canonical message forks require a newer version.Restricted and message-only turns keep their intended tool limits. If an older administrator-managed Codex policy blocks those turns, the error explains the manual file or MDM migration needed to preserve ChatGPT-only login restrictions. Scheduled runs whose app inventory times out keep their saved access binding and report a timeout suitable for existing retry handling, without executing tools or asking for unnecessary reauthorization. Codex cloud sessions also skip startup of an OpenClaw worker they do not use.
Stop Codex turns and understand refusals
Stopping a newly accepted Codex request now waits for confirmation that the selected turn ended, including side questions, while preserving other conversations on the connection. If conversation-history writes are blocked, cancellation and timeout can still release the turn, and a delayed write cannot later save an obsolete successful answer. Missing cancellation confirmation remains a reported failure.Recognized biological-risk and cyber-policy refusals now explain the refused turn without telling you to start over or automatically trying another model. You can continue the same conversation with a later request; the provider’s safety policy still determines what it accepts.
Use installed Claude Code and answer its questions
OpenClaw now talks directly to the Claude Code executable already installed on your computer, preserving existing login and configuration, warm conversations, resumed sessions, approvals, and questions. Script wrappers and command aliases retain their verified launch arguments, and fallback session titles use the first real prompt instead of preceding instruction metadata. Keep Claude Code current.Malformed Claude questions now return the failing field and correction guidance, so a corrected call with a fresh tool-use ID can reach you. Codex and Copilot also show question prompts that could previously remain invisible, including Codex side conversations, while supported credential requests provide a Control UI link for protected entry. A visible prompt can still encounter a separate problem receiving the answer.When Claude deliberately ends a turn without a reply, recognized stop reasons are explained and automatic replay is suppressed. Check any tool effects before retrying manually, because the work may already have changed something even though no final answer arrived.
Preserve compatible reasoning and prune tool context
Supported moves from Opus 5, Sonnet 5, Opus 4.8, or Fable 5 onto Fable 5.1 can retain readable earlier reasoning. Fable 5.1 also keeps the hidden runtime context needed for that continuity in saved transcripts and exports, while leaving it out of visible chat and compaction summaries. Other Anthropic-compatible models return to transient runtime context, avoiding repeated old details on later requests. Switching away and back, changing thinking level, or rewriting the prompt can still invalidate reasoning.Session pruning keeps trimmed tool results trimmed across later requests while preserving the full local history. Direct Anthropic API-key requests in cache-TTL mode use server-side clearing based on token thresholds, rather than the client TTL and hard-clear settings, and protection rules now include historical tools that are no longer available. After restarting a branched conversation, client-side restoration can still pick a sibling branch’s pruning marker and change the context sent to the model. Recover eligible provider failures
A model can still be working before it has visible text to send. Anthropic, Google, Mistral, Bedrock, and Ollama now count parsed keepalives, reasoning, and other response events as activity, and active CLI-backed answers retain their existing quiet allowance and time to finish delivery. Truly silent calls and overall run limits still expire.Temporary provider errors receive more appropriate retry handling and advice. ChatGPT SSE preserves the service’s requested retry delay, and eligible Bedrock connection failures before output can continue from completed tool work within the existing recovery limit. A failed unrelated harness plugin no longer blocks healthy models, later requests can recover from a transient catalog mismatch, and beginning provider sign-in leaves serving plugins active. These paths keep their existing safeguards against replaying completed effects.For a new billing failure, the initial wait falls from five hours to ten minutes, although upgrading does not shorten an already-active window or detect a top-up immediately. Explicitly ordered preferred credentials can also be retried on a later real request after their cooldown. Repeated rate-limit failures without a provider reset time can progressively delay those attempts up to 24 hours, so returning from a paid fallback is subject to successful recovery.
Keep OpenAI request context and terminal facts
OpenAI Responses retains the instruction to finish an answer after compaction through reasoning-only and empty-response retries. If request preparation fails, a later successful request can establish fresh continuation state so subsequent turns stop resending the entire history; that first recovery request still sends the full conversation.Failed requests with unfinished tool calls now retain the provider’s reported usage, served model, and available failure reason when terminal information arrives. Incomplete tools remain blocked, along with later parallel tool completions after the incomplete call. Tiny managed output budgets are raised to the API’s 16-token minimum, and explicitly selected agents can use their allowed API model overrides on multi-agent Gateways without requiring a system agent.
