Beginner 10 minAgents

OpenClaw: what is it, and should you install it ?

What is OpenClaw? Free software that you install on your own machine and that connects your messaging apps (WhatsApp, Telegram, Discord, and others) to an action-capable language model: reading files, running commands, and controlling a browser. This guide explains where the project comes from, how it works, what it requires, and what risks it poses, so you can decide whether to install it yourself. It contains neither in-house testing nor rankings—only what the project documents and what security researchers have published about it.

By Marie L.·Update 2026-10-03·Tested on Windows, macOS, and Linux

#What is OpenClaw? The short answer

OpenClaw is a personal, open-source AI assistant that you host yourself. You write to it from a messaging app you already use, like a contact, and it replies using a language model: one from an online provider or a local model. It is not just a chatbot. It is an agent: it has tools on the machine where it runs and can chain together multiple actions to accomplish what you ask.

What is it?
A program that runs continuously on your system and connects your messaging apps to a language model equipped with tools.
Who does it?
The project was started by Austrian developer Peter Steinberger. The code is published on GitHub under the MIT license and receives contributions from a large community.
How much does it cost?
The software is free. The model may not be: you pay for it by usage through an online provider, or in hardware and electricity if you run it locally.
Where does it run?
On a machine you own, running continuously: PC, Mac, mini-PC, or rented server. Nothing is hosted by the project publisher.
The main risk?
An agent that reads content from outside sources and can execute commands on your machine. If poorly isolated, it exposes your files and accounts.
Do you need to install it?
Yes if you're comfortable with a terminal and ready to isolate it on a dedicated machine. No if you just want to chat with an AI.

One clarification to avoid confusion: the name OpenClaw also refers to an unrelated project, a free reimplementation of the Claw platform game released in 1997. This page covers only the AI assistant.

#From Clawdbot to OpenClaw: three names in three months

The Local Agents Kit

Agents that act on your machine: agentic Cline, MCP, n8n + Ollama, local automations.

  • Lifetime online access
  • PDF + files
  • Lifetime updates

The project first appeared in late 2025 under the name Clawdbot, with a lobster named Clawd as its mascot. The name played on its resemblance to Claude, Anthropic’s model that many users connected to it. In late January 2026, at Anthropic’s request and due to a trademark issue, the project was renamed Moltbot (the lobster’s molt), then OpenClaw a few days later. The latter is the name that stuck.

November 2025
First published by Peter Steinberger under the name Clawdbot.
Late January 2026
Renamed to Moltbot, then OpenClaw a few days later. The project goes viral, and its GitHub repository becomes one of the most followed at the time.
February 2026
Peter Steinberger announces that he is joining OpenAI. He says the project will be entrusted to a foundation and remain open source.

This story has two practical consequences. First, tutorials published before February 2026 refer to Clawdbot or Moltbot and use old command names: it is the same software, but their instructions are outdated. Second, Moltbook, the social network for AI agents that received a lot of attention around the same time, is a separate service launched by another person. It is not necessary to use OpenClaw.

!
Beware of copies
Successive renamings left behind package, domain, and account names that third parties reclaimed, and the project's popularity attracted fake repositories and extensions. Install OpenClaw only from the official repository github.com/openclaw/openclaw and its documentation at docs.openclaw.ai.

#How it works: a gateway between messaging services and the model

The core of OpenClaw is called the gateway (Gateway in the documentation). It is a single process written for Node.js that runs in the background. It keeps connections open with your messaging services, receives each message, forwards it to the agent, then sends the response back to the right conversation. Everything else is organized around it.

Channels
Messaging services connected to the gateway: WhatsApp, Telegram, Discord, Slack, Signal, or iMessage, among others. The up-to-date list is in the documentation.
The gateway
The central process. By default, it listens only on the machine itself (address 127.0.0.1, port 18789) and also serves a web control interface.
L'agent
The loop that lets the model work with tools: command line, file reading and writing, browser automation, scheduled tasks.
The model
The one you choose. OpenClaw doesn't provide a model: it calls an online provider with your key, or a local model served by Ollama or a compatible server.
The workspace
A folder of Markdown-formatted text files containing the assistant’s instructions, personality, and memory. You can read and edit them manually.
Skills
Folders containing a SKILL.md file that teaches the agent a specific procedure. A public registry, ClawHub, lets you install more.

Two things set OpenClaw apart from a conventional chat interface. First, you can reach it from anywhere because you use your usual messaging app, while the work happens on the machine you left at home. Second, it can take the initiative. Scheduled tasks and periodic wake-ups allow it to message you on its own, for example with a daily morning update.

