Skip to content

OpenClaw

Open-source personal AI assistant that runs on your own devices and meets you in the chat apps you already use. Created by Peter Steinberger (Austria), MIT licensed, stewarded by the OpenClaw Foundation, about 390k GitHub stars (2026-09, per the Tools Catalogue).

TL;DR

OpenClaw is a self-hosted Gateway that connects 32 messaging channels (WhatsApp, Telegram, Slack, Discord, iMessage, Teams, Signal and more) and native apps to hosted or local models through swappable agent runtimes (its own embedded runtime, Codex, Claude Code, ACP harnesses). The agent executes shell commands, edits files, drives a browser, schedules automations, uses skills from ClawHub and MCP servers, and keeps Markdown memory in its workspace. Free and MIT-licensed with no paid tier; you pay only for model usage. Its security record (high-severity CVEs, 135k+ exposed instances, a poisoned skill registry in early 2026) makes deliberate hardening mandatory: tool execution runs on the host unless you enable sandboxing.

Key Facts

Property Value
Latest Version 2026.9.6 (2026-09-23), npm latest
Extended-stable 2026.7.35 (2026-09-21)
Versioning Calendar versions YYYY.M.PATCH; several releases per week; channels stable, extended-stable, beta, dev
Repository openclaw/openclaw
License MIT (copyright OpenClaw Foundation), no enterprise edition
Governance OpenClaw Foundation, independent US 501(c)(3); employs the core team and signs releases
Language / runtime TypeScript; Node.js 24.16+ or 26.1+
Stars ~390k (2026-09, per the Tools Catalogue)
Creator Peter Steinberger (joined OpenAI in February 2026; OpenAI is a donor, not an owner)
First Release November 2025 (as Clawdbot)
Current Name OpenClaw (since January 30, 2026)
Default endpoint ws://127.0.0.1:18789 (Gateway WS + Control UI)
Config ~/.openclaw/openclaw.json (JSON5, strict schema)
Install Installer script https://openclaw.ai/install.sh (macOS/Linux/WSL2), install.ps1 (Windows), or npm install -g openclaw@latest
Docs docs.openclaw.ai
Wikipedia OpenClaw

Architecture at a Glance

One Gateway per host owns channels, sessions, and policy; clients and device nodes connect to it over WebSocket, and an agent runtime executes each turn against a model provider. The full diagram and flows are in Explanation.

graph LR
    CH["Channels<br/>WhatsApp, Telegram, Slack, ..."] --> GW["Gateway<br/>127.0.0.1:18789"]
    UI["Control UI, CLI, apps"] --> GW
    ND["Nodes<br/>iOS, Android, macOS"] <--> GW
    GW --> RT["Agent runtime<br/>openclaw, codex, claude-cli, ACP"]
    RT <--> LLM["Model providers"]
    RT --> EX["Tools<br/>host or sandbox"]
    HUB["ClawHub<br/>skills, plugins"] -.-> GW

History & Naming

Warelay, then Clawd/Clawdbot (Nov 2025), then Moltbot (Jan 27, 2026, after Anthropic's trademark request), then OpenClaw (Jan 30, 2026). Steinberger joined OpenAI in February 2026, and the OpenClaw Foundation formally launched as a 501(c)(3) in July 2026. Details: Explanation - History & Naming.

Key Features

Multi-Channel Messaging Gateway

The official catalog lists 32 channels: WhatsApp, Telegram, Slack, Discord, Google Chat, Signal, iMessage, Microsoft Teams, Matrix, Mattermost, IRC, LINE, Feishu, Nextcloud Talk, Nostr, QQ, SMS, Synology Chat, Tlon, Twitch, Zalo, WeChat, WeCom, WebChat, A2A and more. Most ship as official plugins. Full table: Reference - Channels.

Agentic Capabilities

  • Shell execution (exec, process) on the host or in a sandbox backend (Docker, Podman, SSH, OpenShell, Crabbox)
  • File tools (read, write, edit, apply_patch)
  • Browser control and web search/fetch
  • Scheduled automations (cron), hooks, webhooks, heartbeat check-ins
  • Sub-agents, multi-agent routing, cloud workers, and paired device nodes
  • Canvas/A2UI widgets and dashboards in the Control UI
  • Voice on macOS/iOS/Android, plus telephony via the Voice Call plugin

Memory System

Memory is plain Markdown in the agent workspace, provided by a swappable memory plugin (default memory-core):

Tier File Scope
User model USER.md Stable preferences, loaded at session start
Long-term MEMORY.md Durable facts and decisions, loaded at session start
Daily memory/YYYY-MM-DD.md Today and yesterday on /new; searchable via memory_search
Session Transcript in SQLite Current conversation state

A background "dreaming" sweep distills daily notes into MEMORY.md. See Reference - Memory and Workspace Files.

Skills Marketplace (ClawHub)

  • 49 bundled skills ship in the repo's skills/ directory (counted at main on 2026-09-27); per VISION.md, new skills are published to ClawHub rather than core
  • ClawHub is the public registry for skills and plugins, with VirusTotal/ClawScan scanning and trust verdicts
  • Skills follow the AgentSkills SKILL.md format; agents can also draft skills through the Skill Workshop for human approval
  • Earlier notes cited clawhub.dev; the registry domain is clawhub.ai

MCP Support

OpenClaw is both an MCP client (stdio, SSE, Streamable HTTP, OAuth; managed with openclaw mcp add/probe) and an MCP server (openclaw mcp serve exposes channel conversations to MCP clients such as Claude Code). It also speaks ACP and A2A 1.0.

