Connect and choose a provider
Connection screens lead with the problem preventing sign-in and what to do next. Remote setup uses one Gateway secret field, while local setup generates a token by default. Provider selection keeps credentials attached to the provider they belong to, instead of accepting an unrelated sign-in result.Opening desktop or browser setup detects available providers without activating one until you choose it. Fresh native-conversation discovery starts unchecked, and cancelling or failing setup does not select a different provider. Guided setup can also finish without an AI provider. Saved consent choices survive reconciliation with an existing agent.
Finish model setup and reach your first conversation
On a Mac with an independently managed local Gateway, setup can continue into model configuration without waiting for a CLI installation that was deliberately skipped. Finishing model setup still requires a verified response, and failed verification now retains the useful underlying error instead of treating failed or timed-out output as success.Supported provider setup leaves generated model lists to discovery while preserving existing saved models and explicit replacement modes. Channel choices also follow the selected agent’s workspace, while newly installed runtimes become available to the first dashboard conversation.
Install on Docker and Windows
Docker setup preserves the ownership of your project files while repairing the OpenClaw state that needs to be writable. Packaged plugin dependencies are reachable from their Docker installation, and browser-enabled images prepare the private cache parent for the non-root runtime user. Operator-mounted cache permissions still belong to the operator.Windows Startup fallback launches retain saved service environment overrides when inherited variable names use different capitalization. Anchored Windows Gateway commands also avoid opening an unwanted console window.
Source installation and workspace templates
Source-install tooling moves to pnpm 12.3.4, and workspace template instructions clarify bootstrap, backup coverage and identity fields. New workspaces receive more direct default agent guidance without rewriting existing personalized files. Setup scripts also receive valid JSON when combining QR setup-code options.
Share a read-only conversation
Session creators and Gateway admins can publish a revocable link to a conversation’s existing and future text. Anyone with that public link can read it until access is revoked, so review the conversation before enabling sharing. Revoking access cannot recall copies people have already saved. The read-only page leaves out tools, reasoning, files, images and executable widgets.Private-session preview links remain separate. They show a generic OpenClaw social card without reading the conversation, and opening the session still requires its normal authentication. Public HTTPS proxies may need the documented preview routing configured.
Find active work and navigate long conversations
Live activity shows permitted running and queued sessions when you open it or reconnect, with a visible limit notice and connection status. Its recent open-tab feed follows permitted activity across agents and conversations independently of the selected chat. Reloading or changing Gateway or account clears that temporary feed.In wide chat panes, a position rail previews and jumps between loaded conversation landmarks, making earlier exchanges easier to find. Pins now belong to root conversations. Existing child pins disappear and no longer protect those children from maintenance.
Return to mentions and follow notifications
The Mentions Inbox keeps retained mentions and dismissals through restarts and upgrades without replaying old browser alerts. Its existing bounded retention applies, and incognito conversations remain excluded. Notifications open the relevant question, conversation, automation run or task, including failures beyond the first automation page.Activity retains its layout through refresh failures, and choosing an online person opens their Activity feed. Hidden tabs defer background Inbox inventory work until you return.
Follow delegated work and Review progress
Subagent transcripts stay view-only, with a route back to the parent conversation and Stop for runs that can be cancelled. Live progress remains in the parent conversation, while visible persistent sessions created by an agent stay editable in their parent tree.Completed Swarms retain their child counts after cleanup and reload, with fully successful groups collapsing into expandable rows. Child completion still does not mean the parent’s final synthesis has been delivered.Review keeps delayed results attached to the latest selected task or file, and activity rows preserve readable labels without presenting edit-operation totals as checkout diffs. Reopened chats refresh their pending approvals rather than reusing an old set.
Keep drafts and documents through conversation changes
Failed steer or redirect attempts restore their text and attachments without overwriting a newer draft, and delayed rewind completion preserves newer text, attachments and Goal mode. Documents attached during an active run retain extracted text and supported rendered pages, while uploaded images remain visible as a new workspace finishes loading.Resetting a conversation retires old progress cards after the reset succeeds, and deleting its parent clears Side chat. Suggested follow-ups can start without first creating a Git worktree, and generated session titles are available directly in rename dialogs.
Understand failed turns and successful retries
A run that fails before producing an assistant reply leaves a notice that remains after reload, and recognized storage failures explain what needs attention. Redacted supplied failure reasons survive immediate status and later refresh.When a fallback succeeds within the same run, the conversation shows the answer without an empty failed-attempt placeholder. Buffered text is retained before a retry resets the stream, while partial or unresolved failures remain available rather than being hidden.
Reconnect without losing your place
Panels retain their loaded data during connection interruptions and refresh when the connection returns, with offline and restart status in the footer. Suspended tabs can recover missed update notices while keeping their route and stored draft; unsaved settings still need to be saved or discarded before recovery. A tab already stranded by an earlier missed update may need one manual reload.A signed-in operator browser with a live pending pairing request reconnects automatically after approval. Paused connection states retain manual guidance, and existing authorization requirements still apply. Bundled UI startup recovery preserves pending sign-in and asks before sending its credential to the captured destination; damaged packages receive reinstall guidance.
Open dashboards and keep their context
Dashboards keep a themed loading presentation until their widgets are ready, and loaded dashboards retain notes, scroll position and chat drafts across navigation and Settings within the existing per-pane cache. Moving to another Gateway or user clears that cache.Agents can publish bounded native reports containing text, metrics, tables, charts and links without an HTML frame. Report properties are limited to 8 KiB and contain data rather than executable content, and rejected dashboard actions show their error immediately.
Save settings and select devices
Settings retain submitted values and newer edits through delayed refreshes and reconnects. Failed Appearance patches offer a retry for the rejected change, while separate unsaved drafts keep their own Save action. Rejected choices return keyboard and accessibility state to the saved value, including explicit null choices where supported.Phone-width and embedded settings keep usable navigation, and Gateway switching shows the destinations clearly. Saved unavailable execution-device bindings stay visibly selected as unavailable, rather than implying that another device was chosen. Profile headers show the connected person’s identity when known. Devices also supports editable aliases, and remote configuration-file opens confirm that the file opened on the Gateway host. Unsaved device-alias edits are dismissed on reconnect.
Search conversations and browse folders
The command palette keeps chat-search failures visible alongside usable navigation and catalog results, and model results follow the selected agent’s current catalog. Model entries take you to Models rather than silently selecting one. Model-picker search stays applied through refresh, with Escape clearing the query before closing.Folder browsing filters as you type and supports keyboard completion. Availability-aware shortcuts open supported side panels, while loaded local conversation links show titles and hover cards.
Read attachments and copy file content
Supported same-origin text attachments can be read and selected directly in Files, with a literal UTF-8 preview up to 256 KiB. Unsupported or external documents remain download-only. File references with line ranges open at the first line, and leaving an agent-file preview through Edit restores focus to the editor.Download names retain literal percent sequences and complete supplementary Unicode characters. Copy actions also avoid a delayed older fallback replacing a newer clipboard choice, and browser-card URLs can be copied on plain HTTP.