If the concept of an agent is still unclear, our “AI Agent: What Is It?” guide covers the basics: a model, tools, and a loop. OpenClaw applies this principle and adds a messaging layer. It can also connect to external tools, a topic covered in our guide to the MCP protocol.

#What OpenClaw is used for day to day

The uses described by the documentation and community revolve around one idea: delegating by message tasks that usually require opening a computer. None is guaranteed. The result depends heavily on the connected model and the care taken with the instructions.

Daily check-in
Receive a summary of your calendar, notes, or monitoring feed every morning, sent by the assistant without you asking for it.
Remote tasks
Ask from your phone to run a script, check a file, or restart a service on the machine left at home.
Notes and reminders
Dictate an idea or task in the messaging app, and the assistant files it away and reminds you at the right time.
Search and synthesis
Browse a few web pages and receive a summary, with the usual caveats about the reliability of what the model reads online.
Custom automations
Chain actions across multiple personal tools using skills, without writing a complete program.

We also need to say what OpenClaw is not. It is not a language model: without a connected model, it cannot respond to anything. It is not an online service: no one hosts or monitors it for you. And it is not a finished consumer product: installation requires a terminal, and maintenance is your responsibility.

#What you need to run it

The gateway itself is lightweight: it simply relays messages and calls a model. The requirements mainly concern machine availability and model choice.

A machine that stays on continuously
A messaging-accessible assistant needs to run continuously. A mini PC, an older computer, or a small rented server will work as long as the model is called online.
A compatible system
macOS and Linux are supported directly. On Windows, the documentation points to WSL2, the Windows Subsystem for Linux.
Node.js
A recent version is required: version 22 at a minimum, as far as we know. This requirement has already changed, so check it on the official installation page.
A model
An API key from an online provider, or a local model. Usage terms for consumer subscriptions with third-party tools vary by provider: read them before connecting yours.
An email account
Preferably an account or number dedicated to the assistant, separate from your personal account.
Some time
For the initial setup, and then for updates. The project publishes new versions at a rapid pace.
Preview — the documented installation takes two commands
# Installer la commande openclaw (Node.js requis)
npm install -g openclaw@latest

# Lancer l'assistant de configuration et installer le service
openclaw onboard --install-daemon

These two commands are provided here to measure the required effort, not as a tutorial. The setup assistant then asks questions about the model, messaging platforms, and security: follow the official documentation when installing, because the steps change from one version to another.

#What about a local model?

It's possible: OpenClaw can call a model served by Ollama, which listens by default on http://localhost:11434. But an agent is more demanding than a simple conversation. The model must be able to call tools reliably and have a large context window, because the instructions, tool descriptions, and skills already take up a lot of space before your first message.

In practice, small models with 3 to 7 billion parameters (about 2 to 5 GB of VRAM in Q4) are rarely comfortable in this role. Plan instead on a 14-billion-parameter model (about 9 GB in Q4_K_M, within reach of a RTX 3060 12GB) or a 32-billion-parameter model (about 19 GB, requiring a RTX 4090 24GB or a Mac with unified memory), while leaving room for context. The project documentation also recommends using the most capable model available to you because it handles malicious instructions better.

#Risks to know before installing

The danger does not come from an isolated flaw, but from a combination of factors. OpenClaw reads content from outside sources (messages, web pages, files), has access to private data, and can act on the machine. Bringing these three elements together in one program requires precautions, and the project's documentation says so plainly.

Prompt injection
A message, email, or web page read by the agent may contain hidden instructions that it will mistake for yours. No model is completely immune to this. Our https://quelllm.fr/guide/injection-de-prompt-llm-local guide explains the mechanism.
Exposed gateway
At the beginning of 2026, researchers identified thousands of installations accessible from the Internet. The gateway must remain listening locally, and remote access must go through a VPN or SSH tunnel.
Vulnerability fixed
The CVE-2026-25253 vulnerability made it possible to steal the gateway's access token and take control of it via a malicious link. It was fixed in late January 2026: older installations must be updated.
Malicious skills
Security researchers reported hundreds of malicious skills on the public ClawHub registry in early 2026. A skill contains instructions and sometimes scripts, executed with your permissions.
Secrets on disk
API keys, messaging sessions, and the assistant's memory are stored in its configuration directory. Anyone who reads that directory can retrieve your credentials.
Model bill
An agent that loops or wakes up frequently consumes tokens without you seeing it. Set a spending cap with your provider.

The project provides safeguards. By default, an unknown person who messages your assistant receives only a pairing code, and the agent ignores their messages until you approve that code. Group conversations can run in an isolated Docker container rather than directly on the machine. Finally, two built-in commands control the installation and flag dangerous settings.

