OpenClaw Release Notes
252 release notes curated from 14 sources by the Releasebot Team. Last updated: Aug 21, 2026
- Aug 21, 2026
- Date parsed from source:Aug 21, 2026
- First seen by Releasebot:Aug 21, 2026
release-publish/0368cbf252d8-1787307721
OpenClaw fixes its release workflow by pinning the deployed ClawHub workflow.
fix(release): pin deployed ClawHub workflow
Original source - Aug 21, 2026
- Date parsed from source:Aug 21, 2026
- First seen by Releasebot:Aug 21, 2026
release-publish/43dc8d2bb38f-1787305092
OpenClaw fixes staged ClawHub publication authorization.
fix(release): authorize staged ClawHub publication
Original source All of your release notes in one feed
Join Releasebot and get updates from OpenClaw and hundreds of other software products.
- Aug 21, 2026
- Date parsed from source:Aug 21, 2026
- First seen by Releasebot:Aug 21, 2026
release-publish/bfa7c3d38e6d-1787271693
OpenClaw fixes release QA to accept frozen beta.3 evidence.
fix(release): accept frozen beta.3 QA evidence (#126894)
Original source - Aug 21, 2026
- Date parsed from source:Aug 21, 2026
- First seen by Releasebot:Aug 21, 2026
release-publish/b6d7394a98a8-1787299755
OpenClaw fixes a release issue to pass ClawHub parent state policy.
fix(release): pass ClawHub parent state policy
Original source - Aug 20, 2026
- Date parsed from source:Aug 20, 2026
- First seen by Releasebot:Aug 21, 2026
release-publish/a4493e2521b0-32410682801
OpenClaw fixes release tagging to trust exact protected tooling tags.
fix(release): trust exact protected tooling tags (#126809)
Original source Similar to OpenClaw with recent updates:
- Perplexity release notes29 release notes · Latest Jul 27, 2026
- Cursor release notes127 release notes · Latest Aug 19, 2026
- Obsidian release notes107 release notes · Latest Aug 20, 2026
- Anthropic release notes770 release notes · Latest Aug 21, 2026
- OpenAI release notes944 release notes · Latest Aug 21, 2026
- xAI release notes217 release notes · Latest Aug 21, 2026
- Aug 20, 2026
- Date parsed from source:Aug 20, 2026
- First seen by Releasebot:Aug 20, 2026
release-publish/45ed68e6ea62-1787220256: fix(release): accept trusted Codex scan layouts (#126588)
OpenClaw tightens trusted release inventory to accept one reviewed Codex source layout and fail closed on invalid layouts.
Allow the trusted release inventory to accept exactly one complete reviewed Codex source layout while remaining fail closed for partial, mixed, duplicate, absent, or unknown layouts.
Frozen-candidate and upstream Codex contract proof are recorded in the PR.
Original source - Aug 20, 2026
- Date parsed from source:Aug 20, 2026
- First seen by Releasebot:Aug 20, 2026
release-publish/c28c279afa37-1787225611: fix(release): keep frozen validation independent of main (#126622)
OpenClaw fixes release validation with frozen contract, candidate identity checks, and release isolation gate cleanup.
fix(release): freeze validation tooling identity
fix(release): enforce frozen validation contract
fix(release): validate candidate identity in parent
fix(ci): close release isolation gate findings
Original source - Aug 16, 2026
- Date parsed from source:Aug 16, 2026
- First seen by Releasebot:Aug 18, 2026
pr-124528-profiles
OpenClaw reuses prepared plugin generations in the gateway for better performance.
perf(gateway): reuse prepared plugin generations
Original source - Aug 15, 2026
- Date parsed from source:Aug 15, 2026
- First seen by Releasebot:Aug 15, 2026
OpenClaw 2026.8.1-beta.2
OpenClaw ships a broad 2026.8.1 release with stronger secret egress security, atomic model and runtime switching, shared plugin lifecycle monitors, SQLite snapshot backup and restore, macOS app profile isolation, and a host of Control UI, Buzz, and gateway reliability upgrades.
2026.8.1
Highlights
Secret egress host binding: bind each shared-store secret to exact HTTPS destination hosts across CLI, Gateway RPC, and Control UI so unbound sentinel substitution fails closed before plaintext egress. Thanks @shakkernerd.
GPT-5.6 Ultra and runtime switching: support Sol, Terra, and Luna across OpenClaw and Codex engines; keep model, runtime, and thinking selection atomic through /model and fallback; and add live matrix coverage for both harnesses. Thanks @anyech and @vincentkoc.
Channel plugin ingress monitors: add a shared plugin SDK monitor for durable admission, polling, pruning, claim identity validation, adoption handoff, and shutdown, and migrate IRC, Synology Chat, and Google Chat to the shared lifecycle. Thanks @vincentkoc and @shakkernerd.
SQLite snapshots: add openclaw backup sqlite create|list|verify|restore for compact, verified global and per-agent database artifacts with fresh-target-only restore. Thanks @giodl73-repo.
macOS app profiles: isolate named app instances across state, preferences, Keychain, Gateway services, and duplicate-instance ownership while keeping host-global login and node services untouched. Thanks @shakkernerd and @vincentkoc.
Plugin install provenance warnings: require explicit --force acknowledgement for arbitrary executable plugin sources in CLI and chat installs, keep trusted ClawHub, bundled, official-catalog, and tracked-update flows frictionless, and restrict Crestodian installs to trusted sources. Thanks @jesse-merhi and @vincentkoc.
Control UI update recovery: the "A new version is available" Reload button now waits out the gateway restart that stranded the chunk and reloads as soon as it answers, instead of silently doing nothing and leaving a manual hard reload as the only way out. Thanks @vincentkoc.
Changes
Secret egress host binding: bind each shared-store secret to exact HTTPS destination hosts across CLI, Gateway RPC, and Control UI so unbound sentinel substitution fails closed before plaintext egress. Thanks @shakkernerd.
Release validation: defer beta candidate Parallels smoke to postpublish release:beta-smoke by default, keep stable/full prepublish coverage, and bound nested release workflow monitors with explicit job timeouts. Thanks @vincentkoc.
macOS app profiles: isolate named app instances across state, preferences, Keychain, Gateway services, and duplicate-instance ownership while keeping host-global login and node services untouched. Thanks @shakkernerd and @vincentkoc.
