Release notes for OpenClaw v2026.9.5, with Atomic Updates, supported plugin installation without a Gateway restart, read-only conversation sharing, GPT Live for meetings and calls, shared browser pages, conversation archiving, guided specialist teams, and everyday reliability improvements.
Reading formats:Release notes for readers · Plain Markdown for AI agents and tools.OpenClaw 2026.9.5 brings Atomic Updates that check the next version before switching over, plugins you can install without restarting your Gateway, conversations you can share, GPT Live in your meetings and phone calls, browser pages you can work on alongside your agent, conversation archives you can revisit later, guided setup for your own team of specialist agents, everyday reliability improvements, and more.This release includes 4,179 pull requests and 64 direct commits, with credits to 502 contributing accounts.The UI screenshots below use a fictional Waypoint launch team and synthetic conversations, research notes, and metrics. The feature explainers are conceptual illustrations, not live status screens.
Setup can help you create a specialist or a small team, choose an avatar, and get connected. Installation and recovery guidance also covers more of the places where setup can get stuck.
Set up a specialist team
Start with a chief of staff, researcher, writer and reviewer, or choose a single specialist. Guided setup can create the four-agent team, and New agent in the web UI offers the same roles through a proposal you approve before anything is created. Setup remembers your chosen coordinator if you need to resume. Choosing Skip creates the team offline, with AI access still to configure.If creation stops partway through, check openclaw agents list and repair the incomplete team before retrying. If all four members already exist, finish with openclaw onboard --workspace <workspace> without --team.Synthetic example: The setup conversation offers specialists and keeps creation behind your approval.
Choose an avatar for a new agent
Once you agree on your new agent’s name and personality, setup can offer four matching portraits and save the one you choose. You’ll need an available image provider. You can skip this step and keep the emoji, which also lets setup continue if generation or saving fails. Existing avatars and completed workspaces stay unchanged.
Start with fewer setup decisions
Fresh OpenAI and ChatGPT/Codex setups start with Astra if you haven’t chosen a primary model. Existing choices stay in place. If your account does not offer Astra, choose an available model during OpenAI setup. Verified official plugins also skip a redundant approval step before sign-in. Third-party plugins and those OpenClaw cannot verify still need the applicable consent.Local onboarding now selects Full tools when no profile is set, including when you rerun onboarding. This includes messaging and available optional tools from enabled plugins. Explicit profiles stay in place, and an ordinary upgrade leaves an unset profile unchanged. Security settings now save an explicit Full choice. Full selects tools; Full Access controls execution permissions, which remain separate from tool selection and other access restrictions.The existing openclaw setup-and-repair helper is now discoverable in the tool list. It also belongs to group:automation and group:openclaw, so denying either group blocks the helper even if you explicitly allow it. To use it, narrow or remove a conflicting group deny. Restricted profiles still need an explicit selection through tools.alsoAllow, subject to the remaining restrictions.
Recover command-line installation
The installer can reuse your compatible Node and nvm setup without replacing system software or changing your shell profile unnecessarily. If it needs to install Node through nvm, it asks first and explains any change to your default Node version. If you decline or run unattended, it stops and gives you commands to prepare the installation.Mac app CLI setup can now recover from temporary-directory permission errors without an administrator password, provided /tmp is writable. The Linux companion’s installer also avoids the bundled OpenSSL conflict that could stop system download tools during AppImage setup.On Linux, Gateway installation can recover from stale session connection settings while preserving working custom connections to the service manager. It also works again on systems running systemd 239. If the service manager is unavailable or its files cannot be read, the error explains what needs repair.
Set up OpenClaw in a container
The Docker guide now explains how to set up the web UI’s browser inside your container and troubleshoot missing Chromium. If permissions block a package update inside the container, OpenClaw recommends replacing the image and redeploying with your existing state and configuration mounts. Docker source builds that include Matrix also get past the import errors that could stop the build.When OpenClaw runs in Docker, its sandbox shell and browser tools can now see the same workspace and skill files even when the host uses different paths. Workspace and state folders, including nested managed sources, must use verified host bind mounts. Named volumes, tmpfs and files stored only in the image remain unsupported, and OpenClaw refuses sources whose container or Docker daemon it cannot verify. Read-only mounts stay read-only, and custom sandbox binds still use host paths.Restart the Gateway after changing its mounts or Docker connection. If existing sandbox containers have different mounts, OpenClaw keeps them and gives you a command to recreate the affected containers. Browser-control connections over the default Compose bridge remain a separate limitation.
Connect a device with clearer guidance
A browser using only its device token can now reconnect after an administrator approves Request admin, instead of being sent back to login. Changing shared authentication still invalidates old credentials, and previously damaged tokens are not automatically repaired. Pairing requests also accept pasted IDs with surrounding spaces or newlines, and long Node host setup commands fit inside the pairing dialog while remaining complete when copied.Authorized operators using trusted-proxy authentication can generate mobile setup codes without adding an unused Gateway token or password. Your phone must still sign in through the proxy, and scanning a QR code does not sign you into Cloudflare Access. Secure-transport rules and pairing approval still apply, and authentication mode none is still rejected.
Keep your default agent after migration
Migrated multi-agent setups now keep their saved default after a restart, so integrations can find the intended agent again. The web UI saves and displays that same choice. If your agent list has no valid default, choose one with Set Default in the web UI. Choosing a default does not move your older workspaces or conversation data.
Install the CLI on FreeBSD
You can now install the CLI on FreeBSD with install-cli.sh using system Node and npm. First, have an administrator install bash, node24, npm-node24, git, python3 and gmake. Follow the npm installation route with a published version or compatible built package; Git source installation remains unsupported. System packages stay administrator-managed, and the installer’s private --node-only recovery option is unavailable on FreeBSD.Setup and error messages explain how to connect to a Gateway you start yourself, using the same account you used for onboarding. Run openclaw gateway run in a terminal or manage an installed package service separately. The CLI does not install or control FreeBSD services, and it cannot report their status.Keep pkg/Ports installations under their package owner’s management. On affected FreeBSD 2026.9.4 installations, the old updater stops before it can download the repair. Follow the manual update procedure through the owning package manager first, preserving the same installation, state and configuration and using the actual service or foreground owner to stop and start OpenClaw. After that bootstrap, the repaired updater can update an independently managed x64 installation, subject to package and service ownership checks. ARM64 updates remain unverified, and rc.d services still need their external owner.
Keep migration options in effect
Migration commands now keep your selected source, output format and credential exclusions when shared options appear before list, plan or apply. Options explicitly set on a subcommand still take precedence. Use openclaw migrate plan to preview a migration. The apply command does not support dry runs and now rejects a preceding --dry-run before changing anything.
Resume interrupted local setup
Interrupted local setup can now finish in the workspace you already approved while keeping your saved agents, model and runtime choices. Recovery checks that the pending setup still belongs to the same configuration, so replacing the configuration or switching to a remote Gateway does not carry that approval forward.
The web UI makes it easier to find an agent, follow its work, and keep a conversation going while the rest of the page catches up.
Find agents and their conversations
The new Agents overview brings recent activity and conversation previews together, with a direct link to each agent’s main chat. Turn on Show all agents for an optional team sidebar that groups conversations by agent. That choice is remembered in this browser for each Gateway, and agent creation remains available in Settings.Activity keeps delegated subagent work with its parent conversation, so it no longer crowds out your conversations or inflates people counts. Switching agents also cancels obsolete archive-deletion confirmations from the previous agent.Choose whether empty sidebar groups hide When filtering, Always, or Never, with separate choices for each user and Gateway in this browser.Synthetic example: A coordinator, researcher, writer, and reviewer—with recent work to pick up.
Choose artwork for agents and conversations
To give a conversation its own artwork, paste a custom SVG in Icon & color → Custom icon…, or ask your agent to set it. Artwork keeps its own colors and must be self-contained and no larger than 16 KiB decoded. Scripts, embedded documents, and external references are rejected.
Arrange plugin pages in the sidebar
Plugin pages can now join your saved sidebar order alongside built-in pages, keeping their places after a reload or temporary absence. Home stays first in chip mode. Pages shown by default can be reordered, but only optional plugin pages can be dragged out to unpin them.
Enter text in the command palette
The command palette shows Searching sessions… or Searching commands… while it is still looking, with local commands available in the meantime. When you compose text with an input method, Enter, Escape, and arrow keys stay with that input instead of selecting a result or closing the palette.
See conversation activity on browser tabs
The browser-tab icon now shows when the selected agent is working, needs an answer or approval, has finished while you were away, or has disconnected. The completion indicator clears when you return to the tab. Failed or interrupted runs do not appear as completed work.
Choose where a new task runs
New Session puts your devices in a searchable picker, with capacity details and an Any available device choice when you have several. Cloud options sit beside their provider, and suggested tasks can start in the current conversation, a new session, or a separate Git worktree.A worktree needs a Git checkout. Local means the computer running OpenClaw, which may be different from the computer running your browser.For empty remote workspaces, see Start remote tasks in an empty workspace under Browser and Computer Use.Automatic placement now counts work already accepted or starting when choosing a paired device. If the chosen device becomes unavailable for the task, OpenClaw can try another eligible device after confirming cleanup of the failed attempt, with at most three devices tried in total. These retries stop once workspace preparation begins. Choosing a device does not reserve capacity, and idle sessions reserve no slots.Synthetic example: A useful brief and a choice of devices—before the next task starts.
Keep drafts and queued input intact
You can submit text and attachments while chat history loads and start your next draft immediately. Delivery waits until the conversation is ready. During a reconnect, a message OpenClaw has tried to send appears once in the conversation; messages it has not tried to send stay editable in the queue. If the connection drops while you correct one of those waiting messages, you can still save the correction. It keeps the message’s delivery choice and queue position, even if the main composer now uses Steer or Interrupt. Attachments show when they are being prepared, and removal controls name the file.Discard removes the local pending copy; it cannot cancel a message OpenClaw has already received. Most commands still need the conversation to finish loading. If saving a queued correction fails because of browser storage, keep the tab open and copy the affected text before freeing storage. For saved drafts that fail to load, reload without clearing site data, after copying any unsaved correction; clearing site data would delete local drafts.Web chat also shows accepted queued follow-ups from CLI, TUI, native apps, and RPC clients while the agent is working. Labels such as via CLI describe the submitting app; they do not establish a person’s identity or grant permissions. If an interruption leaves input queued outside the saved conversation, resend it explicitly after restart. That queue is not replayed automatically.Eligible foreground New Session submissions open a read-only chat preview while the conversation is being created. If creation fails, the original draft returns. The preview does not mean the session or its first turn has already been accepted.Unfinished queued-message corrections survive switching conversations and block automatic update reloads until you save or cancel them. An explicit browser reload still discards those corrections. Incognito New Session drafts survive destination changes and Back within the same tab, but disappear on reload or closure; turning Incognito off resumes ordinary autosave for the existing draft.
See teammates' unsent drafts
In shared sessions, each person’s live draft now appears in a softer chat bubble labeled Typing · not sent, or as their own typing dots. These temporary previews disappear after inactivity or sending. They are not saved in the conversation or included in model context.Synthetic example: A teammate’s temporary draft stays clearly marked—not saved conversation history.
Enter emoji by name
In Chat and New Session, type an emoji name such as :smi to see suggestions, then choose one with the arrow keys and Enter, Tab, or a click. Completing a recognized shortcode such as :smile: also inserts its emoji. This edits the draft without sending it, while code, URLs, and unknown names stay literal.
Choose optional composer visitors
Optional lobsters and other occasional visitors now gather around the New Session composer. They yield to typing, attachments, and controls, and keep your existing visit, sound, and reduced-motion preferences. Dismissing a visitor applies to that composer opening; permanent dismissal turns visits off.
Add comments to selected chat passages
Select a passage and choose Add to chat to save a comment without disturbing your message draft. Collect several comments, reopen them to edit or delete, then send them with their selected passages as text attachments. The compact editor grows as you type, and long comments remain readable in scrollable previews.Retained comments keep their controls when history or the composer changes, and new formatted selections keep their previews after sending and reloading. You can hover, focus, or tap a sent comment count to read it. Sent comments are read-only.Synthetic example: Turn “change that part” into a concrete note attached to the right words.
Keep the project when forking a conversation
Fork conversation and Fork from here now keep an eligible selected local folder or project, so existing file references and subsequent work use the intended workspace. An explicitly chosen destination takes precedence. Previously created forks are unchanged.
Read replies and long histories
Loading earlier messages now keeps you on the message you were reading, including when you choose Show earlier. Completed answers stay visible after later tool activity, and Japanese, Chinese, and Korean bold text and multiline table cells display as intended. Desktop navigation groups loaded assistant responses by run, while long user messages have visible Show more and Show less controls.Background-task notifications imported from Claude appear as collapsed system notices, with the original content available to expand. The same XML deliberately pasted by a person remains their message.Reopening a long active chat no longer repeats saved progress updates after their live replay has expired. Loading older history also removes temporary duplicates of confirmed sent messages, even while their assistant replies are waiting to appear. Separate submissions with the same text remain separate.Activity summaries sit closer to their replies without shrinking touch controls, and hidden panes remember your reading position. Large plain-text replies, including text shown when Markdown rendering fails, take less work to display while retaining the existing HTML sanitization.Synthetic example: a readable plan brings workstreams, owners, and next steps into the conversation.
Inspect tool activity when needed
Tool failures appear as a muted count beside collapsed activity, with full errors available when you expand it. Named operations keep their commands together, and plugin icons follow the current theme color. Background tasks use a compact, full-width feed with expandable commands, while the assistant’s reply keeps growing as one message. Saving conversation memory… now explains when that work is happening before a reply.Web and macOS chat show each subagent task’s name beside a claw that moves while it runs, with badges for failures and timeouts. Hover for its status, or use keyboard focus in the web UI; screen readers receive the explanation too. Reduced Motion keeps the claw still. In web chat, progress folds while you read older messages and stays compact as output arrives. Choose Latest to follow again. Manual open and closed choices are remembered for that conversation across visits and new runs on the same Gateway connection, and reset when you reload or switch connections. Completion can reopen progress only when you are already at the live end and have not manually closed it.Progress cards avoid freezing on large runs of unmatched HTML opening tags, including in macOS WebKit. New background command tasks save short, redacted command previews as their labels, making tests and builds easier to distinguish without repeating Running. Existing task labels remain unchanged.You can also drag or scroll the Task progress header to leave just part of the panel open. Incoming output and the final response keep that chosen height. Click, Enter, or Space toggles the full panel, and Latest resumes following the conversation. Partial heights apply to the current task and reset for a new one.
Ask a side question without losing the conversation
Side chat puts the cursor in the right input when you open it and keeps the main conversation visible. Questions now wrap and grow as you type, with Shift+Enter for a new line and the existing 400-character limit.You can now ask /btw side questions about photos attached to the current message when using a direct model provider or the bundled Codex integration. Reply photos are included when the channel supplies them. CLI runtimes instead report how many images were omitted, and third-party agent integrations may ignore images. Images already described by media understanding remain excluded, and their descriptions are not forwarded instead.Synthetic example: Check the reasoning without steering the main conversation away from its task.
Choose models while discovery continues
The model picker opens with choices already loaded, and adds newly discovered models while the menu stays open. Models settings also keep healthy choices usable when another provider fails, with a warning and Retry available. Account labels help distinguish subscription access, API keys, and an explicitly selected account. People with permission to edit a session can also change its thinking level and fast mode for subsequent turns.If the model list or selected account changes during loading, the picker can retry the resulting stale-list rejection once without losing your draft. The retry keeps the original time limit and still respects cancellation. A second failure stays visible; permission and connection failures do not trigger this retry.Active chats and split panes make fewer routine requests for model information. Choosing a model, account, or agent runtime still refreshes that information promptly, as do credential and availability changes. Ordinary account usage remains recorded without making every connected web UI reload its model information.
Review changes and repository state
Activity now shows available Git change counts and pull-request previews, so you can check coding work without opening every conversation. Review also restores missing patches for filenames containing spaces or escaped characters. Activity counts describe the checkout or pull request, including applicable uncommitted work. Recent pull-request links from the same repository remain available after checkout changes, and the check-status control is easier to recognize and open.Pull-request badges now reflect fetched state, and status reads say Loading. Shared publication progress can return after reconnecting or reloading, with unavailable warnings when fresh GitHub information cannot be fetched.Check status reads the recorded outcome without publishing again. If an acknowledgement was lost, an empty lookup does not prove the action never ran; check the original request before using Retry publication, which explicitly retries that same request. Recovery stays within the current session and workspace, and existing personal confirmation and permissions still apply.For an open or draft pull request, open the CI indicator to see named checks and expand GitHub Actions jobs for their steps, statuses, and durations. Details refresh while the monitor is open, with warnings and Retry for unavailable, partial, or rate-limited results. Full logs open on GitHub; other CI services remain listed without Actions step details.
Use images and documents from chat
Markdown attachments open as formatted documents beside the conversation, with headings, tables, and working code controls. Chat menus can copy available message Markdown, complete code, tables ready for a spreadsheet, or an attachment’s download link or name. New generated images stay with their completion reply without adding a duplicate image-only message. Uploaded image frames now align with their prompts, including in Safari, and user image galleries sit closer to the text that explains them.You can also right-click chat images for the browser’s familiar copy and save actions. The browser may copy the displayed thumbnail. Use OpenClaw’s Copy image action when you want the full-resolution file.Images reserve their place while loading, reducing jumps in the conversation. Failed managed previews retain an explanation and Retry, and loading animation respects reduced motion. Assistant images and attachments also stay between their original paragraphs, so Before and After labels remain with the right images.Relative local file references resolve from the session’s selected project or worktree and appear as attachments, with existing file-access checks. Files on a remote execution host must first arrive through managed attachment delivery.Rewind and Fork restore supported image attachments for resending, with a 5 MiB decoded limit for restored inline images. Failed queued sends and their attachments remain available after reload for you to retry.
Inspect the sources cited in an answer
Completed researched answers can show a Sources strip with up to eight cited pages. Open a card to read its recorded snippet or excerpt, then choose Open source for the original page. These previews reflect what was retrieved for that answer, rather than a fresh check of the page, and some citations have no excerpt.Synthetic example: Open the recorded excerpt before deciding whether to follow the original source.
Recover attachments after website sign-in expires
When expired website sign-in blocks images or files, OpenClaw first tries to renew access without interrupting the conversation or unsent draft. Silent renewal needs a valid global sign-in session and browser cookie and framing support. If that cannot work, sign in in a separate tab and return to the same chat; failed attachments retry after access is verified. Session lifetimes stay unchanged.
Keep dashboards and embedded views usable
Ask your agent to add a hosted HTTPS website to a session dashboard, expand it across the task area, and return through a named, pinned session. The browser also remembers layouts, panel choices, and dashboard tabs for up to 500 sessions.Dashboard editors can use Layout → Use current view as default to save a shared fullscreen or split starting view, and agents can save it too. A viewer’s personal layout takes priority, and saving a default never rearranges active viewers. Fullscreen fills the task area, rather than the browser screen.Some sites block embedding or need a separate sign-in; Open website opens them in another tab. Personal layout preferences, docking, and dimensions stay in this browser, and a live website frame is kept only while its task view remains cached.When a split-chat window narrows, the active chat and its file panel now fill the available area. Widening it restores the saved desktop proportions and independent drafts, while hidden panes stay inactive.
Use page controls in a shared desktop toolbar
Desktop pages outside Chat now place titles or hub tabs and page actions in a shared toolbar. The layout also keeps Arabic and Persian page actions clear of the fixed sidebar controls. Chat, Settings takeover views, and mobile headers keep their existing layouts.
Inspect machines in Systems
The new Systems workspace brings searchable machines, their reported resource readings, and an available remote desktop into the main workspace. Desktop viewing starts in view-only mode; taking control remains an explicit action subject to your permissions. If you customized your pinned navigation, add Systems through Edit pinned items.Offline and headless machines remain inspectable. Readings may be last-known or unavailable, and a related-session link shows an association rather than proof that work ran on that machine.
Open and manage terminal tabs in Chat
Native Codex and Claude Code sessions open in a main terminal page, with the sidebar available and a URL you can return to within the existing terminal lifetime. Access still requires the terminal capability and administrator permissions. Page tabs and dock tabs remain independent.Within Chat, shell sessions now appear directly in the side-panel header beside their status and actions, leaving more room for output. Choose + → Terminal again to open another shell.
