# openclaw v2026.8.1-beta.2 — OpenClaw 2026.8.1-beta.2 - Product: openclaw (https://whatsnew.fyi/product/openclaw) - Vendor: openclaw - Date: 2026-08-15 - Version: v2026.8.1-beta.2 - Original notes: https://github.com/openclaw/openclaw/releases/tag/v2026.8.1-beta.2 - Permalink: https://whatsnew.fyi/product/openclaw/releases/v2026.8.1-beta.2 - Labels: Pre-release What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Secret egress host binding to exact HTTPS destination hosts across CLI, Gateway RPC, and Control UI so unbound sentinel substitution fails closed before plaintext egress - **added** — Support for GPT-5.6 Ultra and runtime switching with Sol, Terra, and Luna across OpenClaw and Codex engines - **added** — Atomic model, runtime, and thinking selection through `/model` and fallback with live matrix coverage for both harnesses - **added** — Shared plugin SDK monitor for durable admission, polling, pruning, claim identity validation, adoption handoff, and shutdown - **added** — SQLite snapshots with `openclaw backup sqlite create|list|verify|restore` for compact, verified global and per-agent database artifacts - **added** — macOS app profiles to isolate named app instances across state, preferences, Keychain, Gateway services, and duplicate-instance ownership - **added** — Plugin install provenance warnings requiring explicit `--force` acknowledgement for arbitrary executable plugin sources in CLI and chat installs - **added** — Browser extension relay CDP compatibility to answer `Target.getBrowserContexts` for Puppeteer-based clients without remote-debugging permission prompt - **added** — Local model setup with provider-owned Ollama, llama.cpp, and LM Studio setup choices advertised to Control UI and macOS - **added** — Fish Audio speech with hosted S2.1 synthesis including streaming, voice notes, voice discovery, and telephony, plus local Fish S2 Pro reference-voice streaming in native macOS Talk - **added** — Control UI cloud workspace conflicts surface with staged-ref guidance, bounded conflicted paths, structured transcript events, and sidebar attention - **added** — Control UI who's-online roster accessible by clicking the sidebar footer facepile to view everyone online with avatars, names, and emails - **added** — Discord and Slack native login with `/login` in native command menus while keeping pairing-code issuance limited to private chats and the Web UI - **added** — Control UI user profiles allowing trusted-proxy users to manage their own display name and avatar - **changed** — Migrate IRC, Synology Chat, and Google Chat to the shared plugin SDK monitor lifecycle - **changed** — Release validation to defer beta candidate Parallels smoke to postpublish `release:beta-smoke` by default - **changed** — Plugin uninstall cleanup to remove exact recorded install paths from `plugins.load.paths` for marketplace, npm, and other managed installs - **changed** — Developer workflow to remove the obsolete scoped-commit helper and use standard Git commands in isolated worktrees - **fixed** — Control UI update recovery so the Reload button waits out the gateway restart and reloads as soon as it answers instead of silently doing nothing - **fixed** — Crabbox hydration on unprivileged cloud sandboxes by falling back to a user-writable pnpm store when the shared `/var/cache/crabbox` cache is unavailable ##### 2026.8.1 ###### Highlights - **Secret egress host binding:** bind each shared-store secret to exact HTTPS destination hosts across CLI, Gateway RPC, and Control UI so unbound sentinel substitution fails closed before plaintext egress. Thanks @shakkernerd. - **GPT-5.6 Ultra and runtime switching:** support Sol, Terra, and Luna across OpenClaw and Codex engines; keep model, runtime, and thinking selection atomic through `/model` and fallback; and add live matrix coverage for both harnesses. Thanks @anyech and @vincentkoc. - **Channel plugin ingress monitors:** add a shared plugin SDK monitor for durable admission, polling, pruning, claim identity validation, adoption handoff, and shutdown, and migrate IRC, Synology Chat, and Google Chat to the shared lifecycle. Thanks @vincentkoc and @shakkernerd. - **SQLite snapshots:** add `openclaw backup sqlite create|list|verify|restore` for compact, verified global and per-agent database artifacts with fresh-target-only restore. Thanks @giodl73-repo. - **macOS app profiles:** isolate named app instances across state, preferences, Keychain, Gateway services, and duplicate-instance ownership while keeping host-global login and node services untouched. Thanks @shakkernerd and @vincentkoc. - **Plugin install provenance warnings:** require explicit `--force` acknowledgement for arbitrary executable plugin sources in CLI and chat installs, keep trusted ClawHub, bundled, official-catalog, and tracked-update flows frictionless, and restrict Crestodian installs to trusted sources. Thanks @jesse-merhi and @vincentkoc. - **Control UI update recovery:** the "A new version is available" Reload button now waits out the gateway restart that stranded the chunk and reloads as soon as it answers, instead of silently doing nothing and leaving a manual hard reload as the only way out. Thanks @vincentkoc. ###### Changes - **Secret egress host binding:** bind each shared-store secret to exact HTTPS destination hosts across CLI, Gateway RPC, and Control UI so unbound sentinel substitution fails closed before plaintext egress. Thanks @shakkernerd. - **Release validation:** defer beta candidate Parallels smoke to postpublish `release:beta-smoke` by default, keep stable/full prepublish coverage, and bound nested release workflow monitors with explicit job timeouts. Thanks @vincentkoc. - **macOS app profiles:** isolate named app instances across state, preferences, Keychain, Gateway services, and duplicate-instance ownership while keeping host-global login and node services untouched. Thanks @shakkernerd and @vincentkoc. - **Developer workflow:** remove the obsolete scoped-commit helper and use standard Git commands in isolated worktrees. - **Plugin uninstall cleanup:** remove exact recorded install paths from `plugins.load.paths` for marketplace, npm, and other managed installs while preserving parent, child, prefix, and unrelated paths. Thanks @vincentkoc. - Fixed Crabbox hydration on unprivileged cloud sandboxes by falling back to a user-writable pnpm store when the shared `/var/cache/crabbox` cache is unavailable, preserving the hardlink import mode after hydration, and making Docker an explicit routed capability instead of an implicit install requirement. Thanks @vincentkoc and @joshavant. - **Browser extension relay CDP compat:** answer `Target.getBrowserContexts` so Puppeteer-based clients (chrome-devtools-mcp) can drive the paired Chrome without the remote-debugging permission prompt, serve DevTools-style `/json/list` target descriptors, and add `openclaw browser extension cdp` to print the relay endpoint plus auth header for external CDP clients. Thanks @vincentkoc. - **Local model setup:** advertise provider-owned Ollama, llama.cpp, and LM Studio setup choices to Control UI and macOS, retry unavailable LM Studio services in place, and verify the exact prepared model before showing success. Thanks @vincentkoc. - **Control UI first-run setup:** continue verified model setup into Custodian, explain _[Truncated at 4000 characters — full notes: https://github.com/openclaw/openclaw/releases/tag/v2026.8.1-beta.2]_