Developer workflow: remove the obsolete scoped-commit helper and use standard Git commands in isolated worktrees.
Plugin uninstall cleanup: remove exact recorded install paths from plugins.load.paths for marketplace, npm, and other managed installs while preserving parent, child, prefix, and unrelated paths. Thanks @vincentkoc.
Fixed Crabbox hydration on unprivileged cloud sandboxes by falling back to a user-writable pnpm store when the shared /var/cache/crabbox cache is unavailable, preserving the hardlink import mode after hydration, and making Docker an explicit routed capability instead of an implicit install requirement. Thanks @vincentkoc and @joshavant.
Browser extension relay CDP compat: answer Target.getBrowserContexts so Puppeteer-based clients (chrome-devtools-mcp) can drive the paired Chrome without the remote-debugging permission prompt, serve DevTools-style /json/list target descriptors, and add openclaw browser extension cdp to print the relay endpoint plus auth header for external CDP clients. Thanks @vincentkoc.
Local model setup: advertise provider-owned Ollama, llama.cpp, and LM Studio setup choices to Control UI and macOS, retry unavailable LM Studio services in place, and verify the exact prepared model before showing success. Thanks @vincentkoc.
Control UI first-run setup: continue verified model setup into Custodian, explain that the web app is ready without a channel, and offer an optional dismissible path to Channels.
Fish Audio speech: add hosted S2.1 synthesis with streaming, voice notes, voice discovery, and telephony, plus local Fish S2 Pro reference-voice streaming in native macOS Talk. Thanks @Conan-Scott, @vincentkoc, and @Patrick-Erichsen.
Control UI cloud workspace conflicts: surface staged-ref guidance, bounded conflicted paths, structured transcript events, and sidebar attention for cloud worker results that kept local versions. Thanks @vincentkoc.
Control UI update recovery: the "A new version is available" Reload button now waits out the gateway restart that stranded the chunk and reloads as soon as it answers, instead of silently doing nothing and leaving a manual hard reload as the only way out. Thanks @vincentkoc.
Control UI sender identity polish: attributed user messages show the author's real avatar in an always-visible gutter on identity-resolving gateways, sender labels drop the opaque profile-UUID suffix (new and historical transcripts), and profile-id senders resolve avatars through the canonical gateway route. Thanks @shakkernerd and @vincentkoc.
Control UI who's-online roster: click the sidebar footer facepile to open a scrollable roster of everyone online, showing each person's avatar, name, and email with your own entry pinned first.
Discord and Slack native login: register /login in native command menus while keeping pairing-code issuance limited to private chats and the Web UI.
Control UI user profiles: let trusted-proxy users manage their own display name and avatar, resolve attributed chat and presence identities through uploaded avatars or a private cached Gravatar proxy, and keep other users' profiles admin-only. Thanks @vincentkoc.
Trusted-proxy browser pairing: optionally auto-approve new Control UI and WebChat devices from allowlisted proxy identities with non-admin scope caps, while keeping existing-device upgrades manual. Thanks @vincentkoc.
Channel plugin ingress monitors: add a shared plugin SDK monitor for durable admission, polling, pruning, claim identity validation, adoption handoff, and shutdown, and migrate IRC, Synology Chat, and Google Chat to the shared lifecycle. Thanks @vincentkoc and @shakkernerd.
Dashboard MCP apps: pin originating-session MCP app views as living dashboard widgets, renew their sandboxed view leases, and keep tool interactivity behind revision-bound grants with graceful stale-state recovery. Thanks @vincentkoc.
External gateway supervision: add OPENCLAW_SUPERVISOR_MODE=external for lifecycle owners such as OCM, preserving verified restart and deferral behavior without exposing native service authority, blocking native service mutation and self-update, and providing a versioned atomic restart-handoff consume contract. Thanks @shakkernerd.
Buzz message fidelity: preserve Markdown output and accept Buzz normal, rich-content, and structured-diff room messages through the existing authorized inbound path. Thanks @shakkernerd, @vincentkoc, and @zw-xysk.
Buzz typing indicators: show room- and thread-scoped typing during agent replies and heartbeat deliveries, refresh through the active authenticated connection without waiting for relay acknowledgement, and drop ephemeral updates safely during disconnects or shutdowns. Thanks @shakkernerd and @vincentkoc.
Buzz sender directory: expose current bot, member, room, and room-member directory entries from bounded relay state; use current Buzz profile and room names in inbound context while preserving public keys and UUIDs as stable authorization and routing identities. Thanks @shakkernerd and @vincentkoc.
Buzz native mentions: resolve unique current room-member names and explicit NIP-27 identities into native p tags for replies, proactive sends, and bounded standalone delivery; reject out-of-room identities and unresolved labels without an explicit identity, and preserve Buzz reply-thread session parsing during maintenance and heartbeat runs. Thanks @shakkernerd, @vincentkoc, and @joshavant.
ClickClack guided setup: configure ClickClack from openclaw onboard or openclaw channels add clickclack with URL, token, and workspace prompts, default-account env fallback, nonfatal live connection validation, and gateway-aware next steps that connect automatically when OpenClaw is already running. Thanks @shakkernerd and @vincentkoc.
ClickClack command menus: publish each bot's native OpenClaw commands to ClickClack composer autocomplete at gateway startup, with per-account opt-out and nonfatal compatibility handling for older tokens and servers. Thanks @shakkernerd and @vincentkoc.
ClickClack bot collaboration: add opt-in bot-authored inbound dispatch with explicit sender authorization, mention gating, retry-safe loop protection, and independent thread budgets while keeping bot traffic denied by default. Thanks @jjjhenriksen, @shakkernerd, and @vincentkoc.
Skill Workshop approvals: run agent-initiated apply, reject, and quarantine actions without an additional approval prompt by default while preserving skills.workshop.approvalPolicy: "pending" as an opt-in approval gate. Thanks @shakkernerd and @vincentkoc.
TUI fuzzy selectors: delegate list matching to pi-tui, adding slash-token and alpha-number matching while removing the local matcher fork.
macOS paired-node terminals: advertise duplex Codex and Claude terminal resume commands from the embedded node host and forward interactive input and cancellation through the native app bridge. (#107335) Thanks @vincentkoc.
Control UI catalog terminals: open eligible Codex and Claude Code sessions in the native CLI on their Gateway or paired-node host, with viewer-versus-terminal preferences, validated resume commands, and an interactive PTY relay. Thanks @vincentkoc.