Open optional panels with clear loading feedback
Home and System busyness open their panel frames immediately, with loading and Retry inside the panel so you can keep editing the main chat. Home keeps its saved size and docking position, and closing a loading panel keeps it closed. Settings no longer automatically restores Ask OpenClaw, though you can still open it yourself.
Manage mentions and browser notifications
Mentions leaves more room for the entries you came to read. Notification settings now sit in the shared Inbox header, so you can reach them from any Inbox tab.
Browse large People lists
Sorting a large session sidebar by People does less repeated work, especially when many different people own sessions. The ordering, selected session, and familiar controls stay the same.
Edit settings with clearer controls
Established Labs controls now live with their related settings, including Swarm and loop detection under Agent Defaults → Tools. Settings forms put readable controls and individual hints first, without repeating their defaults in a block of raw JSON.Settings reloads no longer trigger the repeated loading calls that could overwhelm the browser. Save conflicts still receive their existing recovery controls, and you must explicitly retry a failed save.Agent Files keeps unsaved edits when you switch agents, including their save-conflict checks. Save before leaving the Agents settings page, reloading the browser, or changing Gateway connections; these drafts are temporary.
Recognize channels and session links
Channels show artwork from the plugin that provides them. Local session links have a claw marker and aligned titles, and desktop WebKit browsers show the missing chat permission icons again.
Inspect current usage details
Enabled usage footers keep available totals and cache counts even when separate input and output counts are missing. When a session is recreated, Usage clears the old timeline selection so it no longer hides the new conversation’s messages. Hour filters also handle daylight-saving changes without freezing, and Models settings labels its usage-record count as messages. These display fixes leave billing totals unchanged.
Open and switch busy conversations
The conversation you open now loads before automatic background session lists. Long histories and chats with many child sessions need less repeated database work, and large session lists let other requests proceed while they load. Chat startup also avoids compression delays on busy Gateways.Opening one conversation no longer waits for the entire session list to refresh. Stored titles and usage can appear first, while older titles, previews, and some model details arrive later. Cold archives and oversized content can remain without those optional details, and missing usage is not reconstructed.Large session lists also reuse unchanged titles as messages arrive, choose the correct title after a reset, and keep child-session links in a consistent order. Opening an exact session link and preparing list pages now require less repeated work, including when conversations have many subagents.Session refreshes also release old versions of session-list data that were being kept in memory, fixing a leak that could exhaust Gateway memory and interrupt work.Panes showing the same conversation share history recovery, and activity elsewhere avoids unnecessary redraws.The connection now sends uncompressed frames, so large histories and rosters use more bandwidth.If a chat misses the signal that work finished, it can clear its busy state when saved history confirms that same run is complete. When both history and live updates fail, Retry now retries both, including approval-card updates.
Read current controls in your language
The 20 existing interface languages receive updated labels and guidance for connection settings, session storage, website dashboards, and other current controls. This keeps the translated interface in step with the screens you use.
Browse chat files in tabs
Keep several chat files open in tabs and switch between them without losing your reading position. HTML files offer Preview and Source, and reopened editable drafts can save or resolve conflicts directly from Preview. Strict mode keeps document scripts disabled and applies the guarded preview’s resource restrictions.Tabs clear when you reconnect. HTML previews retain the 256 KiB limit and do not load relative assets from the file’s directory; attachments from another origin remain download-only.Reopen a file from chat, a tool card, or the Files list to refresh its saved contents in the existing tab. Simply selecting its tab keeps the current preview. Unsaved edits and newer saves stay protected from delayed reads, including when you switch sessions or connections.Synthetic example: Review a launch draft in context, without losing the conversation.
Inspect Gateway connection and resource graphs
Settings → Gateway now shows connection ping statistics beside CPU, memory and activity graphs, helping you investigate a slow connection or a busy Gateway. Readings and uptime stay visible during refresh. Ping includes Gateway handling time and does not measure how long a model takes to reply; graph history resets when you leave or reconnect.Full Debug status, health and model snapshots refresh when opened, when the connection or agent changes, or when you choose Refresh. Heartbeat and command activity stay live.Minimize System busyness to keep CPU, diagnostics-request time, and process-memory graphs in a small widget while you work. Readings and history continue while minimized and return to the panel when you expand it. Closing stops the readings, and a lost connection shows Unavailable.The widget’s ping measures the existing system.info request, separately from Settings’ connection ping. Neither measures model response time. The memory graph shows memory held by the Gateway process, known as resident memory or RSS.
Keep Undo controls available
Notifications pause their expiry timer while you hover over them or focus their controls with the keyboard, giving you time to use Undo. The remaining time resumes once both hover and focus leave, and you can still dismiss the notification immediately.
Continue an offline device's conversation on the Gateway
Continue on Gateway now recovers an offline device’s conversation even when pending workspace results previously blocked the action. After recovery, you can send a fresh message or delete the session with its transcript archived.You must explicitly confirm the loss of unsynced device work. Ordinary moves continue to preserve pending results. Cleanup stays pending until the old device acknowledges its stop, so a recovered conversation does not prove that device has stopped.If a single Delete or Archive is blocked by offline device work, the web UI now offers the same recovery choice. Reconnect the device to preserve its changes, or explicitly confirm losing its unsynced files and in-flight work. The discard route restores the last Gateway-synced workspace and retries the requested removal once; interrupted work is not replayed.Cancel preserves pending work, and a failed recovery move does not trigger removal. For a batch, recover each affected session individually before retrying the selection. CLI and native clients do not gain this interactive recovery flow.
Catch up with Activity recaps
Activity recaps help you catch up on a conversation without reopening its full history. These rolling summaries survive page reloads, Gateway restarts, and archival. Previous text stays visible while a recap refreshes or fails, with freshness feedback and Retry recap when available. A recap is a convenience for catching up, not proof that a task is complete.Generating recaps sends the previous recap and bounded transcript excerpts through the owning agent’s utility model. These separate model calls may incur usage charges. Disabling utility routing stops new recaps, and a failed call does not fall back to the primary model.Read-only viewers can read cached recaps without requesting model work. Incognito, subagent, and scheduled-job sessions are excluded. Scheduled jobs keep their scheduler-owned summaries.Synthetic example: Short recaps connect the research, writing, and review across your team.
Keep screen controls in the requesting browser
When you ask an agent to change a page, pane, or panel through screen controls, the change now stays in the browser that requested it. Your other tabs and other people’s dashboards keep their views. Reply also returns focus to the composer when a streamed update has redrawn the conversation.Standalone RPC and MCP integrations must start screen actions from a Control UI connection or a turn begun there; the previous broadcast behavior is no longer supported. If the original browser has disconnected or no browser was captured, the action returns UNAVAILABLE. Ask again from the open Control UI.
Atomic Updates check the next version before switching over on supported update paths. Conversation archiving compresses older history you can reopen later, with storage controls in Settings.
Archive older conversations and inspect storage
Conversation archiving compresses older, inactive history while keeping it available to reopen later. Settings shows how much storage each agent’s conversations use, with a Run now control for archiving. Cold storage is off by default. Turn it on to archive eligible inactive history after 30 days, or change that interval without restarting. Opening or resuming an archived conversation restores its history and makes it searchable again, even if you have since turned archiving off.Make and verify a backup before upgrading. This release changes the conversation database even with archiving off, so going back requires the matching older build and backup. Keep archive files with the database; supported backups include and verify them.Synthetic example: Inspect the inventory, choose an archive policy, and keep the backup guidance in view.
Prepare for the session database upgrade
Large conversation stores avoid repeated full scans when OpenClaw checks access to a session or reopens its database. The first check still reads the store, and the change adds some startup, memory, and write overhead.This release upgrades agent databases to schema 21, which older builds cannot open. Make and verify a pre-upgrade backup that includes committed data still in the database journal, or WAL. Going back requires restoring that backup with its matching older build and loses work saved after the backup. Reinstalling an older package alone is insufficient. Do not change schema markers or delete database tables to force a downgrade. Users updating from 2026.9.2 must follow the manual schema-upgrade instructions.
Repair older state explicitly with Doctor
Older conversations, workspace metadata, pairing records, and file-based message queues now wait for an explicit repair instead of being converted during ordinary startup. If OpenClaw reports pending legacy repairs, stop the Gateway through its service owner and run openclaw doctor --fix. Restarting alone no longer completes these conversions. Current prepared-message recovery and ordinary database opening continue normally.Doctor preserves retained conversations and their associated records during supported migrations. Where damaged history permits only a partial import, its warnings name the files that still need attention. Keep those originals and your backups until you have checked the result, and follow the stopped-Gateway recovery guidance. Unread history is not recovered, and retained old messages are not automatically sent.
Choose whether an update repair agent runs
If an interactive update fails, AI repair starts only after you choose Yes, because it uses your account and tokens. Enter, No, cancellation, or a 30-second timeout skips repair and leaves diagnostics and manual recovery instructions. An older updater already running may still use its old prompt.
Request updates from authorized chat accounts
Owners can ask their agent to update the OpenClaw installation hosting the conversation through the default tool profiles. /update remains available when the model or update tool is unavailable. Existing owner permissions and restart restrictions still apply. Optional first-owner setup asks you to confirm the exact account and defaults to Skip; ordinary permission to chat does not grant administration.
Choose a coding CLI for repair assistance
Triage can hand repair work to installed Muse Code, Grok Build, Cursor, Kimi Code, and Qwen Code, alongside its existing choices. Select one with openclaw triage --agent; Cursor requires cursor-agent on your PATH. These choices extend explicitly requested repair assistance, while unattended recovery keeps its existing routes.Review the selected CLI’s permission policy. Kimi runs its single repair prompt with native automatic permissions and no approval prompts, which triage announces before launch. Qwen opens an interactive session with its normal approvals; saved headless commands retain its native restrictions.
Preserve linked files in backups
Backups preserve external, cyclic, and dangling symbolic links, and Mac metadata files no longer stop backup creation. When several filenames point to the same managed SQLite database through hardlinks, each name in the backup now gets the same saved data, including changes still in the database journal. Every hardlink must be included in the managed backup inventory. Incomplete or conflicting sets are refused.Symbolic links retain their original targets without copying the files they point to. Review those targets before restoring elsewhere, and use an updated restore reader for these newly supported link archives. See the backup guide.With openclaw backup git create --all, healthy agents receive fresh snapshots while an unavailable configured agent keeps its previous Git backup, if one exists. The result warns that coverage is degraded because the retained snapshot is older. Explicit agent selection and runs with no copyable databases still fail.
Keep stale queued messages from replaying after upgrades
Upgrades hold back abandoned messages from older file-based queues instead of sending them when a channel reconnects. This applies to pending messages at least 72 hours old and those with missing or invalid timestamps, including future dates. It does not change ordinary message expiry.Review withheld messages in the private .migrated backups and verified queue-owned attachments in .media.migrated, then send a new message deliberately. Do not restore old pending entries to resend them. Finish any reported attachment preservation and cleanup before downgrading; openclaw doctor --fix on the same state directory retries incomplete cleanup.
Finish core updates with clear plugin outcomes
A missing plugin update no longer has to hold up the core update. OpenClaw can keep a compatible installed plugin and explain what still needs repair or consent. Eligible official plugins pinned to older releases can return to normal catalog updates, including some manually pinned versions. A version or tag explicitly requested in your current update command still takes precedence. Explicitly linked local plugins keep their selected source, even when a bundled plugin has the same name; follow the warning to update them at their source. A completed core update can therefore still need plugin follow-up. The update guide explains these outcomes.Unavailable configured plugin paths now produce actionable warnings while preserving their settings. Fix the reported path or permissions, then run openclaw doctor --fix; the plugin remains unavailable until repaired, and structural errors can still block the update. Pending plugin migrations retain their original inputs, so conflicting edits are refused until repair finishes. Complete pending migrations before returning to an older build when you need to preserve later ACP session changes.
Update the installation you actually use
Updates recognize custom npm installations, handle affected pnpm package-directory changes, and check build identity before skipping an explicitly selected same-version package. Git updates can prepare their required files before stopping service, and Mac package replacement preserves launcher permissions.Older updaters, including 2026.9.4, can now finish an otherwise healthy managed-Gateway update that previously rolled back during a late service-configuration check. The replacement package supplies this repair, so it can help on that same upgrade.The separate managed-service-preflight refusal before package replacement still needs the manual update instructions for your installation, as may other older-updater blockers. If you see candidate-config-read-failed, the existing service configuration is left unchanged; inspect the problem with the updated CLI. If a baseline scan times out, the update retains a warning that rollback verification was reduced.
Update partial Git clones with clear recovery guidance
Partial-clone Git updates can work with intentionally omitted historical objects while still requiring the complete files for the proposed version. If transfer fails, the error distinguishes missing-object recovery guidance from verified corruption. Local edits still stop an update before installation or service shutdown, now with a failure result and instructions to commit the changes and retry or use triage.Doctor’s Git maintenance guide also explains optional cleanup of harmless leftover partial-clone markers. Check for missing objects and verify integrity first, move markers into the prescribed backup, and keep that backup through successful follow-up checks. Cleanup remains a manual choice.
Keep managed services on the selected runtime
Managed Gateway and node services can stay on the exact Node or Bun executable you select with --runtime-path, including a version-manager path. Use an absolute executable path; reinstall and repair preserve it, and an invalid pin produces an error instead of silently choosing another runtime. Set a different path to replace the pin, or explicitly use --runtime node without a path to return to automatic selection. See the Gateway service guide.
Retain local package changes through updates
Package updates save supported local edits for recovery, and --reapply-local-overrides lets you explicitly replay trusted changes against matching original files. Fresh-profile updates now honor that choice too. Back up your edits and data before the first upgrade from an older updater. Recovery bundles are separate from data backups, remain on disk until you remove them, and keep conflicting changes available for manual recovery.
Check updates without disturbing live work
On supported update paths, Atomic Updates check the next version against a private copy of your setup while your current Gateway keeps running, then switch over and verify the updated installation. If something goes wrong, recovery can restore the previous version when your data and configuration remain compatible. Keep a verified backup before upgrading, because rolling back the application cannot undo database migrations. The private validation copy is not a rollback backup.Once the corrected updater is installed, update checks account for large databases and plugin folders when choosing temporary storage and allowing time to finish. Simple version checks avoid copying entire conversation histories. Checks of the proposed update leave copied background tasks idle and live Workshop files intact, preserve authentication policy, and avoid using the MCP Apps sandbox port needed by your running installation.Background update checks now read and save their data in the background, and shutdown waits for accepted checks to finish their save attempt. Usage statistics remain opt-in, and current consent, Do Not Track, and update-check settings are checked before a request is sent. Storage failures can still prevent those results from reaching disk.Conceptual illustration: Check the next version. Keep working.
Understand update failures and recovery
Failed updates now show what went wrong first, any later repair or cleanup failure, and the next step to take. Full update repair now restores and health-checks the Gateway service it stopped before reporting a Doctor failure or an expired repair deadline. If restoration fails its checks, the result retains the cause and recovery commands. A service that was already stopped stays stopped. Keep preserved originals until you have checked the result. A recovery check does not mean rollback has finished, and a failed rollback may leave earlier saved changes in place.Stalled activation now reports a timeout instead of waiting indefinitely. The Gateway can remain stopped while update work is unfinished or when restoration itself fails. Check openclaw update status and Doctor’s guidance, wait for the updater and its child processes to stop, and follow the reported repair step. Externally managed systemd services still require their owner to stop the affected Gateway before repair.After an abandoned update has been successfully reconciled and acknowledged, obsolete failure banners, retry controls, and triage prompts clear while failed historical phases remain available. This does not clear newer failures that still need repair.Doctor refusals during affected older Git updates now provide manual recovery commands when the previous revision can be verified, or ask you to inspect Git history when it cannot. Wait for the updater to exit and use an independent terminal; restoring source alone is insufficient after data repairs. Update reports also distinguish an unavailable version reading from a real mismatch, and separate saved recovery advice from a Gateway responding now. That response does not establish that the update succeeded or make rollback safe.Git and package updates can now finish Doctor work without mistakenly rejecting the updater that handed it over. An older updater already running can still report Parent executor is suspended for its candidate. After it exits, run openclaw update repair --yes --json from the updated installation with the same profile and state/config overrides. Check the repair result before restarting a stopped Gateway through its service owner.Check status now shows when a refresh is pending, completed, or failed; it does not retry the update. New configuration refusals name invalid fields without exposing their values. Package disk warnings also appear earlier, but remain advisory.A separate early check stops the update before staging when every eligible location has a measured shortage of space for its state snapshot. Free space or choose a suitable TMPDIR before retrying. That early inventory excludes plugin copies and registered external databases; unknown measurements remain warnings, and the complete later check still runs. Older installed updaters retain their first-update behavior.With managed proxy routing set to gateway-only, the updater now checks the proposed version’s exact local health URLs directly. If an eligible check runs out of time while that version is still running, the update can continue with a warning, but readiness remains unconfirmed. Explicit proxy routing still applies. Blocked routing, cancellation, lost update authority, or the checked version exiting still fail the check. Older updaters keep their original polling code, so the documented first-update workaround temporarily disables managed routing and restores it afterward.Windows updates can warn and continue when they cannot read when an update process started. A confirmed process-identity mismatch still stops the handoff, but the fallback cannot always distinguish a new process reusing an old process ID. If an interrupted update leaves one of these fallback records, recover with the fixed build. Older builds refuse those records.
Distinguish accepted updates from completed updates
When an update launched inside a supported managed Gateway service hands work to a background helper, the initiating command now exits with 75. This means accepted and still in progress. Automation must check openclaw update status --json or openclaw update history --json, then follow the printed health guidance before treating the update as complete. Do not retry merely because this acknowledgment is nonzero; other nonzero exits remain failures. An older updater performing the first upgrade keeps its existing exit behavior.
Restart services and recover with Doctor
Doctor and service checks handle more Linux restart and inspection cases, including temporary session-bus loss after a manager has been identified. Repairs retain referenced environment credentials and can bring back a service that was running before maintenance, while leaving an already-stopped service off.Standalone update repair now recognizes its own Doctor process, while another active or uninspectable update still blocks maintenance. Doctor can temporarily stop and restore its managed Gateway even with --no-restart, which skips update activation only. An already-stopped service stays stopped.Windows stop and restart can continue after a broad process lookup fails when individual checks still identify the intended Gateway. Linux diagnostics explain when leftover child processes block maintenance; have their owning service or process administrator stop them. If Doctor warns that Windows state is in OneDrive, stop the Gateway, move the whole state directory to local storage, update its service environment, then restart and rerun Doctor.Native shutdown can abandon unfinished calls when its deadline arrives, including after five seconds of draining on macOS launchd. An older running process still uses its old shutdown code. Where an external service manager owns OpenClaw, follow the Doctor recovery instructions to stop and restart it through that manager. Keep any preserved repair files until you have verified the result.Restart preserves a recorded Gateway that is still starting and can target a verified healthy Gateway you launched manually, even when a Windows task is installed. If that process is unhealthy or cannot be identified, OpenClaw leaves it running with guidance. External supervisors and other tasks still need their own stop and restart controls.Restored background tasks with a recorded, verifiably dead local process are marked canceled, so ended work does not repeatedly delay later restarts. Older tasks and unknown, foreign, or unsupported remote owners keep their existing grace periods. Downgrading does not undo cancellations already recorded.Plugin cleanup failures now name the affected plugin and make stop or restart unsuccessful. A failed in-process restart exits with code 1 and starts no successor. Shared cleanup still finishes, and memory-only cleanup warnings remain nonfatal.
Fit Linux shutdown within the service deadline
Linux Gateways now reserve cleanup time within the running systemd service’s stop deadline, including externally managed services. A service allowing 90 seconds gives active work 75 seconds, leaving time for cleanup and exit. Unfinished work may still be interrupted.The deadline is read when the new Gateway starts. Changing the service timeout requires a restart, and the first stop of an older binary still uses its old behavior. Failed inspection logs a warning and uses a 90-second fallback, which may differ from a custom unit. Follow the restart guidance and retain KillMode=mixed when adjusting the service through its owner.
Start and inspect large agent fleets
Large agent fleets avoid preparing chat metadata and Codex session locations for every agent before they are needed. Model preparation and multi-agent status scans give other Gateway requests more opportunities to run, while shared background workers reduce per-agent worker accumulation. These changes address specific sources of delay and memory growth; resource use still depends on the fleet. Parallel database checks can increase peak memory and disk activity, and keeping more authentication readers ready uses more open files.Online openclaw status --json now uses the running Gateway’s facts instead of repeating local fleet scans. Its collection flags distinguish uncollected checks from clean results, and some fields can be null. Run openclaw security audit, openclaw plugins inspect --all, or openclaw memory status --deep when you need those inspections. Plugin authors must also treat registration-time api.config as read-only; plugins that modify it may fail.