Configure voice and video services
Respect exclusive Copilot tools
Keep optional Codex apps from blocking chat
An unavailable optional Codex app no longer prevents an unrelated conversation or heartbeat check-in from starting when a successful app snapshot identifies the problem. OpenClaw logs the unavailable apps and continues with the remaining tools, including supported resumed sessions and forks. The unavailable app stays unavailable, and snapshot failures, tool permissions, and scheduled access checks retain their existing restrictions.
Retain Codex usage and ordered live replies
Concurrent conversations keep reply text in order while a reader temporarily falls behind, including across tool and final events, within the existing connection limit. A client that permanently stops reading can still be disconnected.Codex turn usage now adds the reported counts from every unique completed response, including responses before a retry or cancellation. Those totals remain separate from the current context window, so a missing final context snapshot stays unavailable instead of showing the cumulative usage as if it were the remaining conversation context.
Build trusted custom plugin interfaces
Feature plugins can give your Claw its own pages, panels, widgets, and session actions, or replace parts of the conversation interface and the whole workspace. An agent can build a plugin archive and propose that exact archive for your review before installation, giving you a way to shape the interface around your work without changing OpenClaw itself.Native interfaces from user-installed plugins are experimental and off by default. Enable Settings → Labs → Custom plugin UI, restart the Gateway, and reload your browser tabs, using the connected Gateway’s own HTTPS or trusted localhost address. Install only code you trust because it runs with your signed-in operator permissions, without a plugin sandbox. Authors should pin and test their OpenClaw host version.Normal layouts currently hide the floating Customize UI entry, limiting access to replacement selection and Reload plugin UI. A full plugin workspace still offers Built-in recovery. Disabling the lab keeps installed plugins and their saved state, and enabled bundled interfaces such as Workboard remain available. Keep MCP tools connected through changes
Continue coding with cloud workers
A coding agent on an OpenClaw cloud worker or paired session host can commit, push, and open a GitHub pull request during its turn, so it can see the result and respond before handing the work back. This needs GitHub CLI on the worker and an available shared Gateway GitHub account with access to the repository. It uses that shared identity, not the paired computer’s personal login.When a replacement worker starts behind the session’s pushed branch, it brings in those commits while preserving local edits and deletions, allowing the agent to continue with an ordinary push. Divergent history still needs attention. File reconciliation back to the Gateway remains separate from Git history, and Codex remote-exec keeps its own publication path. Use a dedicated worker account where required by the setup guide because per-turn credentials do not isolate processes sharing an operating-system account or revoke tokens already held by background processes.Cloud startup now rejects unusable local-only callback addresses before allocating a machine. At the other end of a session, SSH workspace cleanup can finish after the worker’s RPC credential expires, with ownership and SSH checks still enforced. Stop and Move show the current provider cleanup cause and any supplied retry guidance when release remains pending, while local checks of larger returned workspaces do less repeated file work. Continue a shared Beam snapshot
A shared Beam snapshot can now become the start of a conversation with a Team agent. Write a message in its composer and OpenClaw copies the retained history into a new session belonging to you, using the source model when it is available and allowed, or explaining the switch to the agent’s configured model.The copy follows the Team agent’s normal permissions and treats imported history as untrusted reference material. It does not resume the source computer, inherit its tools, or synchronize later changes. Shared Beams are visible to Gateway operators with read permission; continuation also requires write or admin permission and access to the chosen agent. Delayed uploads no longer replace a newer snapshot or turn a completed snapshot live again at the same revision, keeping the saved history used for continuation intact. Preserve Workboard work through reloads
Reloading or disabling Workboard now stops its retired background services and lets already accepted operations finish before closing their database connection. Saved cards remain available when Workboard reopens, without each reload accumulating another set of open database handles or leaving old polling services writing warnings.Commenting on a blocked card, refreshing its claim, or releasing that claim also reports a successful saved update correctly through the plugin-tools MCP bridge. Custom integrations consuming heartbeat, release, comment, or unblock results should read the returned card under card. The Workboard registration helper again supports integrations that let it create and manage the store.
