Releases: openclaw/openclaw
Release list
OpenClaw 2026.8.1-beta.2
2026.8.1
Highlights
- Secret egress host binding: bind each shared-store secret to exact HTTPS destination hosts across CLI, Gateway RPC, and Control UI so unbound sentinel substitution fails closed before plaintext egress. Thanks @shakkernerd.
- GPT-5.6 Ultra and runtime switching: support Sol, Terra, and Luna across OpenClaw and Codex engines; keep model, runtime, and thinking selection atomic through
/modeland fallback; and add live matrix coverage for both harnesses. Thanks @anyech and @vincentkoc. - Channel plugin ingress monitors: add a shared plugin SDK monitor for durable admission, polling, pruning, claim identity validation, adoption handoff, and shutdown, and migrate IRC, Synology Chat, and Google Chat to the shared lifecycle. Thanks @vincentkoc and @shakkernerd.
- SQLite snapshots: add
openclaw backup sqlite create|list|verify|restorefor compact, verified global and per-agent database artifacts with fresh-target-only restore. Thanks @giodl73-repo. - macOS app profiles: isolate named app instances across state, preferences, Keychain, Gateway services, and duplicate-instance ownership while keeping host-global login and node services untouched. Thanks @shakkernerd and @vincentkoc.
- Plugin install provenance warnings: require explicit
--forceacknowledgement for arbitrary executable plugin sources in CLI and chat installs, keep trusted ClawHub, bundled, official-catalog, and tracked-update flows frictionless, and restrict Crestodian installs to trusted sources. Thanks @jesse-merhi and @vincentkoc. - Control UI update recovery: the "A new version is available" Reload button now waits out the gateway restart that stranded the chunk and reloads as soon as it answers, instead of silently doing nothing and leaving a manual hard reload as the only way out. Thanks @vincentkoc.
Changes
-
Secret egress host binding: bind each shared-store secret to exact HTTPS destination hosts across CLI, Gateway RPC, and Control UI so unbound sentinel substitution fails closed before plaintext egress. Thanks @shakkernerd.
-
Release validation: defer beta candidate Parallels smoke to postpublish
release:beta-smokeby default, keep stable/full prepublish coverage, and bound nested release workflow monitors with explicit job timeouts. Thanks @vincentkoc. -
macOS app profiles: isolate named app instances across state, preferences, Keychain, Gateway services, and duplicate-instance ownership while keeping host-global login and node services untouched. Thanks @shakkernerd and @vincentkoc.
-
Developer workflow: remove the obsolete scoped-commit helper and use standard Git commands in isolated worktrees.
-
Plugin uninstall cleanup: remove exact recorded install paths from
plugins.load.pathsfor marketplace, npm, and other managed installs while preserving parent, child, prefix, and unrelated paths. Thanks @vincentkoc. -
Fixed Crabbox hydration on unprivileged cloud sandboxes by falling back to a user-writable pnpm store when the shared
/var/cache/crabboxcache is unavailable, preserving the hardlink import mode after hydration, and making Docker an explicit routed capability instead of an implicit install requirement. Thanks @vincentkoc and @joshavant. -
Browser extension relay CDP compat: answer
Target.getBrowserContextsso Puppeteer-based clients (chrome-devtools-mcp) can drive the paired Chrome without the remote-debugging permission prompt, serve DevTools-style/json/listtarget descriptors, and addopenclaw browser extension cdpto print the relay endpoint plus auth header for external CDP clients. Thanks @vincentkoc. -
Local model setup: advertise provider-owned Ollama, llama.cpp, and LM Studio setup choices to Control UI and macOS, retry unavailable LM Studio services in place, and verify the exact prepared model before showing success. Thanks @vincentkoc.
-
Control UI first-run setup: continue verified model setup into Custodian, explain that the web app is ready without a channel, and offer an optional dismissible path to Channels.
-
Fish Audio speech: add hosted S2.1 synthesis with streaming, voice notes, voice discovery, and telephony, plus local Fish S2 Pro reference-voice streaming in native macOS Talk. Thanks @Conan-Scott, @vincentkoc, and @Patrick-Erichsen.
-
Control UI cloud workspace conflicts: surface staged-ref guidance, bounded conflicted paths, structured transcript events, and sidebar attention for cloud worker results that kept local versions. Thanks @vincentkoc.
-
Control UI update recovery: the "A new version is available" Reload button now waits out the gateway restart that stranded the chunk and reloads as soon as it answers, instead of silently doing nothing and leaving a manual hard reload as the only way out. Thanks @vincentkoc.
-
Control UI sender identity polish: attributed user messages show the author's real avatar in an always-visible gutter on identity-resolving gateways, sender labels drop the opaque profile-UUID suffix (new and historical transcripts), and profile-id senders resolve avatars through the canonical gateway route. Thanks @shakkernerd and @vincentkoc.
-
Control UI who's-online roster: click the sidebar footer facepile to open a scrollable roster of everyone online, showing each person's avatar, name, and email with your own entry pinned first.
-
Discord and Slack native login: register
/loginin native command menus while keeping pairing-code issuance limited to private chats and the Web UI. -
Control UI user profiles: let trusted-proxy users manage their own display name and avatar, resolve attributed chat and presence identities through uploaded avatars or a private cached Gravatar proxy, and keep other users' profiles admin-only. Thanks @vincentkoc.
-
Trusted-proxy browser pairing: optionally auto-approve new Control UI and WebChat devices from allowlisted proxy identities with non-admin scope caps, while keeping existing-device upgrades manual. Thanks @vincentkoc.
-
Channel plugin ingress monitors: add a shared plugin SDK monitor for durable admission, polling, pruning, claim identity validation, adoption handoff, and shutdown, and migrate IRC, Synology Chat, and Google Chat to the shared lifecycle. Thanks @vincentkoc and @shakkernerd.
-
Dashboard MCP apps: pin originating-session MCP app views as living dashboard widgets, renew their sandboxed view leases, and keep tool interactivity behind revision-bound grants with graceful stale-state recovery. Thanks @vincentkoc.
-
External gateway supervision: add
OPENCLAW_SUPERVISOR_MODE=externalfor lifecycle owners such as OCM, preserving verified restart and deferral behavior without exposing native service authority, blocking native service mutation and self-update, and providing a versioned atomic restart-handoff consume contract. Thanks @shakkernerd. -
Buzz message fidelity: preserve Markdown output and accept Buzz normal, rich-content, and structured-diff room messages through the existing authorized inbound path. Thanks @shakkernerd, @vincentkoc, and @zw-xysk.
-
Buzz typing indicators: show room- and thread-scoped typing during agent replies and heartbeat deliveries, refresh through the active authenticated connection without waiting for relay acknowledgement, and drop ephemeral updates safely during disconnects or shutdown. Thanks @shakkernerd and @vincentkoc.
-
Buzz sender directory: expose current bot, member, room, and room-member directory entries from bounded relay state; use current Buzz profile and room names in inbound context while preserving public keys and UUIDs as stable authorization and routing identities. Thanks @shakkernerd and @vincentkoc.
-
Buzz native mentions: resolve unique current room-member names and explicit NIP-27 identities into native
ptags for replies, proactive sends, and bounded standalone delivery; reject out-of-room identities and unresolved labels without an explicit identity, and preserve Buzz reply-thread session parsing during maintenance and heartbeat runs. Thanks @shakkernerd, @vincentkoc, and @joshavant. -
ClickClack guided setup: configure ClickClack from
openclaw onboardoropenclaw channels add clickclackwith URL, token, and workspace prompts, default-account env fallback, nonfatal live connection validation, and gateway-aware next steps that connect automatically when OpenClaw is already running. Thanks @shakkernerd and @vincentkoc. -
ClickClack command menus: publish each bot's native OpenClaw commands to ClickClack composer autocomplete at gateway startup, with per-account opt-out and nonfatal compatibility handling for older tokens and servers. Thanks @shakkernerd and @vincentkoc.
-
ClickClack bot collaboration: add opt-in bot-authored inbound dispatch with explicit sender authorization, mention gating, retry-safe loop protection, and independent thread budgets while keeping bot traffic denied by default. Thanks @jjjhenriksen, @shakkernerd, and @vincentkoc.
-
Skill Workshop approvals: run agent-initiated apply, reject, and quarantine actions without an additional approval prompt by default while preserving
skills.workshop.approvalPolicy: "pending"as an opt-in approval gate. Thanks @shakkernerd and @vincentkoc. -
TUI fuzzy selectors: delegate list matching to pi-tui, adding slash-token and alpha-number matching while removing the local matcher fork.
-
macOS paired-node terminals: advertise duplex Codex and Claude terminal resume commands from the embedded node host and forward interactive input and cancellation through the native app bridge. (#107335) Thanks @vincentkoc.
-
Control UI catalog terminals: open eligible Codex and Claude Code sessions in the native CLI on their Gateway or paired-node host, with viewer-versus-terminal preferences, validated resume commands, and an interactive PTY relay. Thanks @vincentkoc.
-
Control UI coding catalogs: show provider brand icons beside Cl...
openclaw 2026.7.1-2
Fixes
- npm plugin updates: accept singleton-array metadata from newer npm clients so tracked official plugins can install and update to correction releases. (#108336)
openclaw 2026.7.1-1
Fixes
- Codex progress replies: keep app-server turns running after delivered progress messages so GPT/Codex reaches its authoritative terminal response instead of stopping mid-turn. (#106961, #108487) Thanks @joshavant.
