Skip to main content

v2026.9.6

AI agents and tools can read these release notes as plain Markdown. OpenClaw 2026.9.6 brings clearer managed-update outcomes, recovery for unfinished work after restarts, and complete 30-day Usage reporting. A GitHub reader brings public discussions and diffs beside chat, while remote workspaces gain Files, Memory, and Skills and meeting notes update as capture continues. Optional Decision Models add TypeSafe Jev and local choices, alongside new chat-model support for Claude Opus 5.5, GPT-6 Sol and Luna, and Grok 4.7. Release scale: 2,614 pull requests, 178 direct commits, and 350 contributors.

Installation and Onboarding

Setup has clearer recovery paths when an installation cannot continue, and new custom agents keep the job you approved for them.
The Windows installer can continue after a failed Node package-manager attempt, trying the remaining options before downloading an official portable runtime into your user account. That portable recovery needs no administrator access, while setup still stops if it cannot validate a supported runtime. OpenClaw also recognizes supported JavaScript command-line launchers configured by their full path without requiring changes to Windows’ executable-extension settings. See the installer guide for setup options.
On FreeBSD, an unsupported source installation now stops before changing your existing installation and points you to the package installation route. Use a published npm version or compatible built .tgz package with the same installation prefix. If pkg or Ports manages OpenClaw, continue using that package manager. Source installation remains unsupported, and this change does not make FreeBSD a Tier 1 platform.
If Node explicitly denies permission to start worker threads, OpenClaw can check SQLite in the current process instead of incorrectly reporting that SQLite is unavailable. This helps setup and diagnostics in restricted environments while leaving permissions and the Gateway’s other worker requirements in place.
When Podman cannot create a sandbox because its host-side init helper is missing, the error now explains what to repair. Install catatonit or correct its configured path on the computer running the Podman engine, including inside Podman Machine when you use it. The Podman setup guide covers this requirement, which you must supply before retrying with the existing sandbox protections enabled.
If invalid configuration blocks setup, the error now directs you to run openclaw doctor --fix before retrying. Doctor applies supported repairs when you explicitly request them. Setup also stays responsive while saving recommendations and waits for progress to be saved before continuing, with storage failures still reported as errors.When OpenClaw automatically installs the fd or ripgrep search helpers, valid encoded downloads no longer fail because their transfer size differs from the downloaded archive. Installation can also find a readable tool inside the archive when an unrelated directory cannot be read. The existing 100 MiB limit on decoded archives and extraction controls remain in place.
A new custom agent created through the Control UI now keeps its approved purpose as saved instructions for later conversations. This applies when creating a custom agent in a local workspace. Existing instructions stay intact, and conflicting instructions prompt you to choose another workspace. Changing the proposed purpose requires fresh approval.Reopening New agent brings back the creation choices without discarding your Ask OpenClaw conversation, once pending questions, setup steps and approvals are finished. New agents also retain the display name you requested separately from their identifier, including when you choose a bundled role.
Production npm installs on macOS, Windows and Linux carry about 18 MiB less unused Bash parser material while keeping the same command-parsing behavior. This is a reduction in installed files, with no configuration change needed.Newly built Cloudflare template images also leave out an unused Litestream download archive while keeping the executable. Existing deployed images stay unchanged until you rebuild and deploy them.

Web UI

The Web UI now shows 30 days of usage across the full session report you can access, alongside improvements to everyday chat and its controls.
Use the command palette to start an independent task from text or a pasted screenshot while keeping your current conversation and draft in place. Press Cmd/Ctrl+K to open it and Cmd/Ctrl+Enter or New session to start the work, while ordinary Enter applies the current search instead of opening a stale result. Failed creation keeps images for another try, but closing the palette normally discards unsent images.You can also select up to ten people to mention when starting the task. Typing a name alone does not select a recipient, and a mention does not share the conversation or grant access.
Suggested tasks keep their full summaries and Start controls reachable in shorter windows, and launching one in a new session or worktree leaves your current conversation and draft selected. If the selected repository cannot start the task, you can correct it without retyping the prompt, then explicitly retry with a usable repository that has a commit.
New-session placement makes the cloud profile, operating system, machine size and starting branch easier to confirm, and submits the choices shown in the picker. Your prompt and attachments remain visible beside startup progress while the first message waits for the destination to become active. Open session returns to a created conversation without sending the prompt again. Configured size defaults still apply and existing instances are not resized. Administrators can also register an existing repository using an accessible absolute path with a valid Git HEAD. Interrupted Incognito prompts remain only in the current tab’s memory.A failed project lookup now keeps your saved choice and blocks starting until discovery recovers or you deliberately change the destination. New Session also remembers a supported Fast mode choice, including off, for the same agent and Gateway.
Leaving the worktree From choice untouched now starts from the fetched remote default branch, as does leaving Base branch empty when creating a worktree manually in Settings. An explicit or saved local branch keeps its meaning. Branch editing stays usable and an accepted start clears the custom name it consumed, so it does not accidentally name the next session. Rejected starts retain the name, and failed remote lookup retains the source-HEAD fallback. If name cleanup is unconfirmed, check Name before starting another session.Failed Git discovery also keeps a saved separate-worktree choice instead of silently switching to the current checkout. Starting waits for recovery or your explicit Current checkout choice.
Conversations can be archived or restored directly from the sidebar with Undo, and keyboard shortcuts open a New Session draft or archive the current eligible chat. Archiving keeps the conversation and its work, while group moves appear immediately and retain confirmed placement if the next refresh fails. New tabs keep the original draft in place and open with navigation expanded, and generated links retain the intended conversation. On desktop, right-click or Shift+F10 opens the full row menu, while touch keeps a menu button. If a group save is uncertain, refresh and check its placement before retrying.Incognito links now retain the exact conversation, provided you have administrator access and its memory-only session still exists. Reopen it from the sidebar to replace an older broken short link.
The sidebar keeps loaded Codex conversations available while paired computers refresh, identifies linked messaging conversations from their recorded details, and keeps grouped agent-created chats searchable and reopenable. More room goes to conversation names by removing redundant owner avatars, duplicate Home entries and Worktree or Checkout row labels, with repository details still available on hover. Session lists and previews also reuse unchanged information more often, reducing repeated preparation as activity arrives.Healthy session catalogs can also progress while another source is slow. Automatic list refreshes may wait for five idle seconds or briefly cool down after a slow read, while deliberate refreshes, navigation and reconnects bypass that delay.
Temporary child runs now belong in transcript activity and Tasks, leaving ordinary navigation for persistent conversations. Their parent conversation continues to show an activity ring during follow-up work, and the icon keeps its resting size when that ring starts. Use Tasks or transcript activity to inspect the work itself, since a failure tooltip is not a link to the child conversation.
Search can find authorized conversations beyond the currently loaded sidebar, with avatars, owner badges, highlighted matches and All, Sessions or Messages filters to help recognize the result. Results remain a bounded set of matches, and cold archived history must first be restored by opening its conversation. Within a chat, Escape closes focused transcript search and returns focus without clearing your draft or pending reply.
Settings → Search brings provider setup, routing information and real test queries into one place. People with read access can inspect which search route an agent and model would use, while administrators can configure a managed provider and test it against normal account limits and billing. These settings apply across agents, and a configured provider is not necessarily a working one. For native or external search, Test in chat opens an unsent draft rather than running a query. Paid Parallel can be detected from its API key, while Parallel Search Free requires an explicit selection.
Automatic naming can finish and update the sidebar after worktree setup stops waiting, while failed naming uses a neutral two-word name for a new session or worktree instead of copying the opening prompt. Setup can wait up to 30 seconds for a name, and a later title leaves an already-created branch unchanged. Manual names remain intact, and composing characters in the title editor no longer saves or discards a rename before composition ends.
Long chats load older history in fewer batches and keep navigation markers and reading position steadier as replies stream, the composer changes size or images finish loading. Expanded details and code-reading controls stay in place while the current part of a reply is still being written. Code controls now also survive a closing code fence and later paragraphs in that same live reply, though saved-history replacement or a source correction can still reset them. Code examples stay literal, reduced-motion preferences apply from startup, and opening a chat no longer slides the whole conversation into place. The initial history load stays small, while older-history batches can be larger.Returning to a chat restores your saved reading position once, then leaves scrolling under your control. Delayed history refreshes also preserve newer live replies and keep saved transcripts with the selected agent.
After rewinding and resending, the branch menu reveals the preserved conversations without a reload, and loaded history follows the branch you selected. Repeated branch listings and history reads also avoid some unnecessary transcript work. These are conversation branches, and returning to one does not undo earlier tool actions or file changes.
Dedicated compaction checkpoint links, history cards and branch or restore controls have been removed, along with sessions.compaction.list, sessions.compaction.branch and sessions.compaction.restore. Ordinary Fork, rewind, conversation history, compaction summaries and available token-savings reporting remain. There is no equivalent replacement for checkpoint restore, and the retirement does not require a data purge or configuration migration.
Reading older messages in a shared chat no longer gets interrupted by another person’s message or typing, including when an automatic scroll was pending. Deliberate reader navigation remains active, and the active reply stays visible through queued sends and saved history. A message from your own account in another browser also counts as remote activity. Sending from the current pane or selecting Latest resumes following the conversation, while typing produces fewer repeated presence updates.
Parallel conversations keep more of their individual working state. A Side chat that finishes loading late does not pull typing away from your current input, archiving a neighboring pane preserves your unsaved comments and draft, and each conversation retains its own Chat or Dashboard view. Archiving the conversation you are editing still dismisses its controls.You can keep editing a Side chat follow-up while its answer is pending, although sending still waits. Reloaded split panes also restore their own conversation’s side panels instead of inheriting another pane’s Files selection.
Chat notices, reply context, Goal previews and selected recipients sit above a reachable message field in a bounded footer, keeping controls usable in narrow or overlapping panes. Shared pickers continue to dismiss correctly as panes close, and moving between menu rows closes the previous submenu. Removing a selected recipient leaves the mention text in your message.Multiline drafts remain readable during keyboard navigation and selection, while affected typing layouts avoid repeated resizing and unnecessary redraws around selected mentions.
Long pasted excerpts appear as two-line cards in the composer and compact chips in sent messages, while newly attached Home context appears separately from the words you wrote. You can inspect the source, copy the original text or choose Show in text field directly on its card to restore it alongside your current draft without sending. The text sent to the model stays unchanged. Pasted-text previews cover up to 256 KiB and downloads retain the full content. The Home treatment applies to new messages with recorded context metadata, and attached context grants no additional permissions.
Files appear immediately in stable attachment slots with individual reading progress and removable errors, so you can see which file needs attention before sending. That progress measures the browser reading each file, and sending waits for active reads while excluding unreadable files. Replies retain failed attachment cards beside successful media, selected local workspace files can reach supported progress and final replies, and progress attachments survive the repaired cleanup race. Older failed deliveries may need a resend, and previously deleted files cannot be recovered by this fix.Eligible connections served from the same Gateway’s HTTPS origin can fetch inline transcript artifacts as raw file bytes, with fresh download permission on each click. The connection-bound links expire after five minutes and are not share links. Proxy operators must forward /api/artifacts/download/ under the configured UI mount, as described in the client guide; other connections and failed HTTP transfers retain the authenticated chat-connection path. Reconnecting or closing the preview prevents an outdated transfer from saving.
Browse the images attached to one message with buttons, arrow keys or swipes without closing the viewer. Sharper previews can open while originals load, then upgrade in place without resetting zoom, and a failed original leaves the preview visible. The gallery stays within one message and covers raster images, with SVG handled separately. Protected images still require Allow.
Attachments marked as voice notes now play inside chat with compact play, seek, time and mute controls and a waveform measured from the audio, without file headers or opening a side panel. Ordinary audio files keep their metadata and expansion controls. If a voice note cannot preview, its available download opens separately so the conversation stays in place.
Self-contained HTML attachments can fill the available height beside chat, making larger reports and interactive pages easier to inspect. Same-origin UTF-8 HTML previews now support up to 2 MiB, while text, Markdown and workspace reading or editing retain their 256 KiB limits. Cross-origin HTML remains download-only and the preview’s sandbox permissions are unchanged.Authored section links now scroll within the displayed document, including strict previews, without losing form values. Links created later by scripts are outside this change.
Explicit chat file links open the intended reader, including CSV files and authored Markdown links with spaces, emoji or punctuation in their names. Website paths keep their hostname instead of becoming local-file buttons, and local directories that resemble hostnames need an explicit path such as ./. Background link renewal preserves reader focus and controls, while Escape from any in-file search control returns focus to its search button.Agent Files also waits for file contents to load before allowing edits or saves, while retaining loaded files and unsaved drafts during refresh.
Use /export or /export-session without a path to download conversation Markdown from the browser. The guidance now matches that workflow, and an invalid path or a late export completion preserves your current draft and attachments. HTML and workspace exports in other clients keep their separate behavior.
Structured assistant answers can be explored in expandable Tree and literal Raw views, with copying that preserves the original source and expansion choices that stay in place. Complete JSON objects and arrays use the inspector, while unfinished, invalid or oversized content keeps a readable fallback. Your own code fences and passive previews remain ordinary code.
Pending comments on selected passages can be removed individually while the remaining preview stays open, or cleared together with focus returning to the composer. Remove all comments cannot be undone and no longer shows an Undo notification. Your message draft, ordinary files, already-sent comments and comments in other conversations stay intact, and reopened sent-comment previews remain visible after an interrupted hide animation.
Agent questions keep entered answers and selected options while you move between them, retain the original wording after completion, and stay with the conversation they came from. Optional questions remain reachable above the composer or in a minimized strip, and unedited questions can move to history after later successful work while remaining reopenable. Archival supplies no answer or permission, secret answers remain masked, and blocking questions retain their separate Skip action. Ordinary and Other answers now support multiple lines, with Enter adding a line and Cmd/Ctrl+Enter submitting. Unfinished optional answers can recover after reload, reconnect or switching conversations in the same browser and authenticated Gateway identity, within a seven-day expiry and shared 20-record limit. Incognito and deletion retire saved data, and storage or conflicting-tab problems show a warning.Dismiss postpones an optional question without answering, approving or stopping work, with immediate Undo or later Answer restoring unfinished input. Submitted answers show queued, sending, failed, uncertain or confirmed status, with Retry answer retaining the original answer and Discard reopening its draft. Saved history confirms delivery, so a recovered draft or a disappearing queue entry is not confirmation that an answer arrived.
Task-progress cards stay steadier when you send a message, make overflowing checklists easier to notice and keep keyboard focus visible. Refresh task progress asks for a current status update without adding a chat message, retains the previous card while waiting and confirms an update only when a newer saved version arrives. The refresh does not resume work or answer pending questions. You can also hide the cards as a browser-local display preference without stopping the underlying task. See progress-card refresh for its controls.On mobile, progress stays collapsed by default across new messages and completion unless you open it. Completed work durations include the final model request when matching timing is available, and omit missing or mismatched timing instead of guessing.
Open a background task or inline subagent activity to inspect its status and transcript inside Tasks, then use Back to tasks to return to the list. Review keeps its diff and Files keeps its selection, while reload can restore the selected task or show that it is unavailable. Compact activity summaries retain expandable details, and completed or canceled tasks update their labels correctly. Operation counts include repeated attempts and do not mean distinct files or successful results.
Running, queued and waiting subagents keep a stable order in live chat activity. Finished, failed, canceled and timed-out runs leave that list when their final state arrives, making all five slots available for ongoing work. Their results, delivery details and final edit statistics remain in Tasks history and details, where expanded results remain readable and accessible. Completed native subagents also publish their final Tasks status without requiring a page reload.
If Pause, Resume, Clear or editing a Goal returns an uncertain result, Check outcome lets you check the original action without repeating completed work, even after reconnecting or reloading a normal chat. Recovery is explicit and requires browser tab storage for normal chats, while Incognito recovery remains in memory. Saved requests expire after 24 hours, after which Review current goal refreshes the current state before your next decision. The Goal controls guide explains the recovery flow.Goals now pause after terminal errors or timeouts, retaining their objective and usage with a frozen timer and a readable pause reason. Resume is deliberate, and an ordinary message does not restart a failed paused Goal. Starting or resuming a Goal still requires the built-in runtime.
Available Right Now includes tools bound to the current conversation and refreshes after a session reset, so the inventory better reflects the tools that conversation can use. Opening Tools also avoids refreshing the entire model catalog unnecessarily. Inspecting this list does not add tools or grant permission to run them.
Explicitly linked GitHub accounts can keep one person’s avatar, preferences and mention Inbox, and people search supports full names and verified handles. Selected mentions show avatars and open full person cards using information you are allowed to see, while assignment and sharing pickers remain searchable and current. Typing or pasting a name alone does not notify someone or grant membership. Before downgrading, keep a backup because older writers can discard secondary account links, and upgrading again will not restore them without explicitly relinking.New visible child conversations can inherit the human owner when the verified requester matches the parent’s human owner. Other cases retain the agent fallback, and existing conversations are not reassigned.
An explicit mention can bring an accessible conversation into Involving me without requiring you to reply first. Personal Hide and Show controls follow your profile across browsers and restarts, and a fresh mention can bring a hidden conversation back. These controls appear when more than one identity is available and remain separate from Inbox dismissal, shared membership and archive state. Older conversations are not scanned for missed mentions. See finding sessions by owner.
Inbox snoozes stay separate for each account and Gateway in a shared browser, and Dismiss or Dismiss all shown makes the scope of clearing ordinary notifications explicit. Failed or uncertain sends now appear in Inbox → System, with conversation identity and Review opening their recovery controls, including offline. Ordinary queued messages stay in chat, and account or connection displays no longer show Outbox counts. Review does not resend or discard a message, recovery entries cannot be dismissed like ordinary notifications, and an uncertain message may already have arrived. These recovery entries belong to the local browser tab and Gateway, without per-person or cross-device isolation. Older snoozes without a known owner may let an alert reappear once.
Forget this browser in Settings → Connections → Gateway → Browser resets the current Gateway’s browser sign-in without clearing unrelated preferences or other Gateways’ sign-ins. It signs out the current tab and may require signing in or approval again, but does not revoke server-side devices or start a stopped Gateway. During ordinary reconnects, chat stays usable while its session list loads, with clearer account identity and connection status. Send problems are available from Inbox → System.An approved browser can also finish reconnecting when pairing approval overlaps its handshake, while current identity and permission checks still apply. Disconnects without a supplied reason explain whether reconnection is automatic or needs a retry.
Failed or timed-out chats can show their saved error and Copy error even when the live notification was missed, while temporary history-index rebuilding returns a retryable error. Failed pending messages can be discarded locally and stay removed after reload, and queued follow-ups can proceed once completion of their exact run is confirmed. Discarding does not undo accepted work or history. An outdated guarded Stop request also leaves a replacement conversation and its newer queued work alone.Late events and a failed steering follow-up now preserve the current reply, draft and Stop target. A direct follow-up can pass older explicitly queued input without losing it, while explicit Queue and Goal ordering remain in place.
Ask an agent to discover, choose or create a personal theme and save it to your authenticated profile for use across signed-in browsers. Appearance uses the same catalog, including enabled plugin themes, and connected browsers update as choices change. This requires an updated UI and Gateway together, while older tweakcn imports remain browser-local. If a selected theme becomes unavailable, Claw renders temporarily and the selection is retained for its return.Plugin themes can also package bounded, self-contained SVG hats and composer visitors, while personal themes use the built-in decoration choices. The existing Lobster visits preference still controls visitors.
Choosing a different theme now applies its default fonts and full palette, and eleven built-in themes gain locally bundled light and dark backgrounds. Existing preferences survive the upgrade and you can customize a theme after selecting it. Custom palettes use neutral artwork, increased contrast and forced colors hide artwork, and reduced transparency makes the composer opaque. Before downgrading to a Gateway that accepts only hex accents, remove ui.prefs.accent=theme or replace it with a hex color. Appearance settings covers these choices.Personal and plugin themes can opt into neutral branding, their own waiting phrases and supported avatar hats or visitors. Omitted options retain the usual appearance, and these additions do not change built-in themes by default.
An unchanged dashboard restores its selected, closed and focused panel arrangement after reload, and moving a loaded widget to an unopened tab preserves unsaved input and counters. The layout menu shows when the current view matches its shared default, while a lone full-width widget gets more unobstructed space with controls in the task menu. Explicit presentation changes still take precedence, and preserving a widget during a move does not make arbitrary widget state durable across reloads or deletion.Use current view as default now saves both the opening view and split or fullscreen presentation, while personal layouts retain priority and existing viewers are not rearranged. Identical previously approved widgets can also avoid another model review for the same agent, name, content and declarations, subject to current permissions. This temporary reuse excludes new or changed widgets, MCP apps and Incognito sessions; see dashboards.
Activity recaps and people lists avoid preparing information they do not need, reducing repeated work during refreshes. Session assessments and recaps also recover when an implicit model choice selects unavailable Codex, while an explicitly chosen unavailable Codex route still reports failure. These utility requests remain tool-free.
Activity shows compact, uncropped HTTPS image previews that can expand without taking over the list, and plugin README and agent-file previews can load HTTPS images automatically. Those images are fetched directly by your browser, so their hosts receive its network address. HTTP images remain blocked, and Markdown attachments and Workshop previews retain click-to-open behavior.
Usage opens with the last 30 calendar days, with history and totals covering the full session report you’re allowed to see, even beyond the visible list. Started by helps you compare tokens, estimated costs and session counts by who started the work. Each whole session is attributed to its recorded creator, with older unknown creators shown as Unattributed.Costs are estimates rather than provider bills, and the page makes loading or incomplete totals explicit. Session CSV exports and session, text or hour filters use the loaded rows, with exports respecting your selections and filters.
The System busyness panel separates host and Gateway CPU readings, uses clearer labels and can be moved with a mouse, touch or keyboard, with its position remembered in browser storage. Gateway 100% means one CPU, while host 100% represents the machine’s total capacity, and child or remote processes are excluded. High ping receives a visible warning color, and unavailable counters stay absent rather than implying a measurement.Vitals continue updating when another tray request is slow. Hidden tabs pause polling, and a reset leaves samples absent until a fresh measurement arrives.
Systems offers a compact machine list with sorting and online or offline filters, plus recent load, memory and volume free-space graphs for the selected machine. History accumulates while Systems is open and resets after reconnects or gaps, so it is a recent view rather than a stored monitoring history. Connected nodes report their home volume, and load should not be read as CPU utilization.
Mobile web layouts keep message margins, galleries, session controls and sidebar tools within reach, with search available from the navigation drawer and placement choices stacked for smaller screens. On recognized iPhone and iPad Safari browsers, a single Attach entry opens the existing file chooser, with camera and source prompts still controlled by the operating system.
Twenty existing interface languages receive updated wording for setup, chat status, recovery, themes, usage, models and desktop guidance. These updates bring more current controls and explanations into those languages without introducing new language choices or changing the behavior of the features they describe.
Chat and sidebar updates avoid some layout stalls, and opening a conversation downloads less information for Inbox alerts. The automation editor still loads the complete job settings when you open it.Logs, Debug, Devices and channel-pairing views now pause selected background polling while hidden and refresh when you return. Explicit refresh remains available, and requests already underway are not canceled.