Read formatted replies and GitHub references
GitHub issue and pull-request links appear as recognizable chips, including standalone URL code spans and supported repository-aware shorthand. Other code stays literal. Raw previews, copied code, indented blocks and saved captions preserve their text and ordering, including HTML comments and closing tags.Verified imported conversations hide generated trust wrappers only in their human-facing presentation; stored history and model-facing protections remain intact. On narrow screens, chat text and working output align with the composer, while avatars avoid overlapping the conversation.
Follow pull-request and GitHub status
Visible pull-request sessions reuse current Git and GitHub facts and avoid redundant refresh work after replayed messages. Profile status also distinguishes a failed GitHub lookup from a disconnected publishing account, keeping a temporary read failure from looking like a sign-out.
Start repository work and native coding terminals
Available create-capable CLI agents appear by default, subject to terminal availability, permissions and node authority; explicit opt-outs remain available. Bun-hosted Gateways can start native Codex and Claude Code terminals on Linux and macOS using Node on the Gateway PATH.Empty repositories explain that an initial commit is required, and placement failures keep their specific, readable diagnostics. Cancelled placement dialogs stay closed after delayed loading, while pending commands can show instructions before completion.
Start repository work on a remote runner
Repository sessions can start directly on managed cloud or paired nodes without first cloning on the Gateway. The remote node owns checkout and setup, accepted changes survive Stop through retained checkpoints, and Move to Gateway is an explicit action when local execution is wanted.Update paired hosts or reprovision cloud nodes with the current worker bundle. Checkpoints retain accepted work; they are not full Git history or backups of unaccepted changes.
Upload files to a terminal
Terminal staging is bounded to 256 MiB and 64 retained directories, while the existing 16 MiB per-file limit and 24-hour retention remain. A partially failed batch can insert paths for files already uploaded. Recovered uploads retain their original expiry through renames and cleanup retries, and inserting a path does not execute a command.
Understand usage and export matching details
Context meters use the matching last-run prompt budget and fall back to context capacity when that budget is stale after a model or cap change. Refresh reloads the selected session’s timeline, conversation and prompt breakdown alongside totals, while exports stay tied to the concrete session instance being shown.Repeated tool invocations are counted correctly within selected loaded timeline intervals. Chart sampling, filter preparation and provider history views also avoid repeated local work within those views.
Read the interface in your language and find help
Existing translation catalogs follow the current interface, including connection, approval, Swarm and prompt-budget labels. Control UI documentation is split into task-focused pages, with restored legacy anchors keeping older entry points useful.
Rehearse an update before activation
OpenClaw validates supported core and plugin updates in isolated candidate state before switching the running installation. Enabled npm plugin targets are checked before downtime, and private plugin copies preserve supported linked and workspace dependency layouts so rehearsal can load them against the staged host. Incompatible agent stores are rejected before installation changes.Eligible validation failures can enter a bounded repair using your configured model in disposable rehearsal state. The candidate must pass independent validation before activation, and changes that require editing your configuration are reported for you to resolve. Plugin metadata checks confirm the selected target but do not reserve its eventual download.
Verify and recover the activated installation
Final update verification checks service ownership, health, the running version and build, plugin activation, channel readiness and HTTP readiness without making a model call. A failed check follows the supported repair or rollback path, while a healthy restored service is reported as recovery rather than a successful update. Verified rollback also avoids starting unnecessary automatic triage.Eligible failed updates and repeated Linux systemd startup failures can start a bounded installation-owned repair with existing authentication and permissions. On macOS, launchd startup recovery provides diagnostics. Only one repair runs per installation, and uncertain cleanup can block an automatic successor while leaving manual diagnosis available.
Read update progress and report failures
Long updates retain their progress watcher until completion, and update history keeps terminal failures, restart outcomes and current update availability distinct. Abandoned records can be recovered without stopping a healthy matching Gateway when no post-update work remains, with conservative checks for active drivers and explicit recovery for records lacking driver identity.A failed-update action can prepare a sanitized report for your review and submit it only with explicit consent. Missing GitHub authentication offers a browser handoff rather than sending anything automatically.
Update an existing 2026.9.2 installation
Eligible updates driven by 2026.9.2 can cross a shared-state schema change while the older updater finishes reading its update history. Agent-schema migrations, missing state metadata and failed state migrations still require the documented external-install and fresh-Doctor recovery path. See schema-bump recovery if your update is refused. Switch installation channels and align official plugins
Switching between Git and packaged installations preserves the owned service profile and distinguishes updater staging from unrelated checkout changes. A same-version change can still replace the installation method, and returning from an npm development link preserves the external checkout. Restoring that link after failure does not by itself verify the checkout or authorize an automatic restart.Post-update maintenance runs through the activated CLI. Version-bound official plugins follow the selected release, missing untracked official plugins receive the matching stable version on their first repair, and explicit pins keep their intended selectors.
Keep work available across restarts and updates
Eligible interrupted work, follow-ups and attachments can resume after an update, while accepted child results wait for their parent to recover. Update the Codex plugin with the Gateway for the corresponding work recovery; unknown submissions remain unconfirmed, and missing attachment bytes need to be sent again.Cloud provisioning can resume across a Gateway restart, and an idle cloud session whose old worker was deliberately retired can prepare a replacement on its next message. Explicit Stop and destroy intent still take precedence. Shutdown also closes abandoned setup prompts and stops queued startup work from entering a closing Gateway.
Let Linux child work finish during shutdown
New and reinstalled systemd service units let child work drain while the Gateway shuts down. Existing service definitions are preserved during ordinary updates, so run openclaw gateway install --force for the selected profile to receive the changed service configuration. Operator-supplied systemd overrides remain separately editable. See restart recovery.Service installation and repair use monotonic deadlines so a wall-clock adjustment does not consume their timeout budget. Recover service connections on Mac and Windows
Mac lifecycle commands recognize LaunchAgent ancestry so an in-service restart can hand off without killing its own caller, including services without the usual markers. Stop, install and uninstall still require an external shell in that case. Older launchctl status output is also recognized.Windows startup creates protected SQLite staging directories through native APIs without the compiler subprocess implicated in reported antivirus failures.Tailscale crash recovery retains cleanup ownership, and foreground route conflicts point to the confirmed owning process rather than suggesting unrelated route removal.
Preserve the configuration you wrote
Configuration edits and Doctor repairs keep authored settings, explicit defaults and supported include-file ownership intact. An eligible nested change is written into the fragment that owns it, while unsafe shared-file or mixed-array changes remain refused rather than being flattened into a different configuration. Failed prefix recovery preserves the original file, and audit history retains the writer label supplied with a change.