- Memory Core startup repair: recover derived legacy-index and cache-sidecar conflicts without trapping the Gateway in a fatal restart loop, while keeping structural vector-store corruption retryable. (#107220, #108652) Thanks @goutam-adwant.
- WSL state permissions: tolerate
EROFSfrom guarded chmod operations only when the existing state path is already private, preserving fail-closed handling for broad permissions. (#108250, #108258) - Legacy migration recovery: keep reviewed migration residue nonfatal during startup instead of blocking otherwise healthy upgrades. (#106101)
- Managed plugin updates: recover stale npm lock metadata so official managed plugins can update cleanly. (#107294, #107866)
openclaw 2026.6.34
2026.6.34
Highlights
- Safer browser and network boundaries: sandboxed browser routes, trusted DNS targets, custom browser origins, and loopback provider endpoints now reject unsafe access paths. (#97958, #38290, #103075, #110693) Thanks @eleqtrizit, @brunowowk, @mosidevv, @pgondhi987, and @lsr911.
- More resilient agent and provider runs: retained session writes, provider fallbacks, stream progress handling, and stdio failures now recover without silently ending active work. (#96100, #97128, #90908, #99803, #100521) Thanks @xialonglee, @sallyom, @richwilson-bloom, @LiuwqGit, @vincentkoc, @yetval, @shengting, and @cxbAsDev.
- Stronger channel recovery: pending channel work resumes after recovery, acknowledgements are idempotent, and sustained Discord gateway bursts stay bounded. (#79811, #97041, #104919, #109108, #110954, #103793, #94016) Thanks @indulgeback, @cuiyuxin-gif, @Pick-cat, @Glucksberg, @evan-YM, @zhangguiping-xydt, @yetval, @sheyanmin, and @thomasthelen-kibeauftragter.
- Safer operator diagnostics: command and status surfaces keep owner-only actions protected and prevent credentials from appearing in account URLs or summaries. (#98260, #107754, #105017) Thanks @eleqtrizit, @joshavant, @ooiuuii, @aniruddhaadak80, and @tzy-17.
- More robust local runtime state: SQLite checkpoints, workspace reads, gateway process signalling, plugin HTTP responses, and dependency handling no longer turn transient host conditions into failed runs. (#99067, #100910, #102125, #109590, #112406) Thanks @ooiuuii, @masatohoshino, @vincentkoc, @mushuiyu886, and @krissding.
Changes
- Extended-stable hardening: this maintenance release carries targeted security and reliability repairs without adding new release-line features.
Fixes
- OpenCode Go: use the documented
hy3model identifier instead of the failinghy3-previewalias. - Codex native subagents: retain the parent app-server subscription and recognize multi-agent V2 child activity until a yielded child completion reaches its requester.
- Dependency security: updates production dependency resolutions for patched
brace-expansion, PostCSS,fast-uri,ip-address, and Undici versions. (#113428, #118804) - Execution and transport safety: browser, sandbox, exec, MCP, and secret-resolution paths reject unsafe inputs and handle stream failures without crashing the host process.
- Delivery and channel stability: outbound receipts, delivery evidence, channel lifecycle, health monitoring, and gateway queues recover cleanly under retries, restarts, and overload.
- Gateway and storage reliability: plugin responses, process probes, workspace bootstrap reads, and SQLite writes tolerate expected transient failures while preserving correct state.
Upcoming deprecations
- Plugin SDK migration:
before_agent_start, rootopenclaw/plugin-sdkimports,providerAuthEnvVars, andchannelEnvVarsare scheduled for removal after July 24. Migrate to the modern hook stages, focused SDK subpath imports, and manifest setup descriptors. See Plugin SDK migration and plugin manifests.
Complete contribution record
This audited record covers the complete v2026.6.33..496c84b history plus release-validation backports: 25 merged PRs. The generation manifest also supplies direct commits as editorial input; the grouped notes above prioritize user impact.
Pull requests
- PR #96100 Related #95915. Thanks @xialonglee, @sallyom, and @richwilson-bloom.
- PR #79811 Related #79753. Thanks @indulgeback and @cuiyuxin-gif.
- PR #97041 Thanks @Pick-cat and @vincentkoc.
- PR #97128 Related #96518. Thanks @LiuwqGit, @vincentkoc, and @yetval.
- PR #90908 Thanks @shengting.
- PR #97958 Thanks @eleqtrizit.
- PR #98260 Thanks @eleqtrizit.
- PR #99803 Thanks @cxbAsDev and @vincentkoc.
- PR #99067 Related #99066. Thanks @ooiuuii.
- PR #100521 Thanks @cxbAsDev.
- PR #100910 Thanks @masatohoshino and @vincentkoc.
- PR #102125 Thanks @mushuiyu886.
- PR #38290 Related #46520. Thanks @brunowowk and @mosidevv.
- PR #103075 Thanks @pgondhi987.
- PR #104919 Related #104903. Thanks @Glucksberg and @evan-YM.
- PR #107754 Related #98633, #102932, #105427. Thanks @joshavant, @ooiuuii, and @aniruddhaadak80.
- PR #109108 Thanks @zhangguiping-xydt.
- PR #105017 Thanks @tzy-17.
- PR #109590 Thanks @krissding.
- PR #110693 Thanks @lsr911.
- PR #110954 Thanks @zhangguiping-xydt.
- PR #103793 Thanks @yetval.
- PR #94016 Related #94008. Thanks @sheyanmin and @thomasthelen-kibeauftragter.
- PR #112406 Thanks @vincentkoc.
- PR #107938.
Release verification
Extended-stable Gateway release: npm and container images only. GitHub Releases has one repository-wide Latest flag, not a per-channel Latest; this page is intentionally not Latest. The npm and container extended-stable selectors currently resolve to 2026.6.34.
- npm package:
openclaw@2026.6.34 - npm registry tarball:
openclaw-2026.6.34.tgz - npm integrity:
sha512-Rm4khBrWn9HYqE99NBryCFgjwlsIuwBqK5jIANn2773CGXJ1JIZkDn5twEHB+8SVFdh0FPNPHRVgZepzNJDfHg== - npm signatures and SLSA provenance attestation are published
- Container images: GHCR and Docker Hub, with exact tags
2026.6.34,2026.6.34-slim, and2026.6.34-browserfor amd64 and arm64 - Container manifest digests: default/slim
sha256:47d342bafe83bd3b2dca6f1d8d8b608ba7b542a1952564960648943346206759; browsersha256:55203a7abced818c0378aac0a128a2fceee5448c08f36be7e0058762a3b3ff41. The matchingextended-stable,extended-stable-slim, andextended-stable-browseraliases resolve to those same digests in both registries. - Release commit:
5c38f996d4059ebd9080cf74dc611ec3a17f4d50 - Successful release workflows: npm preflight, Full Release Validation, plugin npm publish, and Docker Release
openclaw 2026.7.2-beta.7
2026.7.2
Highlights
- State safety and recovery: protect persisted data with a quarantine store that survives primary-database damage, crash-recoverable SQLite snapshots, crash-durable filesystem publication, schema-upgrade data-loss rejection, and rollback-writer snapshot recovery. (#110453, #113367, #113453, #113473, #113580) Thanks @vincentkoc.
- Durable channel delivery: keep accepted messages recoverable across gateway restarts and local crashes through the shared ingress drain and dead-letter recovery, covering Telegram, Signal, Slack, QQBot, Twitch, Synology Chat, Tlon, IRC, and Zalo User. #108656, #107246, #109911 (#108924, #107288, #109907, #109910, #110844, #110852, #110899, #110910, #110914, #110916, #111029) Thanks @obviyus and @edenfunf.
- Session rewind and branching: rewind or fork conversations from individual messages, switch transcript branches across web and native apps, fork upstream Codex sessions, preserve branch-safe queued sends, reject stale-pane writes, and restore prompt images after a fork. (#110660, #110857, #110886, #111149, #112056, #112284, #113073, #113945) Thanks @vincentkoc.
- Interactive MCP Apps and dashboards: host ticketed MCP Apps with bound tools, resources, and bounded context updates; open them from channel replies, pin them to durable dashboards, harden their shared sandbox, and let native plugins declare them directly. #109851, #110451, #113218 (#109861, #109807, #110515, #111211, #111212, #111524, #111687, #111748, #113224) Thanks @fuller-stack-dev.
- Questions and approvals everywhere: let agents ask structured questions with option cards across web, channels, macOS, and native apps, while approvals gain push notifications, history, fair queuing, headless resolution, Claude tool-request relay, reviewer detail, and clearer formatted prompts. #85954 (#108505, #108709, #108776, #109922, #110242, #110372, #110584, #110681, #110989, #111060, #112918, #113027, #113193) Thanks @omarshahine.
- Meetings and realtime Talk: join Teams, Zoom, and Google Meet calls with default-enabled meeting plugins and durable transcript collection, while realtime Talk adds OpenAI and Gemini video and requires a supported OpenAI Platform API key instead of the rejected Codex OAuth fallback. #86425, #113353, #115021 (#109579, #109719, #109964, #111048, #113022, #113053, #113122, #113354, #115211) Thanks @shushushv, @Solvely-Colin, and @vincentkoc.