Updates and Maintenance

Managed updates can finish with recoverable warnings and clear repair guidance, while restart recovery helps unfinished conversations continue from saved progress. Make and verify a backup before updating, because rolling back the application does not restore your data.
Packaged headless nodes on stable or beta releases now update automatically when their work and cleanup are idle, keeping their pairing, settings and launch options. They check hourly after connecting, leave at least 12 hours between activations, and fall back to the previous runtime if the replacement cannot start. Busy work and plugins without explicit idle reporting can defer activation indefinitely.You can turn this off with nodeHost.autoUpdate.enabled: false, update.checkOnStart: false, or OPENCLAW_NO_AUTO_UPDATE=1; the Gateway’s automatic-update switch is separate. Native app nodes, private workers, source installs and extended-stable pins keep their existing update paths. Releases needing database migration or repair still require openclaw update, and older co-located Gateways need one normal upgrade first. See headless node updates.
Operator-created scheduled agent jobs can request an ordinary Gateway update without inventing a chat owner identity. Jobs originating from external requesters do not gain that exception, and notification destinations do not become the authorizing user. Existing update restrictions still apply. If scheduled authority ends while update preparation is underway, inspect the update status; that late revocation may not stop the prepared update from proceeding. See updating.
In larger installations, prepared agents can take requests while the rest of the fleet finishes starting, with pending agents shown as still preparing. Startup and session-source reads also avoid repeated checks and unnecessary loading of saved prompts. A ready Gateway can therefore have optional agents that are not yet available; readiness does not mean the whole fleet has finished, but the required default and system agents must have usable databases.
Large-fleet updates reuse configuration and plugin inspections and prioritize repairs needed to start the replacement. Optional checks that are deferred have not passed yet, so run openclaw doctor --fix after activation to finish them. Older installed updaters keep their existing time limits until they have been replaced.
Backups can finish when ordinary files disappear during capture, preserving the surviving files and reporting omitted paths. Completed database copies also return their result without waiting for unrelated activity, while archive creation and verification avoid repeated copying and searches. Required roots, unsafe file substitutions and capture or I/O failures still stop the backup, so review omissions before relying on an archive.Backups also recognize duplicate registrations of the same database and preserve committed journal data across supported hardlink aliases. If a core database has hardlinks, include every alias in the backup’s admitted resources and stop writers when directed; conflicting owners, ambiguous journals or capture-time changes still prevent an archive. Maintaining a private snapshot does not grant permission to maintain its live source.
Saved agent history now uses selective lossless compression, and memory vectors keep their full precision in a more compact binary form. Search maintenance can find the rows belonging to a conversation without scanning unrelated history. Existing database files may not immediately shrink, and reading or appending full conversation bodies can take more CPU. Valid vector conversion happens locally without an embedding-provider call.Use the supported update or Doctor migration path with all writers stopped, a verified backup that includes pending database journal data, and space for temporary tables, journals and backups. The final formats are agent schema 23 and shared-state schema 18; older builds refuse converted stores, so downgrading requires the matching older build and pre-upgrade backup in a separate state directory, not changing version markers. Direct database readers need supported accessors or exports, and compressed rows require a compatible decoder. See database versioning.
Updates no longer reject a retained launcher backup solely because the platform cannot preserve explicitly unsupported symlink metadata. Link targets, entry types and regular-file contents still have to match, and genuine mismatches leave the failed backup available for inspection. This belongs to the installed updater, so an older updater blocked before activation may need the documented manual first upgrade.
Doctor preserves explicitly chosen workspace locations, leaves comments and formatting alone when no repair is needed, and keeps session-store ownership through unrelated settings changes. It can offer confirmed recovery of a removed owner setting from an eligible root-only, same-store backup, while conflicting tool lists are repaired only when permissions can be preserved. Ambiguous permission changes remain your decision, and a refused configuration write stops dependent service repair.Successive repairs also preserve authored environment references, literal values and included-file ownership, checking for intervening edits before each write. A later refusal keeps earlier committed repairs and backups, and removing redundant local OAuth copies preserves the chosen preferred and fallback account order.
Historical conversation titles, ACP metadata, transcript markers, worktree paths and task identifiers are repaired through Doctor maintenance, keeping ordinary startup and reads from rewriting that history. openclaw update already runs the required repair pass. Supported container image upgrades now invoke Doctor maintenance automatically before serving. Direct binary replacements, state touched by older writers, or a specific remaining historical repair still need the supported Doctor preparation; when offline repair is required, stop writers and run openclaw doctor --fix against the same state and configuration before restarting.Successful imports can continue past archive-only or scratch-cleanup warnings, while changed originals, incomplete captured data and storage or ownership failures still need attention. Ambiguous task identifiers remain unchanged rather than risking a result reaching the wrong task; title repair also retains a limitation when several agents share one physical store.Intentionally retained stores from deleted agents no longer block unrelated active-agent repairs, and valid ACP ownership repairs can finish while retired workers settle. Deleted agents stay deleted, with unverified or changed history still protected.
If an old session index disappeared or a restored file changed identity after history was imported, openclaw doctor --session-sqlite recover can repair the import records using verified retained content. Current conversation settings and deletions remain authoritative, and changed or unverifiable files stay protected for inspection. Follow the SQLite recovery guidance and preserve files named in conflicts; a running Gateway does not by itself mean those files are ready for cleanup.With the Gateway stopped, Doctor can settle verified leftover imported transcripts, append an eligible missing suffix and archive the original bytes. Conflicting or malformed files remain protected, and recovery through a fixed custom store for a nondefault agent still has a path-selection limitation. New reports distinguish current findings from historical errors; a retained archive warning alone needs no repair when the expected conversations are present.
Doctor’s final results now retain the original reason for a refused migration, identify plugins that failed to load, and give useful disk-space guidance. Completed checks survive cleanup-only delays instead of becoming false update failures, while unfinished checks still report a timeout. Standalone noninteractive Doctor exits with an error for plugin-load failures; updater-invoked Doctor can retain those findings as warnings when the update can otherwise proceed. See how updates run for the remaining older-updater limits.Private update validation can also defer named optional inspections and print the commands to run after activation. Those checks have not passed, required failures still block, and this does not extend an older updater’s overall deadline.
After a manual core upgrade, openclaw doctor --fix can bring eligible official npm plugins back into line while respecting newer pins and nondefault tags. Repair guidance now distinguishes an attainable release from registry lag, reports unreadable required manifests, and avoids sending you around a circular migration fix. Third-party plugins stay with their own maintainers, unavailable packages remain warnings, and missing required manifests can still make post-upgrade checks fail.Doctor can reconnect existing settings after an interrupted installation of a trusted, declared replacement plugin ID, while existing canonical settings and explicit disables take precedence. Candidate inspection also accepts valid import.meta syntax and names remaining per-plugin parse warnings without treating a malformed plugin as healthy.
Updates preserve local plugin overrides and the npm copies they shadow, with guidance about which copy is active. Check that your override supports the new release, or deliberately remove it to return to the managed copy. Preserving a local plugin does not grant it trust, and channels blocked by trust policy stop retrying until that policy is resolved. The plugin sync guidance explains the update behavior.
Plugin and hook updates can finish longer work when no work deadline was supplied, while explicitly short deadlines are honored. The same distinction carries through supported Doctor, plugin-convergence and finalization paths, without removing separate metadata, readiness, cleanup or enclosing updater limits. Git plugin clone and checkout still have a cancellation gap when running without a deadline, so this is not a promise that every stalled update can be canceled immediately.
Long package updates retain exclusive control until their work has settled, and cancellation waits for cleanup before another update or repair can proceed. If cleanup cannot be confirmed, OpenClaw keeps recovery files and may leave the Gateway stopped. Inspect openclaw update status before retrying, and do not delete a lock merely because it is old or its parent process has exited.
Managed restarts verify the serving Gateway and give admitted agent, subagent and scheduled work time to finish before storage and helpers close. Unknown activity no longer counts as idle. Forced restarts close new admissions immediately and normally allow up to five minutes for admitted work, capped by the service’s remaining shutdown allowance; work still running at the deadline is canceled. An explicit forced wait of zero is immediate, while ordinary --wait 0 remains unbounded except for native service limits. These Unix recovery changes require the updated launcher. Recognized stale Linux shutdown policy can now be repaired during eligible updates or Doctor maintenance; custom definitions may still need same-profile openclaw gateway install --force to pick up KillMode=mixed. See restart recovery.Already-pending authorized answers and approvals can complete during graceful draining, and eligible replacement subagents can save their results. New work stays blocked, and exhausted budgets are not renewed. Older forced callers that supply no budget retain at most 45 seconds of draining within their 60-second replacement window.An update can now get past a stuck Gateway that refuses connections because its installation has already been replaced. OpenClaw warns before stopping it, and active tasks may be interrupted. Other failures to inspect active work still follow the usual restart protections.
You can return to unfinished conversations after a restart with their saved history, progress and tool results, plus a restart notice. The agent leading the conversation decides how to continue interrupted subagents instead of automatically relaunching them, checking that earlier work stopped and whether an action already took effect before repeating or replacing it. Stopped conversations stay stopped, and continuation still depends on current permissions and recovery checks. See what survives a restart.
Restart, update and diagnostic checks distinguish a Gateway that is still making startup progress from one that has failed, and local health checks recognize serving wildcard listeners on macOS. At the restart wait limit, exit code 2 means still starting, not healthy; health and channels JSON may likewise exit 0 with status=starting. Check openclaw gateway status --deep and inspect again before treating the service as ready. Existing wait budgets remain, and an older updater already running cannot inherit the new checks.
On supported Node installations on macOS and Linux, SIGUSR1 now opens the debugger without restarting the Gateway. Change scripts that used it for restarts to SIGUSR2, or use openclaw gateway restart, which retains handling for verified older running Gateways. The restart and supervision guide explains the signal change.
With live configuration reload enabled, more settings apply without restarting the Gateway, including Cloud Worker profiles, meeting capture, Desktop connections, Browser control and access policy. Successful overlapping settings and secrets reloads also avoid an unnecessary recovery restart. Affected services or clients may reconnect, existing workers keep their original provisioning settings, and newly enabled auditing does not fill historical gaps. Listener address or port, effective authentication mode and TLS topology still require a restart.
Eligible same-version clean restarts reuse completed database verification, and startup loads fewer unused dependencies. Memory, document and Codex workers also start with less overhead, while concurrent Windows UI preparation can reuse fully verified assets. Upgrades, unclean shutdowns, replaced files and migrations still require full checks; damage within the same file may be found after readiness, so a quick restart is not a fresh integrity certificate.
Updates and Doctor can identify eligible managed Gateways pointing at a different installation. Eligible updates repair recognized stale service settings through a backed-up transaction, and standalone openclaw doctor --fix now uses that same repair on writable packaged installations. Supported custom values are preserved while unknown edits stay available for review. Credential writes and unrelated command changes still need confirmation, and unverified recovery remains pending. Supported Node installation changes may trigger a noninteractive installation of a private compatible Node runtime without changing system Node. Already-stopped services remain stopped, externally managed services keep their owner, and --no-restart does not rebind a service. Windows and some custom overrides retain the service-root fallback described in update execution.Doctor and update repairs can now proceed for a loaded Linux user service even when system-wide ownership checks are unavailable. OpenClaw still verifies that your account can change the service, and blocks the repair if ownership conflicts or permissions cannot be confirmed.
Mac service commands recognize native XML and binary definitions, preserve original LaunchAgent bytes and permissions during supported rollback, and verify that the service has unloaded before reporting a completed stop. Run maintenance from the service owner’s logged-in session and use openclaw gateway status --deep to inspect it; a disabled but still-loaded service must be unloaded before runtime replacement. Affected older update helpers may need their first upgrade from an independent Terminal. Service inspection from an inaccessible working directory remains a known limitation.Service repair retains a supported recorded Node path unless an explicit choice overrides it. If a Mac wrapper reports malformed environment input, preserve the service definition and private environment, repair from the same owning account and profile, then verify status and health.
Windows updates and snapshots retain exact directory identity, and managed Gateway shutdown keeps track of the verified process through its handoff. When native Windows Job support is available, cleanup can also stop and verify owned descendants after their parent exits. If that cleanup cannot be certified, locks and temporary files remain for recovery; foreign or reused processes are still rejected.The updated Windows updater reports backups retained because a loaded native addon prevents deletion without repeatedly waiting on that locked file. An already-running older updater keeps its previous cleanup behavior; genuinely critical removal and rollback failures still surface.
Source-checkout updates handle larger Git packs and shallow partial repositories, show installed and target revisions, and preserve local edits when checking retained builds for rollback. Older installed updaters may still need missing Git objects fetched or a manual first upgrade, and staged packs need disk space. Doctor also gives selective recovery advice for source self-links without rewriting unrelated dependency edits.The source-server update script stops the Gateway before clean builds and restores generated output after ordinary build failures. Custom automatic service commands need paired, nonblank stop and restart settings; an exactly empty restart setting keeps manual lifecycle control. Recovery covers generated output only, and retained nested build work remains a limitation on automatic rollback and restart.Git updates also check destination disk capacity before stopping the Gateway and avoid letting an unrelated unavailable remote block the selected update source. Stable and beta-fallback Git updates skip extended-stable tags, preserving the selected release line; older installed updaters retain their first-upgrade limits.
Extended-stable releases numbered .33 and later can now come from either of the two preceding completed months, giving eligible release lines a longer maintenance window. A line leaves that window when it becomes the third preceding month. Eligibility does not guarantee a published release or continued support, and extended-stable updates remain a package-installation route. See release channels.
Homebrew installations now receive the correct formula upgrade guidance. Back up and stop the Gateway, run brew upgrade openclaw-cli, run openclaw doctor --fix, then restart. New or refreshed services use Homebrew’s stable formula path; an existing service pointing into an old version directory may need same-profile openclaw gateway install --force from the upgraded CLI. OpenClaw does not run the Homebrew upgrade for you.
If an external supervisor owns your installation, the update screen explains that you need to use that server or deployment’s update workflow. The refusal leaves packages and the Gateway untouched and removes irrelevant repair suggestions. If a later status read fails, Check status remains available without starting another update.
A Gateway running in a terminal now hands supported updates to a fresh process, avoiding missing-module failures after its runtime files are replaced. Candidate validation happens while it serves, followed by a brief activation interruption; Stop waits for owned update work and leaves it stopped. OPENCLAW_NO_RESPAWN refuses before changes and gives manual instructions.Use the coordinated openclaw update path when possible. A Gateway already running the new detection code can also notice manual package replacement and drain toward managed restart or foreground relaunch with openclaw gateway run; an old running binary cannot gain that behavior from replacement files alone. If Stop remains unconfirmed, inspect the updater and retry Ctrl+C in the original terminal or SIGTERM to the original process, as described in update execution.Update maintenance can wait for the same exiting foreground process to release its state, without signaling or restarting that process. A foreground first upgrade from the published 2026.9.5 updater still needs stop, update and start; if files were already partly replaced, stop the old process and complete verified repair from the new installation while retaining state and backups.
Supported older-updater handoffs can complete offline session repairs and verify the replacement Gateway, including supported Linux/npm upgrades from 2026.9.2. Missing inherited update history or backup coverage still stops maintenance, and backups an older updater already removed cannot be recreated. After a committed package change, recovery may require a compatible installed build, same-state openclaw doctor --fix, then openclaw gateway start. Keep a verified backup because package-only rollback can be unsafe after migration; rollback and recovery explains the boundary.Current finalization can keep database work in the compatible newly installed runtime after shared-state migration. That fix must already be in the installed updater and cannot patch an older driver that is already running; the narrower older-version handoff paths above remain separate. Code-only rollback after migration remains unsafe.During supported non-Windows upgrades, OpenClaw can stop a managed Gateway for Doctor repairs and bring that same service back, even if a later check fails. When the update caused the stop, it may restore the service despite --no-restart and explain the exception; a service you had already stopped stays stopped. Repairs must be enabled, and the older updater must have handed control to the new version.
Supported container image upgrades now run Doctor’s retained-state migrations automatically before serving traffic, including on qualifying FUSE volumes. A refused default or system agent prevents a healthy readiness response, while an optional refused agent can remain isolated. Use /readyz when incoming traffic needs usable agents, and retain verified matching backups for rollback.Unsafe required state exits with code 78 and a repair reason. FUSE recovery needs same-directory hardlinks and directory synchronization; if the filesystem cannot provide them, expose the same retained data through its native backing path before retrying. Stop writers and run same-state offline openclaw doctor --fix when instructed or when a specific historical repair remains; a separate offline command is no longer required for every supported image swap.
Packaged installs can restore a missing native filesystem addon from its exact declared prebuilt package after optional-dependency fallback. Healthy installations avoid a download, explicit native-off settings stay off, and source checkouts or existing broken addons are left untouched. Unsupported or offline recovery reports a warning instead of promising native support.
Restored or repaired managed worktrees remain visible when an older missing-path check finishes, and cleanup can proceed while the Gateway writes its database. Creation also avoids walking unrelated ignored dependency folders, while failed preparation preserves changed worktrees and committed reset actions. Already-removed records are not reconstructed, and historical repairs may still need Doctor.Cleanup now distinguishes completed, deferred and partial results and explains why a worktree was retained. Partial CLI JSON results include details and exit with an error, so automation should not treat a reported deletion count as proof that all requested cleanup finished.
Advanced operators can archive a supported detached managed worktree without losing partially staged edits, using openclaw worktrees remove <id> --exact-state <file> with a request matching its observed state, then openclaw worktrees restore <id> to recover it. This is an explicit archival route, separate from ordinary force removal. The original checkout is retained for 30 days, so its disk space is not immediately reclaimed.Exact-state restoration requires a supporting runtime, a full non-sparse checkout, Git file refs and a supported index. Restoration normally returns the retained checkout, including later file writes; if only the snapshot survives, recovery covers eligible files and exact staging rather than a complete filesystem image or unrelated ignored caches.
OpenClaw reclaims eligible abandoned managed plugin copies after an ownership check and a one-hour grace period, while session cleanup avoids repeatedly scanning data it cannot reclaim. Active and protected history remains protected, and openclaw sessions cleanup --enforce still requests immediate cleanup. Committed session resets finish their remaining actions even if later cleanup fails, with the original error kept visible.Claw removal keeps user files when a scan cannot finish, and failed backups or snapshots can reclaim verified disposable temporary files even on a full disk. Doctor reports recognized abandoned backup scratch and doctor --fix attempts cleanup, preserving live, unknown and recovery data. A Windows rename limitation remains, so this does not guarantee automatic reclamation on every platform.
More maintenance, snapshot and shared-state database work runs in background workers, reducing work that competes with messages and status requests. Catalog refreshes avoid redundant copies, unused queued snapshots can be canceled, and update rehearsals can capture consistent individual databases while other processes write. Retention rules and uncertain or active owners remain protected; these individual copies do not create an atomic rollback across every database.When a database checkpoint cannot finish, disk-pressure cleanup now defers further archive and history pruning until a completed checkpoint is observed. Increasing the budget or waiting out a timer does not clear that protection, and deletions already committed stay committed. Diagnostics help investigate the blocker without claiming that every database lock or growing journal has been fixed.
Managed updates can finish with recoverable plugin warnings and keep a verified new Gateway running while remaining maintenance waits. Results distinguish a healthy requested version from a restored previous version and show which repairs are still pending. Retaining the updater also takes less copying on filesystems with hard-link support, although some mixed link/copy layouts can still block that step.For deferred maintenance, stop the Gateway through its service owner, run openclaw update repair, then start it through the same owner. Required database repairs, invalid settings, lost permission or a repair process that may still be writing prevent completion; a warning does not mean every check passed.
Saved update reports retain redacted failure causes, identify the operation that failed and show recovery paths and observed rollback results. They also distinguish a completed check with slow process exit from a check that never finished, and avoid warning about rollback damage when preparation changed nothing. These reports help explain the failure rather than repair it, and older discarded details cannot be reconstructed. Review a report before submitting it.New reports explain when another OpenClaw process is using the same state, distinguish invalid configuration from a validator that could not run, and preserve sanitized npm causes with relevant disk-space, permission or missing-version guidance. These capture improvements apply to runs using the updated updater; they cannot add details to an older run.When npm selects a different installation, reports now show sanitized details of its destination and the running installation. Follow the destination troubleshooting guidance to correct the owning account or npm prefix before retrying; the mismatch is not automatically repaired and another installation cannot simply be overwritten. An older updater that refuses before staging cannot load these new diagnostics.
Updates, verification and rollback no longer require model credentials. Optional model-powered repair starts through triage only after a failed update has settled and released control, using normal shared or OAuth authentication without changing the recorded update outcome. Supported assistance recognizes eligible older and hybrid Linux cgroup layouts, rechecking that it still belongs to the right service. Triage also explains when an agent CLI is missing from PATH and offers a saved debugging prompt when available. Assistance does not itself prove recovery or authorize a restart, and PATH changes remain yours to make.
Diagnostic views retain complete structured Gateway logs, identify failed storage inspections and show background-worker memory use, including Prometheus metrics grouped by worker script. Memory-growth alerts distinguish sustained growth from recurring allocation peaks, while absolute pressure checks remain immediate. Samples can be partial, and these diagnostics identify where to investigate rather than fix a memory leak.Routine model and voice logs are quieter, with detail available at debug level while errors, slow responses and secret-egress audits remain visible. Invalid directory log paths now show an error and keep the last records visibly stale. Routine structured log records can omit _meta.path, which matters if your log-processing tools expect that field.Console records also retain their severity and subsystem labels so warning and error filters work correctly. Maintenance errors preserve more useful cause and timing information, while expected restart refusals and bounded cleanup listeners avoid misleading failure warnings.