Control UI coding catalogs: show provider brand icons beside Claude Code and Codex session catalog headings in the sidebar. Thanks @vincentkoc.
Skill Workshop history review: add a manual, newest-first session scan that progressively searches older substantial work for conservative skill ideas, stores only SQLite cursor metadata, and leaves up to three results as pending proposals even when autonomous self-learning is disabled. (#106182) Thanks @vincentkoc and @shakkernerd.
SQLite snapshots: add openclaw backup sqlite create|list|verify|restore for compact, verified global and per-agent database artifacts with fresh-target-only restore. Thanks @giodl73-repo.
GPT-5.6 Ultra and runtime switching: support Sol, Terra, and Luna across OpenClaw and Codex engines; keep model, runtime, and thinking selection atomic through /model and fallback; and add live matrix coverage for both harnesses. Thanks @anyech and @vincentkoc.
OpenAI GPT-5.6 defaults: use openai/gpt-5.6 (Sol alias) for fresh API-key setup and exact openai/gpt-5.6-sol for fresh Codex/OAuth setup, default Sol to medium reasoning across both runtimes, and preserve existing primaries, fallbacks, aliases, and explicit GPT-5.5 selections. (#103234) Thanks @shakkernerd and @vincentkoc.
Meta provider: add bundled muse-spark-1.1 model support with Responses API streaming, tool calls, encrypted reasoning replay, onboarding, and standalone npm/ClawHub distribution. Thanks @HamidShojanazeri and @vincentkoc.
Android chat agent selector: switch the active agent directly from the live chat screen while keeping chat, Talk mode, and home canvas on the same canonical session. Thanks @bcperry and @joshavant.
Gateway host status: show the connected Gateway's host, network address, OS, runtime, uptime, CPU, memory, and disk details in Control UI Settings. Thanks @vincentkoc.
iOS offline chat: pre-paint recent sessions and canonical transcripts from a protected, bounded per-gateway cache, keep sending disabled offline, and purge cached conversation text when pairing is reset. (#100194) Thanks @vincentkoc.
Slack progress indicators: use Slack's native assistant thread status and rotating loading messages by default while keeping acknowledgement reactions static; lifecycle reaction updates now require messages.statusReactions.enabled: true. Thanks @vincentkoc.
Control UI Talk controls: keep voice, model, sensitivity, and other realtime defaults in Settings → Communications → Talk, and use the composer microphone caret to select any browser audio input. (#101046) Thanks @vincentkoc.
Control UI session workspace shortcut: expand or collapse the active Chat pane's session workspace rail with ⇧⌘B without changing the main app sidebar or the separate detail and Canvas preview panel. Thanks @shakkernerd and @vincentkoc.
Control UI Settings shortcut: open Settings with ⇧⌘, while leaving the browser-owned ⌘, shortcut unchanged. Thanks @shakkernerd.
Control UI chat layout: center the transcript on the composer axis, keep assistant and tool output left and user bubbles right within the same readable frame, and preserve custom message-width overrides. (#104474) Thanks @shakkernerd, @vincentkoc, and @zw-xysk.
Control UI composer footer: center the chat settings chip and model controls between the divider and the card edge instead of pinning them to the divider. (#105866)
Control UI assistant actions: keep assistant name and time first while placing hover actions beside them on the left instead of at the far edge. Thanks @shakkernerd.
Cron model selection: choose an agent-turn model in Control UI Quick Create and show configured or default models in cron job rows and details. Thanks @ly85206559, @joshavant, and @vincentkoc.
Control UI GitHub previews: show issue and pull request state, title, author, activity, comments, and change statistics in hover and keyboard-focus cards.
Logbook work journal: add a disabled-by-default bundled plugin that turns paired-node screen snapshots into a private timeline, daily standup, and timeline-grounded Q&A in a plugin-contributed Control UI tab. Thanks @vincentkoc.
Control UI message context: reveal per-message token, context, and model details from the timestamp on hover or activation instead of showing a separate Context button.
Control UI session titles: reveal truncated recent-session names with a reduced-motion-safe hover animation.
Control UI sidebar navigation: show a small customizable pinned destination set, keep the remaining pages under More, move Settings to the footer, and persist sidebar customization in the browser. Thanks @vincentkoc.
Control UI sidebar usage: remove the provider usage quota row from the expanded sidebar while keeping usage details available in the chat composer and Usage page. Thanks @shakkernerd and @vincentkoc.
Android chat code highlighting: render fenced Kotlin, Swift, TypeScript, JavaScript, Python, Bash, and JSON blocks with bounded, theme-aware syntax colors while preserving plain rendering for unknown, partial, or oversized blocks.
Gateway TTS playback: add an operator-scoped tts.speak RPC that returns configured-provider speech as inline whole-clip audio for remote clients. (#100708)
Workboard dispatch cap: add a request-scoped --max-starts override while preserving the default cap, sequential starts, and one-card-per-owner guard. (#100174) Thanks @souvikDevloper, @Souvikalp, and @jwest75674.
Plugin install provenance warnings: require explicit --force acknowledgement for arbitrary executable plugin sources in CLI and chat installs, keep trusted ClawHub, bundled, official-catalog, and tracked-update flows frictionless, and restrict Crestodian installs to trusted sources. Thanks @jesse-merhi and @vincentkoc.
Custodian rich setup controls: render the Gateway's sanitized wizard steps as native selects, multiselects, text fields, and masked secret inputs while preserving text-only chat compatibility. (#114631) Thanks @jesse-merhi and @shakkernerd.
Fixes
Codex subagent fan-out: settle successful terminal yields immediately and preserve requester ownership so completed children reliably resume their parent. Thanks @vincentkoc.
Control UI session companion: load bounded visible session context before answering, keep unavailable questions retryable, and prevent private companion reference wrappers from appearing as answers. Fixes #120746 Thanks @shakkernerd and @maweibin.
Telegram live locations: expose initial, moving, and stopped live-location updates through the channel-neutral message_received hook without starting agent turns for edits.
Updater plugin convergence: keep pre-plugin doctor passes from installing configured plugins before the updater's plugin sweep, while preserving the final post-plugin migration pass and preventing ambient update-phase state from leaking into fresh doctor processes. Thanks @vincentkoc.