- Wear OS companion: add the phone-proxied Wear companion with home-screen agent/session/model selection, realtime Talk controls, audio-reactive playback, and an instant-talk tile. #108781 (#108835, #109341, #109433, #109483, #110661, #111516, #112721) Thanks @sibbl, @IWhatsskill, and @Solvely-Colin.
- Guided setup and local inference: guide setup across browser, Linux, and macOS with local-provider detection, strongest-model selection, downloadable models, lean mode, memory imports, and an in-process RAM-gated llama.cpp/Gemma path. #108604 (#108605, #108868, #108977, #109250, #109444, #109585, #110054, #110141, #110596, #113476)
Changes
- Models and providers: add Claude Opus 5 across catalog and runtime, Kimi K3, and GPT Live realtime support with the supported Platform API authentication path. (#113391, #113392, #113633; related #113412; #113909, #113354; related #113353) Thanks @fuller-stack-dev, @vincentkoc, and @Solvely-Colin.
- Local inference and setup: detect local inference providers during onboarding, add in-process llama.cpp GGUF inference and Baseten Model API support, discover models from live provider catalogs, and offer model downloads from web and macOS setup. (#108605; related #108604; #109444, #108708; related #108665; #112412; related #112405; #113476) Thanks @fuller-stack-dev.
- Sessions and dashboards: add rewind/fork and branch switching across web and native chat, session boards and dashboards, archived/visibility/draft/incognito session states, and suggestion queues with typing indicators. (#110660, #110857, #110886, #111149, #110644, #110960, #112554, #112787, #113006, #113127, #113173)
- Native apps: bring Quick Chat to macOS and Linux with streaming, routing, context capture, dictation, and model controls; add Linux desktop integration and signed updates; add multi-gateway apps and mobile dashboards; and expand Wear OS companion/Talk support. (#109720, #109947, #110285, #110631, #110632, #110635, #110994, #109236, #108770, #111932; related #111931; #112163, #109341, #109433; related #108781; #109483, #112721) Thanks @sibbl, @IWhatsskill, @Solvely-Colin, and @vincentkoc.
- Meetings: add Teams and Zoom meeting guests, enable Teams, Zoom, and Google Meet plugins by default, and automatically collect durable meeting transcripts. (#109964, #111048, #113022, #113053, #113122)
- Channels: add the Buzz plugin, Slack user-identity and Agent View modes, Telegram Bot API rich blocks and native Markdown lists, and richer Matrix formatting. (#113419, #109837, #103895; related #103673; #107986, #113158, #113199) Thanks @Patrick-Erichsen and @obviyus.
- Browser and MCP Apps: add a secure per-tab browser copilot, batch browser CLI, bounded page-question extraction, a ticketed MCP App host and Control UI bridge, and manifest-declared MCP Apps for native plugins. (#109817, #111457, #113861, #109861; related #109851; #109807, #113224; related #113218) Thanks @anagnorisis2peripeteia, @FMLS, @cursoragent, @hxy91819, and @fuller-stack-dev.
- Memory: add fast active-memory recall, default cross-conversation recall for personal installs, guided imports from Claude Code/Codex/Hermes, and a dedicated Memory settings page. (#108043, #110597, #108977, #114037)
- Scheduling: add per-job dynamic cadence, gated script payloads, durable schedule-source streaming, cron-backed heartbeat monitors, heartbeat-task conversion, current-conversation defaults, and
/loop. (#110978, #111112, #112387, #112585, #113165, #114328) - Fish Audio speech: add hosted S2.1 synthesis with streaming, voice notes, voice discovery, and telephony, plus local Fish S2 Pro reference-voice streaming in native macOS Talk. (#115790) Thanks @Rheingold777, @ImLukeF, and @Conan-Scott.
- Control UI setup: continue verified model setup into Custodian, explain that the web app is ready without a channel, and offer an optional dismissible path to Channels. (#116078, #116079) Thanks @vincentkoc.
- Buzz messaging: preserve Markdown and structured room content, then add room- and thread-scoped typing indicators with reconnect-safe lifecycle handling. (#116096, #116194) Thanks @shakkernerd.
- Automations naming: rename the scheduler-facing
cronagent tool and visible CLI/UI surfaces to Automations while retaining the compatible CLI alias. (#114841, #114854, #114853) Thanks @omarshahine. - DuckDuckGo search: move DuckDuckGo search into the plugin boundary so provider ownership, installation, and runtime behavior stay outside core. (#116740) Thanks @vincentkoc.
Fixes
- Security and authorization: prevent channel allowlists from granting owner access, keep session exports inside the workspace, close a forged-marker/web-search boundary bypass, prevent non-owner ACP session exposure, reject unsafe explicit approval IDs, harden secret redaction and exec/OAuth approvals, validate downloaded install scripts, and prevent insecure secrets-plan writes. (#107403; related #104984; #104708; related #102391; #110417, #110745; related #103055; #111055, #112947, #112952, #112953, #112956, #112946, #112957, #113307; related #90013; #113707) Thanks @obviyus, @yetval, @VACInc, @pgondhi987, and @SebTardif.
- SQLite and data safety: commit session indexes before transcript eviction, preserve state through maintenance races and live-WAL verification, reject invalid backups and schema data loss, make snapshot publication crash-recoverable, retain complete backups after interrupted commits, and evict only the exact corrupted cached database owner so repairs recover without a Gateway restart. (#108378, #113216; related #113209, #113210, #113211; #113287; related #113265; #113367, #113473, #113607, #114016, #114278) Thanks @yetval, @vincentkoc, @VACInc, and @rizquuula.
- Channel delivery: stop Telegram durable-ingress loss across restarts and persist offsets only after spool writes, preserve Discord/iMessage/WhatsApp traffic across crashes or restarts, restore assistant context and interrupted turns after restart, suppress outbound echoes, deliver ingress retries whose queued run was dropped, report finalized Telegram previews to plugins, explain invalid native queue arguments instead of false model-failure fallbacks, validate native settings, and preserve Telegram ingress outcomes. (#107288; related #107246; #113368; related #113315; #110274, #110409, #110418, #112548; related #112520; #112562, #114058, #114531, #111341, #115891; related #115888; #116214; related #116171; #116726; related #116688; #116773) Thanks @obviyus, @carlosjarenom, @JesusSerrano-Seimako, @vincentkoc, @edenfunf, @joshavant, and @hannesrudolph.
- Sessions and transcripts: preserve final replies, active turns, Codex-bound history, and transcript cursors; prevent repeated tool-call IDs from poisoning sessions; close lifecycle races and cross-agent deadlocks; keep migrated transcripts usable after restart; keep restart prompts on the active transcript tail; and preserve TUI session state across switches and reconnects. (#107799; related #106594; #110389, #110518; related #109443; #112016, #112988, #114477; related #103077, #103089, #113005, #114187; #114524, #114504, #116077, #116399, #117260) Thanks @joshavant, @lockhartheavyindustries, @flashosophy, @yetval, @realaudreyserber-afk, @hvhoon, and @vincentkoc.
- Install and upgrade: preserve working installs on unsupported Node and npm 12, isolate source postinstall state, repair missing native adapters, keep versioned plugins off source paths, avoid dirty source build...
openclaw 2026.7.2-beta.6
2026.7.2
Highlights
- State safety and recovery: protect persisted data with a quarantine store that survives primary-database damage, crash-recoverable SQLite snapshots, crash-durable filesystem publication, schema-upgrade data-loss rejection, and rollback-writer snapshot recovery. (#110453, #113367, #113453, #113473, #113580) Thanks @vincentkoc.
- Durable channel delivery: keep accepted messages recoverable across gateway restarts and local crashes through the shared ingress drain and dead-letter recovery, covering Telegram, Signal, Slack, QQBot, Twitch, Synology Chat, Tlon, IRC, and Zalo User. #108656, #107246, #109911 (#108924, #107288, #109907, #109910, #110844, #110852, #110899, #110910, #110914, #110916, #111029) Thanks @obviyus and @edenfunf.
- Session rewind and branching: rewind or fork conversations from individual messages, switch transcript branches across web and native apps, fork upstream Codex sessions, preserve branch-safe queued sends, reject stale-pane writes, and restore prompt images after a fork. (#110660, #110857, #110886, #111149, #112056, #112284, #113073, #113945) Thanks @vincentkoc.
- Interactive MCP Apps and dashboards: host ticketed MCP Apps with bound tools, resources, and bounded context updates; open them from channel replies, pin them to durable dashboards, harden their shared sandbox, and let native plugins declare them directly. #109851, #110451, #113218 (#109861, #109807, #110515, #111211, #111212, #111524, #111687, #111748, #113224) Thanks @fuller-stack-dev.
- Questions and approvals everywhere: let agents ask structured questions with option cards across web, channels, macOS, and native apps, while approvals gain push notifications, history, fair queuing, headless resolution, Claude tool-request relay, reviewer detail, and clearer formatted prompts. #85954 (#108505, #108709, #108776, #109922, #110242, #110372, #110584, #110681, #110989, #111060, #112918, #113027, #113193) Thanks @omarshahine.
