On this page
On this page
Release notes
v2026.9.9
v2026.9.9
AI agents and tools can read these release notes as plain Markdown.
OpenClaw 2026.9.9 adds GPT-6.1 Sol to the Codex model list and supports Claude Haiku 5.5 through Anthropic and Claude CLI, improves recovery after failed updates, fixes missing iMessage replies, and keeps an old scheduled job from interrupting a newer conversation.
Release scale: 112 pull requests, 69 direct commits, and 91 contributors.
Installation and Onboarding
- Channel setup. Adding channels one after another in guided setup no longer leaves saving stuck on Working while OpenClaw waits for the setup window itself. #161116 by @steipete.
Web UI
- Windows workspaces. Creating an empty workspace on Windows no longer fails because of the way OpenClaw calls Git. You can choose New workspace and start a conversation without changing your global Git settings. First install Git for Windows using the native Windows setup guidance. Folders nested too deeply can still hit a separate Git limit. #164202 by @steipete.
- Conversation titles. When your model server handles one request at a time, OpenClaw can try naming a new conversation again after its first reply finishes instead of leaving it with a random name. Names you choose yourself are preserved. #163817 by @MertBasar0 and @obviyus.
- Chat reading position. After jumping to the latest message and scrolling back, resizing the chat no longer pulls you down to the newest messages. #162411, with coauthor @steipete.
- Channel conversation history. Messages sent from the dashboard into a channel keep their original conversation association. New messages from linked requesters also stop appearing twice in Claude CLI chat history, with internal requester instructions kept out of the displayed text. Existing records are not rewritten. #151786 by @Alix-007, reported by @Rotocruz; #161012 by @Marvinthebored and @Peetiegonzalez, with reports from @Oldrich333, @holgergruenhagen and @obnoxious2011-cmd.
- Opening and updating chats. Chats can open while their labels or activity details change, and saved background replies stay visible when an older history request finishes late. #162681, #162763, with contributions from @VACInc and follow-up investigation by @steipete.
- Chat scrolling. Chats keep following incoming turns and large updates when you are watching the latest messages, while scrolling back preserves your reading position. Expanding details and delayed layout changes retain that choice. Refreshing history without changing its height also avoids an unwanted jump. be6713b, 0c01cc6, #166239, #166258, #166301, #166341, with contributions from @steipete and @RomneyDa.
- Expanded chat details. Opening a message's expandable details keeps the clicked content in place instead of pulling it toward the bottom of the chat. #166200 by @RomneyDa, with included source work by @steipete.
- Streaming replies and composer spacing. Replies keep scrolling as text arrives after a jump to the bottom that needed no movement. Empty notices also stop leaving a blank gap above the message box. #166348 by @RomneyDa, with the spacing fix by @vincentkoc.
Updates and Maintenance
- Update completion. Updating OpenClaw no longer fails just because it is saving data at the same time. Updates from affected older versions keep the files plugins need to finish their upgrades, and global npm installs avoid a false recovery-file check failure. Once required database work has finished, a stalled shutdown can also stop holding up the update result; that safeguard applies to subsequent updates run by the fixed installation. 30c180a, ecac0d3 (original migration fix), 55360c6 by @RomneyDa; #161258 by @steipete.
- Maintenance errors. Fixed a false maintenance warning that could interrupt an update and unnecessarily return OpenClaw to the previous version. #164554 by @RomneyDa, with source work by @steipete and reporting and investigation by @DasX.
- Failed-update recovery. Supported updaters can recover a compatible OpenClaw installation after a failed update while preserving data written during the attempt. Returning to 2026.9.8 also keeps later updates possible. An older updater already running cannot gain these safeguards. On macOS and Linux, restart stays blocked until Doctor processes are confirmed stopped. Follow the repair steps and rollback guidance. #164497, #164724 by @RomneyDa, with original recovery work by @steipete and reports from @DasX and @jarvisnextgeneration20-lang.