Control UI browser tab identity: keep selected tab styling, accessibility, focus, address, and page snapshot aligned across in-place navigation and tab reordering. Fixes #120745 Thanks @shakkernerd and @vincentkoc.
Control UI staged attachments: preserve unsent images, files, pasted images, and large pasted text across same-tab route and narrow split-pane remounts while keeping pane close, mismatched pane/session/Gateway remounts, application shutdown, and hard reload as cleanup boundaries. Fixes #121519 Thanks @shakkernerd and @vincentkoc.
Control UI browser annotations: keep marked screenshots and generated page context together in structured composer cards, preserve user-written drafts when annotations are removed or replaced, retain complete unsent annotation packages across same-tab route and active split-pane remounts, and offer bounded Undo without restoring removed context into another session. Fixes #120744 Thanks @shakkernerd and @vincentkoc.
Control UI profile avatar refreshes: carry canonical content revisions through mutation responses and live presence so rapid replacements refresh every connected browser without stale cache rollback. Thanks @shakkernerd and @vincentkoc.
Control UI appearance accessibility: keep the unavailable custom-theme card announced as an Import command while preserving selected-state semantics for selectable themes and text sizes. Thanks @shakkernerd.
Control UI dashboard index refresh: keep an open Dashboards page current after session changes, agent-scope updates, and Gateway reconnects while preserving the last safe list until replacement hydration completes. Fixes #120602 Thanks @shakkernerd and @vincentkoc.
Browser extension relay security: require canonical 64-character relay secrets and safe WebSocket pairing URLs, and recheck OpenClaw tab-group consent at the extension edge before every authority-bearing existing-tab command. Thanks @vincentkoc and @joshavant.
Control UI debug diagnostics: keep last-good status, health, model, and heartbeat snapshots visible when refreshes fail, show the failure inside Snapshots, isolate it from Manual RPC state, and prevent older manual calls from overwriting newer ones. Thanks @shakkernerd, @vincentkoc, and @maweibin.
Control UI read-only preferences: keep personal preference edits browser-local without attempting unauthorized config writes or claiming server sync, preserve offline intent for a later authorized reconnect, and restore the current server value on local reset. Thanks @shakkernerd and @vincentkoc.
Control UI owner handoff: give browsers opened by host-issued dashboard and graphical onboarding links durable administrator access, including same-browser recovery from a limited credential, while keeping generic, Telegram, mobile, and ordinary scope-upgrade paths bounded. Thanks @shakkernerd and @vincentkoc.
Control UI agent and skill permissions: gate Agents, Skills, Skill Workshop, and delayed mutation dispatches by the current Gateway method catalog and operator scopes while preserving read-only browsing and legacy Gateway compatibility. Fixes #119176 Thanks @shakkernerd and @vincentkoc.
Guided onboarding skip-UI routing: keep openclaw onboard --skip-ui and openclaw setup --skip-ui on guided onboarding while skipping both browser and terminal handoffs, instead of silently switching to the classic wizard. Thanks @shakkernerd.
Telegram durable ingress: preserve pre-identity control-lane ownership during replay and attempt each drain snapshot row only once per pass, preventing targeted commands from spinning the spool and blocking polling shutdown. Thanks @vincentkoc.
Control UI operator session permissions: honor Gateway-advertised operator scopes for new-thread creation, thread management, checkpoints, and sharing controls while preserving read-only navigation and legacy Gateway compatibility. Fixes #117786 Thanks @shakkernerd and @vincentkoc.
Control UI delayed session commands: bind slash-command mutations and confirmed resets to their originating Gateway, recheck current operator scopes after asynchronous work, and retain reset authorization through queued delivery so reconnects cannot target a replacement connection. Thanks @shakkernerd and @vincentkoc.
Control UI archived session deletion: send archive-gated delete requests from Sessions-page row and mixed-selection actions so write-scoped operators can remove archived threads while active-session deletion remains admin-only. Thanks @shakkernerd, @joshavant, and @vincentkoc.
Control UI command recovery: keep delayed detached and immediate command failures scoped to their submitting session, preserving failed drafts and attachments for that pane without overwriting the active session. Fixes #116846 Thanks @shakkernerd and @vincentkoc.
Microsoft Teams message-tool replies: keep automatic live previews from duplicating a message already delivered to the current Teams conversation, while preserving distinct follow-up text and cross-conversation sends. Fixes #116397. (#116398) Thanks @a-tokyo, @vincentkoc, and @maweibin.
Buzz plugin packaging: keep the live QA runner on the shipped QA runner SDK surface and remove the obsolete package shrinkwrap so standalone npm and ClawHub package builds use current host exports and dependency resolutions. Thanks @shakkernerd and @vincentkoc.
Control UI sharing connection isolation: discard stale visibility and membership mutation results after switching gateways or accounts so previous-connection refreshes and errors cannot update the replacement connection. Fixes #116800 Thanks @shakkernerd and @vincentkoc.
Control UI session refreshes: preserve explicitly queued list filters and background hydration across later Gateway event invalidation, while keeping append pagination followed by a canonical refresh. Fixes #116697 Thanks @shakkernerd and @vincentkoc.
Gateway device clock skew: sign device proofs with the Gateway-issued challenge timestamp across TypeScript, Control UI, browser extension, Android, Apple, Linux, and watchOS clients so incorrect local clocks no longer block authentication, while retaining no-challenge compatibility for pre-challenge Control UI servers and older watch-node HTTP endpoints and keeping nonce binding and freshness checks enforced. Fixes #103455 Thanks @joshavant and @vincentkoc.
Control UI dynamic deep links: reuse the initial route loader result when publishing real agent, session, dashboard, Workboard, Memory, and Plugins paths, avoiding redundant route-loader work during startup. Thanks @shakkernerd and @vincentkoc.
Linux gateway service ownership: refuse user-scope systemd publication and activation when the same gateway unit name is already owned or cannot be verified in the system scope, including --force, with actionable recovery guidance instead of creating restart-looping dual managers. Fixes #116129 Thanks @vincentkoc Thanks @obviyus and @vincentkoc.
macOS remote tunnel lifecycle: prevent cancelled or superseded restart backoffs from recreating SSH tunnels, and join a tunnel create that another caller started while the actor was suspended.
macOS location permission requests: coalesce concurrent prompts so every caller resumes, and stop cancelled timeouts from opening Settings or completing a newer request. Thanks @vincentkoc.
macOS Voice Wake cancellation: stop superseded silence, capture, and recognizer-restart timers immediately so cancelled work cannot restart the microphone pipeline or keep stale monitor loops alive.
