changelogs.info
OpenClaw Claude Code Codex Gemini Kilo Code Hermes Models Dispatches
OpenClaw Changelog Guide
Tracking 3 latest entries

OpenClaw

Personal AI assistant platform — run your own AI on any device, any channel

openclaw status
openclaw status
Gateway: running
Version: v2026.7.1-2
Releases: 30 tracked
Breaking: 6
Updated: 5h ago
_
Releases 30
Breaking 6
Stable 10
Latest v2026.7.1-2

TL;DR

Latest Release
v2026.8.1-beta.3 PRE Aug 24, 2026

This openclaw release, version 2026.7.1-2, primarily focuses on a crucial fix for npm plugin updates. The system now correctly accepts singleton-array metadata from newer npm clients, which is vital for ensuring that official openclaw plugins can properly install and receive correction releases. This resolves an issue that might have prevented users from updating their plugins to the latest stable versions, potentially leading to missed bug fixes or performance improvements. While there are no new features, commands, flags, or environment variables introduced in this release, the fix for npm plugin updates is significant for maintaining the stability and up-to-dateness of the openclaw ecosystem. Developers should consider upgrading to ensure their plugins are always on the latest correction releases. There are no breaking changes or specific migration steps required for this update.

Recent Changelog
2026.7.1 BREAKING
Aug 24, 2026
Notable changes
  • OpenClaw v2026.7.1 brings major Control UI and onboarding overhauls, major updates to the official iOS, Android, and macOS apps, expanded model and provider support including GPT-5.6 compatibility, Tencent Hy3, and Meta Muse Spark 1.1, and stronger Codex and connected coding-agent workflows. Telegram, Slack, Discord, and Apple Messages each receive substantial updates, while Gateway crash loops, scheduled work, remote browser control, workspace terminals, sessions, and goals also improve. There are also many general fixes and refinements throughout OpenClaw.
  • Full release notes
  • #### Control UI
  • The Control UI now works more like one browser workspace for conversations and parallel work. Chats receive clearer titles, recent sessions are easier to find, pin, group, rename, fork, archive, and mark read, and multiple sessions can sit in resizable panes that return after a reload. Drag-and-drop placement, a denser Sessions page, and a live Tasks view make it easier to move between active work without juggling browser tabs.
  • Chat controls are clearer while work is in progress. The composer keeps attachments, model choice, voice, reasoning, send and stop state, and message actions usable across screen sizes; Talk users can choose or refresh a microphone from settings and get readable permission guidance on narrow screens; quoted replies preserve the point being answered; and compact tool rows keep inputs, results, images, progress, errors, approvals, and steering available without overwhelming the conversation.
  • Usage information is easier to understand from both status views and the browser. The Usage page compares recent estimated spend and daily values without repeated reloads or hovering, shows each provider, model, agent, or channel's share, and can include provider-reported plans, quotas, balances, budgets, and Anthropic or OpenAI billing details. Seven-, thirty-, and ninety-day charts now keep zero-activity days visible, large all-agent reports limit concurrent work to reduce slowdowns and memory pressure, and chat-level context panels and completed-message details show the active model, tokens, cache use, context pressure, and estimated cost.
Show all changes (1952 more)
Highlights
  • Mobile pairing, Gateway health, desktop-node approvals, linked GitHub work, workspace files, scheduled jobs, worktrees, Workboard items, and background tasks are now available closer to the conversation. Their status, permissions, and next steps are also clearer.
  • The rework also strengthens the paths underneath those controls. Dashboard connects and reconnects use less temporary Gateway memory, reducing false pressure warnings, while temporary Gateway restarts and stale assets recover more cleanly. Path-routed Gateways keep the right destination and credentials, saved choices survive refreshes, and authentication, protocol, update, and pairing failures show more useful next steps instead of leaving the page stuck or ambiguous.
  • Responsive layouts keep chat history and controls usable on phones, tablets, short landscape screens, and large desktops. Keyboard and focus behavior, contrast, assistive labels, copying, scrolling, and touch targets are more consistent, while navigation, pairing, voice, schedule, and status text reaches more supported languages.
  • New Control UI chats now receive concise sidebar titles from their first message, and operators can route dashboard, Telegram topic, and Discord thread title generation through a smaller utilityModel. #87643 Thanks @juliangsm, @zhangguiping-xydt.
  • Paired administrators can now create a mobile setup QR or copyable code from Control UI Nodes and use it to connect an official iOS or Android app. #94672 Thanks @bkudiess, @douhualili.
  • Control UI now makes conversations easier to create, find, and switch from a populated session sidebar, while keeping context pressure and provider quota information close at hand. #99289 Related #99288.
  • The Control UI sidebar now focuses on sessions and a few default destinations while letting users pin their preferred pages and keep those choices across reloads. #100296
  • The redesigned Control UI composer keeps attachments, provider and model selection, voice, run state, and message actions clearer and more stable across mobile and desktop layouts. #100461 Thanks @fuller-stack-dev.
  • Control UI Talk users can choose and refresh a microphone on narrow screens and read clear permission guidance when browser access is blocked. #101377 Thanks @fuller-stack-dev.
  • Control UI chat can now show multiple resizable sessions side by side or stacked, preserve the pane layout across reloads, and keep the active pane usable on narrow screens. #100754
  • The Control UI now has a live Tasks page where operators can inspect active and recent background work, open its session, refresh details, and cancel queued or running tasks when authorized. #100789
  • Session lists across web and mobile now support pinned and custom groups, shared read and unread status, background-output indicators, transcript forking, and in-place rename, archive, move, and delete actions. #100814
  • The Control UI Sessions page now fits more useful status and actions on a typical screen, with row details opening to reveal labels, tuning controls, and checkpoint history instead of forcing routine sideways scrolling. #100943
  • Control UI users can drag a session directly into the current pane or onto any side to create a split, with a preview showing where it will land. #101191
  • Operators can configure token or full per-reply usage footers once with messages.responseUsage, while users can turn them off or reset a session to the inherited default. #89762 Thanks @marvinthebored, @obviyus, @peetiegonzalez.
  • The Control UI Usage page now makes recent estimated costs, daily values, and each provider, model, agent, or channel's share easier to compare without repeated reloads or hovering. #100432
  • The Usage page now shows provider-reported plans, quotas, reset times, balances, spending, and budgets alongside OpenClaw session analysis, including OpenRouter and Venice coverage. #100520
  • Control UI Usage can now show Anthropic and OpenAI daily spend, tokens, requests, top models, and billing categories for today, seven days, and thirty days when admin credentials are configured. #100672
  • Daily token and cost charts now include zero-activity days across bounded date ranges, so 7-day, 30-day, and 90-day views show the full calendar period instead of shrinking around active days. #81467 Thanks @adapepper.
  • All-agent cost reports on large installations now limit concurrent Gateway work so the dashboard is less likely to slow down, time out, or add memory pressure. #101589 Thanks @vincentkoc, @zw-xysk.
  • Hovering or keyboard-focusing a public GitHub issue or pull request in Control UI chat now previews its status, title, author, activity, comments, and change size without leaving the conversation. #100434
  • File paths in Control UI chats are now clickable, opening a searchable syntax-highlighted preview at the cited line with options to reveal, copy, or open the file in a supported editor. #100679
  • Control UI connection failures now show actionable messages such as "Pairing required" instead of replacing them with a generic gateway disconnect. #54758 Thanks @ruanrrn.
  • Control UI sessions using full verbose output now open tool inputs and results by default, reducing repeated clicks during debugging and review. #74398 Thanks @samrusani.
  • The Control UI context indicator now remains visible with an approximate cached total while a response is active, without using stale data for urgent warnings or the Compact action. #89772 Thanks @bladin.
  • Control UI and WebChat no longer let a non-terminal internal tool failure dominate the transcript with a red error banner after the assistant has already produced a normal final answer. #90122 Thanks @harjothkhara.
  • A default agent selected in the Control UI now remains selected after refresh without saving unrelated unfinished settings. #91457 Thanks @zengwen-dt.
  • Segmented streaming replies in Control UI WebChat now stay under one assistant avatar and footer instead of appearing as several separate responses. #92063 Related #63956. Thanks @contentfree, @harjothkhara.
  • Dashboard WebChat users can right-click a completed message and reply with visible quote context instead of manually copying and formatting it. #92654 Thanks @programmingwtf, @vincentkoc.
  • After an update installs, the Control UI now says when a Gateway restart is already in progress instead of making the Update button appear unresponsive. #93082 Thanks @goutamadwant.
  • Live tool-using replies in Control UI WebChat now keep the assistant's introduction ahead of the tool card, even when browser and Gateway clocks differ. #93184 Thanks @pick-cat.
  • Control UI Quick Create now lets users choose a model for an agent-turn cron job and shows whether existing jobs use that model or the default. #95341 Thanks @ly85206559.
  • Control UI WebChat can now show Codex preamble and commentary while tools are running, with a choice to hide or retain that progress after the final answer. #95708 Thanks @obviyus, @ragesaq.
  • Long reply IDs containing emoji or other supplementary characters now remain valid when shortened for WebChat and Gateway reply directives instead of being cut into malformed text. #96938 Thanks @ly-wang19.
  • Long tool activity details now remain readable when shortened for chat, UI, or logs, even when an emoji or other supplementary character falls at the cutoff. #96958 Thanks @bartok9, @ly-wang19, @vincentkoc.
  • WebChat now shows long provider and model names together with the selected reasoning level in the composer, while narrow screens retain a sensible overflow limit. #96990 Thanks @maweibin, @xiayingren123.
  • Agents can use targetless message.send for progress or intermediate updates in the current WebChat without an explicit destination. #97167 Related #96840. Thanks @mantiscartography, @zhangguiping-xydt.
  • New Control UI chats now use the selected model's current context window instead of inheriting an outdated, smaller limit from a parent session. #97332 Thanks @galiniliev.
  • WebChat stays on the newest reply when assistant audio or video finishes loading, while respecting readers who intentionally scrolled upward. #97575 Thanks @turbotheturtle.
  • Control UI pages for multiple Gateways on one domain now stay connected to the Gateway named by their path instead of reusing a sibling page's saved destination. #97665 Thanks @alix-007.
  • /pair qr now delivers a scannable code in Telegram and Control UI or a readable code in the TUI without storing the one-time setup secret in chat history. #97933 Thanks @joshavant.
  • Expired /pair qr cards in Control UI now clearly say the code is unusable and direct users to generate a fresh one. #98049 Related #98039. Thanks @ooiuuii.
  • Expired mobile-pairing codes now explain how to run /pair qr again in the selected language. Sources: bb4afe4, da9308d, dfaec18, 6b7986e, 21af6e7, 4e62124, 6cd0106, a72a641, a143ae4, cd30b1c, f69e27a, ccddbee, 9ed03df, f84243f, 3d06ee9, 9bd071e, 405b7a5, 1a160ce.
  • Control UI now shows channel-triggered agent runs as in progress, so users can tell that messages from channels such as Weixin are actively being handled. #98257 Thanks @scotthuang.
  • The Control UI workspace rail now gives long Project files lists their own scrollbar so files remain browsable without spilling off screen. #98646 Related #98566. Thanks @645648406-max, @wuqxuan.
  • Session Workspace file paths can now be copied from Chat even when the Control UI runs over plain HTTP or another context without the standard Clipboard API. #98764 Related #98759. Thanks @adinballew, @zengwen-dt.
  • Tool-heavy Control UI chats now use compact expandable activity rows, so commands and results take less space while full details stay one click away. #99763
  • The Control UI now stays fixed during trackpad overscroll on Mac and desktop browsers while chat threads and lists continue scrolling normally. #99830
  • Control UI chat is easier to scan with quieter composer controls, a Faster-to-Smarter reasoning slider, and connection status that no longer competes with persistent version text. #99838 Related #99837.
  • Mounted deep links, Set Default, authenticated avatars, cron alerts, and Workboard scrolling now behave correctly again across the Control UI. #100106
  • Administrators can now open mobile pairing from any Control UI page or Quick Settings, while non-admin operators continue to see the action disabled with an access explanation. #100157
  • The Control UI now shows a ready mobile-pairing QR code immediately even when the pending-device list is slow, then adds approval requests when they arrive. #100179
  • Control UI users can select and copy tool activity without toggling its row, and failed tools no longer repeat redundant error indicators. #100199 Thanks @steipete-oai.
  • The Gateway Dashboard login now fits and behaves better on phones and short windows, with larger touch targets, easier URL entry, and reachable recovery help. #100208
  • Control UI users can organize large session lists by custom group, channel, kind, agent, or date, with persistent assignments and drag-and-drop management. #100262
  • Users can open the Control UI context ring to inspect exact context use, the latest input and output token counts, and the active model without leaving chat. #100264
  • Images returned by tools such as read now appear directly in the Control UI conversation instead of only being mentioned in text. #100295 Thanks @lzyyzznl, @pandah97, @rquinones84.
  • Control UI tool activity now combines matching calls and results into one consistent row, removes repeated labels and categories, and keeps inputs, outputs, previews, and real errors accessible. #100318
  • The Control UI context panel now shows the latest run's estimated total cost and available input, output, cache-read, and cache-write breakdowns beside the provider and model. #100379
  • The Control UI sidebar now keeps all pinned chats visible alongside nine ordinary recent chats in a more compact, conversation-focused desktop and tablet layout. #100386
  • The Control UI composer now shows reasoning level clearly, keeps Talk and its settings together, and preserves usable model controls on phone and landscape layouts. #100445
  • Control UI Talk now starts from a simpler composer while administrators can set durable provider, transport, timing, and reasoning defaults in Settings. #100453
  • Temporary Gateway disconnects no longer replace an authenticated Control UI page with the login screen, preserving dashboard context while automatic reconnection continues. #100479
  • The Control UI Cron Jobs page now uses compact summaries, clear status cues, expandable details, and an overflow menu so large job lists are faster to review. #100646
  • The Control UI sidebar now keeps recent chats in place while switching, combines search entry points, supports touch session actions, and reduces unnecessary chrome. #100648
  • Images received through Telegram, iMessage, and other channels now reappear inline when users revisit Control UI chat history after a reload. #100725 Thanks @sweetcornna, @vergissberlin.
  • The Control UI goal pill now supports pause, resume, clear, inspection, and edit preparation with live timing and token details, while command and TUI users can reword a goal without resetting its budget. #100736
  • The Control UI keeps Overview, Workboard, Agents, and More visible while allowing the session list to use available height and scroll independently. #100742
  • Assistant documents downloaded from the Control UI now keep recognizable original filenames instead of exposing UUID-suffixed staging names. #100743
  • Copying code from a long Control UI reply now keeps the chat at the same reading position instead of jumping upward. #100807 Thanks @jvlegod.
  • Desktop Control UI users can choose whether Enter sends or inserts a new line, with Command+Enter or Ctrl+Enter available as the send shortcut and the choice retained for that Gateway. #100810 Thanks @moomx, @vincentkoc.
  • Switching Control UI chats no longer unexpectedly moves the selected session to the top, and users can choose stable creation order or recently updated order for the sidebar. #100927 Thanks @shakkernerd, @vyctorbrzezowski.
  • Control UI Settings now use consistent /settings/... paths while old bookmarks continue to work, making reloads and links more reliable on hosted or reverse-proxied installations. #100928 Thanks @vyctorbrzezowski.
  • Control UI navigation now places branding, search, and sidebar controls where desktop and mobile users expect them, with clearer active sessions, compact timestamps, and easier terminal access. #101017 Thanks @shakkernerd, @vyctorbrzezowski.
  • The Control UI sidebar collapse control now sits in the sidebar it affects instead of looking like an unrelated topbar or terminal button. #101038
  • Control UI Talk users can choose the system default or any browser-visible microphone beside the Talk button and receive a clear message when a saved device is unavailable. #101100
  • Sidebar session groups can now be renamed, removed without deleting sessions, created while empty, or disabled to restore one flat recent-session list. #101117
  • The Control UI now shows Workboard navigation only when Workboard is enabled and presents a cleaner collapsed sidebar with clearer icons and status spacing. #101123
  • The Control UI now puts search, sidebar access, theme choice, and macOS branding in clearer, more predictable locations with accurate screen-reader labels. #101497
  • Temporary Gateway drops no longer push Control UI content down with a full-width banner, so the dashboard stays in place while a compact Retry notice appears. #101812
  • Temporary Gateway disconnects now use a calmer, dashboard-native reconnect pill with the same Retry and accessibility behavior. #101844
  • Control UI commentary settings now use the selected language across the supported translations in this release. Sources: 34badde, a9cb866, ce9166d, 6b67ada, 006c2f7, 6bdffa5, b4476ab, 5b5c623, 1520d09, 6140326, 75bd44a, c1aeaf9, 49edc0a, cb69ce7, bb0af61, 0dcfbb0, db73ece, 21e6fc9.
  • The All Sessions sidebar label now uses the selected language across the supported Control UI translations in this release. Sources: b2c3dc2, 61347a5, a2674b6, bbabad4, 8909289, 22552d6, 96e3615, 452351c, 5e9a62c, 0a9648b, a803589, 7c30ff8, e3d2878, 620f2e3, aa0f36c, c336256, 64dd688, e2ecbc8.
  • The Control UI mobile-pairing flow now appears in the selected language across 18 supported locales instead of mixing localized screens with English setup text. c78b0d5
  • A failed Control UI login or Gateway connection now immediately shows the error, recovery steps, and relevant documentation link instead of hiding them in a collapsed panel. f9e194e
  • The web sidebar now reliably fills pinned and overflow navigation routes, keeping destinations such as Worktrees available. 55a0012 Thanks @vincentkoc.
  • Non-English Control UI users now see translated cron overflow-menu and "run if due" labels, including the assistive label for more actions. 2585d6b
  • The Control UI microphone-access warning for realtime voice input now appears in the user's selected language. 68c85ef
  • The Control UI sidebar now builds cleanly with session grouping and drag-to-split behavior intact after stray merge-conflict text was removed. 0e3ce24
  • Hindi and Russian users can now receive matching Control UI translations, and documentation operators can generate those language editions through the existing locale workflow. 689baa5 Thanks @vincentkoc.
  • During device pairing, / pair qr now follows the same authorized pairing flow as /pair qr without starting an agent turn or disrupting the existing Control UI route. #98262 Thanks @brokemac79.
  • Opening or reconnecting the Control UI dashboard now uses much less temporary Gateway memory, reducing false rss_growth warnings while preserving requested usage totals. #100054 Thanks @nianjiuzst.
  • Control UI Settings now shows a remote Gateway's host identity, address, operating system, runtime, uptime, CPU load, memory, and free disk space without requiring SSH. #100478
  • The Control UI now shows execution approvals for supported desktop nodes and rejects pending, unsupported, or policy-blocked requests before they reach the node. #100505 Thanks @vincentkoc.
  • A configured ui.seamColor now changes Control UI buttons, highlights, selections, and focus rings, while invalid values fall back cleanly. #93699 Thanks @dennis-lynch, @goutamadwant.
  • QR codes and other half-block text art in the Control UI now preserve spacing, scroll when needed, and copy with enough padding to remain usable. #93869 Thanks @emg110, @vincentkoc.
  • Open Control UI tabs now switch to the active build after a service-worker update, reducing stale JavaScript, CSS, and protocol mismatch errors after upgrades. #96141 Thanks @andrewccctechlink, @brokemac79.
  • Chat clients can now match each pending user message to its exact Gateway-confirmed message, reducing duplicate or mismatched bubbles during interleaved turns. #96273 Thanks @datus1982, @wyf027.
  • Clicking a cron job's History button now gives immediate feedback and scrolls directly to that job's updated run history. #96281 Thanks @wyf027, @yzhong52.
  • Control UI token totals near one million now display as 1.0M instead of the confusing 1000k. #96298 Thanks @ly-wang19.
  • Usage Mosaic and usage summaries now show near-million token totals as 1.0M instead of 1000.0K. #96450 Thanks @ly-wang19.
  • The Voice, Model, and Sensitivity controls in Control UI Talk settings now align consistently in one row without duplicate selected-value text disturbing the layout. #96925 Thanks @evan-ym.
  • Control UI approval prompts no longer inherit failures from older requests or re-enable controls while the current decision is still being processed. #98394 Thanks @haruaiclone-droid.
  • Control UI now stops retrying after detecting an incompatible Gateway protocol and shows the update or reload guidance needed to reconnect. #98414 Thanks @haruaiclone-droid.
  • On phones and other short landscape screens, the Control UI composer now scrolls within a bounded area so chat history and all composing controls remain accessible. #98683 Related #98615. Thanks @jin-li, @qingminglong.
  • The Control UI now retries after a temporary failed load during a Gateway restart or stale-asset transition instead of remaining stuck until the page is refreshed manually. #99111 Thanks @zengwen-dt.
  • Large pasted PNG screenshots can now be sent through Control UI webchat without failing during attachment processing. #99213 Thanks @jincheng-xydt, @vincentkoc.
  • The Control UI mobile-pairing flow is now fully localized for Hindi and Russian users, from setup-code creation through pending-device management. #100040
  • The Control UI workspace rail now sits flush with the window and uses less space when collapsed, removing the empty strip without overlapping chat. #100088
  • Control UI chat history now hides only exact duplicate final delivery mirrors, leaving legitimate repeated sends, forwards, and distinct replies visible. #100136
  • Control UI chats now leave consistent space above the first message across phones, standard desktops, and tall windows. #100144 Thanks @steipete-oai.
  • Control UI Settings now offers a persistent Simple/Advanced switch, cleaner Appearance controls, and a Pending label only when a Context Profile change is actually staged. #100147
  • Control UI tool-call bubbles and error badges now share clean right-edge alignment, so failed activity is easier to scan on phone-sized and desktop chats. #100163 Thanks @steipete-oai.
  • OpenAI users now see only the supported Standard and Fast choices in the Control UI speed picker, with inherited Fast mode shown correctly. #100190
  • Short drafts in the Control UI composer no longer show an unnecessary scrollbar gutter, while long drafts still scroll when needed. #100252
  • Clearing a session label now removes the old name promptly from other subscribed Control UI clients without requiring a full refresh. #100266
  • Desktop Control UI users can hover a shortened recent-session name to reveal its hidden tail and distinguish similar conversations without opening each one. #100276
  • The expanded Control UI sidebar no longer repeats provider quota information already available in chat, Overview, and Usage views. #100356 Thanks @shakkernerd.
  • Completed Control UI messages now use the timestamp to open token, cache, context, cost, and model details instead of adding a separate Context control to every footer. #100391 Thanks @steipete-oai.
  • Autonomous session history now keeps an earlier failed cron or scheduled turn marked as an error even after a later turn succeeds or the page reloads. #100514 Thanks @qingminglong.
  • The Control UI Skills page now shows readable Agent and Search labels with aligned filters and correctly sized selection controls. #100526 Thanks @evan-ym.
  • After a Control UI reply finishes, the composer now stays on Send despite delayed completed-run state, while a real new run still switches it to Stop. #100527 Thanks @tiffanychum.
  • Control UI and Skill Workshop file previews now show a single Escape shortcut hint while retaining Escape-to-close behavior. #100528 Thanks @xianshishan.
  • Expanded Control UI tool activity no longer repeats the tool name and icon, making completed and in-progress calls quicker to scan. #100606
  • Clearing a Control UI session model override now shows the selected agent's own default model rather than the unrelated global default. #100719 Thanks @hyspacex.
  • Assistant-sent documents in WebChat now download with their original server-provided filename, including Unicode names, instead of opening as an unnamed browser document. #100728 Thanks @lptrichor.
  • The Control UI now accepts /steer guidance during an active run instead of incorrectly replying No active run. #100803 Thanks @hackerismydream.
  • New Control UI sessions now stay visible at the front of the sidebar after users switch to another chat, without requiring a page refresh. #100981 Thanks @shakkernerd.
  • Worktrees management now lives under Control UI Settings instead of occupying a top-level sidebar item, while existing deep links remain valid. #100995
  • Long /btw answers in the desktop Control UI now stay within the browser window and scroll inside the result card, while mobile retains full-card scrolling. #101169 Thanks @snoutfirst.
  • Finished chats no longer remain stuck with a busy spinner in the Control UI sidebar, even when an older Gateway update arrives afterward. #101293 Thanks @fuller-stack-dev.
  • Large Skill Workshop support files now scroll, switch, filter, wrap, and copy without freezing or severely slowing the Control UI. #101319 Thanks @shakkernerd, @xianshishan.
  • Users can stay signed in to multiple path- or query-routed Control UI gateways on one HTTPS origin without one gateway overwriting another's device token. #101352 Thanks @fuller-stack-dev.
  • Control UI users can type /approve to release a waiting exec prompt without the decision getting queued behind the blocked chat run. #101532 Thanks @vincentkoc.
  • Control UI build errors now keep emoji and other supplementary characters intact when command output is shortened for display. #101591 Thanks @maweibin.
  • Workboard cards can now be edited, moved, archived, stopped, opened, or deleted directly from the detail drawer, while read-only viewers still see no mutation controls. #101658 Thanks @momothemage, @princebansal.
  • The Control UI microphone button is now visually quieter while idle and more distinct while recording, making the current voice state easier to recognize. #101843
  • Users with saved working dashboard credentials no longer see the login screen flash briefly while Control UI reconnects. #101849
  • Typing anywhere in the active Control UI chat now places the first character in the message composer without stealing input from the command palette. #102210 Thanks @shakkernerd.
  • #### Setup and onboarding
  • Onboarding now offers clearer paths to a usable first chat. Fresh CLI installs enter guided setup, configured installs open the TUI, and conversational Crestodian setup remains optional. Android and macOS guide users through pairing, permissions, local or remote setup, and recovery; macOS can also test detected Claude Code, Codex, Gemini CLI, API-key, and supported provider-catalog choices before saving them. Interrupted authentication or channel setup retains earlier choices, while users without a working model are guided through credential and model selection instead of being sent into an unusable chat. Owners and administrators can also renew an expired Codex or OpenAI login through private Telegram, Web UI, Discord, or Slack commands without SSH access.
  • Existing installations receive safeguards before their working state is changed. Doctor and updates refuse to replace an unreadable configuration, Doctor preserves model tuning while merging retired entries, and extended-stable updates retain the selected release channel. Container upgrades complete migrations and plugin repairs before reporting readiness, and unsafe runtimes are stopped before they can open OpenClaw state databases.
  • openclaw doctor and updates now refuse to replace an unreadable openclaw.json, preserving existing Gateway, agent, channel, and plugin settings instead of breaking the installation. #96469 Thanks @obviyus, @yetval.
  • openclaw doctor --fix now preserves aliases, parameters, streaming choices, runtime settings, and other model tuning when several retired model names merge into one current model, and reports any merge conflicts accurately. #96544 Thanks @vincentkoc, @yetval.
  • Owners and admins can now restore an expired Codex or OpenAI login from a browser through private Telegram, Web UI, Discord, or Slack commands without SSH access. #98006 Thanks @100yenadmin, @jalehman, @obviyus.
  • The CLI now guides fresh installs through setup, opens configured installs directly in the TUI, preserves existing choices on reruns, and finishes onboarding in a usable terminal chat. #98218 Thanks @fuller-stack-dev.
  • Package installs can now select and retain openclaw update --channel extended-stable, inspect its availability, and fail safely if its npm metadata is incomplete. #99811 Thanks @kevinslin.
  • Fresh installs can now complete conversational Crestodian setup, approve the proposed plan once, connect channels, and continue into the normal agent while classic and scripted onboarding remain available. #99935
  • First-time onboarding now preserves earlier choices after authentication or pairing trouble and gives users an actionable model-configuration next step instead of opening an unusable first chat. #100632
  • Container upgrades now finish required migrations and plugin repairs before reporting the Gateway ready, and failed repairs stop with actionable guidance instead of leaving a false-green service. #101881 Thanks @sallyom.
  • Crestodian setup now guides users who lack a usable model provider through masked credential entry and model selection, while deterministic setup and repair commands remain available until inference is configured. #101887 Thanks @fuller-stack-dev.
  • OpenClaw now blocks unsafe runtimes before they can open SQLite-backed state, guides legacy Bun services to Node, and selects a WAL-safe Node runtime during setup and repair. #106065 Thanks @vincentkoc.
  • #### Official apps
  • The official iOS, Android, and macOS apps received substantial updates across setup, navigation, chat, voice, permissions, localization, files, scheduled work, native session controls, and Gateway recovery. Recent conversations remain useful through temporary disconnects: cached sessions and transcripts stay available for reading, supported text sends can wait for reconnection in the correct chat, and long conversations are easier to resume without losing the current place or mistaking an offline view for live history.
  • These improvements also bring the native clients closer together. Mobile queues survive app restarts, the macOS app gains fuller session and transcript tools, and each client refreshes the same conversation when the Gateway returns.
  • ##### iOS and Android
  • iOS and Android chats now preserve the reader's scroll position as new messages and tool activity arrive, with a clear way to return to the latest reply. #98258 Related #98255. Thanks @christopheraaronhogg.
  • ##### iOS and iPadOS
  • iPhone and iPad chat now opens with the last known conversation and lets users browse recent cached sessions while the Gateway is unavailable. #100219
  • iOS users can queue chat messages while disconnected, keep them through app restarts, and send them in order after reconnection with clear retry and delete controls. #100331
  • ##### Android
  • Android chat now shows the last known transcript immediately and keeps recent cached conversations readable during a Gateway outage, then refreshes them after reconnection. #100227
  • Android users can queue text while the Gateway is offline, keep it through an app restart, and send it in order after reconnection with Retry and Delete controls for failures. #100290
  • ##### macOS
  • Mac chat now restores recent sessions and transcripts immediately, remains browsable while disconnected, and queues offline sends for the correct Gateway identity. #100275
  • The native macOS chat window now provides a full session sidebar, real new-session creation, slash-command completion, context and cost visibility, message copying, transcript export, and compact or clear-history actions. #101103
  • #### Models and providers
  • OpenClaw model selection expands across major hosted, managed, and local choices. Each supported provider route retains its own authentication, model limits, reasoning controls, tool behavior, image support, and usage reporting.
  • ##### GPT-5.6 and Codex
  • Organizations with GPT-5.6 preview access can select Sol, Terra, or Luna through supported OpenAI and Codex routes with the expected context metadata, text and image input, reasoning levels, and cache-write accounting when OpenAI supplies it. Fresh OpenAI API-key and ChatGPT/Codex setups choose their intended GPT-5.6 defaults without replacing an explicit model choice. Supported Ultra choices remain aligned across OpenClaw and native Codex, and Codex supervision records native Codex child agents as tasks and returns their results to the parent.
  • GPT-5.6 users can now select supported Ultra modes consistently, keep model and thinking choices aligned across OpenClaw surfaces, and receive native Codex child-agent results as tracked tasks. #98021 Thanks @anyech.
  • Organizations with GPT-5.6 preview access can select Sol, Terra, or Luna across supported OpenAI and Codex paths with correct reasoning controls, context metadata, and cache-write accounting. #98333 Related #98296. Thanks @steipete-oai.
  • Legacy-state upgrades no longer stall repeatedly, while fresh OpenAI and ChatGPT/Codex setups select the intended GPT-5.6 defaults and use supported temperature and tool-call behavior. #104656 Thanks @bdjben, @obviyus, @sallyom.
  • ##### Tencent Hy3
  • Tencent Hunyuan Hy3 now has a complete setup path through TokenHub or TokenPlan, including first-class authentication choices, CLI onboarding, model discovery, and configuration validation. Existing TokenHub configurations retain access to hy3-preview alongside the stable hy3 model.
  • Tencent Hunyuan Hy3 now has a complete supported OpenClaw setup path through TokenHub or TokenPlan, including first-class authentication, model discovery, configuration validation, CLI onboarding, and compatibility for existing hy3-preview setups. #99076 Thanks @moncac.
  • ##### Meta Model API and Muse Spark 1.1
  • Operators can configure Meta Model API with MODEL_API_KEY or the onboarding authentication choice, select meta-model-api/muse-spark-1.1, and use supported streaming, tool calling, image input, and reasoning-effort controls.
  • OpenClaw now supports Meta Model API setup and the Muse Spark 1.1 model, including streaming, tool calling, image input, and supported reasoning controls. #102873 Thanks @davemorin, @hamidshojanazeri, @jalehman, @solvely-colin.
  • ##### Claude models
  • Claude Sonnet 5 is selectable through direct Anthropic, Claude CLI, supported Vertex regions, Bedrock inference profiles, and Bedrock Mantle with its documented context, output, image, thinking, and pricing behavior. Users with Claude Mythos 5 access can select it through supported Anthropic-family routes with its required context, output, adaptive-thinking, caching, and replay behavior.
  • Claude Sonnet 5 is now selectable across Anthropic, Claude CLI, supported Vertex regions, Bedrock inference profiles, and Bedrock Mantle with its documented context, output, image, thinking, and pricing behavior. #98254 Thanks @vortexopenclaw.
  • Users with Claude Mythos 5 access can select it through Anthropic, Anthropic Vertex, Amazon Bedrock, or Bedrock Mantle with its required context, output, thinking, caching, and replay behavior. #101238 Thanks @vincentkoc.
  • ##### More provider options
  • Copilot sessions can explicitly use supported custom OpenAI, Azure OpenAI, Ollama-compatible, or Anthropic providers and start a compatible session when connection or credential settings change. Paired computers can run short tasks on eligible local Ollama models, while ClawRouter can expose the models granted to one managed key and report their usage and budget. Users can also claim active promotional models without replacing existing defaults, install LongCat-2.0 through its official provider, and continue Gemini latest tool-calling conversations across both supported Google transports.
  • Copilot sessions can now use explicitly selected custom OpenAI, Azure OpenAI, Ollama-compatible, or Anthropic providers and restart cleanly when model, endpoint, credentials, headers, or token limits change. #96345 Thanks @vincentkoc.
  • OpenClaw agents can now run short tasks on chat-capable Ollama models installed on paired macOS, Linux, or Windows nodes, with a separate control for disabling node inference. #99234 Related #99228.
  • A single CLAWROUTER_API_KEY can now expose only its granted models across supported transports and show managed requests, tokens, spend, and monthly budget in normal status views. #99658 Related #99657.
  • Users can discover active promotional models and claim them with openclaw promos claim <slug> without rerunning onboarding or unexpectedly replacing existing defaults and credentials. #100236 Thanks @fuller-stack-dev.
  • Hosted LongCat-2.0 can now be installed through the official LongCat plugin, configured with LONGCAT_API_KEY during onboarding, and selected as longcat/LongCat-2.0 for multi-turn tool use. #100501 Thanks @vincentkoc.
  • Gemini latest aliases now continue tool-calling conversations across both supported Google transports instead of stopping with a missing-thought-signature HTTP 400. #100605 Thanks @chenxiaoyu209, @guarismo.
  • #### Coding agents
  • OpenClaw now works more cleanly with coding agents that live outside the current chat. openclaw attach can open Claude Code against the main or a selected Gateway session with temporary, revocable access instead of process-wide credentials. Codex app-server sessions can resume, delegate to native subagents, and return their results as tracked work, while Copilot sessions can use explicitly selected custom providers and restart when their connection settings change.
  • The surrounding session workflow is more durable too. Important conversations can be pinned, renamed, archived, restored, and monitored as ongoing work, while active goals remain part of working memory across later turns, compaction, queues, and interruptions.
  • External tools can now receive session-scoped Gateway access without process-wide credentials or permission to impersonate another session, forming the secure base for openclaw attach. #96351 Thanks @anagnorisis2peripeteia, @obviyus.
  • openclaw attach now launches Claude Code with temporary access to the main or selected Gateway session, keeps credentials out of arguments, and revokes the grant when the session ends. #96454 Thanks @anagnorisis2peripeteia, @obviyus.
  • GPT-5.6 users can now select supported Ultra modes consistently, keep model and thinking choices aligned across OpenClaw surfaces, and receive native Codex child-agent results as tracked tasks. #98021 Thanks @anyech.
  • Codex app-server agents can again list allowed agents, spawn OpenClaw or connected subagents, and yield during delegated work without resumed heartbeats hitting incompatible tool definitions. #99561 Related #99464. Thanks @100yenadmin, @joshavant.
  • Codex-native delegation from OpenClaw threads now creates native task records again, while unsupported custom Codex app-server versions fail startup with a clear minimum-version error. #101221
  • Copilot sessions can now use explicitly selected custom OpenAI, Azure OpenAI, Ollama-compatible, or Anthropic providers and restart cleanly when model, endpoint, credentials, headers, or token limits change. #96345 Thanks @vincentkoc.
  • Sessions can now be pinned, archived without losing transcripts, restored, renamed from chat surfaces, and monitored for active runs as durable conversation threads. #98510 Thanks @maziyang2.
  • An active /goal now keeps guiding later turns and survives compaction, queues, and interruptions until the goal is paused, completed, blocked, or limited. #100468
  • #### Telegram
  • Telegram received broad work across live progress, media, documents, topics, commands, retries, account routing, setup, and delivery. Albums reach the model with every available image, long replies remain easier to follow while they run, and temporary conflicts or network failures are less likely to block later messages or create duplicates.
  • Messages and actions also stay with the intended bot, topic, and conversation more consistently, while setup and account-health problems provide clearer ways to recover.
  • Telegram photo albums now give the model every successfully downloaded image in order instead of only one photo and unusable file references, while failed items are omitted. #97045 Thanks @nianjiuzst, @obviyus.
  • Telegram's live progress view now keeps reasoning, commentary, formatting, and tool activity readable and stable, then leaves a concise completion summary instead of disappearing. #98907 Thanks @marvinthebored, @peetiegonzalez.
  • Telegram users should see fewer failed final replies or bot delivery sends during flaky network handshakes, without increasing duplicate-message risk for failures that may have happened after a request was sent. #101258 Thanks @lzw112.
  • Telegram PDFs and other documents now provide agents with a usable local path so normal runner tools can open the attachment. #97647 Thanks @gallup007, @joshavant.
  • Telegram timeout logs now hide bot tokens embedded in Bot API paths, including custom and proxy roots, while retaining useful endpoint context. #99428 Related #96982. Thanks @liuhaiyang14, @xialonglee.
  • Telegram bot tokens now remain masked even when they cross internal boundaries inside very large logs or tool-error messages. #103861 Thanks @vincentkoc.
  • When a Telegram plugin approval cannot be routed, operators now receive practical Web UI, terminal UI, and configuration guidance instead of a generic failure or timeout. #95973 Related #95800. Thanks @chrisbot2026, @monkeyleet.
  • Scheduled deliveries to numeric threads such as Telegram forum topics now return to the configured thread after Gateway restarts instead of falling back to the general chat. #98699 Thanks @yetval.
  • #### Slack
  • Slack threads retain their conversation history more consistently, interactive cards and progress stay in the right place, and accepted replies are less likely to be repeated after an uncertain confirmation. Long-running conversations also avoid more unnecessary waits before reaching the agent.
  • Slack replies stay attached to the root thread's session history instead of accumulating separate, nearly empty child sessions. #97168 Related #96535. Thanks @gorkem2020, @liuwqgit.
  • When Slack accepts a reply but the confirmation is lost, OpenClaw can verify the existing post and avoid sending a duplicate. #97480 Thanks @joeyfrasier.
  • Slack and similar channel turns with context-injecting plugins now send each inbound system label to the model once instead of duplicating it. #95349 Thanks @gorkem2020, @openperf, @vincentkoc.
  • Slack rooms that require a mention no longer wake OpenClaw for ordinary messages when the bot identity is missing or untrusted, and setup warnings point operators to a Bot User OAuth Token when needed. #91584 Thanks @hiragram.
  • #### Discord
  • Discord improves reply visibility, attachments, voice sessions, progress, reconnects, and multi-account behavior. Completed replies produce more useful unread cues, brief Gateway reconnects are less likely to lose outbound messages, and repeated session-resume failures can recover without taking the whole Gateway down.
  • Completed partial-stream Discord replies now arrive as fresh messages that can trigger normal unread cues after a user leaves the channel. #99711 Thanks @davelutztx.
  • Discord replies, cron reports, and other outbound messages are less likely to disappear during a brief Gateway reconnect, without replaying chunks or media Discord already accepted. #100896 Thanks @tiffanychum.
  • Discord bots can now recover in place after repeated session-resume rejection, reducing prolonged outages, lost replies, and full Gateway restarts. #103596
  • Discord Code Mode progress no longer fills with repetitive Wait rows from background polling, while ordinary custom and plugin tools remain visible. #100164
  • Long Discord approval previews now preserve complete emoji and flags when shortened, avoiding broken replacement characters. #99539 Thanks @zhangguiping-xydt.
  • Discord read allowlists now block guild metadata, channel details, and thread listings before any provider request when those resources are outside the configured scope. #98966 Thanks @pgondhi987.
  • Discord users can complete approved Codex Computer Use actions such as get_app_state and receive the native tool result instead of getting a false timeout while the tool is still running. #96818 Thanks @pollybot13, @zhangguiping-xydt.
  • #### Apple Messages
  • Apple Messages receives broader improvements to replies, typing, media, routing, setup guidance, and chat continuity. Remote Mac attachments can reach the active conversation through a usable local path, replies work in more bridge setups, and ordinary message text is less likely to be mistaken for internal role markers.
  • Photos bridged from a remote iMessage Mac to a separate Gateway host now arrive in Codex conversations through a readable local path rather than a Mac-only filename. #91803 Thanks @turbotheturtle.
  • AppleScript-only and bot-user or SSH iMessage setups now deliver replies even when threading is unavailable, and database changes no longer leave inbound messages hidden behind stale recovery state. #100446 Thanks @omarshahine.
  • Direct iMessage chats using the imsg private API bridge now show typing as soon as a slow turn is accepted, without waiting for a read receipt. #95621 Thanks @omarshahine.
  • iMessage replies no longer lose ordinary sentence text that happens to end with user:, system:, or assistant:. #96392 Thanks @ly-wang19.
  • Hidden MiniMax reasoning no longer appears as a new iMessage or feeds back into the conversation as an echo-triggering inbound message. #93820 Thanks @alix-007.
  • Renaming iMessage groups, changing icons or membership, and leaving groups now require verified owner or administrator authority. #97961 Thanks @eleqtrizit.
  • Mac users setting up iMessage can install or update imsg from the setup flow, receive clearer probe guidance, and recover sessions that still reference the old skill location. #101407 Thanks @omarshahine.
  • #### Gateway restart recovery
  • A supervised Gateway that repeatedly fails during startup now leaves operators a stable restart and recovery process to inspect and repair. Instead of relaunching forever, the control path remains available while automatic channel and provider restarts pause until the underlying problem is fixed.
  • A repeatedly crashing supervised Gateway now leaves a stable control process available for inspection and repair instead of trapping operators in a restart loop. a18708c Thanks @obviyus.
  • #### Automation, browser control, and terminals
  • Scheduled work can wake when a command finishes or a watched condition changes, remote browser control can pair selected signed-in tabs and save completed downloads safely, and guarded workspace terminals are available across web and mobile.
  • ##### Scheduled work
  • Scheduled jobs can react when an external command finishes or a watched condition changes, so the full agent runs only when there is something new to handle. Reapplying the same declaration updates the intended job in place, preserving identity and history instead of creating duplicate schedules.
  • A cron job can now watch a build, deploy, script, or other command and resume the originating workflow with its exit code and recent output when it finishes. #92037 Thanks @anagnorisis2peripeteia.
  • Cron declarations can now be safely reapplied without duplicate jobs or lost history, while ownership, next run, latest result, delivery, and failure notifications are easier to inspect. #100480
  • Cron jobs can now watch an outside condition and run their real payload only when that state changes, avoiding full agent wakeups on unchanged polls. #101195
  • ##### Remote browser control
  • Browser control is easier to use across machines: operators can pair the bundled Chrome extension with a remote Gateway, share only selected signed-in tabs, diagnose Windows and WSL2 connection details, and revoke access by removing a tab from the OpenClaw group. Agents can also wait for delayed downloads and save the finished file to a guarded local path with its final URL and suggested name.
  • Windows and WSL2 users now get IPv4 and IPv6 checks plus the matching portproxy guidance needed to restore Chrome browser control without broadening CDP exposure. #100590 Thanks @owlock, @zengwen-dt.
  • The bundled Chrome extension now lets users control selected signed-in tabs from a phone or another channel without someone approving remote debugging at the desktop, and removing a tab revokes access. #100619
  • Remote Gateway users can pair the bundled Chrome extension from another browser machine with openclaw browser extension pair --gateway-url wss://..., without installing OpenClaw or Node.js there or opening an inbound port. #101127
  • Agents can now save a browser download to a chosen guarded path or wait for a delayed export, receiving the final URL, filename, and local path. #101369 Thanks @grd-chang.
  • ##### Workspace terminals
  • Authenticated operators can open a guarded workspace terminal from the Control UI, iOS, or Android without leaving the current workspace. Sessions use the selected agent's workspace and configured shell, can be disabled by policy, and follow the Gateway protocol controls for ownership and connection state. Browser terminals can dock, resize, and run side by side, while iOS and Android provide focused entry points with clear connection guidance.
  • Same-release browser hardening completes the capability: terminals can reattach after reloads, sleep, or brief network drops and replay recent output; newly enabled support appears without a manual refresh; and closing, reopening, theming, cursor focus, prompt glyphs, and new-tab controls remain usable through repeated sessions.
  • Authenticated admins can open an interactive terminal in an agent workspace from Gateway-backed controls, while fully sandboxed agents remain blocked and the feature can be disabled with gateway.terminal.enabled. f083f35
  • Control UI admins can now keep chat, session controls, and live shells together by opening multiple dockable, resizable terminal tabs inside the browser workspace. ec72de4
  • Opt-in Control UI terminal sessions can now survive page reloads, sleep, and brief network drops, letting operators reattach and replay recent output instead of losing running commands. #100089
  • Opening a new Control UI terminal after closing the final tab now starts with a blank fresh shell instead of restoring the closed terminal output. #100665
  • Control UI terminal tabs now close cleanly while opening, follow theme changes, and reopen at a usable size instead of leaving hidden sessions, stale colors, or unreachable controls. 2399ce7
  • An already-open Control UI page now notices when terminal support is enabled and makes the terminal available without requiring a manual refresh. 3f976f9
  • Opening a new Control UI terminal tab after closing another no longer inherits an old exited state. 3c03389
  • The Control UI terminal no longer crashes when its web component is loaded more than once in a shared browser registry. f2e5159
  • Control UI terminals now use installed Nerd Font fallbacks so supported prompt and listing icons render as glyphs instead of placeholder boxes. #100128
  • The Control UI integrated terminal now shows one cursor instead of overlapping Chrome and terminal carets, making focus and typing state clearer. #100240
  • The Control UI terminal's new-session button now aligns with the surrounding tabs for a cleaner, easier-to-scan tab bar. #100256
Channels and Messaging
  • Replies and media now stay attached to the intended conversation more consistently across workspace, mobile, and community channels. Signal can quote the triggering message and use friendly destination aliases, while Telegram handles albums, progress, retries, topics, routing, and delivery with fewer dropped, duplicated, stale, or hard-to-read results.
  • Discord, Slack, WhatsApp, Apple Messages, and other supported channels also receive clearer command, thread, attachment, proxy, and recovery behavior. The Apple Messages setup and delivery paths in this group preserve the chat context readers expect rather than exposing the routing work underneath.
  • #### Telegram
  • Telegram automations can now tell from platform metadata whether a sender is a bot, making routing and classification less dependent on usernames or naming conventions. #96810 Thanks @lin-hongkuan, @ohyeah521.
  • Telegram sends and message actions that omit an account now consistently use the configured default bot instead of a stale identity that can misroute or reject the action. #98789 Thanks @yetval.
  • Telegram destinations genuinely named current, self, this, or me can now be reached through configured entries, while accidental bare session words fail closed. #94107 Thanks @obviyus, @silver-state, @zhangguiping-xydt.
  • Telegram sends to an username now use the account's configured proxy or custom Bot API endpoint for both target resolution and message delivery. #100868 Thanks @machine3at.
  • Telegram webhook startup now releases its listener, bot, and network resources after a fatal registration error such as invalid or revoked credentials. #100863 Thanks @machine3at.
  • Telegram photo albums now give the model every successfully downloaded image in order instead of only one photo and unusable file references, while failed items are omitted. #97045 Thanks @nianjiuzst, @obviyus.
  • Telegram replies now omit internal tool-execution failure lines and deliver only the intended assistant answer. #95774 Thanks @mushuiyu886.
  • Telegram replies retain literal wording such as <think> when it is part of the answer, while genuinely marked reasoning remains hidden. #97286 Thanks @drickon, @obviyus.
  • Telegram heartbeat fallbacks now hide the notify=false control marker and deliver silently as requested, including suppressing marker-only replies. #100735 Thanks @hackerismydream, @vincentkoc.