- Meetings and realtime Talk: join Teams, Zoom, and Google Meet calls with default-enabled meeting plugins and durable transcript collection, while realtime Talk adds OpenAI and Gemini video and requires a supported OpenAI Platform API key instead of the rejected Codex OAuth fallback. #86425, #113353, #115021 (#109579, #109719, #109964, #111048, #113022, #113053, #113122, #113354, #115211) Thanks @shushushv, @Solvely-Colin, and @vincentkoc.
- Wear OS companion: add the phone-proxied Wear companion with home-screen agent/session/model selection, realtime Talk controls, audio-reactive playback, and an instant-talk tile. #108781 (#108835, #109341, #109433, #109483, #110661, #111516, #112721) Thanks @sibbl, @IWhatsskill, and @Solvely-Colin.
- Guided setup and local inference: guide setup across browser, Linux, and macOS with local-provider detection, strongest-model selection, downloadable models, lean mode, memory imports, and an in-process RAM-gated llama.cpp/Gemma path. #108604 (#108605, #108868, #108977, #109250, #109444, #109585, #110054, #110141, #110596, #113476)
Changes
- Models and providers: add Claude Opus 5 across catalog and runtime, Kimi K3, and GPT Live realtime support with the supported Platform API authentication path. (#113391, #113392, #113633; related #113412; #113909, #113354; related #113353) Thanks @fuller-stack-dev, @vincentkoc, and @Solvely-Colin.
- Local inference and setup: detect local inference providers during onboarding, add in-process llama.cpp GGUF inference and Baseten Model API support, discover models from live provider catalogs, and offer model downloads from web and macOS setup. (#108605; related #108604; #109444, #108708; related #108665; #112412; related #112405; #113476) Thanks @fuller-stack-dev.
- Sessions and dashboards: add rewind/fork and branch switching across web and native chat, session boards and dashboards, archived/visibility/draft/incognito session states, and suggestion queues with typing indicators. (#110660, #110857, #110886, #111149, #110644, #110960, #112554, #112787, #113006, #113127, #113173)
- Native apps: bring Quick Chat to macOS and Linux with streaming, routing, context capture, dictation, and model controls; add Linux desktop integration and signed updates; add multi-gateway apps and mobile dashboards; and expand Wear OS companion/Talk support. (#109720, #109947, #110285, #110631, #110632, #110635, #110994, #109236, #108770, #111932; related #111931; #112163, #109341, #109433; related #108781; #109483, #112721) Thanks @sibbl, @IWhatsskill, @Solvely-Colin, and @vincentkoc.
- Meetings: add Teams and Zoom meeting guests, enable Teams, Zoom, and Google Meet plugins by default, and automatically collect durable meeting transcripts. (#109964, #111048, #113022, #113053, #113122)
- Channels: add the Buzz plugin, Slack user-identity and Agent View modes, Telegram Bot API rich blocks and native Markdown lists, and richer Matrix formatting. (#113419, #109837, #103895; related #103673; #107986, #113158, #113199) Thanks @Patrick-Erichsen and @obviyus.
- Browser and MCP Apps: add a secure per-tab browser copilot, batch browser CLI, bounded page-question extraction, a ticketed MCP App host and Control UI bridge, and manifest-declared MCP Apps for native plugins. (#109817, #111457, #113861, #109861; related #109851; #109807, #113224; related #113218) Thanks @anagnorisis2peripeteia, @FMLS, @cursoragent, @hxy91819, and @fuller-stack-dev.
- Memory: add fast active-memory recall, default cross-conversation recall for personal installs, guided imports from Claude Code/Codex/Hermes, and a dedicated Memory settings page. (#108043, #110597, #108977, #114037)
- Scheduling: add per-job dynamic cadence, gated script payloads, durable schedule-source streaming, cron-backed heartbeat monitors, heartbeat-task conversion, current-conversation defaults, and
/loop. (#110978, #111112, #112387, #112585, #113165, #114328) - Fish Audio speech: add hosted S2.1 synthesis with streaming, voice notes, voice discovery, and telephony, plus local Fish S2 Pro reference-voice streaming in native macOS Talk. (#115790) Thanks @Rheingold777, @ImLukeF, and @Conan-Scott.
- Control UI setup: continue verified model setup into Custodian, explain that the web app is ready without a channel, and offer an optional dismissible path to Channels. (#116078, #116079) Thanks @vincentkoc.
- Buzz messaging: preserve Markdown and structured room content, then add room- and thread-scoped typing indicators with reconnect-safe lifecycle handling. (#116096, #116194) Thanks @shakkernerd.
- Automations naming: rename the scheduler-facing
cronagent tool and visible CLI/UI surfaces to Automations while retaining the compatible CLI alias. (#114841, #114854, #114853) Thanks @omarshahine. - DuckDuckGo search: move DuckDuckGo search into the plugin boundary so provider ownership, installation, and runtime behavior stay outside core. (#116740) Thanks @vincentkoc.
Fixes
- Security and authorization: prevent channel allowlists from granting owner access, keep session exports inside the workspace, close a forged-marker/web-search boundary bypass, prevent non-owner ACP session exposure, reject unsafe explicit approval IDs, harden secret redaction and exec/OAuth approvals, validate downloaded install scripts, and prevent insecure secrets-plan writes. (#107403; related #104984; #104708; related #102391; #110417, #110745; related #103055; #111055, #112947, #112952, #112953, #112956, #112946, #112957, #113307; related #90013; #113707) Thanks @obviyus, @yetval, @VACInc, @pgondhi987, and @SebTardif.
- SQLite and data safety: commit session indexes before transcript eviction, preserve state through maintenance races and live-WAL verification, reject invalid backups and schema data loss, make snapshot publication crash-recoverable, retain complete backups after interrupted commits, and evict only the exact corrupted cached database owner so repairs recover without a Gateway restart. (#108378, #113216; related #113209, #113210, #113211; #113287; related #113265; #113367, #113473, #113607, #114016, #114278) Thanks @yetval, @vincentkoc, @VACInc, and @rizquuula.
- Channel delivery: stop Telegram durable-ingress loss across restarts and persist offsets only after spool writes, preserve Discord/iMessage/WhatsApp traffic across crashes or restarts, restore assistant context and interrupted turns after restart, suppress outbound echoes, deliver ingress retries whose queued run was dropped, report finalized Telegram previews to plugins, validate native settings, and preserve Telegram ingress outcomes. (#107288; related #107246; #113368; related #113315; #110274, #110409, #110418, #112548; related #112520; #112562, #114058, #114531, #111341, #115891; related #115888; #116214; related #116171; #116773) Thanks @obviyus, @carlosjarenom, @JesusSerrano-Seimako, @vincentkoc, @edenfunf, and @joshavant.
- Sessions and transcripts: preserve final replies, active turns, Codex-bound history, and transcript cursors; prevent repeated tool-call IDs from poisoning sessions; close lifecycle races and cross-agent deadlocks; keep migrated transcripts usable after restart; and preserve TUI session state across switches and reconnects. (#107799; related #106594; #110389, #110518; related #109443; #112016, #112988, #114477; related #103077, #103089, #113005, #114187; #114524, #114504, #116077, #116399) Thanks @joshavant, @lockhartheavyindustries, @flashosophy, @yetval, @realaudreyserber-afk, @hvhoon, and @vincentkoc.
- Install and upgrade: preserve working installs on unsupported Node and npm 12, isolate source postinstall state, repair missing native adapters, keep versioned plugins off source paths, avoid dirty source builds, repair plugin config during upgrades, stabilize package-to-dev switches, restore production installs after the TypeBox package removal, ship documented plugin SDK typings, and disco...
openclaw 2026.7.2-beta.5
2026.7.2
Highlights
- State safety and recovery: protect persisted data with a quarantine store that survives primary-database damage, crash-recoverable SQLite snapshots, crash-durable filesystem publication, schema-upgrade data-loss rejection, and rollback-writer snapshot recovery. (#110453, #113367, #113453, #113473, #113580) Thanks @vincentkoc.
- Durable channel delivery: keep accepted messages recoverable across gateway restarts and local crashes through the shared ingress drain and dead-letter recovery, covering Telegram, Signal, Slack, QQBot, Twitch, Synology Chat, Tlon, IRC, and Zalo User. #108656, #107246, #109911 (#108924, #107288, #109907, #109910, #110844, #110852, #110899, #110910, #110914, #110916, #111029) Thanks @obviyus and @edenfunf.
- Session rewind and branching: rewind or fork conversations from individual messages, switch transcript branches across web and native apps, fork upstream Codex sessions, preserve branch-safe queued sends, reject stale-pane writes, and restore prompt images after a fork. (#110660, #110857, #110886, #111149, #112056, #112284, #113073, #113945)
- Interactive MCP Apps and dashboards: host ticketed MCP Apps with bound tools, resources, and bounded context updates; open them from channel replies, pin them to durable dashboards, harden their shared sandbox, and let native plugins declare them directly. #109851, #110451, #113218 (#109861, #109807, #110515, #111211, #111212, #111524, #111687, #111748, #113224) Thanks @fuller-stack-dev.
- Questions and approvals everywhere: let agents ask structured questions with option cards across web, channels, macOS, and native apps, while approvals gain push notifications, history, fair queuing, headless resolution, Claude tool-request relay, reviewer detail, and clearer formatted prompts. #85954 (#108505, #108709, #108776, #109922, #110242, #110372, #110584, #110681, #110989, #111060, #112918, #113027, #113193) Thanks @omarshahine.