- Backups on FUSE storage. If you use storage mounted through FUSE, backups and restores no longer fail solely because a file's recorded times changed. OpenClaw checks that the contents still match before proceeding. This covers updates, Doctor repairs and rollbacks; see the container upgrade guidance. 3ecb62a (original FUSE fix) by @steipete.
- Older memory databases. Doctor can finish upgrading an older memory cache even if some saved entries are too large or damaged. It warns you about skipped entries, which rebuild as needed while your original data stays intact. Before a database upgrade, stop processes using it and take a verified backup as explained in the migration guidance. #164303 by @steipete.
- Package-manager updates. pnpm updates avoid the “not a terminal” failure, and optional plugin syntax errors can produce warnings instead of blocking the update snapshot. Large npm installs can continue past a scan limit with a warning that full package contents are unverified. An older updater may need a manual first update or the plugin recovery steps. df11aae by @alkor2000; #161001, #162298 by @steipete, with reporting by @jamiezigelbaum.
- Windows update checks. Fixed an older-updater compatibility problem that could make the first Doctor check fail and roll back a Windows update. #162245 by @steipete, reported and diagnosed by @WG-Mojo.
- Docker startup. Fixed an upgrade loop on affected older Linux hosts that repeatedly rejected an unchanged database. Retries reuse verified rollback backups instead of making another full set each time; historical backups remain available. See the Docker recovery guidance. #162305 by @steipete, with reports and investigation by @Ludwigtheo0815, @rebarshop-24 and @nweishar.
- Doctor maintenance. Long database checks show progress and respond to Ctrl+C, waiting for work already underway to finish cleaning up before exiting. Rerun Doctor after interruption to finish the repair. Doctor can also continue when optional update-history checks are unavailable. Doctor also lets cleanup finish before closing, avoiding a Windows crash risk during shutdown. Maintenance guidance, #162213, #163608 by @steipete, with reports from @fenglanhua and @ringbe-cyber. 5d7fa8e.
- Session archive repairs. Doctor can import sessions blocked by older migration records and retry interrupted archive repairs. Missing file copies stay flagged for recovery, with the original database content retained. Doctor also attempts to restore a managed Gateway it stopped once maintenance has finished. Rolling back OpenClaw does not undo archive changes already committed. #164867 by @steipete, reported by @hshs38033-cmd; #165854 by @RomneyDa and @Olli0103, with reports and investigation from @A1fred-AI, @mpquemel, @goncalonc and @steipete.
- Plugin installation records. An upgrade encountering damaged old plugin metadata preserves the original record and its valid installation entries. Already-lost data still needs a backup, and a separate unresolved registry-refresh problem can overwrite preserved entries; do not use refresh as an assured recovery step. #161485 by @steipete, reported by @aniruddhaadak80.
- Quarantined databases. Opening sessions now respects an existing corruption quarantine. Affected installations may lose read-only access until repair or restoration succeeds; preserve the database and its WAL file and follow the recovery guide. #161783 by @SunnyShu0925, reported by @steipete and verified by @Patrick-Erichsen.
- Restart recovery. If automatic triage repairs a refused Gateway restart, OpenClaw tries starting once more. A failed retry, or an installed triage handler that declines or cannot finish, can now exit with an error. Foreground and container deployments need an external restart policy to recover from that exit. #160173 by @steipete, reported by @dh-js.
- Monterey service commands. On affected macOS 12 installations, Gateway stop, restart and update commands can run from an independent Terminal window when OpenClaw can establish that it is safe to do so. An unfixed older updater may still need the one-time stop, update and start sequence. #163317, #165935 by @NovaUnboundAi, @xXG0DLessXx and @RomneyDa.
- Very old configurations. Update errors for retired settings now explain the required intermediate upgrade through 2026.9.5 and
doctor --fix. Keep the same profile and configuration paths and follow the older-version upgrade guide. #162150 by @steipete. - September database compatibility. Upgrading from September stable keeps shared data in the format used by 2026.9.8. Data already converted to the newer format by an October beta cannot be opened by this version and is left unchanged; this update cannot downgrade or repair it. #166959 by @RomneyDa, with earlier compatibility work in #166026 by @RomneyDa and @shakkernerd.