  • Telegram stickers and other plugin message actions now stay in the active forum topic or thread when sent to the matching conversation, including through Gateway dispatch. #80293 Thanks @artdaal.
  • Telegram messages can now be sent proactively through the message tool or openclaw message send instead of failing as an unsupported channel. #92107 Thanks @bladin, @obviyus.
  • sessions_send now rejects Telegram topic child sessions before dispatch and directs callers to the parent group, reducing misrouted agent work. #99845 Thanks @nianjiuzst, @qingminglong.
  • Polls now follow the selected direct or hybrid channel instead of being misrouted through the Gateway, with clear errors for unsupported duration or anonymity options. #99950 Thanks @nianjiuzst.
  • Established Telegram direct-message sessions now avoid resending recent messages already stored in the transcript, reducing token use and repetitive or confused replies. #89855 Thanks @sweetcornna.
  • Telegram direct-message follow-ups now include one copy of the previous assistant reply in recent context instead of duplicating it and wasting tokens. #98769 Related #98767. Thanks @rabsef-bicrym.
  • Telegram bots in ambient group mode now see recent room context before deciding whether to speak, reducing replies to isolated fragments that were not directed at the bot. #99143 Related #99142. Thanks @obviyus.
  • Telegram group agents now receive one chronological copy of recent messages instead of duplicated history and repeated delivery details consuming context. #99256 Related #99218. Thanks @obviyus.
  • Telegram ambient group conversations can now retain unmentioned room context across later turns, restarts, and compaction without repeatedly replaying the same window. #99306 Related #99257. Thanks @obviyus.
  • Telegram ambient group sessions now restore the relevant older chat context after a reset instead of silently treating archived messages as already visible. #99385 Related #99373. Thanks @obviyus.
  • Telegram group agents now post visible replies when directly mentioned or replied to, while continuing to ignore unaddressed background chatter. #99866 Related #99854. Thanks @obviyus.
  • Telegram direct-message follow-ups now include one accurate copy of each earlier assistant reply instead of duplicating a hidden-instruction version. #100573 Thanks @momothemage, @mooresoftware.
  • Telegram's live progress view now keeps reasoning, commentary, formatting, and tool activity readable and stable, then leaves a concise completion summary instead of disappearing. #98907 Thanks @marvinthebored, @peetiegonzalez.
  • Telegram rich replies and progress messages containing OAuth email addresses now arrive instead of being rejected by Telegram validation. #95900 Thanks @obviyus.
  • Telegram progress updates now truncate safely around emoji and other multi-unit characters, preventing broken glyphs and rejected Bot API payloads. #96456 Thanks @he-yufeng.
  • Telegram streaming draft previews no longer break or show garbled text when an emoji falls at the size boundary, so long previews can keep updating normally. #96504 Thanks @mushuiyu886, @obviyus.
  • Telegram replies now keep typing visible through more temporary API failures and fall back to plain text when valid rich content cannot be delivered. #99745 Thanks @obviyus, @veda-openclaw.
  • Telegram typing indicators now retry after transient network failures, restoring status feedback without adding duplicate-message risk to normal sends. #100762 Thanks @lzw112, @vincentkoc.
  • Telegram's final collapsed progress summary now includes Claude CLI thinking activity that was shown during the run instead of making that work appear to vanish. 4212de9 Thanks @vincentkoc.
  • Telegram users with /reasoning on now receive the model's saved reasoning messages alongside the final answer. #97875 Thanks @fuller-stack-dev, @marvinthebored.
  • Telegram groups and forum topics now show a typing indicator as soon as an addressed message is accepted, without signaling activity for ignored chatter. #99965 Thanks @moeedahmed.
  • Telegram configurations with legacy capabilities: [] now inherit the normal inline-button policy, restoring clickable buttons without overriding intentional opt-outs. #96468 Thanks @vincentkoc, @zhangguiping-xydt.
  • Telegram users still receive a plain-text reply when rich formatting for an email, URL, mention, hashtag, command, phone number, bank card, or similar entity is rejected, instead of the bot going silent. #96642 Thanks @moguangyu5-design.
  • Telegram inline buttons supplied by plugins now run their intended actions and cleanup instead of posting raw callback data into chat. #97174 Thanks @goldmar.
  • Telegram rich-text replies now render math formulas more reliably instead of exposing raw LaTeX-style markers. #97197 Thanks @vincentkoc, @wangwllu.
  • Telegram final replies and media sends now fall back to readable plain text when formatting, captions, or quotes are rejected, and routine flood waits up to 60 seconds are honored instead of dropping the message. #98786 Related #98778. Thanks @obviyus.
  • Telegram plugins can now turn a button tap into a normal user reply to the agent, while failed or skipped submissions leave the button available for another attempt. #98922 Thanks @goldmar.
  • Telegram tables, rankings, and literal line breaks now remain readable, with explicit logs when rich content must fall back to plain text. #99861 Related #99833. Thanks @obviyus.
  • Telegram rich messages using richMessages: true and Markdown table mode block now display bordered, striped tables with the source column alignment. #95822 Thanks @obviyus, @zhangguiping-xydt.
  • Telegram fallback messages now replace invalid numeric Unicode surrogate entities safely instead of emitting malformed text, while valid numeric emoji entities still render. #96581 Thanks @llagy007, @weeli-009.
  • Telegram documents received through a containerized local Bot API now arrive with their actual contents when its mounted data path differs between containers. #91984 Thanks @ailucasdz, @dizesales.
  • Telegram documents sent near a Gateway restart now retry after recovery instead of disappearing silently, while permanent failures still request a resend. #98102 Related #98076. Thanks @davearcher18, @luoyanglang, @obviyus.
  • Telegram rich messages and text-bearing forwards without a normal caption now reach the agent as readable conversation content instead of an unsupported-message placeholder. #98735 Thanks @obviyus.
  • Telegram now tells users when an attachment cannot be downloaded, reports the actual size limit for oversized files, and still retries transient failures such as rate limits. #100051 Thanks @batyaro777.
  • Telegram replies and forwards now preserve visible text from rich details, lists, math, captions, and credits so the agent receives the context users actually saw. #100570 Thanks @veda-openclaw, @wangwllu.
  • MP3 speech from Piper, Kokoro, and other OpenAI-compatible TTS endpoints now arrives in Telegram as a native voice note rather than a filename-style audio attachment. #100715 Thanks @hemantsudarshan.
  • Telegram no longer follows a successfully delivered final answer with a contradictory generic error when a later dispatch step fails, while partial-only failures still receive the existing fallback. #90152 Thanks @zhangguiping-xydt.
  • A temporary Telegram reply-session conflict no longer traps a DM or forum topic in constant retries that block later messages; retries are paced, conversation order is retained, and unrelated chats continue processing. #96550 Thanks @cnbarrier404, @vacinc.
  • Telegram reactions and message deletions now retry brief socket or Undici network failures, reducing unnecessary action failures without adding duplicate risk to ordinary message sends. #96612 Thanks @miorbnli.
  • Telegram messages entering through isolated ingress now proceed to the agent reply instead of replaying the same message in a loop. #96847 Thanks @obviyus.
  • Long-running Telegram turns can finish without being reclaimed and processed again midway, reducing stalled or duplicate delivery while giving operators a clearer unhealthy status when the backlog stops draining. #96962 Thanks @joshavant.
  • Telegram bots using isolated polling can resume ordered message processing after a stalled drain or Gateway restart without manual database repair. #97118 Thanks @romneyda, @vincentkoc.
  • Long non-streamed Telegram group replies now keep every chunk visible, including the beginning, while delivery receipts cover all generated text chunks. #97304 Thanks @aliseturtle-lu, @obviyus.
  • Long streamed Telegram replies now deliver their middle sections under the default configuration instead of silently omitting part of the answer. #97312 Thanks @brycemurray, @obviyus.
  • Telegram polling now recovers from temporary rate limits, server failures, and malformed error responses without disabling the account, while busy bots avoid cache writes that could trigger false stall restarts. #98775 Related #98772, #98773. Thanks @obviyus.
  • A repeatedly failing Telegram update no longer blocks later messages in the same chat or topic, and replayed updates are retried safely without duplicate commands or apology spam. #98776 Related #98774. Thanks @obviyus.
  • Telegram webhook messages now survive Gateway restarts and temporary processing failures, while accounts recover from brief startup errors and repeated restarts stop leaking network connections. #98806 Related #98777. Thanks @obviyus.
  • Queued Telegram updates now remain replayable until restart recovery is safely recorded, reducing message loss during a crash at processing startup. #104032 Thanks @obviyus, @vincentkoc.
  • Telegram sends now retry a safe TCP or TLS connection timeout, reducing lost final replies during flaky handshakes without retrying failures that may already have reached Telegram. #101258 Thanks @lzw112.
  • Telegram startup logs now show local socket failures such as EADDRNOTAVAIL instead of incorrectly steering operators toward DNS troubleshooting. #97130 Thanks @zhangguiping-xydt.
  • Telegram bot probes, webhook checks, membership audits, and polling now reject oversized Bot API success bodies before they can exhaust Gateway memory. #97271 Thanks @hugenshen.
  • Telegram chat-ID lookup now fails safely on oversized getChat responses instead of risking excessive Gateway memory use during onboarding or routing. #97274 Thanks @hugenshen.
  • Telegram onboarding now offers both the classic BotFather chat flow and the official web interface for creating a bot and copying its token into OpenClaw. #100540
  • After /login codex succeeds in Telegram, retrying the request now uses the newly authenticated OpenAI profile instead of the previous account. fca0c81 Thanks @100yenadmin.
  • Telegram /steer and /tell commands can redirect an active Codex task during streaming or tool work instead of arriving late or becoming follow-up messages. #98126 Related #81594. Thanks @100yenadmin, @kyzcreig.
  • Saying wait in a Telegram group conversation no longer cancels active OpenClaw work, while explicit stop commands still take effect immediately. #98639 Thanks @ianchen08.
  • Telegram messages that cannot be steered into an active Codex turn are now retained for handling afterward instead of disappearing without a reply. #103916 Thanks @jalehman.
  • When Telegram requests overlap, the newest authorized message now wins without an outdated reply being sent or replaced queued work being started. #103965
  • A Telegram reply that has already started is no longer unexpectedly cancelled when another authorized command arrives. 52a3314 Thanks @vincentkoc.
  • #### Signal
  • Signal auto-replies now quote the message that triggered them, making responses easier to follow in groups and busy conversations. #95718 Thanks @jesse-merhi.
  • Signal reaction shortcuts now apply only to the intended structured exec or plugin approval, including forwarded monitor and chunked prompts, while ordinary messages that merely quote approval commands no longer gain controls; older delivered prompts may still require /approve once after upgrade. #96880 Thanks @joshavant.
  • Signal users who enable status reactions can now see when OpenClaw accepts a message, works, uses tools, compacts, stalls, or finishes in direct and group chats. #98791 Thanks @jesse-merhi.
  • Signal QuickStart now shows one clear signal-cli installation failure and proceeds directly to the custom-path prompt instead of repeating the missing-binary message. #96932 Thanks @romneyda.
  • Signal plugin setup now handles slow, malformed, or oversized GitHub release metadata without risking process memory exhaustion. #97536 Thanks @hugenshen.
  • Signal container mode now stops oversized or runaway signal-cli-rest-api responses from threatening the entire OpenClaw process. #97539 Thanks @alix-007.
  • Invalid JSON from the Signal REST container now produces a clear Signal-specific failure instead of exposing a raw parser error. #98073 Thanks @lsr911, @vincentkoc.
  • Signal QuickStart on macOS now installs signal-cli through Homebrew instead of downloading an incompatible Linux package, and gives platform-specific guidance when Homebrew is unavailable. #96909 Thanks @romneyda.
  • Signal container receives now reject oversized JSON frames before buffering them, limiting memory pressure without affecting normal messages or separately fetched attachments. #99992 Thanks @sunlit-deng.
  • Signal users can assign stable names such as signal:me or signal:ops to repeat contacts and groups instead of reusing raw phone numbers, UUIDs, or IDs. #95738 Thanks @jesse-merhi.
  • Signal users now receive clean assistant replies without internal tool status, reasoning tags, or tool-call markup. #97360 Thanks @masatohoshino.
  • Signal local-file attachments that are oversized or use suspicious paths now fail quickly with a clear error before consuming excessive Gateway memory. #101391 Thanks @cxbasdev.
  • #### Slack
  • Slack channels can keep ambient OpenClaw participation while the opt-in ignoreOtherMentions setting prevents replies to conversations aimed at another person or group and retains that conversation as context for a later bot mention. #53467 Thanks @hanamizuki.
  • Slack operators can now choose off, first, all, or batched reply threading per channel, with automatic replies and message tools following the same effective choice. #82253
  • Slack button and select interactions now remain in the correct assistant thread and show a working status there until the follow-up turn finishes. #82895 Thanks @wukongai-cmu.
  • The first Slack reply after a daily or idle reset can reuse recent thread history, so the conversation does not suddenly start from scratch. #97100 Thanks @bek91.
  • Slack replies stay attached to the root thread's session history instead of accumulating separate, nearly empty child sessions. #97168 Related #96535. Thanks @gorkem2020, @liuwqgit.
  • Ordinary Slack thread replies no longer download and process the opening message attachments again, while new or reset sessions still receive those files once. #100516
  • Session history now identifies Slack replies that were generated but intentionally superseded before delivery, so operators do not mistake them for messages the user received. #100607 Thanks @bek91.
  • Slack replies in very long threads and on busy Gateways now avoid several unnecessary waits, reducing stalls before thread and direct-message events reach the agent. #101888 Thanks @obviyus.
  • Slack agents can now read thread messages whose visible content exists only in attachments or blocks, including alerts with empty top-level text. #97727 Thanks @chthtlo.
  • Slack Codex conversations now retain one final assistant reply in history instead of duplicating it through both the app-server transcript and delivery fallback. #100160 Thanks @steipete-oai.
  • Scheduled and heartbeat-driven Slack messages now use the configured agent name and icon, with graceful fallback to the app identity when Slack rejects customization. #84335 Thanks @rohang2005.
  • Longer Slack assistant-thread replies now show changing progress notes so users can tell OpenClaw is still working. #85507 Thanks @emergentash.
  • Slack presentation messages now arrive as native Block Kit cards with working headers, controls, and receipts instead of flattened plain text. #95463 Thanks @zoowh.
  • Slack rich-text block actions can now include emoji near the preview limit without producing malformed interaction text or downstream encoding failures. #96577 Thanks @llagy007, @weeli-009.
  • Slack buttons and menus now preserve time labels such as 9:00 and return the intended action value when selected. #99877 Thanks @qingminglong, @rodja.
  • Slack message reactions now accept common emoji or shortcode names, can target the current message without repeating its ID, and provide clearer member-lookup guidance. #100375 Thanks @gorkem2020.
  • Slack now uses one static acknowledgement reaction alongside its native assistant loading status by default, avoiding two competing progress displays for the same reply. #100462 Thanks @steipete-oai.
  • Slack messages and Block Kit labels now truncate without splitting emoji into broken replacement characters or invalid payload text. #96382 Thanks @ly-wang19.
  • Long Slack command and plugin approval previews now keep emoji intact at the length boundary, avoiding malformed approval text or payloads. #96576 Thanks @llagy007, @weeli-009.
  • Slack slash-command choice menus now shorten long labels without splitting emoji at the 75-character limit. #97923 Thanks @lexes7.
  • Slack replies now keep each agent's custom name and avatar through streaming or fallback delivery instead of reverting to the app identity. #100084 Thanks @moerai.
  • Slack operators running multiple Gateways through one Socket Mode app now receive a startup warning explaining why events may reach another connection and how to choose a safer deployment setup. #79938 Thanks @jeffvsutherland.
  • Slack replies no longer expose internal tool-failure banners, reasoning scaffolding, or tool-call markup to users. #97367 Thanks @masatohoshino.
  • When Slack accepts a reply but the confirmation is lost, OpenClaw can verify the existing post and avoid sending a duplicate. #97480 Thanks @joeyfrasier.
  • Slack replies now retry after a temporary session-start conflict instead of stopping before the expected message is delivered. #99647 Thanks @steipete-oai.
  • Slack read actions can again access intentionally allowlisted channel names when Slack supplies an ID and dangerouslyAllowNameMatching is enabled. #95313 Thanks @jontsai.
  • Slack message and attachment text is no longer copied into verbose or debug logs during inbound processing. #96312 Thanks @steipete-oai.
  • OpenClaw can use a trusted override for a compatible Slack API endpoint, while normal workspaces continue using Slack's public API and untrusted project .env files cannot redirect bearer-token requests. #97154 Thanks @romneyda.
  • Slack agents can now identify admitted bot-authored messages through is_bot: true, making it easier to prevent unwanted bot-to-bot replies. #97822 Thanks @masatohoshino, @vincentkoc.
  • Slack Socket Mode relay diagnostics now distinguish malformed WebSocket frames from transport failures, making channel problems easier to identify. #98587 Thanks @lsr911, @vincentkoc.
  • Slack startup and account checks now warn when a user OAuth credential is configured as the bot token, before identity confusion affects mentions or replies. #99931 Thanks @ooiuuii.
  • Long-running Slack integrations now keep conversation metadata caching within a fixed limit, preventing memory use from growing indefinitely as more channels and workspaces are encountered. #101562 Thanks @vincentkoc, @zhangguiping-xydt.
  • #### Discord
  • Discord tool-only replies no longer leave overlapping typing refreshes that suggest another answer is still coming, while explicitly configured typing behavior remains intact. #84288 Thanks @dr00-eth.
  • When a Discord voice-note reply fails, users now receive the assistant's answer as a threaded text fallback without duplicating text that was already delivered. #89962 Thanks @danhayman.
  • Discord's clear-all reactions action now returns a real error if any bot reaction remains instead of claiming complete success. #90038 Thanks @masatohoshino.
  • Discord now shows enabled Anthropic reasoning, notes, and tool activity in the right order with accurate counters and nonblank summaries. #96106 Thanks @marvinthebored, @obviyus, @peetiegonzalez.
  • Discord users now receive the reply text and a clear notice when an attachment is too large instead of seeing the completed response disappear. #99577 Thanks @lin-hongkuan.
  • Completed partial-stream Discord replies now arrive as fresh messages that can trigger normal unread cues after a user leaves the channel. #99711 Thanks @davelutztx.
  • Discord completion and error reactions now remain visible for the configured doneHoldMs and errorHoldMs durations instead of fixed default delays. #94736 Thanks @liuwqgit.
  • Discord voice replies now keep their accompanying text and extra media attached to the original message even when single-use reply mode is enabled. #95978 Thanks @nxmxbbd.
  • Discord attachments queued while OpenClaw is busy now remain available when the message finally runs instead of disappearing after temporary download links expire. #96183 Thanks @judsonnudson, @zacharyyw.
  • Generated Discord thread names now preserve multiple Markdown emphasis spans without dropping or stranding formatting markers. #96394 Thanks @ly-wang19.
  • Discord's recent-model buttons now shorten long names without breaking emoji or producing invalid picker payloads. #97600 Thanks @llagy007, @weeli-009.
  • Long or media-rich implicit Discord replies now quote and notify the referenced user once in first or batched mode, while explicit and all replies retain every intended reference. #100784 Thanks @qingminglong, @revision-co-ltd.
  • Discord replies, cron reports, and other outbound messages are less likely to disappear during a brief Gateway reconnect, without replaying chunks or media Discord already accepted. #100896 Thanks @tiffanychum.
  • Discord automatic thread titles now handle long messages and channel details containing emoji without building malformed prompt text. #101551 Thanks @alix-007.
  • Discord voice playback failures now produce a readable error within the 8,192-byte limit, including when ffmpeg output contains non-English text or emoji. #104230 Thanks @qingminglong.
  • Multiple Discord bot accounts in one server now keep independent voice sessions, and configured voice auto-join works even when Discord becomes ready before voice startup completes. #87530 Thanks @geekhuashan.
  • Checking a Discord member who is not in voice now reports them as disconnected instead of raising a misleading command or gateway failure. #90969 Thanks @asock.
  • Adding a named Discord account no longer knocks a SecretRef-backed default account offline or into a restart loop. #96401 Thanks @849261680.
  • Discord voice conversations in stt-tts mode now retain earlier spoken context across turns instead of starting over after each reply. #97746 Thanks @karabaralex, @sanjays2402.
  • Discord voice playback now turns broken ffmpeg output pipes into a normal playback error instead of an uncaught Gateway-level exception. #101088 Thanks @masatohoshino.
  • Discord bots can now recover in place after repeated session-resume rejection, reducing prolonged outages, lost replies, and full Gateway restarts. #103596
  • Discord voice playback now cleans up ffmpeg after output-pipe failures, reducing both Gateway crashes and leftover transcoder processes. #101124
  • The configured primary Discord account now starts first in multi-account setups, so the main bot is not delayed behind secondary or invalid entries after a restart. #101292 Thanks @turbotheturtle.
  • Discord message reads and searches now decode raw compressed responses correctly and return clear errors for unexpected data instead of garbled output or opaque failures. #80788 Thanks @jbetala7.
  • Discord REST calls now fail with a clear error when a response is oversized or stalls instead of risking unbounded memory use and process instability. #95412 Thanks @alix-007.
  • Discord account health checks now fail safely on oversized identity responses instead of risking a Gateway crash or out-of-memory failure. #97278 Thanks @hugenshen.
  • Discord message, thread-history, and attachment requests now reject oversized successful responses before they can drive excessive Gateway memory growth. #97693 Thanks @alix-007.
  • Discord PluralKit lookups and voice-upload setup now stop unexpectedly large JSON responses before they can exhaust memory. #97706 Thanks @cxbasdev.
  • Malformed successful Discord responses now fail with endpoint-specific context instead of surfacing a raw parser error or crashing OpenClaw. #97889 Thanks @lsr911.
  • An oversized Discord gateway metadata response now logs a bounded error and falls back to Discord's default gateway URL instead of risking a Gateway crash. #98682 Thanks @wings1029.
  • Discord deployments in restricted networks can now route Gateway and REST traffic through an explicitly configured DNS or private HTTP(S) proxy without opening broad direct HTTPS egress. #99126 Related #98266. Thanks @joshavant, @sallyom, @svuppala2006.
  • Discord Gateway connections now cap incoming frames at 16 MiB, preserving tested large member events while rejecting extreme traffic before it pressures memory. #99998 Thanks @sunlit-deng.
  • Discord agents now receive is_bot: true for admitted bot messages while human and PluralKit sender behavior stays unchanged. #97824 Thanks @masatohoshino, @vincentkoc.
  • #### WhatsApp
  • Logged-out or replaced WhatsApp accounts now stay stopped until reconnection instead of entering repeated restart loops that can consume resources and slow other accounts. #78511 Thanks @openperf.
  • Eligible WhatsApp messages received during a brief reconnect now reach OpenClaw for an automatic reply instead of being marked read and silently skipped. #80642 Thanks @vishalj99.
  • Concurrent WhatsApp Web replies, media, reactions, and queued messages now send one at a time per account, reducing interference and unpredictable delivery order. #99050 Thanks @ooiuuii.
  • Completed WhatsApp replies now continue delivering when another message arrives mid-delivery, so overlapping conversations are less likely to go unexpectedly silent. #100205
  • Invalid OPENCLAW_WHATSAPP_WEB_SOCKET_URL values now fail immediately with a clear configuration error instead of breaking later during socket startup. #97697 Thanks @romneyda.
  • WhatsApp can now restore a saved linked-device session from a valid credential backup when the primary file is interrupted or corrupted, avoiding an unnecessary QR re-pair. #99070 Thanks @leonidaslux.
  • openclaw channels login --channel whatsapp now replaces expired QR codes in place so interactive terminals show one current, scannable code. #100159
  • A WhatsApp message interrupted by a temporary reply-session conflict can now be retried instead of being marked delivered and silently ignored on redelivery. #101106 Thanks @andersonjeccel.
  • OpenClaw can use a trusted override to point the normal Baileys socket at a compatible local WebSocket endpoint, while normal WhatsApp connections continue using the default path unless explicitly overridden. #97155 Thanks @romneyda.
  • WhatsApp group owners can reliably use /new, /stop, /status, and similar commands even when their sender identity arrives as an internal LID. #93379 Related #77755. Thanks @jiveshkalra, @xialonglee.
  • Direct WhatsApp polls now honor the same outreach timelock as other sends instead of reaching recipients during a blocked window. 1d128b4 Thanks @vincentkoc.
  • Replies to OpenClaw-authored WhatsApp group messages now remain visible on WhatsApp Desktop and other multi-device clients with their quote context intact. #94879 Thanks @bartok9.
  • WhatsApp direct sends and automatic replies now render combined bold-and-italic Markdown without stray asterisks, including when the formatted text contains emoji. #96570 Thanks @llagy007, @weeli-009.
  • Long WhatsApp auto-reply and inbound-message previews now preserve emoji and report the truncated character count accurately, making affected diagnostics readable without changing delivery. #96580 Thanks @llagy007, @weeli-009.
  • WhatsApp direct messages blocked by a reachout timelock now fail immediately with an explicit explanation instead of appearing accepted before a later delivery error. #101264 Thanks @mcaxtr.
  • With channels.whatsapp.actions.calls, MeowCaller, and telephony TTS configured, a WhatsApp agent can now call the requester and speak a short task-completion or urgent message. #99635
  • #### Weixin
  • Configured Weixin accounts with opaque IDs containing characters such as an at sign or . now start normally and preserve their account-specific routing. #93686 Related #93556. Thanks @htkillermax-gif, @zhangguiping-xydt.
  • Official Weixin installs and core-upgrade reconciliation now target plugin version 2.4.6 with its correct compatibility requirement instead of unexpectedly returning users to 2.4.3. #96801 Thanks @lin-hongkuan.
  • #### Apple Messages
  • Compatible iMessage bridge users can create, read, and vote on native Apple Messages polls, with upgrade guidance for unsupported imsg installations. #98421 Thanks @lobster, @omarshahine.
  • Photos bridged from a remote iMessage Mac to a separate Gateway host now arrive in Codex conversations through a readable local path rather than a Mac-only filename. #91803 Thanks @turbotheturtle.
  • Voting for an emoji-labeled iMessage poll option no longer sends an extra one-word message that repeats the selected answer. #98691 Thanks @omarshahine.
  • Agents now answer iMessage polls, including polls with comments, with one native vote instead of an ordinary text answer, a repeated selection, or a separate reply to the comment. #98781 Thanks @omarshahine.
  • AppleScript-only and bot-user or SSH iMessage setups now deliver replies even when threading is unavailable, and database changes no longer leave inbound messages hidden behind stale recovery state. #100446 Thanks @omarshahine.
  • Direct iMessage chats using the imsg private API bridge now show typing as soon as a slow turn is accepted, without waiting for a read receipt. #95621 Thanks @omarshahine.
  • iMessage replies no longer lose ordinary sentence text that happens to end with user:, system:, or assistant:. #96392 Thanks @ly-wang19.
  • Bursts of long iMessage messages can now be combined without cutting an emoji in half and sending broken text to the agent. #97598 Thanks @weeli-009.
  • iMessage startup warnings now distinguish working sender-allowlisted group setups from truly blocked configurations and point blocked operators to the correct fix. #100046
  • Bare 32-character iMessage group IDs from imsg now route scheduled and direct sends to the intended conversation instead of a nonexistent phone number. #99525 Related #89235. Thanks @matthewdelprado.
  • An iMessage helper pipe failure now ends pending work predictably and lets the monitor recover or stop cleanly instead of crashing the Gateway or hanging requests. #101084 Thanks @masatohoshino.
  • iMessage CLI send and action failures caused by broken output pipes now return a controlled error instead of risking a Gateway worker crash. #101401 Thanks @cxbasdev.
  • #### LINE
  • Default and named LINE bots configured under channels.line.accounts now receive working webhook routes unless explicitly disabled, preventing valid inbound messages from ending in 404 responses. #81471 Thanks @edenfunf, @honorlin.
  • LINE file uploads now retain recognizable audio extensions such as .m4a, allowing valid recordings to reach transcription instead of being treated as unknown files. #96403 Thanks @tancolo, @zaidazmi.
  • LINE template titles, fallback text, and alt text now keep emoji intact at field limits, preventing broken previews and rejected payloads. #97428 Thanks @ly-wang19, @vincentkoc.
  • Long LINE button labels, quick replies, postback data, and media controls now preserve emoji at field limits instead of producing malformed text. #97470 Thanks @ly-wang19, @vincentkoc.
  • LINE messages, cards, menus, locations, and code blocks now preserve emoji and other multi-unit characters at field limits instead of producing broken text or rejected payloads. #98994 Thanks @lexes7, @vincentkoc.
  • LINE replies that combine text with an image, card, or location now report a failed rich-media portion accurately while delivering the text once and avoiding duplicate retries. #100996 Thanks @masatohoshino.
  • #### Feishu
  • Feishu replies now arrive as completed blocks when block streaming is enabled without streaming cards, rather than disappearing entirely. #94250 Related #55027. Thanks @vincentkoc, @xialonglee, @zichaolong.
  • When an interactive command button falls back to text, users now receive the command they can copy, with Feishu document comments explaining the manual step. #94385 Related #69754. Thanks @1yihui, @xialonglee.
  • openclaw channels login --channel feishu now prints a compact QR code that stays scannable in a normal terminal window. #97087 Thanks @nianjiuzst.
  • Long Feishu streaming-card summaries now keep emoji and other non-BMP characters intact at the truncation boundary. #97462 Thanks @ly-wang19.
  • Long Feishu comments containing emoji at the cutoff now reach the agent as valid text instead of being split into malformed characters. #97595 Thanks @llagy007, @weeli-009.
  • Feishu and Lark registration and streaming-card requests now reject oversized provider JSON before it can place unbounded pressure on memory. #97782 Thanks @alix-007.
  • Supported interactive-card JSON sent through Feishu messages, thread replies, or text payloads now renders as a card instead of appearing as raw JSON. #100883 Thanks @martingarramon, @vincentkoc, @zenorewn.
  • Stalled Feishu tenant-token or streaming-card requests now time out with a clear error and release the processing lane so other Gateway messages can continue. #102948 Thanks @hugenshen, @sallyom.
  • Feishu setups that could send bot pushes but silently lost user replies now pass incoming messages into OpenClaw instead of failing during monitor startup. #94013 Thanks @xydt-tanshanshan.
  • Feishu one-to-one chats can receive text, media, card, and fallback replies again instead of losing the response after the incoming message was processed. #94760 Thanks @obviyus, @xydigit-zt.
  • Feishu card headers now show a clean agent emoji and name instead of descriptive text from identity.emoji, while flags, skin-tone variants, family emoji, and other valid sequences remain intact. #96587 Thanks @harjothkhara, @leedongyu1128.
  • Feishu video messages now show the duration of local and remotely loaded MP4 clips when duration detection is available. #98235 Thanks @areslp.
  • Temporary Feishu streaming-card refresh failures are now contained and logged for diagnosis instead of surfacing as unhandled errors. #99301 Thanks @lwy-2.
  • Feishu direct messages received while the bot identity is temporarily unavailable no longer turn ordinary user mentions into accidental forwarding targets. #100891 Thanks @zhangguiping-xydt.
  • Feishu error logs now shorten emoji-containing text at a valid character boundary, making card-action and WebSocket cleanup failures easier to read. #101364 Thanks @zengwen-dt.
  • Feishu Drive can now list files beyond the first page of a large shared folder by accepting its returned next_page_token, with invalid page sizes rejected clearly before the request. #101572 Thanks @zhangguiping-xydt.
  • A Feishu connection that stops receiving messages is less likely to remain falsely marked healthy because transport activity now updates channel health. #90966 Thanks @acache, @richardataxai-lab, @vincentkoc.
  • Canceling a Feishu reconnect, startup, or bot-identity retry wait now ends cleanly instead of risking a ReferenceError during cleanup. #98137 Thanks @zhanglei99586.
  • Feishu bot replies no longer expose internal tool or runtime failure banners alongside the intended response. #98705 Thanks @zengwen-dt.
  • Multi-account Feishu setups can now start the default channel with an environment-backed top-level SecretRef and separate inline secrets for named accounts, without replacing the protected secret with plaintext. #96965 Thanks @zw-xysk.
  • #### Google Chat
  • Google Chat sends and request verification now bound oversized API, certificate, and error responses, allowing normal traffic through while broken or hostile bodies fail or truncate without exhausting memory. #96772 Thanks @vincentkoc, @wangmiao0668000666.
  • Google Chat agents can now distinguish allowed bot messages through is_bot: true and handle automated senders differently from people. #97825 Thanks @masatohoshino, @vincentkoc.
  • Long Google Chat approval cards now preserve emoji at the text limit, preventing corrupted approval text or malformed card payloads. #96573 Thanks @llagy007, @weeli-009.
  • #### Google Meet
  • Google Meet join, creation, talk-back, transcription, and related automation now work across browser and account languages by using English in OpenClaw-controlled Meet tabs. #89671 Thanks @unayung.
  • Google Meet sessions launched through a paired macOS Chrome node now open the intended URL with the configured Chrome profile and audio tools, while unsupported actions and executable overrides are rejected before reaching the node. #96908 Thanks @joshavant.
  • When Google Meet's local OAuth callback port is occupied, openclaw meet auth login now offers the manual redirect-paste flow instead of stopping sign-in. #96492 Thanks @jinduwang1001-max, @yetval.
  • #### Microsoft Teams
  • Microsoft Teams replies to long parent messages now keep emoji and similar characters intact in the agent's parent-message context instead of inserting malformed text. #96569 Thanks @llagy007, @weeli-009.
  • Microsoft Teams Adaptive Card button clicks now deliver the submitted value to the agent instead of arriving as empty messages. #97546 Thanks @jimmypuckett.
  • Microsoft Teams file delivery and chat lookup now cap large Microsoft Graph responses and return a labeled error instead of risking a process crash. #97784 Thanks @alix-007.
  • Microsoft Teams attachment recovery now declines oversized Graph metadata with diagnostics instead of buffering it into Gateway memory, while normal hosted media still downloads within configured limits. #101082 Thanks @cxbasdev.
  • The Microsoft Teams personal-chat welcome card now displays its greeting with the intended bold, medium emphasis. #96290 Thanks @ly-wang19, @vincentkoc.
  • Microsoft Teams thread history now preserves literal entity text such as <APIKEY> instead of turning it into different markup before the agent sees it. #96342 Thanks @ly-wang19.
  • Microsoft Teams feedback on long responses now carries intact emoji into reflection processing, preventing a cutoff from corrupting prompts, logs, or encoding. #96578 Thanks @llagy007, @weeli-009.
  • Oversized or malformed Microsoft Teams personal-chat attachment metadata now fails safely with a warning instead of consuming unbounded Gateway memory. #99125 Thanks @ly85206559.
  • #### Matrix
  • Long Matrix thread starters keep emoji and other special characters intact when OpenClaw shortens them for agent context. #97121 Thanks @bartok9, @ly-wang19.
  • Matrix operators now receive a structured warning when token rotations leave multiple populated storage roots, with details for identifying and carefully archiving stale folders. #97353 Thanks @eldron81-r2d2, @outdog-hwh.
  • Long Matrix reply quotes sent to agents now truncate emoji and other multi-unit characters without leaving broken text. #97471 Thanks @ly-wang19.
  • Matrix media downloads now enforce size and idle-timeout limits before buffering, including for encrypted media. #97662 Thanks @alix-007.
  • Malformed successful Matrix responses now produce a controlled homeserver error instead of an opaque unhandled JSON parsing failure. #97973 Thanks @lsr911.
  • Matrix dependency setup now stops its child process predictably and reports the failure when a local command's output pipe breaks. #101597 Thanks @alix-007.
  • Matrix replies now deliver the intended answer without leaking internal tool diagnostics, reasoning tags, or assistant-only scaffolding. #97372 Thanks @masatohoshino.
  • #### Mattermost
  • Mattermost streaming draft previews now shorten long text containing emoji without showing a malformed replacement character. #97472 Thanks @ly-wang19.
  • Mattermost channel monitoring now rejects inbound events above 16 MiB and reconnects, limiting memory exposure while continuing to accept normal large messages. #99366 Thanks @sunlit-deng.
  • Mattermost API calls now stop oversized or endless successful responses before they can consume unbounded memory, while normal requests and uploads continue unchanged. #96033 Thanks @alix-007.
  • Mattermost API failures with an empty JSON body now produce a clear status-based error instead of an Unexpected end of JSON input crash. #97851 Thanks @pick-cat.
  • Mattermost installations repaired after an upgrade now load and reconnect on Gateway restart without requiring a manual plugin-enable setting, including restrictive allowlist setups. #98608 Related #98564. Thanks @jacobtomlinson, @shakkernerd.
  • Mattermost teams with more than 200 members can now discover and address valid peers beyond the first page of the team directory. #98877 Related #98871. Thanks @qingminglong.
  • Mattermost replies now show the intended assistant response without exposing internal tool-failure diagnostics. #98693 Thanks @zengwen-dt.
  • Native /oc_* Mattermost commands work again in packaged installs using openclaw/mattermost, without allowing disabled or denied plugins to bypass Gateway checks. #98819 Related #98740. Thanks @amknight, @keltech-services.
  • #### Nextcloud
  • Nextcloud Talk sends and reactions now bound server response sizes, protecting OpenClaw from hangs or runaway memory use while preserving normal delivery. #96031 Thanks @alix-007.
  • Nextcloud Talk startup checks now show a concise bot-admin API failure without buffering an arbitrarily large error body. #97811 Thanks @pick-cat.
  • #### IRC
  • Long IRC messages now keep emoji and other supplementary characters intact when split into delivery chunks, including with unusually small configured chunk limits. #96572 Thanks @llagy007, @weeli-009.
  • IRC reconnects now rotate fallback nicknames after a 433 conflict instead of repeatedly retrying the same occupied name. #96108 Thanks @wendy-chsy.
  • IRC outbound text now preserves escaped emoji and keeps invalid surrogate escapes literal instead of silently replacing them with corrupted characters. #97683 Thanks @llagy007, @weeli-009.
  • Long IRC replies now arrive complete when they contain Chinese, Cyrillic, emoji, or other non-ASCII text, while respecting messageChunkMaxChars. #99138 Thanks @yetval.
  • IRC bots now reconnect and rejoin configured channels after a temporary server or network disconnect instead of staying silent until OpenClaw is restarted. #100799 Thanks @zhangguiping-xydt.
  • IRC users now receive the intended answer without internal tool-failure banners or assistant-only scaffolding appearing in channel messages. #97214 Thanks @masatohoshino, @studentzhou-svg, @vincentkoc.
  • IRC allowlists now reject host-less nick!user entries by default and guide operators toward verified full host masks, reducing impersonation risk. #98339 Thanks @yetval.
  • #### SMS
  • Twilio SMS account checks now handle malformed successful JSON with safe phone-number listing or a clear Messaging Service error. #97999 Thanks @lsr911.
  • SMS replies now hide internal tool-trace failure banners and show only the intended assistant response. #97989 Thanks @zengwen-dt.
  • #### Synology
  • Long Synology Chat messages and diagnostic previews now truncate without cutting an emoji or other supplementary character in half, keeping downstream text valid. #96574 Thanks @weeli-009.
  • #### Zalo
  • Zalo setup, polling, sending, and health checks now reject abnormally large successful replies before they can push the Gateway into severe memory pressure. #97277 Thanks @hugenshen.
  • Zalo operators can point Bot API calls at a compatible alternate endpoint without patching code, while ordinary workspace environment files cannot silently redirect traffic and millisecond message times remain accurate. #98768 Thanks @romneyda.
  • Zalo gateway startup output now shows the connected bot account name when the Bot Platform supplies it. #99274 Thanks @romneyda.
  • Zalo operators can send proactive CLI or scripted messages to valid nonnumeric chat_id values without an Unknown target rejection. #101548 Thanks @goutamadwant.
  • #### QQBot
  • QQBot upgrades now migrate recoverable credential backups into SQLite without deleting source files when import fails, while disposable caches rebuild separately. #89597
  • QQBot can now deliver documents and media created by sandboxed agents from authorized workspace paths while continuing to block path escapes. #92872 Thanks @sliverp, @zhangguiping-xydt.
  • QQBot speech-to-text now returns an early, labelled error when an OpenAI-compatible transcription endpoint sends an oversized response instead of buffering the full body in memory. #96968 Thanks @mushuiyu886.
  • QQBot Markdown tables now keep escaped pipe characters inside their cells, so commands and expressions do not shift into the wrong columns. #97429 Thanks @ly-wang19.
  • QQBot reminders created from long text now receive readable job names even when an emoji falls at the cutoff, rather than storing a broken character. #96575 Thanks @llagy007, @weeli-009.
  • QQBot status now reports disconnections and fatal close reasons accurately, then returns to connected only after a READY or RESUMED event. #100127 Thanks @masatohoshino, @vincentkoc.
  • QQBot approval cards, message previews, logs, media paths, and retry warnings now shorten emoji-containing text without broken replacement characters. #101421 Thanks @wangmiao0668000666.
  • QQBot previews, errors, commands, speech-to-text messages, media diagnostics, and logs now remain valid when emoji-containing text reaches a length limit. #101516 Thanks @vincentkoc, @wangmiao0668000666.
  • QQBot now avoids accidental reminders, limits exposure of private media details, and requires explicit confirmation before destructive channel or announcement actions. #98032 Thanks @patrick-erichsen.
  • #### Tlon and Urbit
  • Tlon and Urbit channel failures now bound oversized or malformed error responses before they can cause memory spikes, while retaining useful short messages. #98496 Thanks @pandah97.
  • Tlon now stops oversized or stalled external image downloads before they consume unbounded memory and can continue the message with the original URL. #100374 Thanks @hugenshen.
  • Oversized Tlon scry responses now fail with a clear path-specific error instead of risking a Gateway out-of-memory crash. #100376 Thanks @hugenshen.
  • Tlon approval notifications now keep emoji intact at the preview limit, preventing malformed message previews. #97599 Thanks @llagy007, @weeli-009.
  • Tlon media uploads now stop safely when Memex returns an oversized or malformed response instead of allowing the upload attempt to consume excessive memory. #101115 Thanks @cxbasdev.
  • #### Nostr
  • Repeated Nostr profile publishing now clears relay timeout timers after success, reducing stale resource buildup in long-running agents. #98720 Related #98463. Thanks @wangmiao0668000666, @zhanglei99586.
  • #### Voice Calls
  • Google Meet and direct Voice Call sessions now keep the identity, workspace, routing, and transcript attribution of the agent that started the call instead of silently switching to the default agent. #77763 Thanks @quangtran88.
  • Google Live call history now keeps both sides of the conversation, while reconnects avoid submitting unfinished speech or combining unrelated utterances. #84161
  • OpenAI Realtime outbound calls now play one opening greeting even when the recipient speaks immediately after answering, while later interruptions continue to stop active speech. #86285 Thanks @giodl73-repo, @jnikolaidis.
  • Callers using realtime OpenAI or Google voice calls can now interrupt assistant speech and have buffered phone audio stop promptly, while other providers keep the existing local fallback. #90749 Thanks @moellenbeck.
  • Voice callers now hear a completed answer without waiting for post-turn compaction, and a successful early playback is no longer repeated. #94015 Thanks @xialonglee.
  • Twilio voice-call operators can select US1, IE1, or AU1 so call control and records use the intended Region, with US1 remaining the default. #95832 Thanks @jodok.
  • Inbound Telnyx-style and Plivo voice conversations can now continue after the caller's first response instead of falling silent before OpenClaw speaks again. #100255 Thanks @dvy.
  • Valid Twilio and Plivo callbacks now pass signature checks behind trusted IPv4 reverse proxies even when Node reports the proxy as an IPv4-mapped IPv6 address. #100261 Thanks @rohitjavvadi.
  • Repeated voice-call webhook deliveries are now acknowledged without repeating call or transcript side effects within the replay window. #100263 Thanks @xialonglee.
  • The Twilio voice-call provider now rejects unsupported API hostnames before sending a request and accepts only OpenClaw's supported Twilio regional hosts. 094c0d4 Thanks @vincentkoc.
  • An accepted voice message that arrives while OpenClaw is already replying can still receive a voice response when tts.auto: "inbound" is configured. #95596 Thanks @mcaxtr.
  • Realtime voice prompts now remain readable when long agent names or injected context containing emoji must be shortened. #101304 Thanks @alix-007.
  • Google Meet local audio bridges now shut down cleanly and log a warning when a capture or playback command pipe fails, rather than crashing on an unhandled stream error. #101596 Thanks @alix-007.
  • Voice Call history now stays with the correct configured agent across Gateway restarts and upgrades, while ambiguous legacy state is left untouched with actionable warnings. #89884 Thanks @mushuiyu886.
  • Completed Voice Call status remains available through the Gateway, tool, and CLI after restart or eviction instead of incorrectly appearing missing. #99797 Thanks @darren2030.
  • #### ClickClack
  • ClickClack agent replies to top-level messages now stay in the active channel or direct message, while replies inside real threads remain threaded. #100582 Thanks @marvinthebored, @vincentkoc.
  • ClickClack can now show opt-in, durable commentary and tool activity during a run so users are not left with an empty channel until the final reply. #99954 Thanks @obviyus, @ragesaq.
  • ClickClack now stops oversized REST success responses at the provider limit, giving users and operators a predictable failure instead of continued streaming and memory growth. #96970 Thanks @mushuiyu886, @vincentkoc.
  • #### Shared channel improvements
  • Messages that fail before reaching Discord, Slack, Matrix, or another channel can now be replayed after connectivity returns, while uncertain post-send outcomes still avoid blind duplicates. #101024 Thanks @sunnyshu0925.
  • Messages sent through OpenClaw's message tool now retain configured static or identity response prefixes, keeping routed and broadcast messages consistently labeled. #93639 Thanks @zengwen-dt.
  • Completions from subagents, scheduled tasks, media jobs, and agent harnesses now return through the same configured account, destination, and thread that requested them. #98240 Thanks @yetval.
  • Replies and attachments already accepted by a channel are no longer resent after a restart or recovery failure, while genuinely unsent items remain retryable. #99600 Thanks @zhangguiping-xydt.
  • Outbound sends now report failed and partially delivered messages with useful per-part outcomes instead of presenting every attempt as a success. #99928 Thanks @masatohoshino.
  • Non-streaming channels no longer send the same final text or media twice for one message, while genuinely separate replies with different routing or thread identities still go through. #100828 Thanks @vincentkoc, @zhangxiaojiujiayi.
  • Cron and outbound channel sends no longer report success without a usable platform receipt, making missing notifications show as not delivered or suppressed instead of falsely delivered. #79811 Thanks @indulgeback.
  • Queued messages now resume at a gentler pace after an outage, restart, or reconnect, reducing avoidable channel and provider rate-limit bursts while keeping recovery bounded. #101118 Thanks @zengwen-dt.
  • Noisy phone numbers with extra plus signs now match the intended Signal, iMessage, or WhatsApp contact, while identities with no digits are rejected safely. #100467 Thanks @morluto.
  • Reply directives containing hidden unsafe characters now produce stable, display-safe reply IDs before chat routing uses them. #96446 Thanks @lin-hongkuan.
  • Ambient agents now stay quieter in observed group conversations and honor operator instructions such as replying only when spoken to. #99144 Thanks @obviyus.
  • Ambient group chats now remain silent unless the agent deliberately sends a message, without stray status lines, tool summaries, compaction notices, delivery warnings, or overflow follow-ups. #99145 Thanks @obviyus.
  • Always-on group agents can now receive and answer valid unmentioned messages after a plugin fallback instead of silently dropping them. #99506 Related #99457. Thanks @lzy3538, @zqchris.
  • Agents catching up in busy group chats now receive clearer sender-by-sender history, making multi-person conversations easier to follow without exposing local paths or URLs. #100366 Thanks @gorkem2020.
  • Telegram and Discord plugin commands that send their own response can return { suppressReply: true }, preventing a second misleading empty-response warning or failure. #80928 Related #80756. Thanks @alexuser, @unclouded77.
  • With messages.ackReactionScope: "all", ambient room messages now receive the configured acknowledgement reaction across Discord, Slack, and Telegram. #87433 Thanks @paul-phan, @scoootscooob.
  • Channel plugins can resume automatic recovery after a long healthy run, so an occasional later disconnect is not blocked by an old restart budget while true rapid crash loops remain capped. #101413 Thanks @clintoncodewell.
  • Telegram and other channels can recover automatically after certain API outages and timed-out shutdowns instead of remaining silent until a Gateway restart. #94016 Thanks @sheyanmin.
  • A partially delivered queued send is no longer blindly replayed after reconnect, reducing duplicate Telegram and other channel messages. #96247 Thanks @obviyus, @rosenlo.