Meeting node audio retention: bound captured audio and terminal retention for Google Meet, Teams, and Zoom node-host sessions, make close idempotent, and force stalled bridge processes down after the graceful shutdown window. Thanks @vincentkoc and @obviyus.
Control UI update reconciliation: preserve an unresolved managed-update request across disconnects, accept the replacement Gateway version when it proves success, and otherwise show explicit recovery guidance instead of trusting an unrelated cached update result or failing silently. Fixes #116075 Thanks @shakkernerd and @vincentkoc.
Control UI model readiness: put AI setup first when no model is selectable, distinguish signed-in credentials from ready providers, and route accounts with no exposed models directly to provider recovery instead of leading with disabled default controls. Thanks @shakkernerd and @vincentkoc.
Control UI Talk session isolation: stop active realtime Talk media and retire its callbacks before chat session changes, Gateway disconnects, or pane disposal so previous-session audio, transcript, camera, and status updates cannot leak into the next view. Thanks @shakkernerd and @vincentkoc.
Control UI Realtime tool calls: execute OpenAI WebRTC tools only from completed responses, bound retained call identities and UTF-8 arguments, and ignore provisional or late duplicate events so long Talk sessions cannot grow tool state without limit. Thanks @vincentkoc and @maweibin.
Gateway reconnect event ordering: reset the shared TypeScript client's outer event-sequence baseline for each replacement WebSocket, preventing gap recovery from comparing unrelated connection generations across Control UI, TUI, SDK, and browser extension clients. Thanks @shakkernerd and @vincentkoc.
Skill Workshop offline apply: preserve configless local proposal apply after upgrades under exclusive Gateway startup ownership, while keeping running Gateway snapshot invalidation fail-closed when CLI credentials are unavailable. Thanks @vincentkoc.
macOS and Control UI keyboard navigation: let Tab traverse links and controls inside embedded Dashboard, browser, and Canvas web views, and keep shortcuts working on non-Latin keyboard layouts without firing during IME composition.
Control UI session diffs: hide unchanged checkout modifications and untracked files that already existed when a thread started, so the diff panel attributes only files touched by that session. Fixes #115628. Thanks @vincentkoc.
Code Mode small-model repair: give malformed pre-dispatch exec calls one bounded correction turn, expose typed failure-phase and bridge-dispatch evidence, and stop retries after nested tools begin. Fixes #115311 Thanks @vincentkoc.
Shared state corruption recovery: evict only the exact cached SQLite owner after proven read or write corruption so a repaired database recovers without a Gateway restart while caller-injected handles remain untouched. Fixes #114269 Thanks @rizquuula and @vincentkoc.
Dev-channel updates: finish package-to-git switches in a fresh CLI process even when source SHA and version metadata are unchanged, preventing stale hashed chunks from loading after the global package root changes. Thanks @joshavant and @vincentkoc.
Parallels release smoke: preserve Windows installer reboot results across Parallels, wait for WSL MSI/default-version readiness, force explicit test-owned gateway stops, and reset Linux package, config, and cache state before install lanes, preventing false prerequisite, safety-gate, and stale-config failures. Thanks @vincentkoc, @joshavant, and @shakkernerd.
OpenAI Realtime Talk auth: remove the non-public Codex OAuth realtime fallback and require an OpenAI Platform API key for Talk, Voice Call, and Discord realtime voice, preventing OAuth-only gateways from advertising a browser session that the live service rejects. Fixes #115021 Thanks @shakkernerd, @vincentkoc, @maweibin, and @joshavant.
Codex native subagent handoff: tell Codex harness turns to use sessions_yield for later-turn child completion delivery, reserve wait_agent for immediately blocked same-turn steps, and omit the guidance when yielding is unavailable. Fixes #115443 Thanks @shakkernerd and @vincentkoc Thanks @bek91, @vincentkoc, and @shakkernerd.
Codex native controls: stop misclassifying valid thinking/fast runtime controls as provider overrides so Codex routes keep their native controls, while provider-native objects and invalid values stay fail-closed. Thanks @VACInc, @vincentkoc, and @shakkernerd.
State snapshot verification: run SQLite snapshot verification in a separate process so worker-thread file closes no longer drop the Gateway's POSIX WAL locks, eliminating spurious WAL misses and I/O errors. Thanks @VACInc, @vincentkoc, and @zw-xysk.
Reply latency with model policies: reuse one immutable plugin-metadata snapshot per model-selection run instead of repeating plugin discovery, cutting reply delay when a model policy is configured. Thanks @VACInc, @vincentkoc, and @shakkernerd.
Claude cache after stalls: recover stalled Claude CLI sessions by forking from the last pre-turn checkpoint so native cache continuity survives without duplicating the pending prompt, with a cold reseed fallback for CLIs without checkpoint support. Thanks @VACInc, @vincentkoc, and @obviyus.
Control UI initial prompts: keep accepted first messages visible across Gateway transport reconnects by binding the process-local handoff to the logical browser client instead of the per-handshake hello snapshot. Thanks @vincentkoc.
Gateway exec deny fallback: fail closed immediately when shell-expanded arguments prevent an allowlisted command from producing an enforceable execution plan and effective policy is ask=off with askFallback=deny, instead of registering an approval that can only time out. Fixes #113191 Thanks @shakkernerd and @vincentkoc Thanks @jrvanwinkle and @vincentkoc.
Cron local-provider preflight: report the guarded-fetch deadline as a bounded preflight timeout, preserve concrete nested non-timeout errors, and carry the failure reason into fallback warnings. Thanks @shakkernerd, @vincentkoc, and @zw-xysk.
Buzz lifecycle recovery: isolate relay and room-role failures to the Buzz account reconnect loop, prevent subscription cleanup from terminating the Gateway, and clear stale channel errors after successful reconnects. Thanks @shakkernerd and @vincentkoc.
Buzz standalone sends: let openclaw message send and other non-Gateway processes open a bounded authenticated relay connection, publish the message, and close cleanly while running Gateways continue to reuse their active connection. Thanks @shakkernerd.