Messaging

Conversations keep more of the context needed to answer a follow-up, and accepted requests have clearer paths to a final reply. Changes across the messaging channels also keep progress, attachments, and delivery results attached to the work they describe.
Telegram group and topic history now survives restarts and /new or /reset, so the agent can look back at earlier discussion when a recent message refers to it. The automatic context window stays bounded, normally at 50 messages, while explicit reads can page through older permitted messages. Mention requirements still apply, and reads stay within the authorized account, group, topic, and sender permissions. Only messages OpenClaw received and was allowed to record are retained, and older attachments may expire.Retained group history grows with traffic. Setting historyLimit to 0 turns off automatic context but keeps recording and explicit reads enabled, while resetting a session does not delete that history. Make a compatible pre-update backup if you may need to downgrade, and restore it before running an older release against this data because older versions can damage expanded retained history.
Rapid pieces of a pasted Telegram message can now reach the assistant as one request, even when short and long chunks are mixed. Ordinary text waits for 300 ms of quiet by default, adding a small startup delay and sometimes combining messages you intended to send separately. Commands bypass batching, and ordinary media stays outside text batches.The Telegram-specific messages.inbound.byChannel.telegram setting takes precedence over the global messages.inbound.debounceMs setting. Explicit 0 disables ordinary batching, while automatic assembly of near-limit pasted text stays active. Once a batch closes, later messages cannot join it.
Accepted group and channel requests now require an answer by default, including unmentioned messages in groups configured to accept them. If tools finish and the agent ends silently, reply recovery can produce the missing answer without repeating completed actions. Confirmed or still-pending delivery prevents another recovery reply, and pending tool or delegated work stays pending while restart recovery waits for capacity.Always-on groups may receive more replies after updating. To keep optional replies for unaddressed requests, set agents.defaults.silentReply.group to "allow" or use the corresponding surface override described under silent replies. Mention and access rules still decide which requests reach the agent, while ambient events, heartbeats, and internal helper turns remain optional. Internal child-result and coordination notifications can now finish silently without triggering a repeated answer. Messages canceled by Stop while still queued also remain silent, while new user requests retain normal reply recovery.
After a restart, addressed messages can pick up fresh recent discussion from Slack and Discord without turning quiet room messages into new agent turns. The default windows are 50 messages for Slack and 20 for Discord, with 0 disabling automatic history. Slack’s room historyLimit also caps thread.initialHistoryLimit, including when set to zero. Reads respect current access, edits, deletions, retention, and bounded retrieval, so unavailable history is omitted rather than replaced with stale text. Discord replies also retain quoted bot responses and automation alerts as untrusted context, making follow-ups understandable without copying the original message.Automatic observed-message context is now capped at 200 messages. The maximum JSON integer selects each channel’s default instead, while other oversized settings use the cap. Saved settings, stored messages, transcript retention, and explicit Telegram history reads are unchanged.
Interactive chats can show a waiting acknowledgement when delegated work would otherwise go quiet, and status checks remain visible without interrupting the running task or entering its later model context. Private child results return internally to the correct conversation, while cross-session requests from the Control UI receive their result without bouncing the human-facing response back to the other session. Thread-bound spawning is available again where channel settings and permissions enable it. The waiting acknowledgement is a single update, while independent agent peers keep their existing bounded exchanges.
Telegram inspection and interrupt commands can respond while the conversation is busy, so checking or stopping active work does not have to wait behind ordinary buffered messages. Commands that change the session, including /new, /reset, and /think, remain ordered, while /btw uses its separate lane. Existing authorization checks still protect buffered input from unauthorized controls.
With Discord streaming.mode set to progress, an accepted handoff to child agents keeps the existing progress checklist visible while their work continues. The final answer arrives separately, so the checklist remains a useful record of the work in progress. Declined handoffs and media or control-message paths keep their ordinary delivery behavior.
Telegram keeps the same progress card and checklist while delegated work continues, including eligible restart recovery when the existing card’s delivery record is available. The final answer remains separate and silent child work stays hidden. Interactive questions and their settled outcomes also survive progress cleanup, while temporary previews still retire; a missing delivery record does not create a replacement progress card.Once delegated work ends and a final reply is confirmed in the matching Telegram account and topic, OpenClaw removes that exact temporary progress message when deletion remains permitted. Pending or uncertain delivery keeps progress in place, and a cleanup failure never resends an accepted answer.
If a channel accepts a reply and saving its status later fails, OpenClaw keeps the known delivery result instead of treating the message as unsent. When only part of a reply arrives, the failure includes what reached the recipient. Pending messages and attachments remain available when the outcome is uncertain, and OpenClaw avoids speculative resends while recovery checks what happened.Reply completion tracking also survives failing plugin observers, and delayed cleanup preserves newer Discord and Slack previews and Slack messages people have replied to. A cleanup failure does not resend an accepted answer. Message dry runs now report a simulation rather than delivery, without automatically sending a real message.If a conversation’s assignment is changed, removed, or superseded before dispatch, OpenClaw asks you to retry instead of continuing through the old session. Custom session-store updates and newly recorded delayed replies also keep the selected agent, while /session idle and /session max-age wait for their settings to be saved before confirming success.
An accepted message can continue once through verified conversation compaction, which condenses older context to make room for more work. When continuation cannot be established, Refresh preserves the draft without sending a second message. Reset, replacement, restart, and cancellation checks still apply, and clients waiting on a canceled chat now receive its completion result after the running dispatch settles instead of waiting until they time out.
Canceled Mattermost sends stop before their next recipient lookup, upload, or posting request, and shared message actions stop later recipient lookups after cancellation. Teams polls also stop before submission when permission to send ends. Already accepted messages and polls keep their delivery results and vote tracking, so cancellation does not retract something already sent or guarantee that an in-flight request can be stopped.
Editing a streamed Mattermost reply or completing an interactive button now preserves the post’s existing pins and reactions. Partial edits also retain message text and files when those fields are omitted. Edits containing channel-wide mentions preserve the previously read properties, but can still overwrite property changes made elsewhere between the read and update.
Repeated --media flags in the message CLI now preserve every attachment in command-line order, using each channel’s existing sending behavior. Animated WebP files keep their animation within the existing size and model limits, with oversized animations rejected instead of flattened. Attachments also survive when a caption is stripped, without bringing the removed text back into chat. Older tool calls without a recorded publication no longer reconstruct a reply bubble, but their expanded diagnostics remain available.Discord videos and images with duration metadata also keep their visual media type instead of being mistaken for voice notes, while genuine waveform-bearing voice notes remain audio. Video understanding still depends on the configured provider’s capabilities.
Long replies keep emoji, flags, and accented characters together when splitting them into messages, except when a single character cluster exceeds the channel’s limit. Streamed code examples retain their fences and literal tags, and reply preparation preserves attachment details and the intended reply target through formatting and recovery. Several formatting paths also avoid repeated work on long text and code-heavy replies. Older third-party adapters need the prepared-operation interface to avoid reparsing replies in their own code; existing transcripts are not rewritten.Top-level indented code also keeps its leading indentation and internal blank lines through streaming and final reply preparation, while identical snippets written at different positions remain distinct. Very long whitespace runs can still lose spaces at message edges under unusually tight limits.
Login, logout, and directory commands now reject an explicitly blank --channel, preventing an empty shell variable from silently selecting a configured channel or affecting saved credentials. Omit the flag when you want automatic selection. Valid names, surrounding whitespace, and supported aliases keep their existing behavior.
Removing or disabling a Discord account, or removing a Matrix, Telegram, or Slack account, no longer blocks conversation discovery for the remaining active accounts. Retained history stays intact, while access to retired-account conversations is still restricted. An account that is configured but not yet ready can remain temporarily unavailable.
LINE send errors now identify an unreadable configured token file, and Nextcloud Talk distinguishes an unavailable configured bot-secret source from missing credentials. An unavailable QQ Bot secret blocks its own account while healthy accounts remain usable; failed explicit references do not silently fall back, and only unchanged accounts can retain previously working credentials during reload. Live channel status also remains readable from a reachable, authenticated Gateway while local state maintenance is underway.Online status JSON now labels a channel summary that was not collected, instead of implying that no channels are configured. Use channels status or its --probe option for configured-account or live checks.
Speakers already authorized to talk to the agent can ask to list or change the current Discord call voice without also being configured as command owners. A change affects everyone in the shared call, while saved defaults and other owner-only permissions stay in place. That voice access ends with the call or turn, cancellation, or revoked access.
Established Discord and GPT Live playback can continue while other Gateway work is busy, reducing stutters caused by that work. Changing voices keeps speech that has not started without replaying speech already underway. Speaker admission, microphone forwarding, agent work, and transcripts can still wait on the Gateway, so this does not remove every source of voice delay.
Discord thread creation now reports an accepted first message separately from the thread’s creation-time counters, which may still show zero or no value. Use the delivery result to check whether the initial message was accepted, and inspect uncertain sends before retrying. An empty standalone thread has no message-delivery receipt.
Feishu account shutdown waits for accepted message handlers and duplicate-message bookkeeping to finish before releasing their resources. Reaching the five-minute ordering limit does not cancel an already accepted handler, allowing its work to settle during shutdown.
If a Feishu meeting invitation fails before the agent durably accepts it, a later delivery of that invitation from Feishu can be processed again instead of being discarded as a duplicate. vcAutoJoin remains an explicit opt-in, and this change neither schedules retries nor guarantees a meeting join. Already accepted invitations and older duplicate-message records keep their existing behavior.
Delayed Matrix replies can obtain their connection after the original message handler finishes normally, and generated images or queued replies can reuse the matching live connection after a configuration-only reload. Startup and synchronization storage work also moves off the Gateway’s main thread. Shutdown, account removal, and explicit cancellation still stop pending work.Matrix also restores single-message assistant and tool progress drafts in affected sessions by using the account’s saved settings. Final replies are unchanged, and multi-message chunking still requires the plugin runtime.
Requesting a specific Matrix message through the message CLI or agent tool now returns that event or an error, instead of substituting unrelated recent room history. Existing permissions and encrypted-message limits still apply, while ordinary history reads keep their current behavior. Configured contact, room, and approver checks avoid unnecessary credential reads, and expired secret-storage requests fail promptly while transient network errors can still retry.
Normal logs now report when Slack fails to clear an accepted working status at the end of a turn, making that failure easier to diagnose. This exposes the cleanup problem without adding retries or repairing Slack Desktop’s separate stale-indicator behavior.
When Telegram sticker media is unavailable, its emoji and reply context remain in the conversation instead of leaving a blank turn that could revive an unrelated request. A sticker label fills in when no emoji is available, without adding visual analysis or animated and video sticker downloads.
Telegram avoids repeated escaping, link, and HTML-tag processing while preparing replies with the same supported formatting. With richMessages enabled, long and nested rich replies also avoid unnecessary repeated checks. The improvement is in local formatting work and varies with the message; it does not establish faster network delivery.Long Telegram code snippets also retain their internal blank lines and code formatting when split into messages, while honoring the existing message limits.
Telegram now selects the complete installed HTTP client under Bun, repairing the affected reply path and /models provider picker that could fail with dispatcher.compose is not a function. The live verification used a custom Bun build, so this scoped fix does not establish general stock-Bun support.
Teams can use the current inbound message when adding, removing, or listing reactions in the same conversation, without requiring its message ID to be supplied again. Reactions in another conversation and message deletion still require an explicit ID.When someone adds or removes a reaction in a channel thread, the agent now receives that reaction’s context in the owning thread rather than the parent conversation.
In Teams channels where the bot waits for a mention, unmentioned messages now stay available for the next request in their own thread. Answering in another thread no longer consumes that pending context. Group chats and messages without a thread keep their existing history behavior, and the separate issue of rapid messages from different threads being batched together remains outside this fix.
With inbound batching configured, rapid WhatsApp messages from the same sender can reach the agent together instead of waiting through separate batching delays. Group conversations keep each participant’s identity and message order, including when another person’s quoted or buffered message interrupts a batch. This restores the existing setting’s behavior without introducing a new default.
Zalo applies the same photo-caption limit to ordinary and polling replies without splitting the two-part encoding of an emoji at the cutoff. Text beyond 2,000 UTF-16 units is truncated rather than sent as extra messages, and this does not guarantee that every multi-character emoji sequence stays together.
When several iMessage questions arrive while an answer is being written, queued text and media replies can stay attached to the question that prompted each one. Explicit targets and the first, all, and off reply settings still apply. This requires both the updated iMessage plugin and a host that supports its inferred reply targets; updating the plugin alone is insufficient. The startup database read that establishes the latest seen message also moves off the Gateway’s main thread.
Looking up watched external conversations can now run alongside other OpenClaw requests. When monitoring stops, results that arrive late are discarded.