Run Doctor and database maintenance
Doctor checks maintenance ownership before expensive database inspection and reports required migration failures without proceeding into later repairs. Initial integrity checks move off the main event loop, while schema repair and compaction retain their own costs. Startup maintenance refusals are distinguished from crashes instead of feeding a channel-suppression restart loop.Other conversations can save edits while cleanup checks a database’s integrity. Deletion still waits for the complete verification.General Doctor checks avoid reading personal browser profiles for optional readiness checks, reporting that they were not inspected. Unsupported workspace state and unreadable databases retain actionable manual recovery guidance. Removing an installed Claw also drains its verified monitors, which requires an authenticated running Gateway even when no jobs are listed.
Back up state and read Git history
Large Git backups and restores use bounded batches, reducing the need to hold complete database tables in memory while keeping verification checks. State-only backups leave shared-workspace scratch out of the archive, and oversized required Git output produces an error instead of a partially parsed history.
Maintain a source checkout
Source installations build browser assets from the checked-out source and can run maintenance from another working directory. Normal source-server updates build the runtime, plugins and UI without regenerating developer declarations unless requested. Windows MSYS Git paths are normalized at filesystem boundaries while revision arguments remain intact.
Understand maintenance and connection diagnostics
Slow-operation logs distinguish queue, work and completion delays and identify the process or worker that emitted them. Connection diagnostics retain close causes, duration, local ping-write state and last-pong age, helping operators distinguish observations without treating a completed local write as proof that the remote side received it.
Browse saved meetings and search transcripts
The meeting library lets you browse saved notes, search full transcripts and manage capture sources in Communications settings. Exports include the complete selected meeting even when a search filter is active, with Markdown and JSONL available under the existing archive permissions.The download limit remains 4 MiB. Larger exports fail without producing a partial file and need the documented CLI export path on the host. Capture status describes subscriptions rather than proving that a recording is active.
Stop and resume meeting capture
Meeting capture keeps its history and ownership through more interrupted starts and cleanup failures. Duplicate auto-start attempts settle as conflicts instead of creating another recording, and stopping a meeting requests cancellation of active consults and ignores late speech. Cleanup failures remain visible and retryable until termination is confirmed.Discord recordings stay independent of voice-conversation work. For full room transcription coverage, use batch transcription; realtime-only capture remains limited. Occupancy capture only reopens recent transcripts whose stored origin confirms a generated ID, preserving supplied-ID and unknown legacy history.
Send Telegram albums and follow progress
Consecutive eligible photos can be sent as native Telegram albums of up to ten, keeping their order, captions, reply targets and forum topics. Single photos and messages with controls continue to send individually. Concurrent forum topics retain independently paced typing actions, subject to Telegram’s own display and account backoff behavior.Enabled answer previews can show compaction status, and native choice controls no longer repeat their fallback list in the message text. Telegram conversations also keep visible delegated tasks attached to their parent conversation without relaxing spawn permissions.
Control Discord access and bot replies
Bots in mention-only mode need an active native or configured mention to reply. A handoff that relied only on Discord’s reply ping needs an explicit mention. Policy-only changes apply to new messages and interactions without waiting for an active Control UI turn to finish, while transport changes and mixed edits remain deferred and work already admitted keeps its original context.Status explains empty allowlists and deferred reloads, and setup catches a numeric application ID pasted where a bot token belongs. Authorized reset commands recognize the supported sender aliases without changing the session ID.
Read Discord replies and use voice conversations
Discord persona and bot replies share Markdown formatting, preserving leading indentation and expanding mentions after multiline code while leaving names inside code literal. Nested Components v2 starter text and forwarded snapshots remain readable when the agent joins a thread.Voice recordings remain available until transcription finishes. Supported English voice requests that mention farewells can take the request path while recognized closing phrases stay quiet.
Keep Slack structured replies intact
Slack delivers valid structured sections intact even when their accessibility text exceeds the preferred chunk size. Custom emoji names that happen to match JavaScript object properties remain usable, and reply preparation avoids repeating table and Markdown work without changing delivery order.
Preserve Teams replies and shared uploads
Multi-part Teams progress replies keep their first segment and deliver later parts in order after stream close. Finalized replies, edits and native file captions preserve supported formatting and mention entities, while unfinished previews can still show Markdown.Shared Slack and Teams uploads avoid an extra file-data copy at handoff, and cancelled captured responses can release transport without waiting for a diagnostic copy of the body.
Preserve Feishu mentions and group routing
Feishu uses accepted group-binding changes on the next message and keeps mention names readable when messages are combined. Replies to merged-forward cards include bounded, ordered forwarded content, and static replies with too many Markdown tables fall back to post delivery instead of being rejected as cards.
Read Matrix room information and maintain accounts
Matrix leaves archived state out of active-account selection and Doctor scans. Explicit replies keep their selected quoted message inside the intended thread, and wording-only edits avoid repeating mention alerts when the required history can be read.Room information includes alternative aliases, while disclosed polls are recognized across supported event namespaces. Matrix can also start on the opt-in Bun runtime, with native crypto bindings still required for encryption and Node remaining the recommended runtime.
Recover queued replies without sending another copy
Pending or ambiguous queued deliveries remain with the recovery owner instead of automatically sending another copy. Safely abandoned claims can be retried, and authorized reset commands can recover a chat after terminal restart-recovery failure. Accepted or uncertain injections still need to settle before their ownership is released.Deferred tool continuations discard obsolete interim answers while retaining the final reply and attachments. Broadcast results also report structured native send failures and partial outcomes accurately.
Finish child delivery and continue the requester’s work
An answer already delivered to the main conversation stays marked as delivered when an older helper notification or history update arrives. Replies still being sent retain all their parts. Once follow-up work has been accepted by the requesting conversation, it continues under its normal runtime and Stop controls instead of inheriting the shorter notification deadline.
Respond to WhatsApp approvals after an outage
WhatsApp approval reactions remain available for replay after transient Gateway failures instead of being discarded prematurely. The Gateway still decides which answer is accepted first.
Follow channel progress and answer questions
Persistent progress cards keep checklists visible through tool calls and clear without erasing unrelated activity. Native subagent progress reaches the supported Slack and Discord displays, while inactive cards pause. Progress visibility follows its configured setting and retains transport behavior such as iMessage typing.Question prompts explain typed replies when a channel has no buttons, and forwarded context remains separate from the sender’s own commands so quoted instructions do not execute a second time. Loopback questions are delivered to their originating channel, and cancelled unsent questions do not replay later.
Keep media and message formatting readable
Shared Markdown formatting preserves block boundaries inside list items and the surrounding text around fallback tables. Long blank-line runs in details replies avoid repeated formatter scans, and XML examples keep literal final tags inside Markdown code regions.Video attachments with non-square pixels display at their intended proportions, while one-off speech follows the destination channel’s final voice-versus-audio choice.