  • Discord and other progress views now hide repetitive internal Code Mode polling while continuing to show meaningful tool activity. #99893
  • Long-running Discord and Nextcloud Talk integrations now bound their channel metadata caches instead of letting each newly encountered room increase memory use forever. #101650 Thanks @alix-007, @vincentkoc.
  • A transient Gmail watch-renewal failure now produces an error without crashing a long-running foreground openclaw webhooks gmail run process. #100342 Thanks @cxbasdev, @vincentkoc.
  • Channel previews, thread names, snippets, and shortened errors across browser and messaging integrations now preserve whole emoji and other Unicode characters. c16bb87 Thanks @vincentkoc.
  • Long Slack context labels, Zalo messages and captions, and extension command output now truncate without breaking emoji or other non-BMP characters. 7e03242 Thanks @hugenshen, @mushuiyu886, @vincentkoc.
  • Fenced code blocks that contain example lines resembling Markdown fence markers are now kept together instead of being split mid-block and becoming confusing or misread. #96745 Thanks @ly-wang19, @vincentkoc.
  • Long unbroken messages now keep emoji intact when split into delivery-sized chunks, preventing garbled replacement characters for users and channel plugins. #96951 Thanks @bartok9, @ly-wang19.
  • Skill command descriptions now remain fuller where supported and stay valid in Discord and Mattermost when emoji appears near a platform limit. #99593 Thanks @pick-cat.
  • Long emoji-containing agent labels now produce clean native channel thread names and introductions instead of broken characters. #101527 Thanks @lsr911.
  • Chinese, Japanese, and Korean bold labels followed immediately by text now render as bold instead of exposing literal ** markers in Telegram and other shared-Markdown channels. #101230 Thanks @nicknmorty.
  • Attachment download failures across WhatsApp, LINE, Signal, iMessage, Teams, Feishu, Mattermost, and Zalo now remain visible and actionable instead of disappearing or masquerading as successful media. #100119
  • OpenClaw now recognizes .m2a recordings as audio, allowing them to move through attachment, transcription, memory, and chat display workflows without conversion. #92167 Thanks @llljjjwww333.
  • Files sent through Telegram and other supported chat channels now keep clean names such as report.png instead of exposing an internal cache identifier in the attachment filename. #96565 Thanks @narahariraghava, @obviyus.
  • Cron summaries, Teams and Slack replies, and other embedded assistant responses no longer expose provider reasoning markers such as </mm:think>. #101036 Thanks @velanir-ai-manager.
  • Punctuation around a model's NO_REPLY token no longer turns it into a visible chat message, while legitimate messages containing the token still arrive. #98224 Thanks @sunnyshu0925.
  • Slack, Discord, Telegram, WhatsApp, and Microsoft Teams users now receive a clear retry and re-authentication message when a model provider returns a recognized HTTP 401 error instead of seeing only a reaction or no useful reply. #96599 Thanks @sjf-oa.
  • Text commands such as /model fable now reliably display their confirmation even in flows that suppress ordinary source replies. #100151
  • The bare /think command now shows available thinking levels promptly in Telegram, Slack, and Discord without waiting on slow model discovery. #101926 Thanks @vincentkoc.
  • Direct mentions to Telegram and Discord group bots using message_tool_only now produce visible channel replies on both new and resumed sessions. #99389 Related #99371. Thanks @obviyus.
  • The /usage full footer is shorter and easier to read on Telegram and other narrow displays, with detailed token information still available through dedicated views. #92877 Thanks @marvinthebored.
  • Custom usage footers now render alias and map fallbacks correctly even when model or mode names collide with properties such as toString or constructor. #98503 Related #98466. Thanks @chenyangjun-xy, @zhanglei99586.
  • Transient stdout or stderr read errors from gog gmail watch serve no longer crash OpenClaw while Gmail watch mode is running. #100519 Thanks @cxbasdev.
Providers and Models
  • Across Anthropic and Claude, Gemini, OpenAI and Codex, local models, and other supported routes, providers now handle credentials, catalogs, limits, fallbacks, streaming, and tool calls more consistently. Readers should see fewer requests fail because the selected route used the wrong model metadata, replayed incompatible reasoning, lost authentication state, or interpreted a provider response incorrectly.
  • The model catalog also reports availability and capability more accurately, while Codex supervision keeps connected model choices and session behavior aligned with the backend that was actually selected.
  • #### Provider setup and model selection
  • ##### New providers and integrations
  • OpenCode Zen users can browse and run its supported Claude, GPT, Gemini, GLM, DeepSeek, MiniMax, Qwen, and other models without manually defining each route. #92495 Thanks @mushuiyu886, @sallyom.
  • Library and integration developers can now install a version-matched package, create independent AI runtimes, and reuse OpenClaw's supported model transports without embedding the full application. #99059
  • Featherless AI now has an official provider install and onboarding path, including FEATHERLESS_API_KEY, a curated featherless/Qwen/Qwen3-32B default, and support for exact Featherless model IDs. #101092 Thanks @vincentkoc.
  • Meta Model API is now exposed through the public meta provider, with meta/muse-spark-1.1, canonical provider docs, and standalone npm or ClawHub installation paths. #103070 Thanks @vincentkoc.
  • The bundled Meta provider now uses https://api.meta.ai/v1, advertises Muse Spark 1.1's documented 131,072-token output limit, and applies official-host request protections. #103680 Thanks @vincentkoc.
  • ##### Anthropic, Google, and OpenAI setup
  • Claude Fable 5 now works through Anthropic Vertex for simple-completion tasks such as generated conversation labels instead of failing before the request reaches Vertex. #98932
  • Claude CLI users can combine multiple --mcp-config files without losing servers or corrupting the prompt, and concurrent Gemini CLI runs are less likely to interfere with shared credential files. #98983 Related #98944, #98945. Thanks @obviyus.
  • Google image generation can now use models.providers.google.apiKey and an optional custom baseUrl without separate environment credentials or an auth profile. #100779 Thanks @amknight.
  • OpenAI image generation can now be enabled from models.providers.openai with a usable API key and custom base URL, without also requiring OPENAI_API_KEY or an auth profile. #100745 Thanks @amknight.
  • Configurations using the retired openai-codex-responses API ID now receive a validation message naming the supported replacement instead of a generic failure. #96257 Thanks @james-16, @yetval.
  • Legacy openai-codex references now direct operators to openclaw doctor --fix and openclaw models status instead of suggesting configuration that fails validation. #100120 Thanks @jason-vaughan, @sunnyshu0925, @vincentkoc.
  • ##### Local and self-hosted models
  • Ollama model discovery now stops oversized or never-ending endpoint responses before they can exhaust memory or leave setup hanging. #96027 Thanks @alix-007.
  • LM Studio model discovery and startup now stop pathological server responses at a fixed size and report a clear error instead of buffering them indefinitely. #96042 Thanks @alix-007.
  • openclaw models list now reports configured local Ollama models as available when they are running and usable. #97491 Thanks @lingfeizi, @qingminglong.
  • Custom Xiaomi MiMo and other OpenAI-compatible models without a known output limit can now complete chats instead of failing with an invented oversized cap. #98312 Thanks @peole, @sanjays2402.
  • ##### Shared provider configuration
  • Provider setup now stops reading runaway model-discovery responses before they can stall or exhaust memory, while normal self-hosted server responses continue to work. #95244 Thanks @alix-007, @sallyom.
  • Rerunning provider onboarding or refreshing models now preserves operator-owned timeouts, transport settings, MiniMax models, and SecretRef credentials instead of silently erasing them. #100107 Thanks @frank-beans.
  • With models.mode set to replace, agent startup now uses only explicitly configured providers and skips the slow implicit provider scan. #82638 Related #66957. Thanks @eldar702, @wangzhengshu.
  • Bundled provider aliases now accept supported overlay settings such as request timeouts without demanding custom-provider fields like baseUrl and models. #88400 Thanks @pluviobyte.
  • Isolated cron jobs can now use models supplied by enabled bundled plugins without failing as unknown or silently resolving to the wrong provider. #96070 Thanks @sallyom, @sunnyshu0925.
  • Z.AI endpoint and model detection now fails gracefully on oversized or endless error responses instead of exhausting host memory. #97540 Thanks @alix-007.
  • Microsoft Foundry connection tests now stop oversized or continuously streamed error responses while preserving concise setup diagnostics. #97812 Thanks @pick-cat.
  • Generic provider configurations for official DashScope/Qwen, Moonshot, Z.AI, DeepSeek, Groq, Cerebras, and Chutes endpoints now retain the compatibility behavior those services require even without optional plugins. #100125
  • Provider onboarding no longer writes an empty request block when no request overrides were supplied. 3a0a736 Thanks @vincentkoc.
  • ##### Model catalogs and selection
  • Switching a live Control UI or TUI session through a provider-qualified model alias now saves the canonical provider and model, preventing the next request from being rejected. #100209 Thanks @sahilsatralkar.
  • Bedrock Mantle model discovery now times out and caps oversized catalog responses instead of hanging or consuming excessive memory, while cached models remain available. #99961 Thanks @zhangguiping-xydt.
  • OpenRouter video model discovery now stops oversized or runaway catalog responses promptly instead of letting them consume memory without limit, while normal discovery behavior is preserved. #96505 Thanks @mushuiyu886.
  • Model aliases and partial names such as opus now resolve to the newest matching version even when catalogs reach double-digit versions, preventing silent routing to an older model. #96609 Thanks @yetval, @zw-xysk.
  • Paginated provider catalogs now expose models beyond the first page, while malformed, endless, or redirected catalogs fail safely instead of caching an incomplete list or forwarding sensitive headers across origins. #97012 Thanks @zhangguiping-xydt.
  • Hugging Face model discovery now falls back to the bundled catalog when a provider response is malformed or oversized instead of risking excessive memory use. #101079 Thanks @cxbasdev.
  • Trusted official external providers can now show model-specific thinking choices before full runtime activation, including off, low, high, and max for Z.AI GLM 5.2. b4fce16 Thanks @vincentkoc.
  • Status summaries now respect provider-local model aliases, showing the selected alias without a false pinned-model mismatch warning. 1d4e789
  • OpenRouter scans now interpret model names such as 8b-70b by their larger parameter size, improving minimum-size filters and small-model security warnings. #96288 Thanks @ly-wang19.
  • Media-generation catalogs now keep the correct default model marker even when provider metadata includes harmless surrounding whitespace. #96430 Thanks @lin-hongkuan.
  • Very long OpenRouter Fusion model IDs now remain valid Unicode in the agent prompt instead of showing a corrupted character when an emoji reaches the display limit. #104433 Thanks @zhangguiping-xydt.
  • #### Sign-in and credentials
  • ##### Anthropic and Claude
  • Anthropic OAuth token exchange and refresh now reject oversized endpoint responses early instead of reading an unbounded body into memory. #96644 Thanks @solodmd.
  • Anthropic sign-in now rejects unsupported callback-host overrides, keeps authorization on standard local loopback addresses, and avoids callback failures or exposure through a non-local listener. #96917 Thanks @xialonglee.
  • Expired Claude CLI authentication now shows the exact recovery command claude auth login && openclaw models auth login --provider anthropic --method cli instead of a generic failure. #97669 Thanks @alix-007.
  • Anthropic OAuth subscription requests now carry the Claude Code-style billing identity, helping them use the intended subscription route instead of failing or being treated as the wrong request type. 709be93 Thanks @vincentkoc.
  • ##### OpenAI, ChatGPT, and Codex
  • ChatGPT OAuth sign-in and refresh now reject unexpectedly large token responses cleanly instead of risking Gateway memory exhaustion. #99479 Thanks @pandah97.
  • Cloudflare 403 challenges on OpenAI or Codex OAuth requests now produce gateway-block guidance instead of incorrectly telling users their authentication failed. #94440 Related #94432. Thanks @lzyyzznl, @pbm9z95m6z-hue.
  • OpenAI authentication errors now point ChatGPT/Codex OAuth users to a model compatible with their existing sign-in instead of recommending an outdated default. #100579 Thanks @zhangguiping-xydt.
  • For Codex-backed OpenAI models, /status now identifies ChatGPT login authentication as oauth (codex-cli) instead of incorrectly labeling it as an environment API key. #91240 Related #91099. Thanks @849261680, @ukstem.
  • OpenAI Realtime voice in Talk, Voice Call, and Discord was announced with a Codex/OpenAI OAuth fallback in #100671. Correction: public Codex OAuth accounts do not have a supported realtime transport, so current builds require an OpenAI Platform API key. Thanks @steipete-oai.
  • ##### Google and Gemini
  • Google Gemini CLI sign-in now rejects oversized OAuth, profile, project, and onboarding responses with labeled errors instead of risking excessive memory use. #97587 Thanks @hugenshen.
  • Google Gemini CLI OAuth failures now keep oversized or malformed provider responses bounded while preserving useful error details. #99605 Thanks @mushuiyu886.
  • Google OAuth sign-in, token exchange, and project discovery now return a bounded error for oversized responses instead of risking a process crash. #97628 Thanks @vincentkoc, @wangmiao0668000666.
  • ##### GitHub Copilot
  • GitHub Copilot sign-in, refresh, and model-list checks now fail with labeled size limits when GitHub or a proxy returns an oversized response. #97499 Thanks @wangmiao0668000666.
  • GitHub Copilot sign-in and token refresh now reject oversized service responses with a clear error before they can exhaust OpenClaw's memory. #97579 Thanks @hugenshen.
  • GitHub Copilot device login now fails cleanly on an oversized successful response instead of risking an out-of-memory crash. #97583 Thanks @hugenshen.
  • OpenAI-compatible providers routed through the GitHub Copilot BYOK harness now retain bearer authentication, reducing false 401 errors for valid credentials. #99955 Thanks @hxy91819.
  • ##### xAI and Grok
  • xAI and Grok OAuth sign-in now works on SSH hosts, containers, VPS systems, and other headless environments without forwarding a localhost callback port. #97249 Thanks @fuller-stack-dev, @jaaneek.
  • xAI sign-in, token refresh, and device approval now stop oversized OAuth responses before they can consume unbounded memory. #97615 Thanks @cxbasdev.
  • Existing xAI and Grok OAuth sessions using the retired token endpoint can renew after expiry without forcing another browser or SSH-tunneled login. #96146 Thanks @fuller-stack-dev, @jaaneek.
  • ##### Ollama, MiniMax, Chutes, Z.AI, OpenRouter, and ClawRouter
  • Ollama Cloud setup now stops oversized or malicious authentication responses before they can consume excessive memory, while normal sign-in remains unchanged. #97581 Thanks @hugenshen.
  • MiniMax OAuth device setup now limits authorization response size so a faulty proxied or self-hosted endpoint cannot exhaust Gateway memory. #96322 Thanks @lsr911.
  • Chutes login, user lookup, and token refresh now stop unexpectedly large OAuth responses with a bounded error instead of buffering them without limit. #96777 Thanks @wangmiao0668000666.
  • Chutes onboarding now fails clearly when token-exchange or user-info responses are oversized, preventing abnormal authentication traffic from causing unbounded memory growth. #96779 Thanks @wangmiao0668000666.
  • Z.AI users can recover a profile that accidentally stored an onboarding command as the API key without wiping all authentication state. #97520 Thanks @zhangguiping-xydt.
  • Chutes sign-in and token refresh errors now include a useful bounded snippet without allowing an endpoint to stream an unlimited response into memory. #97808 Thanks @pick-cat.
  • OpenRouter sign-in now fails safely on oversized replies, and Discord webhook sends remain successful when their optional response body is absent, malformed, or too large. #98098 Thanks @lwy-2.
  • OpenRouter model probes and agent requests now use discovered environment or profile API keys correctly instead of failing with a missing-authentication-header error. #98187 Related #97934. Thanks @laurencebrown, @sunlit-deng.
  • ClawRouter models selected in agent defaults now resolve at runtime when the credential is stored in an auth profile instead of the environment. #99759
  • ##### Amazon Bedrock
  • Amazon Bedrock users can now analyze images and PDFs with the same AWS profile, role, SSO, environment, or instance credentials already used for chat. #72092 Thanks @truffle-dev.
  • ##### Shared sign-in and credential behavior
  • OpenAI/Codex and Anthropic OAuth result pages now show OpenClaw branding instead of the legacy Pi logo. 1834592
  • Agents created by copying credentials now preserve the source agent's portable provider-profile priority instead of unexpectedly choosing a different credential. #100833 Thanks @machine3at.
  • New or updated provider credentials entered through the CLI now appear in the running Gateway and Control UI model picker without a manual secrets reload or restart. #101256 Thanks @fuller-stack-dev.
  • OAuth-backed models now become available in Gateway model browsing after credentials are renewed from another CLI process, without requiring a Gateway restart. #104732 Thanks @fuller-stack-dev.
  • #### Fallbacks and model switching
  • ##### Anthropic and Claude
  • Anthropic conversations rejected for a missing tool result now tell users to retry or start a fresh session with /new instead of showing only a generic provider failure. #98163 Thanks @masatohoshino.
  • Claude native-thinking sessions can now recover automatically after Anthropic rejects a replayed thinking block, without manual compaction or transcript loss. #98411 Related #98308. Thanks @clearhorizoninvestments, @sunlit-deng.
  • Claude CLI agent runs now fail over instead of presenting provider errors or raw stream data as answers, preserve multilingual and emoji output, and stop runaway one-shot output before it exhausts Gateway memory. #98942 Related #98896. Thanks @obviyus.
  • Eligible direct API-key requests to Claude Fable 5 now return an Opus 4.8 answer when Anthropic's safety classifier declines Fable, with diagnostics and Opus billing made clear. #99906
  • ##### Google and Gemini
  • Gemini streaming can retry with another configured API key after a retryable quota or rate-limit response instead of failing on the first key. #97328 Thanks @monkeyleet.
  • ##### Ollama, OpenAI-compatible providers, and Z.AI
  • Ollama requests whose native response stream ends early can now continue to a configured fallback model instead of stopping with LLM request failed. #100482 Thanks @turbotheturtle.
  • A detail-less failure from an OpenAI-compatible provider no longer puts a valid API-key profile into cooldown or forces avoidable fallback traffic. #100617 Thanks @fengjikui.
  • Z.AI and similar HTTP 429 responses now distinguish temporary service overload from ordinary rate limiting and preserve provider-supplied retry timing. #98165 Thanks @sunnyshu0925.
  • Continued conversations with strict custom OpenAI Responses-compatible endpoints no longer fail on an unsupported input[n].status field and needlessly switch to a fallback model. #100831 Thanks @chenxiaoyu209.
  • ##### Shared fallback and model-selection behavior
  • Replay-safe model timeouts can now advance to the next configured provider, letting agent, chat, and cron runs recover without repeating work that may have side effects. #96142 Thanks @brokemac79, @riazrahaman.
  • Agent runs can move to the next configured model after a provider drops a stream, while genuine cancellations still stop promptly. #90908 Thanks @shengting.
  • Embedded-agent runs can now try the next configured fallback model after a temporary upstream LLM request failed error. #95542 Thanks @altaywtf, @mikasa0818.
  • Configured fallback chains now try an alternate model when the primary provider reports model_not_found, reducing failures after model availability changes. #97571 Thanks @liuhao1024.
  • When a configured runtime model is no longer available, chat now explains that a new session will not help and directs operators to choose an available model. #97611 Thanks @romneyda.
  • Provider failures now keep fallback error text within the configured size limit, preventing oversized responses from overwhelming logs or visible diagnostics. #99340 Thanks @pick-cat.
  • /model default now actually returns an active session to its configured model after steering, fallback, or a previous manual selection. #96318 Thanks @marsman-lab, @sunnyshu0925.
  • Gateway chat now classifies mixed provider messages as rate limits when throttling is the real failure, giving users recovery guidance that matches the problem. #100755 Thanks @pick-cat.
  • openclaw status and session_status now identify when a session is using a fallback model and show the configured primary model beside it. #101337 Thanks @lzy3538.
  • #### Replies, reasoning, and tool calls
  • ##### Anthropic and Claude
  • Claude CLI replies that streamed successfully are now retained when the final success envelope contains no text, preventing the completed answer from disappearing or triggering an empty-response fallback. #90450 Thanks @totobusnello.
  • Claude Code 2.1 users can again approve and run Bash, WebFetch, Grep, Glob, AskUserQuestion, and other native tools in claude-cli sessions. #98665 Related #95171. Thanks @carterdawson, @yetval.
  • Claude CLI-backed agents now show native reasoning in /reasoning stream or /reasoning on, while /reasoning off consistently suppresses it for queued follow-ups too. #99401 Thanks @marvinthebored.
  • Anthropic Opus 4.8 can now run with tools.profile=coding without every turn failing with an HTTP 400 schema error before the assistant replies. #100492 Thanks @lin-hongkuan, @vincentkoc.
  • Anthropic Messages-compatible proxy users no longer see raw antml tool-call XML or arguments leak into visible Claude replies. b2787a1 Thanks @jerry-xin.
  • Anthropic agents routed through AWS Bedrock can keep Feishu Bitable write tools enabled without the tool definitions blocking every conversation. #94990 Thanks @twinslee, @vincentkoc.
  • Claude Fable 5 now uses the expected Anthropic context1m stream setup when 1M context is enabled, without affecting similar model IDs. #100572 Thanks @zhangguiping-xydt.
  • Claude conversations through GitHub Copilot can continue after a tool failure with no visible output instead of entering repeated provider-schema failures. #101373 Thanks @galiniliev.
  • Anthropic-compatible calls with token caps too small for manual thinking now run normally without thinking instead of failing provider validation. #101415 Thanks @pick-cat.
  • ##### OpenAI-compatible and local models
  • Ollama Cloud and other OpenAI-compatible Ollama chats can now continue after a tool call instead of failing the next turn with a provider 400 error. #96474 Thanks @849261680.
  • vLLM, Ollama proxies, and other OpenAI-compatible gateways can deliver streamed replies even when they incorrectly label an event stream as JSON, avoiding an early parsing failure that previously ended the agent run. #96503 Thanks @zengwen-dt.
  • GPT-5.5 and other models can send valid streaming events larger than 64 KiB through ChatGPT Responses without failing the request, while malformed unbounded streams remain limited. #98198 Thanks @marvinthebored, @obviyus, @peetiegonzalez.
  • openclaw agent --local now reports a clear first-event timeout when a provider opens a stream but never sends usable output instead of appearing to hang indefinitely. #98525 Thanks @osolmaz.
  • MCP tools that expect arrays or objects can now accept those values when Xiaomi MiMo, Ollama, or another affected provider returns them as JSON strings, avoiding a pre-execution validation failure. #96922 Thanks @liuhao1024.
  • Repaired plain-text tool calls from LM Studio, xAI, and Ollama now emit a final completion event so plugins and other streaming consumers can finish them reliably. #104714
  • ##### Google and Gemini
  • Google Live voice sessions can now register and call OpenClaw tools instead of rejecting their declarations before a tool-backed turn begins. #100260
  • ##### MiniMax, OpenRouter, Mistral, and opencode-go
  • MiniMax M3 replies, including those routed through Fireworks, no longer expose hidden mm: reasoning in visible chat or progress output. #93767 Thanks @drhack1, @vincentkoc.
  • Long opencode-go model runs are less likely to be falsely stopped as stalled while valid provider events are still arriving. #97128 Thanks @liuwqgit, @vincentkoc, @yetval.
  • OpenRouter's DeepSeek V4 Flash and Pro models can answer with thinking enabled without failing with an HTTP 400. #97208 Related #97196. Thanks @nianjiuzst, @patelmm79.
  • Direct mistral-medium-3-5 requests now send the user-selected adjustable reasoning level to Mistral as reasoningEffort. #100688 Thanks @aniruddhaadak80, @wm0018.
  • ##### Shared reasoning and tool behavior
  • Realtime voice sessions now omit an individual custom tool with an invalid provider-specific name and warn about it instead of letting that tool break the entire OpenAI, Azure, or Google session. #89175 Thanks @vincentkoc.
  • Switching from thinking-off mode to a reasoning-required model now selects its lowest supported effort rather than silently choosing the most expensive level. #93335 Thanks @obuchowski.
  • #### Voice, transcription, images, and video
  • ##### OpenAI and Azure voice and images
  • OpenAI Realtime voice and transcription sessions now start behind Clash, Surge, sing-box, and similar TUN proxy setups that resolve api.openai.com into fake-IP ranges. #86526 Thanks @shushushv.
  • OpenAI and Azure realtime voice connections now close inbound messages above 16 MiB, limiting avoidable gateway memory pressure. #99450 Thanks @sunlit-deng.
  • OpenAI realtime voice sessions now default to gpt-realtime-2.1 when no model is specified, while explicit model pins continue to work. #101390 Thanks @vincentkoc.
  • OpenAI image generation and reference-image editing no longer crash when credentials or a custom base URL are ready before the provider model catalog finishes loading. #105518 Thanks @vincentkoc.
  • OpenAI video generation now stops oversized or endless submission responses with a bounded provider error before they can hang the request or exhaust memory. #96905 Thanks @alix-007.
  • ##### Google and Gemini media
  • Gemini CLI media analysis now returns its description even when the valid response also contains nested usage or other metadata. #96432 Thanks @lin-hongkuan.
  • Google Veo video generation now ends oversized create or status responses early with a clear bounded error, preventing a broken endpoint from hanging OpenClaw or consuming memory indefinitely. #96605 Thanks @alix-007.
  • ##### MiniMax, xAI, and Fal-hosted media
  • Reference-image edits through Fal-hosted Grok Imagine and Nano Banana 2 Lite now reach the correct service, while mixed-model fallbacks honor each candidate's supported resolution and reference limits. #98688 Thanks @davenicoll, @vincentkoc.
  • MiniMax TTS now accurately explains that volume must be greater than 0 and may be as high as 10 when a directive is invalid. #101359 Thanks @quratulain-bilal.
  • MiniMax VLM and native PDF provider errors now remain readable when emoji or other supplementary characters land at the diagnostic snippet limit. #101728 Thanks @wings1029.
  • MiniMax video generation now rejects oversized task, status, or file-metadata responses before unbounded memory use or binary download begins, while normal responses continue to work. #96889 Thanks @alix-007.
  • xAI video generation now stops oversized create or status responses with a clear size-limit error instead of buffering until OpenClaw hangs or consumes excessive memory. #96903 Thanks @alix-007, @vincentkoc.
  • MiniMax image understanding now stops oversized or malformed successful responses at a bounded limit, protecting memory while returning a useful diagnostic. #100694 Thanks @zhangguiping-xydt.
  • ##### Video providers and generation services
  • Moonshot video understanding now returns a predictable error for oversized or malformed responses instead of hanging or consuming memory indefinitely, including with custom base URLs. #96502 Thanks @hugenshen.
  • Qwen video understanding now stops oversized or malformed endpoint responses with a clear error instead of hanging or reading without limit, while normal descriptions continue unchanged. #96604 Thanks @alix-007.
  • BytePlus video generation now stops oversized task-submission or status responses with a clear error before they can stall OpenClaw or exhaust memory, while normal responses continue unchanged. #96606 Thanks @alix-007.
  • DashScope-compatible video submission and polling now reject oversized JSON responses with a bounded error instead of risking memory pressure or process instability, while ordinary responses continue normally. #96782 Thanks @wangmiao0668000666.
  • OpenRouter video generation now rejects oversized submit and polling responses before they can hang OpenClaw or consume runaway memory, while normal-sized malformed responses retain their established error handling. #96873 Thanks @alix-007.
  • Vydra image, video, and speech generation now fails with a bounded error on oversized or endless control responses instead of hanging or exhausting memory, while valid responses continue normally. #96875 Thanks @alix-007.
  • fal music and video generation now stops oversized successful responses with a clear size-limit error before they can hang or exhaust memory, while normal generation continues as before. #96886 Thanks @alix-007.
  • Together and PixVerse video generation now returns a provider-labelled size error for oversized successful responses instead of continuing until severe memory pressure or process failure. #96904 Thanks @alix-007.
  • Runway video generation now stops oversized create and status responses instead of continuing to consume memory or stall, while normal polling and provider-specific errors remain intact. #96907 Thanks @alix-007.
  • Comfy image-generation workflows now stop oversized ComfyUI responses with the actual size-limit error instead of risking memory exhaustion or misreporting the response as malformed JSON. #96927 Thanks @wangmiao0668000666.
  • DeepInfra video generation now rejects oversized successful responses with a bounded error instead of risking an out-of-memory crash. #97486 Thanks @hugenshen.
  • ##### Voice and transcription across providers
  • Configured Voice Call transcription providers such as xAI remain selectable when another provider registry is active, allowing Talk sessions to start normally. #97170 Thanks @solavrc.
  • Missing official media providers now produce errors with the exact recovery commands needed to restore transcription and other media workflows. #97484 Thanks @wangmiao0668000666.
  • A malformed Inworld voices response now produces a clear provider-specific error instead of an unhelpful parsing exception or process crash. #98660 Thanks @solodmd.
  • Short non-English audio now keeps the configured language hint without an unrelated English prompt, reducing accidental translation when users expect a transcript in the spoken language. #99023 Thanks @flyveryhigh, @nianjiuzst.
  • ##### Shared media selection and response safety
  • Image and video tools can now automatically select configured provider-plugin models authenticated through environment variables. #98623 Thanks @medns.
  • Automatically configured video understanding now uses provider defaults such as Moonshot's intended video model unless the user selected a model explicitly. #99791 Thanks @vincentkoc, @zhangguiping-xydt.
  • Image generation now stops with a clear size-limit error when a provider or custom endpoint sends an oversized or endless response, preventing hangs and runaway memory use while valid images and edits continue normally. #96495 Thanks @hugenshen, @sallyom.
  • #### Speech, search, embeddings, and documents
  • ##### Speech and transcription
  • Google Gemini TTS now rejects oversized responses before buffering them into memory, while normal speech results continue through the existing audio workflow. #96984 Thanks @mushuiyu886.
  • Inworld text-to-speech and voice-list requests now fail safely on oversized, malformed, or never-ending responses instead of hanging or consuming unbounded Gateway memory. #95416 Thanks @alix-007, @vincentkoc.
  • Azure Speech, Microsoft Speech, ElevenLabs, MiniMax TTS, OpenRouter transcription, and xAI transcription now stop oversized or endless responses before they can stall speech work or strain Gateway memory, while ordinary responses remain unchanged. #96496 Thanks @hugenshen.
  • Volcengine, BytePlus Seed Speech, and Xiaomi TTS now stop oversized provider responses before one speech request can stall or destabilize OpenClaw. #96874 Thanks @alix-007.
  • Google audio and video understanding now stops oversized provider responses at the shared 16 MiB limit with a clear error instead of allowing them to consume excessive memory. #96920 Thanks @mushuiyu886, @vincentkoc.
  • ##### Embeddings and memory search
  • Gemini memory-embedding batch uploads, creation, and status checks now fail safely when a compatible endpoint returns an oversized control response. #97535 Thanks @hugenshen.
  • OpenAI-compatible embedding requests now close oversized responses early with a clear provider error instead of buffering until OpenClaw stalls or runs out of memory, while normal embeddings continue working. #96868 Thanks @alix-007.
  • OpenAI embedding batch polling and Realtime setup now cancel oversized successful responses early and return a bounded error instead of growing memory without limit. #97533 Thanks @hugenshen.
  • OpenAI-compatible embedding batch downloads now process valid large outputs while stopping oversized files or JSONL records before they can exhaust memory. #98554 Thanks @sunlit-deng, @vincentkoc.
  • GitHub Copilot model discovery and memory search now reject oversized or malformed responses instead of buffering them without limit, while valid catalog and embedding results continue normally. #96499 Thanks @hugenshen, @sallyom.
  • Voyage embedding batch jobs now stop oversized status, failure, and error-file responses before they can hang or exhaust worker memory, while oversized diagnostics degrade safely and ordinary responses remain unchanged. #96608 Thanks @alix-007.
  • LM Studio embedding preload now respects the configured context limit, reducing GPU out-of-memory failures during memory search on constrained hardware. #100750 Thanks @hxz398, @zak-li, @zoowh.
  • Malformed Voyage embedding batches now close their download connections after parsing fails, reducing resource buildup during repeated or large workloads. #98840 Thanks @solodmd.
  • ##### Search and document processing
  • Google Meet document processing now rejects oversized Google Drive exports before they can destabilize OpenClaw, while ordinary documents still export as text. #97620 Thanks @alix-007, @vincentkoc.
  • Parallel web search now returns a bounded error when an upstream response is malformed, oversized, or never-ending instead of risking a hang or out-of-memory crash. #96035 Thanks @alix-007.
  • Exa searches now reject responses above the supported limit, preventing excessive provider output from hanging OpenClaw or creating memory pressure. #96038 Thanks @alix-007.
  • #### Provider response safety and clearer errors
  • ##### Anthropic and OpenAI-compatible streams
  • Anthropic-compatible requests now fail promptly with a bounded transport error when an upstream stream sends an oversized partial event instead of hanging and consuming memory. #100686 Thanks @zhangguiping-xydt.
  • OpenAI ChatGPT Responses streaming now cancels oversized or endless provider bodies with a clear error before they can consume excessive process memory, while normal responses keep using the existing parser. #96762 Thanks @vincentkoc, @wangmiao0668000666.
  • OpenAI-compatible provider and proxy streams now stop oversized malformed or never-ending bodies at the affected request instead of letting them destabilize or crash the OpenClaw process. #96989 Thanks @vincentkoc, @wangmiao0668000666.
  • OpenAI-compatible Chat Completions now use OpenClaw's guarded network path, adding the same response safety controls used by other protected model calls. #97228 Thanks @vincentkoc, @wangmiao0668000666.
  • Azure OpenAI Responses now bound oversized streaming and error bodies, protecting memory while preserving normal errors and cancellation. #97349 Thanks @wangmiao0668000666.
  • Anthropic-compatible model requests now consistently use OpenClaw's guarded transport, response normalization, and managed stream cleanup rather than bypassing them through the SDK. #101357 Thanks @wangmiao0668000666.
  • When an OpenAI or OpenAI-compatible chat-completions model refuses a request, users now see the provider's explanation instead of a blank assistant reply. #102344 Thanks @wuqxuan, @yetval.
  • ##### Proxies and other provider endpoints
  • Proxy-backed model streams now fail with bounded, clearer errors when responses are oversized, malformed, incomplete, or idle instead of hanging or consuming unbounded data. #97235 Thanks @vincentkoc, @zhangguiping-xydt.
  • Mistral-compatible endpoints now stop oversized streaming responses with a labeled error before OpenClaw can run out of memory. #97648 Thanks @wangmiao0668000666.
  • Abnormally large Google Meet, Calendar, or OAuth responses now stop with an error before they can consume uncontrolled Gateway memory. #98850 Thanks @pandah97.
  • ##### Shared provider diagnostics
  • Request-format and schema failures now show the relevant diagnostic without sending users through unnecessary provider login or reconfiguration steps. #95779 Thanks @pick-cat.
  • #### Codex app-server and supervised sessions
  • ##### Runtime and model compatibility
  • Codex users can route both codex/* and openai/* models through the bundled runtime, and older conversations resume without unnecessary context reprojection. #105034
  • The bundled Codex plugin can complete backend requests again after updating its managed app-server runtime, with no model-picker or configuration migration required. #106098
  • OpenClaw's managed Codex workflow now uses app-server 0.143.0, and self-managed installations must use 0.143.0 or newer for protocol compatibility. 366258d Thanks @vincentkoc.
  • The managed Codex harness now surfaces supported GPT-5.6 Sol, Terra, and Luna models returned by the account catalog and gives self-managed users current version guidance. f80ce21 Thanks @vincentkoc.
  • Managed Codex users on macOS, Linux, and Windows now receive app-server 0.144.1 instead of 0.144.0. 5dcba9f Thanks @vincentkoc.
  • Codex-native delegation from OpenClaw threads now creates native task records again, while unsupported custom Codex app-server versions fail startup with a clear minimum-version error. #101221
  • Codex sessions using gpt-5.5-pro or gpt-5.4-pro now clamp unsupported reasoning levels before the first turn, avoiding an immediate request rejection when live metadata is unavailable. #101484 Thanks @zhangguiping-xydt.
  • ##### Session reliability and diagnostics
  • Scheduled and CLI Codex runs with an explicit timeout longer than 30 minutes can now use that full budget instead of being stopped by the terminal-idle guard. #85296 Thanks @alkor2000, @vincentkoc.
  • A missing or hung local Codex tool result no longer switches the active session to another provider that cannot resolve the local failure. #95543 Thanks @mikasa0818.
  • Codex app-server runs with an invalid ChatGPT OAuth session now surface the real sign-in error promptly instead of waiting for a misleading ten-second authentication timeout. #100713 Thanks @lin-hongkuan.
  • Codex runs stopped by the guardian rejection limit now say why they ended, so operators do not have to mistake the result for a crash, cancellation, or generic interruption. #101220 Thanks @darren2030.
  • Crestodian setup and repair chats on Codex-backed runs can now access the status and repair tool they need instead of stopping with a missing-tool response. #101281
  • Shared Codex app-server clients now keep usage limits, auth cooldowns, thread subscriptions, and resumed connections tied to the account and conversation that actually owns them. #101376
  • Codex app-server stdout failures now end affected requests cleanly, while a diagnostics-only stderr failure no longer interrupts an otherwise healthy turn. #101505 Thanks @mushuiyu886, @vincentkoc.
  • #### Usage, context, cost, and diagnostics
  • ##### Usage and quota reporting
  • Anthropic usage checks now cap unusually large error responses so a CDN, firewall, or proxy page cannot exhaust OpenClaw's memory. #97614 Thanks @cxbasdev.
  • OpenAI and Codex users authenticated through the app server can again see their five-hour and weekly quota windows in chat, CLI, and JSON status output. #92520 Thanks @brokemac79.
  • OpenAI OAuth usage checks now cap oversized WHAM rate-limit responses before they can destabilize the process. #97702 Thanks @cxbasdev.
  • GitHub Copilot usage checks now contain oversized or endless endpoint responses as a usage error instead of buffering them indefinitely, while normal usage data still loads. #96607 Thanks @alix-007.
  • OpenRouter cost tracking now caps unexpectedly large metadata responses and keeps the original streamed estimate instead of disrupting the agent turn. #97490 Thanks @hugenshen.
  • MiniMax and other shared provider usage checks now fail safely on oversized or malformed replies instead of buffering them without limit. #97659 Thanks @cxbasdev, @vincentkoc.
  • OpenRouter completions that the provider bills at $0 now stay recorded as free in transcripts, summaries, logs, and usage totals instead of being replaced with estimated catalog pricing. #101177
  • ##### Context limits and prompt efficiency
  • Amazon Bedrock adaptive-thinking Claude and Fable runs now honor configured high output-token limits for longer answers, reasoning, and tool calls. #97343 Thanks @lilan0125, @prasithg.
  • Long, tool-heavy or media-heavy embedded-agent conversations now retain more prompt-cache reuse between turns, reducing repeated token processing, latency, and cost on prefix-cached providers. #102610 Thanks @ugiezzz.
  • Nemotron 3 Super now exposes its full 1,048,576-token context budget in OpenClaw's bundled NVIDIA fallback catalog instead of compacting at the stale 262,144-token limit. #98726 Thanks @eleqtrizit.
  • ChatGPT OAuth-backed Responses sessions now retain backend affinity across turns, improving prompt-cache reuse and reducing repeated processing of the same conversation context. #100233 Thanks @marvinthebored, @obviyus, @peetiegonzalez.
  • ##### Session and model diagnostics
  • After /model changes a session's provider, /status and session_status now report that provider's usage, authentication, runtime, and context details rather than stale defaults. #93384 Thanks @obviyus, @osolmaz, @rollingshmily, @samiralibabic, @zhangguiping-xydt.
  • Model-call traces now include prompt-size and per-call token usage details, helping operators investigate cost and prompt growth without capturing raw content. #95770 Thanks @amknight.
  • The diagnostics timeline now shows when provider model calls ran, how long they took, and whether they succeeded without recording prompt or response content. 7253552 Thanks @vincentkoc.
Memory and Sessions
  • Memory indexing, recall, wiki synchronization, and search recover from more malformed pages, stale status, large indexes, transient reads, and provider mismatches without hiding useful stored context or overwriting user notes. When a result is incomplete or a configured memory provider is unavailable, the failure is clearer instead of looking like a complete answer.
  • Sessions, transcripts, compaction, goals, and routing also retain the intended conversation more consistently through restarts, resets, delayed follow-ups, tool-heavy runs, and client changes. The practical result is less missing history, fewer replies stored against the wrong session, and more dependable continuation of long-running work.
  • #### Memory search and recall
  • QMD search and vsearch modes now skip the LLM reranker, reducing latency and avoiding unnecessary GPU failures while full query mode keeps reranking. #88887 Thanks @potterdigital.
  • Memory-wiki pages titled Index now remain stored, searchable, and retrievable instead of being hidden or overwritten by generated directory pages. #94326 Thanks @vincentkoc, @yetval.
  • Active Memory now warns when recalled operational details may be outdated and clearly marks clipped summaries, so old or incomplete status is less likely to look current. #95888 Thanks @spencer2211.
  • Memory-wiki pages in subfolders now appear in search, lookup, compiled indexes, digests, and vault counts just like pages at the top level. #96022 Thanks @machine3at, @vincentkoc.
  • Large memory indexes can now return filtered matches beyond sqlite-vec's first 4,096 candidates without failing or silently missing valid results. #96157 Thanks @itsuzef, @vincentkoc.
  • Repeated QMD-backed memory_search and openclaw memory search requests can return faster after the first lookup, while diagnostics separate setup time from search time and missing collections still trigger repair. #96655 Thanks @bek91.
  • Memory search now works with installed generic embedding plugins such as local llama.cpp, including their default model and connection details. #97095 Thanks @849261680.
  • One memory-wiki page with broken YAML no longer blocks healthy pages from being searched, compiled, linted, counted, or updated. #97177 Related #96125. Thanks @cow11023, @sunnyshu0925.
  • Memory Wiki now marks claims with malformed explicit freshness timestamps as unknown instead of masking the bad metadata with the page date. #97465 Thanks @ly-wang19.
  • Detailed /status plugins now warns when a configured memory embedding provider is unavailable and semantic recall has fallen back to keyword search. #97968 Thanks @masatohoshino.
  • QMD memory recall now turns malformed or warning-filled mcporter output into a clear, filtered error instead of exposing raw subprocess text. #98381 Thanks @miorbnli.
  • memory_get with corpus=all can now return an available wiki supplement when the requested memory file is missing instead of stopping with an empty result. #100904 Thanks @mushuiyu886, @vincentkoc.
  • With memorySearch.provider: none, OpenClaw now starts FTS-only memory without an unnecessary plugin capability scan. fbf574a
  • Interactive QMD memory searches with no matches now return an empty result promptly instead of appearing stuck during unnecessary index maintenance. #90030 Related #90023. Thanks @ruben2000de, @sahibzada-allahyar.
  • openclaw doctor --fix can now carry legacy Memory Core indexes from 2026.6.9 upgrades into the current store without forcing a full re-embed. #95631 Thanks @mushuiyu886, @vincentkoc.
  • openclaw memory status now warns when session transcripts still need indexing instead of incorrectly reporting memory as current. #97857 Related #97814. Thanks @che10x, @zw-xysk.
  • Memory Core now preserves short standalone concepts such as kv and s3 in tags, improving recall without matching them inside unrelated words. #96304 Thanks @ly-wang19.
  • Memory-wiki bridge status now returns a usable warning instead of crashing on malformed plugin artifacts, and readMemoryArtifacts: false now reliably prevents those reads. #100900 Thanks @huveewomg.
  • Wiki search and retrieval now explain when an older or partial memory plugin lacks shared-search support and offer a practical workaround instead of exposing a raw TypeError. #100902 Thanks @huveewomg, @vincentkoc, @xuanmingguo.
  • Memories containing emoji or supplementary CJK characters can now be indexed without malformed text stalling the operation. #101574 Thanks @jensenwang560-blip.
  • When both a primary memory read and its wiki supplement fail, memory_get corpus=all now returns the original structured read error instead of crashing the tool call. #101902 Thanks @aniruddhaadak80, @vincentkoc, @zw-xysk.
  • Memory-index debug logs now show whether an embedding batch completed or failed, making indexing problems easier to trace. #94732 Thanks @doubleji817-lang, @xydt-tanshanshan.
  • openclaw memory status --fix now repairs session-corpus state without mistaking healthy daily-memory records for stale data. #93389 Thanks @alix-007, @vincentkoc.
  • openclaw memory status no longer shows impossible session indexing totals where the indexed file count exceeds the total file count. #95452 Thanks @buyitsydney, @liuhao1024.
  • #### Memory Wiki and long-term memory
  • Durable memory promotion now keeps OpenClaw's managed dreaming markers and adjacent managed content out of MEMORY.md when a recalled range touches a block boundary. #83718 Thanks @grifjef.
  • Inferred follow-up commitments now return to the queue after temporary model or network extraction failures, reducing missed reminders without duplicate processing. #89817 Thanks @masatohoshino.
  • Memory-core light dreaming no longer repeats an unchanged work-summary block in DREAMS.md, while genuine daily-note updates can still appear later. #97446 Thanks @aaajiao, @qingminglong.
  • Memory Wiki lint now ignores link-looking text inside inline and fenced code while continuing to report genuine broken links in prose. #98095 Thanks @durambar, @vincentkoc, @zhangqueping.
  • Memory-wiki source updates now preserve hand-written Notes when a temporary read failure prevents OpenClaw from safely loading the existing page. #98360 Related #98345. Thanks @qingminglong, @vincentkoc, @yetval.
  • Memory-wiki source sync can now recover when a page is missing or collides with a non-file, while preserving existing content when a retry remains unsafe. #99276 Thanks @obviyus.
  • Memory Wiki imports now continue when a source page collides with a protected vault entry instead of stopping the whole import. 76db9a3 Thanks @vincentkoc.
  • Newly promoted long-term memories now omit raw transcript, summary, session-header, flush-prompt, and scoring clutter so useful notes are easier to find. #94636 Thanks @josephur, @pinghe-learn, @tayoun.
  • Dreaming now keeps deleted or reset transcript archives and cron-created child conversations out of its learned session set, reducing duplicate history and automation noise without removing retained archives from historical search. #96517 Thanks @adam-researchh, @jalehman, @xialonglee.
  • Memory Wiki import summaries now shorten ChatGPT text containing emoji without leaving corrupted replacement characters. #97362 Thanks @mushuiyu886.
  • Rerunning memory-wiki synthesis or ChatGPT imports no longer risks erasing handwritten notes, frontmatter, or import state when an existing page cannot be read briefly. #98787 Thanks @vincentkoc, @yetval.
  • Memory dreaming now records structured success or failure outcomes for light, REM, and deep phases so dashboards and health checks can monitor them reliably. #97723 Thanks @lg320531124, @momothemage.
  • openclaw wiki lint now ignores wikilink-like patterns inside code examples so real broken Memory Wiki links are easier to spot. #97954 Thanks @durambar, @liuhao1024, @vincentkoc.
  • openclaw wiki lint now recognizes valid imported Obsidian links by title, slug, fragment-free path, or source-path suffix, reducing false broken-link warnings. #100017 Thanks @ishangodawatta, @k-kerrigan, @vincentkoc.
  • Archived memories around user messages that begin with [cron:] remain searchable after a session reset or deletion, while genuine cron-generated archives stay hidden. #101322 Thanks @ly-wang19.
  • #### Session continuity
  • After /new or /reset, the previous conversation remains available for daily memory summaries and full-history searches through the session-logs skill. #71537 Thanks @injinj.
  • A group chat or Gateway session can now resume on the next visible request after a failed, timed-out, or killed turn without requiring /new or manual session-file edits. #89045 Thanks @jerry-xin.
  • Aborted or timed-out embedded runs now release their session write lock, so the next message can proceed without minutes of waiting or manual file cleanup. #96100 Thanks @richwilson-bloom, @sallyom, @xialonglee.
  • Replies that span an automatic daily or idle reset now remain together in one accessible transcript instead of losing later output. #97164 Thanks @joshavant, @yetval.
  • Resuming work from a project now opens only that project's saved agent session, preventing unrelated transcripts from being mixed together. #97785 Related #96542. Thanks @qingminglong, @yetval.
  • Recurring provider-CLI cron jobs and local openclaw agent runs now keep their existing provider conversation across the daily reset boundary instead of silently losing context. #98356 Thanks @yetval.
  • Discord, WebChat, and other ongoing conversations can keep receiving replies when background activity touches the same session during reply startup, without a false initialization conflict or dropped message. #98835 Related #98672. Thanks @aaronfaby, @jalehman, @moguangyu5-design.
  • Resetting a multi-agent room now restores message delivery promptly instead of blocking most agents' acknowledgement and queued replies for several minutes. #99091 Thanks @gorkem2020, @zengwen-dt.
  • Rapid follow-ups in the same chat no longer freeze both messages while the first automatic reply is finishing. #99549 Thanks @shagrat2.
