OpenClaw: what is it, and should you install it ?
What is OpenClaw? Free software that you install on your own machine and that connects your messaging apps (WhatsApp, Telegram, Discord, and others) to an action-capable language model: reading files, running commands, and controlling a browser. This guide explains where the project comes from, how it works, what it requires, and what risks it poses, so you can decide whether to install it yourself. It contains neither in-house testing nor rankings—only what the project documents and what security researchers have published about it.
#What is OpenClaw? The short answer
OpenClaw is a personal, open-source AI assistant that you host yourself. You write to it from a messaging app you already use, like a contact, and it replies using a language model: one from an online provider or a local model. It is not just a chatbot. It is an agent: it has tools on the machine where it runs and can chain together multiple actions to accomplish what you ask.
- What is it?
- A program that runs continuously on your system and connects your messaging apps to a language model equipped with tools.
- Who does it?
- The project was started by Austrian developer Peter Steinberger. The code is published on GitHub under the MIT license and receives contributions from a large community.
- How much does it cost?
- The software is free. The model may not be: you pay for it by usage through an online provider, or in hardware and electricity if you run it locally.
- Where does it run?
- On a machine you own, running continuously: PC, Mac, mini-PC, or rented server. Nothing is hosted by the project publisher.
- The main risk?
- An agent that reads content from outside sources and can execute commands on your machine. If poorly isolated, it exposes your files and accounts.
- Do you need to install it?
- Yes if you're comfortable with a terminal and ready to isolate it on a dedicated machine. No if you just want to chat with an AI.
One clarification to avoid confusion: the name OpenClaw also refers to an unrelated project, a free reimplementation of the Claw platform game released in 1997. This page covers only the AI assistant.
#From Clawdbot to OpenClaw: three names in three months
Agents that act on your machine: agentic Cline, MCP, n8n + Ollama, local automations.
- Lifetime online access
- PDF + files
- Lifetime updates
The project first appeared in late 2025 under the name Clawdbot, with a lobster named Clawd as its mascot. The name played on its resemblance to Claude, Anthropic’s model that many users connected to it. In late January 2026, at Anthropic’s request and due to a trademark issue, the project was renamed Moltbot (the lobster’s molt), then OpenClaw a few days later. The latter is the name that stuck.
- November 2025
- First published by Peter Steinberger under the name Clawdbot.
- Late January 2026
- Renamed to Moltbot, then OpenClaw a few days later. The project goes viral, and its GitHub repository becomes one of the most followed at the time.
- February 2026
- Peter Steinberger announces that he is joining OpenAI. He says the project will be entrusted to a foundation and remain open source.
This story has two practical consequences. First, tutorials published before February 2026 refer to Clawdbot or Moltbot and use old command names: it is the same software, but their instructions are outdated. Second, Moltbook, the social network for AI agents that received a lot of attention around the same time, is a separate service launched by another person. It is not necessary to use OpenClaw.
#How it works: a gateway between messaging services and the model
The core of OpenClaw is called the gateway (Gateway in the documentation). It is a single process written for Node.js that runs in the background. It keeps connections open with your messaging services, receives each message, forwards it to the agent, then sends the response back to the right conversation. Everything else is organized around it.
- Channels
- Messaging services connected to the gateway: WhatsApp, Telegram, Discord, Slack, Signal, or iMessage, among others. The up-to-date list is in the documentation.
- The gateway
- The central process. By default, it listens only on the machine itself (address 127.0.0.1, port 18789) and also serves a web control interface.
- L'agent
- The loop that lets the model work with tools: command line, file reading and writing, browser automation, scheduled tasks.
- The model
- The one you choose. OpenClaw doesn't provide a model: it calls an online provider with your key, or a local model served by Ollama or a compatible server.
- The workspace
- A folder of Markdown-formatted text files containing the assistant’s instructions, personality, and memory. You can read and edit them manually.
- Skills
- Folders containing a SKILL.md file that teaches the agent a specific procedure. A public registry, ClawHub, lets you install more.