Connect the intended channel account
Pairing notifications come from the approved channel account, and a notification failure does not undo the approval itself. Mattermost direct messages on private servers retain the account’s existing network permission, Nostr honors positive relay acknowledgements, and failed iMessage helper pipes stop leaving pending requests waiting.Signal, Discord and Mattermost select their declared WebSocket implementations on opt-in Bun installations. Account names in CLI listings remain display labels alongside stable IDs, without changing routing.
Keep Buzz replies at the thread root
Implicit Buzz replies stay at the active thread root, while an explicitly selected child reply keeps its nesting.
Find notes when semantic search is unavailable
Keyword indexing can continue when optional embedding credentials or providers are unavailable, so a missing optional model does not make all of your notes disappear from search. When SQLite extensions cannot load, a batched fallback scan can still return vector-backed results, although that degraded path can be costly on larger collections.Exact filenames retain their ranking in project-aware searches, short literal terms match note contents with Unicode case folding, and older dated notes remain eligible for keyword recall. Explicitly required embedding providers still report failures; keyword fallback does not supply semantic vectors.
Search while memory maintenance continues
Published memory remains searchable while changed-file writes and cleanup contend for database access. Deadline recovery can return memory-file keyword hits with a warning, while session hits remain outside that fallback. Large state replacements and clears also yield between batches so other queued work can proceed.When results may be stale, Memories shows the existing rebuild command with its warning. Exhausted file-watcher capacity falls back to the existing synchronization path, although an initial search may still use the previous index while that refresh finishes.
Avoid repeated memories from long conversations
Adding messages to a long conversation now resumes memory import from the previously verified position, avoiding repeated imports of earlier messages. Existing memory history stays intact, while edits and truncations still trigger a conservative rescan.
Keep memory maintenance within the current context budget
OpenClaw-managed compaction accounts for the full incoming request once that context is prepared, and background memory work stays separate from human prompts. Cold sessions use their prepared model’s context limits while honoring smaller explicit caps, and transcript growth after the last provider report contributes to fresh accounting.In the built-in agent loop, cancelled or failed tool turns no longer commit unfinished exchanges to context-engine memory. Native runtimes retain their own compaction behavior.
Recall the current question
LanceDB automatic recall follows the current question when a conversation changes topic. Promotion previews remove blocked-origin entries before ranking, leaving their limited space for eligible notes.
Use the prepared LM Studio embedding model
LM Studio embeddings use the prepared model instance and its context capacity, and can reload an evicted embedding model when preloading is enabled. Existing cached vectors are retained rather than recomputed by these fixes.
Read memory results and diagnose failed imports
Memory and Import Memory show agent-list errors with a usable retry instead of remaining in a loading cycle. Reads from additional memory folders report relevant permission or file errors, and skipped symlink roots point to their canonical directories without silently rewriting the configuration.Cited excerpts keep the leading spaces and tabs that make code and structured notes readable. Profile workspaces and Termux home paths are honored by memory-host lookups, while command JSON distinguishes a disabled backend, a backend that failed to open, and a successful search with no results.
Read and index larger notes with less repeated work
Long lines and weighted Unicode stay within embedding chunk budgets, and searches can rebuild an index after the chunking version changes. Curated annotations are scanned without repeated parser work while preserving their recall metadata and project isolation.Small excerpts from large notes can be selected in one forward pass while preserving continuation offsets and the existing output budget. Memory Wiki pages without link brackets skip unnecessary link parsing, and indexing reuses prepared database statements within each nonempty file.
Keep learned skills with the agent
A skill your agent learns now belongs to that agent’s Workshop, so moving between workspaces no longer means moving the collection along with it. Installed skills and suggestions have separate views, keeping what the agent can already use distinct from changes awaiting review.Startup and Doctor migrate legacy skills when ownership is established. Ambiguous or conflicting copies remain available for review, and the old skills.workshop.allowSymlinkTargetWrites option is retired. Read and review complete skill instructions
Workshop comparisons now show the complete instructions with additions and removals inline, including changes near the end of a long skill. Current instructions remain readable while the comparison loads; the comparison covers the instruction body rather than frontmatter or supporting files.Collection reviews are also instructed to look across related skills while preserving useful task boundaries. Compatible CLI backends, including Claude CLI, can perform these reviews within the permitted root using the existing sandbox and approval settings.
Recover interrupted Workshop changes
Doctor now explains what to do when a suggestion’s draft is missing and distinguishes recoverable work from preserved backups that need your review. Installed skills and remaining recovery files stay intact, and an unfinished apply must be recovered before its suggestion can be dismissed.
Create skills and use skill commands
Skill-library creation and import forms check names before continuing and explain the existing naming rules. For scripts, skill JSON keeps meaningful whitespace in descriptions and paths while continuing to remove terminal control sequences.
Choose how Workshop learns
Automatic learning can maintain complete Workshop packages with normal file tools while foreground work continues. In auto mode those are direct edits without an automatic rollback copy, and completed writes remain if the background run later fails or is cancelled. Choose propose mode when you want to review each capture before it changes a skill.Pending Workshop approval requests also regain their Allow Once and Deny controls in the authorized Telegram DM, including requests that began in a group. Follow weekly collection reviews
In auto mode, weekly Workshop reviews now run as ordinary isolated automations, with file discovery and run history available through that workflow. They review the agent’s collection using ordinary file edits, so completed changes remain if a later step fails or is cancelled; there is no new whole-collection backup or automatic rollback.Reviews need a supported backend, such as the embedded runtime or a compatible restricted Claude CLI backend. If sandboxing is enabled, it must allow writes to the Workshop. Codex-harness and node-placed CLI reviews remain unsupported.
Use Android across folds and small windows
Android keeps content clear of separating hinges, and on suitable book folds it keeps navigation beside the content. In tabletop posture, the conversation sits above the fold and the composer below it, with the layout falling back when the available panes are too small.When the keyboard leaves little height, chat extras move into Details so your draft and Send controls remain accessible. Larger text can wrap in more settings and quick actions, and approval details gain clearer contrast. Chat and attachment menus, plus Model and Permissions sheets, also stay within usable fold-safe regions.
Keep Android conversations and settings current
You can send a follow-up while Android is working without clearing that run’s output, and reopened chats return to the latest content while manual scrolling still pauses following. Android keeps completed runs settled when delayed history or send acknowledgements arrive, and overlapping history requests no longer leave the chat’s health refresh unfinished. Resolved approval cards disappear together with their outcome, while a failed file share leaves the preview open so you can retry.During prolonged outages, Android backs off repeated reconnect attempts and resumes retrying when the network returns. Settings search finds existing options by name or category, and model settings follow the selected agent’s credentials and accepted configuration changes. Failed model refreshes show a warning while preserving choices and drafts, with another attempt available through Refresh chat.
Understand Android model usage
Android’s compact Model sheet keeps more of the conversation visible while distinguishing the space left in the current context from the latest run’s accumulated usage. Stale counters clear after compaction and history refresh, and optional model-call details remain available without treating unknown usage as zero.