Recover and isolate agent database problems
Healthy agents can remain available while another agent’s database checks finish. The affected agent is shown as degraded until preparation succeeds; even the default agent can remain unavailable while healthy peers serve. A responding Gateway therefore does not mean every agent is ready. Shared-state failures and uncertain database ownership can still block work. Stop the Gateway before Doctor repair or verified-backup restoration, then restart and check the affected agent.Doctor also continues independent repairs when older agent folders contain conflicting files, preserving current files and existing SDK conversations. Databases awaiting relocation stay at their original location with their companion files. Inspect retained quarantines before removing them.Bun can now open more than four independent worker-backed databases, within its existing 64-client limit. Multiple connections to one database still consume that budget. See Bun compatibility.Windows now treats ordinary and extended-length spellings of the same internal database path consistently. Run standalone openclaw doctor --fix on the corrected build after updates finish to consolidate existing duplicate registrations, preserving their newest facts and external database locations. Consolidation skips active updates and candidate checks. An older updater blocked before the corrected code runs may need one manual corrective installation.
Clean up large session stores
Large conversation stores avoid repeated metadata reads during cleanup, and bulk cleanup no longer hits the reported stack-overflow crash. Cleanup can wait through brief database contention. It also leaves more room for other activity by reusing cleanup workers and pausing between phases, while long transcript rewrites do less repeated search-index work. Automatic cleanup waits for ongoing conversation changes to finish and keeps the existing retention rules and protections for active conversations.
Verify large databases with less repeated work
Large databases do less repeated checking during ordinary use. OpenClaw can reuse a successful check of the same file for the current Gateway lifetime, while fresh processes, Doctor, backups, and explicit maintenance retain full checks. Background inspections and temporary-file cleanup also leave more room for other work.Eligible full startup checks can now inspect agent databases directly without copying their entire contents, while retaining fresh integrity, ownership, and migration checks. Recovery-sensitive databases, empty files, and incomplete journal families still need snapshots. Independent agent checks can run two at a time, which can increase peak temporary-storage use and disk activity.Damage introduced after a file was checked may be detected by normal database access, the daily verifier, or explicit maintenance instead of the next reopen. Full integrity checkers use a larger temporary cache, with about 64 MiB more peak memory per active checker in the recorded measurement.If an inspection exhausts its ten attempts, the error now explains the limit and suggests waiting for database writes to settle before retrying. Ongoing writes are a possible cause, and the message does not guarantee the next attempt will succeed.
Read and write session storage efficiently
OpenClaw does less repeated database work when reading and saving conversations, including fewer unnecessary file-permission changes on macOS and Linux. On older installations, offline Doctor recovery can make conversations searchable again when they were missing from the old registry and their transcript files still exist. Explicitly deleted conversations stay deleted.Conversation saves and model changes wait for database maintenance and cleanup shutdown before writing. Canceled conversation changes stay canceled.
Save current settings and recover failed writes
Settings now confirms the version actually saved, including changes in included configuration files. If you revert a form change while autosave is running, that choice is preserved. Outdated drafts that conflict with included files ask you to reload, and save results distinguish what reached disk from what the running app has applied.After a stale write is rejected, choose Reload to retrieve current settings, then explicitly retry your change. The rejected write preserves external edits; reloading does not automatically replay it.If preparing a settings save fails, existing backup history stays intact. Failed saves can restore the original file when ownership checks allow it. If restoration is uncertain, Settings keeps your draft, pauses coordinated UI saves, and tells you which configuration file and backup to inspect. The draft is discarded only after a successful reload of an existing valid file. After reconnecting, a successful Reload Config also resumes autosave. Failed or offline reloads keep your draft.Doctor repairs now preserve supported nested model and agent settings without flattening included files. Removing an explicit included default model policy keeps an empty policy so later aliases do not unexpectedly restrict model access. A later update failure can leave the candidate package installed after those include changes, so retain the native backups and follow the repair guidance.
Approve settings changes and corrections from chat
Chat can propose settings edits that were previously refused, including runtime pins and model or provider settings. After a validation failure, the assistant can offer one correction with a separate approval under your session’s policy. A notice saying completion is unconfirmed means you should inspect current settings before retrying. Saving settings does not test whether an API key or model route works.For settings that run a command to obtain a secret, a remaining limitation can allow that preflight command to start after delegated approval ends. Do not rely on canceling the approval to prevent every such command from starting.
Find the cause of slow or failed maintenance
Status checks avoid unnecessary copies of large conversation databases and reuse session reads. Optional diagnostic timelines show where status collection spent time, while storage logs identify slow transcript reads and cleanup. Doctor also explains the fixed USER.md size limit and useful ways to shorten or move excess information.In pretty and compact console output, Gateway warnings, errors, and fatal messages can now show their redacted diagnostic fields, including in systemd journals. Long diagnostic tails can still omit later fields. This improves investigation without changing file logging or repairing the underlying slow operation.Deep status and Doctor now warn when pending database writes cannot finish moving from the journal into the main database. Capture the status output and restart gracefully if directed. Never delete a WAL file to clear the warning; it can contain committed data. Status polling also reads task summaries with less interference in chat work.Shutdown failures now retain the failed step and redacted exception details after exit, with bounded time for pending logs to flush. Inspect them with openclaw gateway stability --bundle latest --json. This helps diagnose failures once the fixed Gateway is running; it does not repair the original exception or recover details already lost.
Investigate a running Gateway's CPU and memory use
Administrators running OpenClaw on Node can investigate a busy Gateway without restarting it. Live diagnostics offers diagnostics.cpuProfile for CPU sampling and diagnostics.heapProfile for sampled allocation call stacks, through openclaw gateway call. Both require operator.admin and are requested manually.Profiles cover the main JavaScript runtime rather than all process memory or threads. Capture adds overhead and can take longer than requested if the Gateway stalls. Avoid competing profilers and review retained code symbols before sharing a profile. The results help investigate a problem; they do not repair it.
Keep bundled tools compatible after updates
The bundled tool refresh preserves chat scroll position during streaming and dock changes, fixes cleanup after an unused iOS voice capture is canceled, and keeps hidden Mac Dashboard and chat windows hidden. MCP app discovery, themes, and command-line selections also retain compatibility with their updated dependencies.The acpx backend now accepts incoming messages up to 64 MiB per raw line. Larger trusted messages need ACPX_MAX_ACP_MESSAGE_BYTES and a Gateway restart; 0 removes that limit. The direct OpenClaw ACP bridge is unaffected. Remote authenticated Lobster calls now need an explicit nested --token, separate from the approval-resume token. Ambient OpenClaw credentials are no longer forwarded to remote destinations, and already-dispatched steps are not automatically retried.
See which build is running
Git installations report the built version and flag when it needs rebuilding to catch up with the checkout. Doctor also gives rebuild and restart guidance when the recorded build and checkout commits differ. That warning is advisory and stays quiet during updates. If an agent fails because OpenClaw was replaced while still running, its error explains that a restart is needed.Refreshing Git update status clears stale reminders and behind counts when the checkout is current or ahead. Update settings also display an inferred Extended stable channel correctly.
Read documentation and release history
Documentation fixes make code examples and command labels readable in titles, preserve existing section links, and clarify setup and troubleshooting guidance. Per-version release notes are easier to browse, with labeled formatted and plain-Markdown reading options, including the earlier v2026.9.4 notes.
Back up application databases
Backups can complete when unrelated application databases contain broken references between records, while OpenClaw’s managed databases and declared plugin databases still receive checked snapshots. Agent and plugin discovery works during concurrent writes, including when workspace files are excluded. If discovery fails, resolve the error before creating a state backup. --only-config saves just the active JSON configuration file, excluding included files, state, and external credentials.Unrelated databases and their companion files are copied as ordinary files with warnings. Use the owning application’s backup procedure when you need a consistent copy of a running database or removal of deleted data. OpenClaw v2026.9.4 cannot restore archives containing these database companion files. Follow the backup guide, use openclaw backup create --verify, and keep a verified pre-upgrade backup if you need to downgrade.
Allow more time for slow updates
Updates on slower machines and installations with large databases now allow time based on the work they need to complete. Ongoing copy progress extends the wait, and update-status network checks default to 300 seconds with explicit overrides still available. Larger allowances can mean longer waits during a stall, and an updater already running keeps the timers it loaded. A timeout does not make rollback or restart safe by itself; follow the reported recovery instructions.With the corrected updater, a qualifying slow-starting Gateway can remain running after readiness checks expire, with its backups retained. The result stays gateway-readiness-unverified, not completed success or a promise to finish in the background. Keep the backups and check openclaw gateway status --deep. An already-running 2026.9.3 or 2026.9.4 updater keeps its older completion behavior and can still disable Windows autostart after this unverified result.
Use configured deadlines for setup and repair
Setup and repair conversations now use your configured agent timeout instead of stopping after two minutes. The embedded helper also skips skills it cannot use. Set an explicit shorter agents.defaults.timeoutSeconds value when you want to limit these runs; the documented default is 48 hours, and 0 disables the deadline. See the setup and repair guide.
Experimental room teams let several agents take part in one conversation. Messaging also improves replies, interactive questions and recovery after interruptions across supported channels.
Let specialists participate in a room
Experimental room teams let you bring several configured agents into one conversation, address a particular specialist, and let the agents discuss their answers for a limited number of rounds. Discord and Slack replies and attachments now stay with the participant who answered. Extra rounds use more agent runs, and the discussion’s active budget does not survive a restart. See broadcast groups for setup and limits.
Review cross-service messaging defaults
Agents with message-tool access can now send messages and perform permitted actions across configured chat services without a separate cross-provider opt-in. This also changes existing installations that leave tools.message.crossContext.allowAcrossProviders unset. Other tool, account, channel, and provider permissions still apply.To keep services isolated, set tools.message.crossContext.allowAcrossProviders to false. To confine guarded actions to the current bound conversation, also set tools.message.crossContext.allowWithinProvider to false. Per-agent settings override global settings. CLI calls without a bound source conversation are not confined to one conversation by these controls, and separate shell and filesystem restrictions still matter. See cross-provider messaging guidance.
Use Discord voice and interactive replies
Configured GPT-Live conversations in Discord can play short and subsequent replies, preserve pauses, and hear you interrupt while the agent speaks. Uneven audio arrives with fewer playback gaps, using up to 120 ms of initial buffering, and silence no longer interrupts the reply. Buttons, forms, model menus, and Activity launches also keep their actions tied to the intended choice.For GPT-Live, remove requireWakeName: true and consultPolicy: "always", or choose gpt-realtime-2.1 for host-controlled turns. The separate opt-in alternate Discord endpoint applies across accounts, takes precedence over explicit proxy and custom-fetch choices, blocks off-origin media, has no silent fallback to public Discord, and does not support interactive voice.
Read and address the intended Discord message
Reading a Discord message with --message-id or messageId now returns that message or an error, instead of unrelated recent history. Commands, autocomplete, and model selection also keep the intended channel or thread when Discord supplies only its ID. Authorized actions in your current DM accept equivalent native-channel targets while retaining the existing account and conversation restrictions.
Restore Discord threads and finish accepted work
When Discord starts, saved threads reconnect to their agent conversations without holding up other Gateway work on the database lookup. Failed or canceled startup cleans up the pending thread setup, and presence greetings recheck the current settings before they start. Stopping an account waits for accepted introductions to finish their delivery and recording work, so shutdown can take longer while that work settles.
Send richer LINE replies
LINE can bring photos sent together into one turn so your agent can consider the set, and supported questions in direct chats offer answer buttons. You can also enable native quoted replies or receive completed portions of an answer as they finish.Automatic quoting is off by default. Sending reply blocks uses more of LINE’s message quota. For models without native vision, photo sets need tools.media.image.attachments.mode set to all and a sufficient maxAttachments limit.
Keep Slack threads responsive
Slack keeps one progress card per command, shows interactive choices once, and preserves the complete written answer when controls cannot be used. A duplicate event waiting in one thread no longer holds up unrelated threads, and compatible corrections can reach a queued turn once it starts running.You can change supported access and reply settings for new work without reconnecting Slack. Replies already underway keep their original settings. Account, connection, and other settings that require a restart still reconnect Slack.Incoming messages remain queued for retry through temporary Slack authorization outages, while invalid credentials stay rejected. Socket Mode also handles the affected rate-limit and incomplete notifications without crashing the Gateway.
Keep Telegram conversations and input in order
Telegram conversation titles include known forum topic names, and earlier text reaches the agent before later long-message fragments. An authorized /stop clears your pending input in that chat or topic. Agents can also discover supported persistent subagent conversations again, keeping follow-ups with the same helper when binding is enabled.You can change supported access rules and reply settings for new work without reconnecting the bot. Work already underway keeps the settings it started with. Token, connection, account, and native-command changes still require their usual refresh.Typed commands retain replied-to photos, quotes, and topic context and now run in the chat session. Codex-backed credential requests also deliver their protected form links again, including in side questions. Enter the credential in the masked Control UI form, not in Telegram. Messages interrupted by shutdown before the agent takes ownership return to the queue for restart recovery; already-adopted turns are not replayed, avoiding repeated tool work.On affected self-hosted Telegram Bot API setups, a reply rejected with “rich message must be non-empty” can now arrive as plain text. This preserves the available text without enabling rich formatting on the older server or recovering previously stranded deliveries.
Preserve Teams mentions, tables, and polls
Teams replies preserve mention names containing escaped brackets or backslashes and correctly separate raw tables from code blocks in lists when table conversion is off. Votes submitted while older poll data is being imported are also preserved.
Recover Matrix replies and preserve local files
Previously joined encrypted Matrix rooms can recover replies at startup when their local encryption state is missing. Encryption remains opt-in, and rooms that cannot recover remain blocked from sending instead of falling back to plaintext. Control UI settings can also save again when Matrix account credentials use secret references, preserving those references and keeping their IDs hidden in readback.Background-generated Matrix media can arrive after the incoming request has ended, and recovered deliveries retain accurate reply information. Long messages and spoilers also need less repeated formatting work.Failed migrations now leave unrelated nearby files in place. If startup stops during a migration, retain the local database, source files, and .migrated archives while fixing the reported permissions or file conflict and retrying. The Matrix migration guide explains recovery.
Find Feishu contacts across directory pages
Feishu contact searches now reach later directory pages, and the requested result limit counts matching people. You can request more than 50 contacts; the default remains 50 matches, with existing access rules and a 100-page lookup limit.
Restore iMessage feedback and remote attachments
After the iMessage bridge recovers, supported typing indicators and read receipts can return on the next incoming message using your existing preferences. Official external iMessage installs can also copy permitted remote attachments into OpenClaw again.When iMessage catchup is enabled, OpenClaw recovers the oldest missed messages first at startup. The existing limits still apply, including the 500-message window per chat, your configured age limit, and the cap on messages replayed at each startup. Catchup does not repeat automatically or recover messages that earlier runs already skipped.iMessage setup now offers to correct a command path that points to a folder or a file that cannot run. Custom Windows command extensions must be allowed by PATHEXT; passing the availability check still does not guarantee the command will launch.
Use saved Signal accounts and long replies
Signal accounts with names such as Work Phone can start without running Doctor when they have their own configured phone number. Their own endpoint and access settings now take effect, so review those settings when upgrading. If deleting an account would activate another saved identity, OpenClaw leaves it running and names the conflicting entries for you to resolve. See Signal account guidance.
Answer questions in Mattermost
Mattermost offers buttons for supported simple questions, so you can choose an answer without retyping it. Typing still works, and questions needing private or more complex answers stay in text. Model menus also reflect the account selected for the conversation.
Save and import Nostr profiles
Authorized paired dashboard users can save and import Nostr profiles without supplying another credential. Profile actions can also use a valid saved credential when the browser credential is rejected, and rejected requests show readable errors.If access is revoked while a profile publication is being acknowledged, a retry with another saved credential can publish it again. Revocation cannot undo a publication already sent to a relay.
Keep eligible Buzz rooms connected
An unavailable Buzz room no longer keeps other eligible rooms offline. Granting a skipped room the Bot role can bring it back without reconnecting healthy rooms, while startup and reconnect reuse saved room information to prepare the appropriate history.
Find the next step when a room conversation stops
If a room conversation still cannot continue after restart recovery, a reminder can explain how to start again. Use an authorized /reset or /new, or choose Resume in new session in WebChat when the model is locked. Starting fresh keeps the old transcript.
Use approval buttons and keep prompts available
Authorized operators can use Allow Once or Deny on OpenClaw change-approval cards in Discord and Slack, and late button responses no longer overwrite the final result. Slack can also finish the original pending card after a restart. Configured approval forwarding also sends a text prompt when the destination’s native approval handler is inactive. A local prompt or a recovering handler can show the same request again; a handler stopping after the request arrives does not trigger rerouting.iMessage, WhatsApp, Signal, and Matrix now wait for approval controls to finish registering or clearing before reporting that operation complete. Plugin authors must await the updated registration and deletion methods and use a supporting host. If optional storage fails, the fallback lasts only until the process stops; see the approval SDK guidance.
Inspect and recover channel connections
You can check one channel’s status even if an unrelated account check fails. Accounts you explicitly start stay visible while discovery catches up, and recovery after a computer freeze continues past diagnostic errors. Accounts you stopped manually stay stopped.Replies on affected channels keep working after live settings changes without a restart. Queued replies and attachment cleanup keep using their original storage, even if settings change while they wait. Delayed replies and discovered conversations respect changes to the agent handling them, and follow-up messages waiting behind long replies avoid unnecessary timeout retries.Message scripts must omit --channel when they want automatic selection. An empty value now stops the command instead of silently choosing a channel; see message commands.
Recover Zalo Personal connections and saved sessions
A stalled Zalo Personal connection attempt now times out after 30 seconds and releases its listener so the existing retry path can try again. That is a limit for one connection attempt, not a recovery deadline for every outage. Restoring saved sessions and routinely refreshing credentials also move their database work off the Gateway thread on supporting hosts, preserving logout and replacement-session checks. QR-login replacement and logout keep their existing synchronous storage paths.
Keep incoming email moving
Packaged IMAP no longer lets the affected HTML-only emails block later incoming mail when they contain encoded characters such as an apostrophe. Updating to the repaired package restores parsing without a mailbox reset. If you build OpenClaw from source, rebuild the package to receive the fix.
Preserve location pins and message attachments
Location pins now survive removal of private runtime text from an outgoing message, and group-thread locations remain standalone so an added sender caption does not discard them. Attachments with unusual content-type headers also pass through media handling without the error that could stop an upload. Existing channel support and content limits still apply.
Recover incomplete channel replies
OpenClaw can recover a final answer or missing ending when part of a streamed reply is confirmed unsent. It keeps track of acknowledged text and attachments, while an uncertain send stays under recovery instead of triggering a competing answer. Some formatted replies still need the full-answer fallback and can repeat text when the delivered prefix cannot be matched safely.
Receive replies after channel requests finish
Verified official channel plugins installed through supported external installation paths regain replies from delegated work that finishes after the original turn ends, including the affected Discord setup. LINE and the shared SMS and Zalo webhook paths also keep replies and queued follow-ups alive after the initial incoming request finishes. Existing cancellation and access checks still apply; this does not extend the official-plugin repair to arbitrary third-party plugins.
Stop pending outgoing messages
Canceling supported messaging work now stops more pending sends, uploads, and message changes from starting. For a partly sent broadcast, OpenClaw keeps the completed results and distinguishes possible delivery from destinations never attempted, so you can follow up selectively. Possible delivery is not confirmation.Requests already submitted may finish. Cancellation does not recall delivered messages or files, undo accepted changes, or stop remote tasks already accepted. A file upload alone also does not establish delivery to a conversation.Telegram retains the delivered message when a follow-up pin fails. An optional pin failure leaves delivery successful; a required pin failure is reported as partial failure, with the message and its receipt retained. Recovery does not resend the original message because its pin failed.These protections depend on the channel carrying through OpenClaw’s cancellation check. They do not cover every scheduled-message path.
Prepare long replies with less repeated work
Long lists, code-heavy replies, and streamed progress need less repeated scanning as OpenClaw prepares them for chat. These changes preserve the text and message boundaries, while Discord persona replies also respect the requested size limit after mentions are expanded.