Memory

Memory search and maintenance can recover from more interruptions, helping saved information stay useful as conversations continue.
When an embedding failure interrupts a compatible index upgrade, you can still find previously indexed memories by keyword. This fallback searches the old index, so it may miss later edits and leaves meaning-based search and the rebuild unavailable until the embedding problem is resolved. Changes to the indexed sources or incompatible index history can still prevent fallback. Repeated empty searches also avoid rebuilding an unchanged empty index, and memory status shows the configured local embedding model before loading it.Memory settings no longer flag a loaded plugin as unhealthy just because it provides memory through another integration instead of host search. Actual loading and search failures remain visible, and this status does not certify the plugin’s own service. Built-in searches also do less database work on the thread handling replies, although the searches themselves may take longer.
History and search indexes can catch up while a conversation continues receiving messages, within a bounded amount of new history. Resets, branches, and larger backlogs still need a fresh rebuild. Completed memory saves keep their successful result if cleanup later fails, and the next sync can recover a lock left by completed local work instead of timing out. Recovery checks the original lock and database so it leaves active work and replacement locks alone.Memory rebuilds also avoid a false “owner changed” failure when database commands wait in a queue. Genuine revocation or replacement still stops the affected work.
Context engines that opt into background maintenance can now start summarizing after a saved conversation turn, using idle time without holding up the completed reply. Engines using foreground maintenance, or leaving the mode unspecified, still wait for that work, and some compaction may still happen during later turns. New conversation summaries also receive independent text blocks with their boundaries preserved, avoiding text being joined together before summarization. Existing summaries remain unchanged.Long tasks with repeated tool calls can recover from later context overflows after the model makes successful progress, instead of exhausting one recovery allowance for the entire task. Repeated attempts without progress remain bounded, and refusals, errors, aborted replies, or replies cut short by a length limit do not renew that allowance. Conversation compaction also keeps working after a plugin reload by using the current plugins.
When the compaction quality guard checks a shortened conversation, it now recognizes short requests such as “How about now?” that the summary correctly retained. This avoids unnecessary retries or cancellation caused by that matching error when the guard is enabled.
New Dream Diary entries now save when their recent context was only shortened to fit, instead of being mistakenly discarded as stale. Actual context changes and Forget still prevent stale entries from being written, and previously discarded entries are not recreated. Dreaming also stops trying to reconcile its scheduled jobs while scheduling is disabled, preserving those jobs for later. Explicitly disabling dreaming removes its managed jobs, and resuming scheduling still requires an eligible owner.Generated reflections stay searchable but no longer compete with ordinary memories in promotion rankings for long-term memory, while existing long-term memories remain unchanged.
Workspace adapters can now provide access to Memory files on a remote host for searching, reading, and maintenance, while the computer running OpenClaw keeps the index and original session data. This optional workspace capability requires a separately configured memoryFiles adapter and does not move existing storage automatically.After changing which source files the adapter uses, run openclaw memory index --force --agent <id> before searching. Keep the workspace binding unchanged during maintenance. Revoking access does not retract results already read or retained, and embedding requests or multi-step diary updates may continue after their original access checks.

Skills

Skills now refresh around actual content changes, while Workshop keeps a clearer record of the skills available to an agent and the reviews that shape them.
Unchanged Skills no longer trigger needless session rebuilds and chat metadata refreshes, and identical copies stop producing duplicate precedence warnings. Instruction edits and changes to which skill takes priority still refresh the session, while supporting scripts and assets continue updating in sandbox copies. Discovery also handles returning to an idle workspace and, on Windows, deleting and recreating a skill folder or its parent. Skill folders added during a rescan stay watched for later edits, and filtering Skills keeps each group that remains visible in its existing open or closed state.During initial monitoring setup, OpenClaw now checks that newly discovered nested folders are watched before treating setup as complete. If that initial check fails, later task preparation refreshes the affected skill sources while healthy watchers keep running.
Skill Workshop now lists current skill files and records successful tool-mediated use even when diagnostics are disabled. A rejected proposal remains a failed review when the reviewer sends no reply, and reviews delayed until idle time use the current plugins. Usage counts start with recorded activity rather than filling in older history, exclude native Codex skill activation, and do not follow files when they move.Safety guides and supporting files also stop triggering quarantine or critical audit findings solely for prompt-related wording. Three keyword rules were removed for both harmless guidance and actual instruction-override text, without a replacement detector. Credential checks, approval policy and other blocking rules still apply.Normal startup now leaves legacy Workshop data untouched. To repair it, run openclaw doctor --fix or openclaw doctor --yes with the same state directory and configuration as the affected installation. Doctor during an update continues to handle that repair.
Bzip2 skill archives can now be extracted without installing a system tar command. Finalizing an uploaded archive also lets OpenClaw continue handling other work while it hashes and stores the archive, and uploads that expire before finalization or a repeated commit are rejected. The rest of the upload’s database work now runs in the background too, with expiry checked after queued work is admitted. Existing extraction permissions and protection for uploads already in use by an installation remain in place.
Supported remote workspace connections let agent tasks use Skills and supporting files on the machine where the workspace lives. Adapters that also supply the required host information and management operations can show that machine’s installed skills, choose matching dependencies, and run approved dependency or source and ClawHub management operations there. Missing capabilities return an error without installing on the Gateway computer. The workspace adapter documentation describes the requirements; a document bridge alone does not enable this management, and the paired-node adapter does not support remote source or ClawHub installation, updates or removal.Keep the remote Skills connection in place until its tasks finish. Replacing it with a document-only connection while a task retains its remote skill list can make that task read supporting files from the Gateway computer instead.
Plugin Skill previews now show the main instructions before fetching supporting documents, so you can begin reading without waiting for every file. Supporting files load when you select them, failed reads offer Retry, and background loading preserves your selected document and reading position. Previewing does not install or execute the plugin, and reopening the preview lets you see installed files that were edited while it was open.

Native Apps

The native apps make everyday conversations easier to write, read, and return to, with more room for replies and clearer controls when a connection or permission needs attention.
Android chat brings Gallery, File, and Location into the attachment menu, with a microphone tap for dictation and a long press for voice options. Location goes into a draft you can review before choosing Send, using only the foreground permission and precision you allowed. Failed tools and recovery instructions are easier to read, and tapping an eligible reply’s timestamp opens its recorded model, token use, and estimated cost. Those details describe one model call, so they are not a whole-conversation total or a final bill.Staged photos now show thumbnails you can open before sending. A compact, expandable Tool activity section keeps running tools and saved results with their original prompt, with failures visible even when collapsed. Stop also stays tied to the conversation you selected if you navigate away, and reports rejected or uncertain results without treating an uncertain stop as completed.
Open an Android chat image to pinch, pan, or use visible zoom controls without accidentally closing the preview. Zoom reaches 4×, a double tap switches between 2.5× and the fitted view, and rotating the device refits the image instead of keeping an outdated position. Photo messages use compact rows with four-image pages that let you reach every attachment, and browsing them pauses automatic following of the conversation.
Settings → Appearance now offers five text sizes from 90% to 140%, combined with Android’s own font scaling. The choice survives restart and stays on this device. Page headings and status text wrap more fully, while sidebar pages gain Move up and Move down accessibility actions so reordering does not depend on dragging. The normal sidebar moves visible pages; Edit pinned items includes all pages.
Android connection forms keep their labels visible after you type and put setup errors beside the relevant fields. Overview gives Chat a clearer entry point and makes connection states and destination rows easier to read, while saved credentials remain masked and replacing them still requires confirmation. Nearby Gateway lists also retain current addresses and availability when a service disappears or is rediscovered, without changing pairing or connection checks.
Android Talk can use supported GPT-Live realtime routes advertised by the Gateway and shows which route is active or why device speech was selected. The Codex route tries ChatGPT OAuth first and can fall back to a Platform key; the public API route requires a Platform key. Platform-key use is billed per use, including fallback. An advertised route still needs valid credentials and account access, and changing an active route requires stopping and restarting Talk. Longer replies can use the existing audio buffer more fully, and a stopped session now shows its failure reason in chat.During realtime Talk, the phone leaves automatic local read-aloud silent, including replies started from another client, so consultation answers are not spoken twice. Text remains visible, and native Talk and explicit read-aloud remain available. Reconnecting to the same Gateway also keeps the selected agent in memory, while new Android voice messages send the recognized words without the app’s former added instructions.
Talk keeps valid consultation answers when speech transcription finishes late and shows each new answer once in Chat. Your spoken request remains readable while generated instructions for handing work to the agent stay out of the visible conversation. On supported interruptible relay calls, interrupting a reply also lets you continue speaking without immediately losing the call when the provider is slow to confirm the stop.
Long watch replies now offer Read full reply, with scrolling, part navigation, and retry controls beyond the compact preview. Update both the watch app and phone companion; Chat also needs a Gateway that supports full-message retrieval. Voice status and microphone guidance fit small watches more comfortably, and context selections expose their selected state to accessibility services. Live Chat stays a preview until a stored reply is available, and older Talk text can become unavailable after its session data is retired.
Sending a photo in native iOS chat no longer triggers the reported composer freeze, so you can send the attachment and continue typing without restarting the app. This repairs the send-time focus problem; keeping sent photos visible after history refresh remains separate work.
Native Mac Quick Chat keeps one composer beneath the conversation, preserving your draft and streamed reply when you collapse and reopen it. Separate model and Effort controls make thinking levels and supported Fast mode easier to choose, while the context ring offers Compact Thread. Model pickers keep usable choices visible without unrelated discovery warnings, and capture actions sit in the plus menu. Screenshot capture still sends after selection.
The Tauri desktop app puts your latest exchange above a separate bottom composer, letting you prepare the next message while a reply streams. Collapsing the reply preserves the draft, live text, and widget interactions; sending and switching agents wait until the current turn finishes. Cmd/Ctrl+Shift+O now reaches the foreground app for New Session instead of summoning a background dashboard. The separate configurable Quick Chat shortcut remains available, as described in the desktop app guide.
The Tauri app on macOS can reopen saved local or remote Gateways without the reported startup crash. If the launch environment prevents keychain access, its warning now gives appropriate recovery guidance, including reopening from Finder when relevant.
Opening the native Mac app or changing connection modes leaves independently managed Gateways and other services running. Saved Gateways show the current connection status from their Dashboard windows, even when they are not the primary connection, and About can copy version and build details while offline. Resolve a port conflict through the service that owns it; a green connection indicator describes a connection, not the health of every service behind it.The bundled Mac worker can start with saved desktop-sharing preferences, including named profiles, and honors whether sharing is enabled or disabled. Signing in from an open embedded Dashboard can also restore protected images and files while keeping the same-account conversation. Update both the Mac app and Dashboard for that renewal; signing in through an ordinary browser tab does not renew the embedded session.
Updated Windows startup and recovery helpers avoid opening an extra blank console during background launches. Interactive commands keep their terminal, and the change takes effect when the replacement helpers run.
Mac permission controls can request missing Screen Recording or Accessibility access through Grant, with System Settings nearby when more help is needed. After updating both the native app and Gateway, interacting with OpenClaw also gives agents basic recent-computer activity without Accessibility permission. The renamed System-wide presence detection option stays off by default and needs Accessibility for activity in other apps. Turning it off now disables only system-wide detection, including for previously disabled preferences; app-local activity remains eligible and does not prove who is physically at the computer or which device sent a message.
Canvas widgets can play direct HTTPS audio and video in inline previews, dashboards, and native panels. Update both the Mac app and Gateway, then update or recreate older saved widgets to receive the new media policy. Browser format support and autoplay rules still apply, so playback controls remain useful. Media requests can reach HTTPS hosts beyond a widget’s separately granted API connections; the widget media guide explains the distinction.
Mac settings distinguish an installed Chrome extension from one that needs enabling, and provide separate guidance when its helper needs repair. Older Mac apps keep a usable setup path with a newer Dashboard, including an unknown status when the older app cannot establish whether the extension is installed. Installation status remains separate from a live browser connection.
The Tauri tray menu adds an optional Keep computer awake setting beside Start at Login for long-running local work. It is off by default, remembers the choice on this device, and stays active when windows close to the tray until you disable it or quit. On Linux it can also delay automatic dimming and locking; manual lock, explicit sleep, and lid behavior remain under operating-system control. The native Mac app adopts the clearer name for its existing setting, which still requires a connected, hosting, unlocked Mac.
Hosted workers track unfinished commands through cancellation and node restarts, freeing occupied slots after cleanup is confirmed. Update the Gateway and the node hosts or Mac app together, and restart the updated hosts; older nodes may show Update required. Linux and macOS gain stronger cleanup, while Windows keeps a slot reserved when cleanup is uncertain. Let active workers finish before downgrading to an older version.
Mac packaging trims files the app’s private worker does not need, reducing the universal app’s size while retaining Apple silicon and Intel support. The packaging correction also keeps nested helpers needed by bundled subprocess support, including configured stdio MCP servers. Normal npm installations keep their CLI and Gateway functionality.Packaging now also supports separate Apple silicon and Intel builds alongside the default universal app. Availability of signed downloads and their automatic-update feeds depends on the separate publishing work.
The Mac Dashboard follows the native window’s appearance while loading, avoiding a white flash before the selected theme appears. The collapsed-sidebar Inbox also matches the other titlebar actions and leaves room for its unread badge.
Audio and document attachments can be read through equivalent macOS paths such as /tmp and /private/tmp. The opened file must still be inside a permitted folder, so this fixes path handling without extending access to neighboring folders or shared workspaces.
Existing native-app languages receive refreshed labels for Android controls, Wear reply reading, Apple chat and progress, and Mac consent screens. The translations help explain the current controls and permissions without introducing new languages or changing what those permissions allow.
Native iOS chat now offers Download file on assistant-generated documents, handing the downloaded file to the system share sheet with Save to Files and other apps available. Shared native Mac chat adds a save panel for those documents. Downloads need current Gateway access and stay within the existing 100 MiB limit; expired or removed files need to be regenerated. Images, audio, and video keep their separate controls.
Android packages omit unused resource files, reducing what they carry without changing authentication behavior.

