* perf(doctor): keep telegram doctor enumeration off the runtime graph Telegram's built doctor artifact reached execa through dist chunking, so a source-run host (pnpm dev, tsx CLI, vitest) could not require it and silently dropped all 9 telegram legacy config rules plus its state migration. The artifact also pulled telegram's runtime stores, making it a 674-chunk outlier that dominated doctor enumeration. Root cause: `src/token.ts` took the broad `plugin-sdk/provider-auth` barrel for `resolveDefaultSecretProviderAlias`, dragging the auth-profile store, provider runtime, and plugin install graph (execa, kysely, commander) into the closure. The alias now has a narrow `plugin-sdk/secret-provider-alias` leaf, and provider-auth re-exports it so its runtime surface is unchanged. Thread-binding, sent-message, and sticker-cache row shapes, keys, and legacy sidecar readers move to `*.legacy-state.ts` leaves. The doctor closure keeps the rows and drops the ACP, session-binding, send, logger, and plugin-runtime graphs the stores also load. The postbuild control-plane verifier only required each artifact in a plain Node child, the one host where these graphs resolve fine, so it proved nothing about the invariant that broke. It now also walks each built doctor artifact's static import closure and fails when it reaches the process-spawn graph, which is the dist-level analogue of the source closure guard. Guard rules added for provider-auth, acp-runtime, and conversation-runtime; the telegram boundary test became a real closure assertion instead of a string grep. * fix(doctor): drop dead export surface from the telegram legacy-state split Knip and oxlint caught leftovers from the split: the leaves exported helpers only they use, the store modules re-exported constants nobody imports from them anymore, and thread-bindings kept a `testing` barrel whose last production caller was the migration path that now reads the leaf directly. Tests import the constants from the leaf that owns them, and the reset helper directly. The closure gate's failure message still interpolated a `host` field left over from a probe-host approach that was reverted before commit; the existing verifier test caught it. The gate now has its own coverage: a transitive chunk edge to a forbidden dependency is reported, while dynamic imports and non-doctor contract surfaces are not. * fix(doctor): adopt the upstream telegram thread-binding store split `main` landed an equivalent thread-binding leaf as `thread-bindings-store.ts` while this branch was open, so the branch-local `thread-bindings.legacy-state.ts` is dropped rather than kept as a second path for the same rows. `state-migrations.ts` now reaches token.js through the lazy import `main` added, so `token.ts` is no longer in the doctor closure at all. The narrow `secret-provider-alias` leaf still matters: telegram's contract-api closure reaches `provider-auth` through `token.ts` on current `main`, which is the same execa/kysely/commander graph, so the barrel is repaired at its source instead of being deferred a second time. * fix(scripts): type the built doctor closure gate for the TypeScript migration The gate was authored against the `.mjs` script and landed in the `.mts` file `main` migrated to, so its parameters were implicitly `any` and `check:test-types` failed. Adds the explicit signatures plus the violation type. Regenerates the plugin-sdk API baseline: `provider-auth` re-exports the default secret-provider alias from the new leaf, so its module hash moves while its runtime export surface stays identical.
OpenClaw 🦞 — Your assistant, on your devices, in your chats
OpenClaw is a personal AI assistant that runs on your devices and meets you in the channels you already use. It is designed for a single operator and connects models, tools, messaging channels, and optional companion apps through one Gateway.
Website · Docs · Getting started · Showcase · FAQ · Vision · DeepWiki
Install
The installer supports macOS, Linux, and Windows. It provisions a supported Node.js runtime when needed.
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash
# Windows PowerShell
iwr -useb https://openclaw.ai/install.ps1 | iex
Already manage Node.js? Install the published package instead (Node 22.22.3+, 24.15+, or 25.9+):
npm install -g openclaw@latest
See the installation guide for npm 12 lifecycle-script requirements, Docker, Nix, and other deployment paths.
Quick start
openclaw onboard --install-daemon
openclaw gateway status
openclaw dashboard
Onboarding verifies model access, creates the workspace, and configures the Gateway. The last command opens the Control UI; send a message there to confirm the assistant is working. See the getting started guide for channel setup and troubleshooting.
How it fits together
- The Gateway is the local control plane for sessions, tools, events, and channel connections.
- The Control UI, CLI, and TUI connect to the Gateway.
- Channels bring the assistant to WhatsApp, Telegram, Slack, Discord, Google Chat, Signal, iMessage, and other messaging services.
- Companion apps and nodes add voice, Canvas, camera, screen, and device-local actions on supported platforms.
OpenClaw works with hosted and local model providers. Its tools, skills, and plugins extend what an assistant can do.
Security
Treat inbound messages as untrusted input. DM-capable channels pair unknown senders by default; approve a pairing request with openclaw pairing approve <channel> <code>.
Tools run on the host for the main session unless you configure sandboxing. Read the security guide, exposure runbook, and sandboxing guide before connecting other users or exposing the Gateway remotely.
Documentation
| Goal | Start here |
|---|---|
| Configure models and auth | Models · Model providers |
| Connect a messaging service | Channels |
| Add tools, skills, and plugins | Tools · Skills · Plugins · ClawHub |
| Run apps and device nodes | Platforms · Nodes |
| Use the CLI and chat commands | CLI reference · Slash commands |
| Configure or operate the Gateway | Configuration · Architecture · Updating · Release channels |
Development
The repository is a pnpm workspace. Plain npm install at the repository root is not supported.
git clone https://github.com/openclaw/openclaw.git
cd openclaw
pnpm install
pnpm build
pnpm ui:build
See CONTRIBUTING.md for the contribution workflow and the source setup guide for the development loop.
Community
OpenClaw is developed in the open by the OpenClaw Foundation, a non-profit. See CONTRIBUTING.md for maintainers and contribution guidelines; AI-assisted PRs are welcome.
Use the issue chooser for bugs and feature requests, ask setup questions in Discord, and report vulnerabilities through SECURITY.md. New capabilities usually belong in plugins built on the plugin SDK and shared through ClawHub.
OpenClaw was built for Molty, a space lobster AI assistant, by Peter Steinberger and the community. Explore the project lore, soul.md, Peter's site, Star History, and @openclaw.
Special thanks to Mario Zechner for his support and for pi, and to Adam Doppelt for the lobster.bot domain.
Sponsors
Contributors
Thanks to all clawtributors:
License
MIT © OpenClaw Foundation. See THIRD_PARTY_NOTICES.md for incorporated or adapted code.