- Meetings and realtime Talk: join Teams, Zoom, and Google Meet calls with default-enabled meeting plugins and durable transcript collection, while realtime Talk adds OpenAI and Gemini video plus GPT Live through Codex OAuth. #86425, #113353 (#109579, #109719, #109964, #111048, #113022, #113053, #113122, #113354) Thanks @shushushv and @Solvely-Colin.
- Wear OS companion: add the phone-proxied Wear companion with home-screen agent/session/model selection, realtime Talk controls, audio-reactive playback, and an instant-talk tile. #108781 (#108835, #109341, #109433, #109483, #110661, #111516, #112721) Thanks @sibbl, @IWhatsskill, and @Solvely-Colin.
- Guided setup and local inference: guide setup across browser, Linux, and macOS with local-provider detection, strongest-model selection, downloadable models, lean mode, memory imports, and an in-process RAM-gated llama.cpp/Gemma path. #108604 (#108605, #108868, #108977, #109250, #109444, #109585, #110054, #110141, #110596, #113476)
Changes
- Models and providers: add Claude Opus 5 across catalog and runtime, Kimi K3, and GPT Live through Codex OAuth. (#113391, #113392, #113633; related #113412; #113909, #113354; related #113353) Thanks @fuller-stack-dev, @vincentkoc, and @Solvely-Colin.
- Local inference and setup: detect local inference providers during onboarding, add in-process llama.cpp GGUF inference and Baseten Model API support, discover models from live provider catalogs, and offer model downloads from web and macOS setup. (#108605; related #108604; #109444, #108708; related #108665; #112412; related #112405; #113476) Thanks @fuller-stack-dev.
- Sessions and dashboards: add rewind/fork and branch switching across web and native chat, session boards and dashboards, archived/visibility/draft/incognito session states, and suggestion queues with typing indicators. (#110660, #110857, #110886, #111149, #110644, #110960, #112554, #112787, #113006, #113127, #113173)
- Native apps: bring Quick Chat to macOS and Linux with streaming, routing, context capture, dictation, and model controls; add Linux desktop integration and signed updates; add multi-gateway apps and mobile dashboards; and expand Wear OS companion/Talk support. (#109720, #109947, #110285, #110631, #110632, #110635, #110994, #109236, #108770, #111932; related #111931; #112163, #109341, #109433; related #108781; #109483, #112721) Thanks @sibbl, @IWhatsskill, @Solvely-Colin, and @vincentkoc.
- Meetings: add Teams and Zoom meeting guests, enable Teams, Zoom, and Google Meet plugins by default, and automatically collect durable meeting transcripts. (#109964, #111048, #113022, #113053, #113122)
- Channels: add the Buzz plugin, Slack user-identity and Agent View modes, Telegram Bot API rich blocks and native Markdown lists, and richer Matrix formatting. (#113419, #109837, #103895; related #103673; #107986, #113158, #113199) Thanks @Patrick-Erichsen and @obviyus.
- Browser and MCP Apps: add a secure per-tab browser copilot, batch browser CLI, bounded page-question extraction, a ticketed MCP App host and Control UI bridge, and manifest-declared MCP Apps for native plugins. (#109817, #111457, #113861, #109861; related #109851; #109807, #113224; related #113218) Thanks @anagnorisis2peripeteia, @FMLS, @cursoragent, @hxy91819, and @fuller-stack-dev.
- Memory: add fast active-memory recall, default cross-conversation recall for personal installs, guided imports from Claude Code/Codex/Hermes, and a dedicated Memory settings page. (#108043, #110597, #108977, #114037)
- Scheduling: add per-job dynamic cadence, gated script payloads, durable schedule-source streaming, cron-backed heartbeat monitors, heartbeat-task conversion, current-conversation defaults, and
/loop. (#110978, #111112, #112387, #112585, #113165, #114328)
Fixes
- Security and authorization: prevent channel allowlists from granting owner access, keep session exports inside the workspace, close a forged-marker/web-search boundary bypass, prevent non-owner ACP session exposure, reject unsafe explicit approval IDs, harden secret redaction and exec/OAuth approvals, validate downloaded install scripts, and prevent insecure secrets-plan writes. (#107403; related #104984; #104708; related #102391; #110417, #110745; related #103055; #111055, #112947, #112952, #112953, #112956, #112946, #112957, #113307; related #90013; #113707) Thanks @obviyus, @yetval, @VACInc, @pgondhi987, and @SebTardif.
- SQLite and data safety: commit session indexes before transcript eviction, preserve state through maintenance races and live-WAL verification, reject invalid backups and schema data loss, make snapshot publication crash-recoverable, and retain complete backups after interrupted commits. (#108378, #113216; related #113209, #113210, #113211; #113287; related #113265; #113367, #113473, #113607, #114016) Thanks @yetval, @vincentkoc, and @VACInc.
- Channel delivery: stop Telegram durable-ingress loss across restarts and persist offsets only after spool writes, preserve Discord/iMessage/WhatsApp traffic across crashes or restarts, restore assistant context and interrupted turns after restart, keep queued replies alive, and emit a fallback when a visible turn returns no reply. (#107288; related #107246; #113368; related #113315; #110274, #110409, #110418, #112548; related #112520; #112562, #114058, #114531) Thanks @obviyus, @carlosjarenom, and @JesusSerrano-Seimako.
- Sessions and transcripts: preserve final replies, active turns, Codex-bound history, and transcript cursors; prevent repeated tool-call IDs from poisoning sessions; close lifecycle races and cross-agent deadlocks; and prevent TUI cross-session leaks and lost streams. (#107799; related #106594; #110389, #110518; related #109443; #112016, #112988, #114477; related #103077, #103089, #113005, #114187; #114524, #114504) Thanks @joshavant, @lockhartheavyindustries, @flashosophy, @yetval, @realaudreyserber-afk, and @hvhoon.
- Install and upgrade: preserve working installs on unsupported Node and npm 12, isolate source postinstall state, repair missing native adapters, keep versioned plugins off source paths, avoid dirty source builds, repair plugin config during upgrades, stop packages from deleting UI/runtime files, finish ClawHub uninstall, surface empty npm-install failures, and discover external web-search plugins on fresh installs. (#106994; related #106870; #108100; related #107290; #111514; related #111513; #111682, #112829; related #112827; #113094, #113324, #113856, #113821, #114090, #114215; related #113975; #114327) Thanks @woohahahaaa, @fuller-stack-dev, @vincentkoc, @sallyom, and @alxfyvwebaccts-png.
- Provider reliability: prevent false Codex exhaustion and silent replies, honor Anthropic Retry-After, preserve selected Claude CLI profiles and adopted chats, recover Codex Computer Use and user-home app-server routes, retry transient device polling, correct OpenAI onboarding, and stabilize Ollama/LM Studio/local-model discovery. (#110381; related #96815; #110980, #111072; related #103849; #112458; related #95612, #107668; #113078, #113393, #114397, #114094; related #114086; #114288, #114405, #114582) Thanks @xxw77, @yetval, @fuller-stack-dev, @cstreeter, @josh-cornelius, @lanyoung, @LeonidasLux, and @BomBastikDE.
- Cron reliability: restore one-shot and startup catch-up jobs, preserve script state and scheduled authority across restarts, accept benign same-generation updates, bind jobs to the durable store session, unblock completed jobs behind slower batches, and trim job IDs before exact lookup. (#107236, #110351; related #102236; #111292; related #111271, #111272, #111273, #111274; #112483, #113088; related #113085; #114421, #114441, #110849) Thanks @SL4N, @yetval, @joshavant, @metahacker, @efpiva, and @nocodet888-arch.
- Compaction and response delivery: account for CJK text in compaction estimates and treat
no_compactable_entriesas a benign skip. (#114386; related #103930; #1...
openclaw 2026.6.33
2026.6.33
Highlights
- Safer network and secret boundaries: provider streams, Discord REST responses, browser fetches, OAuth paths, and logs now cap hostile response sizes and keep Telegram credentials out of diagnostics. (#96989, #95412, #99428) Thanks @wangmiao0668000666, @Alix-007, @xialonglee, @liuhaiyang14, @Pick-cat, @mushuiyu886, @vincentkoc, @ZOOWH, @Pandah97, @solodmd, @zhangguiping-xydt, and @obviyus.
- More reliable long-running agents: run release, liveness checks, and watchdog semantics now distinguish genuine stalls from active long model calls and wedged backends. (#102160) Thanks @obviyus, @kiagentkronos-cell, @alvelda, @alkor2000, and @vincentkoc.
- Stronger channel delivery: Discord reconnects no longer silently drop queued messages or repeat ambiguous non-idempotent sends, while Telegram bot-to-bot and reply-fence handling preserve the intended thread and authorization result. (#100896, #103867, #106755) Thanks @tiffanychum, @Godecule, @yetval, @xialonglee, and @RomneyDa.
- Safer credential recovery: service restarts preserve SecretRef-backed Telegram credentials, and OAuth repair no longer overwrites an already-valid destination profile. (#99124, #97541) Thanks @mushuiyu886, @1Wanker, @liuhao1024, @yetval, @Darren2030, @obviyus, and @RomneyDa.
