4Geeks chosen to deliver AI education in the Bahamas alongside Harvard, Oxford, and Columbia.See more
7 min read

What Is OpenClaw? The Open-Source AI Agent Explained

OpenClaw is the open-source AI agent you run on your own machine and message from WhatsApp or Telegram. How it works, how to install it and how to secure it.

Short answer: OpenClaw is a free, open-source AI agent you run on your own computer or server and talk to through WhatsApp, Telegram, Slack, Discord, iMessage and other chat apps. It can run commands, browse, manage files and act on your behalf, and you shape its personality and rules with plain Markdown files. Created by Peter Steinberger in late 2025 and now run by the OpenClaw Foundation, it is MIT-licensed and has more than 390,000 stars on GitHub (OpenClaw on GitHub).

OpenClaw connecting chat apps to an AI agent running on your own server

Few AI tools have grown as fast as OpenClaw. The repository went from launch to more than 390,000 stars in under a year, Amazon offers it as a ready-made server on Lightsail, and NVIDIA builds enterprise blueprints on top of it. It also drew warnings from security researchers and restrictions from Chinese authorities. If you want the wider map of assistants and agents first, start with our AI tools hub. This guide explains what OpenClaw is, how it works, how to install it and the security rules you need before you let it act for you.

What is OpenClaw?

OpenClaw calls itself "the AI that really does things". It is not a model. It is a self-hosted runtime and message router that sits between the chat apps you already use and the AI model you choose, and turns that model into an agent that can take actions on your machine.

It has three layers:

  • Channels: WhatsApp, Telegram, Slack, Discord, Google Chat, Signal, iMessage and more than 20 services in total.
  • The Gateway: a local control plane that manages sessions, tools, events and channel connections, with a web dashboard on port 18789.
  • Agents: the AI that reads your messages, plans, uses tools and answers.

Because everything runs on your hardware, your state and credentials stay with you. That is the main difference from cloud agents such as Grok Bot, which run on the vendor's computers.

Where did OpenClaw come from?

According to Wikipedia, Austrian developer Peter Steinberger published the project in November 2025 under the name Warelay. It was renamed Moltbot on January 27, 2026, after trademark complaints from Anthropic, and OpenClaw three days later. Growth was explosive: 247,000 stars by March 2, 2026, and more than 390,000 today.

On February 14, 2026, Steinberger announced he was joining OpenAI and that a non-profit, the OpenClaw Foundation, would take over stewardship of the project, which OpenAI continues to support (Forbes). Version 2.0 arrived on August 30, 2026, and releases now ship roughly every week with date-based names, such as 2026.9.7 on September 30.

How does OpenClaw work?

You configure the agent through files in its workspace, by default ~/.openclaw/workspace. The workspace documentation describes them:

FileWhat it does
AGENTS.mdOperating instructions and how the agent should use memory. Loaded every session
SOUL.mdPersona, tone and boundaries. Loaded every session
IDENTITY.mdThe agent's name, vibe and emoji, set during the first run
USER.mdOptional: your preferences and active projects
MEMORY.mdOptional: curated long-term memory
memory/YYYY-MM-DD.mdA daily memory log
skills/Workspace-specific skills

This design is the big appeal. The agent's rules and memory are plain text you can read, edit and version with Git, rather than a black box. On top of that, ClawHub offers community skills and plugins that add new abilities, and the runtime handles schedules and recurring checks so the agent can work proactively, not only when you message it.

How do you install OpenClaw?

The getting started guide keeps it short:

  1. Install Node.js 24 or later (Node 26 is recommended).
  2. Run npx openclaw@latest, or the install script from openclaw.ai on macOS and Linux (Windows has a PowerShell command). Guided onboarding starts automatically and lets you reuse an existing Claude Code or Codex login, or a provider API key.
  3. Run openclaw gateway install to keep the Gateway running as a background service.
  4. Connect your first channel. The docs suggest Telegram as the fastest, since it only needs a bot token.
  5. Open the dashboard with openclaw dashboard.

If you would rather not use your own computer, AWS has offered an OpenClaw blueprint on Amazon Lightsail since March 4, 2026. It comes preconfigured with Amazon Bedrock as the model provider, and AWS recommends a 4 GB plan (AWS).

Is OpenClaw safe?

OpenClaw connects a program that can run commands and read your files to inboxes that anyone can message. That makes security the most important part of any setup, and its record is mixed:

  • In February 2026, The Register reported that it was easy to backdoor OpenClaw and that some skills leaked API keys (The Register).
  • In March 2026, Chinese authorities warned state agencies and large banks against installing it on office devices for security reasons (Bloomberg).
  • Version 2.0 added protections, such as blocking network installs that would expose OpenClaw without authentication, but its authors say these controls are not tenant isolation (Help Net Security).

The security guide sets one rule above the rest: one trust boundary per gateway. OpenClaw is not built for mutually distrusting users sharing one installation. Its defaults are conservative: the Gateway binds to loopback, unknown senders get a pairing code instead of an answer, and openclaw security audit reports risky settings. Add these habits:

  • Never expose the Gateway to the internet. AWS gives the same advice and recommends treating the gateway token like a password.
  • Allowlist who can message the agent and use a dedicated phone number or account.
  • Restrict tools. Start read-only, limit filesystem and shell access, and enable sandboxing.
  • Treat skills as code. Review a ClawHub skill before you install it.
  • Keep it away from production secrets. A small isolated server costs less than an incident.

For a broader look at how companies isolate agents, see our OpenBot governance case.

OpenClaw vs Hermes Agent: what's the difference?

Hermes Agent, from Nous Research, is the other big open-source personal agent. Both are MIT-licensed, self-hosted and connected to your chat apps. OpenClaw is a gateway you shape with plain files and a large skills ecosystem. Hermes is built around a learning loop that creates and improves its own skills and searches its memory across sessions. Our guide on what Hermes Agent is compares both side by side.

OpenClawHermes Agent
MakerPeter Steinberger, now the OpenClaw FoundationNous Research
Best forFull control and a large skills ecosystemAn agent that improves at repeated work
ConfigurationMarkdown workspace filesConfiguration plus self-generated skills
Enterprise wrapperNVIDIA NemoClawNVIDIA NemoClaw also supports Hermes Agents

NVIDIA's NemoClaw wraps OpenClaw with policy controls that protect credentials and restrict access, plus routing between local and cloud models. It is a sign of where enterprise use is heading.

The skill behind a safe agent setup

OpenClaw makes it easy to start an agent and hard to run one well. The difference comes from skills you can learn: writing clear instructions, scoping permissions, isolating environments and reviewing what an agent does. If you want to build them with mentors and real projects, compare our AI programs and pick the one that fits your starting point.

Learn to build with agents like OpenClaw

Tell us what you code today and an advisor will help you see which program fits: AI Engineering, AI Engineering for Developers or AI Flex.

Frequently Asked Questions