Buzz presence: publish nonblocking online presence when the Gateway connects, refresh it without overlapping heartbeat writes, and let Buzz's final-connection cleanup provide accurate offline state across reconnects and multiple Gateway instances. Thanks @shakkernerd and @vincentkoc.
Buzz bot profiles: persist optional Buzz account names, publish them as bot display names without delaying Gateway startup, preserve existing profile metadata, and include configured owner attestations so Buzz can show verified provenance. Thanks @shakkernerd, @vincentkoc, and @joshavant.
Buzz agent identity: register connected bots in Buzz's agent directory without overwriting existing profile policy, so later room invitations retain the Bot role instead of downgrading the identity to a normal member. Thanks @shakkernerd.
Buzz guided setup: reuse or generate the bot identity automatically, wait for Bot-role approval before falling back to identity-preserving Retry/Back controls, select single-room defaults, preserve advanced access settings, accept normal room messages by default without relying on composer mentions, verify setup without posting test messages, finish targeted channel setup directly, derive new bot profiles from the routed agent identity, and authorize fresh setups from Buzz's live room roster without per-message relay queries. Thanks @shakkernerd, @vincentkoc, and @joshavant.
Buzz resumable setup: persist paused bot identities, resume disabled setup in place, retry authenticated room discovery without rotating keys, require verified Bot-role room membership instead of accepting unverified room UUIDs, and give accurate CLI authorization guidance for generated identities that Buzz desktop cannot discover. Thanks @shakkernerd.
Buzz inbound authorization: apply shared room sender and command authorization before agent dispatch, allow authorized control commands to bypass mention gating, and preserve Buzz thread/reply identifiers through delivery. Thanks @shakkernerd and @vincentkoc.
ClickClack split-origin setup codes: consume versioned exact claim endpoints without appending a second claim path, validate the returned canonical API base, preserve private API transport overrides, and keep legacy setup URLs working. Fixes #111919 Thanks @shakkernerd and @vincentkoc.
Standalone plugin files: let manifestless files explicitly listed in plugins.load.paths pass config validation and load independently when several files share a directory. Thanks @vincentkoc.
Control UI terminal error messages: preserve message-only assistant output beginning with Error: or a warning marker instead of treating text prefixes as synthetic failures. Thanks @shakkernerd, @vincentkoc, and @zw-xysk.
Channel outbound echo suppression: drop recently emitted platform message and source identities at shared inbound admission and migrate Discord thread unbinds off channel-local expiry state, preventing delayed webhook copies from re-entering agents. Thanks @vincentkoc.
Reef startup reconciliation: contain retryable relay failures during startup without supervisor restart loops, while preserving definitive-error and cancellation handling. Thanks @Yigtwxx and @vincentkoc.
Codex stale-session replies: stop model fallback after another gateway supersedes a Codex session generation and deliver a safe retry notice instead of abandoning the message silently. Thanks @vincentkoc, @shakkernerd, and @obviyus.
Bounded input and provider responses: cap pasted auth/config input and enforce wall-clock deadlines across generated-media downloads, polling JSON, and failed response details so oversized or slow-drip streams cannot exceed resource budgets (thanks @Pick-cat). Thanks @vincentkoc.
LINE durable inbound media: retry transient content preparation, network, and response-stream failures through durable ingress so media-only messages are not acknowledged before their attachment is saved. Thanks @edenfunf, @vincentkoc, and @shakkernerd.
Cloud worker derived workspace caches: exclude Python caches, dependency trees, and macOS metadata symmetrically from outbound sync and inbound reconciliation so local cache rewrites cannot fence later cloud results or worker reclaim. Thanks @vincentkoc.
Codex model status diagnostics: report a configured Codex route as unavailable when its harness plugin is disabled, missing, or quarantined, while preserving the separate credential result and making models status --check fail instead of silently treating fallback execution as healthy. Thanks @shakkernerd and @vincentkoc.
Gateway control-plane rate limiting: use per-method buckets with a 30-per-minute budget so interactive admin writes remain responsive while retaining runaway-loop protection.
External supervisor restart health: accept device-identity policy closes only when the replacement gateway lock and listener PID agree, preventing OCM-managed restarts from timing out after a successful handoff. Thanks @shakkernerd, @vincentkoc, and @joshavant.
ACPX cleanup process inspection: bound host process-table reads so stalled ps calls cannot hang gateway startup or session cleanup while retaining fail-closed ownership checks. Thanks @Alix-007 and @vincentkoc.
Cron lifecycle conflict retries: preserve execution-phase retry decisions across scheduled, manual, and startup-recovered runs so post-execution claim conflicts cannot replay completed messages or tools. Fixes #108428 Thanks @yetval and @vincentkoc.
Discord gateway metadata deadline: carry the existing lookup deadline through DNS and proxy preflight, request headers, and response bodies so stalled gateway startup aborts cleanly. Thanks @hugenshen, @vincentkoc, and @shakkernerd.
Control UI cloud session thinking: expose reasoning level in the New Session model picker and persist the selected level before cloud dispatch. Thanks @vincentkoc.
iOS fresh-install setup: atomically redact spent setup credentials before Keychain cleanup so a deferred item deletion no longer disconnects a successfully paired device. Fixes #107591 Thanks @dagmarjeeves-lab and @vincentkoc.
Tlon SSE connect cleanup: disarm opening deadlines after failed HTTP responses and rejected stream opens so reconnect attempts cannot leave stale timers behind. Thanks @hugenshen and @vincentkoc.
LINE reply-token media kinds: honor video and audio metadata on inbound replies, share the canonical media builder with proactive sends, and fail visibly instead of recording empty media-only deliveries. Thanks @edenfunf and @vincentkoc.
Mattermost websocket connection deadlines: bound opening handshakes so stalled TCP peers cannot hang channel startup indefinitely and reconnect control resumes after timeout. Thanks @hugenshen, @vincentkoc, and @obviyus.
Queued TTS retries: copy local outbound media into queue-owned storage before enqueueing so voice replies survive producer temp cleanup and restart recovery, retain referenced artifacts through retry backoff, and prune unreferenced spool files after one day. Fixes #108501 Thanks @masatohoshino, @vincentkoc, and @obviyus.
Feishu app registration deadlines: bound OAuth device-registration requests to 10 seconds through the guarded fetch boundary so setup cannot hang indefinitely on stalled response headers. Thanks @hugenshen, @shakkernerd, and @vincentkoc.