Use Dashboard settings on Apple devices
The Mac and iOS apps now bring connected administrator settings into Dashboard while keeping connection setup and offline recovery in native controls. Older Gateways need the matching Dashboard support, and sensitive device-capability changes still require native consent.On iOS, saved app-local Talk provider, voice and language overrides are retired in favor of the Gateway’s Talk configuration. The old default share instruction is also retired; instructions supplied with an individual share remain available.
Start an iPhone voice conversation from Shortcuts
The Start Live Voice action opens the current chat and starts Talk from Siri or Shortcuts. Your phone still needs to be unlocked and the app in the foreground, with pairing, provider setup and microphone permission completed.
Keep Apple conversation history in order
New local messages retain their identity and place in the conversation when history refreshes, even when device clocks differ. Delayed history also keeps completed runs settled so the composer remains available.
Connect Apple Watch voice
Normal Apple Watch setup now includes voice authorization in the same connection action. Existing Watches connected only as nodes need to reconnect, and starting a voice conversation still requires Start and microphone permission.
Manage Mac connections and daily costs
The permanent Gateways menu opens or focuses a window for each connection and shows live status while the menu is open. The Mac automation menu also counts every enabled job for the selected primary Gateway.The Mac Connection window uses native Settings controls and toolbar tabs, and Gateway alerts can appear without blocking app shutdown. Today’s cost totals follow the Mac’s local calendar day, including daylight-saving changes.
Control Mac app connections from a shell
The bundled openclaw-mac command lets you inspect and configure the running app’s primary and saved Gateway connections from Terminal or SSH. The app retains ownership of Keychain access, and running-app commands accept secrets through protected files or standard input. A saved connection still needs to connect successfully before it is ready to use.
Use interactive replies on Linux
Linux widget replies stay connected, and Quick Chat reopens in the right place so its controls stay usable.
Maintain paired devices and app packages
Persistent paired computers retain the current worker build between sessions, avoiding another installation when that build is already present. A new build still needs installation on first use. Android setup also saves replacement access before retiring setup credentials, so a newly supplied setup code keeps its intended meaning.
Choose which connected account to use
Administrators can see each provider account’s credential source and health in Models settings, change supported account priority for the selected agent, and sign out of one account without disconnecting the others. Clearing a custom order removes the saved priority while leaving accounts connected; inherited and provider-managed orders explain their restrictions. When an explicitly selected account disappears, OpenClaw keeps that choice and offers recovery guidance instead of silently choosing another account. Missing environment-backed credentials are reported locally, so restore the environment value and reload secrets on a running Gateway before retrying.
Choose an ordered fallback chain
Agents settings now offers searchable model choices for building a fallback chain. Selected models appear as removable chips in priority order, and you can still add a custom model reference when it is not in the catalog. Session diagnostics can also show which fallback completed the answer while keeping your selected primary model distinct.
Continue through temporary provider failures
Temporary rate limits and other eligible provider failures can recover within the same run, keeping completed tool work and attachments available and the recovered answer together. Retry waits remain cancellable, and a terminal error stays visible when recovery is exhausted. Authentication failures, billing problems and refusals retain their own handling, while exhausted usage windows can move to an eligible fallback.After an eligible transient WebSocket failure, a tool-free final answer can use already-completed work without replaying its actions.CLI-backed background work also keeps its existing bounded allowance while work or native input remains pending, rather than being stopped as though nothing were happening.
Keep model choices attached to the right agent
Ordinary model changes now apply to the current chat by default, including administrator selections, while explicitly configured agent or global scopes remain available.Local and CLI-backed model views now preserve the selected agent and canonical provider, and managed Codex conversations use a newly selected model on subsequent turns. Native-owned sessions retain their own selection rules.
Keep prompt caches warm during ongoing work
Tool loops and changing background progress now preserve more of the stable conversation and tool content that supported providers can reuse. Responses history stays append-only, Claude CLI avoids repeatedly changing its startup context, and Codex resends workspace references when they need introduction or refresh.Provider-specific fixes preserve Gemini’s final instructions and stable caches, keep Anthropic tool checkpoints independent of system edits, and place Bedrock checkpoints against retained conversation history. Native OpenAI cache settings reach supported transports, while supported Anthropic-compatible routes receive their cache markers. These changes follow each route’s retention settings and capabilities.Supported Amazon Nova models on Bedrock also gain opt-in prompt caching with a five-minute lifetime.
Read cache usage and cost estimates
Usage separates cached and fresh prompt tokens when Ollama reports the required counters, and request-level diagnostics help explain cache misses. Codex side questions now reach the usage hooks with their tool-loop counters intact.Cost estimates preserve already recorded service-tier prices and apply the corrected rates to new eligible Anthropic requests. These are OpenClaw’s estimates and diagnostics; the provider remains responsible for its bill.
LM Studio now budgets against the context of the loaded model instance, and with preload enabled sends chat to an instance that has enough room. If a new instance is loaded, the request uses its returned identity while your configured model reference stays the same. This avoids budgeting for a larger instance and then sending the conversation to a smaller one.Local model setup preserves other agents’ capabilities and defaults to compact tool discovery. Run openclaw doctor --fix if an upgrade reports retired local-model setup markers.Native Ollama avoids silently truncating history when a conversation exceeds its available context. Its requests honor per-request sampling overrides, including explicit zero values, and retained reasoning stays with tool follow-ups without becoming visible answer text. Setup rejects models known to support embeddings alone before selecting them for chat. llama.cpp preparation also preserves configured preset defaults, comments and unmanaged options. Fresh llama.cpp installation allows time for the first macOS security check, and managed installs receive updated runtime binaries. Continue CLI-backed conversations
Cold managed Codex workers wait until they are ready before starting a first turn. Claude CLI-backed questions can retain their supported waiting deadline, and mixed CLI output handles quoted JSON examples without mistaking them for the answer. Confirmed complete Codex replies remain available when final settlement takes too long, with a warning when saving them could not be confirmed. Side questions preserve completed answers while forwarding cancellation and reporting a disconnect promptly.
Preserve streamed answers and tool media
Provider adapters preserve initial Anthropic text and thinking, keep images with the tool results they came from, and retain tool-schema constraints. Generated-video downloads reject malformed responses, while image setup stops after cancellation or timeout. If an OpenCode Go or compatible completion stream ends after its tools have finished, OpenClaw can recover a final summary without replaying those tools. Several streaming paths also reduce repeated local parsing or copying without changing the provider’s generation speed.
Refresh model catalogs after failures
Failed discovery now stays visible while compatible previously discovered models remain available across more providers, including DeepInfra, NVIDIA, Bedrock, Google, Copilot, Ollama, external llama-server and LM Studio. A successful empty response is still empty, and changing credentials or endpoints can invalidate earlier inventory.Browsing models can initialize a cold catalog on demand, and source installations can load provider plugins that depend on import-only modules. Downloaded hosted catalog changes activate after a full Gateway restart. Finding a model remains separate from having credentials that can actually run it.
