OpenClaw has released version 2026.8.1, also called OpenClaw 2.0, in what the open-source AI agent platform described as its largest update to date.
The release was built by 933 contributors, including 569 first-time contributors, and contains more than 16,000 pull requests across installation, agents, plugins, credentials, browser controls, messaging, automation, memory, and native applications.
The nearly two-month development cycle marks a major shift for the project, which previously shipped 106 releases in 230 days.
OpenClaw said it paused its usual rapid release cadence because the growing project needed a stronger technical foundation and safer upgrade path for both new and existing deployments.
A key focus of OpenClaw 2.0 is security for AI agents that can access tools, files, browser sessions, messaging platforms, cloud workers, and enterprise services.
The update introduces private credential requests, allowing an agent to request a secret via a masked prompt without exposing the credential value in the chat history or model context.
An opt-in proxy can also restrict protected-secret substitution to approved destinations, helping reduce the risk of credentials being exposed through unintended outbound requests. The platform now includes a shared credential store for team environments.
OpenClaw 2.0 Released
Administrators can manage team-scoped secrets and environment values through SQLite-backed CLI and Settings interfaces. Secret values remain write-only, while protected outbound connections can be bound to declared hosts.
OpenClaw also added an optional 1Password broker that supports curated secret references, service-account authentication, per-secret approval, and audit records without exposing the secret value.
Plugin security also received major upgrades. OpenClaw now presents capability, source, version, and artifact details before external plugins are installed or enabled. Installations from arbitrary executable sources require the –force flag.

In contrast, trusted ClawHub, bundled, official-catalog, and tracked-update sources can avoid the provenance warning but still require capability consent. The release also adds ClawHub security-audit information to the plugin installation flow.
For agent execution, OpenClaw 2.0 introduces explicit session permission modes and workspace restrictions. Restricted filesystem access is anchored to the recorded workspace or worktree, reducing the chance that an agent can access files outside its approved scope.
Team operator roles can limit which agents, sessions, and administrative scopes are available to verified users. However, OpenClaw warns that these controls are collaboration features and should not be treated as hostile multi-tenant isolation.
The release also improves approval handling for recurring automations. Users can approve a specific operation once, inspect or revoke the permission later, and require a new approval when the automation’s operation changes. This helps prevent an initially approved workflow from silently expanding its authority over time.

Other defensive improvements include model allowlists, configuration-change history with sensitive-value redaction, database recovery protections, sanitized debugging handoffs through OpenClaw triage, safer startup migrations, and fixes designed to prevent private prompt context from appearing in final or streaming replies.
OpenClaw 2.0 also rebuilds the browser Control UI as a primary workspace and adds shared cloud sessions, browser workflow controls, agent dashboards, and broader support for local and external model providers.
The scale of the update makes security review and staged deployment especially important for organizations using OpenClaw agents with production credentials, plugins, messaging integrations, or cloud execution.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post OpenClaw 2.0 Released With Major Security Upgrades for AI Agents, Plugins and Credentials appeared first on Cyber Security News.
