Skip to main content
Sensitive work now carries more of its authority with it. Approvals stay attached to the exact request, command, session, and person that received them, removing or pairing a device again retires its old access, and protected credentials can reach supported destinations without entering model-visible text. Sandboxes, network requests, browser actions, and plugin installs also recheck the workspace, destination, document, publisher, version, or artifact they depend on, so stale or mismatched authority stops or asks again instead of being reused.
An approval request now has one durable record shared by authorized browser and supported mobile surfaces. The first valid answer settles it, reconnecting cannot revive a completed request, abandoned requests are cancelled, and aborting a run clears the approvals it left pending. Operators can also opt in to installed Control UI PWA approval alerts that open the authenticated request, with the subscribed device, person, current role and scopes, preferences, and request visibility checked again before delivery. Resolved or expired requests replace stale actionable alerts, while optional agent and task alerts remain off by default.Recurring automations can now show their standing grants in the approvals page and CLI, including the owning automation, exact command, use count, and current state. Revoking an active grant takes effect at the next spawn boundary so the next occurrence asks again, and managed deployments can set the default lifetime used for future grants. Reusable command permission can still bind to exact arguments and a working directory, while script-backed commands recheck the bytes that were reviewed before they run. The binding covers the reviewed command and script bytes, while interpreters and changing dependencies can introduce separate behavior; opaque wrappers and commands that can launch something else may ask again.Each session can choose read-only, guarded, workspace, or full access and override MCP servers, skills, or web search where the client exposes those controls, with full access reserved for administrators. Per-turn exec restrictions can tighten that session policy but cannot loosen it, and Doctor provides a migration path for the older persistent exec fields. Scheduled and delegated work retains its originating policy, and an uncertain result from another machine is reported as unknown instead of being retried on a guess.Per-session controls are nonretroactive, so existing sessions without a permission mode keep the previous global posture. Opt-in roles limit collaboration inside one trusted OpenClaw installation rather than creating isolation between hostile tenants.
Pairing authority now lives on the device record. Removing or pairing a device again retires its old connection and worker access, non-admin device tokens can manage only their own pairing, macOS and Android can review pairing state, and administrators can create a short-lived one-paste command for joining a machine.Automatic browser enrollment behind a trusted proxy remains off until enabled and stays within configured role and access limits. Verified proxy or Tailscale identity applies only to the current connection instead of rewriting durable pairing. The separate SSH identity check for private-network machines is on by default and follows normal OpenSSH HostName rules, so operators who want manual-only pairing must disable it and leave CIDR auto-approval unset.Participant, session, agent, and requester identity now travels with more of the work for attribution without widening access. Managed GitHub identities apply to local command-line and API work and author metadata, while Git transport, sandboxes, remote machines, and cloud workers continue to use their own identity paths.
The new team-scoped local Secret Store separates Protected values from Agent-readable environment values. Supported masked requests, Vault or 1Password references, and destination-bound substitution can keep a protected credential out of plaintext configuration and model-visible text while placing it into an approved Gateway-hosted HTTPS request. Masked credential requests on the web, iOS, and Android now preserve the exact entered value and operator-edited destination, refresh affected providers after the value is saved, and close the request and its protected connection with the run that owns them. Agent-readable values are a separate grant for Gateway-hosted commands and can still be printed or transmitted by the command that receives them.Changing a Control UI Gateway URL to a different credential scope now clears the previous endpoint’s password and bootstrap credentials before connecting, while credentials explicitly supplied for the destination still take precedence. A query-only scope change can retain the origin-scoped token but requires the password to be entered again.Secret Store values are not encrypted at rest and depend on the filesystem permissions of OpenClaw’s state directory. Destination-bound substitution applies only to Gateway-hosted HTTPS commands whose subprocess honors its proxy settings. Raw sockets, containers, remote nodes, provider-native harnesses, plain HTTP, and WebSockets stay outside that path.Common credential and signed-parameter patterns are now redacted across covered logs, diagnostics, agent errors, and Control UI failures, while chat history removes inline media bytes, local paths, private shell rows, copied prompt context, and failed-delivery payloads on the covered paths. Extra feature statistics, Android installed-app details, and iOS Health summaries require explicit choices, with Health behind two disabled-by-default gates. Update checks remain on unless disabled, while approximate Activity location is enabled by default for routable addresses and may download its local city database on first use.
Contributor-controlled code is now prepared inside the designated untrusted-code sandbox, and managed worktrees suppress repository Git hooks unless an administrator deliberately runs the separate setup script. Repositories that relied on implicit hooks will need to move that setup into the explicit path.Sandbox identity now includes the workspace that owns the run. Newly created guest sessions that require a sandbox receive a separate identity for each authenticated guest and can share a workspace only read-only, while worker sessions on another machine can opt into per-session containers. Direct execution remains the default, and the same per-guest boundary is not established for child sessions they create.File checks catch more attempts to escape through the named root, denied directories, oversized reads, and POSIX symlink parents. Symlink containment is checked before the filesystem operation rather than atomically beneath the approved root, leaving a remaining window for a path to change between the check and use.
Network policy now blocks unspecified and local-use NAT64 targets by default, validates guarded redirects and no-auth browser origins, and stops telemetry when its configured proxy is invalid instead of bypassing it. Private automation webhook destinations require an exact-host exception or a broader private-network switch, with the broader setting widening trust across every configured cron webhook.Text returned by search, fetch, MCP, plugins, Browser, and other network-backed tools is bounded, normalized, and marked as untrusted external content before the model sees it. This makes the source and boundary explicit, while the model can still be influenced by hostile material it reads.Terminal and CSV output neutralize covered control-sequence and formula injection forms, configuration rejects prototype-polluting paths, and browser references, executable waits, navigation, and MCP App grants are rechecked against the document and live authority that produced them. Browser navigation enforcement covers selected-page document traffic during managed actions and a bounded grace period, leaving popups, Service Workers, background requests, some redirects, and remote backends outside that boundary.
Managed external plugin installs now show one capability review bound to the artifact being installed and ask again when an update requests more authority. Skill security verdicts stay attached to the exact publisher and version, ClawHub GitHub installs require a full commit SHA instead of a mutable branch or tag, and managed Homebrew or NodeSource installers stop when a response fails, is empty, redirects, or lacks a shebang.The capability prompt applies to managed external installs. Bundled plugins skip it, already-enabled legacy plugins keep their existing access, and bundled execution retains named compatibility exceptions. The review shows what a plugin is asking to do, while authenticity and code safety continue to depend on artifact integrity, registry identity, and code review. A full commit SHA pins the downloaded archive bytes while source metadata still depends on the resolver, and the installer response check only confirms that the download looks like a script.