Clean up failed Feishu attachment downloads
If a Feishu attachment fails to save, OpenClaw tries to close the download stream even when no data has been read yet. You still get the original storage or timeout error for troubleshooting.
Read accurate QQBot setup warnings
Valid QQBot direct-message settings no longer trigger contradictory advice to add a wildcard that the configuration does not allow. This corrects the warning while preserving your access settings.
Understand WeChat pairing limits
The WeChat guide now explains that plugin version 2.4.8 uses its own sender list and QR-login fallback, so normal OpenClaw pairing approvals and revocations do not reliably control its chat access. Disable that plugin if you require those controls. This is corrected guidance; the plugin’s behavior has not changed.
Follow progress in channel replies
Supported channel previews now show readable progress notes, so you can see what your agent is doing while you wait. Slack and Telegram also remove abandoned previews after tool work while retaining the final answer or useful failure notice. Slack keeps a preview when someone has replied to it, preserving that part of the conversation. Your existing preview settings still control what appears.In Slack’s compact progress mode, the last complete update stays visible until the next complete one arrives, instead of being replaced by a word fragment.
Keep Mattermost thread participation current
Mattermost keeps a thread’s original participation expiry after a restart, so an expired conversation requires a mention again. It can also recover permitted recent thread context after a restart or reset, including DMs with threading enabled. Recovery respects historyLimit, reads at most one 200-post page per attempt, and has a five-second deadline. A reset can therefore be followed by earlier server-held messages returning as context; flat DMs are unchanged.
Keep messages with the selected destination
Messages now use the room or conversation selected through the active channel plugin, without a saved account default adding a conflicting destination and blocking the send.
Read the intended Teams conversation
Teams searches and member lookups now use the conversation you select, with existing access and membership restrictions still enforced. Channel lists and details also accept valid Teams team IDs when Slack is enabled. Lists still require teamId, and channel details require both teamId and channelId.
Read permitted context through installed channel plugins
Verified official Discord, Slack, and Matrix installs can retrieve supported context from other conversations when your account and destination rules allow it. Discord also restores permission and server metadata lookups. Matrix reads follow the existing room and direct-message access rules, with no new permission to change messages.Official Mattermost, Teams, and Feishu installations also restore their supported, permitted context reads. Mattermost history reads remain disabled until enabled, and Teams member lookup still excludes private and shared channels. Authenticated dashboard conversations can use supported official-plugin reads under their existing permissions. Channel-origin replies through CLI backends also regain permitted Discord actions and Discord/Slack reads; this does not grant the same authority to scheduled work.Update core and the official plugin together. OpenClaw 2026.9.4 lacks the required plugin API, so updating the plugin alone is not sufficient. See the channel-plugin guidance for the supported read actions.Discord server-wide reads require an allowed server and unrestricted or wildcard channel access. Delegated agents do not get the filtered channel-list exception available to direct operators. Other actions and unverified installations keep their restrictions, and revoking access cannot recall a request already sent.
Interrupted memory rebuilds can reuse completed work, and large searches cause fewer pauses for other work in OpenClaw.
Rebuild and repair saved memory indexes
With embedding caching enabled, a memory rebuild can reuse completed work after a retry or restart. The existing search index stays intact until its replacement succeeds. OpenClaw also repairs partially missing keyword indexes during normal initialization.With search synchronization enabled, an older index can rebuild automatically when you search after an upgrade. That first repair can take longer and make paid embedding-provider requests. After a rollback, a newer-format index is preserved and search stays paused until you upgrade OpenClaw or explicitly reindex. Checking status alone does not rebuild it.If changes to secret-masking rules interrupt conversation indexing, OpenClaw keeps the existing index and pending updates for another attempt. Those pending retries last only within the same running process, and new content becomes searchable only after a later synchronization succeeds.
Forget saved memories and their sources
Forget removes a session’s influence on memory ranking while keeping its source transcript. Forgetting a nonempty selection also clears that agent’s entire embedding cache, so later indexing may make new provider requests. Unrelated published memories remain searchable.Consolidated memories now keep the source links needed for Forget when a file replacement reports an error after writing, or its outcome is uncertain. Uncertain writes report an error without automatically appending another copy. This protects future Forget operations in that failure case; it does not recover source links lost before the fix.
Choose how conversations enter memory search
When optional conversation indexing is off, the agent is now guided to use available tools for reading the original conversation before suggesting a settings change. Indexing stays opt-in, and existing tool permissions still apply. When indexing is enabled, excerpts from before and after a conversation reset stay separate. Normal synchronization rebuilds existing indexes once for this fix and can reuse cached embeddings.In affected multi-agent setups, memory_get now reads from the same agent workspace used by memory_search. If you intentionally want that agent to read the parent workspace, set an explicit workspace pin.Memory search now has 30 seconds to run, up from 15, and that clock can pause while OpenClaw prepares the search. If it times out and the agent gives no final answer, a fallback reply explains what happened and counts any available keyword matches from memory files. These results remain incomplete and exclude conversation transcript matches that still need access checks.
Memory search responsiveness
Large memory searches and note preparation cause fewer pauses for other work in OpenClaw by running in the background. Control requests can also continue while large memory indexes are installed, though other database writes may still wait and indexing itself can take longer. Semantic search avoids a repeated-scan problem that could leave affected searches with only partial keyword results, without requiring a reindex.Independent conversations can recall Active Memory at the same time when helper capacity is available. The existing subagent concurrency setting controls this separate shared limit, and busy periods can still cause timeouts. On the Codex path, recall follows the current request through prompt rebuilds instead of being triggered by an old memory question in the conversation history.
Memory Wiki search and compilation
Memory Wiki reuses pages it has already parsed when searching, reading, and compiling your vault. OpenClaw can also find the Obsidian command when a folder with the same name appears earlier in the search path.
Public types for embedding plugins
Embedding plugin authors can use the public SDK types for asynchronous text batches instead of importing internal memory types. Batches remain per-file by default; combining a whole source requires explicit opt-in through sourceWideBatchEmbed.
Keep promoted memories within file limits
Dreaming and manual promotion now check that the updated MEMORY.md fits the startup file limits of agents sharing the workspace. They use the smallest configured limit, up to the existing 10,000-character ceiling. Only memories actually saved are marked promoted or included in dream narratives. To make room, OpenClaw removes only recognized generated sections within the configured prior-entry loss allowance, 25% by default. User-written and ambiguous text is preserved.A full or oversized file can pause new promotions until consolidation, freed space, or changed limits let them fit. Candidates still follow normal eligibility and expiry rules, so retrying alone may not help. Existing oversized user-written text is not automatically trimmed. Dreaming reports also explain why candidates that reached promotion were not saved to long-term memory.
Keep event-triggered reminders current
Event-triggered reminders now wait for ongoing session writes before saving their updates. If a reminder check times out while waiting, it leaves the reminder’s remaining activations intact, so an expired check does not use up a future reminder.
Skills now include interactive visualizations, while Workshop makes it clearer when a suggested change has been applied or rejected.
Find and load selected skills
Available ClawHub skill artwork now appears in search results and detail views, making skills easier to recognize. Sessions with several pinned skills load their revision details together while keeping the exact versions you selected.Explicitly selected manual personal skills now work with workspace-only file access. Agents can read the selected revision’s instructions and supporting files without enabling automatic invocation or opening access to unrelated files. Directory listing and changes to those files remain restricted.
Browse a plugin's complete skill folder
Open a skill from an installed plugin or a catalog detail page to read its instructions, follow bundled reference links, and browse supporting files in the Control UI. Catalog previews stay tied to the exact published version and require no installation or execution. You can also read a disabled plugin’s skills without activating it.Browsing requires read access through operator.read. Text previews have size limits, with explanations for binary, oversized, or unavailable files. Some older catalog entries need republishing or a metadata backfill before their root-level skills can be previewed.
Read complete skill verification reports
Piping openclaw skills verify into another tool now preserves the complete JSON report even when verification fails. Supporting ClawHub servers can return full scanner findings and coverage details, with reports accepted up to 64 MiB. Verification reads a stored scan; it does not start a new one, guarantee that a skill is safe, or authorize installation.
Apply Workshop suggestions with clear results
When you apply or reject a suggestion in Skill Workshop, its row updates as soon as the result is confirmed and stays consistent through refreshes and agent switches. Temporary confirmations disappear on time. If a result is uncertain, refresh and check before trying again. A changed suggestion still needs your review and another explicit action.Doctor also points out automation paths left behind when Workshop moves a skill, so you can update the affected jobs yourself. When sandbox restrictions block Workshop, troubleshooting guidance explains that restriction before suggesting changes to the tool allowlist.If an older Workshop backup was left behind after moving a workspace, run openclaw doctor --fix. Doctor can recover it when exactly one agent’s skills match all the recorded contents, then a Gateway restart clears the retained warning. Incomplete, changed, or ambiguous matches stay preserved for manual recovery. Do not edit the saved manifest or change your workspace to force a match.
Recover automatic Workshop reviews
In Workshop auto mode, weekly reviews now pause visibly when every configured runtime is known to lack support for keeping the review inside the Workshop directory. Inspect paused jobs with openclaw cron list --all --json, configure a supported runtime or fallback, then reload configuration or restart the Gateway. The same jobs become enabled again with their history intact.This does not add Codex support for these reviews or a separate review-only runtime selector. An enabled job still has to pass the checks when it runs, and automatic reviews still require cron to be enabled.
Prepare skills without blocking unrelated work
OpenClaw can keep handling other requests while it checks what skills need to run, prepares their commands or reads sandbox files. This helps when several agents start work at once. Some preparation paths can take longer or use more CPU while allowing those other requests to proceed.Security scans use fresh findings after a skill file is replaced. If you edit a file during a scan and the scan fails, finish editing and retry. Oversized source files are skipped. If a newly loaded pinned skill is rejected because its instructions exceed 1 MiB or use a disallowed link, restore the skill artifact or explicitly detach the pin.The sag speech skill now stays available with supported alternate credentials, such as SAG_API_KEY or an explicitly supplied key file. If it was previously disabled, run openclaw config set skills.entries.sag.enabled true and refresh Skills before your next agent turn. Ready means the executable is available; it does not verify credentials or successful speech generation.When a skill installer cannot find Homebrew on FreeBSD, the error now explains how to recover. Install the required tools manually through pkg or Ports on the computer running OpenClaw, then run openclaw skills check. Add --agent <id> to check a specific agent.
Connect Google Workspace from a remote host
The Google Workspace skill now tells agents to try your existing sign-in before asking you to set it up again. Updated guidance explains how to complete sign-in from a trusted shell when OpenClaw runs on a remote computer. Keep callback URLs and secrets out of chat, and enter callback URLs yourself in that shell rather than passing them through an agent tool.
Create interactive visualizations
The bundled visualize skill helps agents create interactive explanations as one-off visuals or saved dashboards, and update existing widgets. Widgets can now use chart libraries such as D3 and fonts from approved public hosts.Downloaded code can read the widget’s content and use permissions you have granted it. Loading an asset also shares your device’s IP address and the requested asset with its host. Access to dashboard data and actions on the OpenClaw host still require separate permissions.Recreate older saved inline widgets to use these assets, and prefer URLs pinned to a specific library version. PNG exports may omit external styles and fonts, and strict embed mode still disables scripts.
The Mac app now opens the Web experience by default, with an experimental Native option. Mobile and desktop updates also make conversations, connections and work waiting for your attention easier to manage.
Choose Web or experimental Native on Mac
The Mac app now uses the embedded Web UI by default, including existing profiles that have not saved an experience preference. To try Native, enable Native experience (Experimental) under Dashboard → Settings → This Mac → App. Dashboard, Dock and Gateway-window actions follow that choice. The toggle needs a current Gateway UI; the older 2026.9.4 UI remains usable but does not show it.Switching keeps each experience’s loaded windows and drafts available when you return. Drafts stay with their own experience, Gateway address and signed-in account, including the address used by an SSH tunnel. Settings opens on the web, while Connection, About and Quick Chat remain native. Command-N opens the Gateway-window picker, and Shift-Command-N creates a new thread.
Run and maintain a local Mac Gateway
You can run a Gateway on your Mac alongside a remote primary, with separate chat and dashboard windows. Enable “Also run a Gateway on this Mac” in Connection settings. It is off by default, and your remote primary keeps its existing Talk, menu-bar and node role. Connection settings also offers install, update and repair actions for app-managed local Gateways, even after you dismiss setup.
Recover Mac connections and switch Gateways
The bottom-left account menu now shows Gateway health and switching controls, with hints for existing keyboard shortcuts. Use Command-click or Control-click to open another window. Expired Cloudflare sign-ins have a recovery page inside the affected window; windows restored at launch wait for you to click “Sign in again.”If the approval page does not appear, choose “Open browser” and check the browser account before approving. A timed-out attempt needs a fresh sign-in. Closing a sign-in window opened by a command cancels that command.Nearby setup keeps your saved connection until you enter a trusted address, setup code or SSH destination and choose Save. Cancel keeps the current connection, and Direct node pairing now requires explicit approval.
Keep Mac browser tabs with their chat
Each Mac chat now keeps its own browser tabs, so you can switch conversations and return to the pages you left open for that chat. Tabs last while the window stays open and can show the page’s own icon. Update both the Mac app and Gateway-served UI for this behavior. Older tabs stay shared until closed, and login cookies remain shared across chats in the same window.
Keep an authorized Mac desktop available
Authorized Computer work can keep an unlocked Mac awake for up to an hour from its first action. To keep it awake between jobs while connected and hosting, enable Unattended desktop hosting under Settings → This Mac and accept the native confirmation. That option is off by default. It does not bypass login or lock; after locking or losing access, sign in normally and start fresh Computer work.
Choose models and sign in on Apple devices
iOS and Mac chat show the model, thinking and Fast controls supported by your current session, with provider sign-in available from chat. Mac Quick Chat refreshes choices without losing your draft and offers supported speed settings for the next message. If an older Gateway cannot supply native model choices, update it or use /models and /login.
Stop Mac audio and capture cleanly
When you cancel local MLX speech on your Mac, audio arriving late is discarded before playback and cannot interfere with a newer Talk request. Microphone tests finish cleaning up before you can start another, and camera capture ends before the recording is exported.
Mac windows, commands and launch preferences
Dashboard controls stay visible and clickable in full screen, including after reconnecting. Commands that finish quickly return their actual result instead of a false timeout, and rapid changes to launch-at-login preserve your latest choice. Remote-mode users who enable Cookie Sync also avoid its startup-watchdog crash.Automation can close an OpenClaw window without crashing the app or its other windows. Update or rebuild OpenClaw.app to receive this fix; updating the Peekaboo CLI alone is insufficient. Native plugin panels such as Workboard can load their stylesheets over a direct local HTTP connection. Cookies still share a hostname across ports, so do not put mutually untrusted services on that same hostname.
Smaller Mac app packages
Mac app packages omit unused copies of the dashboard, reducing download size and installed disk usage. The Gateway continues to supply the web interface. The reduction depends on the app’s architecture; it does not change how you open the dashboard.
Review work and choose models on Android
Open Chat actions → Review changes to inspect uncommitted code and add a selection to your existing draft without sending it. The viewer is read-only and appears when your Gateway supports change review. The Chat actions menu also stops closing unexpectedly on affected phones.Model controls follow the selected model’s supported Fast and thinking choices, and refresh failures show a warning with a way to retry. Provider sign-in and API-key setup are available from the picker when supported by your Gateway and administrative access; older Gateways show update guidance and retain slash commands.
Navigate Android Gateways and conversations
With multiple Gateways saved, the Android sidebar now lets you switch between them or add another without opening Settings. Add Gateway accepts a QR code, image, setup code or manual address and waits for Connect; Cancel keeps your current conversation. Unsent text and finished attachments stay with their Gateway, agent and conversation. Finish recording, importing or starting a send before switching. An offline Gateway stays selectable, but selecting it does not make it connected.The sidebar also keeps a stable width while opening and dragging, in both left-to-right and right-to-left layouts.
End watch calls and choose models for the current chat
Ending Talk on Wear OS starts microphone and speaker shutdown before waiting for the phone, while “Ending call…” keeps the conversation visible. Model choices now follow the chat selected on your watch, with available choices retained during a partial refresh. Update the phone app and Gateway if the picker reports missing support.Replies stop waiting once their outcome is confirmed, including a completed answer or a successful Stop. The watch also replaces its displayed reply when the phone shortens or clears the text, so an earlier version does not linger.Microphone permission controls offer Retry or Open Settings. After granting access, return to the watch app and tap again to start recording. If the microphone cannot start, Voice now shows an audio error.Accepted Type or Dictate input from Voice now opens Chat to show the reply or error. Canceled, empty or locally rejected input leaves you on the current page, and active Live Talk stays in Voice. You can also tap a failed-reply notification to open the watch app; its Reply action still retries through the original phone and conversation.
Browse inside the Tauri companion
The Tauri companion gains browser tabs beside your conversations, with navigation, screenshots, element inspection and native Save dialogs. Conversations keep separate tabs, but all reading tabs share cookies in one private browsing session. Closing every tab, switching Gateways or quitting ends that session; sign-in links still open in your system browser.
Manage saved Gateways in the Tauri companion
The Tauri companion can save direct and SSH Gateways, open independent dashboard windows and restore the last successful selection after a restart. Quick Chat, desktop actions and the Omarchy panel stay on Primary. Changing Primary requires separate confirmation and a saved token-authenticated connection. Linux needs an unlocked Secret Service credential store, and saved profiles from the separate Swift Mac app are not imported.Manage Gateways now has focused Add and Edit forms. Back discards unsaved form changes; blank credentials retain a saved secret only for the same address. Setup, recovery, the manager and Quick Chat follow system appearance while preserving in-progress text, with the connected dashboard keeping its own appearance setting. On macOS, the Tauri startup crash is fixed and credential-store failures show one dismissible notice. Resolve the reported problem, then choose Manage Gateways → Try again.
Use the Linux tray and Omarchy bar
The optional Omarchy 4 bar panel puts agents, sessions and quick prompts on your desktop, using the Linux app’s Primary Gateway when available. Install it separately with a compatible app or CLI. Drafts stay in memory and are lost when the shell restarts, and uncertain sends are not retried automatically.
Recover Linux Gateway connections
The Linux companion can retry your saved remote Gateway, and leaving Connection Settings keeps your active chat and sign-in. If the app cannot tell whether the Gateway is running, it keeps trying to reconnect and offers Start Gateway only after confirming it has stopped. A failure to monitor system sleep no longer leaves the app thinking the computer is asleep and blocking local recovery.
Retry Linux Quick Chat
If Linux Quick Chat loses confirmation of a finished request, retrying the unchanged draft can retrieve its completed answer without asking the model again. The recovered reply clears the busy state so you can continue typing. If recent history is unavailable or contains no matching completed answer, the error remains.Widget previews can regain access when you reconnect to the same configured Gateway. Switching Gateways leaves old previews unavailable, even if you later return to the same address. Slow widget updates now settle on the latest layout, and outdated failures no longer replace the current status.
Choose agents and keep Mac chat drafts
The native Mac chat sidebar now groups conversations under named agents and keeps a text draft for each conversation. Activity and attention indicators help you find work that needs you, while timestamps and cached message previews make threads easier to recognize. The indicators cover loaded sessions and local history. Finish handling pending attachments before switching conversations.New Thread keeps your selected agent and offers a separate Git working copy when needed. The revised layout leaves more room for reading, the message box grows with your draft, and model sign-in sits nearby when credentials need attention. Full chat windows also keep Reasoning, Tool Activity, pinned and recent models, and collapsed sidebar groups in the active profile. Named profiles use their own model and sidebar choices or normal defaults; unrelated global preferences are not copied into them.
Use the companion's window controls
The Tauri companion puts window controls in the dashboard header, with empty space for dragging and a double-click to maximize or restore. You can still resize from the window edges. Closing the main window leaves the app in the tray, while extra Gateway windows close normally. Older dashboards keep their native titlebars until updated.
Follow Linux desktop updates
Regular stable releases now start Linux desktop publication automatically. While a new bundle finishes, the updater can keep offering the previous signed AppImage. Linux downloads finish separately from the core release, so a new core version does not mean its desktop download is ready at the same time.Updated Linux clients recognize numbered correction releases and keep “Open download page” available if opening it fails. Older installed clients need this fix before they gain that behavior. For a manual update, choose a release that includes the Linux packages and their checksum file.The Linux compatibility guide clarifies that AppImages require glibc 2.35 and GLIBCXX_3.4.30. Quick Chat on Wayland needs a tray host, and Talk microphone capture needs the Control UI in a regular browser.