Repair retired model choices
Doctor can repair persisted automation choices when a provider explicitly declares a model route retired. Restart after the repair and explicitly re-enable jobs that were automatically disabled. Account pins, restrictive policies and locked native sessions remain in force.The ChatGPT model retirements handled here leave Platform API routes unaffected. A model merely missing from a catalog is not treated as retired.
Keep scheduled and manual runs distinct
Manually running an overdue automation now delivers a fresh result without changing the stale-delivery rules for ordinary scheduled runs. A forced run of a disabled one-shot reminder keeps that reminder disabled, and paced checks retain their deadlines through a restart.Recovered work can finish successfully after a spawn was rejected before dispatch, while skipped on-exit work is reported rather than silently queued for later.
Recover monitors and legacy job ownership
Accepted private monitor notes now survive reply transformations and reach the next check without appearing in public replies or notifications. Monitor reconciliation yields so other Gateway requests can make progress during startup or reload. Doctor can repair known legacy multi-agent job owners, and an unresolved owner no longer stops valid jobs from running alongside it. Ambiguous jobs remain inspectable and are skipped until their ownership is resolved.
Choose models and inspect automation history
Automation model suggestions refresh when the catalog changes, and a failed read leaves your draft intact. History and status views avoid some repeated preparation and pause hidden-tab refreshes until you return, while scheduled cost estimates retain the run’s own model prices.
Wait for a direct hook to finish
Direct agent-hook callers can opt in to waitForCompletion and receive bounded status that distinguishes a reply, intentional silence and delivery outcomes. The completion response contains status rather than the model’s response text. The default remains acknowledgement of admission, and mapped or fan-out calls keep that existing behavior.
Keep scheduled results and delivery intent
Images produced by a scheduled report remain in the conversation after reload, and a child’s final answer can replace interim media. Reports intended for the current conversation count as delivered there without inventing an external destination; a separately requested external delivery still has to succeed.Heartbeat and cron execution also preserve pending events when foreground work takes precedence, keeping later recovery tied to the intended result.
Build managed automation flows
The TaskFlow examples now use supported Lobster approval and resume flows, with child work linked through its authoritative owner. These are bounded examples using prepared synthetic batches; connecting a real inbox or pull-request source still requires its own adapter.
Follow the agent’s browser live
The Browser panel shows page repaints as they happen, so you can follow a page loading, scrolling or responding without waiting for the next screenshot. Existing click, type, scroll, Annotate and Inspect controls remain available.Paired-node browsers, Chrome MCP existing-session profiles and routes where streaming is unavailable continue to use screenshots. Frames remain subject to the requesting connection’s access and the browser’s navigation rules. Open links as native Mac tabs
Links opened in the Mac app now appear as native WebKit tabs in the Browser panel, replacing the separate link sidebar. They stay with that window when you switch conversations, with a URL bar, navigation controls and the option to open the page in your default browser.Annotate and Inspect take a one-shot capture of a Mac tab. These are pages you browse directly, separate from the Agent browser tabs your agent controls; links from Settings still open in the default browser.
Return to browser results and capture the right page
Chrome relay tabs can also recover after attachment loss without restarting the browser stack. Opening an old browser result keeps a stopped managed browser stopped and offers Start browser when needed. Preview capture preserves focus for verified visible attached Chrome sessions on macOS and Linux, and screenshot annotations follow the actual image scale and crop.
Set up the Chrome extension on a Mac
The Chrome extension can be set up from the Mac dashboard or local CLI, with Chrome’s approval and any required restart still part of the connection process. The dashboard action applies to that Mac even when its Gateway is remote.
Type into a remote desktop
Remote desktop input sends supplementary Unicode characters as complete code points, avoiding split characters during typing and deletion. The keyboard stays disabled until connected control is ready.
Retry an interrupted desktop shutdown
Failed cloud-tool results are recorded as failures before they enter conversation history. A failed desktop cleanup remains visible and can be retried before another desktop opens. OpenClaw keeps the resources needed to finish that cleanup, and blocks reopening while the previous desktop remains unresolved.
Read page content and keep download names
Existing-session browser profiles can upload files again, including multiple files when the page input supports them, and page-evaluation results retain embedded code fences. Browser-node media keeps its safe node-side filename when saved through the Gateway, making downloaded files easier to recognize. Page extraction also uses the supported bundled DOM entry point when Readability first loads.
Follow team activity in Reports
When installed and enabled, the optional Team Reports plugin collects authenticated GitHub activity and explicitly configured Discord sources into daily, weekly, and monthly reports. It is disabled by default. Stored history, people timelines, calendars, and optional model summaries make it easier to return to what happened across a team.Reports mark incomplete periods and source-coverage gaps, use UTC reporting windows, and remain behind Gateway authentication and operator read permission. Light and dark themes, GitHub avatars, and expandable activity lists help with browsing; collection still has documented limits, including omitted review-submission bodies and some historical commit and attribution cases. In an embedded tab, a theme choice follows in-tab navigation rather than being saved in browser storage. Update plugins for the current SDK
Plugin authors should follow the SDK migration guide when updating execution-policy, approval, inbound-media, and session integrations. Execution-policy helpers now live under execPolicy in agent-harness-runtime, approval account helpers belong to approval-native-runtime, and approval filtering uses the full matchesApprovalRequestFilters contract. The retired generic forwarding evaluator has no drop-in replacement.Use buildChannelInboundMediaPayload for inbound media. The abortAndDrainAgentHarnessRun callable and its returned data remain available, but its removed named result type must be inferred. MCP prompt adapters return typed prompt results, preserving descriptions, roles, and native images for vision-capable models while Code Mode retains the original JSON.Discord, llama.cpp, and Voice Call preserve their declared 2026.9.2 host support through scoped optional-helper and local transport fallbacks. Those accommodations do not restore intentionally retired SDK exports. Load installed plugins and preserve recovery copies
Plugin installation stages managed packages before publishing their files, preserves exact recovery information, and replaces package manifests atomically after builds. Failed deletion leaves a disabled installation available for a later retry, while refreshed metadata and SDK modules reach subsequent plugin preparation.Expired plugin-install owners stop deleting copied source files, and recovery keeps exact ownership and filesystem checks. Retain reported recovery files until the current installation has been checked.OpenShell retains host shadow copies after mirror failures and reports where recovery data remains. Uncertain backups and concurrent replacements stay preserved, so an incomplete restoration is distinguishable from a backup directory that only needs cleanup.