- Doctor repair recovery. Archive repairs can continue past empty old session entries and resume saved progress after interruption. Doctor also retries failed resource cleanup and can restore the Gateway once cleanup is safe, while still reporting the error. State-migration guidance, ed472c0, fab3a66 by @RomneyDa, with coauthors @steipete and @victor-gurbani on the Doctor and Claude CLI repairs.
- Older ACP sessions. Upgrades preserve older ACP session settings even when the original session file has already moved into an archive. 16398dc by @RomneyDa.
- Windows Gateway discovery. An unreadable launcher belonging to an unrelated Windows Scheduled Task no longer blocks Gateway discovery just because that task is running. Some custom Gateways launched through a single BAT file can still go undetected. #166299 by @RomneyDa, with source work by @steipete.
Messaging
- Telegram Control UI. To open OpenClaw's Mini App in Telegram, send
/controluiin a private chat with the bot./dashboardnow belongs to session dashboards. Follow the migration guide to replace old shortcuts and get a fresh button. Access requires your numeric Telegram ID in the bot's owner settings; ask an administrator to add it if you relied on a wildcard or username. #161369 by @mmaps, with command separation by @joshavant. - iMessage replies. OpenClaw could finish writing an answer in an ordinary iMessage conversation but never send it. The affected replies are now sent. #163742, with coauthors @VACInc, @Kimiyu-186 and @steipete.
- Discord task results. A delegated task could post its answer in your Discord thread and still appear to have failed because it sent no further reply. OpenClaw now recognizes that answer as delivered. Replies sent through a webhook also use the webhook and identity assigned to your thread. #163756 by @MertBasar0, reported by @stuart-minion-ai and landed by @obviyus.
- Discord health checks. Configuration and health checks can proceed when Discord activity or voice components fail to load. f489f0f.
- Cancelling queued messages. If you cancel a message that is still waiting to be processed, the reply already in progress can finish instead of getting stuck. A separate unresolved issue can let pending plugin work continue while you reset or delete the conversation. #164230 by @vincentkoc.
- Google Chat and Slack threads. Google Chat replies stay in their original thread when threading is enabled, even if typing indicators fail. Slack replies from CLI-backed agents also retain the originating thread when no other destination was requested. Google Chat guidance, Slack thread guidance, #136689 by @ScientificProgrammer and @obviyus, with validation by @danieljimz; #160751 by @maxpuppet and @obviyus.
- Feishu attachments. Files sent with captions or together in Feishu/Lark posts reach the agent as documents instead of disappearing or being mistaken for video. #151896 by @gokay-ai and @obviyus, reported and diagnosed by @WhitenessTiger.
- Discord follow-ups. A waiting Discord message no longer blocks newer messages in the same channel from reaching the reply queue. Your queue mode determines how corrections and follow-ups are handled; ordering across different senders remains a separate limitation. fe28b2c by @steipete.
- Long voice replies. In affected multi-agent setups, automatic voice summaries use the replying agent's provider access instead of failing and clipping the answer. That agent still needs credentials for the configured summary model. #161454 by @drakeo338 and @obviyus, reported by @aounakram.
Memory
- Saving memory before replies. A long memory checkpoint before a reply no longer makes the channel time out and restart the same message while memory is still being saved. #137359 by @ericcaiwx-star, verified by @obviyus, with reports and investigation from @big-hill, @alexph-dev, @ChuLaiTheGreat, @FlagshipClaw and @KirDE.
Skills
- Plugin skills during updates. In source-checkout installations, valid plugin skills stay loadable during an update instead of temporarily disappearing with hardlink warnings. #165882 by @RomneyDa.
Models and Providers
- GPT-6.1 Sol. The Codex model list includes GPT-6.1 Sol, though using it still requires an eligible account and a compatible Codex setup, including the related provider support. When Codex repeatedly refuses an action, the request can also finish instead of remaining stuck until it times out. 65e89fc by @IstiqlalBhat, with coauthors @RomneyDa and @fuller-stack-dev.
