Bridge paragraph before the enterprise properties: same product spans one
laptop to hardened team deployment, configuration is the only difference,
and the enterprise checklist protects a single operator for free. Adds a
read_when bullet for the reader asking whether enterprise depth makes
OpenClaw heavyweight for personal use.
Replace the feature-list opener with a human introduction: what an agent
inverts about software, why that demands scrutiny, and the OpenClaw
Foundation's mission, governance, and Switzerland-of-AI aim. Dedupe the
Governance section so the sponsor list and 501(c)(3) framing state once.
Three mermaid diagrams for the densest arguments on the page: the
gateway/movable-execution topology, the fail-closed exec policy chain,
and the secret sentinel flow at the egress boundary. All blocks
parse-checked against mermaid.
* docs(start): add Why OpenClaw enterprise architecture page
Source-audited architecture argument for enterprise evaluators: trusted
gateway vs movable untrusted execution, policy-as-code, tiered access,
SecretRef chain, versioned state, provenance, open standards, and a
commit-pinned comparison with Hermes Agent verified against both source
trees. Registers the page in the Get started nav and fixes the OpenShell
policy config description (YAML path, not ID).
* docs(start): link landed feature pages and split the Hermes verdict paragraph
* docs(start): state the comparison in present tense
* docs(start): tighten register after external language review
* docs(start): address review findings
Restore main's OpenShell guide unchanged (rebase resolution had
resurrected the pre-rewrite page), defer the plugin consent screen
claim until its implementation merges, scope the memory forget claim
to tracked artifacts of selected sessions, replace brittle RPC and
capability counts, state OpenAI-compatible API limits, and add
immutable permalinks for every external Hermes citation.
* feat(cli): add openclaw triage for sanitized agent debugging handoffs
Collects read-only doctor findings through a new collectDoctorFindings seam,
reuses the sanitized diagnostics export, writes a bounded 8 KiB debugging
prompt, and prints Claude Code / Codex / embedded agent handoff commands.
Embedded --run gates on an interactive terminal plus a live inference probe.
* fix(doctor): keep word separation when scrubbing multi-line errors
scrubDoctorErrorMessage dropped newlines without substituting a space, so
multi-line errors rendered with glued words in doctor and triage output.
* feat(cli): hand triage prompts straight to a detected coding agent
Interactive triage now detects installed agents via resolveExecutablePath,
offers embedded/Claude Code/Codex/print in a picker, and spawns the chosen
binary with the prompt, propagating its exit code. Embedded inference is
probed only after selection. JSON output adds detectedAgents.
* fix(cli): redact local paths in triage prompts and drop unlaunchable targets
Prompt content now uses canonical path-aware redaction (redactSupportString),
so paths reach external agents as ~/... or $OPENCLAW_STATE_DIR/... instead of
absolute home paths; operator-facing JSON paths and printed commands stay real.
Findings are fitted to the byte budget left after the trailing sections so the
omission notice, bundle path, and privacy statement always survive truncation.
Windows command shims are listed as manual commands rather than offered as a
direct launch that shell-less spawn rejects.
* fix(cli): clarify which Node runtime triage reports
A live agent run flagged the reported version as wrong because the shell
default differed from the runtime executing the CLI.
* docs: route new installs to openclaw triage when setup fails
Getting Started had no recovery path; add one that leads with triage, and
document prompt location, environment inheritance, and exit codes on the
CLI page. Keep the Triage page title untranslated like Doctor.
* fix(system-agent): increase setup inference probe max tokens from 32 to 128
The 32-token cap starves reasoning models that spend tokens on thinking
before emitting visible text. The probe gets a reasoning-only turn and
reports healthy local models as broken inference.
Increase to 128 tokens to accommodate reasoning model thinking overhead.
Fixes#124345
* fix(system-agent): leave reasoning room in setup probes
Co-authored-by: synthclaw <synthalorian@gmail.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Remove the bundled OpenProse plugin and /prose command now that upstream owns the maintained Agent Skill. Preserve /prose as migration documentation and let Doctor clean stale plugin configuration.
BREAKING CHANGE: The bundled OpenProse plugin and /prose command are removed.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
With agents.defaults.heartbeat.every set to "0m", a background exec completion queued its system event and requested a targeted exec-event wake, but the shared unscheduled-wake policy only admitted immediate wakes, so the follow-up agent turn silently never ran. Admit the exact exec-event/event producer shape (session or agent target required) in one per-source predicate, dispatch wake timers outside the requesting attempt's transcript-writer context, and document that "0m" disables recurring cadence only.
Closes#62505
Co-authored-by: Jason O'Neal <jason.allen.oneal@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(onboard): honor secret-input-mode ref for the generated gateway token
`openclaw onboard --secret-input-mode ref` was silently ignored for
`gateway.auth.token`: onboarding generated the token and wrote it into
`openclaw.json` as a plaintext string, so `openclaw doctor` warned about
`gateway.auth.token` on the install it had just created. The flag was
honored for provider credentials, so an operator who explicitly opted into
references still ended up with a plaintext secret and a remediation
(`openclaw secrets configure`) that cannot migrate a self-generated value,
because it validates a ref by resolving one that already exists.
Setup mints this token itself, so reference mode now provisions it:
- an ambient OPENCLAW_GATEWAY_TOKEN keeps an `env` ref to that variable, so a
later rotation stays authoritative instead of being pinned by a stale copy
- anything else (freshly generated, or an existing plaintext token being
migrated) goes into the shared SQLite secret store as a write-only `secret`
entry, with config holding only `{source:"store",...}`
An existing store entry wins over a freshly generated one, so reruns never
rotate a token already paired with clients. The store write precedes the
config write: a ref persisted without its value would leave the gateway
unauthenticatable, while an orphaned entry is reused by the next run.