LLM Agnostic

Model providers are plugins: Anthropic, OpenAI (including Codex subscription auth), Google, xAI, GitHub Copilot, DeepSeek, local servers (Ollama, vLLM) and more. Agent runtimes are swappable too (built-in, Codex app-server, Claude Code CLI, ACP harnesses). Optional Decision Models (2026.9.6) can route small structured choices to Jev via the TypeSafe plugin.

Evaluation

Pros Cons
One assistant across 32 channels and native apps Large attack surface; high-severity CVE history
MIT, foundation-governed, no paid tier or telemetry by default Sandboxing and exec approvals are off by default
Swappable models and agent runtimes, strong plugin SDK Not a multi-tenant boundary; one trust domain per Gateway
Very active development, signed releases, release channels incl. extended-stable Fast churn: config schema and CLI change often, strict validation refuses stale config
Large ecosystem (ClawHub, NemoClaw, claworc) Third-party skills/plugins have carried malware; plugins run in-process

When it fits: a personal or small-team assistant that should live in your chat apps and act on your machines and accounts, operated by someone willing to maintain a hardened Gateway.

When it does not fit: shared agents for mutually untrusted users, environments that cannot tolerate host code execution by an LLM, or teams unable to track frequent security releases.

Ecosystem (Claw Family)

See Claw Family Ecosystem for the full table. Key extensions:

  • NemoClaw (NVIDIA, Apache 2.0, alpha) - runs OpenClaw inside NVIDIA OpenShell sandboxes with managed inference and network policy
  • claworc - multi-instance orchestration dashboard with per-instance containers
  • Lobster - typed workflow runtime with approval gates (official @openclaw/lobster plugin)
  • AutoResearchClaw - 23-stage autonomous research pipeline
  • Paperclip - enterprise management layer

Security Concerns

Security Track Record

OpenClaw's security history demands caution for production use. Summary below; analysis in Explanation - Security Model, CVE table in Reference - CVE Record.

  • CVE-2026-25253 (CVSS 8.8, published 2026-02-01) - one-click Gateway token exfiltration via a gatewayUrl query parameter, leading to RCE; fixed in 2026.1.29.
  • March 2026 - a cluster of disclosures (reported as nine CVEs in four days, March 18-21); CVE-2026-32922 (CVSS 9.9) allowed operator.pairing callers to mint admin tokens; fixed in 2026.3.11.
  • 135,000+ exposed instances across 82 countries (SecurityScorecard STRIKE, February 2026).
  • 341 malicious skills found on ClawHub by Koi Security (ClawHavoc, February 2026), later updated to 824; ClawHub now scans all skills with VirusTotal.
  • Prompt injection is assumed by the project's trust model; mitigations are tool policy, sandboxing, and approvals, not the model.
  • 647 GitHub security advisories published by 2026-08-27 (project figure; a disclosure count, not a safety score).

Deployment Recommendation

Keep the Gateway on loopback with auth on, never expose port 18789 directly, enable sandboxing, stay on a current release channel, audit ClawHub skills before installing, and use NemoClaw/OpenShell for confidential data. Checklist: Reference - Hardening Checklist.

Pricing

Tier Cost
Self-hosted Free (MIT) + model/API costs, which depend on the model and usage (no official estimate is published)
Managed hosting Third-party only; the Foundation has no paid tier or hosted service
NemoClaw Free (Apache 2.0); NVIDIA hardware optional depending on inference route

Topic Map

  • How-to Guides: install, configure, secure, operate, upgrade and troubleshoot an OpenClaw Gateway (2026.9.x).
  • Reference: versions and channels, requirements, paths and ports, config keys, CLI command map, channels, skills, MCP, CVEs, hardening checklist.
  • Explanation: hub-and-spoke Gateway architecture, design choices, security model and threat model.

Sources

Questions

Open

  • How will Foundation governance (Dave Morin as chair, donor mix including OpenAI) shape roadmap neutrality across model labs over time?
  • What share of malicious ClawHub uploads does VirusTotal/ClawScan catch now, versus the 341-824 skills found before scanning?
  • Does Lobster (plus Task Flow) scale for enterprise-grade automation, or is it still best for personal workflows?
  • Did the 2026 H2 stability work (2026.9.1 startup recovery, 2026.9.6 unfinished-work recovery) end the session-crash complaints reported earlier in 2026?
  • Will sandboxing or exec approvals become default-on, given the project's "security and safe defaults" priority?
  • Is the full list of the March 18-21, 2026 CVE cluster published in one place? (Only CVE-2026-32922 verified here.)

Resolved

  • How stable is the non-profit foundation governance model post-Steinberger? - The Foundation formally launched as a 501(c)(3) in July 2026 with a full-time team; it employs the core team and signs releases, and Steinberger continues to steward the project from OpenAI (README; press coverage). Long-term stability remains an open question above.