  • Claude CLI-backed interactive replies now keep their saved session more consistently, preserving continuity and reducing repeated full-history replay. #99595 Related #99372. Thanks @obviyus.
  • CLI-backed agents in multi-person group chats now retain conversational context when participants alternate, without expanding non-owner tool permissions. #99640 Related #99633. Thanks @obviyus.
  • CLI-backed group agents now keep one warm conversation across mentioned and unmentioned follow-ups instead of resetting and losing context. #99722 Related #99696. Thanks @obviyus.
  • CLI-backed agents now keep conversation continuity across prompt-only changes, avoiding needless cold starts while still resetting when security or runtime conditions require it. #99822 Related #99729. Thanks @obviyus.
  • Temporary memory-maintenance failures no longer replace the agent reply, and persistently oversized sessions can recover in a fresh session while preserving the previous transcript. #100618 Thanks @jerry-xin, @rhclaw.
  • A first command-only interaction in an auto-reply flow now keeps its session update even when no session row existed beforehand. 76d686c
  • Sessions renamed with /name now keep that custom name in session lists instead of reverting to an automatic title or UUID-like label. #98841 Related #98742. Thanks @bsg2000, @sunnyshu0925.
  • A successfully completed main-agent conversation now continues in the same session on the next message instead of unexpectedly resetting and archiving its transcript. #99985 Thanks @sunnyshu0925.
  • Dashboard session labels and display names now remain attached when a session rolls over after a day or idle period. #101576 Thanks @merlin-zhou, @zengwen-dt.
  • #### CLI and Codex sessions
  • Claude CLI conversations that exhaust their context now recover into a fresh reseeded session automatically, and timeout retries retain the temporary files they need to complete. #98934 Related #98897. Thanks @obviyus.
  • Local Ollama-backed CLI agent turns can now continue when the context engine reports an already-compacted transcript, allowing the assistant or MCP tool result to reach the user. #99136 Thanks @mushuiyu886, @peterskwang, @pkoserowski, @psedd.
  • Existing Codex sessions can resume their bound threads more reliably after upgrades, resets, and compaction without depending on leftover transcript-side JSON files. #101210
  • A Codex reply delivered through sourceReplyDeliveryMode: "message_tool_only" now completes its turn promptly instead of later ending as an incomplete reply. #95942 Thanks @omarshahine.
  • Codex app-server installations using the retired on-failure approval policy now upgrade to the supported on-request behavior without losing saved bindings. 70153f7 Thanks @vincentkoc.
  • Existing Codex app-server conversations with dynamic tools can resume through the tool-fingerprint format upgrade instead of starting an avoidable replacement thread. 3051748 Thanks @vincentkoc.
  • Legacy Codex bindings with large tool or MCP configurations can now migrate without overflowing plugin-state records or copying raw configuration secrets. 23228b6 Thanks @vincentkoc.
  • Upgraded Codex installations can now finish legacy binding migration and archive old sidecars instead of repeatedly retaining them after an earlier partial import. 39fac06 Thanks @vincentkoc.
  • Codex sessions created in beta 5 can keep their existing conversation after upgrade when the user MCP configuration is unchanged, without retaining its authorization token. 272750d Thanks @vincentkoc.
  • Provider-owned CLI conversations now keep the same session and transcript across the daily default reset boundary unless an explicit reset policy or /reset applies. #97931 Thanks @yetval.
  • New Codex-backed threads now preserve configured plugin apps, can activate remote curated plugins, and run Guardian on the first eligible native OpenAI turn. #98042 Thanks @kevinslin.
  • A stuck Claude CLI startup now fails only the affected turn instead of exiting the Gateway, and heartbeat activity no longer causes the next user turn to lose its CLI conversation history. #98933 Related #98894, #98895. Thanks @obviyus.
  • Claude CLI agent runs now fail clearly when messaging tools are unavailable, recover when Claude exits without a result, retain more long-session continuity, and clean up prompt images and failed preparation files. #99159 Related #98946. Thanks @obviyus.
  • The same-release Codex session-continuity work now covers app-server thread start and resume, with binding fingerprints kept bounded throughout. 78edf1c Thanks @vincentkoc.
  • #### Transcripts and exports
  • Shared group and channel transcripts now retain the sender ID, display name, and username for each durable user turn, making later history and memory processing correctly attribute participants. #90552 Thanks @pick-cat.
  • /export-session now warns when a CLI- or ACP-backed export contains only user messages and points users to the backend transcript for missing assistant, tool, usage, and cost details. #90867 Thanks @tank-x3, @vincentkoc, @xydigit-sj.
  • openclaw export-trajectory and /export-trajectory now include redacted messages from older version 1 sessions instead of producing a successful but empty transcript. #93814 Thanks @yetval.
  • Session-memory files created around /new and /reset now keep one copy of each assistant reply instead of duplicating reasoning-model responses. #94401 Thanks @sallyom, @sunnyshu0925.
  • Compacted agent history now lists genuine tool failures instead of repeatedly mislabeling successful subagent launches, including when older transcript records contain the incorrect error flag. #96842 Thanks @nxmxbbd.
  • Invalid transcript entries now raise a visible write error instead of becoming undefined JSONL lines that silently vanish after reload. #97356 Thanks @miorbnli.
  • openclaw sessions cleanup --fix-missing now preserves fresh cron sessions with valid transcripts and clearly reports repaired entries. #97495 Thanks @qingminglong.
  • Automatic recovery from provider role-ordering conflicts now archives the complete prior transcript as a timestamped JSONL file before replaying a shorter tail. #97544 Thanks @yungchentang.
  • Compacted group conversations now retain identical long messages from different participants while still removing accidental duplicate retries from the same sender. #98336 Thanks @sunnyshu0925, @yetval.
  • Transcript summary and import reads now close files reliably after malformed data, preventing long-running processes from gradually exhausting file handles. #98493 Related #98467. Thanks @wangmiao0668000666, @zhanglei99586.
  • Older or imported sessions with plain-string assistant messages now replay correctly across provider and streaming paths instead of sending malformed conversation history. #98908 Thanks @obviyus.
  • Claude CLI chat history reloads no longer display OpenClaw's internal reseed wrapper as if it were a message the user typed. #99653 Related #99646. Thanks @harjothkhara, @jeehut, @vincentkoc, @zoowh.
  • Transcript-backed history now treats a missing file as empty while reporting real access, directory, or stream failures cleanly instead of leaving partial or unhandled results. #100524 Thanks @cxbasdev, @zhanglei99586.
  • Transient transcript read failures no longer destabilize session-log diagnostics or let an incomplete usage scan overwrite the last complete cost cache as though it were current. #101062 Thanks @cxbasdev, @vincentkoc.
  • Malformed transcript rows now produce an aggregate warning with skipped and loaded counts while the remaining usable session history continues to load. #98669 Thanks @cxbasdev.
  • Transcript tools can now identify channel delivery mirrors as OpenClaw bookkeeping rather than mistaking them for OpenAI Responses output. #99855 Thanks @vincentkoc.
  • Debug-proxy ACP runs now shut down cleanly, mark capture sessions finished, and close their capture databases without reporting a spurious database error. #100827 Thanks @amknight.
  • openclaw sessions tail now rejects oversized trajectory snapshots and updates with a clear limit error before they can exhaust memory. #101450 Thanks @cxbasdev, @vincentkoc.
  • Long usage and session log messages now truncate emoji cleanly instead of displaying malformed character artifacts. #101517 Thanks @maweibin.
  • #### Tool results, files, and media
  • Reopened sessions can now replay older string or single-object tool results correctly instead of treating successful output as empty or failing on its stored shape. #98891 Related #98825. Thanks @obviyus.
  • Agents in long-running WebChat, Discord, and other direct sessions can keep reading fresh command, file, browser, and status output instead of seeing it disappear or turn into an image placeholder. #98955 Related #98874. Thanks @lamkan0210, @momothemage.
  • Imported Claude CLI history now keeps image-only and attachment-bearing turns visible when removing empty legacy reseed text. #99839 Thanks @vincentkoc.
  • Claude CLI model fallback now carries the prior tool-call trail alongside tool results, giving the replacement model enough context to continue coherently. #99851 Thanks @vincentkoc.
  • Long-running agents can now recover full command output and truncated web_fetch content after history cleanup, reducing repeated expensive work and lost page context. #100135 Thanks @obviyus.
  • Embedded agents now receive well-formed summaries of long media or JSON values instead of broken characters at Unicode truncation boundaries. #101311 Thanks @alix-007.
  • Media-provider audit details containing emoji now remain valid and readable when shortened, instead of ending with malformed characters. #101298 Thanks @alix-007.
  • Long agent prompt data containing emoji or other paired Unicode characters now stays well-formed when capped, avoiding broken text in agent and automation context. #101303 Thanks @alix-007.
  • #### Long conversations and compaction
  • Embedded agents now retain configured compaction reserve limits when runtime safeguards save settings, reducing unexpected context-budget shrinkage during long work. #92237 Thanks @sercada.
  • Telling an agent to remember a preference no longer triggers the unrelated warning used for promises to schedule an automatic reminder. #93862 Thanks @arkyu2077.
  • Sessions with large command output or summaries now compact before exceeding the model context, avoiding failed provider requests and misleading token budgets. #97861 Thanks @yetval.
  • Long tool-heavy or compacted sessions now budget the real size of command output and summaries before sending a prompt, reducing context overflow failures. #97928 Related #97927. Thanks @liuhao1024, @yetval.
  • Edge-case fixes now preserve literal memory text and valid Unicode, improve voice-call cleanup and port checks, report Claude models and context limits accurately, and retain useful ClickClack connection errors. #100204 Thanks @cxbasdev, @harjothkhara, @lilan0125, @lin-hongkuan, @liuhao1024, @mikasa0818, @pandah97, @sunlit-deng, @zoowh.
  • Fresh Claude CLI workspaces now run a pending BOOTSTRAP.md on the first reply so required identity, memory, and setup steps are completed before normal conversation. #100560 Thanks @bill-starfoundry, @kruegerb, @vincentkoc.
  • Long-running agents are less likely to lose workspace instructions such as AGENTS.md, SOUL.md, or MEMORY.md for a turn during a temporary filesystem error. #100910 Thanks @masatohoshino.
  • Embedded agent runs that omit a session key now retain the intended fallback session context more reliably. 31a65e0 Thanks @vincentkoc.
  • A malformed custom tool in realtime Talk no longer removes the built-in consult tool or other valid custom tools from the session. 170150a Thanks @vincentkoc.
  • Local-model conversations now retain reusable prompt work when switching between interactive chats and background jobs, avoiding repeated multi-minute warm-up delays. #98267 Related #98261. Thanks @headbouyjb.
  • A response interrupted mid-tool-call no longer runs or saves that incomplete action, preventing accidental child sessions and other unintended side effects. #97140 Thanks @galiniliev.
  • Agents running on macOS 26 now receive the macOS product version in their runtime prompt instead of the Darwin kernel version. #95225 Thanks @sunlit-deng.
  • Level directives such as /verbose and /think no longer remove the first word of the user's message when both are sent together. #97929 Thanks @yetval.
  • Malformed surrogate HTML entities in provider output no longer corrupt agent tool arguments, transcripts, or URLs, while legitimate entities and emoji still decode normally. #99564 Thanks @mikasa0818.
  • Leaving one answer blank in a multi-question prompt no longer shifts the remaining typed answers onto the wrong questions. #100832 Thanks @machine3at.
  • ACP runtime controls can now truly clear saved model, thinking, working-directory, permission, timeout, mode, and backend-extra settings so later turns do not reuse stale values. #101044 Thanks @mushuiyu886.
  • Skill Workshop sessions now carry a clearer prompt with about 1.8KB less repeated prompt and schema overhead while retaining the same reviewable proposal flow. #100481
  • Prompt caching and cache traces now fingerprint malformed incoming text consistently with the cleaned text providers receive, avoiding needless cache misses and misleading diagnostics. #101009 Thanks @qingminglong.
  • Operators now receive payload.large or truncated diagnostics and an accurate count whenever chat.history omits older messages, making hidden history trimming visible without changing client responses. #96788 Thanks @zengwen-dt.
  • With memory flush enabled, important conversation context now gets a chance to reach durable memory before automatic compaction, reducing silent gaps in saved notes. #84792 Thanks @turbotheturtle.
  • Long CJK-heavy sessions using a context engine such as lossless-claw no longer stop on a false prompt too large precheck after the engine has already managed the prompt. #95342 Thanks @jalehman, @mpz4life.
  • Large Chinese, Japanese, and Korean tool results are now estimated more accurately, reducing false context-overflow interruptions and premature compaction. #95447 Thanks @moguangyu5-design, @vincentkoc.
  • Prompts containing fullwidth East Asian characters now receive more accurate size estimates, allowing context management to start before an oversized request reaches the model. #96442 Thanks @lin-hongkuan.
  • Long conversations now recover compaction after transient provider disconnects instead of replacing useful history with a degraded placeholder summary. #97504 Thanks @hugenshen.
  • Long conversations using historyLimit or dmHistoryLimit now retain their saved earlier summary after compaction, helping the assistant remember prior context. #97591 Thanks @liuhao1024, @yetval.
  • Long Codex conversations with heavy tool use can now compact at a real history boundary and continue with relevant tool results summarized instead of retaining the full transcript. #99391 Related #99375. Thanks @imchloe92, @lzy3538.
  • Local-model sessions now retain auto-compaction bookkeeping, reducing repeated context refills and the unresponsive behavior they could cause. #99678 Related #99677. Thanks @headbouyjb, @vincentkoc.
  • Long, tool-heavy agent sessions now preserve the newest command, file, or browser result for the model while shortening older history first. #99756 Thanks @acosx.
  • Long cached Anthropic tool sessions now compact near the configured context threshold instead of interrupting work early because cumulative cache tokens looked like live context. #99864 Thanks @jrex-jooni, @lzy3538, @vincentkoc.
  • Long-lived agents with large context windows now retain fresh tool output, compact under aggregate pressure, and warn users to run /compact or /new if pressure persists. #100077 Thanks @obviyus.
  • Small-context local models can now begin and continue conversations without immediately entering an overflow-compaction loop before useful prompt space is available. #100621 Thanks @vincentkoc.
  • Long sessions that compact in stages now preserve clearer older-to-newer ordering when summaries are combined, reducing the chance that stale context appears equally recent. #100684 Thanks @vincentkoc, @zw-xysk.
  • Context-engine plugins can now identify the exact session that continues after compaction while older integrations using sessionFile remain compatible. #101182 Thanks @jalehman.
  • Preparing a reset for a long-running session now avoids scanning the entire transcript, reducing startup file activity and memory use as history grows. #99335 Thanks @gmschasiepen, @momothemage.
  • #### Session storage and cleanup
  • Gateway and embedded TUI startup now reclaim old session temporary files left by hard shutdowns, reducing hidden disk growth while preserving fresh or potentially recoverable state. #90503 Thanks @sahibzada-allahyar.
  • Long-running gateways can clear stale one-shot model-check sessions before they crowd out real conversation history, with dedicated CLI reporting for review. #91057 Thanks @jalehman, @wangwllu.
  • Mac users now get stronger protection for local OpenClaw SQLite data after abrupt power loss or an operating-system crash, with no configuration change. #99067 Thanks @ooiuuii.
  • Session-memory diagnostics now show the correct workspace and memory-file paths for sibling directories whose names merely resemble the user's home path. #101577 Thanks @cxbasdev.
Gateway and Agent Reliability
  • The Gateway now starts, connects, reloads, and reports health with clearer behavior across configuration, networking, task routing, and result delivery. Agents are less likely to lose their selected workspace or conversation, background work reaches the right destination more consistently, and tool failures can stay out of chat progress when a useful final reply is still available.
  • The Gateway protocol and restart recovery paths also reject invalid state more clearly and keep inspection available during common lifecycle failures. Skill loading and prompt overhead are steadier as well, with skill controls avoiding unnecessary work and preserving cache fingerprints for the text providers actually receive.
  • #### Run completion and replies
  • Timed-out cron jobs, expired agent requests, and disconnected HTTP clients now stop promptly instead of spending more time and provider calls on model fallback. #62682 Thanks @altaywtf, @cinapbot, @simonusa.
  • Channel replies can now continue as soon as an embedded-agent turn finishes instead of waiting roughly 50 seconds for post-run authentication bookkeeping. #85829 Thanks @turbotheturtle.
  • Anthropic sessions stuck on a thinking-signature replay error can now retry once without invalid thinking blocks and continue without /new or transcript repair. #95430 Related #95429. Thanks @alexelgier, @lzyyzznl, @vincentkoc.
  • Codex-backed runs can now deliver a completed final answer instead of timing out or appearing aborted when the final completion event is missing. #99217 Thanks @100yenadmin, @fuller-stack-dev, @sedrak-hovhannisyan.
  • Interactive chat requests that end in a terminal failure now receive one visible error response instead of appearing to be ignored. #99304 Thanks @grox2012, @moeedahmed.
  • Agent sessions are less likely to lose output, alter unrelated formatting, stall after temporary provider errors, reject BMP images, or drop longer ChatGPT connections. #99949
  • Long Claude CLI-backed runs now show honest Thinking... (~N tokens) activity for direct and queued work instead of appearing stalled when readable reasoning text is unavailable. #100148 Thanks @obviyus.
  • Interactive turns that truly end without visible output now send a clear failure reply, while intentional silence and already-completed actions remain quiet. #100474
  • Completed answers from tool-using tasks now reach the user instead of being replaced by an incomplete-turn error, with run metadata attached to the same final response. #100655 Thanks @liuwqgit.
  • Using /stop during a late-aborting prompt no longer leaves a stale session lock that blocks the next turn in the same conversation. f8016c4
  • Long agent runs can now resume from a valid conversation boundary after compaction recovery instead of wedging or incorrectly demoting the selected model. 486033b Thanks @mettlyz11, @neltomw, @obviyus.
  • Embedded agent jobs with an explicitly longer timeout now keep their lane until that requested deadline instead of being recovered at the default limit. 1437512 Thanks @vincentkoc.
  • Mobile, WebChat, consult, and other chat.send clients can apply a one-time thinking level without losing the assistant reply or having the message mistaken for a text command. #98855 Thanks @jesse-merhi.
  • A wedged provider call now releases its embedded agent lane on a bounded watchdog instead of indefinitely blocking queued work when run timeouts are disabled. ec28935 Thanks @arismontclair, @obviyus, @patelmm79.
  • Gateway conversations with an orphaned active task can now recover through diagnostics instead of leaving later turns blocked until restart. b1da734 Thanks @arismontclair, @obviyus, @ralf003.
  • An agent no longer stays silent after compaction when a plugin's final-answer hook hangs; OpenClaw times out the hook and still delivers the response. b2baf79 Thanks @dserious, @obviyus, @villa-feng.
  • Very long agent conversations are less likely to loop through failed overflow recovery because compaction now reflects the prompt OpenClaw actually prepared. #101181 Thanks @jalehman.
  • With messages.suppressToolErrors enabled, tool failures no longer leak into chat as progress updates while normal progress and final replies continue. #98063 Thanks @amittell, @moeedahmed.
  • Interactive and queued turns that finish without a visible answer now return a clear, sanitized failure message instead of leaving the chat looking stuck. #100456 Thanks @mushuiyu886.
  • #### Delegated agents and shared work
  • Legacy subagent sessions now follow their actual nesting level, so nested-agent limits and controls no longer fall back to top-level behavior. #54593 Thanks @ruanrrn.
  • Subagent completion notices now arrive once instead of being repeated when the requesting session changes during delivery. #92274 Related #91527. Thanks @fsdwen, @obviyus, @zackchiutw.
  • Successful embedded-agent subagent launches now remain successful in transcripts and later compaction summaries instead of being recorded as tool failures, while real launch failures stay visible. #96851 Thanks @neomail2, @parveshsaini.
  • Codex-runtime transcripts and compaction summaries now keep successful subagent launches and goal operations out of failure records, while genuine failures remain visible and accepted-launch hooks can run. #96856 Thanks @nxmxbbd.
  • Successfully started subagents now remain visible in /subagents list and subagents(action="list"), including when different sessions own control and completion. #99410 Related #75593. Thanks @aaajiao, @sheyanmin.
  • Codex app-server agents can again list allowed agents, spawn OpenClaw or ACP subagents, and yield during delegated work without resumed heartbeats hitting incompatible tool definitions. #99561 Related #99464. Thanks @100yenadmin, @joshavant.
  • Requester agents now receive a follow-up when an accepted sessions_send delivery later fails because the target session is locked, so they can retry or choose another route. #99907 Thanks @849261680, @alex-heyuqing.
  • Sub-agents and other HTTP loopback MCP clients can again receive browser screenshots and valid image or embedded-resource results without schema failures. #100336 Thanks @tzy-17.
  • A yielded Codex native subagent's completion now reaches its parent run before the shared app-server connection is cleaned up. 2f89de8 Thanks @vincentkoc.
  • Large agent and subagent workloads now place less memory pressure on the Gateway because completed run snapshots are bounded while results still remain available to active waiters. #77973 Related #77976. Thanks @fede-kamel, @vincentkoc.
  • Parent sessions waiting on a subagent now receive the subagent's actual hard-timeout phase and timestamps instead of a generic timeout. #89367 Thanks @pick-cat.
  • Malformed cyclic attachments can no longer crash subagent delivery-evidence collection, so the reply handoff completes and still returns reachable media URLs. #97041 Thanks @pick-cat.
  • A parent session waiting on several subagents now resumes and returns their combined results when the last outstanding work finishes, without requiring the user to send another message. #97090 Thanks @galiniliev.
  • Manually spawned ACP child runs now appear once in the task ledger instead of creating duplicate requester-visible rows. #97131 Thanks @moeedahmed.
  • Cancelling an ACP task from the CLI now reaches the live Gateway-owned run, reports real failures, and avoids duplicate active task rows. #97352 Thanks @aliahnaf2013-max.
  • Stopping a subagent now clears its running task reliably and prevents late completion races from reviving or overwriting the canceled state. #99806 Thanks @masatohoshino, @timofa.
  • After a Gateway restart, a redirected subagent now continues the user's newest instruction instead of returning to stale work. 7b5d86e Thanks @amittell.
  • ACP run-to-session lookups now return the current active run instead of a stale association from an older run. #96427 Thanks @lin-hongkuan.
  • Parent sessions no longer repeat an earlier child-agent progress message when the child later reports completion. #101042 Thanks @mushuiyu886.
  • #### Files, images, and result delivery
  • Isolated cron jobs can announce a cross-session result without feeding the recipient's reply back into the cron run and creating duplicate message loops. #92283 Related #92257. Thanks @harjothkhara, @nailujac, @vincentkoc.
  • Agents can now read structured JSON and resource tool results during provider replay instead of receiving an empty result or generic media placeholder. #97742 Thanks @obviyus.
  • Images attached to a CLI-backed prompt now survive embedded-model fallback, preserving the visual context needed to answer. #99891 Thanks @vincentkoc.
  • Messages mixing inline and offloaded images now preserve every attachment position so model instructions that depend on sequence remain accurate. #99902 Thanks @vincentkoc.
  • Images from the current prompt now reach CLI fallback attempts in the right order, without pulling stale image references from earlier retries or history. #100035 Thanks @vincentkoc.
  • Batched media replies can now finish successfully after delivery without a misleading session-change failure, while active conversation ownership checks remain enforced. #100490 Thanks @scotthuang.
  • Sandboxed auto-replies now wait for remote media copied over SCP to finish and report transfer failures without crashing or cleaning up too early. #100861 Thanks @cxbasdev.
  • Useful JSON, resource data, and CLI tool results now remain visible in transcripts instead of disappearing behind an attachment placeholder. #97268
  • An empty non-image tool result no longer becomes (see attached image) in OpenAI-compatible agent context, avoiding misleading follow-up behavior. #97423 Thanks @scribe-dandelion-cult.
  • Gateway event-delivery failures now produce actionable warnings instead of unexplained process-level promise rejections, while unrelated subscriptions keep running. #100401 Thanks @cxbasdev.
  • Discord now presents commentary, reasoning, and tool activity in a clearer sequence across queued turns, while loopback MCP clients can attach to one Gateway session with an expiring, revocable token. 35af831 Thanks @dwc1997, @lsr911, @ooiuuii, @romneyda, @solodmd, @vincentkoc, @wendy-chsy, @yeager, @zenglingbiao.
  • Successful agent tools that return safe plain text now show that output instead of leaving users with an apparently empty result. #99526 Related #99523. Thanks @snowzlm.
  • #### Gateway restarts and queued work
  • A successfully delivered heartbeat notification no longer leaves stale recovery state that can block later heartbeat alerts or check-ins. #83187 Thanks @agocs.
  • Restarting the Gateway during a deferred channel reload no longer starts the same channel twice, avoiding webhook port conflicts and repeated restart failures. #94964 Related #79487. Thanks @lzyyzznl, @tseller.
  • A damaged SQLite delivery-queue entry no longer blocks recovery of every other valid queued session or outbound delivery after restart. #98354 Thanks @pick-cat.
  • Gateway startup lock failures now clean up partial files and open handles, allowing a later startup to acquire the lock normally. #99291 Related #98958. Thanks @chenyangjun-xy, @zhanglei99586.
  • Gateway status now reports unavailable SSH cleanly and promptly instead of crashing or waiting indefinitely when tunnel startup fails. #99800 Thanks @cxbasdev, @vincentkoc.
  • Heartbeat and cron work on macOS and Linux is less likely to fail with Unknown system error -11 when reconnects overlap session or workspace updates. #100389 Thanks @ogarciarevett.
  • Gateway startup no longer performs unsolicited provider-auth discovery across every configured agent, helping channels and local commands remain responsive while authentication loads on demand. #100667 Thanks @vincentkoc.
  • Unexpected SSH tunnel diagnostic-stream closure no longer crashes the Gateway during tunnel checks or shutdown. #100855 Thanks @cxbasdev, @vincentkoc.
  • A disconnected or failing session-history stream no longer crashes the Gateway and interrupts service for everyone else. #101571 Thanks @vincentkoc, @zengwen-dt.
  • Gateway startup can now be retried immediately after a configuration-change rejection instead of being blocked for up to five minutes by a stale migration lease. #103157
  • Gateway startup channel warnings now use the same plugin manifests as the running startup process, reducing inconsistent warnings and repeated discovery. 10ca94e Thanks @vincentkoc.
  • Gateway startup now skips unnecessary provider thinking-policy work when an explicit setting or model catalog already determines the banner result. b18af41
  • Gateway connection failures now identify the last completed handshake phase, helping operators distinguish upgrade, credential, authentication, session, and ready-state stalls. #93402 Thanks @849261680, @bzelones, @vincentkoc, @youngting520.
  • Control UI and other Gateway clients now show the correct pairing or protocol-version guidance even when detail codes contain extra whitespace. #99555 Thanks @ly85206559.
  • Gateway override authentication errors now tell CLI and TUI users whether to add a token or password, remove --url, or pair the relevant environment variables. #100418 Thanks @gmays.
  • Standalone ACP clients now close the shared SQLite state database during shutdown so hot reloads and immediate restarts can reopen it without stale locks or callbacks. #100691 Thanks @lzy3538.
  • Voice-call webhook setup through ngrok or Tailscale now fails cleanly on tunnel stream errors instead of crashing the Gateway, and shutdown avoids waiting on an already-ended tunnel. #101394 Thanks @cxbasdev.
  • #### Crashes and connection failures
  • Provider failures that contain BigInt, circular objects, or other unusual values now produce the intended structured transport error instead of crashing the error-reporting path. #88401 Thanks @pluviobyte.
  • OpenClaw no longer crashes when a supervised child output stream fails immediately after launch. #99802 Thanks @cxbasdev, @vincentkoc.
  • MCP stdio sessions now report stderr pipe failures as transport errors without taking down OpenClaw or losing available diagnostics. #99803 Thanks @cxbasdev, @vincentkoc.
  • ACPX MCP proxies now turn closed input or output pipes into a clear proxy failure instead of an uncaught Node stream crash. #99852 Thanks @sunlit-deng, @vincentkoc.
  • Shell snapshot capture and validation no longer crash OpenClaw when an unused helper-process output pipe reports a stream error. #100744 Thanks @lsr911, @vincentkoc.
  • A node-host system.run stream failure now returns a clear failed result instead of crashing the node host, and a child that will not stop is terminated after one second. #100849 Thanks @cxbasdev.
  • Docker-backed sandbox file and shell commands now fail promptly with the original input-stream error instead of crashing, hanging, or remaining pending. #101032 Thanks @cxbasdev.
  • APNs relay pushes now reject oversized response bodies as RelayResponseTooLarge instead of exhausting Gateway memory or reporting false delivery. #97550 Thanks @alix-007.
  • An ACP Gateway event-handler failure now produces a concise diagnostic instead of terminating the ACP process or corrupting protocol output. #100558 Thanks @ajwan8998.
  • A runaway tool_search_code subprocess can no longer grow Gateway memory without limit through stderr, while failure reports retain the latest useful diagnostic detail. #101007 Thanks @hugenshen, @vincentkoc.
  • Built-in grep stream failures now become ordinary tool errors instead of crashing the agent runtime, hanging the search, or leaving incomplete results unexplained. #101014 Thanks @cxbasdev.
  • SSH-backed sandbox commands and uploads now stop cleanly, clean up child processes, and preserve the useful error when an input or output stream fails. #101031 Thanks @cxbasdev.
  • #### Gateway controls and settings
  • Experimental local-model lean mode now offers a smaller default tool menu for constrained models, while operators can explicitly retain media, voice, or PDF tools through allowlists. #88881 Thanks @vincentkoc.
  • Operators can now set OPENCLAW_SANDBOX_IMAGE to build revision-specific sandbox image tags for controlled rollout and rollback. #99915
  • Lean local-model agents can now choose the familiar exec tool directly when policy permits it, while existing allowlists, sandboxing, approvals, and hooks still govern command execution. #101607 Thanks @vincentkoc.
  • Busy or slower hosts now give Codex native permission checks and pre-tool hooks more time to finish, reducing dropped policy decisions. 123ec16 Thanks @vincentkoc.
  • Completed or expired exec approvals no longer add misleading follow-up warnings, making the remaining dispatch warnings more useful for spotting real delivery failures. #66685 Thanks @pfrederiksen.
  • Local Gateway approval read or write failures now return a consistent UNAVAILABLE response instead of a generic handler error. #79861 Thanks @martins-oss.
  • Agent requests with several MCP servers now initialize those servers concurrently, shortening the wait before the model begins while isolating slow or failed servers. #94230 Thanks @mmyzwl, @vincentkoc.
  • External tools can now receive session-scoped Gateway access without process-wide credentials or permission to impersonate another session, forming the secure base for openclaw attach. #96351 Thanks @anagnorisis2peripeteia, @obviyus.
  • Operators can inspect the effective tools for global sessions assigned to any configured agent, not only the default one. #97265 Thanks @pick-cat.
  • Agent runs, Doctor, and Gateway tool views now describe access using the same policy that actually governs the run, reducing confusing permission mismatches. #99817
  • Bounded write-scope clients can now rename, pin, archive, categorize, and mark sessions unread without admin access, while user labels and stable list ordering survive refreshes. #100964
  • Embedded terminals can now open, resize, stream output, and close consistently across the Gateway, Control UI, and native apps. 6601576
  • Developers can build against and consume managed-worktree session results from the Gateway protocol package without duplicate-name failures. 8ce620f Thanks @vincentkoc.
  • #### Health, usage, and status
  • Embedded openclaw agent --local runs using OpenAI-compatible providers now report and save streamed token usage instead of showing zero, improving session, context, cost, and monitoring records. #96523 Thanks @ly85206559, @vincentkoc.
  • Unusual ACP failure causes now produce stable, readable diagnostic details instead of a missing or invalid explanation. #96270 Thanks @ly-wang19.
  • Normally completed agent and subagent runs no longer appear as error-level log entries, reducing false alarms while genuine failures remain elevated. #101703 Thanks @zengwen-dt.
  • Gateway logs now reveal when OpenClaw cannot save a terminal session's final lifecycle state, making silent persistence failures diagnosable. #97839 Related #97795. Thanks @aniruddhaadak80, @lzy3538.
  • Gateway MCP logs are now quieter and identify the responsible tool when schema problems occur, while distinct conflicts remain visible. #98821 Thanks @alvelda, @harjothkhara.
  • Malformed Gateway MCP tools/call arguments now return a clear invalid-parameters response before any hook or tool can process them. #99180 Thanks @vectorpeak.
  • MCP attach requests without a valid session key now return the intended validation error instead of crashing the Gateway with a TypeError. #99488 Thanks @zhanglei99586.
  • Starting a new Codex session no longer emits a false history warning before its transcript exists, while genuine history failures remain visible. #100484 Thanks @litang9, @vincentkoc.
  • Gateway usage reports now label start and end dates in the requested timezone, including correct calendar-day handling across local daylight-saving transitions. #100567 Thanks @nianjiuzst.
  • Session usage details now recover malformed transcript dates from available message timestamps and return finite, consistently ordered values instead of nulls. #100687 Thanks @sheyanmin.
  • #### Text, emoji, and translated output
  • Truncated agent logs and diagnostic previews now keep emoji and other extended Unicode characters intact at the cutoff. #96296 Thanks @ly-wang19.
  • Long agent grep lines now truncate emoji and uncommon CJK characters cleanly instead of ending with corrupted replacement symbols. #97559 Thanks @zenglingbiao.
  • Emoji and other supplementary characters now remain intact when long agent progress or active-memory recall text is shortened. #100244 Thanks @vincentkoc, @xialonglee, @zengwen-dt.
  • Shortened text across CLI output, diagnostics, plugin messages, previews, errors, task summaries, and Zalo sends now preserves complete emoji and other supplementary characters. #101654 Thanks @lsr911, @maweibin, @wm0018.
  • Long names, labels, summaries, previews, titles, and diagnostics across OpenClaw now truncate without splitting emoji or other supplementary Unicode characters. #101685 Thanks @lsr911, @ly85206559, @maweibin, @wings1029.
  • Bounded text in Parallel searches, compaction, telemetry, presence, Workboard, badges, and Control UI metadata now keeps or omits whole Unicode characters instead of leaving malformed fragments. #101711
  • Long streamed replies now split only between complete Unicode characters, preserving emoji in plain text and fenced Markdown even at tight message limits. #104441 Thanks @mushuiyu886.
  • Long status messages and command output now stay readable when shortened, without splitting emoji or non-English characters into corrupted text. 2e7ffca Thanks @vincentkoc.
  • Codex usage-limit previews and plan status labels now truncate emoji and uncommon Unicode cleanly at their display boundaries. #97299 Thanks @zenglingbiao.
  • /subagents list now shortens long names and task descriptions containing emoji or uncommon CJK characters without displaying broken glyphs. #97557 Thanks @zenglingbiao.
  • Compact subagent lists now keep long labels and task text within their display budget without splitting emoji or breaking alignment. #100013 Thanks @qingminglong.
  • Shortened web, media, TTS, status, transport, and voice-call text now preserves complete Unicode characters instead of producing replacement symbols or malformed downstream content. #101355 Thanks @alix-007, @vincentkoc.
  • Codex desktop notifications now shorten long assistant previews containing emoji or CJK text without malformed characters. #101534 Thanks @lsr911.
  • ACP tool titles, permission prompts, warnings, and errors now keep long emoji or CJK argument previews readable when shortened. #101535 Thanks @lsr911.
  • Suppressed auto-reply previews in verbose logs now preserve complete emoji and other supplementary characters instead of showing corrupted text at the length limit. #101575 Thanks @wm0018.
  • Oversized agent tool results now preserve complete emoji and similar Unicode characters when shortened before being sent to the model. #102087 Thanks @chengzhichao-xydt.
  • Gateway WebSocket failures now keep non-ASCII close reasons readable and within the byte limit instead of cutting characters into garbled text. #100047 Thanks @narahariraghava.
Accounts, Devices, and Data Protection
  • Trust-sensitive actions stop earlier and explain more of what requires attention. The persistent activity audit can be filtered and exported after restarts, ClawHub installations distinguish blocked releases from releases that need deliberate acknowledgement, and guarded networking supports approved proxy-only paths without weakening destination checks.
  • Credential resolution and redaction now cover more model and plugin paths, while sandboxing and approvals enforce clearer device, permission, and workspace boundaries. The secrets workflow also avoids exposing resolved model credentials in ordinary request and error paths.
  • #### Credentials and private data
  • Model-provider keys stored with SecretRefs now receive additional protection against accidental exposure in logs, errors, proxy captures, SDK setup, and runtime inspection, with a compatibility switch for secret sentinels. #102009
  • Operators can use targeted Doctor lint to detect credential residue in historical config-audit.jsonl entries and preview redaction before running openclaw doctor --fix. #84450 Thanks @giodl73-repo.
  • Gateway service regeneration now keeps environment-backed secrets out of Linux unit definitions and preserves resolved provider and channel credentials on macOS. #96065 Thanks @darren2030, @obviyus.
  • openclaw doctor --fix now preserves separate OAuth accounts for the same provider, including each account reference and saved display name. #97541 Thanks @liuhao1024, @yetval.
  • Bare Fireworks API keys are now masked in logs, provider errors, command details, tool output, and Control UI diagnostics even without a nearby sensitive-field label. #98226 Related #98225. Thanks @ooiuuii.
  • Failed OpenAI or Codex credential refreshes now report that reauthentication is required and privately identify the affected profile instead of appearing healthy until model turns fail. #99134 Related #99120. Thanks @100yenadmin, @fuller-stack-dev.
  • A temporary output-stream read failure from an exec-based SecretRef provider no longer crashes OpenClaw during credential resolution. #100521 Thanks @cxbasdev.
  • Agent payload logs and cache traces now redact provider keys even when those credentials appear inside free-text diagnostic values. d8ee630 Thanks @joshavant.
  • Failed cron webhooks no longer forward raw command summaries or diagnostics that may contain setup prompts, codes, or secret-like output. 1d17263 Thanks @joshavant.
  • Secret target discovery now works consistently for both scoped requests and the full compiled registry instead of failing when no allowed subset is supplied. e490171
  • /login codex now switches the active chat to the account just authenticated without overwriting a newer manual profile choice, and gives recovery guidance if the switch fails. 02c3de9 Thanks @vincentkoc.
  • Profile changes made through /login now use the standard session save path, preserving newer concurrent selections and existing recovery behavior. f07c478 Thanks @vincentkoc.
  • Codex session bindings now keep large MCP configurations and rotated Authorization credentials in bounded fingerprints without persisting readable bearer values. 491e42e Thanks @100yenadmin.
  • Copied provider keys and tokens now have hidden terminal control characters removed before request headers are prepared, while intentional spaces remain intact. #96444 Thanks @lin-hongkuan.
  • Masked malformed credentials now stay on one safe line in setup and authentication diagnostics even when the original input contains newlines or other control bytes. #96445 Thanks @lin-hongkuan.
  • Security audits no longer mistake bundled placeholder keys for LM Studio, Ollama, and other keyless local providers as exposed plaintext credentials. #97622 Thanks @xydigit-sj.
  • Control UI Activity previews now conceal API keys stored under dotted configuration names or returned in structured tool output. #99460 Related #99459. Thanks @ooiuuii.
  • Custom ACP error redactors now keep OpenClaw's built-in secret cleanup, preventing known tokens, credentials, and private-key material from leaking into formatted errors. #100191 Thanks @lin-hongkuan.
  • When another OpenClaw process is refreshing OpenAI OAuth credentials, operators now see one useful contention error without duplicated wording or exposed local file paths. #101573 Thanks @vincentkoc.
  • #### Devices and pairing
  • Running a read-only local Gateway check no longer leaves stale pairing permissions that block a later agent, admin, write, or device-approval command. #96002 Thanks @vincentkoc.
  • /pair now refuses setup codes that point to non-routable 0.0.0.0 or :: addresses and gives operators secure Gateway URL guidance instead. #98617 Thanks @crh-code.
  • Gateway authentication retries now send stored device tokens only to true loopback endpoints, not remote hostnames that merely resemble 127.* addresses. #99859 Thanks @ly85206559.
  • The /pair mobile setup flow now accepts local IPv6 ULA and link-local Gateway addresses without requiring TLS or a different advertised host, while public cleartext URLs remain blocked. #101008 Thanks @zhangguiping-xydt.
  • Device owners can approve the request ID most recently shown by openclaw devices list after a reconnect, without weakening protection against newly expanded scopes. #98145 Thanks @romneyda.
  • Swift native clients now support device-scoped skill approvals, with the reviewer-device field encoded in their generated Gateway models. 1403c64
  • Gateway sign-in tracking now keeps bounded memory use during floods of failed attempts from many addresses while preserving existing lockouts. #96224 Thanks @eleqtrizit.
  • #### Permissions and approvals
  • Browser control now requires the same administrator permission through direct node invocation as through the standard browser request path, preventing write-only credentials or third-party plugins from gaining elevated access. #85916 Thanks @eleqtrizit, @laphilosophie.
  • Only the configured owner can now change whether a group responds to mentions or every message through /activation. #97838 Thanks @pgondhi987.
  • Starting or changing native Codex sessions now requires owner or operator.admin access, while other authorized senders retain read-only inspection. #97952 Thanks @eleqtrizit.
  • ACP session lifecycle and runtime controls now require an owner or internal Gateway administrator instead of being available to any authorized channel user. #97953 Thanks @eleqtrizit.
  • Approving a node that can handle sensitive browser traffic now requires administrator permission, matching the security level already required to use that capability. #104491 Thanks @yetval.
  • Authorized non-owner chat participants can no longer inspect or change owner-controlled MCP server configuration through /mcp. ad5a26c Thanks @joshavant.
  • Auto-reply diagnostics now remain owner-only instead of allowing non-owner participants to run the command. 170bf72 Thanks @joshavant.
  • After an agent is removed, its leftover sessions can no longer start new model runs through the Gateway. #97260 Thanks @obviyus, @pick-cat.
  • Non-owner Gateway chat users are no longer offered the protected cron, gateway, or nodes control tools, even when those tools are otherwise allowlisted. #102030 Thanks @pgondhi987.
  • Trajectory exports from chat now require owner authority, preventing other command-authorized channel users from retrieving sensitive session artifacts. #97840 Thanks @pgondhi987.
  • Gateway-wide Active Memory can now be changed only by owners or administrators, while other authorized users retain session-level controls. #97841 Thanks @pgondhi987.
  • Only owners and administrative Gateway clients can now turn Memory Core dreaming on or off through /dreaming, while status and help remain available to others. #97869 Thanks @eleqtrizit.
  • Non-admin Telegram and Discord users can no longer change the Gateway's Talk voice, though they can still view the current and available voices. #97874 Thanks @eleqtrizit.
  • Installing or reconfiguring Codex Computer Use resources now requires owner or administrator access, while other authorized senders can still inspect status. #97955 Thanks @eleqtrizit.
  • Authenticated owners can use their already-granted shell, file, process, Skill Workshop, and plugin tools in WebChat without extending those permissions to guests or external senders. #101271 Thanks @fuller-stack-dev.
  • With strictInlineEval enabled, versioned Python and PyPy commands plus additional PHP and R inline forms now require fresh explicit approval rather than inheriting executable trust. #96216 Thanks @eleqtrizit.
  • In shared channels, only the person who started a Claude Code command can approve or deny its tool permission requests. #98256 Thanks @eleqtrizit.
  • Running /prose now shows operators the transitive remote imports and asks for consent before OpenProse fetches those code dependencies. 259877d Thanks @joshavant.
  • Codex plugin users can allow read-only app actions while requiring a fresh approval for every write or destructive action. #97123 Thanks @kevinslin.
  • Codex plugin apps now avoid approval prompts for read-only actions, preserve per-app write policies across recovery, and refresh their app inventory after upgrades. #97327 Thanks @kevinslin.
  • Windows exact-path execution approvals now launch the approved executable rather than a same-named program from the working directory. #98260 Thanks @eleqtrizit.
  • The Codex plugin now names per-action destructive approval mode ask, making it clear that each write or destructive action remains available but requires confirmation. #98501 Related #98499. Thanks @kevinslin.
  • Exec approval prompts now display and transmit long command text containing emoji or malformed Unicode without broken characters or encoding failures. #99566 Thanks @mikasa0818.
  • The Control UI terminal is now explicit opt-in, opens tabs under the selected agent's workspace and policy, and closes affected shells when accepted access restrictions tighten. #100081 Thanks @rayncc.
  • Windows companion-node exec policies can now be viewed and updated through node-aware approvals commands and displayed correctly in Control UI. #101669 Thanks @vincentkoc.
  • Using jq through exec now requires an explicit trusted allowlist entry or approval instead of being treated as a harmless stdin-only safe binary. #102032 Thanks @pgondhi987.
  • Always-allow approvals for npm exec, npx, pnpm, and yarn wrappers now apply to the actual command rather than unintentionally trusting different future payloads. #102035 Thanks @pgondhi987.
  • Skills created by agents now remain pending for Skill Workshop review and approval instead of becoming active immediately without the expected safeguards. #98346 Related #96054. Thanks @momothemage, @xianshishan.
  • Status and diagnostic tools can now identify stale exec approval follow-ups intentionally suppressed after /new or /reset instead of treating them as unexplained delivery failures. #98293 Thanks @bsniznd.
  • Codex /btw side conversations now preserve an ask-mode plugin app's requirement to obtain approval before destructive actions. #98812
  • Long Codex app-server approval details and command previews now preserve emoji and extended Unicode characters instead of showing corrupted text. #100177 Thanks @xialonglee.
  • Strict exec approval now keeps joined or clustered interpreter inline-code commands such as python3 -xcprint as one-time approvals rather than reusable allowlist entries. #101353 Thanks @pgondhi987.
  • Long exec auto-review explanations containing emoji or supplementary CJK characters now shorten cleanly instead of showing a broken replacement symbol. #101513 Thanks @wm0018.
  • Plugin approval titles and descriptions now remain readable when emoji or supplementary CJK characters fall at the Gateway's text limit. #101580 Thanks @wm0018.
  • #### Channels, users, and conversation separation
  • Agents using OpenClaw's cron tools are now limited to their own scheduled jobs and session targets, while operator-managed cron remains unchanged and mixed-version setups fail closed with an openclaw gateway restart instruction. #96883 Thanks @joshavant.
  • Cron wake actions started by an agent now remain within that agent's own session lanes, reducing the chance of waking another agent's conversation. #97949 Thanks @eleqtrizit.
  • Write-scoped Gateway clients can still perform supported message actions but can no longer supply identity fields that masquerade as a trusted requester or owner. #102031 Thanks @pgondhi987.
  • Multi-user bridges using openclaw agent --agent ... --channel ... --to ... now keep recipients in separate sessions when per-recipient isolation is configured. #101507 Thanks @pingfanfan, @vincentkoc.
  • Read-only voice-call status now omits phone numbers, transcripts, routing details, processed event IDs, and raw metadata. #97870 Thanks @eleqtrizit.
  • #### Plugin and skill download checks
  • ClawHub now checks community plugin and skill releases before download, blocking prohibited releases and requiring explicit acknowledgement for suspicious ones while leaving existing installs in place when an update is skipped. #81364 Thanks @jesse-merhi.
  • #### Activity history
  • Authorized operators now have a durable audit history for agent and tool activity, with filters, stable paging, bounded JSON export, configurable recording, and automatic retention limits. #98704
  • #### Security checks and guided fixes
  • Operators using workspace repairs can now run doctor --fix to disable policy-denied Gateway HTTP endpoints without removing nested URL-fetch settings. #99731 Thanks @giodl73-repo.
  • openclaw security audit now warns that per-agent skill allowlists do not prevent shell-capable agents from reaching globally configured MCP servers. #98352 Thanks @momothemage.
  • Managed deployments can now require entries such as system.run in gateway.nodes.denyCommands, and Policy doctor warns when configuration drift leaves a privileged node command available. #99121 Thanks @giodl73-repo.
  • policy check --json now tells administrators whether each finding is automatically repairable, needs review or manual work, is validation-only, or is unsupported. #99686 Thanks @giodl73-repo.
  • Operators who explicitly enable Policy workspace repairs can now automatically narrow several unsafe settings, while OpenClaw remains read-only without that opt-in. #99690 Thanks @giodl73-repo, @omarshahine.
  • Policy workspace repairs can now add required tools to the affected deny list while preserving existing entries and avoiding unintended root-policy widening. #99700 Thanks @giodl73-repo.
  • Policy workspace repairs can now move reported open channel groups to allowlist mode and require mentions without changing inherited defaults. #99720 Thanks @giodl73-repo, @omarshahine.
  • doctor --fix now shows the exact gateway.bind=loopback or gateway.nodes.denyCommands change needed for sensitive findings without applying it automatically. #99776 Thanks @giodl73-repo.