The interactive wizard had the same dead end and is fixed the same way.
Default (plaintext) onboarding is unchanged.
User impact: `--secret-input-mode ref` now keeps the gateway token out of
openclaw.json, and a fresh install no longer self-reports a plaintext-secret
warning.
* test(onboard): split gateway onboarding suite under the max-lines gate
The added gateway auth-token tests pushed
onboard-non-interactive.gateway.test.ts to 1014 lines, over the max-lines
limit (check-lint-core-3). Repo policy is to split, never suppress.
Extract the shared vi.mock/harness preamble into
onboard-non-interactive.gateway.test-mocks.ts, following the existing
agent-command.test-mocks.ts pattern, and move the four gateway auth-token
storage tests into their own suite. The reachability mock becomes a holder
object so both suites can swap it across the module boundary, and hoisted
mocks are re-exported in a separate export clause because Vitest rejects
exporting a vi.hoisted binding at its declaration.
Test set is unchanged: the it-declaration multiset matches the pre-split
file exactly, with no duplication across the two suites.
* test(onboard): give the shared gateway onboarding mocks unique export names
check-export-name-collisions flagged `runtime` and `readConfigFileSnapshotMock`
as colliding with program.test-mocks.ts and plugins-cli-test-helpers.ts once the
gateway onboarding preamble became a shared module. Rename the exports to
gatewayOnboardRuntime / gatewayOnboardConfigSnapshotMock per the repo's
unique-export-name rule; suites alias them locally so the assertions read the
same as before.
* test(tooling): route the new gateway auth-token suite from its test helper
test-projects asserts which suites a change to
onboard-non-interactive.test-helpers.ts should run. The new
onboard-non-interactive.gateway-auth-token.test.ts imports that helper, so it
belongs in the expected routing plan.
Align copyable onboarding commands with the mandatory risk acknowledgement and an explicit health disposition for config-only automation.\n\nRefs #121951.
* fix(macos): let onboarding replace an auto-connected AI
The AI page auto-tests the best detected candidate and connects without
asking, then hides every alternative route. Add 'Choose a different AI'
to the connected banner: a re-detect pass with auto-activation
suppressed that ends at the picker (candidates, provider sign-in, API
keys). Also disable the manual key Connect button while another test
runs (submitManualKey silently dropped the tap), and isolate a test
that read the machine's real resume store.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(macos): surface real daemon errors past the Node banner
Gateway daemon failures summarized as 'Node.js v26.5.1' because the
summary takes the last non-empty line and Node fatal errors end with a
version banner. Drop trailing banner lines and prefer the last
error-shaped line above them; all other output keeps its last line.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(macos): hand onboarding off to the dashboard custodian
Native onboarding now ends once inference verifies: welcome, connection,
install (when needed), AI setup. Finish opens the dashboard at
/custodian?onboarding=1, where the custodian onboarding owns memory
import, channels, app recommendations, and the hatch (browser-first per
the onboarding redesign). The native memory-import and permissions
pages leave the first-run flow; 'Set up later' keeps the native ready
page. The native navigation bridge gains a validated optional search
field so the handoff can request onboarding chrome; the URL fallback
carries the query alongside the token fragment.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* refactor(macos): delete the unreachable native memory-import module
The dashboard handoff removed the memory-import page from every flow,
leaving the module reachable only from tests. CI's dead-code scan
rightly flagged the first orphans; remove the whole path (model, page,
mascot wiring, tests) instead of trimming symbol by symbol. The
dashboard's own memory-import surface owns the feature.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Peter Steinberger <steipete@mac-studio-sf2.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* docs(automation): rename scheduled-tasks feature wording to Automations
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WhJ8EiMXue6ADLmHfb7FL6
* docs: regenerate docs map and add Automations glossary entries
* docs(templates): follow renamed automations-vs-heartbeat anchor
* docs(automation): fix markdown formatting drift
* docs(automation): teach the canonical automations tool and sync the copied heartbeat default
Review follow-ups: normal instructions use the automations tool with cron as
an explicit compatibility alias; every verbatim copy of the default heartbeat
prompt matches the new shipped text from the strings PR.
---------
Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* docs: link macOS onboarding pages to app download
Add download handoff to both macOS app onboarding entry points so
first-time users can reach the app before following first-run steps.
- onboarding.md: add <Tip> linking to /platforms/macos#download
- onboarding-overview.md: update comparison table Command row and
macOS section opening sentence with download link
Closes#111338
* docs: tighten macOS download handoff
Co-authored-by: WangYan <wang.yan29@xydigit.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* docs: recommend Node 26 in quickstart, landing, and platform install docs
- Problem: the user-facing quickstart (docs/start/getting-started.md), landing
page (docs/index.md), and Linux/macOS platform install docs still mark
Node 24 as the recommended default, contradicting maintainer PR #114399
('recommend Node 26 as the OpenClaw runtime') and the installer default
(scripts/install.sh NODE_DEFAULT_MAJOR=26, openclaw.mjs
RECOMMENDED_NODE_MAJOR=26). Users following the quickstart pick a slower,
heavier runtime against the project's stated recommendation.
- Fix: align the 4 missed user-facing install surfaces to 'Node 26
recommended', matching the phrasing already in docs/install/node.md,
docs/install/index.md, docs/install/ansible.md, docs/install/bun.md, and
docs/help/faq-first-run.md. Leave docs/start/setup.md (the source/dev
workflow where CI pins Node 24) unchanged on purpose.
- Verification: docs-only diff reviewed; supported-version floors
(22.22.3+/24.15+/25.9+) unchanged; consistent across all install surfaces.
* docs: complete Node 26 installation guidance
Co-authored-by: Santhi Prakash <b.santhiprakash@gmail.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>