Save accepted Logbook work
Logbook now lets accepted captures, activity analysis, and generated standups finish saving before it closes their database during an orderly restart or disable. That also preserves the original analysis error when work fails, instead of covering it with a database-closed error. Shutdown can wait within the host’s existing deadline, and forced termination can still interrupt that work.Questions about a busy day now load only the latest 200 eligible observations already used for the answer context, keeping their chronological order without first loading the whole day’s observations.
Inspect, repair and update plugins
Plugin updates give a clearer account of what is installed and what can change. If an official plugin is pinned to an older version, update and dry-run output can show the newer registry release and the explicit command to replace the pin. Existing pins stay in place until you choose otherwise. Repairing missing plugin files and updating a package now use its current contents, including removing settings for children that the replacement package has retired while preserving unrelated disabled plugins.Doctor also separates configuration problems from plugin problems. It keeps the original invalid-setting diagnostic instead of blaming whichever plugin happened to encounter it, and an absent plugin with an exact enabled: false marker no longer attracts contradictory installation advice just because it remains allowed. Real warnings still appear when console logging is set to warn.For valid retired plugins.installs records, openclaw doctor --fix preserves installation details before removing the old setting so service startup can proceed. It can also repair catalog-proven legacy official ClawHub provenance and explain the installation and storage paths behind a trust refusal. Malformed records still need correction, and trust rules remain in force. If an unreadable native service definition blocks an update, follow the service recovery guide, preserving and resupplying any values stored only in that service’s environment. Keep plugin tools and schemas compatible
Package plugin icons locally
Plugin branding now comes from artwork included in the installed package, so displaying its icon does not contact an arbitrary outside image host. Channel gallery rows, details, and setup screens use matching names and locally bundled icons, making the integration you are configuring easier to recognize.Authors must include assets/icon.png to retain custom branding. URL-only packages show a generic fallback until updated, and missing or invalid artwork does not disable the plugin. Empty icon requests also close their file handles correctly instead of accumulating open files on repeated views. Keep hooks with the current session
Session-aware command integrations can now receive the current session UUID through the resolve_exec_env hook, letting a plugin pass it to scripts for attribution or callbacks. Exporting an environment variable still requires a plugin that chooses to do so.Configured prompt and model-input hooks also remain active when HTTP scripts or local agent work selects a non-default model, while disabled and excluded plugins stay inactive. Installing an npm hook pack no longer requires changing inherited npm dry-run or download-directory settings; the installer keeps its archive in its own temporary workspace.
Continue external-agent tasks within their permissions
A2A tasks that need an execution approval now keep their original task and reply path through the operator’s decision, including peers without an outbound URL. Ordinary text such as “Explain /help please” reaches the agent unchanged.A2A integrations must send plain-text tasks for agent work and use an authorized human command surface for slash commands. Leading-slash requests are rejected, even with permissive command allowlists or a ROLE_USER message value. The routed agent keeps its permitted tools, and approval still belongs to an authorized operator.For IDEs using the Gateway-backed ACP bridge, an externally stopped run can show its carried error cause instead of only an unexplained cancellation. Recording long ACP sessions also avoids repeatedly loading previous message payloads while preserving saved replay. On MCP process tools and Codex’s OpenClaw sandbox process tool, accepted final results clear their matching completion notice so it is not repeated later. Read directory results and locate fetched files
Direct calls to File Transfer directory tools now give the agent usable filenames and distinguish files from directories. A listing can continue after its last displayed entry, and fetched directories show the saved root and relative paths needed to open the files locally. Large fetched trees remain saved even when only part of their manifest fits in the text result; the result explains how to inspect omitted files, and reports when an unrepresentable path prevents text pagination from advancing.Successful individual file fetches also expose both their saved path and a reusable media ID, so an authorized write tool can copy those bytes without guessing at a hidden identifier. Restricted tool sets receive self-contained Bitable and search guidance without being sent to unavailable companion tools. If Bitable creates an application but cannot retrieve its table metadata, the guidance now tells the agent to keep the successfully created application. Preserve plugin state through cleanup
Restoring a plugin registry now cancels obsolete cleanup that was still queued, preserving its saved session state and reporting only cleanup changes that actually committed. Choosing cleanup targets also avoids decoding large saved prompts, reducing that particular source of pauses while keeping retained content intact.Looking up or listing saved plugin artifacts reads committed data without creating an absent shared store. Missing storage produces an empty result, while damaged or unsupported storage still reports an error. Cleanup that writes to storage remains a separate operation.