Models and Providers

TypeSafe Jev and local Decision Models give supporting plugins a way to make structured choices separately from chat. Claude Opus 5.5, GPT-6 Sol and Luna, and Grok 4.7 add new conversation choices, with their own account requirements, settings, and costs.
Models settings now brings global defaults and the selected agent’s provider connections into one workflow, preserving unfinished setup input during rescans. Saving credentials leaves model activation as a separate choice. A model-only change preserves a compatible saved runtime but clears an incompatible saved runtime and its native consent so configured routing can apply. Explicitly choosing an incompatible runtime, or a model whose configured native runtime is unavailable, still rejects the change without altering the session. Model and effort controls remain usable in narrow chats, with more accurate refresh feedback, supported thinking choices, and Fast preferences for delegated work. Agent-requested model changes through session_status now use Gateway checks for runtime, sandbox, worker placement, and the intended session, rejecting stale or incompatible updates without changing agent or global defaults.
Claude Opus 5.5 is now selectable in the Anthropic API and Claude CLI catalogs as anthropic/claude-opus-5-5, with explicit opus-5.5 and opus-5-5 aliases. Existing selections stay unchanged, and the bare opus alias still chooses Opus 5. Thinking is always enabled, defaults to medium, and offers low through max; saved off or minimal settings use low instead. API use carries Opus 5.5-specific charges, and availability still depends on the selected account and route.
GPT-6 Sol and Luna give you two new choices for text, images, and tool use through the OpenAI Responses API or ChatGPT sign-in. For embedded ChatGPT use, explicitly choose the OpenClaw runtime; setting the model alone does not select it. Existing selections and the Astra setup default stay unchanged. Luna has lower standard API rates in the shipped catalog, at 0.10inputand0.10 input and 0.50 output per million tokens compared with Sol’s 2inputand2 input and 10 output. Different pricing tiers apply above 272,000 input tokens.Bundled Codex 0.155.1 also lets eligible ChatGPT accounts discover and use both models through native Codex. After starting or upgrading OpenClaw, /codex models shows your account’s choices. Embedded reasoning supports none through max, with medium as the default when supported; native effort choices depend on the account. The separate Luna Reserve route and its billing distinction remain unchanged.
You can select installed OpenCode, Qwen Code, Pi ACP, and Kilo Code agents from Models settings and use their streamed replies in ordinary chat. Install and sign in to the app on the computer running OpenClaw, then use the discovery feedback and Check again control to resolve unavailable models. Detection alone does not confirm sign-in. Native-agent setup explains how an administrator’s Continue for this chat grants Full Access, turns off optional sandboxing for that chat, and consents to the native app’s permissions. Required sandbox and workspace boundaries still apply.An explicitly selected CLI that is unavailable now reports the failure instead of silently switching to API access. Restore that CLI or explicitly choose an API route. Claude’s picker labels help distinguish those routes, but an API-key account still incurs API charges through Claude CLI. Native consent must be renewed after a reset, runtime change, or stronger settings and does not carry into forks; deleting the OpenClaw session leaves the native app’s history intact.
An installed, signed-in GitHub Copilot CLI can now supply models for ordinary web and channel conversations. Copilot setup uses the account running OpenClaw on that computer, with access and billing owned by Copilot; explicit bring-your-own-key settings and environment tokens can affect which account is used. Discovery is enabled by default, and disabling it stops new discovery and turns while admitted work continues. These native turns use the app’s host permissions, without OpenClaw sandbox or workspace-only confinement.
Claude CLI keeps follow-up tools and the final answer in the original turn when a foreground Bash command takes long enough to be moved into the background automatically. Commands intentionally started in the background still end the turn promptly and do not gain independent later delivery. Supported npm-installed wrappers now launch on Windows, long reasoning streams require less repeated parsing, and recovery timing stays within its existing budget when the system clock changes.Completed Claude replies can also arrive while native background research continues, even with previews and block streaming disabled. Channel progress previews show tracked checklists and completion counts without treating a completed checklist as the end of the run.
Direct Anthropic OAuth requests now advertise a maintained Claude client version to address newer models rejecting an outdated client identity. OpenClaw uses at least version 2.1.278 or a newer installed stable Claude CLI, with the result cached until restart. This updates request compatibility while leaving account entitlement, billing policy, and local model restrictions unchanged.
Grok 4.7 adds a text-and-image model choice with reasoning levels from low through xhigh. New xAI setups choose it when no primary model is selected, and web search, X search, and code execution use it when their model setting is omitted, including on existing installations. Explicit primary and tool selections stay pinned. Eligible Doctor repairs replace retired xai/auto selections while preserving account pins, fallbacks, and authored settings. Pricing above 200,000 tokens differs from the short-context catalog rates.
Xiaomi MiMo V2.6 adds Pro, Flash, and Pro UltraSpeed for pay-as-you-go accounts, with Pro and Flash presets for regional Token Plans. New setups default to Pro when no primary model is selected, while existing selections remain. The new models support text and images, thinking controls, and retained reasoning history; Pro and Flash also prefer automatic Code Mode unless explicitly overridden. Token Plan zero-dollar catalog prices represent quota accounting, not free service.
TypeSafe Jev lets supporting plugins choose among options, score supplied information, or estimate whether a condition is met. It uses the optional Decision Model role, which stays separate from chat and is off by default. Selecting a decision model does not start background work or give an agent new tools or permission to act.The separate @openclaw/typesafe plugin is available on npm for OpenClaw and plugin API 2026.9.6 or newer. Install and enable it, add a protected API-key reference, then select Jev or Jev 1.13.0. Hosted evaluations send the supplied information to TypeSafe and incur its normal API charges. Requests can allow up to thirty seconds, with shorter caller deadlines and saved timeout settings respected. If replacing an external prototype, preserve its settings, credentials, and policy before uninstalling; uninstall --keep-files does not keep the configuration.
The optional ONNX plugin makes structured choices locally on the CPU without sending the supplied information to a hosted inference service. Its @openclaw/onnx package is available on npm for OpenClaw and plugin API 2026.9.6 or newer. Install and enable it, prepare one of seven model presets, and select it as a Decision Model. Five presets have pinned downloads and two require local exports; none is enabled automatically.Evaluations can allow up to thirty seconds, with shorter deadlines still respected. Large cold models may need preloading or a smaller model. Invalid replacement preparation leaves an already-loaded model available, though failure while creating the replacement’s native session can still evict it.
The TypeSafe plugin also connects the Decision Model role to a local Kev server you run yourself. Install and enable @openclaw/typesafe from npm on OpenClaw and plugin API 2026.9.6 or newer, then configure the server’s loopback address and select Kev. The server controls the loaded model weights, and its address applies to every request through the plugin. Local mode needs no hosted key and does not fall back to hosted Jev.The unset timeout defaults to thirty seconds, while shorter caller deadlines and saved overrides remain in effect. A timeout or canceled request does not necessarily stop inference already running on the Kev server.
Model discovery can use saved credentials in custom agent directories, refresh eligible empty catalogs after their cache expires, and retain existing choices when a catalog refresh fails. Failures and Retry remain visible even while other providers are still loading, so you can act on the problem without losing a working selection. OAuth diagnostics also identify the affected agent and profile with the appropriate sign-in command.Default merge-mode catalogs now show eligible newly discovered models alongside older saved provider rows. To restrict the available choices, use an explicit modelPolicy.allow policy or models.mode=replace; a saved provider array alone no longer limits discovery.
Repeated model and authentication refreshes avoid whole-database copies and limit temporary plugin copies created by current discovery workers. Catalog preparation also reuses more existing work and stops recurring retirement checks while workers are idle. These catalog repairs take effect in newly started workers and now release retired catalog registrations after refreshes. Older scratch directories use a separate cleanup path.
OpenClaw avoids more repeated storage reads, process starts, filesystem checks, and copying while preparing model credentials, allowing other Gateway work to progress during asynchronous reads. Reuse is invalidated when relevant credentials or ownership change. Credentials changed by another process can take up to 100 milliseconds to become visible through the cached path, while changes made within the running process invalidate it immediately.Retiring catalog workers now wait for already-started OAuth refreshes to save replacement credentials, while failed Gemini credential replacement removes its staged file and retains the previous credentials for retry. Already-stranded logins may still need a fresh sign-in.
Conversations and scheduled work can reach configured alternatives sooner when a provider asks for a rate-limit wait longer than the saved retry cap. This requires a configured model fallback, a positive cap, and a request that can be replayed safely; zero disables the cap. Switching accounts or models sooner can change costs and answers. Long tasks also regain their transient-outage recovery window after a completed successful model response, while overall retry and run limits remain in force. Conversation compaction now keeps the current healthy account, including a selected fallback, in both explicitly ordered and implicit account pools; actual failures and preferred-account recovery can still change it.Eligible background text requests can try prepared backup accounts while respecting explicit account pins, and canceled requests stop waiting for a shared credential refresh. Saved cloud failures retain their cause, partial output, and usage. Claude also retains generated partial replies and final usage when its context window fills, without completing the truncated answer. Check what already completed before retrying a failed run, because earlier tool actions may have taken effect.
Budget errors no longer trigger futile retries merely because a billing-help URL contains limit-related wording. Upstream server failures also report as server errors instead of misleading timeouts, while genuine rate limits, timing failures, and overload retain their existing handling.Opt-in diagnostic timelines show model activity and explain existing recovery decisions. OpenAI misalignment errors are also identified as provider refusals instead of malformed requests; the separate findings-review flow below governs whether a supported conversation can continue.
When a provider returns a misalignment precaution, chat now shows Review findings and pauses ordinary sends, Talk, and queued input. Supported native Codex and ChatGPT Responses conversations can offer the exact provider-supplied continuation for an authorized operator to acknowledge. The pause clears only when the provider accepts that request, and earlier queued messages remain held for individual review and retry. Ordinary API-key Responses and incognito conversations can show findings without offering continuation, and missing or incomplete findings cannot authorize it.The precaution concerns the agent’s interpretation of the task and does not establish that the user violated a policy. It does not undo completed actions or bypass a refusal automatically. Model failover guidance covers the limits, including that downgrading to code from before this feature removes pause and held-message enforcement.
Compatible custom Responses endpoints preserve optional tool inputs, and managed Chat Completions conversations retain the encrypted provider state needed to continue after tools. Eligible Responses stream conflicts can recover within the existing retry allowance without repeating earlier completed tools. Recovery is limited to qualifying completed responses that have not already exposed output from the failing response, and excludes provider-hosted tools.Explicit terminal status now takes precedence over contradictory output-limit hints, avoiding an unnecessary continuation request while keeping genuine length recovery available.
Gemini tool requests no longer include the internal optional-field metadata that could cause rejection. Plugin authors also get deeper finite-schema support in the Gemini normalizer and unsupported-keyword cleaner, avoiding recursive stack overflow in those two paths while still rejecting circular objects.
Configured cache-TTL pruning now removes expired tool output on eligible OpenAI and ChatGPT/Codex routes. It remains opt-in, and custom proxies must explicitly support prompt-cache keys. Preparing long conversations also avoids some repeated request-copying and Unicode cleanup work while preserving valid multilingual text and emoji.Native Ollama compaction checks now use valid measured prompt, output, and cached-token counts, falling back to estimates when those counts are missing or invalid.
Unknown model costs are now left unavailable instead of appearing as free usage, while explicitly free rates and provider-billed zero totals remain zero. Recorded charges retain their request-time pricing. Plugin consumers should handle the optional usage.costUsd field being absent.Codex usage views now label Luna Reserve as a separate route. Unused Reserve quota does not cover ordinary Luna requests, including with Fast off, and ordinary Luna may still consume credits. This clarifies the display without enabling Reserve routing; account counters are not per-request billing receipts.
Claude Code, Codex CLI, and Gemini CLI now honor explicit search-provider and disabled-search settings. Eligible native OpenAI search also keeps its selected route through Tool Search and Code Mode. Choosing a managed provider suppresses native fallback even when that provider’s connection fails, so a failed connection does not silently change your search choice.
Deepgram prerecorded transcription now retains speech from later audio channels, including recordings whose first track is silent. It uses the best alternative from each channel in the provider’s order; it does not interleave the tracks chronologically or add speaker labels.
Doctor can identify missing commands or arguments in CLI media-tool setup, and transcription rejects those incomplete commands before launching them while retaining model fallback. It provides guidance without rewriting your settings. Audio discovery also skips Whisper model scans when whisper-cli is not installed.
When image generation through ChatGPT sign-in fails, OpenClaw now shows the provider’s available explanation or refusal. The bounded, sanitized diagnostics help explain the result while leaving the provider’s policies and failure rules unchanged.
Expanded llmman guidance explains existing local and hybrid setup, model names, credentials, and troubleshooting. It documents the existing integration rather than adding a new provider or routing feature.
Managed local model servers retain shutdown ownership and wait for child output and termination to settle before a replacement starts. Incomplete shutdown remains visible as an error that later requests can recheck, and Windows cleanup avoids signaling a different process that has reused the old process ID. Existing stop budgets and platform limits still apply.
xAI device sign-in now rejects malformed token-response bytes before they can be saved as corrupted credentials. Successful token-refresh responses are also validated before replacing stored credentials, so malformed responses leave the old local credential intact. Provider-side token rotation can still require signing in again, and existing corrupted credentials are not repaired retroactively.
Codex account status now identifies the selected connection and reports a deleted profile’s own errors instead of showing another subscription as active. Credential import asks for consent before inspection, and upgrade guidance distinguishes missing local profiles from provider authentication failures. Follow the agent- and profile-specific recovery guidance and verify the result with an unfiltered auth list; credentials are not imported automatically. Migration guidance also explains when secret inspection can still prompt for Keychain access. Onboarding now explains the import scope before review and apply, including that sessions and chat history are excluded, credentials require separate consent, and configuration and hooks need manual review.Supervised turns retain their local Codex configuration and login. A shared Codex daemon still shares its login across chats, without per-chat account isolation or fallback to OpenClaw credentials. Changed policy may require a reconnect or retry.
Scheduled Codex app calls retain the connected-account approval requirements captured when the schedule was created, alongside current policy. Plugin installation refreshes shared information without treating another conversation’s readiness as proof that an app is usable in this one, and prompts dismiss when another connected client actually answers them. Missing configured plugins no longer restrict otherwise eligible connected apps, while a present plugin disabled by an administrator retains its restrictions. Older custom runtimes may need /new or /reset after installation.
Codex turns can start after slow process-registration reads and recover from stale records for exited processes after an OpenClaw restart. Valid native configuration forms and managed Bun launch checks also receive the intended handling. Verified setup requires a local native executable or official npm launcher, so an app-server proxy is not a substitute on that setup path. Persistent process-recovery failures still need inspection rather than manual deletion of records.
Eligible local, agent-scoped Codex background titles and narratives can run with administrator hooks in a verified isolated environment. Model-callable tools, apps, and MCP remain unavailable there, and unsupported launchers may need a directly executable wrapper. Optional finalization can also choose silence without generating a missing-summary fallback, while required replies and failure reporting remain intact.
Resumed Codex sessions retain their captured inherited AGENTS.md instructions even if the source file changes or disappears; start a new session to load edited instructions. Eligible /btw side questions regain inherited shell tools, and cancellation settles the side question’s native background terminals or reports when stopping cannot be confirmed. Main-conversation terminals and OpenClaw background jobs keep their existing lifetimes.
Codex remote file and attachment transfers keep their existing elapsed-time budgets when the system clock moves backward, preventing a clock correction from extending the wait. Existing size, path, and cancellation limits remain in force.
Delegated Codex work now completes from native completion events or recovered history, preventing parent commentary from being mistaken for a child’s finished result. Parents can resume after yielding to deliver completed work, and eligible saved results can restore a missing final summary without repeating completed actions. Reply handling also distinguishes delivered, queued, and failed output while preserving unsent images and finalized text.Automatic approval remains limited to one execution, with persistent trust requiring an explicit choice and empty approval forms requiring Allow or Decline. Recovery retains evidence of prior tool effects, but uncertain partial media delivery can still require checking what arrived. Updated Codex and Copilot plugins need a matching core SDK for the delegated-result repair.
Codex conversations keep their selected physical source, with stop and steer reaching the active turn and completed forks retaining their outcome. Compaction waits for confirmation, valid retained text spans can be forked when runtime policy permits, and oversized tool results can be replaced with explicit omission notices when reopening a conversation without changing its full transcript. New sender-attributed messages also preserve the submitted text needed for branching; older mismatched transcripts are not rewritten. Recent assistant explanations survive thread rotation, and successful rewinds or branch switches retire stale native context so the next turn follows the selected history.Older adopted chats without a saved source keep their history but need fresh adoption into a new chat. Pinned chats need their original source restored, or the replacement adopted separately. Older nodes require an update and refreshed capability approval to continue, and native terminal or paired-node CLI resume requires a local stdio source. Archiving a parent protects active descendants, while required requests and tool arguments must still fit the history limits. Sandbox-required sessions cannot use host-only forks, and rewinding or switching branches can reduce prompt-cache reuse without erasing provider-side history.
Long available Codex tool responses now remain saved after a reload, with Show full output, Copy, and Download providing inspection and export of the original captured text. Recognized native Code Mode results also get readable command and text displays with expandable source and Raw details, while unknown or incomplete results keep their original representation and failed exit statuses stay visible. The output guide explains the distinction between execution output and provider responses. Older discarded text cannot be recovered, and redaction, provider truncation, and transport limits still apply, including a requested maximum of two million characters per text field. Neither view proves exactly what Codex later sends to its model.
Interactive Codex sandbox commands now receive real terminals, Ctrl-C reaches interactive and noninteractive commands, and exit results identify the requested process. If command execution is allowed but process management is denied, permitted commands can finish in the foreground while background continuation and explicitly excluded shell tools remain unavailable. POSIX installations running Bun need a real Node runtime for terminal helpers. Cleanup retains owned resources until work settles, including canceled readiness probes.With OpenClaw’s sandbox exec-server and a retained sandbox lease, canceling a turn now stops its own processes and admitted child work while preserving independent background work in the same native thread. Revoking the original source can still stop its retained work; releasing the final lease cleans up children, and other native execution modes retain thread-wide cleanup.
Small Codex catalog replies avoid waiting for a decoder worker to start, while large session lists reduce repeated scans and database work. Catalogs refresh incrementally, with full reconciliation at startup and reconnect; quiet edits or removals in older sessions may wait for a successful fifteen-minute safety cycle. Large catalog parsing moves off the Gateway’s main thread, and recreated connections suppress unused notification traffic, reducing repeated processing without changing model generation.Progressive local lists can show retained rows or loading status while slow discovery continues, and responsive providers can proceed alongside slower ones. Permanent catalog launch failures now stop repeated retries and identify the executable to repair; restart afterward, because a configuration reload does not clear that failure.
New Codex chats, delegated work, and HTTP fallback requests can start while sixteen earlier responses are still streaming. The relay separates preparing and uploading a request from keeping its response open, lets short bursts wait for capacity, and reclaims only completed idle connections. Active responses and newly opened WebSockets awaiting their first request remain protected.Capacity remains bounded, with sixteen preparations or uploads plus sixteen waiting, separately from eighty resident HTTP operations or WebSocket connections and additional space for pending or closing work. Transport limits still apply, and sustained overload can exhaust retries. HTTP connections close after each response and native HTTP retries reconnect, while WebSocket reuse remains supported. See Codex runtime behavior for the detailed limits.