Keep answers visible in Mac chats
In the full Mac chat window, completed work folds into an expandable row above the answer, keeping the result and its attachments in view. Active work, work without an answer and unresolved work after an answer stay expanded. You can open the row to inspect earlier steps, including failures followed by a valid answer. Find in Conversation reveals folded content, and transcript exports keep it.
Switch saved Gateways on iPhone and iPad
With multiple Gateways saved, the iOS sidebar now offers a picker so you can switch without opening Connection settings. Unavailable Gateways stay listed, and the selected connection shows its current status. Before switching, send or clear your draft, finish recording, remove attachments and wait for pending delivery. Drafts do not move between Gateways or restore separately for each one.
Keep answers visible on phones and tablets
On iPhone and iPad, completed intermediate work now folds into a tappable “Worked” row above the answer. Tap to inspect it and tap again to collapse it. Final answers and media stay visible, while active or unanswered work stays expanded.Android adds the same interaction to default, agent-main and dashboard chats, with channel conversations keeping their full transcript. Active and steered work stays expanded, and unanswered failures remain accessible. Folding changes the view without deleting conversation content.
Follow dictation and attachment progress on mobile
Android and iOS now show what is happening while dictation starts, listens and finishes, with recognized words visible before they enter your draft. Android’s Stop finishes listening, Cancel discards a starting or transcribing attempt, and only final text is inserted. iOS adds a live waveform and offers Done to add the transcript or Cancel to discard it.Both show attachment-preparation progress. Android distinguishes local message queuing from delivery, while iOS also shows attachment sending and asks you to select an unavailable photo or video again. Dictation errors give retry guidance without silently leaving you waiting.
Restore and send queued mobile messages
Restoring queued messages now does less repeated database work on Android and Apple clients while preserving message and attachment order. Android also avoids reading unrelated queued messages before sending one, including messages waiting for another Gateway. Existing delivery order and retry behavior stay the same.
Inspect cited sources in native chats
Completed answers in Android, iOS, native Mac chat and Mac Quick Chat can show up to eight cited-source cards. Open a card to read the recorded search snippet or page excerpt, then use Open source to visit the page. Cards need matching successful research from the same answer, and missing excerpts are shown as unavailable. Previews reuse recorded content without fetching the page again; Android does not retain this source evidence in its offline transcript cache.
Preview questions and approvals in native sidebars
Tap a question or approval icon in the iOS, Android or native Mac sidebar to inspect what needs your attention without leaving the current conversation, even in collapsed groups. The count follows the oldest request’s kind. Previewing does not approve anything, and iOS administration approvals still open the Dashboard review page. Resolved requests and requests from a previous Gateway or account stop contributing attention.
Keep native Talk input and cleanup responsive
Android Talk now sends spoken turns that previously stopped after recognition and honors an explicit stt-tts choice using your configured speech provider and voice. Idle recognition beeps, visible fixed Talk instructions and setup readiness without a realtime provider remain unchanged.iOS Talk can return to Listening when developer diagnostic output is blocked. Delayed cleanup also stays with its original Gateway and account, so reconnecting cannot send an old session’s close request through your new connection. If the original connection has retired, cleanup is rejected there.
Prepare Apple notifications without blocking other work
The Gateway can keep handling other work while it looks up the device details needed for an iOS notification or wake request. Existing direct-device and relay registrations keep their current behavior, with no settings change needed.
Read current native controls in your language
Translations across 21 existing native-app locales now cover more Gateway setup, pending questions and approvals, dictation and attachment feedback. Android also gains translated QR-scanning and Talk voice-change guidance, while Mac onboarding gains translated setup and utility-model labels.
Embed OpenClaw in Rust applications
Rust developers can build on repository-local Gateway and node-host libraries for connections, reconnection, platform-managed signing and commands that accept input or report progress. A separate-process bridge adds authenticated messages and local permission checks.These libraries are unpublished and their APIs are unstable. Product integration and deployment remain the developer’s responsibility, and system.run is not included. The bridge authenticates messages without encrypting them, and cancellation of native work depends on handlers cooperating.
GPT Live reaches Talk, meetings and phone calls. Model settings make sign-ins and remaining Codex usage easier to manage, with fixes that preserve selected models and eligible subscription billing.
Use GPT Live in Talk, meetings and calls
You can speak while GPT Live replies in supported Meet, Teams and Zoom meetings, and let it consult your OpenClaw agent during meetings or phone calls. Select Live explicitly for these surfaces. In Talk, unpinned sessions now choose Live using your configured OpenAI access. Existing model pins stay in place.Live is audio-only, so choose gpt-realtime-2.1 when you need a camera. Configured Platform credentials take precedence over ChatGPT subscription access and use the Platform billing route. For meetings, update both Gateway and paired node and use supported isolated audio capture; remove a custom audioInputCommand before selecting Live. Live does not support Voice Call custom functions or host-controlled wake-name and forced-consult modes. On Apple clients, Stop ends the Live session. Headphones help prevent speaker feedback.Conceptual illustration: A voice for the work in front of you.
Change the voice during a call
You can ask the assistant to change its speaking voice during supported Talk calls, or use the browser’s voice picker. Supported Discord calls also offer in-call switching, now including Google Live’s prebuilt voices. The call briefly reconnects while keeping the conversation and unfinished work, and your saved defaults stay unchanged. Speech already submitted to Google may be interrupted and is not replayed. Discord still requires an authorized voice turn with agent delegation and tool access.
Use Apple models for setup and utility tasks
On an eligible Mac running OpenClaw, Apple Foundation Models can help with setup and short utility tasks without an API key. This optional route requires Apple silicon, macOS 27 or later, enabled and downloaded Apple Intelligence, Apple developer tools with the macOS 27 SDK, and a model with at least 8,192 context tokens. Those requirements apply to the Gateway host; connecting a Mac app to a Linux or Windows Gateway does not supply the model.Regular chat still needs a separately selected primary model. Apple’s smaller context and output quality limit its suitability for long prompts and complex tasks. Model Setup offers Recheck & repair if the helper is missing. Before upgrading, keep a verified archive of your current installation state. Returning to the older package requires restoring that archive; downgrading the package alone is insufficient.
Connect accounts and see their remaining usage
Connecting a provider keeps your chosen model. Replacement sign-ins saved through Model Setup stay inactive until you successfully test and explicitly activate them. If activation fails, setup can restore your working connection without overwriting newer connection edits. If setup requests a plugin update or Gateway restart, complete it and retry activation. Before downgrading OpenClaw, remove inactive replacement sign-ins or restore the state from before setup, because older versions may use them.On Models, administrators can compare remaining Codex usage beside each saved subscription login and refresh accounts individually. This display excludes API keys and other providers. Stored accounts return to Ready after verified quota recovery without a Gateway restart.Eligible automatic background OpenAI work keeps using subscription billing when an API key is also present. An explicit choice of a metered account still takes precedence.
Choose models from current account lists
Choosing Show all after sign-in reveals models already fetched from your account. Model lists can refresh expired provider catalogs in the background while keeping saved choices available, and a failed refresh leaves a warning you can retry. Model permissions now match the exact provider and model, so explicitly allow the intended pair if an older accidental match stops working. Showing a model never grants account access to it.If you declare a provider in current settings, supply its credentials and headers through the supported account or configuration settings. Keys and headers stored only in an older models.json no longer fill gaps in that declaration.If an older catalog is stored only in legacy files, run openclaw doctor --fix to import or repair it; ordinary discovery no longer changes those saved files. Unsupported native model IDs may also need an explicit definition before they can be selected or used for a child session. Doctor can repair supported retired Grok choices while preserving account pins and restrictions.
See which model is answering
WebChat shows the model actually generating a reply, including observed fallback changes in local, worker and native Codex runs. The picker keeps your saved choice. Until OpenClaw has an execution observation, the label says Model pending instead of reusing a previous turn’s model.
Keep manual model choices within allowed models
Manual model choices now follow your allowed-model list, including choices made through commands and saved automations. A model being the configured primary or fallback no longer grants permission to select it manually. If an existing explicit choice is rejected, use Default where supported or add the intended model to the list. Current-model reasoning controls remain available, and automatically selected child models keep their separate selection rules.
Preserve model choices when delegating work
When you delegate work to a child using the same agent, it inherits the model currently running in the parent, including temporary overrides. An explicit child choice or configured child model takes precedence, and a different agent uses its own selection. New visible child sessions also retain their configured backup models on later requests when selection was automatic; explicit choices, locks and empty backup lists stay strict. Existing children with incorrectly saved manual choices are not automatically repaired.
Read why a model request was rejected
Live and saved chats now explain recognized provider request limits instead of showing only a generic failure. For example, a rejected request can tell you that it supplied five cache-control blocks when the provider permits four. Private diagnostics remain redacted, and the explanation helps identify what needs correcting without changing the provider’s limit.
Wait and recover after provider limits
When a provider asks OpenClaw to wait, affected runs can finish that retry delay without being mistaken for stuck work. Exhausted daily caps, including OpenRouter’s free-model limits, skip futile same-model retries and move to eligible configured alternatives. Interrupted Responses tool calls can also continue from saved results without executing partial arguments. Cancellation, execution deadlines and existing retry limits still apply.
Guide Codex while it works
With a supporting Codex model, you can answer a question in the web UI while work continues, or return to it after the turn finishes. Suggested answers require your submission. When policy requires permission for a requester’s connected MCP tool, Codex now asks you to allow that call once or deny it.Follow-up work in a native Codex child keeps earlier task results. Eligible accepted follow-ups can recover after a yield or restart when Codex’s saved history identifies the accepted work. Older ambiguous records can remain unresolved, so let pending native work finish before downgrading OpenClaw.
Keep OpenClaw conversations out of personal Codex history
Ordinary Codex-backed OpenClaw chats now use per-agent storage instead of automatically appearing in personal Codex Desktop or CLI history. If you relied on OpenClaw borrowing your personal login, select detected Codex in Model Setup to sign in, or run openclaw models auth login --provider openai and select the resulting profile. Explicit appServer.homeScope: "user" remains an opt-in; remove it to use isolated storage. Your existing personal history is neither moved nor deleted. See OpenAI runtimes for setup.
Start and recover Codex conversations
A failed Codex turn no longer has to strand an otherwise eligible conversation when its instructions change. OpenClaw can resume the same saved thread after confirming that the old process has exited. Recovery still refuses cases where replacement would disrupt active or protected siblings, client-bound sessions or supervised work. Separately, one startup timeout no longer interrupts healthy turns sharing the process, and Linux process checks avoid waiting behind unrelated filesystem work. A native startup that never settles can still block new starts in the same Codex home until that process exits.
Load long Codex conversations with bounded history
Long Codex sessions load a bounded amount of mirrored history for prompt preparation and compaction, reducing memory allocation along that path while keeping full transcripts and native resume state. If required recent context cannot fit, preparation fails explicitly. An authorized standalone /reset or /new can recover by clearing active context, which loses conversation continuity; /reset soft is insufficient. OpenClaw does not reset or resume interrupted work automatically.
Keep Codex replies and reasoning complete
Codex previews keep their opening text, and completed reasoning remains visible even when it did not arrive piece by piece. Asynchronous messages stay separate from the final answer instead of being repeated there. Native conversation history also carries recorded speaker identities through compaction, helping preserve who said what; missing historical identities are not guessed.
Preserve Codex and Copilot task results
Temporary save failures no longer immediately discard completed Codex or Copilot child-task results. Codex retries saving results and delivery status without repeating an announcement just because its status write failed. Copilot retains the original outcome for a later event or cleanup to retry. Pending unsaved outcomes still depend on that OpenClaw process staying alive.
Preserve Copilot conversation continuity
Copilot saves the connection between your OpenClaw conversation and its native session without blocking the host’s main processing thread. Reset and shutdown wait for pending saves and cleanup, and a late compaction result no longer removes a different replacement session.
Keep long-running model commands within their deadlines
Long foreground commands can use their accepted execution time without prematurely aborting the whole agent turn. Codex commands on paired nodes also honor their resolved command budget; upgrade OpenClaw core and the Codex plugin together for that repair. Setting a command timeout to zero disables only its process timer, while transport deadlines, Stop and approval limits still apply. CLI-backed turns also preserve remaining timeout budgets across detected long process freezes.
Use supported reasoning levels
Fable 5 and 5.1 now inherit Medium reasoning effort, as does GPT-6 Astra when the account supports it. Your explicit effort settings still win. Fable and Mythos offer their supported Low through Max choices; update scripts that send /think minimal or /think adaptive to use /think low or /think high instead. The thinking guide explains model-specific defaults and how /think default clears a saved session override.Thinking choices also stay with the selected model and runtime across interactive and automated work. Supported effort levels still depend on that route; selecting Off does not make a model with mandatory reasoning stop reasoning.
Keep custom model settings in effect
Custom OpenAI-compatible models keep their declared advanced reasoning levels when you start a session and send requests, within the API’s supported limits. Custom Anthropic and Mistral requests also keep your chosen response-length limit when the model’s information omits an output ceiling. Provider limits still apply, and Anthropic manual thinking is disabled if it cannot fit that response budget.
Understand model context limits
OpenClaw now counts tool definitions when checking how much room a model has left for a reply. Affected OpenAI-compatible requests log a warning when almost no room remains, helping explain unexpectedly short answers. Custom models configured below the existing 4,000-token minimum now stop before sending a request, even if you set a larger input cap. Correct the model’s declared window or choose one with enough room.If you downgrade, older OpenClaw versions can discard saved model-budget information during recovery, leaving context engines to use their fallback limits.
Continue long conversations through compaction
Long conversations can continue through compaction without overstated context pressure prematurely blocking the next request. Saved summaries retain their full streamed text, checkpoint branches leave the source conversation running, and recorded speaker IDs help preserve attribution. Slow required compaction can finish without repeatedly restarting the waiting reply, while authentication failures now reach recovery guidance. These fixes preserve usable context within the model’s existing capacity.Budget-triggered compaction on public OpenAI Responses now uses its compact endpoint by default. Set params.responsesCompactEndpoint to false to opt out. Manual compaction keeps its previous default, and confirmed overflow or endpoint failure uses client-side recovery. This new default does not extend to ChatGPT, Azure or custom Responses endpoints. See compaction for the available controls.
Continue after a provider's progress message
An agent can continue from a progress message to tools and a final answer when a Responses provider explicitly says the turn is unfinished. You no longer need to send another prompt in that case, and cancellation and stop controls still apply.
Continue conversations on compatible Responses endpoints
A verified compatible custom Responses model can opt into stored HTTP continuation with compat.supportsResponsesContinuation set to true, allowing later turns to send new input with a reference to the previous response. This deliberately permits the backend to retain requests, even on turns that cannot continue. supportsStore: false and explicit no-store policy still take precedence. Dedicated Azure and ChatGPT/Codex routes are excluded, and some turns may still resend full history. See provider configuration before enabling it.
Stop unfinished API work when the client disconnects
When an OpenAI-compatible HTTP client disconnects before its response finishes, OpenClaw now sends cancellation to the unfinished chat, embedding or media-preparation work even when the runtime reports only a closed response. Completed responses keep their normal behavior. Provider-side work may already have started, so disconnecting does not undo completed actions.
Use optional tool arguments with ChatGPT subscriptions
Tools used through ChatGPT subscriptions can leave unused optional arguments absent instead of filling them with empty placeholders. The correction applies to HTTP and WebSocket requests. Required fields and tool-execution checks remain in place; this does not change strict structured response output or guarantee which optional values a model will choose.
Keep image and PDF requests on the intended model
Image descriptions and PDF analysis keep the model selected for that request, and PDF results name the selected model consistently. Heavy image and PDF processing can run separately so other OpenClaw requests continue and cancellation can take effect. Busy workers can reject new work, and their three-minute deadline includes time spent waiting.Restored Codex screenshots now stay beside their original messages instead of appearing attached to a later request. If a whole historical message no longer fits in the model’s context, its images are left out of that request but remain saved.
Use media from the active task's workspace
Image and PDF inspection, along with local generation references, now follow the active task’s worktree and relative directory. A screenshot created in that checkout can be read without moving it to the agent’s default workspace. Local media access still respects approved roots and symlink boundaries, and sandboxed tools retain their filesystem isolation.
Preserve long voice notes and avoid wasted synthesis
Deepgram Flux preserves voice-note audio beyond 20 minutes instead of silently dropping the end, within your configured size and timeout limits. The speech CLI also rejects an unsupported remote Gateway --output request before synthesis starts, avoiding provider usage for a file it cannot save locally. Audio transcription commands now identify the provider and model used when that information is available.
Connect organization models through Radius
The new Radius provider connects your organization’s model access through browser sign-in or an API key, with streamed answers and supported image and tool use. Requests use the selected organization’s credits and follow its budgets and policies. Available models depend on that access, and some advertised models can still be unavailable upstream.
See why a search failed
When every automatic web-search provider fails, operator logs retain the first failure to help you trace the problem. Known docs-search HTTP errors return without waiting for diagnostic response capture to finish. Failed web-search and fetch commands also allow piped output to finish before exiting with failure, within the existing five-second drain limit.
Automatic Daybreak retries
Eligible defensive-security requests can receive one automatic Daybreak retry after a structured OpenAI policy refusal, in both native Codex and embedded OpenAI chats. The retry keeps your selected session model in place. Successful interactive embedded retries name Daybreak or your configured retry model before the answer, including in the originating group or channel.Automatic retries are enabled for eligible unlocked settings and require access granted by the provider. An unavailable target can add a request and delay. Strict model selections, other refusal types and work that cannot safely be repeated still stop without a retry. To disable retries, set plugins.entries.codex.config.appServer.cyberFailover.mode to off for native Codex, or agents.defaults.embeddedAgent.cyberFailover.mode to off for embedded turns. See model failover for configuration.
Keep generated media filenames
Generated music attachments now use the saved audio filename, including a name you supplied, so immediate results and background completion messages identify the same file. Generated images and saved videos also keep readable filenames in their results and completion messages while retaining their unique storage paths. Videos returned only as links keep their existing names.
Generate media with the intended references
Video generation preserves repeated reference positions, so the same image can serve as both the first and last frame of a loop. Image editing and image-guided music generation can reach a compatible configured fallback when the primary cannot accept the references. Invalid provider media responses fail visibly; third-party speech or video endpoints with malformed response headers may need their headers corrected.Alibaba and Qwen video requests now enforce one total timeout, including downloads, using the existing 120-second default. Slow jobs may need an existing timeout override. A local timeout does not establish that the remote job stopped or that billing ended.
Choose the same model through different runtimes
You can offer the same model through OpenClaw and Codex as separate, labeled choices in the chat model picker. Each choice shows the reasoning and context options that its runtime supports. To enable this, set pickerRuntimes on an exact model entry, with up to eight explicit runtime IDs. Your configured agentRuntime stays the default. Per-agent lists replace inherited alternatives, and an empty list removes them. See the models guide for configuration.Each alternative needs an enabled, compatible runtime and current account access. Adding a picker choice grants no credentials or access. ACP and locked sessions keep their runtime restrictions, and unavailable saved alternatives are discarded rather than silently replaced. Use explicit runtime IDs rather than auto or default; wildcard model entries are excluded. Opening the picker uses prepared choices, while Refresh checks for new ones.
Reduce retained text during long replies
During long ordinary-text replies through Completions, OpenClaw keeps less accumulated text in memory as the answer arrives. Completions and Responses also avoid repeated waits when a scheduled pause runs longer than expected. The reply text and cancellation checks stay intact. Processing time varies, and short replies can take longer.
Scheduled work keeps your latest edits and gives you clearer ways to follow what ran, what failed, and what needs attention. You can also see whether delegated work is running, waiting or finished, and whether its result has returned.