- Claude Haiku 5.5. You can select Haiku 5.5 through the Anthropic API and Claude CLI. The
haikualias and Anthropic utility-model default now select 5.5, with adaptive thinking on by default. Choose an explicit Haiku 4.5 model to keep using it. API pricing rises for prompts above 100,000 tokens; see the model, thinking and pricing guidance. #166706 by @RomneyDa. - Bundled Codex. The copy of Codex included with OpenClaw is updated to 0.160.0, bringing fixes for starting sessions and recording diagnostic logs. This bundled copy is separate from any Codex command-line app you update yourself. #163560 by @vincentkoc.
- Copilot tool calls. Plugin and MCP tools keep working after the first Copilot conversation turn instead of failing with “Async work scope is closed.” #164598 by @ericcurtin, with diagnosis by @takyyon.
- Model retries and context. One-shot model requests through the Gateway retain the original task when retrying the same model. Chat Completions conversations also use valid provider token counts to judge how full the conversation is, reducing reliance on estimates that can trigger recovery too early. #160803 by @changeroa, reported by @Oldrich333 and verified by @obviyus; ab24b53 by @RileyJJY.
- Claude CLI background replies. A child agent's completed task no longer takes the place of its parent's pending reply, allowing the parent to return its answer. ed472c0.
Automations and Scheduling
- Scheduled jobs and ongoing chats. An older scheduled job reaching its time limit could stop a newer conversation in the same session and remove its access to tools. That reported problem is fixed. #163704, thanks to @jayzhou2309 for the fix, @AXEG0 for reporting it, @ekinnee and @MasterSwords1 for investigation, and @obviyus for validation and landing work.
- Starting background jobs. Fixed a startup problem that could freeze chat or disconnect the web interface when a scheduled job or Skill Workshop review began. This applies to jobs using their agent's configured workspace, including while older chat history is condensed. Their file access remains limited to the task folder. Scheduled jobs can also proceed using existing model information when a catalog refresh is slow. #164049 by @steipete; #161132 by @jayzhou2309, reported by @Flakedict and verified by @obviyus.
- Editing scheduled jobs. Agents can recover from supported mistakes in how a model formats a scheduled-job update, instead of repeatedly failing and leaving the old message in place. #158543 by @carlosjarenom, reported by @louria and verified by @obviyus.
- Interrupted one-shot jobs. After a restart, an interrupted one-shot scheduled job can run again even if its first message already arrived, so you may receive a duplicate. #166959.
Plugins and Integrations
- Model changes and plugin recovery. Switching models can reuse large plugins already running instead of copying them again and freezing requests. Failed plugin reloads can recover healthy model access and replies without a restart, and a missing context-engine plugin can use the built-in fallback. Initial loading can still block; unsuccessful recovery still needs a reload or restart. #161267 by @obviyus, reported by @cmrstudio56; 8abe351 by @sahilsatralkar; #161023 by @Patrick-Erichsen.
- Plugins under Bun on macOS. Plugins such as iMessage can load when copying a larger dependency hits Bun's bad-file-descriptor error on macOS. #159403 by @sunlit-deng, reported by @hannesrudolph, with follow-up work by @steipete.
- MCP connections. Remote MCP plugins no longer stop native sessions from starting because OpenClaw gives them an unnecessary local working directory. An HTTP error from an MCP server also avoids the affected Node 26 crash path. #162376 by @Patrick-Erichsen; 66c7c35 by @RvsL.
- Tool Search guidance. If an agent tries to use an available direct-only tool through Tool Search, the error explains how to call it directly instead of sending the agent back to a fruitless search. #161055 by @obviyus, reported by @jgs-jeeves.
- Bundled MCP connections. MCP servers imported from Claude and Codex bundles use the connection type their configuration requests instead of incorrectly falling back to another transport. #166200.
- MCP sign-in changes. Background refresh preserves saved credentials when a server changes its sign-in provider. An explicit sign-in can register with the new provider; unused registrations with an outdated callback can also be replaced. #166341, with contributions from @RomneyDa, @Patrick-Erichsen, @steipete and @vincentkoc.