Automations and Scheduling

Scheduled work is easier to run, follow, and return to, with clearer distinctions between work that is executing, work that has finished, and results still waiting to reach you.
You can use Run now on a paused automation in the Agents panel without enabling its schedule. A future Once job keeps its saved occurrence even with Delete after run enabled, including when a manual run waits past that date or OpenClaw restarts. Re-enabling makes the preserved occurrence available again, while genuine schedule edits still take effect and already-deleted jobs are not restored. Manage automations explains the controls and run history.Accepted manual runs can start after the calling tool or native agent reply finishes, without keeping that reply open for the whole job, and acknowledgement now follows a saved run receipt. Cancellation, cleared queues, and withdrawn permissions still prevent activation. If OpenClaw crashes before dispatch, the interrupted receipt remains for diagnosis without automatically replaying the run.
Scheduled jobs keep their own execution and result-saving lifetime after the conversation turn that created them ends. Their command launcher remains available after background handoff, and parent conversations stay available while delegated work or its delivery is pending. Canceling a job or withdrawing message permission stops later message actions while preserving records of deliveries already accepted.Scheduled Gateway tools must run on the Gateway that owns the job. Remove gatewayUrl and gatewayToken from same-host templates before rerunning them. Cancellation cannot recall effects already submitted to a provider.
Remote administrators can create recurring automations in a fresh chat turn under their existing permissions, including jobs attached to the current conversation. WebChat can also create announcements back to that conversation using announce or omitted delivery settings. Fresh creation rights do not carry over to management continuations or grant access to the host, providers, or additional MCP tools, and an explicit delivery.channel=webchat remains invalid.Jobs created in a direct message can use their recorded creator account even when result delivery is disabled or goes to another channel. The account must still be configured and the recorded origin valid, with existing tool restrictions preserved.
Creating or editing an automation preserves meaningful whitespace in shell commands, and invalid cron stagger values are rejected before they can partially change a job. Keyboard focus stays visible above the editor’s sticky save controls, delayed action feedback names the job you acted on, and timeout errors correctly explain that zero disables that particular timeout. Other execution limits still apply.If an older save trimmed a command, reapply the original command to repair it. When creating jobs from scripts, omit working-directory flags to use defaults instead of passing empty strings.
Run history now shows OK · Error or OK · Unknown when execution succeeded but overall completion failed or remains uncertain. These runs still appear under the OK execution filter, so the delivery details matter when checking whether a report reached you. Confirmed final delivery can prevent a later tool error from turning a completed report into a false failure, while progress-only messages do not count as final delivery. Repeated failed runs in a persistent conversation also retain their original errors for diagnosis.Otherwise successful scheduled jobs can finish quietly when there is nothing to report, even with an announcement destination configured, without recovery replies or missing-summary placeholders. Direct user messages still require replies, and real execution, cancellation, child-handoff, or delivery failures remain failures. History also distinguishes loading and failed requests from confirmed empty results, with Retry available when a request fails.
Overdue heartbeat checks no longer hold up scheduler startup or reload, and their results can wait for busy storage without blocking unrelated work. A successful or skipped agent no longer hides another agent’s failure in a combined heartbeat result. Background command results can also reach their idle originating conversation while unrelated sessions are busy, when automatic wake is enabled. Activity in the destination conversation or pending recovery can still defer delivery, and subagent sessions remain excluded from automatic wake.Routine heartbeat checks with no queued events or tasks now skip a busy agent if preparation has not started, avoiding a false timeout and error backoff. Their next opportunity is the normal scheduled tick. Manual wakes, queued work, and checks already started keep their retry behavior, and real execution timeouts remain errors.
Parents waiting on delegated work can resume across provider retries, and old pending result delivery no longer blocks new launches within the existing active-run limits. Eligible native children paused with sessions_yield can continue under their original task when their controlling parent sends an ordinary message, allowing the task and its chat activity to finish together. Explicit follow-ups remain separate work, and interrupted children after a restart report back for parent-directed continuation.Queued children are recorded before startup, and native follow-ups before acceptance, while completion notices remain owed until the parent turn finishes. If follow-up acceptance is still pending, inspect the returned run before retrying. Results remain accessible through conversation compaction and cleanup, with existing access checks preserved; pending or failed saves remain visible rather than being treated as delivered results. Completion and cancellation notices keep their intended destination through delayed storage work, and an accepted or uncertain send no longer triggers fallback solely because a later save fails.Completed child results can reach a parent after it yields, and delayed cross-session replies can resume a requester after its original connection ends. The retained permission context lasts within the running process; restart recovery and explicit retries require newly admitted authority. Later turns recognize earlier pending children without restarting them, and matching late results are accepted without resending input. Running children continue through existing completion delivery, while paused children still need a continuation through sessions_send.
Task details show complete command inputs with sensitive values redacted, and distinguish live Running, Queued, waiting, and Finished execution from a saved task record. Quiet background commands can still show as running, while delayed activity no longer makes finished work look active. Finished describes execution, so success and pending result delivery remain separate facts, and unavailable activity does not by itself mean failure.Failure notices offer concise previews with full diagnostics available through tasks show, and unreadable task metadata produces an explicit error instead of a falsely empty list. Previously truncated command inputs cannot be reconstructed, and command output remains bounded.
Task tracking, maintenance, and flow reports do less repeated storage work while preserving newer progress, deletions, delivery details, and late results. Maintenance can continue around unsettled tasks, and restored or retried workflows show their committed status even when a background worker’s reply is delayed. Large task flows can also enter a waiting state without redundant result copies exhausting the worker’s memory. Individual requests can still wait for storage, and queued events become durable only when saved.Historical task-identifier repair belongs to Doctor before ordinary runtime use. The normal openclaw update path runs it, and supported container upgrades over retained state can run exclusive Doctor maintenance automatically during startup. Keep the matching database backups for rollback. When offline repair is required, stop writers and run openclaw doctor --fix against the same state before restarting. Ambiguous identifiers produce a warning and leave the repair unchanged, and unsafe required state still refuses startup with repair guidance.

Browser and Computer Use

OpenClaw can keep apps beside your conversation, show more kinds of cloud desktops, and make the browser work easier to inspect as it happens.
Ask the agent to open an app in Crabbox and show it beside your chat, then keep working with the same machine on later turns. Attached apps need a configured Crabbox profile and a persistent conversation outside a sandbox. Attached machines skip unnecessary agent startup preparation because the agent stays on its original host and workspace. Native Linux apps also need a desktop-enabled profile and the Cloud Worker Desktop lab, while web apps open in a Portal. Files must be copied or prepared on that machine explicitly. Closing the panel leaves apps running, so save the outputs you need and stop the Crabbox when finished.Remote Portals now use their published HTTPS addresses. Managed Tailscale Portals stay private to your tailnet even when the Gateway uses Funnel, and their separate ports need to be allowed. An optional wildcard proxy needs your own DNS, TLS, access controls, and a Gateway restart. Forwarding the Gateway alone does not expose the apps. Upgrade OpenClaw and its bundled providers together, and stop attachments before downgrading.
Cloud desktops now support native macOS and Windows profiles, with Fit and Actual viewing sizes. Enable the Cloud Worker Desktop lab and a desktop-enabled profile first. Properly prepared native desktops also support computer control and Browser and Terminal launchers. Native machines start cold and do not support remote display resizing. Mac setup needs macOS 15 or newer, Chrome, an unlocked worker account, passwordless sudo, and a separately signed OpenClaw Cloud Worker app with its own Accessibility and Screen Recording permissions. Windows needs its worker-account desktop active and the Crabbox desktop launcher installed. WSL2 desktops, Windows sign-in, and secure Windows screens remain unsupported, and Mac provisioning requires existing EC2 Mac Dedicated Host capacity. Live Mac desktop validation remains incomplete.Before downgrading to an incompatible build, stop and release affected environments and conversation attachments, and wait for confirmed teardown. This includes native Mac and Windows environments and Linux environments using the new fixed launcher arguments. Closing the viewer or suspending a worker is insufficient. Linux cloud sessions also regain resized screenshots and browser reopening; an already affected browser needs a restart or a newly provisioned worker.
Persistent paired Mac, Windows, and Linux computers now offer desktop sharing by default, with native Mac and Tauri switches and connection status. Pairing approval and an authenticated local Screen Sharing or VNC service are still required, and the switch does not turn on that operating-system service. Explicit disables and Gateway denials remain respected. Some existing computers need approval again in Devices after updating. Tauri requires a local OpenClaw CLI, and closing it to the tray leaves sharing active.Access to the computer running the Gateway remains a separate opt-in. An administrator can enable Host Desktop from Systems, with setup guidance for missing services and macOS permissions. Labs changes, including Systems enablement, apply without restarting the Gateway when automatic configuration reload is enabled. Turning access off closes viewers but leaves system screen-sharing services and cloud workers running. Code Mode and Tool Search changes apply to future runs, and disabling Custom plugin UI requires a browser-tab reload to clear code that already ran.
Ordinary Codex Computer Use turns using the default non-strict readiness setting no longer wait for optional live desktop probes before starting. Installation, available tools, and permissions still matter, and a later desktop call can still fail; strict readiness and explicit status or install commands keep their live checks. Computer-control helpers also find a suitable Node runtime when a Bun shim shadows it, though Bun users still need Node installed. Browser refusals give recovery guidance that matches the actual policy or plugin problem, and Linux X11 apps that previously missed brief key taps can detect them.
Browser actions and selected-area screenshots stay tied to the controls that were captured, including pages with repeated labels or frames. If a captured control disappears, the action fails instead of choosing another matching control. Browser input keeps its click and key order, healthy tabs avoid waits on stalled siblings, and form failures explain problems such as covered or disabled controls. Exact storage keys, including surrounding spaces, are preserved.When using an existing Chrome session, captured references now survive condition waits within the same document, and the packaged helper supports controls across cross-origin frames. Navigation still retires references from the replaced document, so take a fresh snapshot before acting again. The default helper ships with OpenClaw and no longer needs an npm download at browser startup. Native coordinate input supports left and double clicks; right or middle clicks and nonzero click delays require a managed profile. A missing target is never silently replaced with another tab.
Browser cards can show public page titles, favicons, and social images when a live screenshot is unavailable, making closed or historical pages easier to recognize. Repeated opens of the same page share a card within an activity group, while actual tabs and distinct routes stay separate. New Browser side panels use more available space without overriding your saved width. Retained computer screenshots also appear during runs and after reopening chat, with image-viewer, copy, and download controls. Discarded pixels cannot be recovered, and some saved-image layouts can still show duplicate tiles.Public metadata fetching follows the existing default-on automaticallyFetchFavicons setting. Turning it off disables those previews while keeping live screenshots. These requests carry no browser credentials, but destination sites and image hosts can see the requested URLs and the addresses making the requests. Computer screenshots shown as observations are not automatically sent as outgoing attachments.
Restarting with several retained cloud sessions can finish recovery sooner because independent provider checks run together within a fixed limit. A submission that has not yet started can also recover after its worker reconnects, update the worker on the same machine when needed, and retry admission once. This requires a compatible worker installer and a successful reconnect. Work already handed to a worker, including interrupted tool calls, is never replayed by that retry. Cleanup guidance now reports the latest cleanup failure, so an old session error does not hide what still needs attention.
Chrome extension setup now shares one inspect, install, and verify flow across desktop apps, the CLI, and the TUI. Use openclaw browser extension setup --action inspect or /browser-setup inspect to see what still needs attention, with install and verify actions available from the same commands. Setup preserves your selected browser profile and distinguishes installation, Chrome approval, and an authenticated connection. It runs on the computer hosting the command, including the remote host when you use SSH. A remote Gateway still needs a browser node on the computer running Chrome, and Chrome’s extension installation and permission approval remain required.After a package move breaks the extension’s local helper connection, deployment owners can inspect it with openclaw browser extension repair --dry-run --json, then use repair --from /absolute/old/native-host-entry.js --json from the replacement installation to repair matching registrations. This preserves existing configuration, pairing, and unrelated installations. Windows setup requires a separately available compatible BrowserBootstrap executable, and relocation repair requires manual work there. Installing or repairing the helper does not by itself mean Chrome is connected.