Keep scheduled work and its outcomes current
Changes you save to a running schedule or watcher now survive completion and crash recovery. Manual runs report that they are queued only after the queue accepts them. That acknowledgement means the run was accepted, not that it has finished; use its run ID to check the outcome.After a plugin reload, script automations can refresh stale tools once before starting. Repeated failures stay grouped, and confirmed successful completion sends a recovery notice. Setup recovery never replays a script or tool action that has already started.Doctor now preserves scheduled reports that return to their original conversation, including setups without an external messaging channel. If an older repair already changed a job to isolated delivery, restore its intended destination manually. Disabled jobs stay disabled.Before downgrading, let affected edited runs finish and let the scheduler finish reconciling their results on the current version. A completed task alone is not enough to preserve those edits when returning to an older version. Stream sources stopped by matching overload or timeout need you to check the expression or server load and explicitly re-enable them; disabling or changing an exit watch cancels its pending exit.Administrator tasks can keep managing existing automations after waiting for subagents, without another user message. That access belongs only to the exact resumed task and covers management of existing jobs. Cancellation, a session reset or archive, a new direct user turn, or a Gateway restart ends the handoff.Click Automation attached in a session hovercard to open its automation editor. If several automations match, you get a list filtered to that session, with Show all automations to return to the full list. Your existing viewing and editing permissions still apply. In the CLI, an ambiguous job name now shows matching jobs so you can retry by ID; scripts using duplicate names must use an ID too.
Read completed automation runs
Choose View transcript in Tasks or automation run history to read the specific completed run, even after its temporary session has been cleaned up. The CLI also makes it easier to investigate a run, with searchable, paged history and separate filters for execution and delivery results. Transcript access still depends on retained history and your permissions. Existing text-block limits remain, so this does not recover deleted history or text that was omitted from the stored view.Synthetic example: A morning pulse, a research roundup, and a review—with outcomes to read.
Keep quiet heartbeat checks silent
Quiet heartbeat checks can finish in the built-in runtime without an unwanted missing-summary warning or another finalization request. If a check falls back to a CLI backend without the response tool, it now receives explicit guidance to stay silent when nothing needs attention. That fallback still depends on the model following the instructions. Accepted alerts and private monitor notes also survive retries and compaction, while stopping or superseding a check suppresses its delivery.
Automation owners and maintenance notices
Explicitly configured owners can now manage existing automations across sessions directly from chat. Eligibility comes from individual entries in commands.ownerAllowFrom, not channel allowlists or wildcards, and management does not transfer the creator’s execution permissions. If Doctor can identify who created an older automation, openclaw doctor --fix restores their ability to edit its prompt without changing tool permissions. Jobs stop before execution when a required creator account is unavailable. Restore that account or recreate the automation under the intended account; changing its delivery account does not transfer ownership. A missing execution agent also leaves a reason in run history.Revoking the initiating device’s authorization stops later scheduling changes from its admitted agent turn, including after disconnect. An ordinary disconnect does not revoke that authority, and already accepted changes keep their recorded outcomes. Existing schedules are not canceled by revoking their creator’s token. A queued run can still be stopped before execution by later revocation.Changing an account-owned job’s type and changing it back now preserves its account restrictions. Jobs that already lost that policy need explicit operator reauthorization or recreation by the authenticated creator. Tool restrictions also stay in effect across OpenClaw and Codex, including an explicitly empty tool list. Every applicable restriction must allow a tool, so jobs relying on the earlier combination of restrictions may lose access to some tools.Doctor also warns when some automatically captured tool lists may be missing file, command or web capabilities. The restrictions may be intentional, so even --fix leaves them unchanged. To add tools, an authorized session must review and replace the complete list, including every tool the job should keep. Agents are instructed to ask an authorized administrator to check a known automation after a restricted lookup fails, before creating a replacement.Scheduled message edits, deletions and pins must match the saved creator provider and account and use an adapter that declares the necessary authorization support. Update OpenClaw and the plugin and load its updated registration if an unsupported adapter refuses these actions. Claude-created automations preserve their saved execution target under automatic placement, but a conflicting explicit host or required sandbox policy rejects execution, including for existing jobs with that saved target.New update and restart notices go only to destinations matched to configured command owners, and update notices respect account send settings. Unsupported destinations lose notices and restart continuations, while update results remain in the Control UI. Review owner eligibility and account send settings if chat notices stop arriving. Later policy changes do not recall notices already queued.
Use permitted channel actions from scheduled jobs
Scheduled agents can read supported channels without an incoming chat, using either their operator permissions or their saved creator account. Eligible Discord jobs can also edit, delete, pin and unpin messages. Operator-created jobs can edit channels and threads through supported adapters; account-owned jobs need authorization from the actual requester in the owning Discord conversation. Current requester and bot permissions, enabled actions, target restrictions and the job’s allowed tools still apply. Delivery settings do not grant access, and changing the default account does not replace the saved creator account.Use an updated, loaded adapter with support for the scheduled action. Older jobs missing creator or requester information need fresh authenticated authorization or recreation. Changes to executable behavior, such as a prompt, model or schedule, can clear prior requester or local-read authority and stop further affected actions; an edit already accepted by Discord can still return its confirmed result. Reauthorize from the owning Discord conversation or, for local-read authority, a fresh authenticated local session. Remote management alone cannot grant local-read authority. The scheduled payload guide explains the required complete tool allowance and recovery paths.
Finish automatic reset hooks
Hooks that run during daily or idle session resets can now finish delayed work after the triggering request ends. This lets a hook wait for another operation and continue its work without losing its place when that request finishes.
Review a subagent's result before announcing it
A parent agent can now review a subagent’s result privately, ask for more work, or stay silent before anything is automatically announced to a channel. Opt in with completionTarget: "parent" when spawning the subagent. A busy parent handles the result in a separate private turn after its current work, and resetting or removing the parent keeps the result from reaching a replacement session. Fast child results wait for the parent turn to settle; after a normal parent response, a ready result can proceed while siblings continue. Private processing also retains accurate timeout outcomes and available final details.This option supports hidden native one-shot runs. ACP, collected results, visible or threaded runs, session mode, and expectsCompletionMessage: false are not supported. Automatic child results, parent replies and generated media stay off the channel on this route, but permitted explicit send tools can still send messages, and operators can still inspect tool arguments and child transcripts. Leaving the option unset preserves existing behavior.Keep a verified pre-upgrade backup and follow the target build’s migration instructions, including stopping processes that write to OpenClaw’s data before running doctor --fix. Rolling back requires the matching released build and backup, losing work saved after that backup. Older builds may discard private handoffs, so downgrading and upgrading again does not guarantee they will resume.
Delegate work to a selected project
An agent can now open a separately visible child session for a registered project or managed GitHub repository, optionally in its own worktree. This gives delegated work its own place to run and a session you can follow. Visible children can also inherit the current conversation while the parent keeps working, with their own assignment made explicit after the inherited history.Use a visible native subagent with exactly one of projectId or projectGitUrl, leaving cwd unset. GitHub HTTPS and git@github.com repository URLs are supported; local paths, file URLs, other Git hosts, hidden runs and ACP runs are excluded. Existing sandbox boundaries, tool limits and setup-script permissions still apply, and arbitrary external directories still require administrator access.
Follow delegated tasks and continue their work
The task inspector now shows whether a subagent is working, waiting or finished, and whether its result has reached the parent. You can inspect its activity and child dependencies beside the parent conversation without losing your draft. When a runtime cannot report current activity, the inspector leaves it unknown.Agents can wait for selected tasks to finish or need attention. OpenClaw reduces a source of delays in subagent waits, task lists and cancellation checks when many past tasks are retained. Explicit message modes let them supply future context, steer supported active work, or start a follow-up turn. Ending a wait or reaching its time limit leaves the tasks running and their results available for delivery. The notify mode queues context for a future turn without waking the target or confirming it has read the message. That queued context can be evicted or lost on restart.The explicit sessions_send mode resume can continue an eligible paused native child while preserving its original task and completion recipient. It requires current authority over that child and returns acceptance, not the final answer. Omit watch and use no positive wait timeout. Ordinary follow-up messages keep their existing behavior, and previously stranded tasks are not automatically repaired.Scheduled jobs wait for delegated work and its result delivery before choosing a final response, within their existing deadline. Repeated wait checks now leave time to process completion. Managed Lobster approval flows can also resume from a saved checkpoint with the flow ID, current revision, owning session and the user’s decision.
Find relevant conversations for agent work
Agents can find conversations by owner, creator, project or workspace, filter for activity, and continue through matching results instead of mistaking the first page for the whole inventory. Metadata-only requests do not read transcripts or start sessions. These filters preserve existing access permissions; filters relative to the current user need a trusted identity, and current activity requires a Gateway connection. Results are a live view, so agents need to account for conversations changing between pages.
Wait for background commands and collect their results
Work resumed after a background command finishes uses the normal agent timeout instead of the shorter heartbeat budget. ACP turns and approved-command continuations can use their configured execution budgets, resumed native subagents retain their saved timeout, and late replies can still be observed after an initial wait expires. Explicit limits and cancellation still apply, and that late-reply observation does not survive a Gateway restart.Background commands still do not automatically wake a subagent. Collect their terminal results with process poll before yielding without another completion source, including after a requested stop. Confirmed requested stops with successful cleanup avoid false failure notices, while real timeouts and cleanup failures remain errors. Completion entries now explain the existing tools.exec.notifyOnExit=false setting for stopping automatic completion turns while keeping background commands. Check per-agent overrides; changed settings apply only to newly started commands, whose results you can collect with process poll or process log.
Keep worker coordination out of the main conversation
Multi-agent conversations hide raw worker reports and automatic coordination replies while keeping useful parent answers and task results visible. Child reports no longer start reciprocal reply loops, and a requested late result can produce one visible parent answer. Human follow-ups still get their own visible replies. Coordination remains in raw transcripts and model context, and older messages without enough sender information remain visible. This display behavior is separate from opting into private parent review before an announcement.
You can share a page in a local managed browser with your agent and use computer controls on supported local or cloud desktops. Cloud sessions also gain more ways to reuse prepared work and recover after interruptions.
Start work from prepared cloud environments
Private repositories can reuse eligible prepared cloud environments, reducing repeated setup when matching capacity is available. Your source GitHub credentials stay on the computer running OpenClaw during preparation. The connected session receives its normal credentials later.Crabbox-based workers require version 0.56.0 or newer. If your host cannot download releases, stage a supported copy before updating OpenClaw, because worker inspection and cleanup need it too.File checks for large workspaces are also faster when preparing node and cloud sessions. Stop can cancel preparation before a worker is allocated, though file reads already underway must finish before cleanup. Upgrade the Gateway to receive this fix; updating only the node is not enough.Linux and macOS deployment images can also reuse a verified cloud-node archive after a restart, avoiding repeated compression. This requires updating the image recipe. Windows and existing images keep building normally, and worker installation and provisioning still happen.
Resume or recover cloud sessions
A first message waiting for cloud setup can continue after a Gateway restart. Returning to a released session now waits for its replacement worker without reporting a false stall, and Stop prevents canceled setup from launching work later.For a failed session, choose Gateway · local in Restart session… to recover on the computer running OpenClaw once worker cleanup finishes. Recovery uses the last accepted workspace checkpoint. Changes that were never uploaded may be lost, and the interrupted turn is not replayed.Archiving an independent cloud session no longer waits for unrelated setup maintenance. Its sidebar row hides immediately and returns with an error if the request is rejected. An already-failed worker with no live turn can stay archived while cleanup is retried separately. Undo restores the row while the retained checkout is intact; it does not restart the worker.Active and provisioning workers still follow their normal steps for stopping and saving work. Deleting or rebuilding a checkout also keeps stricter cleanup checks. Update both the Gateway and Control UI for this behavior, and check the actual archive state after a timeout.If a saved first message is stuck after a startup timeout, Retry can use the worker that has since become ready. Reconnecting alone does not allocate a replacement, and uncertain sends still need Check delivery. Repository conversations marked Worker required now offer Choose worker… so you can continue in the same chat on an eligible device or cloud worker.
Check cloud work with less repeated file processing
Finishing cloud work can avoid repeatedly reading unchanged files, while changed files still receive the checks needed before their results are accepted. Large workspace scans also reuse temporary memory for file checks.Large transfers and result checks now run expensive file calculations in the background so other requests can stay responsive. This can use more CPU and memory and does not necessarily shorten the transfer.
Manage cloud snapshot build results
The Snapshots page keeps build progress, cancellation controls, and failure messages visible even when the image list fails to load. Dismiss a reviewed failure and it disappears from the current view, updating Needs attention as soon as the request succeeds. The retained record can return after a page reload.
Run sandboxed tools on compatible cloud workers
The optional Crabbox sandbox backend can run commands and file tools on a cloud machine while your agent and model credentials stay on the host. Enable and configure the plugin to use it. Initial support is direct Daytona with a compatible Crabbox build; version 0.56.0 lacks the required capability, so prepared-worker support alone is not enough. Cloud resource usage applies, and this backend does not support sandboxed browsers or Docker bind mounts.Before downgrading to a version without this recovery support, disable the backend and finish pending cloud allocation or cleanup using the current version. The shared SSH backend also now requires native no-replace directory renaming to create or recreate workspaces. Existing workspaces remain usable without being reseeded.
Clean up failed local sandbox setup
If Docker or Podman sandbox setup fails, OpenClaw now tries to remove the container created by that attempt. Existing containers with a conflicting name are left alone. Cleanup can still fail, in which case the error reports both the setup and cleanup failures so you know what needs attention.
Inspect and control the intended desktop
An agent on the computer running OpenClaw can now control its configured desktop without a separately paired node. Enable cua-computer, allow the computer tool, and use a vision-capable agent. The configured Gateway desktop is preferred by default. If it is unavailable, the request fails without sending input elsewhere. Provider setup and native display permissions still apply.On desktop-enabled Linux cloud workers, agents can launch a graphical app with exec and use it on the same desktop. Use background: true for apps that need to stay open.The viewer’s Match option resizes compatible virtual desktops to fit the panel when you have control and permission to resize. Fit remains the default, and older fixed-size workers need a backend update and reprovisioning. Supported browsers in a secure context can also open a view-only Picture-in-Picture window, letting you watch the desktop beside other work. Keep the originating viewer open.Supported window actions return a fresh screenshot and element references for the agent’s next step. If input or the refresh fails, get a fresh observation before deciding what to do next. Input is not automatically replayed.After a rapid hide/show of the embedded Desktop, a later disconnect keeps its reason and Reconnect control visible. Repeated Stop requests on paired desktops now wait for cleanup already underway. Cloud Desktop shutdown cancels queued app launches and waits for its local work, including work from a replaced worker. Local cleanup completion does not confirm that the cloud provider has released the machine.
Inspect browser pages and apply policy changes
Browser pages appear directly in the Chat panel header, leaving more room for the page. Mac Browser panes also stay visible beside menus that do not overlap them. Plain accessibility snapshots show references beside their controls, helping agents target follow-up actions on supported backends.With hot reload enabled, you can change browser enablement, JavaScript permission, and network policy without restarting the whole Gateway. The browser service still restarts, canceling pending work and closing OpenClaw-managed Chrome tabs. Attached and remote browsers stay open, but OpenClaw disconnects from them. Extension relay settings still require a Gateway restart.If Chrome loses a tab’s internal automation target, the extension relay can restore control for clients that remain subscribed, provided the tab is still accessible. Take a fresh snapshot before continuing; failed actions are not replayed. Explicit detach and Chrome’s Cancel still stop control.Agent browser previews stay readable during refresh, with progress on the reload button. Browser message-dispatch failures now close the affected connection without stopping unrelated Gateway work. The failed browser operation is not automatically retried.
Recover managed browser sessions and profiles
Slow but healthy managed browsers can keep their process and tabs through startup and later readiness checks. Profile reset and deletion also verify which browser owns the data before moving it, preserving the data when ownership is uncertain.For a lock naming another host, including after a machine rename, close the browser using that profile and verify its Chromium lock before retrying. Automatic cleanup of a browser left by an earlier OpenClaw runtime remains limited to Linux and macOS; this adds no Windows cross-runtime recovery. Late cleanup from an old Chrome connection also leaves its replacement alone, and cancelling a request before it starts preserves other callers’ shared browser work.If installing the browser’s local helper fails while replacing a file, you can retry without restarting OpenClaw. The previous launcher or manifest stays intact, and leftover temporary files no longer block the retry.
Paste text into the agent's browser
Click a field in a managed Agent browser panel or Browser dashboard and paste plain text with Cmd+V, Ctrl+V, or right-click Paste. Password fields, multiline text, and fields inside embedded pages are supported. Paste waits for the remote click to succeed and does not submit the form or change the remote clipboard. File and image paste and Chrome MCP existing-session profiles remain unsupported. See Browser panel controls.
Save a displayed browser file
The Browser sidebar gains a Download file button for the image, video, or document you are viewing, keeping its preview open. Mac tabs use a native Save dialog. Eligible Agent tabs download through your browser; default or network-restricted Agent profiles must use Open in your browser instead. Remote browser-node transfers retain their 10 MiB file limit, and existing-session Chrome MCP profiles do not support this action.
Share a browser page with your agent
A shared Browser dashboard lets you and your agent use the same page. Enter a note or change an app’s filters, then ask your agent to continue from what you changed. It uses a local OpenClaw-managed browser profile and that profile’s login state, including for permitted HTTP apps shown through the HTTPS Control UI.Browser access is required. Remote profiles, paired-node browsers, and attached personal browsers are unsupported, and the page does not use your phone or laptop’s cookies. Stop closes the tab and loses unsaved page state. Resume opens the saved URL.Typing in the Browser panel also preserves spaces between words again.Conceptual illustration: One page. A shared point of view.
Choose which machine handles browser actions
Automatic browser actions now prefer the selected browser on the computer running OpenClaw, even if an installed managed browser has not started yet. If that computer has no browser capability, a single eligible connected node can handle the request. Explicit targets and configured node pins take precedence. A failed action stays with the selected browser instead of being replayed on another machine.This default can change which machine and browser login session you use after upgrading. To keep using a node’s existing session, select that node explicitly or set gateway.nodes.browser.node.
Use real paths for browser output
Browser downloads and traces preserve the directory name you requested, including trailing spaces, and check the whole path before writing. If your output directory passes through a user-created symbolic link, choose its real, canonical path. The Invalid path error can now apply even when the final directory already exists. The macOS /tmp and /var system aliases remain supported.
Start remote tasks in an empty workspace
Choose New workspace to start a task on a cloud worker or eligible paired device without supplying a repository. Remote sessions choose it by default when you have not explicitly selected a folder, project, or worktree. The selection survives draft reload and placement recovery, while explicit source choices keep their existing validation.Existing agent files are not copied. Each new session starts with its own Git history and remotes, and Git remains an internal requirement. Normal managed snapshots and recovery still apply; this does not add disposable workspaces or general multi-repository support.
Install or reload supported plugins while your Gateway keeps running, and give teammates read-only access to selected conversations.
Install plugins and continue the conversation
You can install or reload supported plugins without restarting the Gateway, making it easier to add an integration or try a plugin without taking the whole installation offline. Owners can do this through the command line or an authorized chat command, and the Plugins UI helps you find official and ClawHub packages. Existing permission checks and consent still apply.Managed Codex conversations can continue with changed tools, carrying completed results and accepted follow-up input within bounded conversation context. This stops the current native turn and background terminals. Imported or supervised Codex sessions need a new managed conversation for changed tools.The CLI also accepts several plugins in one enable, disable, reload, update or uninstall command. Earlier successful changes remain if later work fails, so review the result before retrying. Local files and marketplace registrations must be available on the Gateway computer, and offline installs wait for startup. If installation saves but activation fails, follow the repair message and run openclaw plugins reload.After a replacement timeout, recovery can wait up to 60 seconds for unfinished work, restore the previous plugin and restart eligible channels. Cleanup failures can still require another reload or a Gateway restart. Restart into the updated code to receive this repair. Rebuilt bundled code and enabling experimental native plugin UI retain their separate restart requirements; native UI also needs a browser reload.
Recover plugin reloads and release retired resources
Changing Lossless settings no longer lets cleanup from the old plugin close the replacement’s database. Eligible failed replacements can recover using the previous code and settings, while unchanged plugins keep running. Successful cleanup is required before replacement, so slow cleanup delays recovery and a cleanup failure can leave the affected plugin unavailable. A plugin replacing itself from an active call must wait for that call to finish.Repeated reloads also release more retired plugin state and reuse unchanged bundled setup code. Memory growth from native ESM modules remains unresolved, so long-running installations can still accumulate memory across reloads.
Load source plugins under Bun and Node
Bun-hosted Gateways can reload supported installed-plugin source through the existing source checks, and receive targeted fixes for TypeScript, JSX and deferred imports. Node also handles directly imported source SDK code through the appropriate loader. Compatibility still depends on the runtime and plugin’s imports. Some Bun cases require a patched runtime, while conditional package exports and indirect source-SDK imports retain known gaps.