Security and Privacy
- Windows MXC sandbox. The optional MXC sandbox can start and run tools on compatible Windows computers without the old Windows service. If you chose your own MXC executable, update it to the documented requirements or switch back to the bundled copy, then restart the Gateway. A successful start can still warn that isolation is reduced. Keep secrets out of command arguments and environment values because people allowed to inspect processes on the host can read them. #158303, thanks to @paulcam206.
- Request checks on paired computers. Plugin input policies can now reject a request before OpenClaw carries it out on a paired computer. A policy error also blocks the request. These checks cover OpenClaw jobs, not Codex or Copilot, and see only the prompt and history available at the Gateway. If a policy needs instructions or skill context added on the paired computer, run the job locally with a supported runner instead. Blocking a request does not erase text already saved in the conversation. #164270 by @steipete.
- Secret rotation and recovery. Replacing or importing a credential preserves its existing protection and allowed hosts unless you explicitly change them. Doctor also stores a recovered Gateway token in the secret store instead of copying it into configuration. That recovery requires interactive confirmation, even with
--yes; earlier plaintext copies are not cleaned up. #160926 by @zachisfine, @yetval and @steipete; #162372 by @steipete, reported by @waynegault. - Agent-to-agent credentials. An A2A connection rejects a token whose environment variable is missing instead of accepting or sending the placeholder text. Supply the missing variable and reload or restart OpenClaw to restore the connection. 521ae23 by @eleqtrizit.
- MCP sign-in. OAuth login and token refresh refuse redirects that would send credentials to another origin. If a custom provider now fails with that refusal, configure direct token or registration endpoints. Ordinary MCP resource redirects keep their existing behavior. #138263 by @mmaps, with prior work and coauthorship by @hansraj316.
- Export approvals. Diagnostics and trajectory exports keep their designated approval device even when the prompt is delivered to a private chat. Other approval-only devices cannot approve the bound command; the administrator bypass remains. #125663 by @RomneyDa.
Quality-of-Life Improvements
- Delegated task startup. Cloud sessions can start with long assignments without shortening the task, and visible child sessions keep their own worktree on later turns instead of failing a workspace check. #159459, #162308, with contributions from @steipete.
- Delegated task completion. Parents receive complete new CLI-backed subagent answers instead of a shortened prefix. Finished child trees release capacity even when their completion notification is suspended, and same-model retries retain permitted follow-up delegation. Older truncated answers are not repaired. #162843 by @zyz619963502zyz, with diagnosis by @holgergruenhagen; #162368 by @armstrongsam25, reported by @davidcittadini, both verified by @obviyus; #163032 by @stackingrockss.
- Session maintenance commands. Invalid reset targets are rejected before they can clear the main conversation. Compacting a missing session now reports an error, so scripts that relied on success must check the session exists or handle that error. #161533 by @steipete.
Other Bug Fixes
- Windows session storage. Creating a session no longer fails when its database is reached through a Windows folder link, such as a junction. OpenClaw recognizes that the different paths point to the same database, including equivalent Windows long-path spellings. bec0cfd by @cestercian, with coauthor @RomneyDa; #162332 by @steipete, with reports and diagnosis from @zhyx1996, @ngominhduc263, @oxen-horse, @wuwo2119, @dapangkai11 and @ignamiranda.
- Commands that would not exit. Fixed a Node problem that could leave commands running after they had printed all their output. The workaround also covers the Gateway service, hook relays and macOS node worker. Some commands may take longer, and advanced overrides can bypass the fix; see the Node compatibility guide. #163788 by @steipete.
- Sessions on paired computers. A paired computer could appear unavailable while sending routine status updates, causing other sessions running there to stall or fail. Updating the Gateway fixes this interruption. Requests also wait for worker reconnection instead of freezing the computer's OpenClaw host and its other workers. #164087 by @steipete; #160812 by @RileyJJY and @altaywtf, reported by @aniruddhaadak80.
Was this useful?