Two things set OpenClaw apart from a conventional chat interface. First, you can reach it from anywhere because you use your usual messaging app, while the work happens on the machine you left at home. Second, it can take the initiative. Scheduled tasks and periodic wake-ups allow it to message you on its own, for example with a daily morning update.
If the concept of an agent is still unclear, our “AI Agent: What Is It?” guide covers the basics: a model, tools, and a loop. OpenClaw applies this principle and adds a messaging layer. It can also connect to external tools, a topic covered in our guide to the MCP protocol.
#What OpenClaw is used for day to day
The uses described by the documentation and community revolve around one idea: delegating by message tasks that usually require opening a computer. None is guaranteed. The result depends heavily on the connected model and the care taken with the instructions.
- Daily check-in
- Receive a summary of your calendar, notes, or monitoring feed every morning, sent by the assistant without you asking for it.
- Remote tasks
- Ask from your phone to run a script, check a file, or restart a service on the machine left at home.
- Notes and reminders
- Dictate an idea or task in the messaging app, and the assistant files it away and reminds you at the right time.
- Search and synthesis
- Browse a few web pages and receive a summary, with the usual caveats about the reliability of what the model reads online.
- Custom automations
- Chain actions across multiple personal tools using skills, without writing a complete program.
We also need to say what OpenClaw is not. It is not a language model: without a connected model, it cannot respond to anything. It is not an online service: no one hosts or monitors it for you. And it is not a finished consumer product: installation requires a terminal, and maintenance is your responsibility.
#What you need to run it
The gateway itself is lightweight: it simply relays messages and calls a model. The requirements mainly concern machine availability and model choice.
- A machine that stays on continuously
- A messaging-accessible assistant needs to run continuously. A mini PC, an older computer, or a small rented server will work as long as the model is called online.
- A compatible system
- macOS and Linux are supported directly. On Windows, the documentation points to WSL2, the Windows Subsystem for Linux.
- Node.js
- A recent version is required: version 22 at a minimum, as far as we know. This requirement has already changed, so check it on the official installation page.
- A model
- An API key from an online provider, or a local model. Usage terms for consumer subscriptions with third-party tools vary by provider: read them before connecting yours.
- An email account
- Preferably an account or number dedicated to the assistant, separate from your personal account.
- Some time
- For the initial setup, and then for updates. The project publishes new versions at a rapid pace.
These two commands are provided here to measure the required effort, not as a tutorial. The setup assistant then asks questions about the model, messaging platforms, and security: follow the official documentation when installing, because the steps change from one version to another.
#What about a local model?
It's possible: OpenClaw can call a model served by Ollama, which listens by default on http://localhost:11434. But an agent is more demanding than a simple conversation. The model must be able to call tools reliably and have a large context window, because the instructions, tool descriptions, and skills already take up a lot of space before your first message.
In practice, small models with 3 to 7 billion parameters (about 2 to 5 GB of VRAM in Q4) are rarely comfortable in this role. Plan instead on a 14-billion-parameter model (about 9 GB in Q4_K_M, within reach of a RTX 3060 12GB) or a 32-billion-parameter model (about 19 GB, requiring a RTX 4090 24GB or a Mac with unified memory), while leaving room for context. The project documentation also recommends using the most capable model available to you because it handles malicious instructions better.
#Risks to know before installing
The danger does not come from an isolated flaw, but from a combination of factors. OpenClaw reads content from outside sources (messages, web pages, files), has access to private data, and can act on the machine. Bringing these three elements together in one program requires precautions, and the project's documentation says so plainly.
- Prompt injection
- A message, email, or web page read by the agent may contain hidden instructions that it will mistake for yours. No model is completely immune to this. Our https://quelllm.fr/guide/injection-de-prompt-llm-local guide explains the mechanism.
- Exposed gateway
- At the beginning of 2026, researchers identified thousands of installations accessible from the Internet. The gateway must remain listening locally, and remote access must go through a VPN or SSH tunnel.
- Vulnerability fixed
- The CVE-2026-25253 vulnerability made it possible to steal the gateway's access token and take control of it via a malicious link. It was fixed in late January 2026: older installations must be updated.