Find plugins by purpose and inspect them
Purpose-based categories and package logos make plugins easier to recognize and browse. Installed and catalog plugins now share an overview with their capabilities, documentation and available actions, and local controls remain usable when optional catalog information fails to load. Marketplace pages keep their destination when you refresh.Plugin details load through one ClawHub request. Operators of a self-hosted registry must add support for /api/v1/packages/{name}/detail before upgrading this client.With telemetry enabled, deliberate plugin searches send normalized query text and remote result counts to ClawHub analytics, which retains queries for 30 days. Local inventory matches and user, device and session identifiers are excluded. Set CLAWHUB_DISABLE_TELEMETRY to opt out while keeping search results available.
Search and edit grouped plugin settings
Plugin Settings can organize options into searchable sections, with per-field reset controls and permissions on the same page. Plugins without section definitions keep their complete flat form. Text and number edits commit when you leave the field, while switches commit immediately. Escape also commits the focused edit before leaving Settings.
Inspect and edit plugin credential references
Administrators can inspect supported credential fields to see whether a plugin uses an entered key, an environment fallback or a secret reference, and edit declared references directly in Settings. Existing keys stay masked, and only a newly entered replacement can be revealed. Environment fallbacks remain inspect-only, and read-only configuration cannot be edited.Reference saves wait for acknowledgment. Canceling a rejected edit preserves other changes, but a lost acknowledgment can leave the draft and error visible until you reload. Saving a reference does not rotate the secret or verify the provider connection.
Ask about a plugin setting
Use Ask OpenClaw on a plugin or individual setting to prepare a contextual question without losing your existing conversation or draft. The question stays unsent until you choose Send. Generated value previews withhold recognized sensitive values, and help waits while a sensitive setup answer is in progress. This protection applies to the generated preview, so check any private information you type yourself.
Build and inspect custom plugins
Plugin authors get clearer build and verification errors when a package is missing its manifest or a declared JavaScript entry. Builds preserve existing manifest and package-folder permissions. Plugins stored beneath a symlinked parent directory also regain correct manifest hashes; after updating, use openclaw plugins registry --refresh to repair affected registry metadata.Registration-time api.config and its descendants are now read-only. Plugins that mutate them can throw or have writes ignored, so authors need to update those integrations. See the related maintenance change.
Pass large inputs to plugin tools
Passing large datasets to managed plugin tools uses less temporary memory and preparation work before execution. Existing object identities, shared references and cycles remain supported. The improvement concerns input preparation rather than total application memory.
Carry agent setup in Claw packages
Experimental Claw packages now preserve explicit model preferences and delegation settings. With a local Gateway running, add and update can activate up to 64 required plugins together after the usual trust and capability confirmations. Missing models and companion agents still need to be configured separately.Earlier successful steps can remain after a later failure, so follow the reported recovery instructions before retrying. An interrupted installation can also refuse to resume if model or companion-agent availability changes. Offline installation still needs a restart. Removing a Claw leaves global plugins installed by default; explicitly selected plugin removal waits for active work to finish.
Share selected conversations read-only
Session Share lets you share selected conversation groups with teammates on another paired OpenClaw installation, giving them read-only access without handing over control of the conversation. Both sides must enable sharing, and an empty group selection shares nothing. Recipients see conversation text and eligible user-created forks, without subagents, tool activity or reasoning. They can read the conversation but cannot continue it, archive it or use its terminal.Choose groups carefully, since text and metadata may contain private information and revocation cannot recall what someone already received. Keep the source node connected and restart it after configuration changes. Reload an older open shared view after updating, and restore cold history on the source before reading it remotely.Conceptual illustration: Share the conversation. Not the controls.
Browse sessions from installed coding apps
Choose which installed coding apps supply sidebar conversations in Settings → Appearance → Session sources. Claude Code, Codex, OpenCode and Pi now have one place for these controls. Updated paired nodes can show native Codex conversations without a matching Gateway agent, and empty catalogs stay hidden while discovery continues. Large CLI history imports preserve more conversation text and visible results within the response size limit.Codex listings follow native activity recency and preserve conversations sharing the same timestamp. Browsing and search reuse already loaded session details, and valid saved listings can reopen while refreshing after a restart. Renames and successful archives update the catalog without another full scan; external changes may wait for background refresh. Older conversations remain accessible through native paging and search, which can take longer and return partial pages to continue. Very large native responses can still cause memory bursts.These settings autosave for everyone on the Gateway and require a restart; the relevant plugin must be enabled. Update paired nodes as well as the Gateway for the newer Codex discovery behavior. Fresh Claude Code and Codex discovery defaults off, while OpenCode and Pi defaults on. New Claude CLI conversations can use saved subscription tokens while existing conversations retain their account and history. API keys require explicit selection, and your configured fallback policy still applies.
Start and recover coding-agent conversations
Connected coding agents can recover from a stalled /reset or /new after the existing 15-second cleanup deadline, letting a fresh conversation proceed without restarting the Gateway. Old cleanup may continue in the background. Canceling queued or initializing ACP work also prevents unwanted provider submission through the repaired setup paths.ACP clients normally receive a new session’s introduction before its updates, and unrelated session creation no longer holds up an active prompt. An initial backlog above 256 updates can still arrive before the introduction so its content is preserved.
Read and cancel code-navigation results
Bundled code-navigation tools process large, fragmented language-server replies with less copying. Stopping a turn during language-server startup now stops further launches and cleans up the servers that turn acquired. Canceling an individual tool request still leaves its shared server available for later requests.
Work with large Workboards
Opening a Workboard and claiming a task now involve less unrelated card data, so damaged records elsewhere no longer block those actions. Other application work can continue while Workboard waits on its database, and plugin reload lets already-accepted storage work finish. Damaged records still need attention when read directly, and archived cards still prevent a board from being deleted.
Save large Team Reports
Other work can continue while Team Reports waits on its database to save a report. Large roster refreshes use fewer writes, and a failed refresh preserves the complete previous report and roster. Standalone plugin installations need a compatible host with the SQLite worker SDK.
Maintain Logbook without blocking the Gateway
Logbook handles database waits in the background so other application work can continue. Screenshot cleanup waits until active previews and analysis finish reading the images. Expired screenshot metadata is removed in batches while timeline cards, observations and standups remain available under the existing retention rules.Use a compatible worker-capable host for standalone Logbook installations. Stop Logbook and let active work finish before moving its storage. Rolling back the database cannot restore screenshot files that retention already deleted.
Search saved meeting and call history
Find past meetings by words in saved notes or transcripts, then read long summaries with their headings and lists intact. The wider meeting timeline gives those notes more room, with clear loading feedback on desktop and mobile. Larger saved transcript libraries and voice-call histories also avoid repeated database work when you reopen them.
Keep Reef message checks available
Reef can reuse an explicitly configured OpenAI OAuth login for message checks, with the required model permissions and compatible Codex runtime policy. Existing API-key setups remain supported. If message-tracking storage fills, the shared inbox stays connected and parks affected entries until capacity becomes available.An entry may be delivered again if its earlier delivery could not be recorded. Before downgrading from the OAuth setup to an older version, restore the older API-key configuration described in the Reef guide.
Read original timestamps in Fleet logs
Add --timestamps to openclaw fleet logs to compare container events by their original log time. It works alongside --follow, --tail and --since; leave it out to keep the existing output format.
Keep ClickClack discussion setup consistent
ClickClack saves the installation identity used to own a discussion before creating its remote channel. If that identity cannot be saved, channel creation stops and asks you to retry opening the discussion. Existing saved identities need no migration.
Remove a Beam from the current view
Confirming a Beam deletion immediately hides its sidebar row while the request runs. If deletion fails, the current row returns with an error. Successful deletion is permanent and leaves independent continuations intact; uploading the same Beam later can recreate its row.
Diagnose MCP configuration and cleanup
Read-only Doctor checks preserve working MCP OAuth logins by leaving schema inspection to authenticated operations that can save refreshed credentials. Use --severity-min info to see deferred checks and openclaw mcp probe <name> for a configured server. Plugin-provided servers and agent-local profiles need an authenticated serving-agent turn. Already-invalid logins still need reauthorization.Claude CLI tools remain usable after the turn that started their listener finishes. Silent configured MCP calls receive the existing 15-minute active-tool allowance, with cancellation and transport deadlines still in force. Servers denied as a whole no longer start, and unused discovery connections can close while retained tools remain available. If cleanup remains unconfirmed, inspect or stop the affected processes before rerunning Doctor.
Protect current workflow progress
An outdated task-flow update can no longer replace newer saved progress or recreate a deleted flow. Progress notifications also wait until the update commits, so a rolled-back change does not appear to have succeeded.Finished subagent tasks and their linked flows also avoid redundant updates during idle Gateway restarts. Genuine corrections still persist, and failed notifications can still retry.
Adopt asynchronous plugin storage
Plugin authors can use awaited storage, task and flow operations so their database work can run while other application work continues. Loading saved tasks and workflows at startup, during reloads and before awaited SDK reads now uses the background worker too. Webhooks and Lobster wait for managed-flow saves before returning results or starting dependent work. Data-only keyed-store operations now use the shared database worker; callback-based updates, validation and serialization still run on the calling thread. The storage migration guide explains how to switch interfaces without copying data.Check host capabilities before using optional APIs such as deleteIfEqual, await writes, and reread state before retrying a creation whose outcome is uncertain. Existing synchronous APIs remain supported but deprecated. Linking child work to a managed flow does not launch it, and later changes still need the documented revision and ownership checks.
Keep conversations usable with custom context engines
When a custom context-engine hook fails, the conversation’s message order and tool-result history are restored for retry. Pending work keeps the resources it needs, and delayed subagent cleanup stops incorrectly disabling a healthy engine just because its original caller has finished. The history repair restores the message list, not arbitrary changes a plugin made inside individual messages.Intentionally disabling a recognized selected engine uses the built-in engine and keeps your choice for re-enabling. A cold start can still report a missing engine when its plugin has a different ID and no ownership registration is available. Genuine plugin failures retain their existing isolation behavior, and earlier quarantine is not automatically cleared.
Browse and filter Workboard tasks
Workboard filters now work together, so you can narrow cards by status, priority, attention needed and recent completion, including on mobile. Switch from the default board to a list with aligned task details and collapsible status groups when you want to scan more work at once. The list-view choice is not saved. Clearing filters keeps your selected agent context; use the agent picker to return to All agents.
Edit Workboard cards and protect drafts
Workboard card details now organize task information, activity and recent session context into tabs, with common fields editable in place. You can also rename a board and choose or reset its icon and color. Closing changed cards or comments asks before discarding your draft, and failed saves keep your edits available. Dragging cards preserves neighboring status changes, while attachments on a recreated card survive cleanup of its predecessor.Use matching current Workboard, Gateway and Control UI components for these controls. If a move’s result is uncertain, wait for a successful reload before editing again; your open comment draft remains available.
Change several Workboard cards at once
Select several Workboard cards in board or list view to change their status, assignment, priority or labels together, or to archive or delete them. A batch can finish only partly, so review the results before retrying the unfinished cards that remain selected. Deleting a card leaves its running session active. These controls require matching current Workboard and Gateway components.
Finish background plugin work
Deferred plugin webhook callbacks can finish after the request that started them ends, while remaining tracked during Gateway shutdown. This repairs the closed-request failure that could interrupt background processing. Plugin authors using the deferred-work helper should account for callbacks having their own lifetime and continuing after the requester cancels.
Find and combine tools in Code Mode
With Code Mode enabled, an agent can find native and MCP tools together by describing the task it needs to perform. Optional TypeScript checks help combine calls and report several errors at once, while existing permissions and approvals still apply. Exact tool names now distinguish capitalization, and an active wait keeps its tool-call deadline instead of expiring as an idle snapshot.Returned data preserves numeric values and literal object keys. Typed arrays return indexed JSON objects, so use Array.from when you need an array and convert dates explicitly. If a tool returns malformed data, the error identifies problem fields and advises checking what happened before retrying, because the action may already have run.
Continue coding-app conversations after Stop
Stopping a reply now keeps an established coding-app conversation available with its earlier context for the next turn. The partial reply stays visible, and the interrupted turn remains unsuccessful, so you can continue without treating unfinished work as complete.
Reuse results within a Code Mode run
Code Mode can save a result and reuse its complete data in later cells, including after wait and resume, without fetching it again. Eligible oversized final objects and arrays can also become reusable references automatically during interactive execution. A preview is only a sample; load the saved result for calculations over the full dataset.These are temporary snapshots that expire when the run ends or aborts, tools or permissions change, or the Gateway restarts. The store holds up to 64 entries with a default 10 MiB encoded-JSON allowance, and refuses new saves when full without evicting existing results. Result operations are unavailable in restart-safe cells. Automatic retention also excludes headless execution and can fall back to ordinary truncation when the result or reference cannot fit.
List 1Password items efficiently
In installations with many agents, 1Password item listings can skip unrelated access grants and avoid failures caused by damage in those grants. This requires a storage adapter that supports reading only the requesting agent’s relevant grants. Listings still return metadata, with existing secret-access and approval rules in place.
Recover a custom plugin workspace
UI customization now lives under Plugins → Customize UI, replacing the floating button. The Plugins page always opens the built-in workspace so you can reach these controls even when a custom workspace hides navigation. Open /plugins under your Control UI base URL and choose Built-in to return to the standard workspace.
Retrieve files delivered by a specific run
Integrations can request only the files an assistant delivered for a chosen run, leaving out user uploads and raw tool observations. Set messageRole to assistant together with runId; the run ID alone does not select outputs. Scoped managed downloads return the exact selected file or report it missing when its ID is stale.Older Gateways reject the new filter. Integrations must show that limitation instead of silently retrying without it.
Keep registered diff previews during cleanup
Diffs cleanup now preserves an older preview directory if it becomes registered while its age is being checked. It also skips unnecessary database checks for recent files. Files being rendered remain protected, and orphan cleanup still applies only to directories more than 24 hours old.
Recover an interrupted file overwrite
If a pre-approved File Transfer overwrite fails because the disk fills or a file-size limit is reached, OpenClaw attempts to restore the original contents instead of leaving an empty or partly replaced file. The transfer still reports its original error. Restoration is best effort and can also fail; it does not provide recovery from a process crash or power loss.
Cancel PDF extraction without crashing the host
Canceling PDF extraction no longer aborts Node through the repaired PNG-compression initialization failure. Cancellation during that encoding step waits for it and the worker to finish; rendering remains immediately cancellable. A stuck protected native operation can still delay cancellation beyond the task deadline.
Prepare Feishu document tables
Preparing Feishu documents with several tables or longer cell text needs less local processing while preserving table widths and Unicode text. Smaller inputs and some batches may not benefit, and Feishu network requests are unchanged.
Use authorized email services from agent tools
Shared agent instructions now explicitly allow user-authorized email CLI and API actions under existing tool permissions and approvals. Replies to connected chat channels still use OpenClaw routing. This clarifies existing permissions; the separately reported native Codex email refusal remains unresolved.
These changes tighten specific permission checks and improve how OpenClaw handles credentials in tool results and diagnostics. Client developers can also add checks that tie actions to the selected account.
Keep command approval tied to the launch
Covered Gateway and node command paths now recheck saved approval-file permissions before launch and keep reviewed programs tied to their approved paths. This does not stop a process that has already started, and queued Linux helper launches can still start after approval is revoked. Requester-specific MCP tools in OpenClaw’s Codex integration also ask for an allow-once or deny decision when policy requires it. Full-permission sessions and the trusted OAuth sign-in step retain their exceptions; SDK integrations need to supply the approval callback.If you use custom Homebrew curl or git paths, move HOMEBREW_CURL_PATH and HOMEBREW_GIT_PATH from the launch-directory .env into your launching shell or ~/.openclaw/.env. Project environment files can no longer choose those executables during an approved dependency install.
Keep sandbox writes inside their allowed paths
Sandboxed Codex file changes through OpenClaw’s shipped local and remote bridges now reject directory links that redirect them into protected locations. Authorized directory aliases still work. Sandbox file tools also follow the files and permissions visible inside the container, including overlapping mounts. Use exec for container-only storage that file tools cannot verify, and recreate affected containers after changing bind sources or access modes. See the Docker sandbox guide for the supported mount changes. The patch-tool guide explains why full command access can still leave file changes restricted.
Keep sandbox attachments within allowed folders
Sandbox media reads and reply attachments now retain the active session’s allowed folders, rejecting reads from another session’s sandbox and reply staging from an unmounted host workspace on the affected paths. Plugin SDK integrations must supply trusted session context to access sandbox files. Authorized workspace reads remain available, including the existing caller-workspace access in ordinary inbound processing.
Keep subagent attachments separate
Files passed to native subagents now live in OpenClaw-owned storage, with Docker and Podman children receiving read-only access to their own attachments. Use the file paths supplied to the child. Attachment-bearing spawns are refused on shared-scope sandboxes and unsupported backends, including SSH; spawns without attachments continue as before. Pre-upgrade attachments in child workspaces remain for operator cleanup. The subagent guide explains the supported configurations and changed paths.
Use native helpers for guarded file operations
OpenClaw now automatically uses installed native helpers for supported guarded file operations on macOS, Linux, and Windows. Moves that must preserve an existing destination require that helper. If native mode is off or the helper is missing or unsupported, a move to an absent destination is refused with its source retained.On supported installations, change an explicit native-off override to auto or remove it, install with optional platform dependencies enabled, then restart and retry. Unsupported environments need a supported runtime and filesystem for these moves. Check both paths before retrying an error reported after a move starts, since a later identity check can fail after the move completed. See secure file operations for mode and platform requirements.
Mask recognized secrets in tool results and diagnostics
OpenClaw’s built-in agent runtime now masks recognized and registered secrets in completed tool-result text before the next model request, including file reads, command output, and tool errors. With redaction enabled, custom rules retain built-in credential checks. The release also corrects mistaken masking of public status links and masks reflected bot credentials in new Mattermost error diagnostics.Log views and exports now mask recognized credentials and private-key fragments across selected portions of stored logs while keeping JSON readable. The stored files remain unchanged, and reading a selection can take longer because masking may scan earlier history. Secret detection remains limited to recognized patterns and registered values, and the tool-result change does not cover native Codex. Previously shortened message text cannot be restored.
Configure and diagnose secret references
Missing credentials under numeric account names or dotted provider keys now point to the exact setting instead of surfacing as a later authentication failure. The config command also preserves literal secret-provider arguments, including empty strings and surrounding whitespace. Quote those values in your shell, and reapply any previously saved argument whose whitespace an older command removed.
Use private credential files
File-based SecretRef credentials now require a private regular file with a single hard link. Existing hardlinked credentials can block startup or secret activation until you replace them with a new private file at the configured path; changing permissions alone is insufficient. Follow the Linux and macOS replacement procedure, then run openclaw secrets reload for a running Gateway or repair the file before restarting. The separate 1Password broker-token hardlink allowance remains in place.
Read verified credential files on Windows
Secure credential reads on Windows x64 verify ownership and access permissions using the matching native helper. If that helper is disabled, missing, or outdated, the read is refused. Restore auto mode or reinstall the matching helper without resetting your credentials. Native Windows ARM64 has no matching helper for these reads. See secure file operations for recovery guidance.
Honor current tool and messaging permissions
Limited tool profiles now also restrict Codex native shell and file access, and isolated workers retain the command restrictions set by the Gateway. Keep restricted Codex sessions on a compatible managed runtime. Worker commands that need unsupported remote approvals must run locally under the configured approval policy; incompatible retained workers need recovery or reprovisioning. Workspace plugins need explicit trust before replacing configured channels.Messaging topic changes and sends follow the configured cross-context rules, including when the source service is known but its conversation address is missing. Omitted cross-provider settings now permit otherwise allowed actions across services. Set tools.message.crossContext.allowAcrossProviders=false to preserve service isolation, and set allowWithinProvider=false as well to keep a bound conversation within its current chat. Pending sends stop before new provider requests after their caller closes, including Discord queue retries. Rejected unsent messages stay out of recovery once that rejection is saved; already dispatched messages cannot be recalled.PDF access now follows media and OpenClaw group restrictions, so an explicit PDF allow cannot override a conflicting group deny. Narrow that deny if PDF access is intended. Doctor also stops copying LINE direct-message senders into group permissions. Review existing groupAllowFrom entries if you ran an earlier repair, since previously copied entries remain in place.