- Extended-stable updates: package installations can select, update from, and receive availability notices for the
extended-stablechannel without silently falling back to another release line. (#99811, #100438) Thanks @kevinslin.
Changes
- Approval and tool authority: Codex app-server commands now require an actual human/plugin approval, exec auto-review stays bound to the exact resolved command, and narrow tool allowlists remain owned by the factory that constructs them. (#103430, #103457, #104213) Thanks @obviyus, @brokemac79, @Pandah97, @wangmiao0668000666, and @pgondhi987.
- Scoped external tooling: external MCP loopback clients use short-lived session-bound attach grants instead of inheriting mutable child-process authority, and Gateway message actions retain trusted requester provenance and reject untrusted callers. (#102031) Thanks @pgondhi987, @Glucksberg, @wings1029, @Alix-007, @machine3at, and @anagnorisis2peripeteia.
Fixes
- Authorization and disclosure: Gateway HTTP rejects disallowed browser origins before unauthenticated handling, permission repair stays confined to its intended include, MCP status output redacts secrets, and Gateway action bridges reject untrusted requesters. (#102881, #103267, #103396, #102031) Thanks @wangyan2026, @yetval, @NianJiuZst, @obviyus, @pgondhi987, and @brokemac79.
- Gateway and process stability: agent-run caches are bounded, lock probes stop leaking file descriptors, close reasons preserve valid UTF-8, and heartbeat reads survive transient filesystem races. (#77973, #99291, #100047, #100389) Thanks @fede-kamel, @chenyangjun-xy, @zhangLei99586, @NarahariRaghava, @ogarciarevett, @markr9805, @849261680, @mushuiyu886, @vincentkoc, @wings1029, and @masatohoshino.
- Provider and browser reliability: Anthropic-compatible partial streams stop hanging at their size bound, OpenAI Realtime uses the correct authentication and transcription secret flow, and remote CDP credentials stay out of responses. (#100686, #102518, #103139) Thanks @zhangguiping-xydt, @cxbAsDev, @sjf-oa, @sjf, @vincentkoc, and @obviyus.
- Ingress and webhook safety: replayed Twilio requests are rejected under sustained traffic, corrupt queued channel rows are tombstoned without blocking later work, and Telegram tokens are redacted even when split across log chunks. (#101107, #105259, #103861) Thanks @zhangguiping-xydt, @vincentkoc, @mushuiyu886, @Pick-cat, and @xialonglee.
Complete contribution record
This audited record covers the complete v2026.6.11..db7af38 history: 169 merged PRs. The generation manifest also supplies direct commits as editorial input; the grouped notes above prioritize user impact.
Pull requests
- PR #98835 Related #98672. Thanks @moguangyu5-design and @jalehman and @AaronFaby.
- PR #96989 Thanks @wangmiao0668000666 and @vincentkoc.
- PR #95412 Thanks @Alix-007.
- PR #95108 Thanks @vincentkoc.
- PR #97499 Thanks @wangmiao0668000666.
- PR #102953 Thanks @ZOOWH.
- PR #97551 Thanks @Alix-007 and @vincentkoc.
- PR #97540 Thanks @Alix-007 and @vincentkoc.
- PR #95416 Thanks @Alix-007 and @vincentkoc.
- PR #97614 Thanks @cxbAsDev.
- PR #97808 Thanks @Pick-cat.
- PR #96445 Thanks @lin-hongkuan.
- PR #97961 Thanks @eleqtrizit.
- PR #97838 Thanks @pgondhi987.
- PR #98455 Thanks @wings1029.
- PR #100889 Thanks @mushuiyu886.
- PR #77973 Related #77976. Thanks @fede-kamel and @vincentkoc.
- PR #99291 Related #98958. Thanks @chenyangjun-xy and @zhangLei99586.
- PR #99428 Related #96982. Thanks @xialonglee and @liuhaiyang14.
- PR #98130 Thanks @Pick-cat.
- PR #100047 Related #99976. Thanks @NarahariRaghava.
- PR #100389 Related #99994. Thanks @ogarciarevett and @markr9805.
- PR #98682 Thanks @wings1029.
- PR #99479 Thanks @Pandah97.
- PR #101079 Thanks @cxbAsDev.
- PR #101160 Thanks @cxbAsDev.
- PR #102105 Thanks @wangmiao0668000666.
- PR #102450 Thanks @qingminglong.
- PR #100483 Related #100423. Thanks @versatagent.
- PR #102050 Thanks @Alix-007.
- PR #102952 Related #55365. Thanks @lidge-jun and @Mdx2025.
- PR #102160 Related #85826, #96168. Thanks @obviyus and @kiagentkronos-cell and @alvelda.
- PR #96224 Related #77986. Thanks @eleqtrizit and @fede-kamel.
- PR #96599 Thanks @sjf-oa and @sjf.
- PR #96615 Related #96589. Thanks @liuhao1024 and @yetval.
- PR #89812 Related #89626. Thanks @Petru2224.
- PR #92274 Related #91527. Thanks @fsdwen and @zackchiutw.
- PR #96396 Related #95784. Thanks @849261680 and @velvet-shark and @BryceMurray.
- PR #96096 Related #85900. Thanks @849261680 and @velvet-shark and @fanispoulinakisai-boop.
- PR #96831 Related #94083. Thanks @velvet-shark and @ooiuuii.
- PR #96142 Related #95574. Thanks @brokemac79 and @riazrahaman.
- PR #97044 Related #96983. Thanks @zw-xysk and @vincentkoc and @liuhaiyang14.
- PR #94452 Related #94040. Thanks @mushuiyu886 and @xrow.
- PR #96772 Thanks @wangmiao0668000666 and @vincentkoc.
- PR #96042 Thanks @Alix-007 and @vincentkoc.
- PR #96038 Thanks @Alix-007 and @vincentkoc.
- PR #96031 Thanks @Alix-007.
- PR #95103 Thanks @vincentkoc.
- PR #97620 Thanks @Alix-007 and @vincentkoc.
- PR #97693 Thanks @Alix-007.
- PR #98496 Thanks @Pandah97.
- PR #97784 Thanks @Alix-007.
- PR #97140 Related #97091. Thanks @galiniliev.
- PR #95543 Related #95474. Thanks @mikasa0818 and @ElliotDrel.
- PR #97504 Thanks @hugenshen.
- PR #90908 Thanks @shengting.
- PR #97356 Thanks @miorbnli.
- PR #97541 Related #97522. Thanks @liuhao1024 and @yetval.
- PR #97520 Related #97313. Thanks @zhangguiping-xydt and @pmdvedar-ai.
- PR #96544 Thanks @yetval and @vincentkoc.
- PR #97579 Thanks @hugenshen.
- PR #96644 Thanks @solodmd.
- PR #97214 Thanks @masatohoshino and @vincentkoc.
- PR #97372 Thanks @masatohoshino.
- PR #95774 Thanks @mushuiyu886.
- PR #95084 Related #90684. Thanks @jailbirt and @studentzhou-svg.
- PR #97367 Thanks @masatohoshino.
- PR #98693 Thanks @ZengWen-DT and @cursoragent.
- PR #89817 Thanks @masatohoshino.
- PR #96965 Related #96929. Thanks @zw-xysk and @YouToco.
- PR #100107 Thanks @frank-beans.
- PR #97861 Thanks @yetval.
- PR #96444 Thanks @lin-hongkuan.
- PR #96492 Thanks @yetval.
- PR #97870 Thanks @eleqtrizit.
- PR #98142 Thanks @RomneyDa.
- PR #98226 Related #98225. Thanks @ooiuuii.
- PR #99460 Related #99459. Thanks @ooiuuii.
- PR #98354 Thanks @Pick-cat.
- PR #98508 Thanks @lzyyzznl.
- PR #93379 Related #77755. Thanks @xialonglee and @jiveshkalra.
- PR #99070 Thanks @LeonidasLux.
- PR #98720 Related #98463. Thanks @wangmiao0668000666 and @zhangLei99586.
- PR #99800 Thanks @cxbAsDev and @vincentkoc.
- PR #100744 Thanks @lsr911 and @vincentkoc.
- PR #98262 Related #98239. Thanks @brokemac79.
- PR #101366 Related #84600. Thanks @deepujain and @13884379776l.
- PR #100835 Thanks @machine3at.
- PR #102035 Thanks @pgondhi987.
- PR #101617 Thanks @zhangguiping-xydt.
- PR #101744 Thanks @hugenshen and @cursoragent.
- PR #101739 Thanks @Alix-007.
- PR #102089 Thanks @Alix-007.
- PR #102661 Related #98038. Thanks @mabaty.
- PR #102403 Thanks @yetval.
- PR #102398 Thanks @yetval.
- PR #102426 Thanks @pgondhi987.
- PR #102840 Thanks @yetval.
- PR #103441 Related #68691. Thanks @hobo-l-20230331 and @aaajiao.
- PR #103267 Thanks @NianJiuZst.
- PR #104015
- PR #103619 Thanks @pgondhi987.
- PR #104337 Related #104330.
- PR #102881 Related #102834. Thanks @wangyan2026 and @yetval.
- PR #105769 Thanks @mushuiyu886.
- PR #102924 Thanks @hugenshen.
- PR #106056 Thanks @pgondhi987.