  • openclaw security audit now reports Browser exposure only when plugin policy actually allows the Browser plugin to run. #97732 Thanks @amtellezfernandez.
  • #### Network request protections
  • Provider, channel, media, and web requests can now reach public destinations through a managed proxy even when local DNS is unavailable or differs from the proxy's DNS. #98951 Related #98925. Thanks @momothemage, @sandl99.
  • Malformed MCP OAuth failures now return a bounded HTTP-status diagnostic instead of allowing an unbounded error response to exhaust agent memory. #98143 Thanks @pick-cat.
  • Under strict SSRF policy, remote-browser discovery can no longer redirect OpenClaw from the configured CDP endpoint to a different host, port, or security mode. cbc833a Thanks @vincentkoc.
  • Oversized or never-ending responses from supported external providers now stop at a fixed limit with a labeled error instead of consuming memory until the full body arrives. 0a14444 Thanks @joshavant.
  • Web fetch and provider integrations now enforce response-size caps without allocating an entire nonstandard response in memory. #99884 Thanks @zenglingbiao.
  • Trusted custom provider hosts are now protected from DNS rebinding into local services; intentional loopback aliases must use an explicit local origin or enable allowPrivateNetwork. #100835 Thanks @machine3at.
  • Browser-control requests now reject oversized successful JSON responses with a BrowserServiceError before they can consume excessive memory, while supported large browser results still work. #100889 Thanks @mushuiyu886.
  • Browser automation now keeps Chrome control traffic tied to the configured or explicitly allowed CDP host, reducing the risk that a discovered debugger address redirects credentials or control elsewhere. #101171
  • Hidden control characters can no longer break terminal hyperlink boundaries or inject control behavior through documentation link text. #96440 Thanks @lin-hongkuan.
  • MCP include and exclude filters with many wildcard segments now reject nonmatches quickly instead of stalling tool discovery for minutes. #100330 Thanks @lsr911.
  • Anthropic and Gemini PDF analysis now blocks unsafe private-network redirects and oversized responses by default while still supporting configured local endpoints. #97872 Thanks @eleqtrizit.
  • Anthropic requests through Cloudflare AI Gateway now receive OpenClaw's standard private-address blocking, timeouts, retry guidance, and managed response safeguards. #98003 Thanks @wangmiao0668000666.
  • #### File, path, and configuration protections
  • Sandboxed agents with host browser control disabled can no longer reach a signed-in host browser through a paired browser node. #97958 Thanks @eleqtrizit.
  • Hooks and skills no longer activate from unsafe inherited configuration values, while ordinary configured paths and explicit defaults continue to work. #59694 Thanks @yonganzhang.
  • Unsafe, malformed, or unexpectedly large fd and ripgrep helper archives now fail early and clean up after themselves instead of putting agent setup at risk. #98988 Thanks @leonidaslux, @vincentkoc.
  • Config show, set, and unset now operate only on values truly stored in the user's configuration, preventing inherited object state from masquerading as saved settings. #99846 Thanks @vincentkoc, @zenglingbiao.
  • Terminal requests with an unknown agent ID now fail clearly instead of falling back to global defaults and potentially opening a host shell outside the intended agent boundary. 3601dca
  • The Windows installer now accepts patched SQLite runtimes, rejects unsafe or unreadable ones, and reports the detected version when another Node.js upgrade is required. 28db140 Thanks @vincentkoc.
  • Managed host tools no longer inherit the active Conda environment from the shell that launched OpenClaw, avoiding unintended Python and package-manager behavior. #99425 Related #99424. Thanks @krissding, @ooiuuii.
  • OpenShell workspace file operations now stay inside the validated local sandbox mirror, with unsafe symlink, hard-link, cross-root, and changing-directory cases failing cleanly. c6f5725 Thanks @joshavant.
  • Config recovery now warns when the file was repaired but its final permissions could not be hardened, preserving the recovery while exposing the security issue. #95348 Thanks @hugenshen.
  • Installing or updating ClawHub skills, plugins, and packages on Linux no longer risks changing shared /tmp permissions and disrupting unrelated services. #101246 Thanks @ch3ch2cho2021, @yangxiansheng.
Official App Updates
  • Across first-party client surfaces, conversation lists, command palettes, notifications, media, connection state, and file or diff views behave more consistently. Shared keyboard, path, status, Talk, and voice behavior is less likely to drift between clients, and failures leave clearer recovery paths.
  • The Android, iOS, and macOS apps add refreshed navigation, voice-message and Watch reply workflows, multiple Gateway profiles, background location options, and many chat and connection fixes. Cached state, trust, push settings, and the selected Gateway remain better separated when people switch between installations.
  • #### Shared app changes
  • The Diffs viewer now provides a multi-file overview and direct file navigation, while PNG and PDF exports omit controls that cannot be used. #100753
  • After the Diffs viewer is reopened or refreshed, its toolbar controls now act only on the currently displayed diff cards. #96138 Thanks @brokemac79, @davinci282828.
  • Session tools now display the correct absolute path for projects beside the home directory instead of turning a shared text prefix into a misleading ~... path. #96562 Thanks @he-yufeng.
  • Realtime Talk consult calls acknowledge as soon as the embedded agent run is accepted, rather than waiting for it to finish. #101091 Thanks @romneyda.
  • Authorized remote clients can now request playable speech for an individual assistant message using the existing Gateway TTS configuration without accessing server-local files. #100770
  • ##### Android and iOS
  • Trusted Gateway clients can now browse workspace directories and preview supported files, enabling the iOS and Android apps to inspect and share agent output without SSH. #100738
  • iOS and Android users can create empty session groups, rename them once across their sessions, and remove a group without deleting the conversations inside it. #101234
  • Android and iOS now explain which side needs an update when app and Gateway protocol versions differ and avoid offering reconnect attempts that cannot succeed. #98385 Related #98384. Thanks @joshavant.
  • Mobile camera clips and screen recordings longer than 30 seconds can now finish within the existing duration limit without the request expiring early. #99455 Thanks @nianjiuzst.
  • The iOS and Android terminal pages now receive the operator credential from the connected device session, so authenticated users do not land on a terminal that cannot connect. 451190d Thanks @vincentkoc.
  • iOS and Android can now show the Gateway terminal as a focused full-screen view with stored credentials and a clear unavailable state instead of embedding the full desktop Control UI. 9c78489
  • Android and iOS Gateway setup now clearly requires Secure TLS for remote hosts, warns before trusted LAN use without encryption, and offers actionable update guidance for protocol mismatches. #101325 Thanks @joshavant.
  • ##### iOS and macOS
  • iOS and macOS chat now show a context-usage ring that changes warning color near the limit, helping users anticipate compaction or truncation in long conversations. #101183
  • Apple native app users across 21 supported non-English locales now see translated Listen and speech-playback status controls. 0146534
  • Swift clients can now decode skill curator actions and status details such as pinned state, use counts, timestamps, archived reasons, and overlaps. ad833d7
  • Apple chat now presents fenced code with theme-aware highlighting and GitHub-style tables as aligned native tables on iOS and macOS. #100207
  • Apple chat now restores the visible in-progress state after backgrounding or reconnecting, preventing overlapping sends and reconciling one correct final reply. #100277
  • iOS chat now shows and switches the active model, while iOS and macOS model pickers support pinned favorites and the five most recent choices. #100774
  • Display equations in iOS and macOS chats now appear as readable, accessible typeset math, with horizontal scrolling for wide formulas and raw text retained for malformed expressions. #100829
  • iOS and macOS hide the thinking-level control for models that cannot use it, avoid sending stale unsupported settings, and restore the previous level when a reasoning-capable model is selected again. #100875
  • Streaming replies in iOS and macOS chats now reveal text more smoothly word by word, while reduced-motion users still receive immediate text and completed messages remain unchanged. #100884
  • iOS and macOS users can preview a safe link's title and description inside chat before deciding whether to open it. #101198
  • Expanded link previews on iOS and macOS can now show a safe page thumbnail, with the existing text card retained when image loading fails. #101387
  • Finished iOS and macOS chat replies now typeset inline LaTeX formulas while streaming text, code, currency, and invalid math remain readable as plain text. #101388
  • iOS chat and macOS webchat users can search, pin, rename, archive, restore, and reopen sessions from the in-chat switcher instead of scrolling a simple recent list. #101053
  • ##### Native app localization and design
  • Transcript export controls, chat actions, and export failure messages are now translated across 21 supported native app locales. 45f561a
  • Supported non-English native apps now translate newer app information, support links, and message retry, delete, and waiting-to-send states. 82f5ac1
  • Broader native app setup, chat, Talk, permission, connection, session, provider, and status text now uses the selected language across the language packs updated in this release. Sources: a39b07b, f8e1e0c, db27d2e, 28a8414, e8e96bf, 6ea407d, 0011a18, 8c5adbf, 019603d, d3d7282, 267898c, 55ed57a, c54dc67, fd0355d, 49726a5, 2ffeedf, #98043, beca2b1, 4078dc7, e7e98f6, 3020f78, 0c82908, 8a3935f, 3f289fd, 203a896, 6afef15. Thanks @yeager.
  • New-chat and worktree-chat entry points now appear in the selected language across supported Android and Apple app locales. 24bca38
  • Supported non-English native apps now cover more Gateway setup, session, provider, health, messaging, terminal, and device text without English gaps. 52f1e05
  • Refreshed native language packs now cover workspace files, sharing actions, folder states, Android SMS guidance, message delivery states, and related branding. a9b0a9a
  • Supported non-English native apps now translate the new Terminal destination, Gateway setup guidance, Back action, connection messages, and OpenClaw branding. e069cb2
  • Native app onboarding and AI connection guidance now reflects Crestodian and the current setup flow across supported non-English locales. Sources: ad4809f, f0ecc16.
  • Native app command search now translates loading, unavailable, retry, and no-result states across the languages updated in this release. Sources: 745d2d0, 7f7bec7, 35be1c8, 7db67ab, 4bc5766, 0672720, 2a8cd44, fd648fb, 00b0b40, a67990a, 7640f67, 15f4819, 4d1d720, d1d3a27, c2737d5, bd3263d, 127ce63, 0c960cd, e6c3ad9, 84c86f7, e7aea60.
  • Native chat controls for jumping to the latest message or reply now use the selected language across the translations in this release. Sources: e31fa36, 375def8, aabe44f, 48c3f4b, 3db6fb9, a4b51e5, a60686d, 12e17ec, 6c4ac0c, bdc6258, a775f9f, a1f6acc, ee9f61d, f188c66, 2525078, ed5ccda, a6a4792, 0924bee, 0420aef, d23c4fd, 37f0067.
  • Native prompts for starting work, checking status, using phone and voice controls, pairing, and returning to Chat now use the selected language across the translations in this release. Sources: dd050bc, db72ffd, 4997802, 2dc7bd1, 4381c29, 9eb1a05, 7838bc8, 4352eaf, 43fe5cc, 6bd1a4b, 531af42, 305715c, 8f9e163, 2abad57.
  • Native app status and appearance choices now use the selected language across the translations in this release. Sources: 58d199b, c15348b, c047a3a, e191685, b1e173d, 50fecf8, 5211afe, 4c43cf5, fb394de, ba8c1fa, 7bee4f6, 77ab268, 2417d94, 9b6ef34, 9c4274f, 2671bcc, b21153b, 117e8e1, cc0d7e1, e6f3f54, dd64f66, 4c16e66, 3a8375c, 3e3b6d6, c356245, d506201.
  • Native app license notices, acknowledgements, and unavailable-file explanations now use the selected language across the translations in this release. Sources: 34bf5a9, 068088c, a623ac7, 71374d3, a9b0de8, 8f495e2, 436dd39, f917e89, 2c8b97c, ace162b, e60cccf, 359ea4c, b7bc860, 49ea27e, 99cbc58, 204526a, 3821c36, 030d184, 24f639c, 499feb2, 591d099.
  • Native photo-permission controls now explain limited, selected, and recent-photo access in the selected language across the translations in this release. Sources: c360f92, 4dd027e, 9cde1ca, 328fb70, 71e5fcc, b11d710, 55a2a9b, c4b40d0, 3a1b983, dea40a5, 4b1fab8, 44ca739, d36452c, a50a59e, 49b68e1, 122e4ba, 4086d35, 547a563, 538f28a, c5afa92, 32a986d.
  • Native skill availability, Gateway setup, diagnostics, privacy, and access guidance now use the selected language across the translations in this release. Sources: fdcd5c0, 26f6735, 5220eff, bb7dbda, 952245b, edb1e74, f7bad57, 0602930, e779b8f, 0400be7, 851d0ad, 1e0dd95, 703e1ad, 1c93e50, 37c45f2, 8fe917b, da21e4b, f4f63b1, 3e4febb, a82cd35, 52323b6.
  • Native Gateway connection, diagnostics, permissions, onboarding, Chat, and Talk guidance now uses the selected language across the translations in this release. Sources: 3b27bb4, e296d14, 5516775, 6ec4962, 291f2a4, 7e2d41b, 81bc96f, 574556c, 8bb44e6, ae09908, 42fc19d, 28bbb43, 6ff9185, 4be0be6, 0f1fbbe, d893a72, f5cb29b.
  • Wake Words and Discovery Logs now use current, natural labels across supported non-English native app locales. de30d2f
  • Supported non-English native apps now translate workspace file browsing and sharing, image preview failures, offline status, and custom Gateway header controls. 6b99fd9
  • OpenClaw's mascot now uses the same float, blink, antenna, and claw animations across web, iOS, and Android surfaces while respecting reduced-motion preferences. 851156a
  • #### Android
  • ##### Setup, navigation, and app tools
  • New Android users now get a guided first-run path through setup-code or QR entry, Gateway pairing, node approval, permissions, recovery steps, and confirmed phone readiness before onboarding completes. #98752 Thanks @jesse-merhi.
  • Android users can open an agent-workspace shell from Settings > Terminal, with clear connection guidance and Gateway credentials passed without placing the token in the URL when supported. fcd7eb6
  • Android users can sideload the official signed OpenClaw-Android.apk from a stable GitHub release and verify it with the published SHA-256 checksums. #101212
  • Android node reconnects now point users from a failed devices approve attempt to the correct openclaw nodes approve <requestId> command, including a reminder to reuse connection flags. #98115 Thanks @welfo-beo.
  • Android SMS commands now clearly distinguish phone permission from the Gateway's separate opt-in, allowing read-only sms.search without also enabling sms.send. #100993 Thanks @narcissus0702.
  • Android notification forwarding now leaves WhatsApp, Telegram, Discord, and Signal messages with their dedicated channel sessions, preventing duplicate or wrong-conversation replies while other selected apps continue to follow forwarding rules. #101170
  • Android Canvas content can no longer navigate to device-local web services, while normal remote and Gateway-hosted pages continue to work. #99874 Thanks @ly85206559.
  • Android release builds no longer expose detailed camera.clip settings, device data, temporary paths, and recording events in production logs. #99484 Thanks @nianjiuzst.
  • Android Back navigation now returns users from Gateway or Talk settings, Sessions, and Providers to the Voice, Chat, or command-palette tab where they started. #98914 Thanks @lokimorty.
  • Android now presents evenly spaced bottom tabs and avoids the chat-cache startup crash that could block entry to the post-onboarding shell. #100382 Thanks @iwhatsskill.
  • Android's Home overview now uses more consistent card, Talk, and recent-session spacing for a calmer, easier-to-tap first screen. #100059 Thanks @iwhatsskill.
  • Android's command palette now keeps action and session rows visually aligned, with consistent icons, navigation spacing, and clean truncation for long labels. #101072 Thanks @iwhatsskill.
  • Android users can open a scheduled job to inspect its timing, payload, delivery state, recent results, errors, and exact ID. #95107 Thanks @tosko4.
  • The Android Files card now lets users browse the active agent workspace, preview text and images, and share output directly from their phone. #100776
  • Android users can now read bundled third-party and open-source license notices directly from Settings > Licenses. #99299 Thanks @joshavant.
  • Android's About screen now clearly identifies OpenClaw and provides direct links to the website, documentation, source repository, and Discord community. #100994
  • ##### Chat and sessions
  • Android Chat now includes a New chat action and a / command browser that filters the current agent's advertised commands without dropping command arguments. #98796 Thanks @iwhatsskill, @solvely-colin.
  • Android Chat now lets users choose and verify the configured agent for new messages, with Chat, Talk mode, and the home canvas staying aligned to that selection. #80422 Thanks @bcperry.
  • Android chats now render links, lists, quotes, emphasis, code, and plain text consistently through the shared Markdown renderer. #88899 Related #88014. Thanks @iman-sharif, @pluviobyte.
  • Android chat now adds light- and dark-mode syntax highlighting to supported fenced code, making code-heavy replies easier to scan without delaying partial or oversized messages. #100217
  • Android chat now restores an active response with buffered text after reconnecting or reopening, and recovers missed event gaps without duplicating transcript rows. #100384
  • Android chat now keeps sent messages and active replies stable through reconnects, reconciling delayed history without duplicate turns or stale composer activity. #100551
  • Android chats now keep internal reasoning, tool results, and raw operational details out of both live conversations and reopened offline caches. #100826 Thanks @iman-sharif.
  • Android users can long-press a completed chat message to copy all text, select an excerpt, share it, or quote it in a reply without losing their current draft. #100879 Thanks @bdhwan.
  • Android chat users can preview a link's destination and summary before opening it, without messages triggering background lookups and with a clear unavailable state when inspection fails. #100898
  • Android's model picker now stays aligned with the active chat and agent, and a failed model change no longer sends the next message with the previous model. #100985
  • Android hides thinking controls for models that do not support configurable reasoning, prevents unsupported settings from breaking live or queued sends, and restores the user's preference on compatible models. #101002
  • Android users can search sessions by name, label, or key beyond the currently loaded Recent or Archived window, with cached active-session matches still available during a temporary Gateway outage. #101102
  • Android users with a physical keyboard can press Enter to send a chat message while modified Enter combinations remain available for multiline text. #101321 Thanks @3ninyt3nin-creator.
  • Android users can now see safe page thumbnails in expanded link previews, while bad or blocked images quietly leave the text preview intact. #101396
  • Android users can now archive a chat session and delete it from the Archived view even with the app's bounded operator permissions. #101522
  • Android users with a hardware keyboard can now send from the chat composer with Enter, while an unaccepted send still preserves the draft. de8db74 Thanks @vincentkoc.
  • Android users can switch the current chat's model from the composer, pin favorites, revisit recent choices, and return to the default without leaving the conversation; older pairings may need to be renewed. #100798
  • Android chat now renders top-level display LaTeX as readable equations while invalid or still-streaming math remains visible as text. #101435
  • Android's thread picker now prioritizes real conversations, hides internal setup and device sessions, and still makes valid older chats available through All. #99557 Thanks @ly85206559.
  • Returning to an already loaded Android chat no longer flashes a loading screen, and the Overview recent-session list stays deduplicated and steadier during refreshes. #100966 Thanks @solvely-colin.
  • Android Home's Recent Sessions section now keeps recently active rows in a stable order, collapses duplicates, and preserves labels and timestamps during partial live refreshes. #101161 Thanks @solvely-colin.
  • Android physical-keyboard users can press or hold Enter to send once without leaving a stray newline, while Shift+Enter and in-progress input-method composition keep working. #101360 Thanks @3ninyt3nin-creator, @joshavant.
  • Expanded Android link previews now keep thumbnail memory within a byte budget, reducing excessive memory retention during long chats. #101560
  • ##### Gateway setup and connections
  • Android can now keep multiple Gateways paired and switch among them without repeating setup, while each Gateway retains its own credentials, chat state, queued messages, and removable local data. #100947
  • Android Gateway actions now stop promptly when their connection closes, while requests started after reconnect are not cancelled by old cleanup. #98067 Thanks @nianjiuzst.
  • Android connection recovery now identifies expired setup codes, stale credentials, and missing or invalid authentication with the appropriate next step. #98094 Thanks @qingminglong.
  • Android can reconnect to the same Gateway without erasing saved access when credential fields are blank, while endpoint and setup-code changes avoid carrying stale credentials silently. #98277 Thanks @solvely-colin.
  • Android now gives clearer TLS verification guidance for reachable remote and Tailnet Gateways and allows slow valid handshakes more time to show the trust prompt. #98366 Related #98365. Thanks @joshavant.
  • Android can now pair with local Gateways advertised by standard cleartext .local names while continuing to reject unsafe remote or ambiguous cleartext addresses. #98439 Thanks @joshavant.
  • Scanning a valid Gateway setup QR code on Android now starts pairing immediately and advances to recovery or approval instead of leaving users on setup. #98483 Thanks @joshavant.
  • Android Gateway setup now replaces a generic authentication warning with specific recovery labels for expired setup codes, missing or invalid credentials, stale saved authentication, and required device identity. #98698 Related #98046. Thanks @ccaprani, @masatohoshino.
  • Android gateway setup now gives specific recovery actions for expired codes, stale credentials, pending node approval, and terminal authentication failures. #99414 Related #98045, #98046. Thanks @ccaprani.
  • Android manual Gateway setup now defaults blank ports to 18789 for ordinary TLS and cleartext hosts while retaining port 443 for Tailscale MagicDNS. #99865 Thanks @ly85206559.
  • Saved Android Gateway sessions now reconnect promptly when validated internet access returns, without unnecessary retries during captive or partial network changes. #100347 Thanks @ly85206559.
  • Android Gateway settings now give connection details, setup fields, and helper text more stable space on phone-sized screens, reducing clipping and crowding. #100363 Thanks @iwhatsskill.
  • Android now isolates cached conversations and queued commands when users re-pair, sign out, or replace Gateway credentials, preventing a new identity from inheriting the previous one's data. #100454
  • Android onboarding now finishes after permission-triggered node approval instead of trapping users in a loop between the Permissions and approval screens. #100959
  • Android users can now connect to Gateways behind Cloudflare Access or another authenticating reverse proxy by saving the required credential headers in Advanced manual-connection settings. #100765
  • When Android Chat cannot reach the Gateway, users can open Gateway Settings or copy connection diagnostics directly from the blocked screen. #94566 Thanks @tosko4.
  • Android manual Gateway setup now accepts IPv6 hosts such as ::1 directly instead of rejecting an address that works only when entered as a bracketed WebSocket URL. #99107 Thanks @ly85206559.
  • Android manual setup now accepts and preserves complete ws://, wss://, and HTTP Gateway addresses, including embedded ports, so private-LAN onboarding reaches the intended server. #99110 Related #87216. Thanks @cursoragent, @ly85206559, @ruben2000de.
  • Android setup now rejects gateway URLs with unsupported IPv6 interface zones and directs users to an unscoped address or LAN hostname before saving. #99570 Thanks @ly85206559.
  • Android now preserves specific Gateway and A2UI error codes containing numbers, such as A2UI_HOST_UNAVAILABLE, instead of replacing them with a generic failure. #99591 Thanks @ly85206559.
  • Android Gateway settings now show both setup actions as full-width buttons, keeping Pair New Gateway readable and easy to tap. #100090 Thanks @iwhatsskill.
  • The Android app now respects a user's disconnect, connect, or gateway-switch choice during startup and reports final disconnect failures to fire-and-forget callers. #101799
  • ##### Voice and Talk
  • Android users can record and send a voice note of up to three minutes from the chat composer without entering live Talk mode. #101193
  • Android background push-to-talk requests now return NODE_BACKGROUND_UNAVAILABLE instead of attempting a microphone start that the operating system may reject. #98055 Thanks @nianjiuzst.
  • Android now reports Realtime Talk and Dictation readiness separately, opens setup only for the mode that needs it, and keeps useful provider failure details visible. #98269 Related #98268. Thanks @solvely-colin.
  • Android Talk and Dictation now use a connected Bluetooth headset microphone for hands-free capture and fall back cleanly when it disconnects. #99259 Related #96241. Thanks @gwtaylor.
  • Android push-to-talk now takes exclusive microphone control during Talk Mode and resumes the correct realtime listener afterward, preventing duplicate capture. #99986 Thanks @nianjiuzst.
  • Android push-to-talk now cleans up backgrounded, cancelled, or retried captures without reopening the microphone or stopping a newer voice session, and overlapping requests return busy. #100552 Thanks @xialonglee.
  • Android users can now long-press an assistant reply and choose Listen, with visible playback status, tap-to-stop, and on-device speech fallback. #100772
  • Android Talk Mode now keeps push-to-talk busy until the active turn is safely handed off, preventing overlapping microphones, stale playback, or the wrong relay resuming. #100786
  • Android voice features now speak only chat events explicitly identified as assistant replies, preventing user, tool, system, or role-less text from being read aloud. #99123 Thanks @ly85206559.
  • Android Talk now applies supported directive values even when generated or dictated JSON uses different capitalization for keys such as Voice or Language_Code. #99592 Thanks @ly85206559.
  • Android Talk Mode now delivers agent-consult answers even when realtime completion events arrive out of order, preventing sessions from remaining stuck on Thinking.... #100049 Thanks @qingminglong.
  • Android Voice and Talk setup text now truncates cleanly on narrow screens and at larger accessibility font sizes instead of appearing clipped. #100060 Thanks @iwhatsskill, @solvely-colin.
  • The Android Voice tab now gives Realtime Talk and Dictation text and controls enough room to remain readable on phones and at larger font sizes. #100491 Thanks @iwhatsskill.
  • ##### Device permissions, notifications, and capture
  • Third-party Android builds can allow Gateway-requested location checks while the app is in the background by selecting Location > Always and granting Android's persistent location permission. #100967 Thanks @ioridev.
  • Android notification automations now queue accepted events during Gateway connection or reconnection and deliver them in order once the link is ready. #92602 Related #79552. Thanks @ashishpatel26, @hectorrp13.
  • Android one-shot camera captures now turn the camera and privacy indicator off promptly after success, failure, or cancellation. #98040 Thanks @nianjiuzst.
  • Android's selected-photos permission now counts as usable access, allowing photos.latest while clearly showing how to manage the limited selection. #98059 Thanks @nianjiuzst.
  • Android onboarding now marks Contacts and Calendar ready only after both read and write access are available, including when those permissions arrive in separate prompts. #99158 Thanks @nianjiuzst.
  • Android now reports Contacts and Calendar access as granted only when both reading and adding entries are authorized, preventing misleading setup results. #99204 Thanks @nianjiuzst.
  • The Android companion no longer forwards OpenClaw's own notifications back to the Gateway, even when older allowlists still include the app package. #99568 Thanks @ly85206559.
  • Android third-party onboarding now recognizes SMS access when send and read permissions are granted in separate prompts, while genuinely missing permissions remain unauthorized. #99147 Thanks @nianjiuzst.
  • Cancelled, timed-out, failed, or interrupted Android camera.clip requests now release the camera and remove unfinished temporary files before later camera commands run. #99153 Thanks @nianjiuzst.
  • Android node commands now honor common boolean values such as yes, no, 1, and 0 for app filters and camera audio options. #99873 Thanks @ly85206559.
  • Tapping an Android notification created by system.notify now brings OpenClaw to the foreground. #100888
  • ##### Localization
  • Android's "New chat in worktree" action is now translated across supported non-English locales instead of appearing with a missing resource. #100805 Thanks @amknight.
  • Android users in supported languages now see key Gateway setup, connection, trust, shell, and recovery prompts in their device language. #97111 Thanks @vincentkoc.
  • Indonesian Android strings ship under Android's recognized locale; the same prior-release work also prepared the 2026.6.11 Play version and store text. 3412318 Thanks @joshavant.
  • Traditional Chinese users now see localized wording for common native app actions, permissions, connection messages, and mobile states. f0d2066
  • Android now explains in the selected language how to keep a saved token or replace an existing Gateway setup. Sources: 32f3eb3, 6336762, eeb0682, ed72b86, e376f28, a6631fe, 283bd82, 6d5a1db, d3087fc, 8bab3f7, dfb7bc8, 7780e30, b109b88, c1b7bf2, dedb17c, 6f84c10, a8358e8, 2501ca3, 1b40eb9, d47308f, 3a2baef.
  • Android pairing and connection failures now provide localized next steps for expired codes, credentials, approvals, and retries. Sources: 48eae1b, f095eb9, 714c2b0, d2b5bb7, d2551bd, 6b91507, f1c4476, 5ef6fb4, e2e0312, 7fb70b2, d702f5c, 24e6b9f, 7cb41cc, a6040c3, 5e61da3, 18360ac, 17a1e3b, adafb56, 5b5fadb, 9b30570, d331a36.
  • Android Gateway discovery, QR and manual setup, connection checks, approvals, and permission guidance now use the selected language across the translations in this release. Sources: 28062c8, 3d43858, ad74b32, 1b07620, 4fa4c9e, 1dd5230, 9db7ec5, e6f8788, e5cf67e, b52d988, cd3b4ee, c3bcb9f, 8af3aa0, c34e79e, c9c8f6c, 255e251, 0e98ba4, 0cc9927, 97955d9, ba449f2, 0e22e54, ae65251, d957f5a.
  • Android now explains in the selected language when a scoped IPv6 address must be replaced with an unscoped address or LAN hostname. Sources: 5793f73, 066e697, bf35947, 3385817, a0a5054, 66cb9a9, 3da73a7, df659ec, 57a3975, 141b2cf, b043adf, dcc4fa8, eade8f1, 72a8098, 355fa77, 8cc1786, a3ef37b, cb9ac50, cab8147, 7cc3cb0, ca258fb.
  • Android license notices, acknowledgements, empty states, and open-license actions now use the selected language across the translations in this release. Sources: 4b8b60f, 3b16c41, c4966e8, 116e9db, 1617233, a598c97, 3b9e0c8, eebbf6c, 4c08ea4, 21be45c, b415072, 9eec24d, de23987, 898564e, 7af800b, a47ec8d, fac9e58, 61e4ef0, 399f9d6, 9069f69, 2e049f5.
  • Android Talk, dictation, speech-provider setup, readiness, and failure guidance now use the selected language across the translations in this release. Sources: c785196, 9edb906, da67520, 88f13ca, e878efe, 662d127, 5002a0e, fe57718, ebcf8dc, 4e7ca8e, 9863ceb, 768da09, ff5d986, 005ebd1, 2824796, 4eaec93, f99fdc9, 555f601, d2af689, 81e92de, 8ed6c78.
  • Android command search and New Chat labels now use the selected language across the translations in this release. Sources: b81c58b, 8929118, 1eee853, a5c9662, 9035729, 2e359d4, 91f4d0a, e785c4a, 2c5a076, 02250d9, bf23194, 603502f, a837a1a, 26df1fa, c926610, c312f9f, f4275fa, 69d4657, 3e66eb9, db5057e, 1fee4a5.
  • Supported non-English Android builds now localize offline Gateway queue guidance and the Retry and Delete actions for text messages. 660d752
  • Supported non-English Android builds now translate more cron inspection, delivery error, copy feedback, default-state, and agent request details. d83ee4c
  • Android model organization, default-model, and pinning controls now use the selected language. Sources: 41bea62, bdc98f4.
  • Android link-preview controls and status messages now appear in the selected language across refreshed locales. 9997c53
  • The Android background-location explanation, settings action, and Not Now choice now appear in the selected language when Always location mode is offered. 4c38d89
  • #### iOS and Apple Watch
  • ##### Navigation, settings, and app information
  • Opening Control -> Terminal on iOS now goes directly to the terminal without briefly showing the general Web UI login screen during connection. #100727
  • iOS users can open Terminal directly from the Control hub, see a Gateway setup prompt when disconnected, and keep active shell sessions running through unrelated screen updates. 211e0d7
  • The iOS Control, Chat, Talk, Agent, Settings, Gateway, and Overview screens now use clearer navigation, status cues, controls, and a compact expanding chat composer. #98452 Thanks @joelnishanth.
  • The iOS Control, Agents, and Settings screens are now easier to scan, with fewer duplicate destinations, more compact controls, standard navigation, and a direct Gateway shortcut from detail views. #98811 Related #98803.
  • Chat, Talk, Settings, navigation, and onboarding on iPhone and iPad now use more consistent native controls, appearance, and back behavior. #99231 Related #99195. Thanks @marvkr.
  • On iPad, selecting Overview, Chat, Talk, or another sidebar destination now leaves the current Settings detail and opens the requested screen. #94991 Thanks @solvely-colin.
  • The iOS app now opens to Chat for normal launches while preserving direct navigation to Control, Settings, Agent, Talk, and nested destinations. #98353 Thanks @bsniznd.
  • iOS Control, Talk, and Settings are easier to scan with clearer status emphasis, safer action styling, calmer idle visuals, and improved large-text support. #98423 Related #98397.
  • iOS connection, warning, and information text is now easier to read in light and dark modes, and Appearance settings accurately describe the selected behavior. #98443 Related #98440.
  • iOS users who open Gateway, Voice, or Notifications settings from another screen now return to the Chat, Talk, Agent, Control, or Approvals screen they came from. #98898 Thanks @lokimorty.
  • The iOS app now applies OpenClaw's palette consistently across Talk, settings, Gateway, privacy, usage, and workboard views while retaining accessible contrast. #98930 Thanks @joelnishanth.
  • iPhone users who open Chat from a Control detail can now return to that same Overview, Activity, Workboard, or Sessions screen without losing their place. #99245 Thanks @solvely-colin.
  • iOS users can now read OpenClaw's bundled third-party license acknowledgements from Settings > Licenses. #99290 Thanks @joshavant.
  • On iOS 26, affected Settings switches now respond when users tap anywhere on the labeled row, with accessibility labels and values preserved. #99888 Thanks @ly85206559.
  • Talk and Settings rows on iOS now use consistent title sizing and typography, making adjacent options easier to scan. #100515
  • The iOS About screen now presents OpenClaw branding, license information, and direct links to the website, documentation, GitHub repository, and Discord community. #100531
  • Equivalent rows in the iPhone Control and Settings tabs now use the same rounded icon treatment, making both lists easier to scan. #98936 Related #98916. Thanks @sahilsatralkar.
  • The iOS About screen now shows a concise app, device-family, and iOS summary without duplicated identity or a raw hardware identifier. #98985 Related #98943. Thanks @sahilsatralkar.
  • The iOS appearance setting now sits in the normal Settings list, shows the current System, Light, or Dark choice at a glance, and behaves consistently on iPad. #99052 Related #98995. Thanks @sahilsatralkar.
  • The iPhone Control destination list is now denser and easier to scan without changing navigation or status information. #99468 Related #99439. Thanks @sahilsatralkar.
  • Already-paired iPhone users now return to Chat, Talk, and Settings instead of being trapped in setup when older onboarding flags are stale. #101481
  • ##### Chat and sessions
  • Images shared from iOS or through node agent.request now remain attached to the correct conversation turn after history reload, so later messages can still use them. #86936 Thanks @peterdsp.
  • iPhone and iPad users can now browse an agent workspace, preview generated files, logs, and configuration, and share a file without returning to the host computer. #100767
  • Native iOS Chat now follows Larger Text and Dynamic Type settings for messages, the intro, and composer text with less clipping. #97552 Thanks @jmcte.
  • Native iOS Chat now gives the conversation more room, uses a compact composer that grows with longer drafts, and keeps attachment, Talk, and send controls comfortably tappable. #98953 Related #98929.
  • iOS Chat now keeps one final assistant reply per turn instead of briefly showing a duplicate that disappears after history refreshes. #98117 Related #98116. Thanks @joshavant, @ooiuuii.
  • iOS Chat now preserves intentional line breaks in assistant responses and other multiline messages without disrupting normal Markdown rendering. #98304 Related #98028. Thanks @jabato01, @joshavant.
  • The iOS chat experience now offers useful starting prompts, clearer pairing and setup actions, better agent placeholders, and steadier message ordering during refreshes. #99243 Thanks @jcooley8.
  • iOS chat now lets users browse, filter, and select available commands and skills from the composer instead of memorizing exact slash commands. #99426 Thanks @solvely-colin, @viczhang6.
  • iOS chat now provides tactile feedback for accepted sends and most completed or failed runs, though some abort paths may still omit or misclassify failure feedback. #100416
  • iOS users can export the current conversation as a named, readable Markdown file and save or send it through the system share sheet. #100417
  • Offline iOS messages now survive relaunch, remain tied to their original Gateway and conversation, and send once only when delivery can be confirmed, with clear uncertain-delivery status when it cannot. #100942
  • Tapping the iPhone status bar now leaves the chat at the top for reading older messages until the user chooses Jump to latest. #100502
  • ##### Voice, Talk, and Apple Watch
  • Translated Gateway controls on iOS and approval actions on Apple Watch no longer fall back to English in supported locales. #97112 Thanks @vincentkoc.
  • iOS voice notes now stay with the intended chat and recover more reliably across offline queues, app recreation, uncertain sends, and competing microphone use. #101236
  • The iPhone app now presents a compact Talk control bar, a cleaner Appearance picker, and a properly aligned realtime-audio button beside the resting Chat composer. #98736
  • Apple Watch users can dictate a message and hear OpenClaw's final reply on the Watch, with separate silent-send, cancel, and stop controls. #100283
  • iOS users can record and send a voice note of up to three minutes from the chat composer, optionally add text, and see the recording's duration in chat. #100946
  • Paired iOS users can start native ElevenLabs Talk with a SecretRef-backed Gateway key without copying the credential into plaintext mobile configuration. #98210 Related #98209. Thanks @joshavant, @ooiuuii.
  • iOS Talk's Gateway Default now uses the configured Gateway speech provider, and stopping a reply prevents delayed audio from leaking into later turns. #98376 Related #98153. Thanks @jraxworthy, @tony-ooo.
  • OpenAI Realtime Talk on iPhone now uses native WebRTC by default, recovers continuous sessions from provider disconnects, and respects speaker, Bluetooth, and AirPlay output choices. #98563 Thanks @pollybot13.
  • The iOS Talk fallback banner now opens Voice & Talk settings directly instead of sending users to unrelated Gateway settings. #98602 Related #98593. Thanks @pollybot13.
  • Voice Wake on iOS can now pause while Talk, camera audio, or another feature uses the microphone and resume without crashing the app. #99137 Thanks @pollybot13.
  • Apple Watch pairing and companion status now refresh without restarting the iPhone app, while cold-launch actions wait for readiness or return a clear WATCH_UNAVAILABLE error. #100732
  • iPhone users can now choose Listen on an assistant reply, follow preparation and playback status, stop at any time, and fall back to on-device speech when needed. #100771
  • Apple Watch quick replies now survive an unavailable iPhone and reconnect later to the intended Gateway without being lost, duplicated, or misrouted. #100372 Thanks @nianjiuzst.
  • OpenClaw now uses consistent branded typography throughout its iOS, Watch, and Live Activity interfaces while retaining Dynamic Type and accessibility support. #99246 Thanks @joelnishanth, @joshavant.
  • ##### Gateway setup and connections
  • iOS users can pair multiple Gateways once and switch among them while keeping credentials, trust, chats, preferences, device access, and push registration attached to the correct Gateway. #100948
  • iPhone users pairing with a LAN Gateway now stay authenticated after the one-time bootstrap so Chat and the node connection do not immediately disconnect. #98066 Related #98064. Thanks @ooiuuii.
  • After scanning an iOS pairing QR code, users now move to a live connection-progress screen instead of returning to Welcome while pairing continues invisibly. #98302 Related #98297. Thanks @joelnishanth.
  • iOS now explains secure Gateway connection and certificate-verification failures precisely and reliably presents the fingerprint trust prompt for first-time HTTPS connections. #98429 Thanks @joshavant.
  • New iPhone users now get clearer QR, setup-code, and manual Gateway choices, better nearby and connection status, and a direct handoff to Chat after connecting. #98868 Thanks @solvely-colin, @thats2easyyy.
  • iOS users can correct gateway details after a failed manual setup and retry immediately with the values currently on screen. #99220 Related #99219. Thanks @abdullahtas0.
  • iOS gateway QR pairing now stays open through trust and approval, avoids scanner crashes, and keeps credentials and pending actions with the correct gateway during switches. #99572 Thanks @pollybot13.
  • Repeated iOS Gateway setup links now update the visible settings screen with the newest connection instead of being consumed by a hidden view or replaying stale details. #100328
  • The iOS app can now connect through Cloudflare Access, Basic authentication, and similar proxies by storing per-Gateway credential headers for the next reconnect. #100768
  • iOS pairing codes can now advertise both local and Tailnet Gateway routes, allowing the phone to save the first reachable address when it is away from the private LAN. #100317
  • iOS Gateway connection errors now appear as one dismissible toast that returns for a later failure and visibly reacts instead of stacking when the same problem repeats. #98856 Thanks @lokimorty.
  • The iOS QR setup scanner is less likely to crash or become unstable when users open, cancel, or close the camera during onboarding. #101235 Thanks @joshavant, @solvely-colin.
  • ##### Permissions, location, and capture
  • iOS location settings now explain Off, While Using, Always, Precise Location, restrictions, and permission mismatches in the selected language across the translations in this release. Sources: 3542585, 261d79a, ef1474d, cc1d61b, 2a1e118, 748bfee, e0b2dda, f371a2f, ee00cc7, 27f9ae0, 51a07ae, ba9d167, 576169e, 10500a6, a344252, d7d280f, cb2547f, 2191c2e, c63e9f9, 4b1e0de, 525c4c7.
  • iOS location settings now show the permission that is actually in effect, including Precise Location and mismatches between OpenClaw's selected mode and the iOS grant. #99247 Thanks @pollybot13.
  • iOS users can now add contacts and search affected records without crashing the app or disconnecting the node. #99475 Thanks @abdullahtas0.
  • iOS Calendar, Reminders, and Contacts commands now return an immediate permission-required result instead of opening a prompt that leaves the agent request waiting. #99477 Thanks @nianjiuzst.
  • Choosing While Using for location access on iOS now remains selected after approval and after the app is relaunched. #100512
  • The iOS screen.record command now finishes more reliably with a nonempty MP4 instead of crashing the app and disconnecting the node as recording stops. #101550 Thanks @tony-ooo.
  • The iOS app now recovers when a location permission prompt returns without a clear decision instead of waiting indefinitely. 75c8753 Thanks @vincentkoc.
  • Cancelling or interrupting an iOS screen.record request now stops the system recorder instead of letting capture continue after the tool call fails. #99155 Thanks @nianjiuzst.
  • iOS now recognizes Limited Photos access as usable, offers in-app controls for requesting or managing the grant, and avoids interrupting gateway requests with a surprise prompt. #99350 Related #99046. Thanks @tony-ooo.
  • The iOS camera permission prompt now clearly connects access to Gateway setup and assistant-requested photo, video, document, screen, or workspace capture. e77994e Thanks @joshavant.
  • #### macOS
  • ##### Setup and local agent
  • Localized macOS builds now translate the new GitHub link label, including its accessibility-facing text, instead of falling back to English. 8be1d36
  • macOS onboarding now translates local Gateway installation, checks, repairs, retries, paused setup, and resume guidance across the languages updated in this release. Sources: 7a717b7, 85d31e1, 27778a7, cffc6ad, ab0d604, 972d394, edbbdf6, 863a054, ef5650f, 5f2e51f, 5769416, a3aa917, 2f7bd01, c54a6f3, 9c3ffc5, 469e707, d066a81, 72a3b71, 63aa909, b68e2e7.
  • macOS users can run Codex Computer Use desktop controls through managed installation without a manual appServer.command, and an outdated Codex Desktop app-server no longer blocks a supported plugin-local binary. #96730 Thanks @bdjben.
  • New Mac users can now open the app and reach a working local agent without Terminal, Homebrew, administrator access, or an extra approval prompt for the app's own node. #99767 Related #99764.
  • macOS onboarding now verifies the chosen AI connection before first chat, presents clearer local and remote setup choices, and offers friendly recovery or a verified manual API-key path when authentication fails. #100288
  • macOS onboarding now offers the Gateway's supported text-inference provider catalog instead of only Anthropic, OpenAI, and Google, and tests credentials before saving them. #101132
  • First-run macOS setup now recognizes a successfully saved Codex login and is less likely to finish with a stale Gateway or bundled-skills warning. #101218
  • After openclaw doctor --fix archives a legacy sidecar, the macOS app no longer recreates it or triggers the same migration conflict warning on every command or Gateway start. #99039 Related #98917. Thanks @momothemage, @p51moustache.
  • Repeated pairing repair attempts now produce one usable macOS approval prompt per device instead of stacking stale alerts that cannot complete approval. #100976
  • On macOS, an explicit OPENCLAW_STATE_DIR now stays isolated from the machine's existing App Group pairing identity and device tokens. #101779
  • ##### Remote mode and Gateway reliability
  • macOS remote mode can now connect through explicitly selected managed SSH aliases and recover app-owned tunnels when SSH multiplexing or backgrounding is enabled. #99661
  • Finder-launched macOS sessions can now use SSH aliases backed by common user-installed ProxyCommand helpers without losing agent state or failing Gateway readiness checks. #100214
  • Multiple macOS app instances now preserve shared SSH tunnel tracking and clean up stale processes more reliably, reducing port conflicts after a crash. #100601
  • The macOS Dashboard now follows a restarted remote SSH tunnel to its new local port automatically and keeps authentication tokens out of logged URLs. #100488
  • After a macOS crash or force quit, OpenClaw now reclaims confirmed orphaned remote-mode SSH tunnels so relaunches can reuse the preferred local Gateway port. #100489
  • The macOS menu-bar app now uses fewer idle CPU wakeups and less repeated configuration and permission work, reducing background battery use without changing active status behavior. #100463
  • Long-running system.run commands on the macOS app node no longer make the node appear offline or block unrelated Gateway traffic. #100842 Thanks @lvan185, @vincentkoc.
  • The macOS app no longer mistakes a valid launchd-managed local Gateway for an unexpected listener and terminates active assistant or channel work. #100867 Thanks @lsr911, @vincentkoc.
  • The macOS app now keeps the same paired device and node identity across upgrades, restarts, and Gateway reconnects instead of repeatedly asking for approval or creating stale duplicates. #101105 Thanks @yetval.
  • ##### App design and launching
  • The Mac app now shows the animated OpenClaw mascot in onboarding and About, while Reduce Motion keeps it still. f052a2f
  • The macOS onboarding and About mascot now more closely matches openclaw.ai with theme-aware colors, glow, hover scaling, and smoother motion that keeps its antennae visible. 05c9dcc
  • The Mac About screen now links directly to the OpenClaw website, documentation, GitHub project, and Discord community, matching the other native apps. 6e7ef63
  • Opening OpenClaw again from the macOS Dock or Finder now brings up the dashboard or its failure window even when the menu-bar app is already running. #97637 Thanks @solvely-colin.
Terminal UI and Other Clients
  • #### Terminal conversations and recovery
  • openclaw tui now finds the custom port of an active local Gateway automatically, so users usually do not need to repeat its URL with --url. #73338 Thanks @haishmg, @vincentkoc.
  • Gateway-backed and local TUI sessions now display assistant text as it arrives instead of appearing quiet until the final response. #83000 Thanks @flashosophy.
  • The TUI now explains when repeated invalid tool arguments abort a run, giving users a useful correction clue without exposing sensitive inputs. #91002 Thanks @taerlandsen, @wsyjh8.
  • Typing indicators now remain active during long Codex model, tool, command, recovery, and queued follow-up work instead of making the reply appear idle. #95844 Thanks @jalehman.
  • Shortened exec and bash summaries now keep emoji and other supplementary characters intact around the ellipsis instead of displaying a broken replacement glyph. #96963 Thanks @bartok9, @ly-wang19, @vincentkoc.
  • Replies triggered through Telegram or another external channel now appear only once in the terminal UI after history refreshes, while resets, session switches, delayed events, and in-progress recovery continue normally. #96980 Thanks @xialonglee.
  • Long assistant and provider errors now end cleanly when emoji or rare Unicode characters land near the display limit. #97289 Thanks @zenglingbiao.
  • The TUI now directs users to the pending device or scope-upgrade approval command instead of incorrectly sending them through chat-DM pairing. #98144 Thanks @romneyda.
  • Embedded and local TUI sessions now contain event-consumer errors instead of terminating the terminal. #100117 Thanks @cxbasdev.
  • TUI users can now submit prompts while an agent is working and receive the configured followup, collect, or interrupt behavior, with Esc and /stop canceling only the intended work. #100123 Thanks @kevinlp, @sebtardif.
  • TUI /new now performs a real session transition with the expected lifecycle hooks and prevents a new session from racing an active turn. #100241 Thanks @caopulan.
  • Terminal Hatch onboarding and other TUI connections now show starting up until session loading finishes, with accurate running indicators after reconnects. #93999 Thanks @ml12580.
  • Repeated submits while the TUI agent is busy now update one warning instead of flooding the conversation with duplicate notices. #99879 Thanks @vincentkoc.
  • openclaw tui --local now explains when a known slash command requires the Gateway instead of sending that command to the model as an unwanted prompt. #100188 Thanks @goslingmanagment.