Stop revoked sign-in attempts
GitHub Copilot sign-in attempts stop further guarded requests and sign-in steps when the attempt is revoked or superseded. MiniMax chat sign-in also checks current permission before subsequent token requests in both global and CN flows. These changes stop later acquisition steps; they do not revoke existing credentials or undo token requests already sent.
Preserve current device credentials and revocation
Device credential handling now protects newer saved tokens from cleanup left over from an older connection. Integrations using asynchronous storage can finish saving an accepted token through disconnect or shutdown before reconnecting. Rotating or revoking a device token, or removing its device, also invalidates the corresponding retained Dashboard read access after disconnect. Disconnect alone still lets accepted work finish, and revocation cannot undo requests already sent. See device management.
Keep Side chat within current conversation access
Side chat questions and cached answers now follow current conversation visibility, including private drafts in deployments with Gateway roles. Access is checked again before later embedded model requests, including requests delayed by credential or media preparation. Revoking access can stop the next request, but cannot retract context already sent to a provider.
Protect retained conversation history
Retained conversation history continues to follow current sharing permissions after a session is deleted. Direct access to a deleted session’s retained transcript now requires operator.admin; task history keeps its separate authorization rules. Recall also picks up same-size offline transcript edits after restart, archived multiline imports remain readable, and usage totals follow configured stores and known agent ownership in shared storage. Older unregistered files retain their existing accounting behavior. See session history access.
Keep discovery preferences from enabling unwanted plugins
The discovery opt-out that OpenClaw saves for native conversations no longer produces a misleading disabled-plugin warning or, by itself, enables Codex and expands the plugin allow-list. Doctor offers manual guidance for matching historical entries, since it cannot tell whether you intended to enable the plugin. Those entries are preserved. Other activation rules still apply, including Doctor’s default-model repair when no model is configured.
Stop outdated webhook work after settings change
Rotating webhook credentials, changing hook policy, or disabling hooks now stops outdated pending requests before they dispatch more work. A request rejected because settings changed receives 409 and can be retried with the current route and credentials. Already accepted work remains accepted, and successful replay keeps its original result without launching duplicate work.
Apply network limits to downloads and incoming webhooks
Browser download actions now follow the selected profile’s destination restrictions, so downloads that previously bypassed those rules can be rejected. Nextcloud Talk and Feishu webhook listeners also limit simultaneous incomplete requests before authentication, reducing the resources those requests can hold open.At saturation, legitimate webhook arrivals can receive a closed 429 response and may be lost. Reduce or buffer upstream concurrency where needed, and do not assume rejected deliveries will retry. The Nextcloud Talk guide explains its fixed read limit and overload behavior. Mattermost slash commands now have separate upload capacity for recognized command credentials. Preserve the original Authorization Token header through proxies; OAuth callbacks and requests with stripped headers share anonymous capacity and can be throttled, as explained in Mattermost troubleshooting.
Update security-sensitive dependencies
IMAP email handling updates Nodemailer for reported security advisories. The Tauri desktop app updates Rustls to reject invalid TLS 1.3 handshake sequences in its Gateway WebSocket and updater HTTPS connections, while retaining certificate and fingerprint checks.Markdown-it also receives the upstream smartquotes denial-of-service fix for parsers with typography enabled. The proxy-addr update corrects affected Express proxy-trust matching. Downstream Express deployments using malformed mapped prefixes or cross-family trust may need correct IPv4 or mapped-prefix notation.
Limit access to a managed Signal connection
On POSIX hosts, a managed Signal connection can now use an optional private UNIX socket to restrict daemon access by OS user. HTTP remains the default. Follow the Signal setup guide for a distinct absolute socket path and a parent folder owned by the OpenClaw user with 0700 permissions. Socket failures do not fall back to HTTP. This option is unavailable on Windows and does not isolate processes running as the same user or administrators; Linux operators must also ensure the folder hierarchy has no ACLs granting others access.
Keep Fleet actions on the selected container
Fleet start, stop, restart, removal, upgrade, and restore-recovery actions now stay tied to the container that was inspected. Reusing its name for another container no longer redirects those actions to the replacement. Initial creation and startup retain their existing behavior, and an explicitly requested data purge can still delete tenant data even when forced container removal finds nothing left to remove.
Replace Gateway certificates without disconnecting clients
If your Gateway serves HTTPS directly, you can replace certificate files at their existing paths without restarting listeners or disconnecting established clients. Incomplete or mismatched replacements leave the last accepted certificate in use. Turning automatic reload off pauses certificate adoption until you enable it again.Update saved certificate pins on remote clients before reconnecting after renewal. Changing TLS enablement, certificate paths, or listener configuration still requires a restart. Each certificate and private-key file, including a certificate chain, must now fit within 64 KiB. Correct oversized files before startup or inspection; separate CA bundles retain their existing behavior. See hot reload for the supported behavior.
Upload files through protected network connections
File uploads through protected egress now send the correct upload length to services that require it, while retaining authorized secret substitution. This applies to uploads with a known length up to 100 MiB. Cancelling a buffered upload stops its unsent remainder, though bytes already submitted cannot be recalled.These uploads wait until OpenClaw has collected the full body before sending. Shared capacity limits or the five-minute deadline can refuse a transfer. Larger uploads and those without a known length still send in chunks, which some destinations reject.
Keep WebSocket messages working through protected connections
WebSocket connections through protected egress now preserve text and binary messages during connection setup, including on Bun. Disconnecting the client cancels a pending upstream connection. Connections that fill the early-message buffer while waiting for setup are closed.
Protect workspace files during cancellation
Cancelling during preparation can now stop pending workspace writes, edits, and directory changes, with permission checked again before the covered changes are made. Cancelled or timed-out CLI runs also lose Gateway tool access during process cleanup. Worker attachments copy within their allowed size without overwriting files from earlier turns. Cancelling before an attachment is published leaves no new destination file; attachments already published, including any replacements you later saved, stay in place. Managed worktrees also preserve supported files while rejecting source files replaced with symlinks.
Configure the approval reviewer
You can now set the approval reviewer’s reasoning and optional Fast mode independently of the main agent, globally or per agent. Leaving the options unset keeps provider defaults, and existing approval checks and human fallback remain in place. The controls apply to OpenClaw’s model-backed reviews, not native Codex Guardian.Reasoning choices can affect cost, waiting time, and review quality. Fast mode requests priority processing on supported OpenAI Responses and ChatGPT/OAuth routes and may cost more; other providers may ignore it. If you enable these options, remove the new thinking and fastMode keys before downgrading to a version that does not recognize them.
Use correctly owned FreeBSD credentials
The FreeBSD desktop now rejects Gateway token and password files owned by another user. If this affects your connection, correct the file ownership to match the account running the app or replace the credentials in Settings before reconnecting. Rejected files leave your saved settings intact.
Use Git through protected network connections
If you use protected egress, Git commands launched by the Gateway now receive the proxy’s trusted certificate bundle. This fixes the resulting HTTPS certificate error while keeping certificate verification enabled, with no new settings required.
Bind client actions to the selected account
Client developers can now add selected-account checks so their apps detect when the chosen account no longer matches the signed-in profile. Already accepted work keeps its original conversation and receipt through ordinary disconnects or later account selection changes. These checks are opt-in; other requests keep their existing behavior.If a client requires these checks, it must report when the Gateway does not support them. An account mismatch reported after an action starts does not mean the action was undone. Before retrying, check earlier acknowledgements or receipts and keep the original idempotency key, which identifies the request across retries.
Everyday terminal use gains image previews and clearer feedback, while managed worktrees can share source storage across more platforms. Background history loading helps OpenClaw stay responsive while opening large conversations.
See images in compatible terminal chats
Received and generated images now appear as static previews in Ghostty, iTerm2, and Kitty, including supported images in reopened conversations and tool cards. Terminal image previews show up to four images per message and keep the 24 most recent previews. Unsupported terminals retain readable text, and previews are off by default inside tmux and GNU Screen.
Keep terminal controls and output clear
The terminal shows your remembered conversation name while startup checks finish, then confirms it or falls back to the actual session. Ctrl+C hints no longer hide an ongoing response’s activity indicator. Local commands resolve relative working directories from the session workspace, keeping ~ literal and .. parent-relative.Bash completion stops suggesting options after --. If you use a cached completion script, refresh it with openclaw completion --shell bash --write-state and reload your shell.
Share source storage across managed worktrees
Managed worktrees can now share unchanged source-file storage on eligible Linux Btrfs, macOS APFS, and Windows ReFS or Dev Drive destinations, while keeping each checkout’s edits and setup independent. Sharing is selected automatically on supported destinations. Repeated APFS checkouts avoid the initial file-by-file cloning slowdown, and worktree removal saves recoverable tracked and untracked edits with less delay. Creation also checks space for the selected commit, while cleanup protects checkouts still being created, restored, or reused.The first source template and each checkout’s dependencies still need preparation. ReFS sharing can take longer than ordinary Git checkout; set worktreeAcceleration to false to opt out. Btrfs sharing requires the optional native package; unavailable or disabled native helpers use ordinary Git and its normal space checks. APFS uses ordinary Git when inherited permissions cannot be preserved or checked, and cancelling an already-started native clone waits for it to finish.Cancelling workspace cleanup on a worker node now stops deletions that have not started and leaves those items available for a later cleanup attempt. A deletion already underway finishes and cannot be undone.
Choose source profiles for managed worktrees
New managed worktrees can use repository-defined source profiles to check out selected source directories. Add --source-profile <name> to openclaw worktrees create, repeating it to combine profiles. Full source remains the default, existing or restored worktrees are left as they are, and dependency installation and builds remain separate.Source profiles use ordinary Git checkout. Enabling them can also make later full worktrees use Git instead of accelerated sharing, even after expanding the source selection, so allow extra disk space.
Recover managed worktree creation and cleanup
Managed worktree cleanup preserves unpublished work and retains checkouts whose branch changed or whose HEAD became detached. Use openclaw worktrees remove <id> --if-lossless to remove only eligible clean, published worktrees. Run-end cleanup uses the same non-force path.Large ignored dependency folders and untracked directory trees no longer cause the filename-buffer overflow that prevented eligible cleanup; local edits and untracked child files remain restorable. A directory replacing a deleted file in a merge conflict can also be saved and restored, though the conflict itself still needs resolution. Existing retention rules and protection for nested repositories remain in place.Ordinary removal still saves a recovery snapshot before forced checkout removal. --force permits snapshot loss and cannot be combined with --if-lossless. Interrupted deletion retains recovery data but may require manual reconciliation before retry or restore.
Keep goal instructions and budgets intact
Goals retain multiline instructions and meaningful spacing, so a carefully written objective reaches the agent intact. Goals can also be created without a token budget, and reconfirming completion keeps the original finish time.In the Control UI, choosing Goal with Tab, Enter, or a click opens the existing objective form, as does submitting /goal or an empty /goal start, /goal set, or /goal create command. Slashes and spacing in the objective stay literal. Empty objectives cannot be sent, and a rejected submission keeps your draft. Complete and management commands still work as text commands.
Use the expected automatic clock format
Automatic clock formatting now recognizes 24-hour locales that use non-Latin digits, including Persian, so current-time and status text no longer incorrectly switch to AM/PM. Explicit 12- or 24-hour settings and operating-system preferences still take precedence over locale detection.
Avoid repeated local processing
OpenClaw does less repeated work when preparing long conversations, showing progress, and running agents in parallel. It makes fewer temporary copies without changing the conversation content, and requests for recent history, usage, or selected agent results skip older details they do not need.
Inspect saved QA Lab results
QA Lab keeps repeated attempts available for inspection and downloads the log belonging to the selected result. Earlier failures remain visible after retries. Recognized file formats determine the preview, so a descriptive label containing a word such as “gif” no longer hides a log or misidentifies a JSON file.External tools that read only v2 QA evidence need upgrading for newly produced v3 files. OpenClaw’s bundled readers continue to accept historical v2 results.
Run more conversations at once
Installations using the default concurrency limit can run more independent conversations while others wait for model or tool responses. The default now allows four main agent runs per available CPU, with at least eight slots—32 on an eight-CPU host and 192 on a 48-CPU host. Each conversation still runs one turn at a time, and subagent and scheduled-job limits remain separate.More simultaneous turns can use more memory and put more pressure on providers. Existing agents.defaults.maxConcurrent settings still take precedence. Set a lower explicit limit for a constrained machine or resource-heavy work.
Keep the Gateway responsive during history loads
Opening large conversations or loading history in several clients leaves the Gateway more time to respond to controls and other requests. Saved-history preparation now runs in the background, with session and access checks before history is shown. If the background reader is busy, unavailable, or times out, you receive an error and can retry.The tradeoff is more memory use and potentially longer waits for history. The warm background worker added about 270 MiB in the reported four-CPU Linux test. First reads can be slower, including after the worker shuts down while idle, and separate requests can use more CPU. Even small history pages can occasionally take longer to load.Opening the branch list in a large saved conversation also uses a separate background worker, leaving the Gateway available for other requests. Incognito branch lists stay local. In a separate synthetic test, this worker added about 105 MiB of process memory and took about 0.42 seconds for its first request. On Node, cold conversation-list scans also move off the Gateway thread, with possible extra startup time and memory use.History pages with a byte limit and context preparation for large messages also do less unnecessary work. Small, empty, and full-page reads can still take longer.
Interrupted conversations and delegated tasks get more ways to finish from saved work, while explicit Stop requests remain cancelled.
Subagent results and recovery
Ordinary subagents can use completed tool results before pausing. When they resume and finish, the parent conversation can continue with their complete retained answers. Larger answers use more of the parent’s context, and results removed by retention fall back to a marked, shortened copy. Later parent turns can find retained child results still awaiting delivery or continuation. A child you explicitly stop stays cancelled. If the parent finishes its work but misses a required channel reply, the result stays blocked for explicit retry or dismissal instead of automatically repeating its tools. Check completed actions before retrying.Newly accepted native Codex child results can also support restart recovery of a still-owed parent channel reply without rerunning the child. This requires a recorded accepted completion and a supported outbound channel route. Control UI, route-less, remote-worker, and never-admitted completions are outside this recovery path. Update the Gateway and Codex plugin together, and finish pending recovery before downgrading.In OpenClaw’s built-in agent runtime, the system expert can now answer even when only one ordinary agent is allowed to run at a time. Cancelling the parent task can still leave queued expert work able to start. If a subagent was already paused before upgrading, send it a follow-up to resume it. Abandoned tasks cleared by maintenance follow the existing retention rules. Downgrading does not restore their earlier status or records already removed by retention. To return to an older binary, restore a verified pre-update backup into fresh state.
Interrupted conversations and late replies
After a restart, eligible unfinished conversations can continue from saved tool work without repeating your original message or discarding its results. Eligible tasks in the built-in runtime can also keep working when their tools have finished but the model times out, or when a known Responses output limit interrupts a tool call. Cancellation, pending approvals, unfinished tool work, and retry limits still apply. Messages arriving too late to join the current answer get their own follow-up reply. ACP background tasks that finish before cancellation takes effect keep their completed result and end time.When prompted, recover interrupted work before sending new input, and check uncertain tool outcomes before repeating an action. New messages can wait as follow-ups while recovery handles the earlier task. Acknowledged worker cleanup failures now block automatic model fallback from repeating completed actions. Cleanup does not undo earlier desktop input, so inspect the desktop and workspace before retrying.Recovery from an overfull conversation now leaves archived turns and reset markers in their original history instead of copying them into new entries. This prevents new duplication; it does not remove duplicates already stored.
Answer and correct an agent's questions
If you answer only part of an agent’s multi-part question, the chat now explains what needs correcting and keeps the question open. Send a complete answer using the question numbers or IDs. Authorized plain-text answers can reach the waiting run, save its tool result, and let it continue without waiting for the asking turn to finish. Partial answers are not saved as accepted answers.
Respect intentional conversational silence
An ordinary conversation can end quietly when the assistant deliberately chooses no text reply after a failed read, such as a rate-limited thread lookup. OpenClaw no longer adds a generic tool warning in that case. Unanswered requests, failed or unclassified changes, scheduled jobs, heartbeats, and aborted runs keep their failure reporting, and silence for an earlier message cannot hide a later failure.
Hosted tool calls and Tool Search
Tools running inside the Gateway now call it directly, removing redundant connections that could fail during parallel work. Permissions, approvals, cancellation, and message duplicate protection stay in place. Large tool results such as wiki lint reports also keep their useful summary when optional details exceed the output limits. Those details are marked as truncated, while the summary and report reference remain available.
Run and finish commands with clear results
Completed host commands now clean up their retained child processes before reporting completion, reducing process buildup during long-running sessions. This changes shell backgrounding. Children started with & stop when the root command finishes. For work that should continue across turns, use background: true with the long-running command as the root, then collect its result through process. Background command guidance explains the lifetime; sandbox lifetimes remain controlled by the sandbox backend.Linux Gateways running on Node use a small command-launch helper to avoid launching covered commands from the large Gateway process, including Git requests over its WebSocket connection. If the helper cannot start initially, that Gateway process keeps direct launching. Later helper loss fails affected commands without rerunning them. Queued launches can still outlast approval revocation, and a failed search launch can leave grep waiting. File-limit errors now retain their original diagnosis and allow later commands after resource pressure clears; the failed command is not retried automatically.
Busy Gateway responsiveness and diagnostics
The Gateway can handle network traffic between queued session writes instead of waiting for the entire backlog. When a connection stalls during setup, the error now identifies the target and suggests a status check, giving you a clearer place to start troubleshooting. A full request queue shows a plain busy message; wait briefly, then retry your action.Plugin authors using worker pools should handle overload errors from the new queue limits. Rejected work is not retried automatically; check that the original request is still authorized and within its deadline before retrying. These limits cover queued work and reported input sizes, not total process memory.
Bun worker connections and plugin setup
Bundled Canvas and Voice Call configuration updates work again on the affected Bun setup path. Bun workers also keep their Gateway connection options and handle failed output without triggering an extra error. Bun also gets fixes for sessions, provider connections, and streamed Discord requests. Skill edits use polling by default under Bun, while explicit CHOKIDAR_USEPOLLING settings still take precedence. A temporary database lock no longer blocks Gateway startup on the affected Bun 1.4.0 path.Some operations still require Node. The worker, provider, and Discord compatibility fixes were tested with custom Bun builds; stock Bun 1.4.2 lacks a required SQLite fix and still has Slack interoperability limits. They do not establish complete support for that stock runtime.
The 1,623 maintainer and internal changes cover development, testing, and release work. Open a topic below for its complete change list.
Maintain focused regression coverage
Regression tests have less repeated setup and more coverage of the code that runs in production, including resource ownership during queued conversation compaction.
Consolidate internal ownership and helpers
Shared helpers consolidate repeated implementation, including preparation and resource handoff for image, music, and video generation.
Keep types aligned with their contracts
Configuration authoring types reuse existing validation schemas, leaving fewer duplicate definitions for maintainers to keep in sync. Some field descriptions have moved from generated type hovers to the source schemas.
Keep CI plans within their resource limits
Precisely scoped test changes can keep their required execution settings without scheduling unrelated test groups. Measurements from those selected tests stay separate from full-suite timing history.
QA diagnostics and reporting
QA runtime reports keep skipped executions distinct from passing ones while preserving their existing acceptance rules. Maintainers can also compare clean built revisions with six opt-in Code Mode workloads. These require an OpenAI API key and explicit model selection, make paid calls, and assess task results separately from follow-up explanations.
Maintain release records and qualification inputs
Release maintenance covers package alignment, validation tooling, and historical records. Normal extended-stable publishing is now limited to the month immediately preceding the version on main.
Keep development builds compatible
Linux Crabbox setup keeps pnpm dependencies inside the workspace. Running setup again replaces only the two precisely recognized older dependency-link layouts, preserving external targets and unrelated links. Native Windows retains its existing junction layout.Managed Windows build and test commands preserve final output and report cleanup that cannot be confirmed. Temporary test state remains available when cleanup is unresolved.
Clarify contributor and maintenance guidance
Contributor guidance puts the problem and practical impact first in PR descriptions, keeping risks, required actions, and useful validation easy to find. For visible UI changes, before-and-after screenshots must render in both the originating chat and the PR unless the user explicitly waives a destination.PR cleanup stops when worktree ownership is ambiguous, orphaned, or incomplete, preserving paths and metadata for diagnosis. PR tooling also disables automatic maintenance during fetches to avoid unrelated metadata pruning.