- PR #106806 Related #103056. Thanks @yetval.
- PR #96143 Related #77616. Thanks @brokemac79 and @RomneyDa and @slideshow-dingo.
- PR #97271 Thanks @hugenshen.
- PR #96762 Thanks @wangmiao0668000666 and @vincentkoc.
- PR #97235 Thanks @zhangguiping-xydt and @vincentkoc.
- PR #95542 Related #95519. Thanks @mikasa0818 and @altaywtf and @zjx111234.
- PR #97571 Related #97564. Thanks @liuhao1024 and @nicelysalted.
- PR #86088 Thanks @liaoandi and @altaywtf.
- PR #99960 Thanks @masatohoshino and @vincentkoc.
- PR #85296 Thanks @alkor2000 and @vincentkoc.
- PR #100484 Thanks @vincentkoc and @litang9.
- PR #100722 Related #98864. Thanks @cxbAsDev and @carterstebbins23-spec.
- PR #94149 Related #84698. Thanks @ZengWen-DT and @cursoragent an...
openclaw 2026.7.2-beta.3
2026.7.2
Highlights
- Remote coding sessions: run Control UI sessions on cloud workers, open Codex and Claude catalog sessions in terminals on their owning hosts, and resume OpenCode and Pi sessions directly in a terminal. (#107670, #107086, #107200)
- Native automation and nodes: bring Automations parity to mobile, add foreground Voice Wake on Android, and expose camera, location, and notification capabilities from headless Linux nodes. (#106355, #107081, #107193)
- Safer channel operation: prevent Telegram durable-ingress loss after restarts, keep Signal stop and approval controls responsive during active turns, and stop channel allowlists from granting owner access. (#107288, #107422, #107403) Thanks @obviyus, @arduano, and @yetval.
- Guided Control UI setup: configure model providers from Settings, onboard channels through a guided setup page, and choose images and models while creating sessions. (#106490, #106469, #107358) Thanks @alexandre-leng and @fuller-stack-dev.
- Gateway and session recovery: prevent restart admission from wedging the Gateway, recover reply sessions after finalization stalls, and keep one-shot cron jobs enabled through lifecycle claim races. (#107339, #106792, #107236) Thanks @obviyus, @joshavant, @charliemeyer2000, and @SL4N.
- Install and packaging: add Linux deb and AppImage bundles with Gateway guidance, publish them from stable main-based releases, and let Windows installs continue immediately after winget adds Node.js. (#106533, #106891, #106862)
Changes
- External gateway supervision: add
OPENCLAW_SUPERVISOR_MODE=externalfor lifecycle owners such as OCM, preserving verified restart and deferral behavior without exposing native service authority, blocking native service mutation and self-update, and providing a versioned atomic restart-handoff consume contract. Thanks @shakkernerd. - ClickClack guided setup: configure ClickClack from
openclaw onboardoropenclaw channels add clickclackwith URL, token, and workspace prompts, default-account env fallback, nonfatal live connection validation, and gateway-aware next steps that connect automatically when OpenClaw is already running. Thanks @shakkernerd. - ClickClack command menus: publish each bot's native OpenClaw commands to ClickClack composer autocomplete at gateway startup, with per-account opt-out and nonfatal compatibility handling for older tokens and servers. Thanks @shakkernerd and @vincentkoc.
- Skill Workshop approvals: run agent-initiated apply, reject, and quarantine actions without an additional approval prompt by default while preserving
skills.workshop.approvalPolicy: "pending"as an opt-in approval gate. Thanks @shakkernerd. - TUI fuzzy selectors: delegate list matching to pi-tui, adding slash-token and alpha-number matching while removing the local matcher fork.
- macOS paired-node terminals: advertise duplex Codex and Claude terminal resume commands from the embedded node host and forward interactive input and cancellation through the native app bridge. (#107335)
- Control UI catalog terminals: open eligible Codex and Claude Code sessions in the native CLI on their Gateway or paired-node host, with viewer-versus-terminal preferences, validated resume commands, and an interactive PTY relay. (#107086) Thanks @vincentkoc.
- Skill Workshop history review: add a manual, newest-first session scan that progressively searches older substantial work for conservative skill ideas, stores only SQLite cursor metadata, and leaves up to three results as pending proposals even when autonomous self-learning is disabled. (#106182)
- OpenAI GPT-5.6 defaults: use
openai/gpt-5.6(Sol alias) for fresh API-key setup and exactopenai/gpt-5.6-solfor fresh Codex/OAuth setup, default Sol to medium reasoning across both runtimes, and preserve existing primaries, fallbacks, aliases, and explicit GPT-5.5 selections. (#103234) - iOS offline chat: pre-paint recent sessions and canonical transcripts from a protected, bounded per-gateway cache, keep sending disabled offline, and purge cached conversation text when pairing is reset. (#100194)
- Slack progress indicators: use Slack's native assistant thread status and rotating loading messages by default while keeping acknowledgement reactions static; lifecycle reaction updates now require
messages.statusReactions.enabled: true. - Control UI Talk controls: keep voice, model, sensitivity, and other realtime defaults in Settings → Communications → Talk, and use the composer microphone caret to select any browser audio input. (#101046)
- Control UI session workspace shortcut: expand or collapse the active Chat pane's session workspace rail with ⇧⌘B without changing the main app sidebar or the separate detail and Canvas preview panel. Thanks @shakkernerd.
- Control UI Settings shortcut: open Settings with ⇧⌘, while leaving the browser-owned ⌘, shortcut unchanged. Thanks @shakkernerd.
- Control UI chat layout: center the transcript on the composer axis, keep assistant and tool output left and user bubbles right within the same readable frame, and preserve custom message-width overrides. (#104474) Thanks @shakkernerd, @vincentkoc, and @zw-xysk.
- Control UI composer footer: center the chat settings chip and model controls between the divider and the card edge instead of pinning them to the divider. (#105866)
- Control UI assistant actions: keep assistant name and time first while placing hover actions beside them on the left instead of at the far edge. Thanks @shakkernerd.
- Control UI message context: reveal per-message token, context, and model details from the timestamp on hover or activation instead of showing a separate Context button.
- Control UI session titles: reveal truncated recent-session names with a reduced-motion-safe hover animation.
- Control UI sidebar usage: remove the provider usage quota row from the expanded sidebar while keeping usage details available in the chat composer and Usage page. Thanks @shakkernerd and @vincentkoc.
- Workboard dispatch cap: add a request-scoped
--max-startsoverride while preserving the default cap, sequential starts, and one-card-per-owner guard. (#100174) Thanks @souvikDevloper, @Souvikalp, and @jwest75674. - Plugin install provenance warnings: require explicit
--forceacknowledgement for arbitrary executable plugin sources in CLI and chat installs, keep trusted ClawHub, bundled, official-catalog, and tracked-update flows frictionless, and restrict Crestodian installs to trusted sources. (#102197) Thanks @jesse-merhi. - Cloud workers: add session placement, dispatch, and worker-turn routing for remote session execution. (#106332)
- Paired-node coding agents: discover OpenCode and Pi sessions and continue Codex and Claude catalog sessions through streaming CLI agent runs. (#106941, #106927, #105833)
- Catalog sessions: create eligible catalog sessions directly from the Control UI sidebar. (#105810) Thanks @fuller-stack-dev.
- Managed worktrees: configure cleanup limits by count and total size from Settings. (#106224)
- Cron history: serve scheduled-run history from the task ledger. (#106392)
- Coding-agent memory: import Codex and Claude Code memory into the Control UI. (#106406)
- MCP isolation: scope MCP server connections to their requesting session. (#106359) Thanks @obviyus.
- Discord voice: notify agents when voice-channel participants change. (#107004)
- Codex usage: show the signed-in account email alongside app-server usage windows. (#106500)
- Skill Workshop: scan prior session history for conservative, reviewable skill ideas. (#106766)
- Task previews: show the latest tasks from the running-tasks status row. (#107297)
- Session changes: show the active branch and local changed-file state in Control UI sessions. (#106835)
- Channel progress: reserve progress drafts for long-running work and use the model's own preamble as the status headline. (#106026)
- Codex CLI: bump the bundled plugin to Codex CLI 0.144.6 and align GPT-5.6 Codex context metadata with the upstream 272k limit.
Fixes
- Cloud worker derived workspace caches: exclude Python caches, dependency trees, and macOS metadata symmetrically from outbound sync and inbound reconciliation so local cache rewrites cannot fence later cloud results or worker reclaim.
- Codex model status diagnostics: report a configured Codex route as unavailable when its harness plugin is disabled, missing, or quarantined, while preserving the separate credential result and making
models status --checkfail instead of silently treating fallback execution as healthy. Thanks @shakkernerd. - Gateway control-plane rate limiting: use per-method buckets with a 30-per-minute budget so interactive admin writes remain responsive while retaining runaway-loop protection.
- Signal shutdown delivery: drain already-accepted ingress before stopping the monitor so messages received immediately before shutdown finish processing instead of being dropped.
- External supervisor restart health: accept device-identity policy closes only when the replacement gateway lock and listener PID agree, preventing OCM-managed restarts from timing out after a successful handoff. Thanks @shakkernerd.
