Agents AI

OpenClaw

Self-hosted agent in your chat apps

Workflow Automation
Visit website
Free tierFrom FreeOpenClaw Foundation (initiated by Peter Steinberger)Founded 2025Reviewed Oct 2026

Our take

Our verdict

6.4/10

Free, MIT-licensed open-source personal AI agent that runs on your own machine and acts through 20+ messaging apps, with swappable model providers.

Best for: Technical users who want a private, self-hosted personal agent in their chat apps and will invest the time to lock it down.

Overall score6.4/10
Capability8.0
Ease of use5.0
Value for money8.0
Reliability4.0
Support & docs6.0

Pros

  • Free and MIT-licensed, with no subscription or hosted service; state, memory and credentials stay on your own hardware
  • Works through 20+ messaging platforms (WhatsApp, Telegram, Slack, Discord, Signal, iMessage, Teams and more) plus native apps
  • Model-agnostic: swap between Claude, Codex-style cloud models and local models
  • Very large, active community (390k+ GitHub stars) and rapid release cadence; v2.0 added shared multi-user sessions and Docker/Podman sandboxing

Cons

  • Security record is poor: documented critical vulnerabilities, a malicious-skill campaign on its ClawHub registry, and large numbers of internet-exposed instances
  • Sandboxing and per-request execution approvals are opt-in; the default setup permits host-level command execution
  • Needs a recent Node.js runtime and self-management; non-technical users will struggle to run it safely
  • Free software, but you still pay for model API tokens or local hardware, and costs can climb with autonomous use

Overview

OpenClaw is an open-source (MIT) personal AI agent that runs on your own computer and is operated through the messaging apps you already use. It began as a project by developer Peter Steinberger and is now stewarded by the independent OpenClaw Foundation, a 501(c)(3) nonprofit. According to its GitHub repository it has more than 390,000 stars, and it connects to 20+ messaging services, with state, memory and credentials kept locally. It is model-agnostic, working with cloud models such as Claude as well as local ones, and costs nothing beyond the model tokens or hardware you supply.

Version 2.0 (tagged v2026.8.1, August 30, 2026) targeted teams: shared agent sessions with graded access, a rebuilt browser control UI, guided model setup, and wider sandboxing through Docker and Podman, role-enforced permissions and a team secret store. Coverage by The Register noted, however, that sandboxing and execution approvals remain opt-in, with a baseline that assumes one trusted operator and allows host-level commands.

The security history is the main caveat. Researchers reported a high-severity vulnerability (CVE-2026-25253), a malicious-skill campaign on ClawHub (Koi Security found 341 malicious skills among 2,857 audited), and scans finding tens of thousands of internet-exposed instances with unsafe settings. NVIDIA's NemoClaw sandbox, built to run OpenClaw more safely, also had its own disclosed flaw (CVE-2026-65105). The project is powerful and flexible, but it is best treated as expert-grade infrastructure rather than a consumer app. Compare managed alternatives such as Manus or Claude, or Hermes Agent for a similar open-source approach.

Key Benefits

  • Own your data and stack: Everything runs on your hardware, with no vendor subscription and an MIT license.
  • Meet it where you chat: Talk to the agent from WhatsApp, Slack, Telegram and other apps instead of a new interface.
  • No model lock-in: Switch providers or run local models as pricing and quality change.
  • Team features: v2.0 adds shared sessions and optional sandboxing for multi-user use.

Use Cases

  1. Personal assistant in your chat apps — Delegate tasks and reminders from the messenger you already use.
  2. Self-hosted automation — Run a private agent that uses your own files, accounts and tools.
  3. Coding and ops help for technical teams — Use shared sessions to watch or steer a running agent, with sandboxing enabled.
  4. Local-model experiments — Pair the agent with local models for privacy-sensitive workflows, ideally behind a sandbox.
Open Source
Self-Hosted
AI Agents
Messaging
MIT License

Features

  • Runs locally on macOS, Linux, Windows and WSL2 (Node.js 24.16+ or 26.1+)
  • 20+ chat channels, including WhatsApp, Telegram, Slack, Discord, Signal, iMessage and Microsoft Teams
  • Swappable model providers, including local models
  • Plugin and skill ecosystem via the ClawHub registry
  • Browser-based control UI with approvals, files and live agent activity (v2.0)
  • Shared cloud sessions with read-only, suggest, draft or full access levels (v2.0)
  • Docker and Podman sandboxing, per-agent scopes and a team secret store (opt-in)

Pricing

Self-hosted
$0
  • Full open-source software (MIT), no subscription
  • Bring your own model API keys or run local models
  • You pay for tokens and your own hardware or server

Try OpenClaw

From Free · free tier available

Visit OpenClaw

Alternatives to OpenClaw