Short answer: OpenClaw is a free, open-source AI agent you run on your own computer or server and talk to through WhatsApp, Telegram, Slack, Discord, iMessage and other chat apps. It can run commands, browse, manage files and act on your behalf, and you shape its personality and rules with plain Markdown files. Created by Peter Steinberger in late 2025 and now run by the OpenClaw Foundation, it is MIT-licensed and has more than 390,000 stars on GitHub (OpenClaw on GitHub).

Few AI tools have grown as fast as OpenClaw. The repository went from launch to more than 390,000 stars in under a year, Amazon offers it as a ready-made server on Lightsail, and NVIDIA builds enterprise blueprints on top of it. It also drew warnings from security researchers and restrictions from Chinese authorities. If you want the wider map of assistants and agents first, start with our AI tools hub. This guide explains what OpenClaw is, how it works, how to install it and the security rules you need before you let it act for you.
What is OpenClaw?
OpenClaw calls itself "the AI that really does things". It is not a model. It is a self-hosted runtime and message router that sits between the chat apps you already use and the AI model you choose, and turns that model into an agent that can take actions on your machine.
It has three layers:
- Channels: WhatsApp, Telegram, Slack, Discord, Google Chat, Signal, iMessage and more than 20 services in total.
- The Gateway: a local control plane that manages sessions, tools, events and channel connections, with a web dashboard on port 18789.
- Agents: the AI that reads your messages, plans, uses tools and answers.
Because everything runs on your hardware, your state and credentials stay with you. That is the main difference from cloud agents such as Grok Bot, which run on the vendor's computers.
Where did OpenClaw come from?
According to Wikipedia, Austrian developer Peter Steinberger published the project in November 2025 under the name Warelay. It was renamed Moltbot on January 27, 2026, after trademark complaints from Anthropic, and OpenClaw three days later. Growth was explosive: 247,000 stars by March 2, 2026, and more than 390,000 today.
On February 14, 2026, Steinberger announced he was joining OpenAI and that a non-profit, the OpenClaw Foundation, would take over stewardship of the project, which OpenAI continues to support (Forbes). Version 2.0 arrived on August 30, 2026, and releases now ship roughly every week with date-based names, such as 2026.9.7 on September 30.
How does OpenClaw work?
You configure the agent through files in its workspace, by default ~/.openclaw/workspace. The workspace documentation describes them:
| File | What it does |
|---|---|
AGENTS.md | Operating instructions and how the agent should use memory. Loaded every session |
SOUL.md | Persona, tone and boundaries. Loaded every session |
IDENTITY.md | The agent's name, vibe and emoji, set during the first run |
USER.md | Optional: your preferences and active projects |
MEMORY.md | Optional: curated long-term memory |
memory/YYYY-MM-DD.md | A daily memory log |
skills/ | Workspace-specific skills |
This design is the big appeal. The agent's rules and memory are plain text you can read, edit and version with Git, rather than a black box. On top of that, ClawHub offers community skills and plugins that add new abilities, and the runtime handles schedules and recurring checks so the agent can work proactively, not only when you message it.
How do you install OpenClaw?
The getting started guide keeps it short:
- Install Node.js 24 or later (Node 26 is recommended).
- Run
npx openclaw@latest, or the install script from openclaw.ai on macOS and Linux (Windows has a PowerShell command). Guided onboarding starts automatically and lets you reuse an existing Claude Code or Codex login, or a provider API key. - Run
openclaw gateway installto keep the Gateway running as a background service. - Connect your first channel. The docs suggest Telegram as the fastest, since it only needs a bot token.
- Open the dashboard with
openclaw dashboard.
If you would rather not use your own computer, AWS has offered an OpenClaw blueprint on Amazon Lightsail since March 4, 2026. It comes preconfigured with Amazon Bedrock as the model provider, and AWS recommends a 4 GB plan (AWS).
Is OpenClaw safe?
OpenClaw connects a program that can run commands and read your files to inboxes that anyone can message. That makes security the most important part of any setup, and its record is mixed:
- In February 2026, The Register reported that it was easy to backdoor OpenClaw and that some skills leaked API keys (The Register).
- In March 2026, Chinese authorities warned state agencies and large banks against installing it on office devices for security reasons (Bloomberg).
- Version 2.0 added protections, such as blocking network installs that would expose OpenClaw without authentication, but its authors say these controls are not tenant isolation (Help Net Security).
The security guide sets one rule above the rest: one trust boundary per gateway. OpenClaw is not built for mutually distrusting users sharing one installation. Its defaults are conservative: the Gateway binds to loopback, unknown senders get a pairing code instead of an answer, and openclaw security audit reports risky settings. Add these habits:
- Never expose the Gateway to the internet. AWS gives the same advice and recommends treating the gateway token like a password.
- Allowlist who can message the agent and use a dedicated phone number or account.
- Restrict tools. Start read-only, limit filesystem and shell access, and enable sandboxing.
- Treat skills as code. Review a ClawHub skill before you install it.
- Keep it away from production secrets. A small isolated server costs less than an incident.
For a broader look at how companies isolate agents, see our OpenBot governance case.
OpenClaw vs Hermes Agent: what's the difference?
Hermes Agent, from Nous Research, is the other big open-source personal agent. Both are MIT-licensed, self-hosted and connected to your chat apps. OpenClaw is a gateway you shape with plain files and a large skills ecosystem. Hermes is built around a learning loop that creates and improves its own skills and searches its memory across sessions. Our guide on what Hermes Agent is compares both side by side.
| OpenClaw | Hermes Agent | |
|---|---|---|
| Maker | Peter Steinberger, now the OpenClaw Foundation | Nous Research |
| Best for | Full control and a large skills ecosystem | An agent that improves at repeated work |
| Configuration | Markdown workspace files | Configuration plus self-generated skills |
| Enterprise wrapper | NVIDIA NemoClaw | NVIDIA NemoClaw also supports Hermes Agents |
NVIDIA's NemoClaw wraps OpenClaw with policy controls that protect credentials and restrict access, plus routing between local and cloud models. It is a sign of where enterprise use is heading.
The skill behind a safe agent setup
OpenClaw makes it easy to start an agent and hard to run one well. The difference comes from skills you can learn: writing clear instructions, scoping permissions, isolating environments and reviewing what an agent does. If you want to build them with mentors and real projects, compare our AI programs and pick the one that fits your starting point.
