OpenClaw
OpenClaw Foundation / Peter Steinberger and the Community
As of 9 Oct 2026, PAEval has compiled 16 capability records for OpenClaw from 8 source URLs; 1 are independent observations and 12 come from the vendor's own documentation. No independent product-level score has been published for it yet. Scores from different evaluators use different scales and are not combined. PAEval does not publish its own score or rank for it.
Deployable, complete personal agent with messaging channels, memories, tools and resident dispatch, not just a development framework.
No independent product-level score has been published for this product yet. Capability evidence below is documentation and observations only.
- Independent1
- Vendor12
- Third-party report1
- Not established2
16 records · 8 source URLs · 0 external result(s)
Capability summary
Strongest status per domain; every underlying record is listed below. Availability does not establish task success.
Positioning & scope
A personal assistant that runs on your own device; open source MIT.
Regions, eligibility & access
Official website desktop download: macOS/Linux v2026.9.9, Windows v2026.9.8-1.
Limitations: The desktop packaging version does not equal the latest versions of all Gateways, mobile nodes and plug-ins.
Gateway can be self-hosted; the official website is available for Mac, Windows, and Linux; the warehouse lists iOS/Android nodes.
Conditions: Mac desktop requires macOS 15+; Windows desktop requires Windows 10/11; different components require different requirements.
The listed sources were reviewed, but sufficient public documentation was not found.
Limitations: Open source download availability does not mean that every model, channel and feature is available globally; the complete list of countries and interface languages has not been verified.
There is no subscription or official hosting package for the core software; additional model, machine, tool and third-party service costs apply.
Autonomy & background work
User-managed gateway and tooling environment; available in remote or local models.
Limitations: Self-hosting does not mean that all reasoning, search, and messaging are offline.
Persistent cron can wake up the agent and deliver to chat or webhook; there is also a heartbeat/event entry.
Conditions: Gateway needs to be running and external delivery needs to be configured.
Execution environments
The official demonstration shows tasks such as inbox processing, sending emails, calendaring, and flight check-in; tools can operate files, browsers, and commands.
Limitations: Demonstration purposes do not prove success for all sites or execution by any account.
Calls, messages & identity
Supports messaging portals such as Telegram, WhatsApp, Slack, Discord, Teams, iMessage, etc.; plug-ins are extensible.
Conditions: Each channel requires corresponding accounts, authorization and deployment.
Memory & personalization
Workspace Markdown long-term memory and daily notes are searchable; only written content is persisted.
Transactions & bookings
The listed sources were reviewed, but sufficient public documentation was not found.
Limitations: No unified support list and final payment guarantee for cross-merchant transactions, reservations, and payments was found; it relies on skills, web pages, and permissions.
Permissions, security & data
There are DM pairings, allow lists, tool rules, and sandboxes; a Gateway is designed as a single trusted actor boundary.
Limitations: This cannot be considered as multi-tenant isolation between users who do not trust each other; the main session host tool needs to be configured to isolate.
State, memory, and credentials are stored locally; configured models, search, and messaging services can still receive task data.
Provides security auditing, backup verification, and recovery to an empty directory; enabling recovery is an independent offline step.
Limitations: Restoration will roll back the approval and deduplication status, and some message credentials may need to be re-paired; it is not the sent message/transaction reversal.
External evaluations & observations
Separate papers evaluate real attack scenarios on historical configurations and four models.
Limitations: Not a security certification of the current version or a full PA ranking of the same.
Parallel has an OpenClaw/Hermes architecture comparison to help understand deployment differences.
Limitations: Commercial manufacturer article, not independent control variable success rate test.