OpenClaw
by OpenClaw Foundation
An open-source personal AI agent that runs on your own machine and answers in your chat apps
OpenClaw is an MIT-licensed personal AI agent that runs as a local daemon on your own hardware and is driven from messaging apps you already use, including WhatsApp, Telegram, Slack, Discord, Signal and iMessage. It reads and writes local files, runs shell commands, drives a browser and acts on a schedule, keeping its memory as plain Markdown on your disk rather than in a vendor's cloud.
OpenClaw is an MIT-licensed personal AI agent that runs locally rather than in a vendor's cloud, governed by the non-profit OpenClaw Foundation. Architecturally it is a single persistent Node.js process called the Gateway, a local control plane that unifies channel adapters, session management, message queuing, the agent runtime and a control plane, with a web Control UI, a CLI and a TUI attached to it. Users talk to it through the messaging apps they already have — the official site lists 29 supported platforms, including WhatsApp, Telegram, Slack, Discord, Google Chat, Signal and iMessage, in direct messages and group chats — and a heartbeat scheduler wakes it on an interval so it can act without being prompted. It is model-agnostic: hosted providers such as Anthropic, OpenAI and Google work with a bring-your-own key, as do local models via Ollama. Conversations, long-term memory and agent instructions are stored as Markdown and YAML files on disk, inspectable in any text editor. Capabilities extend through portable SKILL.md files, Markdown instructions with YAML frontmatter that follow the same conventions as Claude Code and Cursor and are distributed through a registry called ClawHub. The project was renamed twice — a January 2026 rename thread reached the Hacker News front page — before settling on OpenClaw, after which it became one of the fastest-growing repositories in open-source history, passing 247,000 GitHub stars by March 2026 and roughly 386,000 by August. Installation is a shell one-liner on macOS, Linux and WSL2, a PowerShell script on Windows, an npm global install, Docker or Nix, and DigitalOcean offers a hardened 1-Click Deploy from $24 per month. The software itself is free; the running cost is model tokens and hosting.
The technical individual operator — a developer or engineering leader comfortable running and sandboxing a daemon on their own hardware — who wants an always-on assistant that touches their real files, calendar and inbox without handing that access to a SaaS vendor.
A persistent agent that acts on your behalf between prompts, reachable from the chat app already on your phone, with every conversation and memory stored as plain text on hardware you control.
At a Glance
- Category
- AI Agents & Orchestration
- Pricing
- Free, Usage-based
- Target Market
- CTOs, Enterprise Developers, AI/ML Engineers, DevOps Engineers, Technical Founders
- Deployment
- Open-source, Self-hosted
- Founded
- 2025
- Customers
- More than 135,000 running instances reported at April 2026; roughly 386,000 GitHub stars
Key Features
- ✓Local Gateway daemon
A single persistent Node.js process holds sessions, tools, events and channel connections on your own machine, so the agent keeps running between prompts without a vendor-hosted control plane.
- ✓Messaging-app interface across 29 platforms
You drive the agent from WhatsApp, Telegram, Slack, Discord, Google Chat, Signal or iMessage in direct or group chats, which removes the need to open a dedicated app to give it work.
- ✓Heartbeat scheduler for proactive work
A configurable interval wakes the agent so it can check and act without being prompted, which is what separates it from a request-response chatbot — and also what makes budget alerts essential.
- ✓Plain-text local memory
Conversation history, long-term memory and agent instructions are stored as Markdown and YAML files on disk, so everything the agent knows is readable, greppable and portable in any text editor.
- ✓Portable SKILL.md extensions and the ClawHub registry
Capabilities are added as Markdown instruction files with YAML frontmatter that follow Claude Code and Cursor conventions, distributed through a searchable registry or installed from a URL.
- ✓Model-agnostic provider support
It runs against hosted Anthropic, OpenAI or Google models with your own API key, or entirely against local models via Ollama, so no single provider's pricing or policy can strand the deployment.
Capabilities
Use Cases
- •Inbox and calendar triage from a chat app
The agent organises an inbox, drafts and sends email and manages calendar entries on instruction sent from WhatsApp or Telegram, without the user opening a laptop.
- •Scheduled unattended checks
The heartbeat scheduler wakes the agent on an interval to poll a service, review a feed or run a routine task and report back only when something needs a decision.
- •Local file and shell automation
Because it runs on your own machine with real filesystem and shell access, it performs repository chores and file wrangling that a cloud-hosted assistant physically cannot reach.
- •Privacy-constrained personal assistance
Users whose data cannot go to a SaaS vendor run the whole loop locally against an Ollama model, keeping both the prompts and the derived memory on their own hardware.