  • Workspace skill approvals started in the TUI now appear in that terminal, so users can review and unblock the run without switching to Telegram. #100251 Thanks @vincentkoc.
  • The terminal UI now stays open and shows a safe, useful error when a local shell command, slash command, or message submission fails. #100340 Thanks @cxbasdev.
  • #### Codex CLI session lists
  • Codex CLI session lists now shorten long last-message previews without splitting emoji or similar characters into broken text. #96582 Thanks @llagy007, @weeli-009.
Plugins and Packaging
  • Skills can be drafted from a conversation or source, reviewed, pinned, archived, restored, and kept out of future context when stale. Plugin management is clearer about discovery, installation, updates, marketplace snapshots, connected Codex apps, approvals, and runtime failures, while Codex supervision can give each new thread an explicit bounded app allowlist.
  • Official packages are easier to obtain through the supported Docker and Android paths, and plugin-backed workflows such as Google Meet and Apple Messages recover from more setup and migration problems. Doctor also handles damaged migration caches and older plugin or skill layouts without turning a recoverable upgrade into a dead end.
  • #### Skills and personal workflows
  • Users can turn a conversation, file path, URL, or pasted note into a reviewable Skill Workshop proposal with one message instead of starting from a blank draft. #100442
  • Long-running agents can automatically retire unused Skill Workshop skills from future context, pin important ones, restore archives, and surface possible overlaps without deleting the underlying skills. #101214
  • The opt-in Logbook lets users review a model-organized workday timeline, generate standups, and ask questions about captured activity, with owner-only local storage and configurable retention. #99930
  • Skill archive validation and upload hashing errors now identify the missing or unreadable file while preserving the original filesystem error. #101085 Thanks @cxbasdev, @vincentkoc.
  • The bundled xurl skill now shows a working Node/npm installation path, and the github skill no longer advertises an unsupported Linux apt option. #102158 Thanks @not-stbenjam.
  • #### Codex apps and connected agents
  • Owner-operated native Codex agents can now use selected apps already connected to the operator's Codex account, with a bounded per-thread allowlist and existing approval controls preserved. #100973 Thanks @pash-openai.
  • Updated integration runtimes keep Codex, ACP, Copilot, Telegram, and diff rendering aligned with compatible upstream behavior, while reconnect recovery no longer floods operator logs with duplicate messages. #100027
  • Configured and accessible native Codex plugin apps now remain available when a new OpenClaw thread starts during an app-inventory and activation-state transition instead of disappearing silently. #96872 Thanks @kevinslin.
  • #### Plugin workflows, hooks, and media
  • Changes made by plugin hooks now reach agent and child-run context, including replacements or removals made by agent:bootstrap. #97281 Thanks @outdog-hwh.
  • Embedded context-engine plugins now see the current turn in the transcript during afterTurn, preventing missing first messages and duplicate imports. #97342 Thanks @gorkem2020, @iwhatsskill, @sgh6688, @udjin79.
  • Windows can now load valid inbound media when configured roots and runtime file paths differ only in letter casing. #97630 Thanks @vectorpeak.
  • Plugins can now react when a new DM pairing request is created, enabling owner alerts, audit records, tickets, and approval integrations without polling. #97733 Thanks @clawsean, @omarshahine, @trupe-rs.
  • Provider plugins that mask text now restore intended values inside tool-call inputs before messages, file operations, and other external actions run. #97769 Related #97761. Thanks @get-viti, @zoowh.
  • Plugin and media workflows now handle malformed or truncated ffprobe output without crashing while continuing to read valid video dimensions normally. #98613 Thanks @pick-cat.
  • Ordinary Lobster run and resume approvals no longer fail TaskFlow-only validation simply because unused default flow fields were present. #102036 Thanks @arthurnie, @lilan0125, @vincentkoc.
  • #### Plugin marketplace and development
  • Operators can run openclaw plugins marketplace refresh to verify and save a hosted feed, enforce a SHA-256 match, and see whether live, saved, or bundled data was used. #96155 Thanks @giodl73-repo.
  • openclaw plugins init can now scaffold a model-provider plugin with authentication, model setup, tests, packaging, validation, and ClawHub publishing structure. #94352 Thanks @patrick-erichsen.
  • Existing plugin discovery keeps the same bundled official catalog while gaining a versioned, fail-closed fallback format for the hosted marketplace work. #95846 Thanks @giodl73-repo.
  • ClawHub marketplace reads now fail back to OpenClaw's bundled plugin catalog when hosted data is unsafe or unusable, providing a guarded base for the new marketplace workflow. #95868 Thanks @giodl73-repo.
  • A hosted marketplace can keep serving its last verified catalog when the feed is unchanged or briefly unavailable, without trusting stale or invalid saved data. #95877 Thanks @giodl73-repo.
  • The latest verified hosted marketplace catalog can survive a restart and remain available through unchanged responses or temporary feed failures, with persistence still optional. #95964 Thanks @giodl73-repo.
  • Hosted marketplace entries become installable only when they match approved local sources and trusted ClawHub packages, preventing unknown or untrusted choices from slipping into installation. #95969 Thanks @giodl73-repo.
  • Administrators can configure named hosted marketplace feeds and the trusted local package sources those feeds may reference, while unsupported trust settings are rejected. #95981 Thanks @giodl73-repo.
  • The new openclaw plugins marketplace entries command lists available hosted plugins, versions, and install choices while showing whether results came from live, saved, or bundled data. #96158 Thanks @giodl73-repo.
  • Marketplace diagnostics now show whether refresh and entries commands used a hosted feed, a saved snapshot, or a fallback without logging feed secrets. #96194 Thanks @giodl73-repo.
  • Plugin authors can now import shared textResult and jsonResult helpers from openclaw/plugin-sdk/tool-results instead of recreating common response shapes. #99740 Thanks @romneyda.
  • Plugin authors now have a shared formatByteSize helper for consistent byte labels, while existing labels across OpenClaw remain unchanged. #99768 Thanks @romneyda.
  • #### Plugin installation, updates, and repair
  • Migration agentDir values beginning with ~ now resolve against OpenClaw's effective home. #99901
  • Starting QR login without a required official channel plugin now returns the exact installation command or openclaw doctor --fix instead of only saying the provider is unavailable. #90517 Related #83277. Thanks @carol-iung, @tuaran.
  • Plugin update failures now report the real npm metadata or registry problem instead of disguising it as an unsupported package specification. #96143 Thanks @brokemac79, @romneyda, @slideshow-dingo.
  • Operators can install a pinned older ClawHub plugin when that version is compatible with their OpenClaw deployment, without the latest release's requirements incorrectly blocking it; incompatible or unverifiable versions remain blocked. #96506 Thanks @isaiahstapleton.
  • openclaw plugins update --all now realigns trusted official plugins with the current stable or beta catalog after a core upgrade, without manual force installs or overwriting intentional targeted pins. #96831 Thanks @ooiuuii, @velvet-shark.
  • openclaw plugins update <id> --dry-run now tells operators when a newer default release exists even if the installed plugin is pinned exactly. #97282 Thanks @yungchentang.
  • Windows plugin updates no longer create managed paths so long that official Codex-backed agents fail before they can start and reply. #97488 Thanks @ooiuuii.
  • openclaw update now accepts valid bundle-format marketplace and ClawHub plugins without package.json, preventing plugin sync from aborting and leaving the Gateway stopped. #98010 Related #97985. Thanks @herove, @lilan0125.
  • openclaw/memory-lancedb can now install and update under normal npm dependency resolution, keeping LanceDB-backed memory active without version pinning or bypass flags. #99118 Related #90295. Thanks @allenhurff, @joshavant.
  • Installing a managed npm plugin no longer makes workspace plugins from plugins.load.paths disappear after startup or restart. #99196 Thanks @leonidaslux.
  • Git-backed plugin installs and updates now work when ~/.openclaw and the system temp directory are on different filesystems, without a TMPDIR workaround. #99896 Thanks @bartok9, @carelvanheerden, @vincentkoc.
  • Extended-stable users can install, repair, and update eligible official plugins at the exact OpenClaw core version instead of drifting onto the regular stable line. #100448 Thanks @kevinslin.
  • openclaw update no longer retries a plugin after successfully moving it to ClawHub, preventing a redundant transient failure from disabling the migrated plugin. 3ce26d6 Thanks @vincentkoc.
  • openclaw doctor can continue legacy dedupe migration when a retired cache file contains malformed JSON instead of stopping with a parsing error. #98125 Thanks @pick-cat.
  • Plugin install and update failures now show whether npm exited, was killed, or timed out instead of presenting a blank error that makes valid packages look invalid. #98497 Thanks @sanjays2402, @vincentkoc.
  • Failed plugin installations now show the useful plugin error without adding a false Also not a valid hook pack diagnosis, while genuine hook-pack failures remain visible. #100554 Thanks @vincentkoc.
  • #### Plugin runtime, status, and diagnostics
  • Declared plugin tools now remain callable in subagent sessions after plugin registry changes, avoiding repeated plugin tool runtime missing failures and Gateway restarts. #82562 Thanks @luoyanglang, @vincentkoc.
  • Plugin metadata cache hits no longer flood diagnostics with repeated full-scan entries, leaving smaller timelines where real scans are easier to identify. #86796 Thanks @galiniliev, @vincentkoc.
  • Plugin loading no longer evaluates OpenClaw's own package code twice, reducing startup work and avoiding duplicate module, class, singleton, or registry identities in one process. #88384 Thanks @vincentkoc.
  • openclaw plugins inspect now shows the bundled document-extract plugin's PDF extractor as an available capability instead of reporting none. #91597 Thanks @xydt-tanshanshan.
  • Configured context-engine plugins such as lossless-claw now stay active after discovery instead of being silently replaced by the built-in legacy engine. #96357 Thanks @vincentkoc.
  • Gateway startup now reports configured channels that failed to load, so operators can fix plugin trust, enablement, or installation before messages go missing. #96397 Thanks @849261680.
  • Plugin-heavy startup and configuration checks, especially on Windows, now repeat fewer package-path lookups while rebuilding installed-plugin fingerprints, making those paths more responsive. #96710 Thanks @211-lee, @sheyanmin, @vincentkoc.
  • /status plugins now labels a plugin as loaded only when it is actually running, while still showing healthy installed inventory. #97479 Thanks @masatohoshino.
  • Raising a running Gateway's log level to debug now immediately enables Mattermost, Matrix, Microsoft Teams, IRC, Nextcloud Talk, and other plugin diagnostics without a restart. #97617 Thanks @amknight, @vincentkoc.
  • Detailed /status plugins now flags a plugin that was configured to run but did not load, separating runtime drift from ordinary inactive inventory. #97878 Thanks @masatohoshino.
  • Plugin loading now honors operator-configured Jiti native-module exceptions while retaining protection against duplicate OpenClaw package evaluation. #100344
  • Bundled channel setup plugins now load correctly through current-release symlinks and mixed source/dist layouts without false outside-package warnings. #100758
  • Source checkouts with a partial bundled plugin tree now retain complete built-in metadata for plugin health checks and provider endpoint discovery. 26c0285 Thanks @vincentkoc.
  • The GitHub Copilot plugin no longer breaks openclaw plugins list or openclaw status during metadata-only loading before full runtime state is available. #95229 Related #94516. Thanks @cuihaijun, @sunlit-deng.
  • /status plugins now groups disabled plugins by reason, including allowlist, denylist, default, and override decisions, without changing activation behavior. #99598 Thanks @masatohoshino.
  • Bundled channel runtime and setup plugins now load from valid source-only registry roots in mixed source/dist checkouts instead of silently disappearing. #100737
  • Duplicate plugin-request scopes now normalize consistently, and genuine plugin scan access failures are surfaced. #99932
  • #### Packages and platform installs
  • Official OpenClaw container images are now available from Docker Hub as well as GHCR, reducing reliance on unofficial mirrors. #97122 Thanks @vincentkoc.
  • Docker users now get a more complete bundled AI runtime, reducing startup and runtime failures caused by package links removed during image trimming. 57ca1b0 Thanks @vincentkoc.
  • Affected npm installations can once again start the Gateway and produce replies because speech now loads only through its supported package-backed TTS path. #89899 Thanks @zhangguiping-xydt.
  • OpenClaw npm packages are now about 3.18 MB smaller unpacked and 371 KB smaller compressed, with plugin SDK entrypoints and runtime behavior unchanged. #98758 Related #98757. Thanks @romneyda.
  • Source and macOS package builds no longer fail when the tsdown configuration is loaded from a temporary directory that cannot resolve the runtime package. #100499
  • Global npm upgrades can continue as OpenClaw's packaged files grow without hitting InstalledDistScanLimitError, while runaway scans remain bounded. #101206
  • Source builds now work on supported Node.js distributions without native TypeScript stripping, avoiding a late failure tied to --experimental-strip-types. #91262 Thanks @smoe, @vincentkoc.
Docs and Admin Tools
  • #### Setup and configuration
  • ##### Onboarding and guided setup
  • openclaw onboard now explains up front what setup covers, why full onboarding can take longer, and which optional steps can be postponed. #97482 Thanks @ly85206559.
  • Crestodian on Claude Code or Gemini CLI can now hold multi-turn setup conversations, inspect state, request exact approval for changes, and verify writes instead of falling back immediately to a single-turn planner. #100029
  • Crestodian setup and repair chats no longer destabilize the local TUI when a terminal event consumer fails during response delivery. #100341 Thanks @cxbasdev, @vincentkoc.
  • Crestodian now distinguishes ordinary questions from operational requests, accepts natural approval phrases, clears stale proposals, and keeps sensitive configuration out of the conversation model. #100656
  • Fresh git installs now lead users through setup, or give the exact command to finish later, before missing configuration or Gateway authentication can break first use. #101901 Thanks @fuller-stack-dev.
  • Setup now checks the configured custom agent or auth directory for credentials instead of reporting the wrong bootstrap state from a default location. 0fd69dc Thanks @vincentkoc.
  • ##### Configuration editing and live reload
  • openclaw config now recommends a Gateway restart only when the changed settings require one, so hot-loadable agent, model, and provider edits no longer prompt unnecessary restarts. #80823 Thanks @kiranmagic7.
  • Removing a visible built-in model alias now explains that the alias is automatic and shows how to shadow it, while genuinely absent aliases still report as not found. #81641 Thanks @scientificprogrammer, @vincentkoc.
  • openclaw config unset now explains when a visible value is an inherited runtime default that is not stored in the user's config, avoiding an unproductive loop between config get and config unset while leaving failed attempts unchanged. #96557 Thanks @moeghashim.
  • Configuration and plugin-schema validation hints now show clear allowed values instead of the misleading literal label undefined. #99045 Thanks @lzyyzznl.
  • Valid openclaw.json files with a BOM, PowerShell formatting, or deep indentation can now save authentication, model, repair, and other configuration changes without manual reformatting. #100591 Thanks @vincentkoc.
  • Upgrades from the legacy config-health store no longer repeat a permanent conflict warning, and existing recovery backups remain available without overwriting newer observations. #99728 Related #99280. Thanks @ccbridle, @jalehman, @joshavant.
  • Repeated configuration warnings are now suppressed between meaningful recurrences, keeping long-running Gateway logs readable without hiding new diagnostics. #100569 Thanks @vincentkoc.
  • Gateway settings marked as no-restart now take effect in live and heartbeat-driven turns without requiring a manual restart. #100586 Thanks @obviyus, @sedrak-hovhannisyan.
  • Gateway config.patch now accepts unrelated configuration updates when a bundled provider uses its default endpoint, without saving empty runtime-only provider fields. #98396 Related #98270. Thanks @momothemage, @weltmaister.
  • Gateway configuration updates now reject missing redacted values for keys such as toString or constructor instead of restoring an inherited JavaScript function. #99152 Thanks @zenglingbiao.
  • Manual Gateway setup now rejects port entries such as 1e3 or 0x1000 instead of silently saving a different port, while valid decimal ports remain unchanged. #98689 Related #98681. Thanks @qingminglong.
  • #### Doctor and diagnostics
  • ##### Core checks and repair behavior
  • openclaw doctor now warns when QMD session search is enabled without transcript export and provides commands and documentation to correct the missing recall setup. #80947 Thanks @anyech.
  • openclaw doctor now gives a missing-transcript preview command that actually shows the entries eligible for removal before users choose to enforce cleanup. #83630 Thanks @yuanhanzhong.
  • openclaw doctor now evaluates the default agent's actual per-agent bootstrap limits, producing accurate truncation warnings and remediation guidance. #84424 Thanks @kasangyong, @vincentkoc.
  • Gateway-managed skill checks can now find commands installed through pnpm 11 and common npm-global layouts, reducing false missing-tool warnings and unnecessary reinstalls. #85238 Thanks @shbernal, @vincentkoc.
  • openclaw doctor on Windows now detects supported Chrome versions accurately instead of warning that a working installation could not be identified. #87937 Thanks @mukundakatta.
  • openclaw doctor no longer aborts when a configured agent workspace has not been created yet, while real file operations still enforce workspace boundaries. #89226 Thanks @sasan1200, @shifengwang333-ai.
  • Gateway status, Doctor, and onboarding diagnostics now read large logs within fixed bounds and surface recent useful failures instead of stale noise. #99407 Thanks @sunlit-deng.
  • Terminal notes, Doctor output, and diagnostics now wrap long runs of CJK, full-width, or emoji characters within the requested width instead of spilling across columns. #96746 Thanks @ly-wang19.
  • Default doctor --lint results now focus on actionable configuration and runtime problems, with optional backup and memory advice available only when requested. #99249 Thanks @giodl73-repo.
  • openclaw doctor --fix now completes successfully in locked-down environments when only shell-completion installation is blocked, while still reporting genuine write failures. #99540 Related #99237. Thanks @hunglp6d, @rballiance.
  • doctor --lint --all can now explain the path or permission that would block a configuration repair before operators run doctor --fix. #100093 Thanks @giodl73-repo.
  • openclaw health now warns when gateway configuration hot reload has stopped, so operators know a restart is needed instead of unknowingly running stale settings. #99267 Thanks @masatohoshino, @vincentkoc.
  • ##### Focused lint checks
  • Operators can inspect stale session write locks with openclaw doctor --lint --json --only core/doctor/session-locks and preview which locks a repair would remove or preserve. #84366 Thanks @giodl73-repo.
  • Optional Doctor lint can now report missing, unsafe, unwritable, cloud-synced, removable, volatile, or incomplete OpenClaw state storage with paths and repair guidance. #95979 Thanks @giodl73-repo.
  • An opt-in Doctor lint check now explains which configured plugin installation is broken and previews the repair before operators run the existing fix workflow. #96171 Thanks @giodl73-repo.
  • Operators can run openclaw doctor --lint --all to include every opt-in diagnostic check without changing the behavior of existing doctor --lint automation. #96471 Thanks @giodl73-repo.
  • Operators can run openclaw doctor --lint --only core/doctor/gateway-health, --only core/doctor/gateway-daemon, or --all for structured, credential-safe warnings about Gateway reachability and local service health without changing service state. #97075 Thanks @giodl73-repo.
  • Operators can use the focused auth-profile Doctor lint check to find expired, missing, malformed, cooled-down, disabled, or legacy credentials with structured repair guidance. #97125 Thanks @giodl73-repo.
  • A focused memory-search Doctor lint check now reports provider, credential, backend, and QMD setup problems with structured paths and fixes. #97137 Thanks @giodl73-repo.
  • The workspace-status Doctor lint check now reports plugin drift, compatibility, loading diagnostics, and recoverable TaskFlow state in machine-readable form. #97358 Thanks @giodl73-repo.
  • A focused device-pairing Doctor lint check now provides structured warnings and repair guidance for pending requests, stale authentication, missing scopes, and unreadable stores. #97366 Thanks @giodl73-repo.
  • Operators can request a structured Doctor lint check for configured channels whose backing plugins are blocked, including the unmet requirement and suggested fix. #97496 Thanks @giodl73-repo.
  • A focused tool-result-cap Doctor lint check now identifies settings below model-aware defaults or above the runtime ceiling with actionable paths. #97500 Thanks @giodl73-repo.
  • Linux operators can use the systemd-linger Doctor lint check to learn when logout may stop the Gateway and get the exact loginctl enable-linger remedy. #97514 Thanks @giodl73-repo.
  • Doctor lint can now identify legacy fenced HEARTBEAT.md templates and distinguish files suitable for automatic cleanup from those containing custom content. #98400 Thanks @giodl73-repo.
  • Doctor lint can now flag the combination of WhatsApp, a strained Gateway event loop, and active local TUI sessions that is associated with delayed replies. #98406 Thanks @giodl73-repo.
  • Structured Doctor lint can now report stale global plugin-runtime symlinks, including the obsolete link, its target, and the openclaw doctor --fix cleanup command. #98729 Thanks @giodl73-repo.
  • Operators can use targeted Doctor lint to inspect legacy session transcripts and stale snapshot paths, preview the cleanup, and choose whether to apply it. #95976 Thanks @giodl73-repo.
  • WhatsApp and Telegram default-account routing warnings are now available through selectable structured Doctor lint while normal Doctor output remains unchanged. #96147 Thanks @pick-cat, @vincentkoc.
  • Optional Doctor lint can now identify stale or missing plugin registry data, shadowed bundled plugins, stale install records, and broken OpenClaw peer links. #96169 Thanks @giodl73-repo.
  • Structured Doctor lint can now report low or critical disk space for the OpenClaw state directory, including the affected path, available space, requirement, and remediation. #98391 Thanks @giodl73-repo.
  • Plugin operators can run doctor --lint --only core/doctor/legacy-plugin-manifests or --all to identify legacy manifest keys and see the affected plugin, path, and repair command. #98695 Thanks @giodl73-repo.
  • Operators can use openclaw doctor --lint --only core/doctor/legacy-plugin-dependencies or --all to find stale plugin dependency state and receive a path plus safe repair guidance without changing the installation. #98725 Thanks @giodl73-repo.
  • Channel setup warnings are now available as structured Doctor lint findings with stable paths and repair guidance for operators and automation. #99238 Thanks @giodl73-repo.
  • #### CLI
  • Operators can attach an external coding harness to an existing Gateway session and work with compatible Codex-supervised threads across native and OpenClaw surfaces. Status and configuration commands provide clearer diagnostics, safer defaults, and more dependable control of sessions, services, credentials, and runtime behavior.
  • ##### Attached coding and sessions
  • openclaw attach now launches Claude Code with temporary access to the main or selected Gateway session, keeps credentials out of arguments, and revokes the grant when the session ends. #96454 Thanks @anagnorisis2peripeteia, @obviyus.
  • Owner-controlled agents can opt into appServer.homeScope: "user" to inspect and safely fork the same Codex threads available in Desktop and the CLI. #99821
  • openclaw sessions --json now includes available subagent lineage and runtime details such as parent linkage, workspace, depth, role, timestamps, and status. #87917 Related #80286. Thanks @islandpreneur007, @zhangguiping-xydt.
  • status and status --json now build session model labels with less unnecessary normalization, improving readback speed for larger session sets and incident checks. #87831 Thanks @acskamloops.
  • usage.cost and sessions.usage now reject a start date later than the end date with a clear INVALID_REQUEST instead of returning a misleading empty report. #94096 Thanks @alix-007.
  • Session cost summaries now estimate a real charge when a transcript records zero dollars despite token use and known model pricing. c5260a3 Thanks @nianjiuzst.
  • Session logs and cached cost views now preserve provider-reconciled zero-dollar totals while recalculating genuinely missing costs from stored provider and model details. c45124a
  • openclaw sessions tail --tail now rejects counts too large to represent safely instead of applying an imprecise history limit. #99398 Thanks @qingminglong.
  • A malformed transcript timestamp no longer corrupts session usage and cost records with invalid values. #99420 Thanks @krissding.
  • Session maintenance warnings now say 1 minute, 1 hour, or 1 day at rounded boundaries instead of awkward values such as 60 seconds. #100096 Thanks @narahariraghava, @vincentkoc.
  • Session maintenance warnings now show more accurate wait estimates near unit boundaries, so a roughly 90-second delay is not inflated to two minutes. 58d707f Thanks @vincentkoc.
  • ##### Status, logs, usage, and telemetry
  • openclaw logs --follow can bridge a brief local Gateway outage with journal output and automatically return to normal Gateway logs after recovery. #88159 Thanks @anyech, @vincentkoc.
  • Debug proxy capture now keeps oversized or endless response bodies from crashing the agent, while retaining useful status and header metadata. #97551 Thanks @alix-007.
  • The first Gateway status check after a restart now reports the selected model's actual context window instead of briefly showing a generic 200k limit. #97576 Thanks @turbotheturtle.
  • openclaw health now surfaces permanently failed deliveries with queue counts and oldest-failure age instead of reporting an all-green state. #99842 Thanks @masatohoshino.
  • Timing displays now roll rounded sub-second values over to 1s instead of showing the awkward 1000ms. #100006 Thanks @qingminglong.
  • openclaw logs now reports log-tail stream failures cleanly instead of crashing, hanging, or leaving journalctl running. #100850 Thanks @cxbasdev, @vincentkoc.
  • Trimmed OpenClaw CLI logs now remain valid UTF-8 when the retained byte range begins inside an emoji or other multibyte character. #101029 Thanks @ly85206559.
  • Langfuse, OpenTelemetry, and Prometheus can now capture usage, cost, model, provider, timing, and session data for runs started through /v1/responses and /v1/chat/completions. #96152 Thanks @rocke2020, @xialonglee.
  • File-backed usage-bar templates now keep watcher and file-descriptor use bounded in long-running OpenClaw processes while still reloading templates when needed. #98990 Thanks @chenyangjun-xy, @vincentkoc, @zhanglei99586.
  • Compact /status no longer shows the ambiguous Plugins: OK row, while warnings and detailed plugin diagnostics remain available. #100143
  • Failed OpenClaw and plugin-harness traces now include useful redacted error details in OpenTelemetry instead of only a generic failure label. #101244 Thanks @amknight.
  • OpenTelemetry trace viewers can now display captured tool results alongside tool inputs in standard GenAI fields, making failed-run investigation more complete. #101371 Thanks @amknight.
  • openclaw status --all now keeps shortened channel issue messages readable when an emoji falls at the display boundary. #101503 Thanks @wm0018.
  • OTLP traces, metrics, and logs now follow HTTP_PROXY, HTTPS_PROXY, and NO_PROXY, keeping diagnostics exports on the configured network path. #100616 Thanks @jesse-merhi.
  • ##### Commands, help, tables, and terminal output
  • The bounded openclaw hooks commands now return control promptly after printing their output, so terminals, scripts, and CI jobs no longer remain stuck. #76922 Thanks @dorukardahan.
  • Non-interactive openclaw models list and openclaw models status now exit normally after printing their results, allowing scripts and SSH diagnostics to finish without an external timeout. #77904 Thanks @dorukardahan, @vincentkoc.
  • TUI links now leave malformed fragments and stray punctuation as plain text while keeping valid parenthetical, IPv6, and line-wrapped URLs clickable at the correct target. #100780
  • openclaw docs now rejects oversized search responses with a clear error before they can destabilize the CLI or exhaust memory. #98188 Thanks @cxbasdev.
  • Several edge cases now preserve transcript and voice text, surface MCP failures, bound oversized responses, show current session time, choose the right Linux package manager, and use port 443 for secure Gateway links without an explicit port. #100258 Thanks @connermo, @cxbasdev, @gfaerny, @hailory, @harjothkhara, @ly85206559, @mushuiyu886, @simon-xydt, @sunlit-deng, @uditdewan.
  • Failed openclaw --help and openclaw --version startup now returns exit code 1 promptly instead of leaving the terminal process stuck. #97807 Thanks @aniruddhaadak80, @maweibin.
  • CLI tables now shorten only the actual home directory and its descendants, so sibling paths such as /home/alice2/project no longer appear as misleading home-relative paths. #98876 Related #98872. Thanks @qingminglong.
  • Message read, pinned-message, and search commands can now display more than 25 returned rows when a higher --limit is requested and warn when additional provider results remain. #99089 Thanks @jerrytao-ai, @wm0018.
  • openclaw --help now matches command-specific help and completions, with config patch and config schema visible from the main command list. #100670 Thanks @amirf194, @vincentkoc.
  • Terminal-rendered links containing balanced parentheses now remain clickable through the complete intended URL instead of being shortened or misdirected. #100697 Thanks @aniruddhaadak80, @zoowh.
  • Generated shell completion now suggests accepted OpenClaw command aliases and continues completing their options and subcommands. #99419 Thanks @amirf194, @jack-dev-ops, @vincentkoc.
  • Terminal and setup documentation links now resolve correctly when relative paths begin with http or absolute HTTP schemes use uppercase letters. #96439 Thanks @lin-hongkuan.
  • Long IDs and scopes no longer push openclaw commitments columns out of alignment, keeping the table readable at a glance. #95923 Thanks @parveshsaini.
  • #### Devices, nodes, and Gateway administration
  • ##### Pairing and node management
  • Built-in openclaw nodes status, openclaw nodes list, and related node commands now start quickly without unnecessary plugin initialization, while plugin-provided node commands still load when requested. #96702 Thanks @erhhung, @qijian-zhang, @zengwen-dt.
  • Failed openclaw devices approve attempts now explain whether to approve a scope upgrade elsewhere or refresh the pending request ID and retry. #98146 Thanks @romneyda.
  • An invalid openclaw nodes approve <requestId> now shows available pending IDs and the openclaw nodes pending recovery command instead of a raw client error. #94452 Thanks @mushuiyu886.
  • openclaw pairing list now gives a useful device-approval next step when no chat DM pairing channels exist instead of displaying a broken empty-choice error. #98142 Thanks @romneyda.
  • Node status, list, and pending-pairing views now tolerate malformed saved values and show the usable node information instead of crashing. #93930 Thanks @ly-wang19.
  • Operators can upgrade the Gateway before N-1 subordinate nodes without losing the normal update, restart, repair, status, and maintenance path for those nodes. #101109 Thanks @jtczville.
  • openclaw agents list now shows configured external channels even when their plugin is missing and provides the appropriate install or openclaw doctor --fix guidance. #95363 Thanks @hugenshen.
  • ##### Gateway status, connectivity, and recovery
  • openclaw gateway status now gives relevant credential, configuration, restart, and log guidance when a running Gateway fails its probe instead of telling operators to wait for warm-up. #98183 Thanks @masatohoshino.
  • Remote node hosts can now connect to Gateways mounted at reverse-proxy paths such as /openclaw-gw, including after daemon installation or reconnect. #97679 Related #97678. Thanks @wm0018.
  • Linux operators now see when systemd has stopped restarting a repeatedly crashing Gateway, and openclaw gateway restart can recover the latched failed service. #98291 Thanks @masatohoshino.
  • Control UI, pairing, setup-code, QR, and status links now prefer a reachable LAN address on hosts with VPNs, virtual adapters, WSL, Hyper-V, or multiple networks. #98482 Thanks @joshavant.
  • openclaw gateway status --deep can now identify Windows Firewall rules blocking LAN devices and suggest practical rule, loopback, Tailscale, or SSH-tunnel remedies. #98666 Thanks @joshavant.
  • gateway run --force now ignores malformed listener PID records during port cleanup instead of carrying invalid process state into recovery. #98371 Thanks @lzyyzznl.
  • Gateway busy-port diagnostics and forced cleanup now ignore malformed listener IDs, avoid phantom processes, and verify that a port is actually free before reporting recovery. #98505 Thanks @qiuyuang.
  • Windows now detects active Gateway listeners reliably from localized netstat output, improving port diagnostics and gateway --force cleanup without confusing established connections for listeners. #100012 Thanks @qingminglong, @vincentkoc.
  • A Gateway WebSocket 1006 disconnect now gives operators accurate connection-loss guidance instead of implying that a healthy Gateway necessarily crashed. #101219 Thanks @darren2030, @vincentkoc.
  • Windows Gateway restarts no longer depend on the findstr check that could leave a visible or hung command window blocking the handoff. #101366 Thanks @deepujain.
  • openclaw status, status --json, and status --all now respect their timeout on Linux when systemd is unresponsive instead of hanging indefinitely. #94149 Related #84698. Thanks @zengwen-dt, @zus-assistant.
  • When a local Gateway is listening but unhealthy, openclaw gateway status --deep can surface a recent likely cause such as a full disk instead of only reporting a generic disconnect. #95902 Thanks @vincentkoc, @wangbyg.
  • Remote Gateway status checks now fall back to the configured SSH target when local effective-config probing fails instead of crashing or stalling discovery. #101160 Thanks @cxbasdev.
  • #### Installation, updates, and backups
  • The supported installation and update paths preserve working state more carefully across packages, containers, and daemons. Onboarding and doctor retain choices through interrupted setup and migrations, surface actionable repair steps, and avoid silently continuing with stale services, missing plugins, or unusable model configuration.
  • ##### Installation and prerequisites
  • Shell-completion repair during openclaw doctor and updates now skips expensive plugin-command loading, avoiding unnecessary delays while full user-requested generation still includes plugin commands. #76235
  • Pressing Ctrl+C during the installer upgrade doctor now stops the flow cleanly and prevents an incomplete or failed installation from opening a stale dashboard. #76386 Thanks @sebtardif.
  • LaunchAgent-managed Gateways on permission-constrained macOS volumes now start the generated environment wrapper through /bin/sh, preventing immediate background-service exits. #89967 Related #87199. Thanks @joshdaynard, @zhangguiping-xydt.
  • Windows command lookup now honors the caller's PATHEXT, allowing valid PowerShell scripts and executables to resolve in containers, CI, and isolated environments. #98093 Thanks @wendy-chsy.
  • Windows Gateway setup now detects when Task Scheduler exits without starting a listener and can use the existing fallback launch without creating a duplicate if startup is merely late. #76245
  • Local Docker source builds are less likely to run out of memory, and failures that still exhaust memory now suggest the relevant build settings. #98119 Related #98118. Thanks @zyzo.
  • First-run skill setup on minimal machines now groups missing Homebrew, uv, or Go prerequisites into one clear note while still installing dependencies that can succeed. #99726 Thanks @fuller-stack-dev, @sedrak-hovhannisyan.
  • Installers and runtime checks now reject Node 23.0-23.10 early with supported-version guidance instead of leaving users with a broken OpenClaw CLI. #99832 Thanks @fuller-stack-dev, @vincentkoc.
  • The CLI and full-screen TUI now open with a clear recovery message when their launch directory has been deleted instead of crashing before startup. #93636 Thanks @ml12580.
  • Windows users can launch globally installed Gemini CLI and Claude Code backends through their npm command shims without immediate spawn failures or mangled prompt arguments. #101378 Thanks @wendy-chsy.
  • Failed CLI installations now clean up their temporary Node staging directories and pnpm workspace rewrite files. #103725 Thanks @sebtardif.
  • Git installs now create an openclaw launcher that keeps using the intended Node.js runtime even after the user's PATH changes. be7198f
  • openclaw plugins list now uses substantially less peak memory on fresh and already-migrated packaged installs while preserving required migration behavior. #103132
  • ##### Updates and service handoff
  • OpenClaw update checks now limit malformed or unexpectedly large npm registry responses before they can consume excessive memory. #98508 Thanks @lzyyzznl.
  • openclaw update on Windows now prevents the managed Gateway Scheduled Task from relaunching during package replacement, avoiding partially updated or mixed-version processes. #100757 Thanks @vincentkoc.
  • Managed Gateway updates now allow active work to finish within the configured drain period before timing out the service handoff. #99695 Thanks @zoowh.
  • Extended-stable Gateways now show a periodic openclaw update hint when a newer exact package is verified, without changing the installation automatically. #100438 Thanks @kevinslin.
  • Restarting, updating, reinstalling, or repairing a macOS Gateway now preserves active SecretRef-backed channel credentials instead of leaving Telegram and other integrations unable to authenticate. #99124 Thanks @mushuiyu886.
  • Update and status checks now identify malformed npm metadata as invalid JSON instead of returning only an opaque syntax error. #100338 Thanks @cxbasdev.
  • A failed Gateway replacement process during an update no longer causes an additional uncaught crash in the existing parent process. #101489 Thanks @aniruddhaadak80, @momothemage, @vincentkoc.
  • Windows update and doctor repair now move an owned legacy Startup gateway to Task Scheduler without leaving a stale process, dropping authentication, or removing the fallback too early. #101213 Thanks @vincentkoc.
  • openclaw update now targets the global Node installation that launched it, avoiding false success when Homebrew, nvm, asdf, or Volta exposes another OpenClaw copy. #101228 Thanks @buddyh.
  • ##### Backups and durable state
  • Windows backups now recover more reliably from live-write races by avoiding repeated use of the same locked temporary archive and cleaning stale retry files. #101449 Thanks @lilan0125, @vincentkoc.
  • Large session histories now produce smaller .usage-cost-cache.json files with less parsing and rewrite work, rebuilding automatically after upgrade. #99714 Related #99511. Thanks @dexhunter, @wayne524.
  • openclaw backup create now tolerates disposable runtime files disappearing during a live backup, while continuing to protect durable files under the existing inclusion policy. #98879 Related #98865. Thanks @carterstebbins23-spec, @vincentkoc, @zengwen-dt.
  • openclaw backup create on Windows now retries live-file archive races with fresh temporary paths, reducing locked partial backups and leftover retry archives. #101464 Thanks @lilan0125, @zoowh.
  • #### Scheduled work
  • Scheduled automation retains intended models, timing, state, and delivery across more restarts and edits. Tool calls and results also recover more cleanly from timeouts, malformed content, oversized output, and interrupted work instead of leaving a task looking complete when its usable result was lost.
  • ##### Cron configuration and administration
  • When cron command output is truncated, operators can still recover the earlier login or setup instruction they need without exposing its raw secret through notifications. #96393 Related #96346. Thanks @nz365guy.
  • Default cron failure alerts enabled with openclaw cron edit <job> --failure-alert now survive Gateway restarts instead of silently disappearing after reload. #96615 Thanks @liuhao1024.
  • openclaw doctor now warns when cron jobs target channels whose plugins are inactive, letting operators correct delivery before the next scheduled run fails. #98184 Thanks @masatohoshino, @vincentkoc.
  • Docker and bind-mount installations can finish legacy cron migration across filesystem boundaries, with actionable warnings and duplicate-safe retries when cleanup cannot complete. #98217 Thanks @masatohoshino.
  • openclaw doctor now explains cron jobs that still look in flight after an interrupted Gateway run and how those leftover markers are cleared on the next start. #98620 Thanks @masatohoshino.
  • Doctor now warns when enabled cron jobs are stuck in repeated failures without configured alerts, while healthy and below-threshold jobs stay quiet. #99606 Thanks @masatohoshino.
  • openclaw cron add now rejects invalid --no-output-timeout-seconds and --output-max-bytes values immediately instead of silently creating a command job without the requested limits. #96516 Thanks @zhangguiping-xydt.
  • Human-readable cron list and cron show output now reveals repeated failure streaks such as error (12x) while leaving JSON status values unchanged. #99602 Thanks @masatohoshino.
  • Operators can opt into core/doctor/legacy-cron-store to find legacy cron data that needs attention without the lint check changing any stored state. #99211 Thanks @giodl73-repo.
  • A normal Doctor lint run no longer invokes crontab -l for the optional legacy WhatsApp check unless an operator explicitly selects it. #99250 Thanks @giodl73-repo.
  • Cron jobs with a valid future run exactly on a second boundary now keep that scheduled time instead of being incorrectly treated as stale and rebased. #81731 Thanks @vincentkoc, @yashkot007.
  • Editing a recurring cron job no longer skips a run that is already due or shifts an unchanged interval schedule to the edit time. #96159 Thanks @yetval.
  • Clearing a saved Model or Thinking/Effort override in the Cron Control UI now truly restores inherited defaults, with --clear-thinking available from the CLI. #96293 Related #96287. Thanks @takamasa-aiso, @zengwen-dt.
  • Failed cron add, cron update, and cron remove commands now leave the running scheduler unchanged, so live jobs match the saved configuration and reported result. #99960 Thanks @masatohoshino, @vincentkoc.
  • Editing a scheduled job's message no longer accidentally breaks later CLI-backed runs, while explicit tool restrictions remain protected where they cannot be enforced. #100203 Thanks @obviyus.
  • Cron job updates can now remove a job-specific fallback model setting so scheduled runs inherit the global defaults again without recreating the job. #100801 Thanks @sunnyshu0925.
  • openclaw cron edit now finds jobs more reliably and with less delay on Gateways that contain many scheduled jobs, including --exact and timeout-only edits. #100836 Thanks @machine3at, @vincentkoc.
  • Editing a cron payload with --no-best-effort-deliver no longer silently changes the job's delivery mode to announcements. #100846 Thanks @machine3at.
  • Using openclaw cron edit <id> --no-best-effort-deliver on an older detached job no longer accidentally suppresses its completion announcement. #101027
  • Agent and MCP cron requests using mixed-case command labels now fail closed instead of slipping past the restriction on shell-backed agent cron jobs. #101350 Thanks @pgondhi987.
  • Replies now correctly confirm reminders scheduled through commands such as openclaw cron add instead of also claiming that no reminder was created. #101807 Thanks @bryantegomoh, @vincentkoc.
  • ##### Scheduled runs, delivery, and recovery
  • A timeout while one isolated cron job is setting up no longer restarts the Gateway or interrupts unrelated agent and scheduled work. #96396 Thanks @849261680, @brycemurray, @velvet-shark.
  • openclaw tasks maintenance --apply now preserves active cron session history even when job IDs contain spaces, capitals, punctuation, or explicit session keys. #96352 Thanks @ly-wang19, @vincentkoc.
  • Isolated agentTurn cron jobs can recover from temporarily mismatched runtime artifacts instead of failing at startup with a sourceReplyDeliveryMode error. #85249 Thanks @jerry-xin.
  • openclaw tasks maintenance --apply can now repair false lost-task records when durable cron history proves the run completed successfully. #86088 Thanks @altaywtf, @liaoandi.
  • Scheduled agent jobs now warn when ANNOUNCE_SKIP suppresses a cron completion, making missing reports and partial output easier to diagnose. #90566 Related #68561. Thanks @mibslee, @sahibzada-allahyar.
  • Catch-up cron jobs deferred briefly after startup are no longer skipped merely because an operator checks cron status before they fire. #94022 Related #93935. Thanks @richchen01, @vincentkoc, @yetval.
  • Scheduled agent turns using claude-cli or another CLI backend now start normally, while explicitly unsupported tool restrictions still fail closed. #95615 Thanks @anagnorisis2peripeteia, @obviyus.
  • Timed-out or cancelled isolated cron runs now retain their provider, model, and session details in cron_run_logs, making failed jobs easier to trace. #95943 Related #95873. Thanks @luke-renjoy, @zengwen-dt.
  • A scheduled cloud-model job that opens a response but sends no content can now move to a healthy fallback model before the entire run times out. #96096 Thanks @849261680, @velvet-shark.
  • CLI-backed workers from isolated cron jobs now exit after completion instead of accumulating and slowing the host and Gateway. #97227 Thanks @vianne-droid, @xialonglee, @yusukeit0.
  • Long cron failure alerts now preserve emoji and other supplementary Unicode characters instead of ending with a broken replacement symbol. #97298 Thanks @zenglingbiao.
  • Heartbeat fallback failures no longer send noisy chat messages made only of repeated internal error placeholders. #97364 Thanks @turbotheturtle.
  • Scheduled jobs that permit web_search now report that no usable search provider is selected instead of completing with an unusable result. #97677 Thanks @lilan0125, @riazrahaman.
  • Scheduled commitment follow-ups now stay focused on their original conversation instead of absorbing unrelated heartbeat instructions, queued context, or recovery work. #98169 Thanks @bdjben.
  • Scheduled jobs can deliver to a live chat without blocking replies or mixing background work into its transcript, and operators can clear stale childless cron tasks without cancelling active session-backed runs. #98755 Related #98121. Thanks @ethansk, @obviyus.
  • Recurring cron jobs created for current or session:<id> once again carry their selected conversation history into later runs, while isolated jobs still start clean. #98947 Thanks @ethansk, @obviyus.
  • Completed heartbeat tasks remain recorded when the quiet HEARTBEAT_OK acknowledgment cannot be delivered, reducing repeated work and duplicate follow-up actions on the next heartbeat. #100834 Thanks @machine3at, @vincentkoc.
  • #### Browser control
  • ##### Connections, profiles, and tab control
  • Browser CLI commands now accept --browser-profile before or after the subcommand, restoring existing remote-browser and WSL2 command patterns. #94431 Thanks @ml12580.
  • A stalled remote Chrome or WSL2 browser can no longer hold tab-list requests indefinitely; OpenClaw returns a bounded timeout and can reconnect on the next request. #80147 Thanks @hemantsudarshan, @keaneyan.
  • Remote-browser actions now recover from a closed or replaced selected tab by retrying without the stale tab ID, matching local browser behavior. #89086 Thanks @rhclaw.
  • Updating browser.profiles.* connection details can now take effect without an unnecessary Gateway restart or interruption to active sessions. #93827 Thanks @goutamadwant.
  • Browser automation can now act on tabs by suggested ID, tab ID, label, or unique prefix without false target-mismatch failures. #96178 Thanks @zengwen-dt.
  • Persistent managed-browser logins now survive ordinary Chrome and Gateway restarts, reducing repeated sign-ins and MFA interruptions for unattended browser work. #98284 Thanks @malashenia, @turbotheturtle.
  • Browser extensions can reconnect with a newly rotated pairing token while Browser control remains running, and old tokens continue to be rejected. a703183 Thanks @vincentkoc.
  • Remote browser CDP connections now accept URL-encoded Basic auth credentials containing spaces, at signs, and other reserved characters. #97972 Thanks @vectorpeak.
  • Running /new or /reset in a direct message now closes that conversation's managed browser tabs while leaving other people's tabs alone, even through a brief browser connection hiccup. #100792 Thanks @fmls.
  • Agents can now screenshot a selected background Chromium tab without waiting for the browser command to time out, though capture may bring that tab forward. #100857 Thanks @spencer2211.
  • Managed local browser pages can navigate normally under a restrictive browser.ssrfPolicy.hostnameAllowlist, while remote CDP endpoints and disallowed destinations remain blocked. #100986 Thanks @nianjiuzst, @sarinv.
  • Browser automation attached to an existing Chrome session now stops with a bounded error when Chrome crashes or a request is cancelled, and later requests can reconnect cleanly. #101454 Thanks @aniruddhaadak80.
  • Browser Control users who are missing Playwright now receive a working documentation pointer for installing or repairing the required browser runtime. d460635
  • Browser Control can now emulate no explicit color preference with openclaw browser set media no-preference, and invalid values list every supported choice. 9133118
  • Browser POST actions now complete on supported Node 24.16 and newer runtimes after JSON parsing while still cancelling when the client disconnects. 52044e1 Thanks @obviyus, @vincentkoc.
  • ##### Downloads, uploads, screenshots, and page data
  • CDP-backed browser navigation to CSV, PDF, and other attachment URLs now returns a safely saved managed file with its URL and suggested filename. #89416 Thanks @zhangguiping-xydt.
  • Browser downloads now tell the agent the saved filename and path, helping it use the completed download instead of retrying the action. #93307 Thanks @sunlit-deng.
  • Oversized browser-control error responses can no longer consume excessive Gateway memory, while ordinary failures still provide useful diagnostics. #98455 Thanks @wings1029.
  • Browser responsebody requests for a short prefix of a large response now avoid decoding a second full-size text copy while still returning the requested truncated content. #98940 Thanks @pandah97.
  • Malformed browser fill data supplied through --fields or --fields-file now produces a clear actionable error and exits before any browser action starts. #98861 Thanks @lsr911.
  • Browser screenshots used privately for visual inspection are no longer attached automatically to channel replies and are shared only when explicitly requested. #101434
  • Browser uploads on re-rendering pages now recover more reliably and expose the real stale-reference or action error instead of a generic timeout. #101465 Thanks @diwakarrankawat, @m13v, @tigicion.
  • Browser response bodies and page snapshots now stay valid and readable when output is shortened near an emoji. #101761 Thanks @mushuiyu886.
  • #### Files, documents, and media
  • ##### PDFs and image understanding
  • Vision-capable models can now read rendered pages from scanned and image-only PDFs attached through chat channels. #97354 Thanks @joshavant.
  • openclaw infer image describe now tries configured fallback image models after an explicitly selected model fails and reports which model ultimately succeeded. #98347 Thanks @momothemage.
  • Multi-page scanned PDFs now keep later pages at a usable image size during fallback extraction, allowing vision models to read the full document. #96390 Thanks @cls3389, @vincentkoc, @zengwen-dt.
  • Requesting nonexistent PDF pages now returns a clear range error instead of accidentally sending the entire document to a native provider. #97698 Thanks @zhangguiping-xydt.