LINE control-command mentions: detect authorized slash commands before mention stripping so inline group and direct-message controls preserve the original ingress metadata. Thanks @edenfunf and @vincentkoc.
Feishu document image reads: bound remote document-image headers and stalled bodies with the selected account timeout, parse document Markdown through the plugin's MDAST pipeline, preserve image/block alignment, and reject failed upload input before creating empty image blocks. Thanks @Alix-007 and @vincentkoc.
ClawHub registry reads: retry bounded HTTP 500 responses alongside other transient gateway failures so multi-package release scans survive isolated registry errors. Thanks @vincentkoc.
Slack Socket Mode health: report connected Socket Mode transports as degraded when auth.test fails or the configured bot token resolves to a user without bot_id, while preserving healthy enterprise-org installs. Thanks @zw-xysk and @vincentkoc.
Synology Chat response limits: bound user-list response reads, stop oversized streams immediately, and retain stale cached identities when a NAS exceeds the supported envelope. Thanks @zw-xysk and @vincentkoc.
Usage date ranges: exclude legacy transcript rows without timestamps from finite session ranges while preserving them in all-time totals, and rebuild older usage caches before serving the new semantics. Fixes #89709 Thanks @TurboTheTurtle, @shakkernerd, and @vincentkoc Thanks @syfvb, @shakkernerd, and @vincentkoc.
LINE group history races: retain ambient group messages received during an active mention turn for the next turn while consuming the pre-turn snapshot exactly once. Thanks @edenfunf and @vincentkoc.
Mattermost progress command details: accept the documented streaming.preview.commandText and streaming.progress.commandText modes in channel config validation and bundled metadata. Thanks @shakkernerd and @vincentkoc.
1Password authorization handoff: persist nonce-bound pending approvals in shared plugin state so hook and tool execution across broker instances remain single-use and fail closed. Thanks @vincentkoc and @obviyus.
Control UI chat transcripts: preserve loaded history across session and pane returns, bound automatic backscroll loading, virtualize long transcripts, retain hidden native run boundaries, and keep prepends, streaming, and responsive layouts from flickering or jumping. Thanks @shakkernerd and @vincentkoc.
Codex dynamic tool outcomes: use the shared tool-result failure contract for arbitrary lifecycle metadata, preventing successful Skill Workshop results from being displayed and persisted as failed calls. Fixes #107684 Thanks @shakkernerd, @vincentkoc, @maweibin, and @obviyus.
Codex /status context freshness: consume exact per-response usage from Codex app servers that emit rawResponse/completed; when exact usage is unavailable or omitted, keep context unknown instead of reusing cumulative lifetime totals. Thanks @wuqxuan and @vincentkoc.
Codex resumed permissions: apply stored per-session approval and sandbox overrides to primary resumed harness turns so /codex permissions survives later messages and gateway restarts. Thanks @shakkernerd.
Nested resource ignores: honor slash-free patterns and escaped literal exclamation marks in nested ignore files during skill and resource discovery. Thanks @moguangyu5-design and @vincentkoc.
Proxy bypass precedence: honor blank lower-case no_proxy values shadowing upper-case NO_PROXY consistently with Undici, and reuse the canonical matcher for Telegram fallback selection. Thanks @vincentkoc.
Tokenjuice exec compaction: avoid retaining raw command output inside compacted middleware metadata, preventing large successful compactions from failing the middleware details-size guard. Thanks @vincentkoc.
Agent git package identities: strip refs before hosted-repository parsing and reject traversal segments so GitLab branch refs resolve to the canonical managed install path. Thanks @vincentkoc.
Tlon custom S3 uploads: pass storage endpoints through the AWS SDK's native parser so custom S3-compatible uploads no longer fail before presigning.
Signal active-run controls: keep authorized stop, status, approval, and queue-read controls responsive during active turns while preserving ordinary and stateful turns in canonical session admission, and cancel every pending group sender lane on stop. Thanks @arduano and @vincentkoc.
Agent auth storage locks: surface normal release failures while avoiding redundant release attempts after proper-lockfile reports a compromised lock. Thanks @vincentkoc and @joshavant.
Paired-node session catalogs: authorize bundled Anthropic and Codex catalog requests to invoke their read-only node commands from Control UI read flows, restoring remote Claude/Codex rows and terminal resume availability. Fixes #107406 Thanks @vincentkoc.
Sandbox recreate confirmation: treat Clack cancellation as a decline so Ctrl-C cannot proceed with container removal.
Microsoft Teams HTML text: decode HTML5 entities consistently in quoted and Graph-fetched messages while preserving literal escaped entity text. Thanks @vincentkoc.
ClawHub plugin API ranges: delegate each supported comparator to semver so tilde, partial-wildcard, and prerelease caret bounds are correct while preserving OpenClaw version normalization and the existing restricted range grammar. (#106877) Thanks @vincentkoc.
Web Readability relative links: seed parsed documents with the request URL so article links resolve correctly while removing the plugin's duplicate lazy-loader facade. (#106860) Thanks @vincentkoc and @shakkernerd.
Browser auto-routing: fall back to the Gateway host when an implicitly selected browser node reports that its control host is unreachable, while preserving explicit node pins and ambiguous action failures. Thanks @vincentkoc and @shakkernerd.
Discord voice participant context: maintain the live Gateway voice-state roster and include current channel participants in authorized voice agent turns so agents can answer who is present. Thanks @vincentkoc and @shakkernerd.
OC Path JSONC insertion: patch object and array insertions through jsonc-parser so comments, trailing commas, and CRLF formatting survive. (#106847)
Windows winget installs: continue in the current PowerShell session when winget installs Node.js before the machine PATH update becomes visible, avoiding a false Node.js not found failure. (#106862) Thanks @vincentkoc.
Control UI realtime Talk feedback: request browser echo cancellation, noise suppression, and automatic gain control for every microphone transport, and keep PCM capture processors connected through zero-gain sinks so microphone input cannot play locally. Thanks @vincentkoc.
Agent source-reply recovery: preserve current-chat delivery evidence for message sends executed through Code Mode, preventing successful replies from triggering a redundant retry and misleading delivery-failure diagnostic. Thanks @vincentkoc and @joshavant.
Gateway in-process restarts: clear stale SIGUSR1 restart state and resume prepared host suspensions before rebuilding runtime admission, preventing restart cooldowns or paused scheduling from leaking into the next lifecycle. Thanks @vincentkoc and @shakkernerd.