Set up the Lobster plugin
The Lobster setup guide now includes the missing prerequisite. Install the optional official plugin with openclaw plugins install @openclaw/lobster, restart with openclaw gateway restart, then allow its tool. The tool remains unavailable in sandboxed tool contexts. These are corrected setup instructions for the existing integration.
Use Swarm without enabling a separate lab
Swarm lets an agent coordinate several helpers and collect their results, and eligible agents now have it available by default. It remains experimental and follows your existing tool permissions and limits, with an explicit opt-out in Settings → Agents & Tools → Labs → Swarm. OpenClaw Code Mode remains a separate opt-in.Larger Swarm jobs in Code Mode now queue calls when the bridge is full, allowing accepted work to advance as space opens without manually splitting the job into batches. Stopping the run prevents its remaining queued calls from launching, and pauses within the same process preserve the original arguments. Result collection also preserves the text or structured format requested when each helper started, while agents sharing global sessions can use the same group name without sharing one another’s concurrency allowance or retention schedule.Existing Codex chats keep the tools they started with. Use /new or /reset in an ordinary unlocked chat to get the current tools; keep a supervised chat intact and start a separate ordinary session from the global New Session page with a concrete Codex-backed model. Saved Codex scripts that call tools.openclaw__agents_wait must change to tools.agents_wait. Continue Code Mode after a tool error
Organize conversations and inspect related tasks
Keep long conversation work responsive
Preparing a long saved conversation now happens in background workers so that reading its history does not hold up unrelated Gateway activity. Context loading also batches message reads, startup can check for existing messages without decoding their full contents, and resuming an older view of a conversation uses fewer database statements when saving the next message. These changes reduce interference and unnecessary work while preserving the selected conversation branch; the amount of history still matters, and the work does not have a fixed memory cost.Branching keeps your current conversation in place until the new branch has saved, preserves current session details, and prevents an older run from writing after another run takes over. Shared databases also retain the correct agent ownership in session views and save the activity records needed to inspect non-default agents. Incognito history follows the active branch again while remaining in memory, and stopped history workers release their database leases when cleanup succeeds. A cleanup failure stays visible with restart guidance before deletion.Stopping or timing out compaction now prevents further preparation once cancellation is observed, including after a session handoff, and native CLI cancellation is reported as compaction aborted. An operation already in progress may still need to settle before cleanup completes.
Read command outcomes and monitoring output
Command results give your agent more useful clues about what happened. A foreground command that exits unsuccessfully without printing anything now explicitly says (no output) beside its exit code, and background process lists distinguish an overall timeout from a command that stopped producing output. Polling a completed job clears its pending completion notice only after confirmed chat delivery or successful saving of the tool result, keeping that notice available when delivery or persistence fails.For people working in the terminal, a URL used as an initial message can appear before or after the destination session URL, as shown in the TUI guide, and unusually long wrapped table cells no longer hit the repaired argument-limit crashes. There are two small scripting changes to account for. Stopping openclaw sessions tail --follow now returns 130 for Ctrl-C or 143 for termination instead of success, and diagnostics exports reject empty --log-lines or --log-bytes values. Omit those flags when you want their defaults. Use exact paths and working guide links
Folder browsing now preserves the exact path returned in a listing, including a trailing space, so selecting Project with a trailing space opens that folder instead of a sibling named Project without one. The Files pane also accepts contained names such as ..notes, and matching configured memory sources can discover and read those files without mistaking the name for a parent-directory traversal. This fixes directory browsing; New Session submission and saved-preference handling are separate paths.Documentation section links have been repaired across setup, troubleshooting, permissions, transcription, and skill-trust guidance. Computer-use and Podman instructions point to their intended sections, and maturity pages have unique jump targets without changing their recorded scores or implying a new QA run.