  • Fractional PDF page selections such as 1.5 now fail immediately with a clear validation error instead of silently omitting requested content. #99399 Thanks @qingminglong.
  • ##### Media, attachments, and file transfer
  • Screenshot-style images returned by plugin tools over MCP now reach clients as usable results instead of causing the tool call to fail. #90902 Thanks @k-schmidt, @mushuiyu886.
  • After one generated video clip is ready, a different next clip can start immediately instead of waiting several extra minutes behind stale duplicate suppression. #96018 Thanks @palomyates516-alt, @vincentkoc.
  • openclaw capability video generate now returns a bounded, actionable error when a provider URL serves an oversized video without --output. #97549 Thanks @alix-007.
  • Fetching an empty file with an image-style name now returns a clear saved-file path instead of an unusable inline image result. #99370 Thanks @2loch-ness6, @vincentkoc.
  • File Transfer folder downloads now either produce a complete verified archive or report a clear read failure instead of crashing or returning partial data. #101590 Thanks @sunlit-deng.
  • Multi-attachment prompts now keep real captions while removing duplicate transport markers and placeholder-only text that could confuse the model. #96431 Thanks @lin-hongkuan.
  • GIF attachments are now recognized despite normal Content-Type parameters, spaces, or mixed casing instead of falling through as another media type. #96435 Thanks @lin-hongkuan.
  • Valid inline image data URLs without trailing base64 padding are now accepted, while malformed image payloads remain blocked. #96437 Thanks @lin-hongkuan, @vincentkoc.
  • Video inputs near the configured size boundary are now accepted or rejected according to their actual byte size, avoiding unexpected failures for files that are still within the limit. #96519 Thanks @lin-hongkuan, @vincentkoc.
  • Markdown frontmatter now preserves null-valued fields named toString, constructor, valueOf, or hasOwnProperty instead of silently dropping metadata from skills, hooks, or commands. #99129 Thanks @vincentkoc, @zenglingbiao.
  • Markdown beginning with text such as ---not or ---- now remains ordinary content instead of being mistaken for frontmatter and stripped. #101795 Thanks @nianjiuzst.
  • #### Worktrees and sandboxes
  • ##### Managed worktrees
  • Workboard tasks can now use managed isolated worktrees, with CLI and Control UI tools for creation, cleanup, restoration, and recovery snapshots when work cannot be removed safely. #100535
  • Users can now start a chat in its own managed worktree from the Control UI or mobile app, isolating parallel coding while preserving dirty work and cleaning safe idle checkouts automatically. #100788
  • ##### Sandboxes and workspace paths
  • Agent commands with an invalid explicit workdir, including a literal ~, now stop clearly instead of running from an unintended fallback directory. #94441 Thanks @jesse-merhi, @renaudcerrato.
  • SSH- and OpenShell-backed sandbox commands now clean up remote resources after failed launches, preserve the correct plugin session and channel context, and return a normal tool error for malformed input instead of an internal WeakMap failure. #96926 Thanks @jesse-merhi.
  • OpenShell sandbox sessions now start with the intended workspace files in the managed remote directory, avoiding missing-file and wrong-directory failures. d9034da Thanks @vincentkoc.
  • The optional common sandbox image now includes Node 24 and pnpm so documented Node-based development tasks can run inside it. eabc12b Thanks @vincentkoc.
  • OpenShell sandbox uploads now place workspace directories at the requested remote path so sandbox commands can reliably find their files. #96303 Thanks @vincentkoc.
  • #### Command execution
  • ##### Process execution and cleanup
  • Pending exec approval cards now describe only the approval state, and the foreground-fallback warning appears only after a command actually runs that way. #101561 Thanks @vincentkoc.
  • Timed-out commands on Windows are less likely to leave child processes running when taskkill.exe cannot start. #101392 Thanks @aniruddhaadak80, @zengwen-dt.
  • Failed shell-tool messages now separate the command the agent typed from framework labels and show the exit code, node, and working directory more clearly. #97511 Thanks @aditya-vithaldas.
  • Exec and finished background-session results now include signals, timeout flags, failure kinds, and exit reasons so users can tell why a command stopped. #89104 Thanks @yu-xin-c.
  • Windows autoreview --engine copilot runs now return a completed review result even when temporary-directory cleanup is briefly delayed. #97901 Thanks @paulcam206.
  • Oversized local socket replies now fail promptly without consuming memory until timeout, while large macOS commands still return completion status and bounded recent output. #98130 Thanks @pick-cat.
  • Timed-out, aborted, or output-limited extension commands now clean up their child processes instead of leaving background work running after api.exec() returns. #98340 Related #98335. Thanks @ooiuuii.
  • Emoji and other supplementary Unicode characters remain intact when long command output is shortened for polls, completion notices, or approval follow-ups. #98721 Thanks @zengwen-dt.
  • A set of failure-path fixes now keeps commands and maintenance tasks running through isolated errors, preserves terminal and model text, improves skill and approval diagnostics, and stops Android voice sessions cleanly after microphone loss. #100440 Thanks @cxbasdev, @lavyatandel, @nankingjing, @nianjiuzst, @tzy-17, @wendy-chsy.
  • Agent workflows can now survive transient stdout or stderr read failures from helper processes instead of losing the whole OpenClaw process. #100522 Thanks @cxbasdev, @vincentkoc.
  • Docker sandbox commands now return an explicit failure when output cannot be read instead of crashing OpenClaw or reporting an incomplete result as successful. #100523 Thanks @cxbasdev.
  • Crestodian setup and local-tool checks no longer terminate OpenClaw when a probed command encounters a rare output-stream read failure. #100741 Thanks @lsr911.
  • Stopping a chat through chat.abort can now find and terminate its matching embedded run instead of reporting failure while the underlying tool process continues. #101222 Thanks @zoowh.
  • Broken child-process output, timeouts, and aborts during agent shell commands are now contained instead of causing rare Gateway crashes. #101370 Thanks @wings1029.
  • Repeated failed or cancelled agent directory listings now release their cancellation listeners, avoiding listener buildup over time. #101588 Thanks @lzw112.
  • Codex session tools now honor their requested seconds-based timeout and return their own useful timeout status instead of ending early. #100722 Thanks @carterstebbins23-spec, @cxbasdev.
  • Cancelled ACP background tasks now appear as cancelled in task lists, summaries, and parent-run updates rather than being reported as successful. #101245 Thanks @masatohoshino.
  • ##### Editing, diffs, and task recovery
  • Reliability fixes now reject unsafe cron and plugin inputs, preserve skill formatting, surface Gateway and memory failures, fail LSP startup sooner, and prevent stale Android camera results after cancellation. #100399 Thanks @849261680, @anyech, @cxbasdev, @lin-hongkuan, @masatohoshino, @nankingjing, @qingminglong, @simon-xydt, @snotty, @xialonglee.
  • A broad reliability pass now replaces stalled child-process work with clear errors, improves sandbox diagnostics, bounds mobile calendar and voice state, normalizes cron fallbacks, and rejects unsafe provider responses. #100483 Thanks @aniruddhaadak80, @cxbasdev, @jincheng-xydt, @morluto, @nianjiuzst, @pandah97, @versatagent, @xialonglee, @zenglingbiao, @zengwen-dt.
  • Agent runs now stop cleanly when a write, edit, or apply_patch operation would make no change, preventing repeated false-progress retries while real mutations and valid sibling edits continue normally. #97044 Thanks @vincentkoc, @zw-xysk.
  • The diffs tool now renders default outputs faster, preserves highlighting for pack-only languages, handles unchanged input clearly, and reports file-render and invalid-patch errors more accurately. #100487
  • Failed code-mode tool attempts now show the error type, message, and location, giving the model and operator enough detail to diagnose or correct the problem. #95906 Thanks @vincentkoc, @zengwen-dt.
  • When the edit tool cannot match oldText, its error now points to likely nearby lines and explains common indentation, escaping, and whitespace differences, reducing blind retries. #97038 Thanks @aocogoal-gethub, @vincentkoc, @zoowh.
  • Legacy task upgrades now restore persisted tasks automatically, preventing linked TaskFlows from falsely reporting them missing or requiring manual SQLite recovery. #103946 Thanks @bek91, @theo674.
  • Terminal task lists now shorten emoji-heavy summaries without leaving broken replacement characters in the row. #101600 Thanks @maweibin.
  • Progress summaries for inline scripts and generated files no longer present heredoc content as extra shell commands that ran. #99379 Thanks @zengwen-dt.
  • Failed exact-match edits now show readable current-file context even when truncation falls beside an emoji or other non-BMP character. #99527 Thanks @mikasa0818.
  • #### Search and web
  • ##### Web fetch and link understanding
  • web_fetch now reaches provider fallback much faster for shell-style pages with no locally extractable content, cutting the measured fresh-process delay from several seconds to about one. #98559 Thanks @vincentkoc.
  • web_fetch now handles malformed or adversarial HTML more predictably, reducing excessive processing and keeping hidden script-like text out of fallback output. #102033 Thanks @pgondhi987.
  • Agent-side web_search now sees the configured provider in the active runtime, so Gateway and channel sessions can keep using providers such as Brave without a restart. #88684 Thanks @alexzhu0, @vincentkoc.
  • Link understanding now keeps page fetching available for the slowest configured fallback and applies tools.links.timeoutSeconds consistently regardless of model order. #100731 Thanks @aniruddhaadak80, @cxbasdev.
  • Recovered web_fetch spill files now keep emoji intact and report the actual safely written length when a long page exceeds the inline limit. #101312 Thanks @alix-007.
  • web_fetch now preserves emoji, mathematical symbols, extended Unicode, and intentionally escaped numeric entity text more faithfully. #96268 Thanks @ly-wang19.
  • DuckDuckGo results now preserve intentional entity notation such as < and ' instead of silently changing titles, snippets, or URLs. #96348 Thanks @ly-wang19, @vincentkoc.
  • Canvas embed replies now retain their visible message text when a self-closing embed shortcode is followed by an extra closing marker. #96449 Thanks @ly-wang19.
  • Bracketed labels in Markdown citations no longer make link understanding fetch display-only URLs that the user did not intend to retrieve. #96476 Thanks @ly-wang19, @vincentkoc.
  • DuckDuckGo search pages containing malformed numeric HTML entities no longer crash parsing or inject broken Unicode into titles, URLs, and snippets, while valid emoji entities remain supported. #96583 Thanks @llagy007, @weeli-009.
  • ##### Local and tool search
  • When an installed fd or rg binary is unusable, agent search can now install a working copy and recover instead of failing repeatedly. #96361 Thanks @miorbnli.
  • A failed find search now returns one contained tool error and stops its fd process instead of risking an agent crash or orphaned search. #101158 Thanks @cxbasdev.
  • Tool Search now fails the affected call cleanly and terminates its unusable child when the diagnostic stream breaks, rather than risking a stranded request or Gateway crash. #101295 Thanks @cxbasdev.
  • QMD command pipe failures now report a clean memory-operation error instead of taking down the memory host. #101402 Thanks @wings1029.
  • The agent find tool now reports an interrupted or failed directory search as an error instead of returning a partial match list as complete. #99446 Thanks @zhangguiping-xydt.
  • #### SDK, MCP, and tools
  • Agents can read scanned PDFs with vision-capable models, work in isolated coding checkouts, and handle files, media, browser results, and execution failures with more usable output. Browser control preserves pairing and download state more reliably, while parallel workspace operations are less likely to collide with one another or the user's current files.
  • ##### MCP, ACP, and tool protocols
  • Shortened tool descriptions in catalogs and /tools verbose no longer split emoji or other Unicode characters into garbled replacement symbols. #98644 Thanks @zengwen-dt.
  • openclaw mcp serve and bare openclaw acp now begin with clean machine-protocol output, preventing startup warnings from corrupting JSON-RPC for MCP and ACP clients. #89997 Thanks @kenners22, @vincentkoc.
  • When a bundled MCP server stops mid-session, users now get a prompt server-specific disconnect message and can clear the dead session by refreshing the catalog. #98738 Thanks @masatohoshino, @vincentkoc.
  • Malformed draft-2020-12 tool schemas from an MCP server now produce an actionable setup error that identifies the external schema and retains the underlying failure. #89619 Thanks @vincentkoc.
  • Prompt templates now preserve intentionally blank quoted arguments so later positional placeholders receive the correct values. #96405 Thanks @lin-hongkuan.
  • OpenTelemetry latency dashboards now provide useful duration and context-size distributions for agent and harness work lasting well beyond 10 seconds, including multi-minute runs, without collector-side bucket customization. #96592 Thanks @hcnode, @vincentkoc, @zhiling-chen-20230331.
  • MCP tools now receive optional null values correctly instead of having them changed into empty strings that can break valid calls. #97212 Thanks @vincentkoc, @zw-xysk.
  • Successful Codex thread-goal reads now appear as successful in model context, transcripts, and diagnostics instead of being recorded as failed tool calls. #98659 Thanks @yetval.
  • Message-tool calls with an invalid Gateway timeout now return an immediate validation error instead of appearing to stall. #98652
  • Invalid plugin approval requests now show the actual validation problem instead of misleading users with a Gateway-unavailable error. #100337 Thanks @tzy-17.
  • Oversized ClawHub packages, skills, ClawPacks, resolver archives, and GitHub-source downloads now stop with a clear size-limit error before they can exhaust Gateway memory. #101176
  • Automatic session rotation is less likely to strand the next conversation when a context-engine plugin immediately reads or checkpoints its transcript. #101192
  • Internal hook authors now receive a warning when a likely event-name typo would otherwise leave a hook silently inactive. #99456 Thanks @masatohoshino.
  • Tool-using Anthropic-family requests can now fail over to OpenAI without a 400 error caused by an incompatible tool format. #101443 Thanks @chrisbaker2000.
  • ##### Skill Workshop
  • Natural-language corrections can now become the right pending Skill Workshop improvement after successful or failed turns without repeating old feedback, duplicating /learn, or replacing proposal context. #100576 Thanks @vincentkoc.
  • Skill Workshop approval prompts now include the proposal details needed to apply, reject, or quarantine a change, while unanswered requests stay safely pending and return a clear timeout message. #100498
  • When users say things like "next time" or "remember to," OpenClaw can now offer one reviewable Skill Workshop proposal without requiring autonomous capture or repeatedly prompting after dismissal. #100692
  • Skill Workshop now explains when tool policy is hiding skill_workshop and shows the exact allow or alsoAllow change needed to enable manual review calls. #100654 Thanks @wangwllu.
  • #### Documentation
  • Official operating guidance now matches shipped commands, configuration, setup, status output, placeholders, and recovery behavior more closely. Generated documentation maps also preserve literal command parameters, reducing the chance that a reader follows an example whose identifiers were stripped or whose workflow no longer matches the product.
  • ##### Setup and operating guides
  • The CLI config documentation now clearly distinguishes normal JSON5 value parsing from --strict-json, which accepts standard JSON and rejects JSON5-only syntax. #80981 Thanks @addu2612.
  • The macOS guide now gives users a clearer path from downloading the app through first-run setup, Gateway selection, and focused troubleshooting. #97120 Thanks @romneyda.
  • OpenClaw's public docs now use shorter, task-first instructions with corrected commands, configuration names, defaults, provider behavior, and troubleshooting steps. #100142
  • Logbook users now have end-to-end guidance for setup, model routing, privacy choices, and troubleshooting missing capture or timeline results. b6a7898
  • Safe-restart guidance now states that the default wait can end after gateway.reload.deferralTimeoutMs and explains how to configure an indefinite wait. #95397 Thanks @zhangqueping.
  • The agent configuration guide now identifies the current models selected by the built-in opus and gpt aliases. #96375 Thanks @niks999.
  • Docker operators now have an official path to install, authenticate, verify, and persist the claude-cli backend across container image upgrades. #96380 Thanks @fffrank, @zaidazmi.
  • OpenClaw's Anthropic and Claude CLI documentation now reflects the current subscription-limit treatment for claude -p and related usage, with official references for billing and deployment decisions. #96848 Thanks @fightingsleep, @tirion-p.
  • The public onboarding docs now cover eleven existing non-interactive flags for token auth, Cloudflare AI Gateway, daemon, UI, hooks, and token output. #97753 Thanks @vincentkoc, @wm0018.
  • OpenClaw's mobile documentation now identifies the iOS and Android apps as official releases and provides consistent App Store, Google Play, and hosted iOS push-relay guidance. #98843 Thanks @joshavant.
  • Official OpenClaw docs now help operators and plugin authors handle credentials safely, preflight cron jobs that use local-provider fallbacks, apply Talk timing defaults, configure MiniMax providers and models, and copy a complete minimal plugin package with the required dependency metadata. #100182
  • Android node operators now have an end-to-end guide for securely mirroring and controlling a remote device from macOS, including authorization, troubleshooting, and clean disconnection. #100398
  • The onboarding reference now explains that bare openclaw starts onboarding for a missing config, opens Crestodian for an invalid config, and launches the agent TUI for a valid config. d9dbee7
  • ACP troubleshooting now names PermissionPromptUnavailableError, helping operators recognize a non-interactive permission failure and find the right configuration fix. b3a74cc
  • The onboarding reference now gives accurate signal-cli, Gateway runtime, and channel allowlist guidance, including Windows limits and the IDs expected for direct messages. aaaa803
  • ##### Channels and messaging guidance
  • Plugin and channel-status documentation now clarifies that a MessageReceipt or durable sent result proves platform acceptance, not display or read confirmation on a recipient's device. #90063 Thanks @pdurlej.
  • The Discord setup guide now points users to the correct Developer settings section for enabling Developer Mode and copying required IDs. #97336 Thanks @naseemm123.
  • The Discord setup guide now separates General Permissions from Text Permissions so bot access choices are easier to read correctly. #97584 Thanks @slammajamma28.
  • Telegram's error-reply documentation now lists the supported policies and correct cooldown defaults, avoiding invalid errorPolicy: "reply" configurations. #97635 Thanks @wm0018.
  • The Feishu documentation no longer suggests the rejected dmPolicy: disabled setting, reducing configuration failures copied from the guide. #97640 Thanks @wm0018.
  • Matrix documentation now explains progress streaming, room-specific mention matching, per-room enablement, and bot-loop safeguards that operators can configure. #98318 Thanks @vincentkoc, @wm0018.
  • Telegram channel documentation now correctly states that an unset streaming mode uses partial previews and explains how to choose final-only replies. #98453 Thanks @solodmd.
  • The bundled imsg skill now guides agents toward the correct direct or group conversation, stable targets, least-privilege actions, and confirmation before visible or sensitive changes. #100105 Thanks @omarshahine.
  • ##### Plugin and generated reference guidance
  • Plugin developers now receive clearer SDK deprecations and migration guidance for session-store and transcript-file helpers ahead of the planned SQLite transition. #97494 Thanks @jalehman.
  • Plugin authors now get clearer packaging guidance for runtime dependencies, built artifacts, npm-pack: validation, and trusted official-plugin checks before publication. #99962 Thanks @hxy91819.
  • Official plugin package examples now agree on the required typebox runtime and openclaw peer dependencies, reducing copy-and-paste setup failures. #99973
  • The Codex and WhatsApp plugin references now identify their tools contract, making supported plugin capabilities easier to match with OpenClaw workflows. 46ad3f9 Thanks @vincentkoc.
  • Generated documentation navigation now preserves complete headings with command placeholders such as <id> and <deviceId> instead of hiding required arguments. #99099 Thanks @hxy91819.
Additional contributions
  • Maintainer-facing contributions: #59695, #73649, #83826, #87081, #87695, #89535, #89558, #89585, #90365, #90547, #91134, #91276, #91483, #91519, #91728, #91907, #92667, #93209, #94291, #94526 (related #89352), #94708, #95211, #95230, #95531, #95534, #95622, #95842, #95920, #95954, #96058, #96094 (related #91167), #96222, #96225, #96302, #96320, #96327, #96338, #96340, #96359, #96360, #96366, #96434, #96448, #96460, #96507, #96524, #96527, #96530, #96539, #96543, #96567, #96594, #96595, #96707, #96711, #96714, #96735, #96736, #96765, #96811, #96930, #96945, #96948, #96950, #96952, #96955, #96964, #97079, #97101, #97110, #97113, #97116, #97119, #97124, #97133, #97150, #97151, #97181, #97250, #97297, #97306, #97348, #97351, #97369, #97370, #97374, #97478, #97547, #97548, #97604, #97609, #97632, #97657, #97661, #97689, #97701, #97708, #97712, #97714, #97736, #97802, #97803, #97805, #97891, #97896, #97898 (related #97792), #97900, #97907, #97912, #97915, #97937, #97940, #97941, #97943, #97946, #97947, #97948, #97950, #97951, #97959, #97962, #98009, #98087, #98134, #98138, #98205, #98219, #98233, #98249, #98319, #98325, #98369, #98370, #98395, #98494, #98533, #98536, #98551, #98598 (related #98462, #98464), #98605, #98610, #98611 (related #98566), #98619, #98701, #98749, #98751, #98779, #98792, #98808, #98818, #99098, #99151, #99165, #99169, #99212, #99233, #99261, #99262, #99264, #99265, #99278, #99294, #99296, #99298, #99302, #99303, #99307, #99310, #99352, #99355, #99359, #99361, #99368, #99374, #99520 (related #99513), #99607, #99628 (related #99627), #99629, #99632 (related #99622), #99642, #99649 (related #99648), #99656 (related #99655), #99671 (related #99667), #99676 (related #99663), #99679 (related #99664), #99682 (related #99674), #99687 (related #99675), #99688, #99691, #99702 (related #99697), #99705, #99707, #99710, #99715, #99717, #99718, #99719, #99721, #99735, #99736 (related #99734), #99737, #99743, #99744, #99746, #99750, #99753, #99755, #99766, #99771, #99777, #99778, #99784, #99785, #99786, #99788, #99790, #99793, #99816, #99820, #99850, #99900, #99909, #99917, #99940, #99944, #99945, #99969, #99988, #100002, #100008, #100015, #100019, #100024, #100039, #100053, #100061, #100069, #100083, #100087, #100108, #100114, #100122, #100183, #100186, #100200, #100201, #100206, #100210, #100220, #100221, #100222, #100223, #100239, #100242, #100243, #100249, #100253, #100259, #100272, #100278, #100304, #100332, #100346, #100355, #100370, #100420, #100437, #100441, #100459, #100464, #100466, #100469, #100472, #100473, #100495, #100497, #100507, #100517, #100532, #100533, #100536, #100543, #100545, #100555, #100561, #100562, #100575, #100593, #100599, #100603, #100609, #100611, #100612, #100650, #100663, #100702, #100703, #100723, #100740, #100781, #100793, #100804, #100823, #100856, #100882, #100887, #100895, #100897, #100903, #100909, #100931, #100950, #100952, #100961, #100975, #100989, #100990, #100992, #101012, #101013, #101041, #101045, #101051, #101055, #101063, #101076, #101080, #101081, #101112, #101128, #101131, #101135, #101165, #101173, #101174, #101178, #101179, #101180, #101184, #101185, #101186, #101196, #101223, #101232, #101233, #101242, #101243, #101262, #101273, #101275, #101315, #101331, #101339, #101356, #101362, #101372, #101379, #101393, #101406, #101425, #101440, #101452, #101466, #101470, #101508, #101519, #101523, #101549, #101566, #101568, #101579, #101583, #101594, #101604, #101632, #101647, #101666, #101680, #101682, #101688, #101689, #101699, #101701, #101726, #101731, #101757, #101758, #101771, #101831, #101834, #101858, #101860, #101869, #101875, #101886, #101889, #101892, #101894, #101896, #101898, #101903, #101904, #101907, #101915, #101917, #101922, #101925, #101931, #101936, #101941, #101945, #101949, #101954, #101959, #101963, #101969, #101974, #101980, #101987, #101990, #102005, #102010, #102021, #102029, #102037, #102040, #102042, #102044, #102048, #102059, #102065, #102159, #102256, #102600, #102732, #103163, #103244, #103467, #103556, #103564, #103635, #103650, #103654, #103681, #103685, #103718, #103906, #103923, #104162, #104186, #104684, #104702, #104722, #104750, #104794, #104939, #104975, #105133, #105401, #105444, #105488, #105493, #105500. Thanks @100yenadmin, @645648406-max, @849261680, @acosx, @aleps001, @alix-007, @aniruddhaadak80, @bartok9, @brian-bell, @brokemac79, @bryantegomoh, @clawsean, @cxbasdev, @d1rshan, @dboone323, @deepujain, @dwc1997, @evan-ym, @fuller-stack-dev, @galiniliev, @giodl73-repo, @glenn-agent, @goutamadwant, @guanbear, @haishmg, @hannesrudolph, @hemantsudarshan, @hugenshen, @hxy91819, @hyspacex, @iwhatsskill, @jalehman, @joshavant, @keaneyan, @kesslerio, @kevinslin, @kiagentkronos-cell, @leonidaslux, @lin-hongkuan, @luoyanglang, @ly-wang19, @lzw112, @marvinthebored, @masatohoshino, @maweibin, @mcaxtr, @miorbnli, @ml12580, @morluto, @mushuiyu886, @neatguycoding, @nxmxbbd, @obviyus, @ooiuuii, @osolmaz, @patrick-erichsen, @peetiegonzalez, @pikaqqqqqq, @pmika, @qingminglong, @qiuyuang, @romneyda, @ruanrrn, @saju01, @sebtardif, @shakkernerd, @solodmd, @solvely-colin, @steipete-oai, @sunlit-deng, @super-cabbage, @sweetcornna, @tiffanychum, @totobusnello, @turbotheturtle, @vincentkoc, @vishal-dharm, @vishalj99, @wiidz, @wm0018, @wuqxuan, @xialonglee, @xianshishan, @yonganzhang, @zenglingbiao, @zengwen-dt, @zhangguiping-xydt, @zhanglei99586, @zw-xysk.
2026.6.11 BREAKING
Aug 24, 2026
Notable changes
  • We heard the feedback. v2026.6.11 focuses on the rough edges that make OpenClaw feel less dependable, with fixes for misplaced replies, stuck sends, reconnects, model setup failures, and safer admin defaults.
  • Full release notes
  • #### Channel delivery reliability
  • Delivery and reconnect fixes span Telegram, WhatsApp, Matrix, Google Chat, iMessage, Feishu, Mattermost, WebChat, the Control UI, and the terminal UI.
  • Fixes newer Google Chat direct messages sometimes being treated like group conversations, so they reach the correct one-to-one chat while Space and group-chat messages keep their existing routing. #58993 Thanks @starhappysh, @vincentkoc.
  • Feishu voice replies from OpenClaw now show their duration in the chat bubble, so recipients can see how long the audio is before playing it. #89172 Related #53798. Thanks @areslp, @fxz26284407, @kinrocw.
Show all changes (349 more)
Highlights
  • Discord and Telegram replies and mirrored chat history stay tied to the intended conversation more consistently, including across repeated Telegram replies and session changes. #89911 Thanks @jalehman.
  • Background image, video, and music results now return to the chat that requested them when the task starts without a full conversation target, instead of appearing to fail after creation or being sent to the wrong peer as the session moves. #89949 Related #86034. Thanks @tianxiaochannel-oss88, @wangwllu.
  • Telegram answers now stay attached to the user's current question when they quote an earlier bot message, while quotes of other people's messages still reply to the selected quote. #90475 Thanks @moeedahmed.
  • QQBot group admins can choose how broadly slash commands are available, and private-only commands now direct users to a private chat instead of being exposed or silently ignored in groups. #92154 Thanks @sliverp.
  • Heartbeat checks using reasoning-capable models now show the assistant's intended reply instead of exposing internal reasoning in Telegram, WhatsApp, and other channels, while opt-in Thinking messages still work. #92356 Related #92260. Thanks @jmpei, @tangtaizong666, @vincentkoc.
  • Telegram progress-mode chats now clear an old progress bubble before newer tool output or artifacts appear, keeping the conversation in a clean, readable order. #93002 Related #90753. Thanks @shadow-enthusiast, @zhangguiping-xydt.
  • iMessage command-and-link messages now stay together as one OpenClaw turn when delayed link previews arrive, while unrelated quick messages remain separate for users who enabled same-sender DM coalescing. #93143 Thanks @omarshahine.
  • Successful Discord replies sent through the message tool no longer trigger a misleading failure warning in affected message_tool_only source-channel turns. #94072 Related #93875. Thanks @chenyangjun-xy, @hoyanhan, @vincentkoc.
  • WhatsApp group conversations now preserve the right message and group context more reliably during retries, reconnects, and group changes. #94338 Related #7433. Thanks @mcaxtr, @octopuslabs-fl, @xialonglee.
  • Fixes OpenClaw sometimes replying to its own delayed iMessage echoes when stray leading characters keep the sent message from being recognized. #94442 Thanks @ly-wang19.
  • Telegram webhook users can keep receiving DMs and group messages through brief channel restarts, configuration reloads, and recovery cycles without temporary message blackouts. #94506 Related #90254. Thanks @obviyus, @travellingsoldier85, @xialonglee.
  • Matrix E2EE gateways can stay online during long-running use instead of gradually consuming memory until a crash takes channels and in-flight work down. #94942 Related #90455. Thanks @xzh-icenter, @yar-sh.
  • Telegram users now see the intended native reaction instead of leaked instructions or a dropped reaction-only reply, with success recorded only after Telegram accepts it. #94977 Related #71140. Thanks @cuttingwater, @hugenshen.
  • Telegram progress updates for commands, searches, updates, and API activity now stay readable instead of exposing noisy HTML or code-style rows, with plain-text fallback when Telegram cannot parse the formatting. #95007 Related #95002.
  • Telegram conversations continued in WebChat now show one assistant reply per turn and keep later replies with the active conversation instead of duplicating answers or sending them back to Telegram. #95069 Related #94930. Thanks @heichaowo.
  • Google Chat now hides misleading internal failure banners when a tool result is harmless, leaving users with the completed answer while normal assistant text remains unchanged. #95084 Related #90684. Thanks @jailbirt, @studentzhou-svg.
  • Bound multi-agent channel conversations now load the workspace files for the configured agent instead of the default agent, though previously misfiled conversations may start fresh in the corrected agent store. #95118 Related #92903. Thanks @849261680, @axjing.
  • People sharing an OpenClaw gateway can now assign different models to individual direct-message contacts across supported chat channels, while existing group and wildcard model choices keep working as before. #95120 Related #53638. Thanks @gandalf-at-lerian, @thomaszta, @xydigit-zt.
  • Telegram now shows that OpenClaw is still working during short initial previews or progress-mode replies instead of leaving the chat silent until the final message arrives. #95183 Related #95004. Thanks @obviyus.
  • Matrix users and operators now get a clear failure when a homeserver sends an oversized or stalled response, instead of OpenClaw continuing to buffer it and risking unbounded memory use. #95240 Thanks @alix-007.
  • Fixes delayed or missing Telegram and other queued channel replies in Kubernetes-style deployments with many injected environment variables, where opening the queue database could stall the gateway. #95278 Related #94571. Thanks @kaka-srp.
  • Telegram chats recover after one stuck message times out, allowing later messages in the same chat or topic to reach the agent without restarting the gateway. #95299 Related #95248. Thanks @kriegerbangerz-ship-it, @mikasa0818, @obviyus.
  • When people switch between Telegram and another OpenClaw client in a shared direct conversation, short Telegram replies now follow the latest conversation instead of responding to an older, unrelated Telegram proposal. #95390 Related #95378. Thanks @maiduy708, @mikasa0818, @obviyus.
  • Fixes completed assistant messages appearing twice in Telegram, Discord, Slack, and other streamed chats after a multi-message reply. #95432 Thanks @vincentkoc, @yetval.
  • WhatsApp replies now stay attached to the direct or group message being answered instead of appearing as a separate message that loses the conversation context. #95483 Thanks @mcaxtr.
  • Telegram rich-message replies now keep paragraphs, bullets, and status lines separated instead of collapsing multi-line content into one run-on block, with no configuration change required. #95532 Related #95409. Thanks @amknight.
  • Mattermost operators who enable native slash commands can now use /oc_queue directly in Mattermost to tune active-run queuing, including its mode, debounce timing, cap, and drop handling. #95546 Thanks @amknight.
  • Previously allowed messages keep reaching named accounts after legacy multi-account channel upgrades, with inherited DM and group access rules preserved across Mattermost, Discord, Slack, Telegram, Signal, WhatsApp, iMessage, and IRC. #95550 Thanks @amknight.
  • Mattermost users can keep talking in a thread without mentioning the bot again after it replies, and that participation survives gateway restarts until the thread has been idle for seven days. #95552 Thanks @amknight.
  • Inbound Telegram messages now reach the configured OpenClaw session promptly instead of sitting unanswered until the next polling interval, a gateway restart, or manual intervention. #95577 Related #86957. Thanks @freidrich-goldenflow, @liuwqgit.
  • QQBot users now receive complete markdown tables when valid separators use one or two dashes per column, instead of losing the header and all but the final row. #95637 Thanks @ly-wang19.
  • Synology Chat users can now receive agent replies that take more than 120 seconds when the configured core timeout allows it, instead of having the channel reject them early. #95707 Thanks @sahibzada-allahyar, @vincentkoc.
  • Telegram forum-topic cron jobs now keep separately configured failure alerts going to their intended destination, even when the main announcement uses a topic in the same chat. #95794 Thanks @vincentkoc.
  • Fixes WhatsApp group replies that could quote an older OpenClaw message instead of the user's triggering message, so final answers stay attached to the intended message when a reply target is available and avoid pointing back to stale bot context when it is not. #95914 Thanks @mcaxtr.
  • WhatsApp users can approve or deny prompts by reaction without the prompt staying stuck when WhatsApp identifies the same direct chat differently, while group approvals remain tied to the correct group and person. #95935 Thanks @mcaxtr.
  • Final reply processing now uses less CPU when OpenClaw checks whether block text was already sent, without changing which reply reaches the chat or how duplicate text is suppressed. #96087 Thanks @vincentkoc.
  • Exec approval results from external channel plugins now return to the channel or DM where the command started instead of falling back to WebChat or seeming to disappear after approval. #96140 Related #96103. Thanks @lansenger-pm, @vincentkoc, @yetval.
  • WhatsApp's final answer now stays quoted to the follow-up message a user just sent when replying to an older OpenClaw message, instead of arriving unquoted or pointing back to the older bot reply. #96220 Thanks @mcaxtr.
  • Nextcloud Talk bots now ignore ordinary file-share and lifecycle events without logging them as bot errors or risking disabled delivery, while malformed chat payloads still return an error. #96243 Related #81566. Thanks @arkyu2077, @rafaelmgbh, @vincentkoc.
  • Replies and message-tool delivery in Mattermost channels now use channel and thread guidance because the agent identifies those conversations as channels rather than group chats, while existing group-chat behavior remains unchanged. #96244 Related #95645. Thanks @arkyu2077, @iloveleon19, @vincentkoc.
  • MCP channel integrations now keep conversation lists, message reads, event polls, and waits within predictable bounds even when a client requests excessive limits or timeouts. a39e548 Thanks @vincentkoc.
  • Long-running streamed auto-replies are less likely to stop early or abort inconsistently when an unusually large timeout is configured. 6c85b90 Thanks @vincentkoc.
  • Channel progress now shows a repeated status when work genuinely returns to it after another update, instead of hiding useful context as a duplicate. 8a75c4d
  • Completed channel replies no longer gain late progress notices, preventing stale status text from appearing after the answer is finished. a594d2c Thanks @vincentkoc.
  • During streaming channel replies, progress messages now keep showing the latest state instead of getting stuck on an older update. e114001 Thanks @vincentkoc.
  • Matrix forced resets now handle unavailable secret storage without a runtime error, treating recovery access as unavailable so the reset path can continue safely. 5c5a8a4 Thanks @vincentkoc.
  • Configured channels now remain visible in openclaw channels status --json, while scheduled announcements reject stale entries that have no active plugin to deliver them. a641c0d
  • Discord voice conversations now keep back-to-back assistant responses moving, so a queued reply plays after the previous audio stream closes instead of remaining stuck. 88b64e4 Thanks @vincentkoc.
  • Discord progress previews are less likely to stop before the final edits when an agent response has already started arriving. 86ea382
  • Chats no longer show stray NO_REPLY text when the assistant means to stay silent, while legitimate media responses still arrive without the placeholder. 96c6f80
  • Telegram streaming replies now show each progress heading once, keeping tool and search updates easier to scan. 013e33c Thanks @vincentkoc.
  • Telegram messages that get stuck after a long-running task, crash, or gateway restart now resume processing automatically, so later messages no longer wait silently or require operators to repair the queue by hand. #97543 Thanks @romneyda, @vincentkoc.
  • #### Provider and model recovery
  • Model setup, OpenAI, OpenRouter, opencode-go, and fast-mode follow-up behavior now recover more clearly in affected configurations.
  • MiniMax text-to-speech and voice notes are less likely to fail because OpenClaw now explicitly requests the audio format it can decode instead of relying on provider defaults. #73079 Thanks @efe-arv.
  • Gateway operators can again see provider, model, request status, and timing details in normal logs, making model-routing and transport problems easier to diagnose without enabling extra debug logging. #89648 Related #89300. Thanks @enominera, @xiaobao-k8s.
  • Models reached through Google, Mistral, OpenAI Responses, Azure OpenAI Responses, and ChatGPT/Codex Responses now receive clean system instructions without OpenClaw's internal cache-boundary marker leaking into the prompt. #89716 Thanks @enominera, @masatohoshino.
  • Cron tool calls using Gemini models through OpenAI-compatible providers now run without nullable fields triggering provider schema rejections. #91559 Related #91542. Thanks @pick-cat, @qiukui666.
  • Provider-qualified model IDs now honor their configured agent runtime policies and CLI aliases instead of unexpectedly falling back to OpenClaw's default runtime. #91724 Thanks @vincentkoc, @yu-xin-c.
  • The chat /models list and other plugin-aware model or provider selection paths now respond quickly instead of stalling for seconds and consuming a CPU core through repeated setup scans, while plugin changes still refresh normally. #93356 Thanks @obuchowski.
  • Hosted Ollama Cloud users can keep only the models they explicitly configured after a restart, without the full shared catalog being added back, while automatic discovery continues for local and self-hosted Ollama servers. #93956 Thanks @jason-allen-oneal.
  • Cron jobs can now retry or switch to a configured fallback model when a local provider returns the generic LLM request failed. error, instead of failing with the fallback unused. #94062 Related #93931. Thanks @hugenshen.
  • Expired provider tokens no longer bury useful operator logs under repeated fallback warnings, while the first warning and later duplicate summaries remain available for diagnosis. #94233 Related #56979. Thanks @goutamadwant, @yanan1991.
  • Google Gemini 3.5 Flash can now be selected with its full 1,048,576-token context window, avoiding missing-model errors and needless prompt-size rejections. #94726 Related #94723. Thanks @ajwan8998, @anguslogan01, @kevinat.
  • Dashboard child sessions now handle allowed provider-qualified model choices consistently and give accurate recovery guidance when saved model state is stale. #94752 Related #94713. Thanks @gr4via.
  • Claude CLI users no longer get promises of completion updates that may never arrive, because OpenClaw now blocks unsupported native background work before it can strand progress. #95008 Thanks @anagnorisis2peripeteia.
  • OpenClaw now rejects oversized provider catalog or JSON responses with a clear error before buffering the entire response in memory. #95218 Thanks @alix-007.
  • OpenRouter users can now select and run the advertised short DeepSeek V4 model IDs without requests failing with model_not_found because OpenClaw sent a duplicated provider prefix. #95268 Related #95198. Thanks @daniel-alejandro-t, @darren2030.
  • With /reasoning on, DeepSeek-style OpenAI-compatible models now show the final answer separately from their reasoning instead of folding it into the reasoning block, with no configuration change required. #95283 Related #95280. Thanks @marvinthebored, @vincentkoc, @zengwen-dt.
  • When a Codex subscription reaches its usage limit, OpenClaw now moves to configured fallback models instead of stopping on the failed result, and it does not retry runs that already produced visible output. #95400 Thanks @jason-allen-oneal, @sallyom.
  • LM Studio users can now run quantized or multi-variant local models without false assistant-turn failures or phantom suffixed model entries caused by mismatched model keys. #95401 Thanks @monkeyleet.
  • Google-backed embedded-agent runs now stop reading oversized or never-ending prompt-cache responses before they can exhaust memory or leave the run stalled. #95417 Thanks @alix-007.
  • OpenRouter model scans fail safely on oversized or malformed catalogs instead of risking excessive memory use that can destabilize OpenClaw. #95418 Thanks @alix-007.
  • OpenRouter setups now reject oversized model catalogs before they can exhaust OpenClaw's memory, without caching or immediately refetching the failed response. #95420 Thanks @alix-007, @sallyom.
  • Configured fallback models can now answer when Claude CLI runs out of credits or hits a generic runner failure, instead of leaving users with the failure message as the final response. #95508 Related #95489. Thanks @mikasa0818, @riazrahaman, @sallyom.
  • Gemini-backed web searches using freshness: "day" or pd now complete instead of failing with a provider 400 error, while broader freshness choices and explicit date ranges retain stricter filtering. #95682 Thanks @sunjae-k, @vincentkoc.
  • Follow-up answers from xAI reasoning models such as Grok Composer now preserve earlier reasoning context more reliably, even when configurable reasoning effort is unsupported. #95686 Thanks @fuller-stack-dev, @geraint0923.
  • Vercel AI Gateway users can now run models chosen from the live catalog, including live-only model IDs that are absent from OpenClaw's bundled list. #95710 Thanks @vincentkoc.
  • Fixes manifest-defined providers turning valid model IDs into broken ones when stripPrefixes entries have stray spaces or different casing, so operators and plugin authors get the intended provider model. #95744 Related #95743. Thanks @parveshsaini.
  • First-run setup now opens the credential prompt for a newly installed external provider instead of appearing to loop and leaving OpenAI selected. #95792 Related #95765.
  • Oversized or stalled provider catalogs now fail quickly with a clear error instead of hanging OpenClaw or consuming unbounded memory, while normal catalogs continue to load. #95827 Thanks @alix-007.
  • Xiaomi Token Plan users can now use up to 128K output tokens with mimo-v2.5 and mimo-v2.5-pro instead of being stopped at the outdated 32,000-token limit. #95934 Thanks @idootop.
  • Tool-heavy model responses can stream with less overhead while repeated tool-call IDs and encrypted reasoning details stay matched to the correct call across Google and OpenAI-compatible providers. #95957 Thanks @vincentkoc.
  • Token-usage accounting is more reliable for bundled ACPX users because OpenClaw now includes ACPX 0.11.2's persistence fix by default, without a separate package override or manual client update. #96124 Thanks @vincentkoc.
  • Ollama Cloud users can now find and select glm-5.2:cloud with its 1,000,000-token context window, reasoning, and tool support even when it is absent from the public model list. 11484f8
  • MiniMax image-understanding requests no longer fail before reaching the provider when a timeout is zero, negative, or extremely large; invalid values now use a normal or safe maximum wait. 4b6182e Thanks @vincentkoc.
  • Codex runs now follow the current fast-mode choice instead of carrying over an old speed tier, and the status line clearly shows when fast mode is automatic. 77012f9 Thanks @vincentkoc.
  • Codex-backed conversations now return to normal routing after automatic fast mode is cleared, preventing later turns or model changes from reusing a stale priority tier. 8afc1f7
  • Fallback agent runs now honor each model's configured automatic fast-mode cutoff even when fast mode is overridden for the run, keeping fallback behavior aligned with the selected model policy. efd3172
  • Live model-switch retries now preserve the original fast-mode cutoff for long-running sessions, while explicit fast mode avoids misleading automatic-cutoff progress messages. d990115 Thanks @vincentkoc.
  • Embedded agent runs now keep automatic fast mode working consistently through retries and progress updates without confusing it with a manually selected fast-mode setting. cf1b6fe Thanks @vincentkoc.
  • Fast-mode runs now keep their speed setting through model fallback retries and show the configured automatic threshold in status, avoiding inconsistent retry behavior and an unhelpful generic label. aa3797c Thanks @vincentkoc.
  • Agent replies and scheduled cron runs now handle fast-mode fallback retries more reliably, keeping the state needed for the final attempt to finish or report progress correctly. 14e448e Thanks @vincentkoc.
  • Users no longer see a fast-mode reset notice while model fallback attempts are still running; it appears only when the run reaches its final fallback attempt. 6eb72a8
  • Users and operators now get clearer handling when a configured live model becomes unavailable because OpenClaw recognizes the provider's "selected model was not found" response as a model-not-found failure instead of a generic error. 2405d02 Thanks @vincentkoc.
  • Qwen and vLLM now preserve existing chat-template settings consistently when thinking is switched on or off, and provider plugins can use the same tested helper. 2ba9d6e Thanks @vincentkoc.
  • OpenAI-compatible proxy providers can handle thinking levels and legacy reasoning_effort fields more consistently, with plugin developers and provider maintainers using one documented normalization helper across OpenRouter, Kilocode, and the SDK. 35bafea
  • Browser and Vite builds can now load the OpenAI ChatGPT Responses provider without a server-only dependency breaking the bundle, while WebSocket failures still appear normally. 8c8eb86 Thanks @vincentkoc.
  • OpenRouter model scans now accept the same larger valid catalogs as runtime discovery while still rejecting oversized responses before they can consume unbounded memory. ad3b2f4 Thanks @vincentkoc.
  • OpenAI Responses users, including affected Bedrock Mantle GPT-5.x reasoning setups, now get one clean final answer with aligned saved transcripts and replay context instead of dozens of repeated cumulative copies. #92399 Related #91959. Thanks @amersheeny, @daimingnj, @phoenixyy, @pigfoot.
  • Scheduled jobs and isolated sessions using opencode-go models now move stalled requests into configured timeout or fallback handling instead of hanging for minutes before ending with a generic LLM request failed error. #93965 Related #93610. Thanks @forceconstant, @zhangguiping-xydt.
  • #### Session, memory, and trust continuity
  • Sessions, compaction, memory, QMD-backed memory, and Tool Search retain useful state more consistently, while Matrix recovery, tool policies, and approvals stay attached to the intended trust boundary.
  • Affected agent conversations using OpenAI Responses can now recover and keep replying after a visible channel response leaves their saved history incomplete, instead of every later turn failing before a reply appears. #84708 Thanks @anyech.
  • When a Codex-backed agent produces unusually large tool output, saved and replayed conversations now keep its text within the usual size limit while leaving non-text content unchanged. #87912 Thanks @adrianip0204.
  • Control UI conversations now stay visible and continue in the same session after a sleep, network drop, or Gateway reconnect instead of disappearing when the next message is sent. #89017 Related #87700. Thanks @zhangguiping-xydt, @asicoe.
  • Bundled Codex and Copilot integrations now keep mirrored chat history and transcript updates tied to the correct OpenClaw session as storage evolves, while existing file-backed active transcripts continue working during the migration. #89518 Thanks @jalehman.
  • WebChat's current-session status now matches the conversation you are actually using, so the session identity, thinking level, token context, and cost details no longer come from the fallback main session. #89800 Related #89773. Thanks @killo3967, @sweetcornna.
  • Your conversation is less likely to lose its context after you press stop during automatic compaction because the compaction request is now cancelled too. #89886 Related #89868. Thanks @lykeion-dev, @openperf, @vincentkoc.
  • When cross-agent session access is blocked, OpenClaw now lists all required visibility, agent-to-agent, and allow-list settings, helping operators correct policy configuration instead of chasing a nonexistent agent failure. #90489 Related #90443. Thanks @ramitrkar-hash, @sahibzada-allahyar, @vincentkoc.
  • openclaw memory status now shows an active light or REM dreaming phase instead of incorrectly reporting Dreaming: off, so operators can see that valid memory configurations are enabled. #93113 Related #67868. Thanks @agentarclab, @mrossit.
  • Timed-out QMD memory searches now stop their background work when the agent moves on, preventing abandoned processes from continuing to consume CPU and memory. #93394 Thanks @alix-007.
  • Repeated instructions sent after compaction now remain in the conversation, preventing lost turns, orphaned replies, and malformed history that some providers reject. #94328 Thanks @vincentkoc, @yetval.
  • Memory Wiki's Stale Pages report now leaves durable concept and synthesis pages out of freshness warnings, keeping attention on source and entity pages that may actually need review. #94369 Thanks @sunnyshu0925, @vincentkoc.
  • Long embedded runs with recent progress are now less likely to be interrupted by stale-session recovery, while genuinely stalled runs can still be cleared so queued work continues. #94701 Thanks @imadal1n, @mrclawfield.
  • Ollama memory search now respects a configured smaller embedding dimension and keeps indexes for different dimensions separate, avoiding incompatible vectors being mixed together. #94811 Thanks @mushuiyu886.
  • Memory searches and targeted refreshes now stay connected to the correct OpenClaw session even when transcript filenames change or QMD exports use a different name. #95087 Thanks @jalehman.