ClickClack durable media delivery: route media replies through required delivery, reuse owner-scoped upload and message nonces across retries, repair persisted attachment state without rereading source media, fail closed when an older ClickClack server cannot prove an unknown send, and use the selected provider and model's runtime output budget instead of a channel-level token cap. Thanks @jjjhenriksen, @shakkernerd, and @vincentkoc.
Deepgram realtime custom endpoints: validate Voice Call streaming base URLs with secret-safe errors, preserve explicit ws:// and wss:// endpoints, and map HTTP schemes to their matching WebSocket transport for dedicated and self-hosted deployments. (#105334) Thanks @dwc1997, @vincentkoc, and @zw-xysk.
Control UI New Session reconnects: rediscover agents, nodes, repository branches, and folder-browser state, refresh derived workspaces, gate unvalidated devices, and block ambiguous retries after Gateway client replacement while preserving the typed task and explicit choices. Fixes #106372 Thanks @vincentkoc and @shakkernerd.
macOS remote node readiness: take the main-session key from the node hello snapshot instead of opening an operator connection during node admission, preventing remote tunnel recovery from leaving Computer Use and node exec stuck in lifecycle transition. Thanks @vincentkoc.
Claude CLI context budgets: honor Anthropic model and per-agent contextTokens limits by passing the effective limit to Claude Code's native auto-compactor and persisting the same prepared budget in OpenClaw session state. Fixes #80933. (#93198) Thanks @mushuiyu886, @gorkem2020, @vincentkoc, and @shakkernerd.
Transcript read failures: propagate permission and I/O failures from streaming JSONL session reads instead of treating unreadable transcripts as empty. Thanks @zenglingbiao, @shakkernerd, and @vincentkoc.
Restart sentinel diagnostics: report SQLite read/write and legacy-file cleanup failures while preserving best-effort restart recovery behavior. Thanks @zenglingbiao, @wendy-chsy, @vincentkoc, and @shakkernerd.
Native app connection and relay reliability: keep Android disconnects stopped across Activity recreation, fail remote camera commands without opening permission prompts, refresh mobile node registration after capability changes, surface iOS onboarding connection failures, cancel stale Talk owners on session switches, reject invalid Watch acknowledgments, preserve Watch events received during startup, and prevent older agent overview requests from replacing newer gateway state. Thanks @vincentkoc and @joshavant.
Gateway source watch: hand the configured port off from the installed service before starting the tmux watcher, preserve failed panes for attach/capture, and keep explicit alternate-port watches side by side with the managed Gateway. Thanks @vincentkoc.
Claude CLI max-turn diagnostics: preserve terminal max-turn results with OpenClaw and Claude session context, warn when tool actions may already have run, and stop unsafe auth-profile or model replay for potentially side-effecting turns. (#94130) Thanks @zhangguiping-xydt, @tdrose01, @vincentkoc, and @shakkernerd.
Provider network retries: align provider read/poll/download and agent-wait recovery for transient connection errors, retry bounded provider ENOTFOUND failures while leaving gateway ENOTFOUND and non-idempotent create operations fail-fast. (#101496) Thanks @xialonglee, @joshavant, and @vincentkoc.
Session retry classification: stop permanent provider errors whose identifiers or payload details merely contain 429/5xx digit sequences from re-sending full context, and share bounded rate-limit-window parsing across retry paths. (#105258) Thanks @destire-mio, @yetval, and @vincentkoc.
LINE directive templates: suppress confirms and buttons with blank required fields or unlabeled actions while preserving valid titleless buttons and surrounding reply text. (#105520) Thanks @edenfunf.
SQLite maintenance schema validation: reject current-version global and agent databases with missing or drifted canonical tables, constraints, indexes, triggers, or table options before compaction, while accepting supported additive-migration layouts. Thanks @vincentkoc.
Matrix bootstrap diagnostics: preserve complete UTF-8 code points in bounded stdout and stderr tails so crypto dependency failures do not show replacement characters at retention boundaries. (#105475) Thanks @qingminlong and @vincentkoc.
iOS Watch relay commands: allow paired iPhone nodes to advertise and invoke watch.status and watch.notify through the default Gateway policy while preserving the direct watchOS node's fixed minimal command surface. Thanks @vincentkoc and @shakkernerd.
Swabble status config: honor the global --config path when reading service status instead of silently using the default configuration. Thanks @vincentkoc and @shakkern
Original source - Aug 13, 2026
- Date parsed from source:Aug 13, 2026
- First seen by Releasebot:Aug 14, 2026
release-publish/abd63c06c2f5-1786646045
OpenClaw adds GitHub-hosted npm preflight tooling for 2026.8.1-beta.2
OpenClaw GitHub-hosted npm preflight tooling for 2026.8.1-beta.2
Original source - Aug 13, 2026
- Date parsed from source:Aug 13, 2026
- First seen by Releasebot:Aug 13, 2026
release-publish/8371831eba5e-1786610071
OpenClaw adds npm preflight tooling in 2026.8.1-beta.2.
OpenClaw 2026.8.1-beta.2 npm preflight tooling
Original source - Aug 13, 2026
- Date parsed from source:Aug 13, 2026
- First seen by Releasebot:Aug 13, 2026
release-publish/57fabb2c9c35-1786621048
OpenClaw adds npm preflight tooling for 2026.8.1-beta.2.
OpenClaw npm preflight tooling for 2026.8.1-beta.2
Original source - Aug 12, 2026
- Date parsed from source:Aug 12, 2026
- First seen by Releasebot:Aug 13, 2026
release-publish/716f996be8db-1786550775
OpenClaw fixes CI by preparing the sandbox before repo E2E tests.
fix(ci): prepare sandbox before repo E2E (#122525)
Original source - Aug 10, 2026
- Date parsed from source:Aug 10, 2026
- First seen by Releasebot:Aug 11, 2026
v2026.8.1-beta.1
OpenClaw ships 2026.8.1-beta.1, a new beta release.
OpenClaw 2026.8.1-beta.1
Original source - Aug 10, 2026
- Date parsed from source:Aug 10, 2026
- First seen by Releasebot:Aug 11, 2026
release-publish/f4987deb94b8-1786361493
OpenClaw fixes CI to support frozen validation scripts.
fix(ci): support frozen validation scripts (#121458)
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.