OpenClaw is an open-source AI assistant that runs on your own computer and replies to you inside the messaging apps you already use, including Discord, iMessage, Slack, Teams, Telegram and WhatsApp. Rather than a chatbot in a browser tab, it works as a self-hosted AI agent: a background Gateway on hardware you control runs the assistant, while the model comes from whichever provider you plug in.
The project began in November 2025 under the name Clawd, a pun on Claude, was renamed Moltbot after Anthropic's legal team asked the developers to reconsider, and then settled on the OpenClaw name.
OpenClaw is stewarded by the OpenClaw Foundation, an independent US 501(c)(3) non-profit that employs the core team and signs every release. OpenAI is a donor and creator Peter Steinberger works there, yet the project states plainly that OpenClaw is not an OpenAI product and that donors do not own, control or direct it.
The central trade-off is control versus convenience. You get local state, a free choice of models and deep access to your own machine; in return you install it, configure it, secure it and pay any model provider bills yourself.
Text works on every channel, but support for media and reactions differs from one channel to the next, so the same conversation can look richer in one app than in another.
Together these separate OpenClaw from an ordinary chat assistant, and the same access that lets it finish a task also widens what a mistake or a malicious input can reach.
OpenClaw needs Node.js 24.16+ or 26.1+ and either an existing Claude Code or Codex CLI login or an API key from a model provider.
openclaw gateway status, openclaw dashboard).openclaw security audit).The documentation names five everyday use cases for OpenClaw: personal briefings on inbox, calendar and news; quick research and first drafts; reminders and follow-ups driven by cron or heartbeat schedules; browser automation such as filling forms and collecting data; and cross-device coordination, where a task sent from a phone runs on a server and the result comes back in chat.
Community workflows collected on the official site show what is possible rather than what a typical setup delivers:
For sales and marketing work, the documentation says OpenClaw can help with research, prospect qualification and drafting outreach or ad copy, but it tells users to keep a human in the loop for actual outreach or ad runs and to let OpenClaw draft while a person approves.
OpenClaw fits people who want one assistant that can act across their own accounts and devices and who are comfortable owning the setup:
It is a weaker fit for anyone hoping to run everything on a small local model. Asked whether a local model is fine for casual chats, the documentation answers "usually no", because OpenClaw needs a large context and strong safety, and smaller or quantized models raise prompt-injection risk.
Desktop apps install the Gateway, chat, setup and node features together. Versions below are as captured on September 27, 2026:
| Platform | System requirement | Package | Version |
|---|---|---|---|
| macOS | macOS 15+ | Universal Binary | v2026.9.6 |
| Windows | Windows 10/11, x64 or ARM64 | Desktop app | v2026.9.4 |
| Linux | x64 | AppImage or Debian package | v2026.9.5 |
OpenClaw itself costs nothing: the whole product is MIT licensed, and there is no enterprise edition and no paid version. The money you spend goes to the model providers and any hosting you choose.
Background automation is where bills can surprise. In a February 2026 news report, one user described a heartbeat reminder job that checked the time every 30 minutes and sent about 120,000 tokens of context to Claude on each check, costing almost $20 in Anthropic API usage overnight. That is one person's configuration rather than a typical figure, but it illustrates how a frequent scheduled task with a large context adds up.
The practical dividing line is scope: coding agents focus on a repository, while OpenClaw and Hermes Agent aim to be a long-running assistant reachable from chat apps.
Independent reporting in early 2026 tested these risks in practice. In February 2026, a security audit of 2,857 ClawHub skills reported by a security news outlet found 341 malicious skills across several campaigns. The same month, a security vendor's scan covered in trade media counted 40,214 OpenClaw instances exposed to the public internet and described 63% of observed deployments as vulnerable. Both figures are point-in-time findings from February 2026.
The project publishes its own counts. As captured on September 27, 2026, its security page listed 1,799 reports filed since January 2026, 722 fixes published, of which 39 carry a CVE, and 14 confirmed critical issues, all fixed and disclosed. The page notes that filing a report does not mean a vulnerability was confirmed.
Stability has also wobbled. The project acknowledged that around the 2026.4.24 and 2026.4.29 releases, Gateways got slower and some installs got stuck in plugin dependency repair loops.
update.checkOnStart: false).OpenClaw has no paid tier, hosted service or token. During the early renaming, scammers hijacked the project's old accounts and promoted a fake $CLAWD token that briefly reached a $16 million market cap before collapsing, according to crypto trade press. A coin or token sold under the OpenClaw name therefore does not come from the project.
Yes. The software is MIT licensed and has no paid version. You still pay your model provider for API usage or use an existing subscription sign-in, and you supply the machine or server it runs on.
No. OpenClaw is run by the independent OpenClaw Foundation. OpenAI is one of several donors and employs the project's creator, but donors do not own or direct the project.
Yes. The project was first called Clawd, often written as Clawdbot, and then Moltbot before it became OpenClaw, so older security reports and tutorials under those names refer to the same software.
It can use local models, and a local-only setup keeps data on your device. The documentation cautions that small local models truncate context and raise prompt-injection risk, so it recommends the largest local model you can run.
No. The project has no token, and the $CLAWD token promoted during the renaming was a scam unrelated to the project.