  • Long-running conversations with screenshots or other images now keep their continuity more consistently when OpenClaw makes room for new messages, instead of repeatedly filling up without moving the retained conversation forward. #95128 Thanks @yetval.
  • Windows users can now run QMD-backed memory indexing and search through configured absolute memory.qmd.command paths, including drive-letter and UNC locations, without OpenClaw stripping the path separators before launch. #95274 Related #92302. Thanks @ardooken, @ly85206559.
  • Usage footers selected with /usage full or /usage tokens now remain visible after daily or idle session rollover, so users do not have to turn them on again. #95322 Thanks @litang9.
  • Follow-up replies, reactions, threaded messages, and status checks stay with the chat they belong to after webchat or system activity, while real channel switches still clear outdated routing details. #95467 Thanks @yetval.
  • Long-running main conversations now keep their prior context when users return after an overnight or delayed follow-up, rather than silently starting over after an otherwise normal completion. #95472 Thanks @xydt-tanshanshan.
  • People with large session histories can list, preview, and find sessions without multi-second freezes, while older mixed-case session keys are still migrated at startup. #95699 Thanks @jalehman, @jzakirov.
  • Fixes delivered replies sometimes being saved to the wrong conversation history, or omitted from it, when operators use a custom or per-agent session.store, improving continuity and auditability for the intended session. #95782 Related #95781. Thanks @youngting520.
  • Saved session-memory summaries now leave out raw model tokens, tool-call blocks, media placeholders, role tags, and stale NO_REPLY markers so future conversations keep useful context. #95791 Thanks @sweetsophia, @vincentkoc, @yb0y.
  • Long-running OpenAI sessions using Codex/ChatGPT OAuth can now compact without a separate API key, whether /compact is run manually or triggered automatically. #95831 Related #95693. Thanks @sallyom, @yui-tien.
  • Long, tool-heavy sessions now compact oversized conversations instead of getting stuck when a large tool result appears at the end. #95860 Related #78478. Thanks @jw8957, @wzhgba, @yetval.
  • When memory_search is unavailable because the Node runtime lacks node:sqlite, OpenClaw now points users to a compatible runtime instead of sending them through unrelated embedding-provider troubleshooting. #95916 Thanks @rrrrrredy, @vincentkoc.
  • Developers and operators inspecting a compacted Copilot session now get its summary, before-and-after token counts, and session details instead of an incomplete result. #96049 Thanks @vincentkoc.
  • The /stop and abort commands now keep stopping active runs, clearing queued followups, and ending related subagents promptly even when session keys need canonicalizing or abort metadata cannot be saved. #96201 Thanks @jalehman.
  • Voice Wake upgrades now keep existing trigger phrases and routing rules working as OpenClaw moves them from retired settings files into the shared state database. bdf81a8
  • Upgrades from older OpenClaw state layouts now preserve update notifications, check throttling, available-version records, and automatic-update attempt history as that state moves into SQLite. eb00d49 Thanks @vincentkoc.
  • Plugin-channel conversations keep their intended session more reliably through startup, doctor checks, and state repairs, with older binding records migrated into OpenClaw's shared database. 9f888d9
  • Windows memory-backed session syncing now keeps using the intended transcript file even when path formatting differs. b3b5b08 Thanks @vincentkoc.
  • Embedded agent runs with a missing or blank session key now stay attached to the intended session instead of being sent through inconsistent session routing. 911f853 Thanks @vincentkoc.
  • When a model guesses the wrong tool name, Tool Search and Code Mode now show how to find and retry the correct tool, reducing the risk that long-running sessions get stuck or lose durable memory during compaction. #93374 Related #92273. Thanks @mushuiyu886, @poison, @vincentkoc.
  • Fixes assistant replies disappearing from webchat, Control UI, Feishu, and other embedded conversations after compaction, keeping refreshed chats readable and follow-up requests separate. #95484 Related #76729. Thanks @maweibin, @njuboy11, @vincentkoc.
  • OpenClaw memory features now keep active, reset, and deleted transcript coverage aligned with configured session stores and agent ownership, making dreaming, QMD exports, indexing, and sync less likely to miss or misattribute conversation history. #96162 Thanks @jalehman.
  • Gateway TLS setup now rejects blank certificate or key paths clearly or uses OpenClaw's defaults, avoiding confusing startup and certificate-generation failures while preserving valid paths. #94054 Thanks @miorbnli.
  • Configured plugin policies keep blocking or rewriting sensitive tool calls after Gateway registry changes, reloads, or later hook initialization instead of being silently skipped. #94545 Thanks @jesse-merhi.
  • Mobile operators with operator.approvals can now see and resolve chat-triggered exec approvals on the iOS device that started the request, including while the app is open, without relying only on push notifications. #95175 Thanks @joshavant.
  • Control UI users now get the patched DOMPurify release, reducing exposure to the GHSA-cmwh-pvxp-8882 sanitizer vulnerability without changing how the interface behaves. #95691 Thanks @vincentkoc.
  • "Always allow" approvals for plugin conversation bindings now carry over from the old settings file and are less likely to be lost or overwritten when multiple OpenClaw processes are running. ae41b00 Thanks @vincentkoc.
  • Matrix users now see that the active recovery key is required before a forced cross-signing reset can proceed, preventing a second reset from leaving encryption recovery and room-key backups unusable. #95720 Related #78396. Thanks @jteddy, @vincentkoc, @xialonglee.
  • #### Slack router relay mode
  • Slack router relay mode gives managed and multi-gateway deployments a supported way to centralize incoming Slack traffic while preserving gateway ownership of mentions, threads, and replies.
  • Managed Slack deployments can now use a central router to send mentions and ongoing threads to the right OpenClaw gateway while replies still appear through Slack. #94707 Thanks @pash-openai, @sjf-oa.
  • #### Raft External Agent wake bridge
  • The Raft channel and Raft plugin now support the local CLI wake path for External Agents.
  • Raft External Agent operators can now wake an OpenClaw agent when a workspace has pending work through the supported local CLI bridge, with named profiles and checks for missing CLI prerequisites. #95497 Thanks @vincentkoc.
  • #### Official plugin installation and repair
  • Plugin management and the plugin inventory now cover more official integrations through normal installation, update, and repair workflows.
  • When plugins.allow uses a channel or package name instead of the real plugin id, startup guidance now identifies the unmatched entry and shows the discovered plugin ids needed to correct the configuration. #68389 Related #68352. Thanks @aym9999, @jirboy, @lyfuci, @pahuchi-joe, @zmxccxy.
  • Plugin trust warnings for first-time or fresh installs now include a ready-to-copy plugins.allow example and commands to list or inspect plugin ids, so users can resolve the warning before trusting or reinstalling plugin code. #78105 Related #68780. Thanks @jirboy, @pahuchi-joe.
  • Codex migrations now work with standard global plugin installs because openclaw migrate can find the installed provider instead of failing with Unknown migration provider. #89612 Related #89609. Thanks @mugabuga, @zerone0x.
  • Plugin installs and updates recover from stale OpenClaw-managed dependency pins instead of failing with npm EOVERRIDE, without later synchronization downgrading or removing packages users installed explicitly. #91786 Related #91772. Thanks @amknight, @mkdelta221.
  • Channel plugin developers can now carry native sender and conversation identifiers through hooks and selected exec workflows, giving integrations more precise routing without breaking existing sender and chat fields. #91903 Thanks @lanzhi-lee, @vincentkoc.
  • Plugin discovery now repeats fewer blocking filesystem checks during startup, reducing avoidable cold-start work for bundled plugin trees, especially on slower Windows filesystems, without changing bundle discovery behavior. #93919 Related #76209. Thanks @ml12580, @shenhonglong456-ai.
  • Plugin Gateway methods now work through openclaw gateway call after registration, so plugin authors can use them from scripts and cron jobs instead of hitting an unknown method error. #94154 Related #94127. Thanks @brycemurray, @pick-cat, @vincentkoc.
  • ClawHub skill discovery and install checks are less likely to stall or crash OpenClaw because oversized or stalled marketplace responses are now stopped before they can exhaust memory. #95226 Thanks @alix-007.
  • Pinned official plugins no longer stay on an old release when operators follow the repair advice from openclaw doctor or deep gateway status after an upgrade. #95541 Thanks @ooiuuii, @vincentkoc.
  • Managed npm plugin updates are less likely to break work on a running gateway with missing-module errors, because the older plugin files remain available until a later gateway start cleans them up. #95589 Thanks @ooiuuii, @vincentkoc.
  • Official plugin cards for supported brands now show recognizable icons in ClawHub and other catalogs, and plugin authors can provide marketplace artwork through the documented manifest field. #95845 Thanks @patrick-erichsen.
  • Official plugin icons in ClawHub and other catalogs are no longer forced into the same hard-coded color, allowing Simple Icons to use its default artwork instead. #95987 Thanks @patrick-erichsen.
  • Docker users now have an official openclaw/openclaw Docker Hub mirror alongside GHCR, with versioned beta releases kept from moving the stable latest and main aliases. #97122 Thanks @vincentkoc.
  • Git-based OpenClaw installs now use the repository's pinned pnpm version even when another global pnpm or surrounding project package manager is present, so setup commands no longer run against the wrong package-manager environment. bd74a62 Thanks @vincentkoc.
  • ClawHub skill-card and update requests now complete or time out predictably even when they receive an unusually large timeout value. 8cd0c11 Thanks @vincentkoc.
  • Windows users can complete source installs without a llama.cpp setup step blocking or slowing them, and the installer restores their existing shell setting afterward. ea9065b Thanks @vincentkoc.
  • More official channel, provider, and web-search plugins can now be installed or repaired through normal external package catalogs while still being recognized from their existing credentials. #95683 Thanks @vincentkoc.
Channels and Messaging
  • #### Additional channel fixes
  • Additional Telegram and channel configuration fixes cover narrower delivery and setup problems.
  • Telegram reply chains keep cached replies attached after context changes instead of failing when those cached replies are reused. #82909 Thanks @lidge-jun.
  • Fixes Discord dropping an entire long reply with fenced code blocks when a closing code fence lands near the 2,000-character message limit. #95661 Thanks @ly-wang19.
  • Slack operators can now store tokens and signing secrets as supported SecretRef inputs, while reads, writes, allowlist and target lookups, and setup checks use the resolved credentials instead of rejecting or misreading the references. 7da955f Thanks @vincentkoc.
  • Channel capability checks now return a clear timeout when an integration stops responding, keeping troubleshooting from hanging in a terminal or automation run. 8ecdb97 Thanks @vincentkoc.
Providers and Models
  • #### Additional provider and model fixes
  • Additional model configuration fixes improve selection, usage reporting, status output, and streaming.
  • After changing the default model, starting a fresh channel session with /new or /reset now uses the new default instead of silently reusing the previous cached model, while explicit /model overrides remain unchanged. #77339 Related #77322. Thanks @mjamiv, @zaynl.
  • Behind HTTP or HTTPS proxies, Codex/OpenAI usage and quota checks in openclaw status --usage --json and the Control UI now retrieve usage windows instead of failing when chatgpt.com is unreachable directly. #93943 Related #78714. Thanks @tnzgit, @turbotheturtle.
  • /status now keeps the active model and how to clear a pinned choice on one compact line, so Discord and other chat users can scan model status without a multi-line explanation. #95797 Thanks @solvely-colin.
  • Anthropic streaming responses now keep interleaved text, thinking, and tool-call updates attached to the correct response block instead of mixing them when several blocks are active at once. #96013 Thanks @vincentkoc.
Memory, Sessions, and State
  • #### Additional session and memory fixes
  • Additional memory fixes cover resume, indexing, synchronization, and cleanup edge cases.
  • Memory-wiki status cards and bridge-backed source sync are less likely to fail during simultaneous page rewrites because OpenClaw now retries the transient path mismatch while still stopping unsafe or persistent filesystem writes. #94443 Related #92134. Thanks @cknzraposo, @zengwen-dt.
  • Fixes recent-session resume opening a fresh conversation for users with long workspace paths instead of returning to their existing transcript. #94578 Related #94577. Thanks @rohitjavvadi, @vincentkoc.
  • Memory Wiki now keeps user-written notes intact when an existing source page is re-ingested or synced, while still refreshing its generated content. #95614 Thanks @yetval.
  • Fixes Memory Wiki repeatedly copying its own generated source pages back into itself when its vault is stored inside the workspace memory folder, avoiding duplicate files, repeated cleanup, and unnecessary memory index growth. #95666 Related #95657. Thanks @johannes0402, @turbotheturtle, @vincentkoc.
  • For operators using Active Memory with memory-core dreaming, nightly dreaming jobs no longer start unnecessary recall work and hit 45-second timeouts, while regular web chats continue to receive memory recall. #95721 Related #78500. Thanks @vincentkoc, @vishutdhar, @xialonglee.
  • Agent sessions with many tool calls repair out-of-order results with less repeated work while keeping each result paired with the right tool call. #96014 Thanks @vincentkoc.
  • Windows qmd-backed memory work now stops all related processes after availability probes and command timeouts, preventing qmd children from continuing to run in the background. 830691b
Gateway, Security, and Trust
  • #### Restart and readiness recovery
  • Gateway health, troubleshooting, and openclaw agent workflows now report and recover from more runtime failures clearly.
  • When a configured or explicit remote gateway is slow but reachable, openclaw gateway probe --timeout ... now waits for the requested timeout instead of reporting it unreachable after a shorter internal cutoff. #89859 Related #65355. Thanks @hellocli, @mushuiyu886.
  • Long or parallel internal subagent runs now avoid unnecessary live-preview processing, while visible subagent sessions still show live updates and final responses. #91906 Thanks @lanzhi-lee, @vincentkoc.
  • ACP conversations, especially Kiro-backed threads, now continue past the first reply by starting a fresh session when the backend can no longer resume the old one. #93547 Related #87830. Thanks @amersheeny, @chouzz.
  • When Linux memory pressure kills a child command or session, systemd-managed OpenClaw gateways now stay running and keep channel connections alive while reporting the child failure. #93585 Thanks @snowzlm.
  • Canceling an OpenClaw run during tool work now ends it promptly instead of starting another model turn or leaving the session locked. #94412 Thanks @szsip239, @vincentkoc.
  • Scheduled OpenClaw jobs using cloud models now recover from silent, stuck model calls by default, helping prevent later cron work from backing up while local or self-hosted providers keep their existing timeout behavior. #94445 Thanks @bek91.
  • Gateway readiness checks now turn unhealthy during a restart drain, preventing traffic managers from sending new work to a Gateway that is temporarily rejecting requests. #94915 Related #78136. Thanks @markoub, @maxschachere, @vincentkoc.
  • Mac users can keep LaunchAgent-managed gateways running through OpenClaw upgrades instead of seeing repeated crash-and-restart loops when older text-transform runtime code is still cached. #95081 Related #95057. Thanks @849261680, @yveslarose.
  • Codex-powered conversations in TUI, WebChat, and compatible streaming APIs now show replies as they are written, while replacing provisional text cleanly so the final answer does not include stale drafts. #95404 Related #95422. Thanks @agonza1, @vincentkoc.
  • After a gateway restart, users no longer see a misleading retry notice when OpenClaw is already resuming the interrupted reply or reporting the actual recovery failure, reducing unnecessary duplicate attempts. #95431 Thanks @moeedahmed, @vincentkoc.
  • Long, tool-heavy agent sessions now retain prompt-cache savings as results accumulate, reducing avoidable delays and cost from resending rewritten history between turns. #95624 Thanks @vincentkoc.
  • Gateway restarts no longer leave configured Codex, Copilot, or trusted plugin-based agents temporarily unavailable, and untrusted workspace plugins remain blocked from activating themselves. #95652 Thanks @vincentkoc.
  • Long responses, busy tool streams, image-heavy requests, and memory recall now incur less CPU and filesystem overhead without requiring settings or workflow changes. #95697 Thanks @vincentkoc.
  • Operators can again add or update scheduled announcements for known channels in no-config setups, while configured environments still reject disabled, stale, ownerless, or unknown destinations before delivery. #95754 Thanks @vincentkoc.
  • macOS users are less likely to see a false port-conflict failure when stopping or updating a managed gateway, because OpenClaw briefly waits for normal shutdown to release the port while still reporting conflicts that persist. #95886 Thanks @fuller-stack-dev.
  • Copilot-backed agents can now ask users a question and accept the answer through OpenClaw's normal chat reply flow, while compact tool-search and code-mode controls avoid loading the full tool catalog into the session. #96005 Thanks @vincentkoc.
  • Gateway restarts on systemd or container setups no longer leave old Codex or Claude adapter processes behind, helping new ACPX sessions start without minutes-long cleanup stalls after repeated restarts. #96032 Thanks @t2wei, @vincentkoc.
  • Copilot-backed sessions now show plan updates as work unfolds, and their native child tasks stay visible through completion or failure instead of disappearing from OpenClaw's task view. #96062 Thanks @vincentkoc.
  • Connected agents such as OpenCode now start through OpenClaw even when their harness cannot select a requested model, while genuinely unsupported model choices still return the original error. #96068 Related #95869. Thanks @sabatech-dev, @vincentkoc.
  • Plugins using heartbeat_prompt_contribution now deliver their heartbeat-specific context to models when agents run through harness runtimes such as the Codex app-server, without affecting ordinary user turns or plugins that do not use the hook. #96233 Thanks @azogheb, @vincentkoc.
  • Windows gateway cleanup and listener checks now handle UTF-16 WMIC command-line data consistently, reducing failed or conflicting identification of the running gateway process. 15c880a Thanks @vincentkoc.
  • Long-context, tool-heavy agent sessions now keep prompt-cache reuse steadier across repeated turns without losing per-result size limits, while advanced operators can configure larger tool-result caps for large-context models without configuration rejection. a60947f Thanks @vincentkoc.
  • Long, tool-heavy agent sessions are less likely to bloat model requests as tool output accumulates, while repeated turns keep stable prompt-cache reuse. 2f33999 Thanks @vincentkoc.
  • Gateway restarts now use OpenClaw's durable state database for the handoff, while stale, malformed, wrong-process, or superseded requests are discarded before they can affect the restart. 0ad48da
  • Gateway status, doctor, and restart diagnostics now retain recent restart details in OpenClaw's shared state database, while expired or malformed records are still discarded. a39a3b7 Thanks @vincentkoc.
  • Gateway restarts and managed-service updates now keep the correct continuation message, avoid reusing stale handoff state, and mark failed update handoffs consistently. 514b336 Thanks @vincentkoc.
  • Gateway-launched agents no longer lose owner-only OpenClaw tools during tasks such as live cron checks, so authorized operations can use the intended tools with the correct request context. c2ee9b0 Thanks @vincentkoc.
  • Malformed gateway restart requests now fail clearly without scheduling a restart, preventing bad or accidental integration calls from unexpectedly restarting the gateway. 108d6d7 Thanks @vincentkoc.
  • Stale node requests queued by the gateway now expire automatically, so old work is less likely to linger and affect later activity. f6d432e
  • Plugin workflows are less likely to stall or overload the gateway when an integration requests too much subagent session history, because each read is now capped at a safe limit. b66b450 Thanks @vincentkoc.
  • Image descriptions now handle extremely large timeout settings consistently by capping them to a safe runtime limit instead of risking timer overflow. 88b21fc
  • Embedded agent sessions now wait reliably for another session to release its file lock, even with an extremely large timeout, instead of risking timer overflow. 4c736df Thanks @vincentkoc.
  • Queued commands with extremely large task timeout settings now time out reliably because OpenClaw caps the wait at the runtime's safe maximum. 1f6ae32 Thanks @vincentkoc.
  • Fixes normalization-core exposing the wrong string-coercion entry point and ACP sessions showing an outdated fast-mode value, so integrations receive the intended API and users see the mode actually in effect. 93ad397 Thanks @vincentkoc.
  • Fast auto runs now deliver final replies more consistently, with progress-reset handling limited to automatic mode so it does not interfere with responses or forwarded callbacks. 9e8ab08 Thanks @vincentkoc.
  • Agent sessions using OpenAI Responses now resume tool-based work without failing or losing progress when replayed history contains mismatched tool requests and results. b4bc1f2 Thanks @vincentkoc.
  • Completed plugin subagent and QA runs are no longer misreported as failures when gateways return alternate completion envelope shapes, making successful handoffs more reliable for plugin authors and operators. d1b268f Thanks @vincentkoc.
  • Fixes completed subagent tasks sometimes ending without an update, so users receive the result or the parent agent's next step. 68a1e00 Thanks @vincentkoc.
  • #### Remote result and media delivery
  • Additional Gateway fixes return remote media and completed subagent results to the active conversation more reliably.
  • Generated images from a remote Codex app-server now arrive as attachments instead of showing Media failed or returning only text after successful generation. #96212 Thanks @sjf-oa.
  • When a subagent finishes, its result now reaches the active parent run more reliably instead of appearing silent. 7fc4bbc Thanks @vincentkoc.
  • #### Additional security and trust fixes
  • Additional secret-handling hardening keeps trusted package paths within the intended boundary.
  • Trusted OpenClaw package sources now reject lookalike sibling paths, so trusting /artifactory/openclaw no longer also admits paths such as /artifactory/openclaw-malicious. 12c34fc Thanks @vincentkoc.
Clients and Interfaces
  • #### Client sends and reconnects
  • WebChat, the Control UI, mobile clients, and the terminal UI now recover completed, rejected, or interrupted sends and reconnects without leaving conversations looking stuck.
  • When a WebChat message fails before the agent starts, WebChat and Control UI now show the session as failed instead of leaving it looking like it is still running. #84352 Thanks @jesse-merhi.
  • Fixes the Control UI session picker getting stuck behind hidden subagent sessions, so Load More reaches the next usable chat without showing a misleading total. #89323 Related #89249. Thanks @giodl73-repo, @originsecured-do.
  • When users reopen a Control UI conversation from History, their prompts now appear with the assistant's replies, preserving the question-and-answer context without blank gaps in long transcripts. #93841 Related #90241. Thanks @mushuiyu886, @pronzcw.
  • Control UI deployments behind a path prefix now keep manifest, favicon, and service-worker requests under that prefix, avoiding confusing root-level 403 errors after login. #94204 Related #94157. Thanks @hugenshen, @xrow.
  • Android users can now open Health log and Skill rows in Settings for readable details, making it easier to troubleshoot gateway activity, check skill setup and status, and understand how to pair with an existing setup code. #95148 Thanks @tosko4.
  • Sent prompts no longer reappear in the Control UI composer after a send, so users can switch sessions or start their next message without risking a duplicate send or overwriting a new draft, while intentional re-entry still works. #95503 Related #89466. Thanks @vincentkoc, @zhangguiping-xydt, @zhong18804784882.
  • Android users now get a cleaner Overview where connection status, the configured agent, node health, approvals, recent sessions, and Chat and Talk actions are visible at a glance. #95557 Thanks @joshavant, @solvely-colin.
  • Android users can now refresh and resolve gateway command approvals from the in-app Approvals screen, choosing Allow Once, Always, or Deny while connected. #95593 Thanks @solvely-colin.
  • iOS users now avoid surprise notification prompts and get clear guidance when approval alerts are unavailable, with permission managed from one predictable Settings screen. #95640 Thanks @joshavant.
  • Local TUI shutdowns now stay within safe timer limits even when OPENCLAW_TUI_LOCAL_RUN_SHUTDOWN_GRACE_MS is set extremely high. c21dcfc
  • Canvas A2UI now serves only the current app assets after each build, so outdated compatibility images and leftover files are less likely to appear. a89e65c Thanks @vincentkoc.
  • iOS push relay setup failures are easier to pinpoint because registration diagnostics show where setup stopped while keeping sensitive push credentials out of logs. f2b8668 Thanks @joshavant.
  • iOS devices are now enrolled for push notifications only after users accept the hosted relay disclosure and allow notifications, preventing registration data from being published before consent. 8efed50 Thanks @joshavant.
  • Fixes chat, voice, TUI, and forwarded sends sometimes appearing stuck or disappearing after the gateway had already finished or rejected them, so affected clients now clear the pending state, restore retryable input, refresh history, or show a useful failure. #91049 Related #91048. Thanks @nxmxbbd.
  • #### Additional client interface fixes
  • Additional Control UI, mobile, and desktop fixes improve display accuracy, accessibility, onboarding, and app behavior.
  • Restores the OpenAI/Codex usage quota in the expanded Control UI chat sidebar, so users can check their limits without leaving the conversation. #94219 Related #93041. Thanks @jazzroutine, @pick-cat.
  • iOS screens now use consistent OpenClaw accent and status colors across onboarding, settings, chat, approval prompts, voice permissions, widgets, and shared chat views. #94627 Thanks @zats.
  • The Control UI can now create Early Morning jobs with the Silent preset in the main session and without notifications, instead of leaving the dialog open with no visible result. #95459 Related #95073. Thanks @vincentkoc, @vporton, @zoowh.
  • At the million-token boundary, Control UI badges and usage readouts now show "1M" instead of the confusing "1000k", while the underlying token counts remain unchanged. #95485 Thanks @narahariraghava, @vincentkoc.
  • The Control UI Overview now counts and flags only enabled cron jobs that still need attention, while disabled jobs retain their past failure details without appearing as current problems. #95723 Related #95716. Thanks @voytas75, @zengwen-dt.
  • Control UI users now see shorter System, Light, and Dark theme tooltips, while screen readers announce less repetitive labels without losing the surrounding Color mode context. #95837 Thanks @hannesrudolph, @sannidhyasah.
  • Raw configuration no longer appears missing in Settings after switching from the form view, because the JSON is brought back into view instead of retaining the previous scroll position. #96145 Related #94202. Thanks @sunlit-deng, @vporton.
  • New iOS users now reach OpenClaw's welcome and onboarding before iOS asks for local-network access, while existing users still get the request when opening gateway setup or otherwise needing LAN gateway discovery. #96181 Thanks @joshavant.
Plugins and Packaging
  • #### Additional plugin and package fixes
  • Additional plugin management fixes improve installation, verification, package resolution, and updates.
  • People installing or updating the official Yuanbao channel plugin through OpenClaw's trusted catalog now get version 2.15.0, with the expected integrity check and missing-plugin guidance aligned to that release. #94470 Thanks @jase-283.
  • First-run onboarding can now install the bundled gog skill through Homebrew without failing on the removed third-party tap formula. #95019 Related #95017. Thanks @sedrak-hovhannisyan, @vincentkoc, @zengwen-dt.
  • Canvas, Discord, Slack, Voice Call, and WhatsApp users keep the same skill guidance with each installed or bundled plugin, while references to the former root skills/... paths need to move into the relevant plugin directory. #95664 Thanks @vincentkoc.
  • ClawHub skill verification now accepts the same @owner/<slug> reference used for installs and updates, so users can check the intended publisher without switching to an ambiguous bare slug. #95992 Thanks @patrick-erichsen.
  • OpenClaw's install-time package-manager warning now identifies npm, Yarn, Yarn Berry, and Corepack-style launchers correctly, avoiding misleading guidance when those tools run through alternate executable names. 11a2e03 Thanks @vincentkoc.
  • Package URL installs now handle oversized download timeouts without failing before available package data can be resolved. c310f8c
  • Plugin and CLI developers now see a clearer supported command-formatting API, while device pairing, node registration, and doctor guidance keep producing the same shell-safe commands. 23b4f33
  • Windows ARM64 users now get matching ARM64 Node and MinGit downloads when running the PowerShell installer through an x64-emulated shell. fac091b Thanks @vincentkoc.
  • Default OpenClaw installs no longer spend time building optional llama.cpp support, avoiding native-build failures for users who did not enable it. cc1b3a8 Thanks @vincentkoc.
Docs and Admin Tools
  • #### Setup and command reliability
  • The OpenClaw CLI, tab completion, and openclaw doctor now handle more setup and repair cases cleanly.
  • OpenClaw's zsh tab-completion menu now displays option descriptions containing $ variables or backtick-wrapped examples literally instead of evaluating them as shell input and corrupting the menu. #64490 Thanks @edenkangdw.
  • After upgrading from older sandbox storage, operators now get a clear openclaw doctor warning about leftover registry files and can use openclaw doctor --fix to migrate or clean them up. #84326 Thanks @giodl73-repo.
  • Operators can now use doctor --lint to spot stale legacy Gateway services and preview cleanup, while intentional extra services remain informational and do not fail the default check. #84340 Thanks @giodl73-repo.
  • macOS gateway operators now get a warning before reinstall, repair, or restart overwrites custom LaunchAgent wrapper behavior, while openclaw status distinguishes CLI-only missing-secret checks from the installed service. #90537 Related #90518. Thanks @turbotheturtle, @vincentkoc.
  • Long, multiline, or code-heavy prompts can now be sent to openclaw agent with --message-file, avoiding fragile shell quoting and reporting invalid files before dispatch. #93351 Thanks @ooiuuii.
  • Fixes scheduled doctor --fix --non-interactive repairs restarting an already-running gateway after a temporary health-check failure, so unattended maintenance no longer interrupts the live service. #94148 Related #78217. Thanks @esqandil, @zhangguiping-xydt.
  • openclaw configure and bare openclaw config now stop with clear subcommand guidance when run from scripts or pipes, instead of opening a partial interactive wizard and exiting unclearly. #94238 Related #93953. Thanks @nianjiuzst, @ruomuxydt.
  • Multi-agent operators can now use openclaw gateway usage-cost to view costs for one configured agent or all agents while the existing default-agent command remains unchanged. #94483 Thanks @ly-wang19.
  • Archived Workboard cards no longer clutter the default openclaw workboard list output, while --include-archived and JSON output still provide access when needed. #94562 Related #94555. Thanks @ecican, @vincentkoc, @zengwen-dt.
  • OpenClaw Doctor now gives accurate guidance for working isolated shell-prompt cron jobs instead of repeatedly suggesting a --fix command that cannot clear the warning. #94784 Related #94655. Thanks @altaywtf, @geekoagent, @zengwen-dt.
  • Fixes openclaw doctor showing a fix-required warning for healthy local GGUF memory setups after an intentionally skipped readiness check, while preserving the warning when the configured local model is actually missing. #95393 Related #92582. Thanks @mikasa0818, @neekolascmd, @vincentkoc.
  • On Windows, installer-created gateway tasks now run in the background without a console window that users could accidentally close and stop the gateway. #95480 Related #89231. Thanks @cameronweller, @mikasa0818, @vincentkoc.
  • Agent channel bindings now reject malformed account specs such as matrix:work:extra with a clear error instead of silently routing the agent to a different account. #95572 Thanks @ly-wang19.
  • ClawHub skill updates now honor your configured install safety policy, and openclaw skills update --all updates only tracked ClawHub skills instead of unexpectedly installing other configured skills. #95684 Thanks @vincentkoc.
  • Windows restart and gateway startup workflows are more reliable because OpenClaw now hands commands to the trusted system cmd.exe path instead of depending on process lookup. 7dd01d1 Thanks @vincentkoc.
  • Windows gateway cleanup and listener checks are more reliable when PATH lookup is incomplete, so operators can identify the gateway process and free an occupied port without installed system tools being missed. e9b694e Thanks @vincentkoc.
  • On Windows, OpenClaw startup and TUI Codex handoff now find bun, codex, and other runtime binaries through the trusted system locator even when another where command appears earlier on PATH. 72b9bc7 Thanks @vincentkoc.
  • Windows port diagnostics now use the intended system tools even when PATH entries are missing or shadowed, so gateway and service port conflicts are less likely to be obscured by command-resolution failures. c4facb2 Thanks @vincentkoc.
  • Windows daemon recovery is less likely to miss process detection or cleanup when PATH is incomplete, unusual, or shadowed because scheduled-task fallback now finds PowerShell and taskkill in trusted system locations. 2a140e6 Thanks @vincentkoc.
  • OpenClaw now keeps config recovery markers, last-known-good snapshots, and suspicious-read history in its shared state through migration, without leaving a separate config-health log file behind. 6daabd2 Thanks @vincentkoc.
  • On Windows, Crabbox commands launched through Node package shims now receive provider flags, shell commands, and special shell characters as entered instead of losing or reinterpreting them. 54d24cd Thanks @vincentkoc.
  • Windows-targeted Crabbox workflows are less likely to fail or fall back to slower shell handling when launching Node tools through .cmd and .bat shims. d48dcc6 Thanks @vincentkoc.
  • Windows users can run crabbox, git, and other Node-backed tools through npm-installed command shims without Crabbox stopping before the tool opens. 77f4e45 Thanks @vincentkoc.
  • openclaw doctor now checks profiles that omit tool policy settings without treating the valid omission as an error. 03ba09b
  • openclaw doctor no longer shows misleading tool-section warnings when it cannot evaluate a custom preview profile. 420a0e6 Thanks @vincentkoc.
  • openclaw doctor now limits preview warnings to tool profiles it can evaluate, avoiding misleading configured-grant warnings for unknown profiles. 541f7ff Thanks @vincentkoc.
  • Windows users can install OpenClaw from source without dependency setup being blocked by the installer forcing npm or pnpm scripts through cmd.exe. 1252378 Thanks @vincentkoc.
  • #### Tools and scheduled work
  • Scheduled jobs and tool workflows now finish, validate, and report failures more consistently.
  • Isolated cron jobs using deleteAfterRun now remove their temporary session and transcript after finishing, including runs with delivery disabled, reducing stale files, accumulated context, and manual cleanup. #84794 Related #84707. Thanks @bottenbenny, @turbotheturtle.
  • Individual scheduled jobs can now use their own fallback models, run with fallbacks disabled, or return to normal fallback inheritance through the CLI instead of requiring operators to edit lower-level payload data. #93369 Related #90302. Thanks @849261680, @walliiee.
  • Cron history now reliably finds entries whose job IDs include extra surrounding spaces, and rejects nested or blank IDs before they can create log records that cannot be read back safely. #93567 Thanks @alix-007, @vincentkoc.
  • Adding or removing a cron job no longer causes another recurring job that is already due to lose its pending run. #94323 Thanks @yetval.
  • Word, PowerPoint, and Excel document reads and writes now use the intended .docx, .pptx, or .xlsx path instead of failing against a made-up extension. #95805 Related #93326. Thanks @bhnan, @lzyyzznl, @vincentkoc, @xzh-icenter.
  • Browser automation users keep the same reference-rich snapshots, including useful branches in compact results, with less avoidable processing during snapshot generation. #96072 Thanks @vincentkoc.
  • Fixes timed-out commands and interrupted core updates on Windows sometimes leaving child processes running, so OpenClaw can stop the full process tree more reliably after cancellations, timeouts, or update cleanup. a192b2e Thanks @vincentkoc.
  • Windows users are less likely to see agent-managed tool installs fail while unpacking ZIP downloads such as ripgrep, because OpenClaw now uses the built-in Windows extraction programs instead of relying on PATH lookup. a5fde91
  • Windows setup and runtime checks now find required tools more reliably by using the trusted System32 resolver instead of depending on an unexpected PATH entry. d3b4444 Thanks @vincentkoc.
  • SDK runs created with timeoutMs: 0 now keep the requested zero timeout without an unwanted client-side watchdog. 2bdcc83 Thanks @vincentkoc.
  • Stalled OpenClaw commands now stop reliably even when callers supply extremely large execution or idle-output timeouts. 1425bb3 Thanks @vincentkoc.
  • Commands given extremely large timeout settings now use a safe maximum instead of failing because the runtime cannot schedule the requested wait. 66b94ba
  • Provider-specific tool allow/deny settings now align more consistently with OpenClaw's doctor warnings, including configurations with provider aliases, model-specific keys, OpenRouter-style model IDs, or malformed policy entries. 8f2882f
  • #### Additional setup and CLI fixes
  • Additional openclaw config and CLI fixes improve diagnostics, pairing, startup, and command behavior.
  • Larger OpenClaw configurations can initialize and generate UI hints more efficiently, while sensitive fields continue to be marked the same way. #55018 Thanks @huangyandi-red, @vincentkoc, @xdhuangyandi.
  • Config changes that still need a manual gateway restart now show a clear restart-required notice with the original note preserved, instead of looking finished with a misleading config-patch ok message. #83041 Related #46797. Thanks @stache73, @xuruiray.
  • Help for doctor, gateway, models, plugins, sessions, and tasks now appears in tens of milliseconds, while commands such as sessions --help and tasks --help previously took about 1.6 to 1.8 seconds to begin responding. #89628 Thanks @yyzquwu.
  • OpenTelemetry trace backends such as Langfuse now show the actual provider/model name instead of "unknown" for slash-qualified model IDs. #89981 Thanks @mycarrysun, @vincentkoc.
  • Malformed or older device-pairing records no longer stop openclaw devices list from showing pending approval requests, while valid roles still appear normally. #93504 Thanks @ly-wang19.
  • OpenClaw now rejects SSH targets with stray leading or trailing colons before they can produce invalid SSH configuration or tunnel startup failures for SSH-backed sandboxes and gateways. #93887 Thanks @miorbnli.
  • Users whose non-interactive setup fails its local gateway health check now get runnable openclaw onboard --install-daemon or openclaw onboard --skip-health recovery commands instead of unsupported setup flags. #93994 Related #93947. Thanks @bk-z1, @nianjiuzst.
  • Gateway health and probe checks now accept the same custom --port used to start a local gateway, reject invalid ports early, and show the selected loopback target in JSON output. #94687 Related #79100. Thanks @bryantegomoh, @ozthedivine.
  • gateway --force now detects IPv4-only processes occupying the gateway port and still attempts cleanup when a port check is inconclusive, instead of mistakenly treating the port as free. #94949 Related #94426. Thanks @sunlit-deng, @vincentkoc, @wangwllu.
  • openclaw config validate now accepts command-based MCP server setups that explicitly use transport: "stdio", avoiding false validation errors while still rejecting invalid remote-style stdio configurations. #95102 Related #95082. Thanks @ken-jo, @lzyyzznl.
  • CLI image edits can now return multiple variants in one command with --count <n>, instead of being limited to the provider's default single result. #95300 Thanks @ly-wang19.
  • openclaw sessions export-trajectory now finds sessions that other session commands can already see when custom, ~-based, or {agentId}-templated stores are configured, without requiring the store path again. #95570 Related #95568. Thanks @youngting520.
  • Fixes infer inspect --name <id> --json showing flags that the matching CLI commands did not accept, so developers and operators can reliably discover supported model, auth, and transcription options. #95719 Thanks @ly-wang19, @vincentkoc.
  • People inspecting very large or out-of-order sessions can open usage details and still get the latest timestamped log entries without OpenClaw retaining the entire parsed log history in memory. #96019 Thanks @vincentkoc.
  • Operators can now set up the auth monitor, systemd timer, and Termux widgets for their own OpenClaw host without first replacing maintainer-specific hostnames and filesystem paths. af3e509 Thanks @vincentkoc.
  • Native Windows crabbox hydration now selects the required Windows daemon job automatically, avoiding failed or misrouted runs while leaving WSL2 and explicit job overrides unchanged. d5d9a82 Thanks @vincentkoc.
  • #### User operation documentation
  • The Gateway configuration and related user guides now give clearer setup and operating instructions.
  • People setting a local agent avatar can avoid missing images by keeping workspace-relative files under 2 MB, while HTTP(S) and data URI avatars are not subject to that limit. #78884 Related #65312. Thanks @wangjieweb3-design, @nyx-nocturna.
  • OpenClaw's default agent instructions now ask agents to check for suitable free or open-source solutions before proposing a custom build, while still allowing custom work when it is the better fit. #86608 Thanks @cablackmon.
  • Plugin authors can now use the documented targetSessionKey on subagent_ended events to match them with the corresponding spawn, instead of relying on agentId or childSessionKey fields that are not emitted. #95191 Related #95186. Thanks @ken-jo, @mahaohao-ch.
  • ClawHub skill links in OpenClaw docs and showcase cards now open the canonical owner-qualified pages, and install examples use copy-ready openclaw skills install @owner/<slug> references instead of older bare-slug routes. #95972 Thanks @patrick-erichsen.
  • #### Additional tool and automation fixes
  • Additional plugin SDK and automation fixes improve tool events, cron inputs, and Windows handoffs.
  • SDK applications now receive tool.call.failed when terminal tools fail or are blocked, instead of a misleading completion event, so existing failure handling can react correctly. #95383 Thanks @ly-wang19.
  • Fixes cron add and update requests being rejected when recognized job fields arrive with harmless trailing spaces, so schedules can be saved without relaxing checks for ambiguous or unsafe input. #95674 Related #95407. Thanks @nassiel, @zw-xysk.
  • Codex subagent monitoring handles large sets of child agents and transcript files with less unnecessary scanning, while older transcript filename formats continue to resolve as before. #96085 Thanks @vincentkoc.
  • Fixes native Windows crabbox hydration getting stuck or missing handoffs when the runner and daemon use different home directories, so both can find the same job state and stop files. f354889 Thanks @vincentkoc.
Additional contributions
  • Additional maintainer-facing contributions: #95308, #95465, #95625, #95649, #95681, #95857, #95870, #95872, #95879, #95890, #95909, #95922, #95946, #95967, #95983, #96258, #95094, #95466, #95876, #95880, #95919, #95928, #95991, #96235, #94272, #94622, #95898, #95901, #95999, #96055, #96226, #96271, #97909, #91502, #91506, #94700, #95406, #95858, #95933, #95944, #95947, #95952, #95961, #95971, #95975, #96003, #96017, #96030, #96246, #87121, #90223, #93378, #95475, #95499, #95602, #95653, #76668, #87861, #95243, #78715, #93502, #96044, #96057, #96061, #91193, #95706, #96179, #89912, #90439, #96182, #96191, #96193, #96195, #96204, #96206, #96213, #96218, #95893, #95930. Thanks @aniruddhaadak80, @coder999999999, @davinci282828, @harjothkhara, @hugenshen, @jalehman, @jason-allen-oneal, @joshavant, @kklouzal, @lizuju, @mehrazmorshed, @mmyzwl, @patrick-erichsen, @romneyda, @rushindrasinha, @shuofengzhang, @tayoun, @vincentkoc, @wadydx, @wangmiao0668000666, @whiteyzy, @yachiyo1680, @zats.
2026.6.10
Aug 24, 2026
Notable changes
  • Automatic fast mode starts short conversations quickly, then returns longer or fallback work to normal mode without losing visible state. Provider routing, channel progress, session identity, and trusted tool policies are more reliable, with smaller improvements spanning provider setup, diagnostics, and transcript tooling.
  • #### Automatic fast mode
  • Adds /fast auto so short conversational calls can start quickly, while longer or fallback work returns to normal mode with the effective state still visible. PR #85104, Issue #85087. Thanks @alexph-dev and @vincentkoc.
  • Shows the effective automatic fast-mode state in status instead of reducing it to on/off, and avoids carrying a cleared Codex service-tier choice into later runs. 8845f2f. Thanks @vincentkoc.
  • Keeps automatic fast-mode timing consistent when a turn switches to a fallback model. 075091d. Thanks @vincentkoc.
  • Keeps the original fast-mode timing and progress behavior when a live model switch retries a turn. d1e190f. Thanks @vincentkoc.
Show all changes (38 more)
Highlights
  • Keeps automatic fast-mode progress and reset behavior distinct from explicit fast mode after a run switches modes. 20aec98. Thanks @vincentkoc.
  • Shows the effective fast-mode value in connected-agent sessions instead of the configured value, so status reflects what the session is actually using. 9509aa0. Thanks @vincentkoc.
  • Keeps the effective automatic fast-mode setting visible through fallback transitions in connected-agent sessions. 7f5423c. Thanks @vincentkoc.
  • Keeps automatic fast-mode timing and progress consistent when reply and scheduled-agent runs retry or switch models. 6c29f88. Thanks @vincentkoc.
  • Keeps fast-mode cleanup and status consistent when a run switches between fallback models. c4694f8. Thanks @vincentkoc.
  • Shows the automatic fast-mode reset only when fallback work is finished, so status messages match the end of the transition. f4d93c8. Thanks @vincentkoc.
  • Shows reset and delivery progress at the right time when auto-reply or other follow-up runs retry or leave automatic fast mode. 684e440. Thanks @vincentkoc.
Channels and Messaging
  • #### Channel delivery and progress updates
  • Prevents the next turn after a scheduled message from losing what was delivered or whether delivery failed, so replies can use that context without exposing cron details in the channel. PR #93580. Thanks @jalehman and @scotthuang.
  • Prevents streamed channel progress from dropping a repeated status that represents a separate step, so each meaningful step remains visible in the draft. 2d42e52. Thanks @vincentkoc.
  • Prevents keyed streamed progress from staying on an older status, so viewers see the latest state instead of stale text. 8bb6472. Thanks @vincentkoc.
Providers and Models
  • #### Provider model catalogs and reasoning controls
  • Treats Zhipu/GLM overload responses as overloads, so a configured fallback is selected for the right reason instead of following the wrong failover path. PR #93241, Issue #93211. Thanks @0xghost42 and @zhengli0922.
  • Prevents Telegram, Slack, and Discord /think menus for live Ollama models from hiding supported levels, so users can choose valid reasoning settings without guessing. PR #94067, Issue #93835. Thanks @civiltox and @openperf.
  • Expands zai/glm-5.2 thinking choices beyond binary on/off and sends high or max requests as the intended Z.AI reasoning effort. PR #94136. Thanks @borclaw.
  • Prevents bundled Z.ai GLM-5 models from falling through to OpenAI and producing misleading API-key errors, so they use Z.AI by default. PR #94461, Issue #94269. Thanks @chrysb and @pandah97.
  • Adds GLM-5.2 and Kimi K2.7 Code to the OpenCode Go catalog with current limits, so users can select the models from OpenClaw. 66f84a9. Thanks @samson1357924.
  • Corrects kimi-k2.7-code capability listings so OpenCode Go users are not offered unsupported video prompts when the model accepts text and images. 715dc71.
  • #### Provider plugin onboarding
  • Prevents first-run setup from skipping the selected provider's credential prompt after plugin installation, so onboarding continues with that provider instead of falling back to OpenAI. PR #95792, Issue #95765. Thanks @snowzlmbot.
Memory, Sessions, and State
  • #### Session transcript SDK helpers
  • Adds a durable session-transcript SDK contract so plugins can read, append, publish, and lock the intended transcript without treating legacy file paths as identity. PR #95030. Thanks @jalehman.
  • #### Cross-channel session identity
  • Prevents a shared direct-message session from carrying the previous channel's identity after a switch, so status, reactions, threads, and message references target the current channel. PR #95328, Issue #95325. Thanks @gorkem2020, @jalehman, and @zengwen-dt.
Gateway, Security, and Trust
  • #### Prompt context boundaries
  • Keeps empty prompts separate from hook-added context during compaction or session reuse in Copilot and Codex sessions, so prompt boundaries remain consistent. PR #94838. Thanks @vincentkoc.
  • #### Trusted tool policy enforcement
  • Keeps approval-sensitive Gateway and plugin tools protected when connected extensions change, so configured safeguards continue to apply. PR #94545. Thanks @jesse-merhi.
  • #### Trusted package redirects
  • Prevents authenticated package-source tokens from being sent to an allowed redirect on another origin, while the valid redirected download still completes. b0df6dc.
Clients and Interfaces
  • #### Docker and Podman setup timeouts
  • Prevents Docker and Podman setup from running unbounded on hosts where GNU timeout is installed as gtimeout, so image pulls, builds, and detached startup receive the intended guard. 62b2e9e.
Plugins and Packaging
  • #### Codex service-tier clearing
  • Prevents cleared Codex service tiers from being persisted as explicit stale state, so resumed or switched conversations use the normal default instead. cd32d9f. Thanks @vincentkoc.
  • #### StepFun provider installation
  • Restores ClawHub discovery for the StepFun provider plugin, so operators can install it through either ClawHub or npm. ecb82f1. Thanks @vincentkoc.
Docs and Operator Workflows
  • #### Doctor check ordering
  • Keeps core openclaw doctor diagnostics in their normal order before extension checks, making lint and repair output easier to follow. PR #86627. Thanks @giodl73-repo.
View full changelog →
🚀
Quickstart Up & running in 10 min
💡
Tips & Tricks Quick wins & hidden features
📋
Full Changelog 30 releases
Cheatsheet Commands & tips
📦
All Releases Browse & filter
📡
RSS Feed Subscribe to updates

Clwatch

Monitor coding CLI releases in real-time. Track Claude Code, Codex CLI, Gemini CLI, and OpenClaw all in one dashboard. Get notified when new versions drop.

Launch Dashboard →
🔔 Real-time Monitoring Polls GitHub releases and surfaces new versions the moment they drop.
Breaking Change Alerts Flags breaking changes so you know before upgrading.
📊 Multi-Tool Dashboard Claude Code, Codex, Gemini CLI, OpenCode — all tools in one view.

Stay in the Loop

Get notified when OpenClaw ships new releases. No spam — just changelogs.