- •Reusing skills across agent tools
A team that already maintains SKILL.md files for Claude Code or Cursor points OpenClaw at the same files instead of rewriting automation logic for a second agent format.
Ideal For
Best For
- ✓Developers who want an always-on personal agent reachable from WhatsApp or Telegram rather than a browser tab or terminal
- ✓Automating recurring personal and operational chores — inbox triage, calendar management, scheduled checks — via the heartbeat scheduler
- ✓Privacy-conscious users who require conversation history and memory to stay on their own disk as inspectable Markdown
- ✓Teams that want to avoid model lock-in, mixing hosted Anthropic, OpenAI or Google keys with local models through Ollama
- ✓Extending an agent with portable skills already written for Claude Code or Cursor, since SKILL.md follows the same conventions
Not Ideal For
- ✗Regulated enterprise procurement: there is no SOC 2, ISO 27001 or HIPAA attestation, no vendor SLA and no commercial support contract, because the maintainer is a non-profit foundation rather than a software vendor
- ✗Anyone who cannot properly sandbox it. The agent executes shell commands and drives a browser with your live credentials, and CVE-2026-25253 — a cross-site WebSocket hijacking flaw — turned exposed Gateways into one-click remote code execution across thousands of instances
- ✗Teams relying on a flat-rate LLM subscription to fund it: Anthropic cut off Claude Pro and Max subscriptions for third-party agent frameworks on 4 April 2026, pushing users onto pay-as-you-go and, by press reports, raising some bills tenfold to fiftyfold
- ✗Non-technical users, who face a local daemon install, provider key setup and, per independent guides, common installation failures with no support desk to call
- ✗Cost-sensitive deployments that cannot tolerate variable spend — a misconfigured heartbeat interval can drain an API budget overnight, and heavy agents run several hundred dollars a month
Integrations
Deployment
Market & Ratings
More than 135,000 running instances reported at April 2026; roughly 386,000 GitHub stars
Market Analysis
Pros
- ✓MIT-licensed and free, with a non-profit foundation, full-time maintainers and one of the largest star counts in open-source history
- ✓Local-first data model: memory and history are Markdown and YAML on your own disk, inspectable and portable, with no vendor account holding your context
- ✓Model-agnostic — hosted Anthropic, OpenAI or Google keys or fully local Ollama inference, so no single provider controls the deployment
- ✓Meets users where they already are, across 29 messaging platforms including WhatsApp, Signal and iMessage, instead of requiring a dedicated client
- ✓Skills are portable Markdown files compatible with Claude Code and Cursor conventions, so existing automation logic can be reused rather than rewritten
Cons
- ✗A serious and repeated security record: CVE-2026-25253 (cross-site WebSocket hijacking enabling one-click remote code execution on exposed Gateways) and CVE-2026-33579 (privilege escalation), with practitioners on Hacker News calling it 'a security nightmare dressed up as a daydream' and warning that sandboxes are not sufficient mitigation
- ✗The skill supply chain is compromised in practice — security research found 26% of analysed community skills contained at least one vulnerability, more than 230 malicious skills were uploaded to ClawHub in February 2026 alone, and Cisco researchers identified a top-ranked skill carrying nine vulnerabilities designed to bypass safety mechanisms and exfiltrate data
- ✗Token spend is unbounded and easy to misconfigure: an actively polling agent runs $270 to $540 a month on premium models, a bad heartbeat interval can drain a budget overnight, and one creator reported $1.3M of OpenAI tokens in thirty days
- ✗Provider policy risk is real and has already fired — Anthropic blocked Claude Pro and Max subscriptions from funding third-party agent frameworks on 4 April 2026, with reported cost increases of ten to fifty times for affected users
- ✗Users report the memory is unreliable and that failures are not predictable, and independent guides note installation and setup failures are common with no commercial support to escalate to
- ✗The agent can take irreversible autonomous actions — payments, deletions, outbound correspondence — without a human approval step, and the associated Moltbook platform leaked 1.5 million API keys and 35,000 email addresses within days of launch
Pricing
Self-hosted (MIT licence)
$0
- ✓Full source under MIT
- ✓All 29 messaging channels
- ✓Bring your own model API key or run local models
- ✓Install via shell script, PowerShell, npm, Docker or Nix
DigitalOcean 1-Click Deploy (third-party hosting)
From $24/mo
- ✓Security-hardened managed droplet image
- ✓Hosting only — model tokens billed separately by your provider
The software is free under MIT and there is no hosted commercial edition, so the real cost is model tokens plus wherever you run the Gateway. Independent estimates put a light deployment on budget models at roughly $18 to $36 a month and an actively polling agent on premium models at $270 to $540, and one creator reported spending $1.3M on OpenAI tokens in thirty days — spend is unbounded by design, so provider-level budget alerts are mandatory. DigitalOcean sells a hardened 1-Click Deploy image from $24 a month for hosting only. Note the policy risk: since 4 April 2026 Anthropic no longer permits flat-rate Claude Pro and Max subscriptions to fund third-party agent frameworks, so Claude-backed deployments must use pay-as-you-go API billing.