- ACPX cleanup process inspection: bound host process-table reads so stalled
pscalls cannot hang gateway startup or session cleanup while retaining fail-closed ownership checks. Thanks @Alix-007. - Cron lifecycle conflict retries: preserve execution-phase retry decisions across scheduled, manual, and startup-recovered runs so post-execution claim conflicts cannot replay completed messages or tools. Fixes #108428. Thanks @yetval.
- Discord gateway metadata deadline: carry the existing lookup deadline through DNS and proxy preflight, request headers, and response bodies so stalled gateway startup abor...
openclaw 2026.7.2-beta.2
2026.7.2
Highlights
- Remote coding sessions: run Control UI sessions on cloud workers, open Codex and Claude catalog sessions in terminals on their owning hosts, and resume OpenCode and Pi sessions directly in a terminal. (#107670, #107086, #107200)
- Native automation and nodes: bring Automations parity to mobile, add foreground Voice Wake on Android, and expose camera, location, and notification capabilities from headless Linux nodes. (#106355, #107081, #107193)
- Safer channel operation: prevent Telegram durable-ingress loss after restarts, keep Signal stop and approval controls responsive during active turns, and stop channel allowlists from granting owner access. (#107288, #107422, #107403) Thanks @obviyus, @arduano, and @yetval.
- Guided Control UI setup: configure model providers from Settings, onboard channels through a guided setup page, and choose images and models while creating sessions. (#106490, #106469, #107358) Thanks @alexandre-leng and @fuller-stack-dev.
- Gateway and session recovery: prevent restart admission from wedging the Gateway, recover reply sessions after finalization stalls, and keep one-shot cron jobs enabled through lifecycle claim races. (#107339, #106792, #107236) Thanks @obviyus, @joshavant, @charliemeyer2000, and @SL4N.
- Install and packaging: add Linux deb and AppImage bundles with Gateway guidance, publish them from stable main-based releases, and let Windows installs continue immediately after winget adds Node.js. (#106533, #106891, #106862)
Changes
- External gateway supervision: add
OPENCLAW_SUPERVISOR_MODE=externalfor lifecycle owners such as OCM, preserving verified restart and deferral behavior without exposing native service authority, blocking native service mutation and self-update, and providing a versioned atomic restart-handoff consume contract. Thanks @shakkernerd. - ClickClack guided setup: configure ClickClack from
openclaw onboardoropenclaw channels add clickclackwith URL, token, and workspace prompts, default-account env fallback, nonfatal live connection validation, and gateway-aware next steps that connect automatically when OpenClaw is already running. Thanks @shakkernerd. - ClickClack command menus: publish each bot's native OpenClaw commands to ClickClack composer autocomplete at gateway startup, with per-account opt-out and nonfatal compatibility handling for older tokens and servers. Thanks @shakkernerd and @vincentkoc.
- Skill Workshop approvals: run agent-initiated apply, reject, and quarantine actions without an additional approval prompt by default while preserving
skills.workshop.approvalPolicy: "pending"as an opt-in approval gate. Thanks @shakkernerd. - TUI fuzzy selectors: delegate list matching to pi-tui, adding slash-token and alpha-number matching while removing the local matcher fork.
- macOS paired-node terminals: advertise duplex Codex and Claude terminal resume commands from the embedded node host and forward interactive input and cancellation through the native app bridge. (#107335)
- Control UI catalog terminals: open eligible Codex and Claude Code sessions in the native CLI on their Gateway or paired-node host, with viewer-versus-terminal preferences, validated resume commands, and an interactive PTY relay. (#107086) Thanks @vincentkoc.
- Skill Workshop history review: add a manual, newest-first session scan that progressively searches older substantial work for conservative skill ideas, stores only SQLite cursor metadata, and leaves up to three results as pending proposals even when autonomous self-learning is disabled. (#106182)
- OpenAI GPT-5.6 defaults: use
openai/gpt-5.6(Sol alias) for fresh API-key setup and exactopenai/gpt-5.6-solfor fresh Codex/OAuth setup, default Sol to medium reasoning across both runtimes, and preserve existing primaries, fallbacks, aliases, and explicit GPT-5.5 selections. (#103234) - iOS offline chat: pre-paint recent sessions and canonical transcripts from a protected, bounded per-gateway cache, keep sending disabled offline, and purge cached conversation text when pairing is reset. (#100194)
- Slack progress indicators: use Slack's native assistant thread status and rotating loading messages by default while keeping acknowledgement reactions static; lifecycle reaction updates now require
messages.statusReactions.enabled: true. - Control UI Talk controls: keep voice, model, sensitivity, and other realtime defaults in Settings → Communications → Talk, and use the composer microphone caret to select any browser audio input. (#101046)
- Control UI session workspace shortcut: expand or collapse the active Chat pane's session workspace rail with ⇧⌘B without changing the main app sidebar or the separate detail and Canvas preview panel. Thanks @shakkernerd.
- Control UI Settings shortcut: open Settings with ⇧⌘, while leaving the browser-owned ⌘, shortcut unchanged. Thanks @shakkernerd.
- Control UI chat layout: center the transcript on the composer axis, keep assistant and tool output left and user bubbles right within the same readable frame, and preserve custom message-width overrides. (#104474) Thanks @shakkernerd, @vincentkoc, and @zw-xysk.
- Control UI composer footer: center the chat settings chip and model controls between the divider and the card edge instead of pinning them to the divider. (#105866)
- Control UI assistant actions: keep assistant name and time first while placing hover actions beside them on the left instead of at the far edge. Thanks @shakkernerd.
- Control UI message context: reveal per-message token, context, and model details from the timestamp on hover or activation instead of showing a separate Context button.
- Control UI session titles: reveal truncated recent-session names with a reduced-motion-safe hover animation.
- Control UI sidebar usage: remove the provider usage quota row from the expanded sidebar while keeping usage details available in the chat composer and Usage page. Thanks @shakkernerd and @vincentkoc.
- Workboard dispatch cap: add a request-scoped
--max-startsoverride while preserving the default cap, sequential starts, and one-card-per-owner guard. (#100174) Thanks @souvikDevloper, @Souvikalp, and @jwest75674. - Plugin install provenance warnings: require explicit
--forceacknowledgement for arbitrary executable plugin sources in CLI and chat installs, keep trusted ClawHub, bundled, official-catalog, and tracked-update flows frictionless, and restrict Crestodian installs to trusted sources. (#102197) Thanks @jesse-merhi. - Cloud workers: add session placement, dispatch, and worker-turn routing for remote session execution. (#106332)
- Paired-node coding agents: discover OpenCode and Pi sessions and continue Codex and Claude catalog sessions through streaming CLI agent runs. (#106941, #106927, #105833)
- Catalog sessions: create eligible catalog sessions directly from the Control UI sidebar. (#105810) Thanks @fuller-stack-dev.
- Managed worktrees: configure cleanup limits by count and total size from Settings. (#106224)
- Cron history: serve scheduled-run history from the task ledger. (#106392)
- Coding-agent memory: import Codex and Claude Code memory into the Control UI. (#106406)
- MCP isolation: scope MCP server connections to their requesting session. (#106359) Thanks @obviyus.
- Discord voice: notify agents when voice-channel participants change. (#107004)
- Codex usage: show the signed-in account email alongside app-server usage windows. (#106500)
- Skill Workshop: scan prior session history for conservative, reviewable skill ideas. (#106766)
- Task previews: show the latest tasks from the running-tasks status row. (#107297)
- Session changes: show the active branch and local changed-file state in Control UI sessions. (#106835)
- Channel progress: reserve progress drafts for long-running work and use the model's own preamble as the status headline. (#106026)
- Codex CLI: bump the bundled plugin to Codex CLI 0.144.4.
Fixes
- External supervisor restart health: accept device-identity policy closes only when the replacement gateway lock and listener PID agree, preventing OCM-managed restarts from timing out after a successful handoff. Thanks @shakkernerd.
- ACPX cleanup process inspection: bound host process-table reads so stalled
pscalls cannot hang gateway startup or session cleanup while retaining fail-closed ownership checks. Thanks @Alix-007. - Cron lifecycle conflict retries: preserve execution-phase retry decisions across scheduled, manual, and startup-recovered runs so post-execution claim conflicts cannot replay completed messages or tools. Fixes #108428. Thanks @yetval.
- Discord gateway metadata deadline: carry the existing lookup deadline through DNS and proxy preflight, request headers, and response bodies so stalled gateway startup aborts cleanly. (#104580) Thanks @hugenshen.
- Control UI cloud session thinking: expose reasoning level in the New Session model picker and persist the selected level before cloud dispatch.
- iOS fresh-install setup: atomically redact spent setup credentials before Keychain cleanup so a deferred item deletion no longer disconnects a successfully paired device. Fixes #107591 Thanks @dagmarjeeves-lab and @vincentkoc.
- Tlon SSE connect cleanup: disarm opening deadlines after failed HTTP responses and rejected stream opens so reconnect attempts cannot leave stale timers behind. (#104585) Thanks @hugenshen.
- LINE reply-token media kinds: honor video and audio metadata on inbound replies, share the canonical media builder with proactive sends, and fail visibly instead of recording empty media-only deliveries. (#106515) Thanks @edenfunf.
- Mattermost websocket connection deadlines: bound opening handshakes so stalled TCP peers cannot hang channel startup indefinitel...