OpenClaw
Open-source personal AI assistant that runs on your own machine and answers you on the messaging apps you already use.
- Category
- Agents & Automation
- Pricing
- Free / Open Source
- Website
- openclaw.ai
About OpenClaw
OpenClaw is an open-source personal AI assistant. You run it yourself, on a Mac mini, a VPS or a container, and talk to it through the messaging apps you already use. It keeps memory across conversations, runs scheduled work on its own, and calls out to tools and MCP servers on your behalf. It is MIT licensed and free.
It went from a side project to the default open-source personal-agent stack in under a year, on the order of a quarter of a million GitHub stars, and the ecosystem around it now has its own hosting providers, security vendors and skill marketplaces. At GTC 2026 Nvidia announced NemoClaw and Jensen Huang described OpenClaw as "the operating system for personal AI".
The thing to understand before installing it: OpenClaw is a piece of infrastructure that holds your credentials and acts on your behalf. That is what makes it useful, and it is also why the sections below spend as much time on isolation and cost as on features.
Where it is now, September 2026
The current release line is v2026.9.1. The big one was v2026.8.1, shipped as OpenClaw 2.0: roughly 17,000 pull requests from close to a thousand contributors, a rebuilt Control UI centred on conversations, sessions and transcripts moved onto SQLite, and one connected path for creating, validating, finding, installing and calling skills.
Since then, 2026.9.1 added Mermaid diagrams rendered inline in chat across the web UI and
the native macOS, iOS and Android apps; personal skill libraries for individual teammates on
a shared Gateway; and a considerably safer openclaw update, which now checks
readiness before restarting, rolls back the npm candidate when the post-update Doctor fails,
and preserves your configuration and secret references across a failed upgrade.
Release cadence is fast. Whatever you install this month will not be what you are running in three, which matters more than it sounds when the software holds your credentials.
How it actually works
One Gateway process is the whole system. It holds the agent loop, the memory, the session store and the connections to every channel you have paired. Channels are plugins: WhatsApp, Telegram, Discord, Slack, Signal, iMessage, Teams and LINE among roughly two dozen others, all reaching the same assistant with the same memory.
Capability comes from three places. Skills are packaged instructions that teach it a workflow. Plugins extend the runtime itself. MCP servers connect it to everything else, which is where your calendar, your mail and your repositories come in. Paired nodes let a tool running on one machine discover and call approved tools on another without duplicating server config on the Gateway.
Scheduling is built in, so the assistant can run work on a cron of its own rather than only answering when spoken to. That is the feature that turns it from a chatbot into something that notices things.
What it costs to run
The software is free. The running costs are not, and they split in two.
Infrastructure. Light personal use fits a $5 to $10 a month VPS; a small team wants $15 to $40. Managed hosts start around $3 a month for a plain container and run to roughly $49 for the official OpenClaw Cloud with models bundled in.
Model spend. This is the part that surprises people, because it is usage-shaped rather than fixed. Light personal use lands under a few dollars a month. A small business running real automation is more like $15 to $35. Heavy scheduled automation reaches $80 to $150. Idle or misconfigured schedules typically account for 10 to 30 per cent of a monthly bill, which is worth auditing before you blame the model.
A realistic all-in figure for one person is $6 to $13 a month self-hosted. Whether that is cheaper than a managed plan depends entirely on how hard you use it.
Security, stated plainly
In July 2026 a researcher chained three OpenClaw vulnerabilities to get from a single WhatsApp message to credential theft, a Docker sandbox escape, and code execution on the host machine. All three were patched. The lesson is not that OpenClaw is unusually insecure; it is that an agent reachable from a public messaging channel, holding API keys, with a shell available, is a serious piece of attack surface.
Run directly on your host OS it inherits your user account's permissions, with no filesystem isolation, no network restrictions and no resource limits to contain a mistake. Credentials in plaintext config files are trivially readable once anything gets file access.
The practical hardening list is short and worth doing on day one: enable sandbox mode for
non-main sessions, remove exec from the tool allowlist for anything reachable
from a channel, restrict outbound network access to the connections you actually approved,
and patch quickly, because the fast release cadence cuts both ways.
One more, on WhatsApp specifically: automating a personal WhatsApp account breaches Meta's terms. Numbers do get restricted, with no pattern anyone has reliably predicted. Telegram, Slack, Discord or a WhatsApp Business API number carry no such risk.
Running it for more than one person
OpenClaw's security model is one trusted operator per Gateway. It is not built to hold two parties who do not trust each other inside a single process, so serving multiple tenants means running a complete separate instance for each.
Fleet is the supervisor for that. Each isolated instance is a cell: a full Gateway in a hardened container with its own state directory, credentials, workspace, channel accounts, token and loopback-only port. Fleet creates, inspects, starts, stops and removes them through Docker or Podman.
Fleet is explicitly experimental, and its own documentation is candid about what it does not provide: no shared ingress router, no tenant self-service portal, no billing plane, no delegated administration UI. It is also candid that tenants must trust the host operator, because cell tokens remain visible to whoever runs the host. Anyone planning to host OpenClaw for other people should read that page before writing a proposal.
What you get
- Roughly two dozen chat channels through one Gateway: WhatsApp, Telegram, Slack, Discord, Signal, iMessage, Teams, LINE
- Persistent memory and session continuity, stored in SQLite since 2.0
- Skills, plugins and MCP servers for capability, with a single install-and-call path
- Built-in scheduling, so it acts without being spoken to first
- Native apps for macOS, iOS, Android and Wear OS, plus a browser Control UI
- Paired nodes: tools on one machine can call approved tools on another
- Per-request approvals that stay attached to a command, session and person
- MIT licensed, self-hostable, no vendor lock-in
Specifications
| Licence | MIT, free |
|---|---|
| Current release | v2026.9.1 (Sept 2026) |
| Self-host | Yes |
| Managed hosting available | Yes |
| Chat channels | ~24, incl. WhatsApp, Telegram, Slack, Discord |
| Persistent memory | Yes |
| MCP support | Yes |
| Scheduled automation | Yes |
| Multi-tenant out of the box | No |
| Typical self-host cost | $6 to $13 / mo, plus model spend |