Definition
OpenClaw is an open-source agent platform for running a continuing assistant through messaging services and its own interfaces. Its Gateway coordinates sessions, channel connections, tools, and events. Configurable hosted or local models provide inference; the surrounding platform supplies the action loop and operating state.
The assistant can work through channels such as WhatsApp, Telegram, Slack, or Discord. A workspace retains instructions and other files that support continuity. Tools, skills, and plugins extend its capabilities, subject to configuration and permissions. OpenClaw is commonly used as a personal agent, and its current documentation also supports deployments for mutually trusting teams.
Origin and attribution
Peter Steinberger created the project that became OpenClaw. In his January 29, 2026 introduction, he described a weekend project begun two months earlier and traced the naming journey from Clawd through Moltbot to OpenClaw. Project lore identifies Clawdbot as the earlier platform name and Clawd as the assistant character; the names should not be treated as separate competing products.
The software repository uses the MIT license. Its current README identifies the OpenClaw Foundation and the community as the project's maintainers. This provenance establishes the named project and its public history; it does not establish that OpenClaw invented personal agents or every workspace convention it uses.
Architecture and workspace
The Gateway is the control plane. The Control UI, command-line interfaces, messaging channels, and connected device nodes provide ways to interact with it. A model provider is one replaceable part of the system, so changing from Claude to a GPT model does not turn OpenClaw into a different model family.
Workspace files have different purposes. SOUL.md carries persona, tone, and behavioral boundaries. AGENTS.md supplies operating guidance. USER.md can capture user preferences and context, while memory files support retained information. The workspace's default working directory does not confine filesystem access by itself; execution isolation requires the relevant sandbox and tool controls.
Limits and trust boundaries
A hosted model route sends the request to its provider even when OpenClaw runs on the user's machine. A local model route has a different data path. Review the selected providers and connected services when evaluating privacy.
OpenClaw's documented security model assumes one trust boundary per Gateway: a single operator or people who trust one another. A shared agent with tools is not an isolation boundary for mutually adversarial users. The documentation recommends separate Gateways and credentials, preferably separate operating-system users or hosts, when trust boundaries differ.
Prompt injection can arrive through content the assistant reads, including email and web pages. Restricting who may message the assistant does not remove that threat. Persona instructions influence behavior, while tool policies and sandboxing enforce access limits. The project's documentation describes sandboxing as opt-in, so the presence of a workspace or a SOUL.md file should not be mistaken for an active sandbox.
Operational significance
Evaluate the whole installed agent: which model handles each task, what a channel sender can trigger, where retained context goes, and which tools can change external systems. Keep instructions and memory recoverable, and inspect effective permissions when adding a plugin or another user. A personal assistant connected to many accounts can have much more authority than its conversational interface suggests.
Distinguish it from nearby terms
- A personal agent is a role and operating pattern. OpenClaw is one platform that can implement it.
- An AI model supplies inference. OpenClaw supplies the surrounding harness, interfaces, and state.
- SOUL.md is one workspace instruction convention. It cannot replace the platform's permission controls.
- An agent skill packages reusable guidance or procedures. It is a component an OpenClaw agent may load, rather than the whole platform.
Check your understanding
An OpenClaw installation has a local workspace, uses a hosted model, and reads messages from a group chat. Which facts determine where the messages are processed, who shares the agent's tool authority, and whether shell commands run inside a sandbox?