Plugins and Integrations

The GitHub reader keeps source discussions beside your chat, remote workspaces connect that conversation to files, Memory, and Skills on another computer, and live meeting notes let you follow a capture before it ends.
You can follow meeting notes while capture continues, with updates about every five minutes when new speech arrives and final notes when capture ends. This works with captured voice and Google Meet, Microsoft Teams, and Zoom meetings. The Meetings page refreshes automatically and keeps the complete saved transcript in its own tab, so you can move between the notes and what was said. Users with write access can also generate missing notes. Transcription can lag the conversation, and model-generated notes use your configured model, with normal usage charges and existing summary input limits.
Leaving a meeting now waits for audio startup already in progress and shutdown of the resulting audio runtime before reporting success. Rejoining the same meeting waits for that cleanup, while other meetings remain independent. Failed joins stay reachable while another leave attempt is needed to finish cleanup. Audio cleanup and leaving the browser meeting are separate, and a cleanup failure can still require a retry before replacement proceeds.
The optional FaceTime plugin adds one-to-one audio conversations with your configured agent, including spoken answers to requests that need its tools or memory. It is experimental, disabled by default, and needs a dedicated Apple Silicon Mac running macOS 14.4 or later, OpenClaw 2026.9.6, matching signed native helpers, configured audio devices, and realtime-provider credentials. Matching plugin and native distribution availability remains unconfirmed.Setup also requires participant consent, Developer Tools access, and manually reduced macOS SIP debugging protections. Every allowed handle has owner authority, only one managed call can run at a time, and agent-initiated calls require one-shot approval. Follow the setup guide before enabling it.
Administrators can now sign in to eligible MCP connectors directly from Settings, approve access in the browser, and return to an Authentication saved result. This works for enabled HTTP OAuth connectors using shared native credentials when you open the Gateway through its own loopback or published Tailscale address. Other account modes keep their existing sign-in paths, and saving credentials still leaves connector reachability and tool access to be checked.
New CLI-backend turns keep access to their permitted OpenClaw tools after a plugin replacement, without needing a Gateway restart. Long-running MCP calls also keep their local connection alive while awaiting a result, and Bun cleanup handles a supervisor that outlives its command. Each new turn still needs an active grant, and connection keepalives neither extend deadlines nor indicate progress.Codex-owned MCP connections also honor configured startup and tool deadlines and explicit parallel-call hints, while native read-only parallelism keeps its own rules. Expired legacy SSE connections are replaced for later calls after a message request receives a 404; the call that discovers the expiration still fails and is not replayed.
ACP-connected coding agents resolve model choices against the currently connected harness, including after reconnecting, and newly spawned child work appears once in the task list. Explicit model choices fail if they are unknown or ambiguous, so an unsupported selection cannot silently become another model. Failed ACPX starts also release unused session state while preserving queued retries.Managed ACP agents now default to at most eight Tokio workers per child, or fewer when fewer CPUs are available, while preserving an inherited worker setting. This is a worker-pool default, not a total thread or CPU limit. ACPX 0.19.1 adds startup, logging, launch-admission, and cleanup fixes; let active turns finish and restart embedding hosts to load the updated runtime. Windows queue cleanup requires every participating acpx client to be updated.
When an A2A task switches models, its completed result now contains the fallback model’s actual answer. The task no longer finishes early with only the notice that a different model will be used.Replies also complete their original A2A task under message-tool-only settings, rather than leaving the caller polling after the answer is finished. Explicit strict settings and peer isolation still apply.
Embedded and Copilot agents now use Tool Search when its setting is omitted and higher-precedence Code Mode is inactive, discovering relevant tools as needed instead of receiving every eligible tool’s full description upfront. You can turn it off in Labs or set tools.toolSearch to false; restoring direct tool descriptions also requires Code Mode to be inactive. Extra discovery turns can cost more, particularly with a small tool catalog.Existing explicit settings keep their meaning. true selects the legacy Node code bridge, an empty object leaves Tool Search disabled, and Code Mode takes precedence. Codex’s native tool discovery is unchanged.
Code Mode now activates automatically for catalog-preferred models when the global setting is absent, including after an upgrade. Explicit false, an empty global object, or a global object containing only options stays off unless an agent or model override enables it. Haiku 4.5 remains available through explicit activation but is excluded from automatic selection, and native Codex Code Mode is unchanged.The default Node executor runs with the Gateway’s operating-system privileges and is not a security sandbox. Choose quickjs through tools.codeMode.executor for an isolated guest, or disable Code Mode when trusted Node execution is inappropriate. Explicit legacy quickjs-wasi choices migrate to QuickJS; choosing an executor alone does not force activation. An unavailable selected executor fails without falling back, and neither executor resumes cells after a Gateway restart.Code Mode now executes plain JavaScript only, while its tool discovery still provides typed documentation. This is a breaking change for existing TypeScript cells. Rewrite those cells without TypeScript-only syntax and remove both language and typecheck arguments, even when their values are "javascript" or false. Eligible startup migrations remove the old tools.codeMode.languages setting; otherwise run openclaw doctor --fix. Configuration migration does not rewrite your code.Tool inputs and results are checked at runtime, so a later error can occur after an earlier action has already completed. Structured results also reject BigInts, cycles, and failing serializers with catchable errors; convert those values explicitly to JSON-compatible data and keep your configured output limits in mind.
The GitHub reader brings public issues, pull-request discussions, commits, and expandable diffs beside your conversation, so you can inspect a reference without leaving chat. Tabs let you keep several items open, while previews and refreshable snapshots of automated checks help you follow the work. The reader is public-only and read-only, with private content and edits staying on GitHub; check results are bounded snapshots, not a merge-readiness verdict.Documents and previews use your configured GitHub identity to avoid unnecessary anonymous rate-limit failures. Screenshots load anonymously without cookies or credentials, supporting PNG, JPEG, GIF, and WebP files up to 2 MiB. If your installation uses a restrictive plugin allowlist, add and enable github while preserving its other entries to use the reader and previews.
Publishing a session’s work accepts valid recreated branches even when their reflog has expired, while preserving published history through ancestry checks and publication conditional on the exact observed remote branch. Concurrent branch changes are rejected, and later workspace edits cannot enter an already accepted snapshot. Publication errors now distinguish another operation holding the lock from unavailable storage or cancellation, making the next step clearer. A storage failure can be retried with the original request or checkpoint; cancellation before the operation acquires its lock is not automatically retryable. Canceled Doctor inspections are reported as not performed, rather than as a health result.Session writers can publish ordinary changes from sessions they created through the configured shared GitHub account. Membership in someone else’s session does not grant that right. Adding, editing, deleting, or renaming GitHub Actions workflow files, and publishing through a personal account, require full operator write permission. Queued requests stay tied to the original requester and accepted permission ceiling across restarts; a new invitation or later promotion cannot revive an ended grant. Results GitHub already accepted can still be recorded after a disconnect, but that does not authorize another write. Uncertain readback remains pending.This changes shared state to schema 18, which older versions refuse to read. Stop older writers and keep a verified pre-upgrade backup that captures data still in SQLite’s write-ahead log. Check recorded or uncertain GitHub effects before freshly authorizing unfinished legacy shared requests. To downgrade, use the matching older build and backup in a separate state directory; restoring local data does not undo changes already made on GitHub.
An agent that explicitly waits for delegated work can resume using supported owner-only plugin tools without requiring another message from you. Eligible sessions also retain their GitHub tools across supported harness continuations, with the same current permissions and publication approvals. Plugin authors must opt in to the owner-authorized continuation contract and check that authority immediately before an action; unrelated sessions and scheduled jobs gain no owner privileges.
Agents can discover configured cloud profiles and request an advertised operating system and machine size when starting a separate visible worktree session. The cloud-session tool path requires a live hosted Gateway, a supported provider, and the existing placement permissions. Failed or uncertain starts retain the session for inspection without silently running locally, so inspect that state before retrying. Work already assigned remotely also avoids provisioning an unrelated local Docker sandbox.
Worker launch failures now explain rejected commands and unconfirmed cancellation more clearly. Stopping a node environment attempts the remaining cleanup even if one part fails, and replacement work waits while cleanup is unresolved. This can leave capacity occupied until the old work is confirmed stopped, rather than starting another worker over it.Portable cloud workers now include the browser assets needed for provisioning and the SQLite executable needed for authorized shell commands, at the cost of a larger runtime download. After a Gateway restart, unstarted submissions can wait up to two minutes for retained workers to reconnect, capped by the turn timeout, with one retry and Stop still available. Work already handed off is not resent, and incompatible worker runtimes still need an update.Cloud workers also receive the conversation history preceding the request they are handling, even if later messages arrive during preparation. Supported retries before handoff retain that starting point and save the input only once.
Cloud workspaces can return larger rebases within increased transfer limits, and transfers work on POSIX hosts whose defaults create group-writable directories. The permission repair applies only to OpenClaw-owned directories, preserving transferred file modes and the host’s defaults. Large returns remain bounded at 500,000 before-and-after records and 768 MiB of changed content or patch data, with the existing 64 MiB per-file and 256 MiB compressed rollback limits.Uploads retain their frozen source files until transfer settles, stop further staging writes after access is revoked, and reject redirected parent paths during staging. Update the installed node runtime to receive the node-side manifest-preparation improvement; refreshing only the session bundle is insufficient.Applying cloud results and restoring rollback snapshots preserve exact supported filenames and file contents independently of Git attributes or checkout encodings. Canceling private preparation waits for staging cleanup to settle; the host filesystem’s filename restrictions still apply.
Supported host integrations can point the existing agent document editor and instruction readers at the workspace on a paired node, without maintaining a local copy. This requires an explicit workspace mapping, a compatible connected node, and separate file grants, with a 16 MiB document limit. If that workspace becomes unavailable, reads fail instead of using stale local files. Owner writes remain limited to the root AGENTS, SOUL, IDENTITY, and USER documents, and an already-dispatched write cannot be undone by disconnecting.
You can send uploaded files to the computer where an agent’s workspace lives and receive its finished files back in chat, with Memory files and supported workspace Skills available on that same computer. This requires an explicitly configured host integration, current file and command grants, and matching OpenClaw versions on the Gateway and paired node. Workspace Skills can be discovered, read, watched, and have their dependencies installed there; remote Skill source installation, updates, removal, and ClawHub management remain unsupported.Transfers default to 50 MiB per file, and uploads hold the admitted file in memory. If an enabled upload fails, the turn does not start without its file; missing or denied output files fail explicitly instead of returning stale local copies. Remove saved file.create grants before downgrading to an older version.
Fleet status shows whether a cell is recorded as using Docker or Podman, and ordinary registry reads see newly committed cell information. The recorded engine helps identify the configuration; it does not confirm that the engine is currently running.
Chat plugin cards update to Installed after installation, and agent guidance favors tools you already have before suggesting more from ClawHub. Plugin archives avoid development-only dependency failures, while incomplete npm installations name missing required dependencies and can be repaired by Doctor when eligible. Repairs deferred during an update may require another Doctor run afterward. Installation fixes also cover stale paths after moving OpenClaw, equivalent Windows directory names, and native dependency asset paths.Administrators can install directly from a plugin’s overview and follow stage progress and elapsed time through completion. Installation accepts the plugin’s declared capabilities without granting hook or model permissions, and policy warnings still require acknowledgment. Ready new plugins enable automatically, while missing required configuration or an existing disabled choice keeps them disabled. Disabled installed plugins put Enable first. The final response determines success, and uncertain outcomes retain protection against duplicate installation.Grouped, searchable settings bring related fields and permissions together, and Ask OpenClaw opens an editable, unsent help draft for the selected plugin. Administrators can explicitly reveal a stored literal API key for a declared field at the current configuration revision; secret references and environment values are not resolved or revealed. Damaged installations get recorded-source reinstall guidance rather than a misleading consent request, while complete plugins still require capability consent.
Plugin loading follows the current selected copy, profile, and configuration, including valid structured secret references. A failed setup keeps its original error without repeatedly initializing the same plugin, and repeated failures no longer bury distinct diagnostics in duplicates or remove healthy sibling tools. Packaged installations also skip unnecessary source parsing during plugin startup.Dependency warnings now recognize plugin IDs despite capitalization differences, valid stored-secret references avoid false setup errors, and malformed external schemas no longer prevent healthy plugins from loading. Invalid settings and malformed bundled schemas still fail.
Unchanged sibling plugins keep running when another workspace’s plugin changes, object keys reorder, or duplicate notifications report the same configuration. Changes to actual values, list order, sources, or policy still trigger the required refresh.A busy plugin reload can now refuse before stopping the serving runtime, keeping chat available while an active turn or its cleanup still needs that plugin. Active search and fetch calls retain their selected plugin files until the work actually finishes. Finish the work and retry a refused replacement; it is not queued automatically.Reloads already waiting for active calls can restore the previous runtime when its recovery files remain intact and the replacement cannot finish, including recovery after delayed cleanup succeeds within the existing 60-second window. A retirement timeout does not mean plugin files have been deleted, and cleanup that never finishes can still need operator attention.Replacement can also proceed when the old temporary source files have disappeared, with a warning that the previous code cannot be restored. If that replacement fails, the affected plugin remains visibly failed until a replacement succeeds.Requests crossing reloaded plugin code also retain their context and selected plugins, so provider hooks and failure handling use the intended request settings.
Growing plugin caches no longer consume a shared row quota that can block replies, execution records, or background jobs. Individual namespace, expiry, value, and blob limits still apply, but total storage can grow. Keep a verified pre-update backup if you may downgrade, because older versions restore the aggregate quota. Do not delete durable ownership records to make the data fit that older limit.
Managed model-catalog temporary files can now be reclaimed after a crash while live workers retain the files they need. Model discovery reuses an already loaded plugin’s files instead of creating duplicate copies, and ordinary CLI runs release their own scratch copies when they finish.Upgrade the host, inspect with openclaw doctor, then use openclaw doctor --fix during maintenance with no other OpenClaw producer running. On Linux and macOS, Doctor can reclaim eligible legacy captures only after a complete, fresh process check. Windows, recognized containers, and incomplete or ambiguous checks remain report-only. Live, changed, managed, foreign, and symlink-target content stays protected; age alone is not a reason to delete files, and reported sizes can overcount hardlinks.
Plugin-requested answer revisions wait for session history to become available, and required execution-start callbacks finish before the run continues. For plugin authors, a returned startup promise now delays startup and can fail it, so do not return unrelated background work. Worker-pool closure also waits for delayed preparation and cleanup and can report their errors. Cancel preparation waits before closing their own pool, since factories that never settle can keep closure waiting.Plugin authors also gain awaited conversation-binding inspection and activity APIs while existing synchronous APIs remain through their deprecation window. CLI and loopback MCP completion hooks again receive isolated outcomes and approved arguments without duplicate notification; these observers are best effort and do not block the tool, and results that cannot be isolated are skipped with a warning.
Local speech commands preserve intentionally empty quoted arguments, preventing later options from shifting into the wrong position. Ordinary replies also skip unnecessary Markdown parsing when OpenClaw checks whether they should be spoken, without changing speech policy or synthesis limits.
Background image, video, and music generation can complete independently of the request that started it, avoiding a wait cycle that could trap the originating request in completion work. Managed-image metadata reads also move off the Gateway’s main thread.Restored media-task status keeps the correct requester and current completion state. Media handling can fall back to a valid URL, and a staging failure preserves other attachments while retaining existing access and size limits.
PDF extraction keeps images of low-text or visual-only pages alongside selectable text, so a text-rich page no longer hides a neighboring diagram or scanned page. This affects extraction fallback; native Anthropic and Google PDF input is unchanged. More rendered pages can increase image-token charges, while the existing 20-page default selection, 200,000-character text cap, and shared four-million-pixel budget remain.
Logbook avoids fetching unused metadata when reading a range of frames, while returning the same public results.
Team Reports adds a Work sessions directory and overview preview with links directly to current conversations. Member reports also link to conversations their members currently own. These are current work views, not a reconstruction of ownership during an older reporting period, and existing viewer permissions and exclusions for archived, incognito, automated, system, and hidden sessions still apply. Stored reports, transcripts, and full downloads are unchanged.
Workboard loads the cards relevant to the selected work or conversation, so an unrelated damaged card no longer blocks those operations. Deleting an eligible empty board is also isolated from malformed notification subscriptions on other boards. Errors in selected cards still surface, and default or nonempty boards remain protected from deletion.Search now finds loaded cards by full ID or a case-insensitive prefix within the current filters. Blocked cards with parents explain how to unblock them before claiming, without changing eligibility or unblocking them automatically.
Session Share reads transcript-derived titles for the page you are browsing and batches creator lookups, reducing unnecessary reads while keeping the same discovery permissions and labels. Update the plugin on the source node to receive the page-scoped behavior; updating only the receiving side is insufficient. Searching still resolves titles before filtering.
DuckDuckGo search stops parsing additional results once it has the requested valid entries, preserving their returned text and snippets. The full response is still received and checked for bot challenges.Brave, Exa, paid Parallel, and Perplexity Search honor the requested number of structured results, including cached replies, and Brave’s LLM-context cache keeps different requested counts separate. Local trimming does not reduce upstream billing. Canceled or timed-out xAI searches stop waiting for credentials without later sending the search, while already-owned credential refresh and cleanup may finish independently. Search results also omit impossible calendar dates without dropping or reordering the results.
Geolocation continues using a valid downloaded database when saving its optional cache fails, and separate Gateways stage downloads independently. Cache failures produce a warning; invalid or failed downloads still use the existing cache.
Stopping or restarting ClickClack waits for accepted room creation and persistence to finish, helping those operations complete before the integration closes.

Security and Privacy

Permission checks now cover more of the moments when a chat starts, a file is read, or background work continues after its original request. These changes also make credential repair and access changes clearer for people operating OpenClaw.
Standalone tool calls now follow an authenticated operator’s agent and sandbox restrictions even when no saved session exists. Automation that relied on that exception may now be refused; callers required to use a sandbox must first create and target a recorded sandboxed session. Agent shell scripts also need to send reports through available attributed session tools or normal subagent completion, so their messages retain their agent origin. The shell marker used for this check is not authentication or isolation from other processes owned by the same user.Command errors now distinguish an unsupported command form from a human denial and explain how to retry through the approval flow. Unsupported forms remain blocked. The approvals guide also clarifies the existing approvals get --node and approvals set --node commands, with --file or --stdin supplying a replacement policy.Role restrictions now preserve the access they still permit, such as narrowing a write credential to read-only. Built-in tools retain their permitted default access, while explicitly supplied permission lists stay exact, including an empty list. Queued and delegated work keeps the initiating operator’s permission ceiling and respects later revocation; incompatible queued inputs wait in order instead of borrowing stronger permissions.
Sandboxed sessions can work on an authorized registered project with worktree: true in a private Docker or Podman checkout, with accepted changes returned to the managed worktree. Host Git credentials and ignored provisioning stay outside that checkout. Explicit read-only access remains read-only, and unsupported backends refuse this workflow. Later files created only on the host need git add before entering an existing private checkout. Let pending changes finish before downgrading, and use a supporting version to recover unfinished work, as described in managed project workspaces.File patches also recheck permission before changing files, and operator logs explain which workspace restriction rejected a patch without relaxing required roots. Automatic cleanup now follows each sandbox owner’s retention settings, so one agent’s shorter retention window does not prematurely remove another’s working environment.Sessions that require a sandbox now reject host-only native forks before creating the new conversation. If permissions change during creation, initialization stops and cleanup removes only the unfinished work still owned by that operation. Plugin authors should adopt sessionForkV2 and its checks immediately before native changes. The older sessionFork remains source-compatible through October 12, 2026, but does not gain those final checks.
Saving settings that display hidden secrets now preserves their real values, and OpenClaw rejects known redaction placeholders as credentials. If a stored Gateway token was already replaced by a placeholder, install this fix and run openclaw doctor --fix or openclaw doctor --generate-gateway-token. Doctor verifies a backup before repairing the token; then restart the Gateway and reconnect or re-pair devices with the replacement. Other corrupted secrets need a real replacement at their source.Background commands using the optional secret proxy on the Gateway host now keep HTTPS access after the originating turn ends. Each command retains its original secrets and allowed destinations until it stops. After changing credentials or bindings, stop older commands to revoke their access immediately and start a new run and command to use the changes. Exit, cancellation, timeout, and Gateway shutdown also revoke access. This proxy does not cover sandbox, remote-node, or provider-native shell execution.
Chat images, documents, and trusted audio now retain the requesting sender’s file restrictions throughout preparation. Pending reads and copies stop when access is revoked, the workspace or execution location changes, or the turn is canceled, and rejected preparation removes its newly staged files. Already-produced text remains available, while previously retained attachments keep their existing retention rules. These boundaries are covered in the Control UI security model.In Discord, /new and /reset in unbound channels now respect channel disablement, allowlists, group policy, and server command authorization before changing a session. Previously bypassed commands may now be refused, while existing configured-binding recovery exceptions remain available.
Cloudflare Access OIDC sign-in can reuse an existing OpenClaw profile, role, and history when the verified email matches a linked alias. Cloudflare admission and identity-provider email verification remain required; an unmatched email gets a separate profile with the configured default role. Tailscale profile-picture adoption also moves its database work off the main Gateway thread while preserving a picture you have explicitly chosen.Administrators can also opt into verified GitHub credit through OIDC by configuring the trusted issuer, provider, and account-ID claim. This adds coauthor credit without changing roles or the account used to publish. Conflicting identities need an explicit users.linkEmail action; missing configuration stays email-only, and malformed trusted claims are rejected.For the private, source-built Team plugin’s Visitor Access feature, invitation expiry or revocation now closes dependent Gateway connections and cancels affected active and queued work. Saved results and independent staff access remain available. Operators must apply the restricted Guest role’s accessPolicyPlugin: "visitor-access" binding as the final setup step; unavailable policy denies access, and older Gateways reject this field. Keep the binding and restrictions during recovery. The plugin remains excluded from ordinary npm packages. Failed Cloudflare policy cleanup still retries at startup or hourly and may leave provider access active until it succeeds, but it no longer extends the dependent local work. Cloudflare login sessions are not separately revoked, and an invitation issued after expiry requires fresh admission.
Switching session stores now stops delayed child-agent activity from bringing the old store’s context into a new conversation. Changing stores does not migrate conversations, and suspended child-result delivery needs explicit recovery even if you later select the old store again. Completed task results remain available; old watches whose store ownership is unknown need fresh registration. Separately, creating an incognito session with an explicit key checks for a collision without scanning unrelated durable history, while preserving existing isolation and authorization rules.Pending session previews and local tool inventories now recheck access and the exact conversation before returning content, while queued plugin context stays with its selected conversation across resets and conflicting names. Recovery continuations also check permission on their destination conversation. An ordinary disconnect does not cancel admitted work, but revoking its original permission can.
Secret masking avoids repeated scans of unchanged tool results and skips AWS credential checks that cannot match, while changes to output or redaction policy still trigger fresh checks. Transcript saving keeps its separate sanitization. Queued audit history writes and retention cleanup also move off the main Gateway thread. Audit collection remains best effort, so queue saturation, storage failures, or shutdown deadlines can still drop waiting metadata.Secrets audits now reject symlinked generated models.json files and keep malformed file contents out of error messages. These checks are read-only and limited to 5 MiB per generated model file; ordinary hardlinks and parent-directory aliases remain supported.
Substantively editing an automation now retires its previous Always allow approval, even if you later restore the old contents. Pausing and resuming an otherwise unchanged automation keeps its approval. Older grants without this binding need one fresh approval after upgrading, so unattended jobs may wait for you to approve their next matching operation. Standing automation approvals remain tied to the work you approved. Older binaries cannot enforce the new binding, and edits made by an older version without any observable record cannot be reconstructed after upgrading again.
An administrator can explicitly link a stable channel account to an existing person with users.linkChannelIdentity, then inspect or remove links with users.listChannelIdentities and users.unlinkChannelIdentity. Linked people who already have effective administrator access can use owner-only channel commands without duplicate owner lists. Display names and session identity links do not establish this connection, and channel restrictions still apply. Links do not expand conversation visibility or give a group the administrator’s authority. Demotion, unlinking, reassignment, or revocation blocks pending privileged actions; a replacement grant cannot revive the original request.
Administrators can grant operator.sessions.read and operator.sessions.write for conversation work without granting general settings, secrets, or administration access. A verified person with session-write access can create their own conversations using valid saved defaults or Gateway model and account selection, and Stop stays tied to the original run and caller. Shared read access does not grant permission to change someone else’s conversation. Explicit personal-account selection and changing defaults still require broader write access, and these permissions are not a boundary around just one session.Guests can also see and answer ordinary questions from their own authorized runs, including recovering pending questions after reconnecting. Joining someone else’s conversation does not reveal their questions. Secret, administrative, and sessionless prompts remain privileged, answers add no permissions, and a new grant cannot take over a question whose original authority was revoked.
The default gateway-only managed proxy mode now keeps localhost and literal loopback connections direct, fixing WebChat and Codex failures when their local model relay was sent through an external proxy. External destinations and non-loopback private, LAN, and tailnet traffic still use the proxy, while explicit proxy and block modes and application network-access checks retain their restrictions. Doctor now explains failed local connectivity; restrictive configurations may need gateway-only restored and a Gateway restart.
The shared Rust Gateway client updates Rustls to 0.23.45, including the fix for GHSA-2mjx-qc3c-rqvc.