Keep MCP connections and plugin hooks available
Session-owned MCP servers now remain alive between turns by default. An unset or zero idle timeout disables idle eviction; a positive timeout opts into it. Reset, deletion, Stop, and shutdown still clean up their servers, and run-owned servers still end with their run.Startup and shutdown also coordinate late listeners and service cleanup, and context-engine plugins receive completion for successful compaction that had nothing to remove. Failed, cancelled, and owner-lost compaction attempts remain separate from successful completion.
Continue connected coding-agent sessions
Connected coding agents preserve more of the context around their work, including ACP arguments and history, SDK terminal outcomes, replay order, and empty client tool results. Successful closes retire their managed delegates, while failed closes remain retryable and wait deadlines remain distinct from terminal outcomes.ACP history limits now count UTF-8 bytes consistently, which can make previously undercounted Unicode history eligible for earlier eviction on a later write. Transcript fallback cannot reconstruct every tool or system event, and unsupported saved model overrides may still require resetting the session.
Prepare cloud workers and inspect startup
Cloud bootstrap reports individual preparation phases so operators can locate delays, and runtime archives use bounded streaming preparation instead of thousands of temporary files. Updated warm images can reuse the installed runtime in later sessions, without implying that every warm session starts faster overall.Preparation completes before a provider allocation is recorded, failed local preparation can retry, and idle remote sessions can finish Stop without waiting for unrelated provisioning. Worker Git operations preserve patch bytes and use Windows-compatible paths, while portal connections handle either loopback address family.
Discover installed tools and inspect integration status
The system agent can read installed plugin versions, sources, and dependency diagnostics directly. Tool assembly continues past a safely reported broken factory, preserves the originating tool context across supported backends, and avoids repeating plugin eligibility work within a single operation. Read-only discovery does not change installation or approval authority.
Inspect account and runtime diagnostics
Personal GitHub connection status no longer needs an agent workspace, and Profile links effective agent authentication to its account settings. An authenticated account still needs access to the repository it will use.Prometheus can identify the running process and loaded build, while supported diagnostics exporters report elapsed garbage-collection duration. These observations help identify the runtime and its activity; they do not establish health or attribute a particular delay to a collection event.
Run supported integration transports under Bun
Affected Gateway, worker, voice-call, and ClickClack connections use their declared transport implementations under Bun, preserving the options and payload behavior those integrations expect. The fixes are scoped to those paths and do not establish complete Bun compatibility across OpenClaw.
Load files and media through installed integrations
Fetched files keep readable names through media staging, PDF extraction respects global plugin disablement and document allowlists, and HTTP cancellation reaches input downloads. Cancellation does not stop a codec that is already running.
Keep Workboard drafts and Logbook entries readable
Workboard can refresh pinned navigation names without discarding an open card draft, while Logbook timestamps stay clear of the activity stripe.
Delete beamed sessions and archive external entries
Beam sessions can be deleted after confirmation, and supported external catalogs offer their own archive action. Beam deletion is permanent, although a later upload can recreate the session; a Codex archive follows that catalog’s separate, potentially reversible behavior.
Review device capabilities and pairing accounts
Requests for additional capabilities on an already paired device survive disconnects and restarts until they are resolved. Keeping a request available grants no access, and ordinary device pairing still expires after five minutes. Upgrade the Gateway and older CLIs that write directly to its database together, because old writers can remove aged requests that a later upgrade cannot restore.Pairing commands reject explicitly blank account selectors, caller-supplied fields cannot replace a request’s scope, and revoked node connections lose access before asynchronous cleanup finishes. Approval listings also show the scope of executable grants.
Keep execution within its permissions
Plugin setup validates the file it is about to load, and delegated model overrides are checked against the destination agent’s resolved model. Filesystem transfer checks include exact archive entries and their implicit parent directories, cloud media access stays with the filesystem owner, and eligible Apple state files have unintended extra ACL grants removed within the supported ownership rules.Tool-policy groups use the same aliases and membership as core. Claude native Bash honors fully bindable exec allowlists under on-miss prompting while retaining deny and always-prompt behavior; an argument policy is not a sandbox. Prometheus scrapers now need effective operator read permission and receive a refusal when it is missing.
Protect credentials and private connection details
Unrelated Settings saves preserve plugin secret references, sensitive-field metadata survives plugin ownership changes, and private Talk route identifiers stay out of public configuration and catalog projections. Failed local secret lookups explain the problem without disclosing the secret itself.Saved CLI context is restored only within verified account and transcript boundaries. Unknown, imported, mixed, or legacy history is not automatically replayed or deleted. Blank or stringified-null Gateway tokens are refused; inline tokens can be repaired with Doctor’s token-generation action, while external references need correction at their source and clients need the updated credential.Documentation also distinguishes authorized, user-requested sign-in handoffs in private conversations from reusable secrets, warns about shared plaintext credentials that still need attention, and includes enabled diagnostic exports when explaining where data can go.
Keep private runtime context out of replies
Private yield context and recognized runtime prefaces are kept out of public tool results and delivered replies, while Codex dynamic-tool text is redacted before budgeting and truncation. Streamed reasoning previews also handle the supported echoed-marker case without stripping ordinary reasoning or final answers.The updated runtime-context projection applies to genuinely new sessions; existing transcripts retain their earlier policy. These targeted changes do not establish a general prompt-injection or context-disclosure guarantee.
Bind desktop access to its connection
Desktop viewing and control end when the requesting Gateway connection disconnects or loses authority. Connection-bound tickets and both relay directions are checked, while internal callers without a connection retain their existing timeout-based behavior.
Honor Android's approximate-location choice
When Precise Location is off, Android coarsens cached, fresh, and pending location responses and removes altitude, speed, and bearing. The two-kilometre grid is an approximation method, not a guaranteed minimum distance from the real position, and changing the setting does not retract locations already delivered.
Preserve trusted network connections
Protected HTTPS renews leaf certificates while keeping the process trust chain stable, allowing existing subprocesses to continue beyond the previous one-day boundary. The authority key remains scoped to the process, with a longer-lived certificate; operators should still protect copies of that key.Realtime transcription retains its payload limits on the affected Bun transport path.
Understand telemetry choices
Telemetry documentation explains opt-in controls, inventory counts, and network-level IP handling. The local preview command is described as a preview from the current CLI process rather than a history of submitted data. These help and documentation corrections do not change payloads or consent defaults.
Understand public transcript sharing
Public-sharing guidance clarifies who can enable a link and what it exposes. Shared links make existing and future conversation text available to anyone holding the link, and revoking access cannot recall copies someone has already saved.
Compose tools in Code Mode
Fast tool replies return to the same running JavaScript environment, allowing valid in-memory values to survive without an unnecessary checkpoint. Explicit yields, exhausted budgets, and worker pressure still checkpoint execution and enforce the existing limits.Optional TypeScript checks use the available tool declarations before execution, errors point back to original source, and bounded console output helps with diagnosis. TextEncoder and TextDecoder remain available across waits and resumes, while unawaited promises are identified instead of appearing as empty objects. These additions do not grant unrestricted filesystem or network access.