Terminal — built-in controls
# Diagnostic de l'installation et de la configuration
openclaw doctor

# Audit de sécurité de la passerelle et de ses réglages
openclaw security audit --deep
!
Not on your primary machine
Do not install OpenClaw on the computer that contains your documents, password manager, or banking credentials. Use a dedicated machine, virtual machine, or rented server, with accounts created for the assistant and API keys limited in both permissions and budget.
i
A local model does not eliminate these risks
Running the model locally avoids sending your conversations to a provider. Prompt injection, malicious skills, and gateway exposure remain the same: they depend on the tools given to the agent, not where the model runs.

#Should you install OpenClaw? Decide in five steps

The right question is not whether the tool is impressive, but whether you have a specific use case and the means to contain it. These five steps, in order, let you decide before touching a terminal.

  1. 01
    Name a specific use case
    Write one sentence describing what the assistant will do for you each week. If nothing concrete comes to mind, a local chat interface will be enough and will spare you from maintaining an agent.
  2. 02
    Verify that you can isolate it
    Do you have a dedicated machine, a virtual machine, or a small server? If not, wait. Isolation is the precaution that limits all other errors.
  3. 03
    Choose the model and budget
    Online: an API key with a spending cap. Locally: a model capable of calling tools and a graphics card that can load it with a large context. When in doubt, start with a capped online model.
  4. 04
    Start small
    A single messaging channel, pairing left enabled, no third-party skills, and no access to your personal accounts. Expand access only once the assistant's behavior has become predictable to you.
  5. 05
    Plan for maintenance
    Update regularly, rerun the security audit after every configuration change, and review the assistant's memory files from time to time.
Rather yes
You’re comfortable with the command line, you have a machine to dedicate to it, and you have a recurring task to assign to it.
Not now
You mainly want to chat with a local model. Ollama together with Open WebUI or LM Studio meets that need with a much smaller attack surface.
Probably not
You plan to connect it to a workstation or professional data without a validated security framework. The risk outweighs the benefit.
→
A trial with no obligation
To get a feel for it, create a Telegram bot dedicated to testing, install OpenClaw in a virtual machine, and give it a single task for one week with no sensitive data—for example, a daily summary of public feeds. You’ll quickly know whether the tool is useful to you, and you can delete everything without consequences.

#The alternatives to know

OpenClaw is not the only self-hosted agent. We do not publish a ranking here because no comparison was conducted under identical conditions. Here is simply what distinguishes the closest options.

Hermes Agent
Nous Research's open-source agent, also reachable via messaging and equipped with persistent memory. Our guide explains how to connect it to Ollama. https://quelllm.fr/guide/hermes-agent-ollama-guide
Agent Zero
A general-purpose agent delivered in a Docker container, with a web interface and a built-in Linux environment. Isolation is part of its design. https://quelllm.fr/guide/agent-zero-ollama-docker
n8n with Ollama
For automations where every step is decided in advance. It’s less flexible than an agent, but much more predictable. https://quelllm.fr/guide/n8n-ollama-automatisation-workflow
Ollama with an interface
If you only need to chat with a model on your machine, without tools or messaging, this is the simplest approach.

#Official sources to consult

This guide is not based on any in-house testing. The project evolves every week: the commands, required Node.js version, and list of messaging apps may have changed since it was written. If this guide conflicts with the current state, the official documentation takes precedence.

Official GitHub repository
https://github.com/openclaw/openclaw
Official documentation (in English)
https://docs.openclaw.ai/
Documentation: gateway security
https://docs.openclaw.ai/gateway/security
Project history and references (Wikipedia, in English)
https://en.wikipedia.org/wiki/OpenClaw
CVE-2026-25253 vulnerability details
https://nvd.nist.gov/vuln/detail/CVE-2026-25253

#Go further

This page is meant to help you understand OpenClaw and make a decision. To explore the concepts it covers in greater depth, these site guides take over:

AI agent: what is it?
The definition, working examples, and reasons agents fail. https://quelllm.fr/guide/agent-ia-c-est-quoi-definition-exemples
MCP: what is it?
The protocol that connects a model to tools and data, and what it costs with a local model. https://quelllm.fr/guide/mcp-c-est-quoi-model-context-protocol
Hermes Agent with Ollama
Another self-hosted agent connected to a local model: configuration, memory, and limitations. https://quelllm.fr/guide/hermes-agent-ollama-guide
Agent Zero with Ollama
Installing a confined-by-design agent in Docker, with its real limitations. https://quelllm.fr/guide/agent-zero-ollama-docker
Did this guide help you?

Feedback, an error, or a clarification? Let us know—it improves the guide for everyone.