Quality-of-Life Improvements

Everyday work gets clearer progress and less repeated preparation around tools, replies, and stored conversations.
Shared agent instructions more explicitly connect your corrections and an agent’s promise to check something with continuing the authorized work. They also tell an agent receiving delegated results to address fixable failed checks before stopping, while preserving approval requirements, pauses, and cancellations. These are guidance changes, so individual model behavior can still vary.
Configuration help now explains that skipBootstrap controls creating workspace files, while existing files can still enter the prompt. The workspace settings reference clarifies the existing contextInjection choices for the embedded runtime, including never. Those choices do not control ordinary CLI-backed prompt preparation or prevent an agent from reading files with tools.
Operators can add optional personal preference files at users/<canonical-profile-id>/USER.md in an agent’s workspace. Shared USER.md defaults load first, followed by at most one personal file selected for the assigned human session owner, or otherwise the authenticated human creator. Other participants can steer the conversation without replacing its running personal context, and reassignment takes effect on the next new turn, including queued work.This works with supported local embedded, generic CLI, and native Codex conversations, excluding ACP, realtime, and remote-worker execution. Files are operator-created, and profile merges require moving them manually. A missing selected file leaves shared defaults rather than choosing someone else’s file. These preferences do not isolate files or conversation history or grant tool permissions.
Progress and conversation history suppress repetitive checks while keeping useful updates and distinct failed, blocked, completed, or unknown tool outcomes recognizable. Your channel’s visibility settings still apply, so Telegram quiet mode can hide intermediate tool failures unless tool progress is enabled.
Help and read-only commands for hooks, nodes, sandboxes, and worktrees load less unused code. JSON agent and session listings also avoid repeated lookups or terminal-only display preparation while preserving their output.
Remote terminal typing and paste require less preparation, while tool-output redraws and scrollback reading avoid repeated work. On macOS and Linux, a terminal launched through Bun can also find a real Node installation when a shim hides it, keeping input and cursor keys working. A real Node installation is still required.
Compact tool previews omit extreme array nesting instead of overflowing the formatter, without changing the original arguments used to run the tool. Plugin authors using the display metadata helper should expect values beyond 64 array levels to be omitted and a possible undefined result. Suggestions after an unknown-tool request also avoid repeated lookup preparation.
When messaging tools offer only sending and broadcasting, their definitions take up less model context while keeping supported options. Automation descriptions also remove repeated argument lists, and large tool outputs reuse valid text counts during context checks and trimming. Context limits and trimming rules stay the same.
Agent requests skip unused diagnostics when debug logging is off, and media progress sections share a fresh task read within each turn. Large-request diagnostics and shell setup also avoid some repeated preparation before execution; these changes concern local setup work rather than media generation speed.
OpenClaw avoids some repeated local cleanup and rendering while receiving long replies containing comparison text or final-answer tags. The benefit depends on the reply, and the final-answer path can use more peak memory while reducing repeated processing.Further changes skip unnecessary scans in bracket-heavy prose, cleanup in final-tagged answers, and diagnostic checks that cannot yet emit an update.
Repeated conversation and state reads reuse eligible database connections and workers instead of repeatedly opening them. Healthy reusable resources can stay available for 30 idle minutes, reducing setup during intermittent activity while reads continue to see current data. Larger active installations can consequently retain more memory and open file handles during that window.Node workers can now reclaim unused heap after completed operations while remaining available for reuse. Automatic retirement of idle workers under critical memory pressure requires diagnostics to stay enabled; idle garbage collection works independently and skips Bun. Applicable workers also request a 512 MiB old-generation heap cap, which can constrain large active operations.
Bursts of conversation writes leave more opportunities for other work to proceed, and saving large replies or tool results shortens the time other writers can be held up. Small requests arriving during startup or reconnect can wait up to 10 seconds for capacity instead of failing immediately, while memory and oversized-request limits still apply. Lookups through large task and conversation histories also inspect fewer unrelated records.Selected identity, profile, command-authorization, pairing, and conversation-membership operations now move database work off the request thread, and prepared conversations can resume without waiting for unrelated writers. Pairing has an important cancellation limit while a pairing change is pending. A local abort or timeout may leave remote work running, so it is not confirmation that the remote operation stopped.Settings saves can now refresh configuration health asynchronously while keeping late or canceled refreshes from overwriting newer settings or environment values.
Live conversation updates avoid preparing duplicate message data that would be replaced before delivery. Each recipient still receives the version allowed by their permissions, with the existing per-client preparation intact.
Creating an eligible session now queues a notice for its agent’s Home conversation, including the session key and available title, creator, and creation source without copying messages. This is enabled by default, and you can opt out with session.notifyOnCreate: false in session settings. Home receives the notice on its next turn or scheduled heartbeat, without an immediate wake-up or ongoing monitoring of that conversation.Drafts, incognito sessions, hidden internal sessions, scheduled cron runs, and Home itself are excluded. Reopening or resetting an existing session does not send another notice, and pending notices do not survive a restart.
The 2026.9.1 release guide gains interface illustrations and labeled conceptual examples to explain that older release. The figures document existing capabilities, with fictional and conceptual examples identified as such.

Other Bug Fixes

These fixes address interrupted work, misleading command failures, and database waits that could get in the way of everyday use.
Stopping a chat turn now interrupts optional idle waits and affected cleanup reads that were waiting on a stalled history rebuild. Required saves and cleanup still run, saved answers and attachment references remain intact, and an interrupted delivery check stays pending until its outcome is known. Completions canceled during connection setup now stop before contacting the provider, and PDF or image-analysis fallbacks also stop if their prepared resources are no longer valid. Requests already sent retain their existing cancellation limits.Manually canceled background commands no longer trigger an unwanted follow-up reply just because they produced some output. Their logs remain available through process poll and process log, and cleanup failures still notify. Confirmed process cleanup is retained accurately, while an unconfirmed stop remains uncertain. Process cleanup also recognizes an exit confirmed at the existing deadline. Database cleanup at process exit makes one automatic attempt, leaving failures for explicit recovery instead of repeatedly retrying and flooding logs.
A terminal on a paired node now reports a timeout and removes its local terminal session after the existing 30-second inactivity limit, even if the node never sends its first heartbeat. Each heartbeat renews that limit. OpenClaw requests cancellation once, but the local timeout does not confirm that the remote process has stopped.
Commands that stop reading their input early now return their actual exit status and error output, avoiding misleading broken-pipe failures. File edits also recover from limited newline and backslash encoding mistakes in replacement lists sent as strings, while preserving the intended literal text. Incomplete lists and malformed outer requests still fail validation without applying a partial edit.Failed command launches preserve the original operating-system error, and valid JavaScript using dollar-prefixed names or dollar text now reaches Node without being mistaken for shell syntax. Node reports its own errors, and statements before a runtime error may already have run. An identical replacement repeated across batch and legacy edit arguments is applied once, while genuine duplicates within a batch and conflicting edits still fail without writing.
Optional archive cleanup now waits for a later opportunity when the database is busy, instead of holding up OpenClaw. Work already accepted can finish before a database worker closes, and saving device tokens or task information avoids additional waits on the main process. State directories reached through filesystem aliases, such as macOS /var and /private/var, also avoid a timeout caused by treating those paths as different locations. Fully received results survive cleanup failures, while writes with an unknown outcome are not automatically repeated. Database requests also avoid being refused prematurely just because a busy Gateway has not yet made its access decision.
Shortened update Doctor warnings and Skill Workshop error records avoid leaving half of an emoji at the cutoff. An affected emoji is omitted whole, so shortening the message does not introduce a broken-character symbol.
Commands give more useful feedback for invalid agent selections and empty node invocation keys, and plugin and skill listings preserve version labels without adding duplicate prefixes. If a request times out or loses its connection after being sent, the message now advises checking its current state before retrying, because the operation may already have completed.
The terminal interface restores your remembered conversation even when newer conversations have similar names, and can show its model details without relying on a short search-results list. After reconnecting, old connection responses can no longer replace the current details. Existing agent scope and hidden-conversation rules still apply. Opening or attaching to a conversation now uses the agent identified by the Gateway, including when an older link names a different agent. Replies and side-question results from other agents are rejected, with existing attachment permissions unchanged.
When a long terminal-upload filename needs shortening, the resulting name still follows the portable rules for reserved names and trailing characters. This applies to newly staged uploads and leaves existing filenames alone.
Temporary-directory checks no longer reject valid filesystem identifiers just because they use signed numbers. The shared filesystem dependency carries the fix into OpenClaw and components that use it directly.

Maintainer and Internal Changes

This release includes 1175 maintainer and internal changes covering tests, development tools and implementation upkeep. The topics below keep the full change list and contributor credits available for people working on OpenClaw.
Coding-agent and provider tests use more controlled startup, clocks and cleanup, helping failures point to the behavior under test. Shared fixtures retain coverage for model selection, streamed responses and credential preparation.
Database tests finish pending work and close their readers before removing temporary files. Suites also reuse prepared databases where appropriate while clearing each case’s state.
Agent execution, sessions and scheduled work share more of their existing preparation and cleanup code. These changes remove repeated lookups, temporary copies and unused imports while retaining current routing and recovery rules.
The temporary extension of tool and model duration histograms was reverted, leaving the existing finite buckets ending at ten seconds. Anyone who deployed the brief main-branch extension should compare common bucket boundaries or keep observations separate across the rollback. The source list also retains credit for a codec-import repair whose merge added no further changes.
Swift and Android tests reuse preparation and wait for observable readiness, while Apple catalog checks follow the current app text. Windows lifecycle fixtures retain their compiled files until cleanup completes.
Gateway and command tests coordinate startup, background work and teardown more explicitly. Isolated ports, profiles and workspace fixtures help preserve coverage for complete workflows without letting unrelated activity interfere with assertions.
Media handling and browser snapshot processing reuse information already prepared during the same operation. Shared parsing and formatting helpers retain existing attachment selection, transcription requests and browser output.
Credential preparation and permission checks share existing helpers and avoid repeated reads or unused data preparation. The work retains current account selection, access rules and redaction behavior.
CI planning accounts for current test costs and runner capacity, with fixes for cache matching and job allocation. Failure reports retain more useful diagnostics, and standalone Control UI uploads are limited to sanitized summaries. Some expensive matrices now run only in full validation or when their test files change, so source-only regressions may be found later. Compatible Linux PR and UI tests can use pinned Bun routing while required Node coverage remains.
Control UI tests control clocks, focus and viewport state and wait for rendered elements before checking them. Shared fixtures reduce repeated setup while preserving coverage for chat, navigation, sign-in and appearance.
Fresh source dependency installs use cloned or copied package files so an install in another checkout cannot falsely invalidate active compiler inputs. Existing hardlinked installs need a fresh checkout and install, and copy fallback can use more disk space, as explained in the local testing guide. Build and typecheck fixes also cover Windows paths with spaces, selected compiler runtimes and custom Control UI output directories.
Process tests wait for the intended child to start and finish, use the required runtime and retain diagnostics when cleanup is incomplete. Controlled clocks remove fixture delays while preserving production timeout settings.
PR tools provide clearer checkout, review and merge diagnostics and avoid repeated GitHub metadata requests. Supported REST paths can continue selected operations after GraphQL quota exhaustion, with reviewed-revision and merge-approval requirements still enforced. Eligible GraphQL paths also handle exhausted REST quota or persistently unknown mergeability, using the actual merging account for policy checks. Recovery of inspected refusals before submission retains fresh approval and identity checks; accepted or ambiguous merge attempts are never replayed.
Command setup and diagnostic formatting avoid unused imports, repeated scans and temporary copies. Displayed results and selection behavior remain the same.
Messaging integrations share configuration types, formatting and account-preparation helpers. This maintenance retains existing routing, account ownership and attachment choices.
Messaging tests isolate credentials, temporary paths and background work, and wait for delivery or cleanup to reach the state being checked. Shared fixtures retain each channel’s existing regression scenarios.
Configuration handling separates pure traversal from file access and reuses validation inputs. Existing settings, error reporting and reload decisions remain intact.
Contributor guidance clarifies test-failure investigation, focused verification and database access, with updated technical references and remote-test instructions. Generated maturity reports continue to show evidence gaps alongside completed checks.
Repository review notices identify the revision, affected files and approvals contributors need. Review routing separates maintainer approvals from SecOps-owned files, whose independent merge enforcement depends on the repository ruleset.
Control UI maintenance consolidates queued-message cleanup, session preferences and subscriptions under their existing owners. Rendering also reuses unchanged favicon colors.
Database and filesystem code share bounded reads, query preparation and record conversion, with selected database work moved to existing workers. Stored formats and data-ownership rules remain unchanged.
Compatible dependencies and generated metadata have been refreshed within the existing release-age policy. Required version holds remain in place.
Update and package tests reuse isolated preparation and distribute independent scenarios across workers. Fixture repairs preserve checks for historical upgrades, service replacement, migration and backup ownership.
Local test tools reuse verified compiled workers where supported and keep large test inventories complete. An optional offline Gateway test path is available for trusted, keyless tests on Linux with rootless Podman and a matching prepared image and toolchain; it does not support SELinux, external network access or automatic fallback to host execution.
Localization maintenance removes entries whose interface text has already been retired and shares Android quote-validation logic. Active translations remain unchanged.
Memory file watching is separated from indexing, and diagnostics and search-result preparation reuse existing information. This is maintenance of the current Memory implementation.
Model and provider processing avoid repeated catalog searches, metadata preparation and response parsing. Selection precedence, permission checks, provider output and fallback rules remain intact.
Shared native clients gain interfaces and cross-language contract checks for continued development, alongside consolidated Apple Watch status formatting. The shared-client groundwork does not activate a new macOS sidecar.
Release tools improve package checks, publication readback and recovery of interrupted work while preserving exact-package verification and explicit approvals. Optional early activation remains off by default and is limited to direct core publication; using it can leave the release page public while Docker distribution is still incomplete. Authorized extended-stable publication can create a GitHub release page without moving Latest, with bounded waits for npm visibility and explicit operator-approved waiver handling.
Benchmarks distinguish startup preparation from completed work and retain more useful installed-package diagnostics. These changes improve how performance is measured and compared without establishing an application speedup.
Plugin tests cover asset lookup across installation layouts, cleanup after failed preparation and package lifecycle behavior. Their fixtures isolate database state and temporary dependencies while retaining existing assertions.
Plugin loading and catalogs avoid repeated path resolution, unused metadata reads and temporary allocations. Existing tool behavior, migration history and execution ownership are preserved.
QA Lab keeps Evidence Archive filters within their toolbar and rejects replay reports with missing runtime results. Channel test tools also improve credential-fixture cleanup and retain clearer bounded failure diagnostics. Existing scenarios are selectable, and QA Lab controls and links receive layout and refresh fixes. Slack and Discord readiness tools require provisioned credential pools; Slack message checks make explicitly requested test writes, while Discord’s read-only checks do not establish write permissions. API receipts, Gateway replies and actual client rendering remain separate checks.
Historical release pages, plain Markdown mirrors and illustrations preserve earlier release records. Operator references clarify release handoffs and recovery procedures.
Crabbox reports classified fetch failures without exposing raw private Git output and waits for cancellation cleanup. It can inspect and recover verified abandoned local staging, while keeping copies whose ownership or cleanup remains uncertain. Testbox validation stays in the selected checkout, restores targeted source uploads and accepts verified Microsoft OpenSSH installation locations on Windows. Stop and rewarm existing Testbox leases after preparation updates; support for live staging on filesystems without flushing does not permit recovery of unverified abandoned copies.
Skill installation separates file operations from policy, and status checks avoid unnecessary installer loading. Workshop review status and skill-filter checks reuse their existing inputs without changing installation or review behavior.