Security & Compliance
Connect
Sources
This page was written from 6 sources, 5 on domains other than openclaw.ai.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
SuperNinja Enterprise
24/7 AI employees on open-weight models, deployed in your own cloud for a fixed annual fee
Capacity
AI-native customer experience platform: omnichannel AI agents, real-time agent assist and automated QA on one knowledge layer
Relevance AI
No-code AI agent builder for sales, marketing, support and ops teams to build and run a multi-agent AI workforce
xpander.ai
Vendor-neutral enterprise AI agent platform with a universal agent harness and Omni, an AI forward-deployed engineer
Mentioned In
NVIDIA Bets on OpenClaw for Enterprise: NemoClaw Brings Security & Governance
NVIDIA Bets on OpenClaw for Enterprise. For CISOs and security teams: risk assessment, compliance requirements, and security architecture for enterprise AI s...
March 16, 2026NVIDIANVIDIA GTC 2026 Day 1: $1 Trillion Revenue Path, Vera Rubin Platform, and OpenClaw Partnership
NVIDIA GTC 2026 Day 1. For CFOs and finance leaders: cost implications, budget planning, and ROI benchmarks from enterprise AI deployments.
March 16, 2026NVIDIANemoClaw vs OpenClaw: Why NVIDIA's Security Layer Changes Enterprise AI Agents
NemoClaw vs OpenClaw. For CISOs and security teams: risk assessment, compliance requirements, and security architecture for enterprise AI systems.
March 17, 2026NVIDIANVIDIA's Agent Toolkit: 17 Enterprise Giants Just Signed On (Here's What It Means)
NVIDIA's agent toolkit signed by 17 enterprise giants at GTC 2026. For platform teams: standardized AI agent development framework with production-grade orch...
March 18, 2026MCPMCP vs LangChain vs OpenAI Functions: Which for Enterprise?
Choosing between MCP, LangChain Tools, and OpenAI Functions isn't an either/or decision—many teams use MCP for standardized data access alongside LangChain for orchestration. The real question is which to prioritize for your enterprise use case.
March 22, 2026NVIDIANVIDIA GTC 2026 Final Roundup: $1 Trillion Revenue, 50x Performance Leap, and the Groq Acquisition That Changes Everything
NVIDIA GTC 2026 roundup: $1T revenue forecast, 50x performance leap, Groq acquisition. For enterprise leaders: strategic implications of accelerated computin...
March 22, 2026Enterprise AINVIDIA's 2026 State of AI: The Hard ROI Numbers Every CFO Needs
Enterprise AI analysis: NVIDIA's 2026 State of AI. Strategic insights, ROI considerations, and implementation guidance for technical and business leaders eva...
March 11, 2026Enterprise AIEnterprise Connect 2026: When AI Gets Held Accountable
Enterprise AI analysis: Enterprise Connect 2026. Strategic insights, ROI considerations, and implementation guidance for technical and business leaders evalu...
March 12, 2026AI ResearchFour AI Research Trends Shaping Enterprise Automation in 2026
Four AI research trends from Stanford, MIT, and Google shaping 2026 enterprise automation. For technical leaders: which trends justify budget vs hype.
March 13, 2026AI InfrastructureNutanix Agentic AI Stack: Scaling Enterprise AI Factories at Lower Cost per Token
Enterprise AI analysis: Nutanix Agentic AI Stack. Strategic insights, ROI considerations, and implementation guidance for technical and business leaders eval...
March 16, 2026Agentic AIRIAD's Yeyak: Why B2B Travel Needs AI Agents, Not Chatbots
Korean startup raises seed bridge from Silicon Valley's Sazze Partners. 90%+ revenue from global markets. AI agents automate multi-step workflows chatbots can't touch.
March 21, 2026OpenAIOpenAI's 17 Acquisitions: Vendor Lock-In and $207B Funding Gap
OpenAI's 17 Acquisitions in 3 Years Signal Vendor Lock-In Risk as $207B Funding Gap Looms. For enterprise decision-makers: strategic analysis, cost implicati...
March 25, 2026Enterprise AIGoogle Agent Smith Writes 30% of Code While Humans Sleep
Google's Agent Smith now generates 30%+ of production code autonomously. Access got capped after demand surge. Context beats capability.
March 29, 2026