Read usage and failure information
Checking usage and costs no longer loads large saved skill or system prompts just to prepare the metrics, avoiding the associated history-processing stalls while leaving full context available where it is needed. Turn completion and usage displays also skip fallback price lookups when recorded costs already suffice, or when only token counts are being shown. The pricing calculation and displayed costs are unchanged, and estimated costs remain estimates.When a run fails without enough information to classify the cause, the message now says the agent run failed and keeps the available model context instead of blaming the provider. Recognized provider errors retain their specific guidance, so the wording reflects what OpenClaw actually knows without claiming to diagnose or repair an unknown failure.
Keep completed tool work and answer results
When a file already contains the change you asked for, the agent now treats that as a successful step and continues to the rest of the task, including its final answer. Local CLI agents also keep access to their embedded Gateway tools after starting a run.Completed work has two more paths back to a useful response. If a temporary provider failure interrupts the final summary after all tools have finished, eligible runs can try a summary without executing those tools again. When a CLI-backed turn has already returned its answer, a later session-saving failure preserves that answer and its usage information instead of automatically repeating the action. Remote computer cleanup failures likewise retain the captured result and the earlier error or interruption, so the cleanup problem remains visible. Resolve that problem and check what the tools already did before retrying work whose outcome is uncertain.
Preserve accepted conversation history
A failed conversation repair now leaves both the active chat and its saved history at their last committed state, allowing the same repair to be retried once the problem is resolved. When an authorized rewrite succeeds, the message already accepted for the current turn stays in the active conversation exactly once, including through repeated rewrites and later replay.History-index rebuilds also wait for writes they have already accepted before reporting that they have finished, while keeping the database resources needed to complete them. Alongside those changes, stored messages avoid false “edited” errors caused by serialization, and damaged session metadata follows the full reader’s parsing rules when it is used for listings and cleanup decisions.
Stop stalled command preparation
Command timeouts and cancellation now apply while a process is still starting, including service-managed commands waiting for credentials, so those startup waits can return a timeout or cancellation result. The first cancellation reason stays attached to the run even if a timeout fires afterward.Cancelling a request also releases runtime state that nobody else needs and skips obsolete workspace preparation that has not started yet. Other callers can keep using shared preparation, and finished or combined queued chats release their unused cancellation listeners. Work already performing discovery is not forcibly interrupted by this cleanup, and stopping startup does not guarantee that every descendant of an interactive terminal process has been removed.
Continue after a device is permanently offline
If a paired computer will not reconnect, Continue on Gateway… can now move its session back to the computer running OpenClaw so you can resume from the last synced workspace. This is an explicit recovery choice that discards changes still held only on the offline device, so use it when waiting for that device to return is no longer the right option.The cloud-session recovery guide explains what remains on the Gateway. Physical cleanup can still be pending after the session becomes available again, and moving the session does not confirm that an old process on the disconnected computer has stopped. File reads, agent recreation, and runtime housekeeping
Agents can read from the beginning of a blank line without receiving a false end-of-line error, including when an ordinary Markdown or memory file starts that way. Operators can also delete an agent with file cleanup, recreate the same ID, and create new sessions without restarting the Gateway.Several narrower changes remove work that no longer needs to be retained. Code Mode can release completed calls’ inputs while slower calls continue, compute workers no longer require the parent process to hold their input copies throughout execution, and session-list refreshes can let go of obsolete cached pages. Long-conversation preparation avoids repeated validation and unnecessary copies, while voice processing skips debug-capture filesystem checks when capture is disabled. These changes reduce specific processing and retention costs; total history loading can still be dominated by database reads.
Report empty replies and finish Apple Talk playback
If final filtering removes everything from a reply, OpenClaw now reports a failure instead of leaving the conversation looking successful with nothing to read, including when a fallback model also produces no visible answer. Deliberate silence and valid delivery or continuation paths keep their existing behavior.On Apple clients, Talk relay playback now follows the audio player’s actual completion. The speaking state, playback acknowledgments, and microphone echo suppression stay active until queued audio finishes, while pause, interruption, and cancellation can still stop playback earlier.