- Malicious skills
- Security researchers reported hundreds of malicious skills on the public ClawHub registry in early 2026. A skill contains instructions and sometimes scripts, executed with your permissions.
- Secrets on disk
- API keys, messaging sessions, and the assistant's memory are stored in its configuration directory. Anyone who reads that directory can retrieve your credentials.
- Model bill
- An agent that loops or wakes up frequently consumes tokens without you seeing it. Set a spending cap with your provider.
The project provides safeguards. By default, an unknown person who messages your assistant receives only a pairing code, and the agent ignores their messages until you approve that code. Group conversations can run in an isolated Docker container rather than directly on the machine. Finally, two built-in commands control the installation and flag dangerous settings.
#Should you install OpenClaw? Decide in five steps
The right question is not whether the tool is impressive, but whether you have a specific use case and the means to contain it. These five steps, in order, let you decide before touching a terminal.
- 01Name a specific use caseWrite one sentence describing what the assistant will do for you each week. If nothing concrete comes to mind, a local chat interface will be enough and will spare you from maintaining an agent.
- 02Verify that you can isolate itDo you have a dedicated machine, a virtual machine, or a small server? If not, wait. Isolation is the precaution that limits all other errors.
- 03Choose the model and budgetOnline: an API key with a spending cap. Locally: a model capable of calling tools and a graphics card that can load it with a large context. When in doubt, start with a capped online model.
- 04Start smallA single messaging channel, pairing left enabled, no third-party skills, and no access to your personal accounts. Expand access only once the assistant's behavior has become predictable to you.
- 05Plan for maintenanceUpdate regularly, rerun the security audit after every configuration change, and review the assistant's memory files from time to time.
- Rather yes
- You’re comfortable with the command line, you have a machine to dedicate to it, and you have a recurring task to assign to it.
- Not now
- You mainly want to chat with a local model. Ollama together with Open WebUI or LM Studio meets that need with a much smaller attack surface.
- Probably not
- You plan to connect it to a workstation or professional data without a validated security framework. The risk outweighs the benefit.
#The alternatives to know
OpenClaw is not the only self-hosted agent. We do not publish a ranking here because no comparison was conducted under identical conditions. Here is simply what distinguishes the closest options.
- Hermes Agent
- Nous Research's open-source agent, also reachable via messaging and equipped with persistent memory. Our guide explains how to connect it to Ollama. https://quelllm.fr/guide/hermes-agent-ollama-guide
- Agent Zero
- A general-purpose agent delivered in a Docker container, with a web interface and a built-in Linux environment. Isolation is part of its design. https://quelllm.fr/guide/agent-zero-ollama-docker
- n8n with Ollama
- For automations where every step is decided in advance. It’s less flexible than an agent, but much more predictable. https://quelllm.fr/guide/n8n-ollama-automatisation-workflow
- Ollama with an interface
- If you only need to chat with a model on your machine, without tools or messaging, this is the simplest approach.
#Official sources to consult
This guide is not based on any in-house testing. The project evolves every week: the commands, required Node.js version, and list of messaging apps may have changed since it was written. If this guide conflicts with the current state, the official documentation takes precedence.
#Go further
This page is meant to help you understand OpenClaw and make a decision. To explore the concepts it covers in greater depth, these site guides take over:
- AI agent: what is it?
- The definition, working examples, and reasons agents fail. https://quelllm.fr/guide/agent-ia-c-est-quoi-definition-exemples
- MCP: what is it?
- The protocol that connects a model to tools and data, and what it costs with a local model. https://quelllm.fr/guide/mcp-c-est-quoi-model-context-protocol
- Hermes Agent with Ollama
- Another self-hosted agent connected to a local model: configuration, memory, and limitations. https://quelllm.fr/guide/hermes-agent-ollama-guide
- Agent Zero with Ollama
- Installing a confined-by-design agent in Docker, with its real limitations. https://quelllm.fr/guide/agent-zero-ollama-docker
Feedback, an error, or a clarification? Let us know—it improves the guide for everyone.