Read files and structured results in Code Mode
Code Mode receives complete admitted structured tool results for filtering and reduction, with explicit errors when a result exceeds its budget. Directory and search results avoid duplicating bounded text, and file data stays separate from display notices so pagination and handled errors remain usable.Find and Grep callbacks read text from details.content. Directory callbacks use LsToolDetails.content and optional nextAfter, passing the cursor as after for another page. File reading and media preparation also avoid holding some discarded text and buffers longer than needed, while their existing decoding and output limits still apply.
Schedule tools and continue delegated work
Bounded recursive session spawning is enabled by default, retaining depth, concurrency, target, and sandbox restrictions. Set maxSpawnDepth to 1 to retain leaf-only children. Tool scheduling respects sequential-only tools across Code Mode, Tool Search, and MCP while parallel-capable work can still run concurrently.Core handoffs acknowledge settled children, yielded orchestrators can resume their original task, and reset or cancellation targets the current child execution. If unfinished native child work cannot be cancelled, the conversation remains uncleared with an actionable error. Ordinary sub-agents are recommended for one or a few tasks, with Swarm reserved in guidance for larger batches.
Manage long conversations and session lists
Older durable conversations are archived instead of deleted, retaining their identities and transcript generations for restoration. The default target rises to 5,000 active sessions while explicit configured limits remain in effect, and protected history may exceed disk targets.Session listing, selection, and single-session actions avoid loading unrelated saved prompts or doing full-inventory work when metadata is sufficient. Long-conversation preparation also reduces repeated copying and projection work, without changing billing totals or turning localized measurements into a universal response-time promise.
Read terminal output and diagnostics
Terminal pickers close after selection without discarding the next draft, status commands retain channel and account rows, and approval guidance uses operator-assigned device names. Note input preserves line endings and Unicode, while raw hexadecimal input remains available alongside normal terminal keys on supported POSIX paths.Diagnostic formatting handles very large command output without its earlier stack failure, and explicitly blank numeric options are rejected rather than silently treated as defaults. Scripts should omit an option when they want its default; refreshed Bash completions preserve quoted and escaped option values.
Preserve formatting in exported conversations
HTML conversation exports retain Markdown formatting inside tight list items, including bold text, links, and literal inline code.
Follow child worktree setup
Child worktree failures appear in chat, and missing objects in partial Git clones are fetched in batches before worktree sizing. Interrupted or failed setup remains visible instead of looking like a child that is quietly waiting to start.
Find command and configuration help
Configuration references are divided into focused pages with familiar anchors preserved, and corrected redirects keep older entry points useful. CLI documentation searches can limit displayed results, while revised examples explain existing command deadlines, approvals, secrets, hooks, diagnostics, and Code Mode output helpers.
Preserve complete transcript rewrites
Conversation maintenance publishes complete transcript rewrites atomically and preserves the selected history through resets, interruptions, and later messages. Input relocation is published before fallible observers, keeping immediate replay attached to the intended path.Keep the updated writer and readers together when rolling back code. Older unpatched readers are not a supported rollback for this change, and previously damaged histories are not repaired automatically.
Preserve conversation history and task outcomes
Transcript maintenance is paced without discarding queued writes, and other conversations can save changes while an archived worktree is being restored. Session cleanup and cold updates reduce specific causes of database contention and stalls, while storage errors retain bounded, redacted causes and separate validation stages.Fresh tool results remain protected until the next assistant response uses them, unsuccessful child completions settle durably, and final replies can survive the end of their launching turn. Cleanup and recovery preserve ownership checks so an older operation cannot clear or publish into a newer one.
Finish and cancel commands
Command cleanup preserves the original result while observing remaining owned processes, and completed output can be returned without waiting indefinitely for retained descendants. Background results retain their process-specific lifetime, SSH diagnostics survive split reads, and terminal control sequences can span output chunks.Cleanup stays conservative when the operating system cannot confirm that a process group has exited. Some strict cleanup paths use a non-PTY fallback, and deliberately escaped descendants remain outside the owned process group’s containment.
Recover connections and runtime startup
Early WebSocket errors and rejected connections are handled without leaving unrelated connections exposed to an unhandled failure. Prepared model runtimes finish closing before authentication is torn down, and supported foreground restart failures leave the process available for an operator to correct the cause and retry, serving no requests until startup succeeds.Other fixes preserve selected-service credentials during status probes, apply configured environment changes after an in-process restart, and support agent state on SQLite builds without native extensions. Native vector extensions still require a compatible SQLite library.
Diagnose workspace conflicts and coordinate Git writes
Workspace recovery distinguishes unreadable conflict records from verified absence. Shared Git writes are coordinated within the process during cleanup and result publication, while external Git contention remains an error rather than a reason to delete locks. Blocked cloud-worker archives retain bounded explanations without forcing an archive or silently repairing cloud resources.
Handle files and media errors
Oversized inline images reach the intended size-limit error instead of overflowing the parser’s stack. Older supported ffprobe diagnostics use the existing fallback, and complete quoted cache validators are compared correctly even when their text contains commas or asterisks.
Preserve command arguments and output
CLI dispatch keeps parent options and literal argument boundaries intact, multiline terminal pastes do not accidentally become exit commands, and Unicode survives delegated-task diagnostics. Disabled accounts display as off, bare telemetry help exits successfully, and headless Linux file opening reports the missing opener clearly.
Parse malformed Code Mode input
Malformed assignment-prefixed Code Mode input with repeated quotes reaches a syntax error promptly instead of stalling its worker. The accepted grammar and execution budgets remain unchanged.
Runtime implementation and resource ownership
Internal changes consolidate shared runtime helpers, typed contracts, database queries, and resource ownership across agents, providers, channels, and clients. Their source details preserve the specific areas affected without treating implementation cleanup as additional product features or general performance guarantees.
Focused tests and fixtures
Test work improves temporary-state isolation, cleanup, synchronization, and platform-specific fixtures while retaining checks on the behaviors those tests own. Several suites move coverage to public boundaries or remove duplicated scenarios; test-only repairs do not establish new runtime capabilities.
Build, review, and release tooling
Build and release tools preserve frozen source identities, improve validation routing and failure evidence, and keep contribution credit tied to verified identities. Changes to routine CI do not replace the fuller manual qualification required for release artifacts.
Maintainer documentation and translation tooling
Maintainer references describe review commands, release operations, and validation ownership more clearly. Translation-memory and glossary updates support the documentation and localization process without implying that every tooling update changes visible app text.
Previously shipped changes in release history
These ten changes are present in the release ancestry but were already backported into 2026.9.2. They are retained here for traceability and are not new 2026.9.3 behavior.
Reverted work retained in release history
The updater-policy and recorded-owner Workshop migration changes listed here were reverted before release. Their original changes and the revert remain accounted for, without presenting the withdrawn behavior as a shipped fix.