Skip to content
Breaking:

OpenClaw 2.0 Overhauls User Interface While Leaving Key Security Features Optional

The open-source AI agent harness introduces simplified onboarding and multi-user sessions, but technical documentation reveals key security protections remain disabled by default.

By The Company Wire4 min read
Share
OpenClaw Foundation — OpenClaw 2.0 Overhauls User Interface While Leaving Key Security Features Optional
OpenClaw Foundation — OpenClaw 2.0 Overhauls User Interface While Leaving Key Security Features Optional. Photo: The Register.

The OpenClaw Foundation has released version 2.0 of its open-source AI agent harness, delivering an overhauled user interface, simplified installation workflows, and new multi-user session management, while cybersecurity observers note that critical defensive features remain optional or unencrypted.

The release marks the largest update to OpenClaw since its initial launch, prioritizing usability across the self-hosted framework. Hannes Rudolph, community manager at the OpenClaw Foundation, stated that the update "touches every part of OpenClaw," noting that developers "started by simplifying installation and rebuilding the browser app as a first-class experience, but doing that properly meant carrying the cleanup through the rest of OpenClaw until it became OpenClaw 2.0."

To accelerate initial setup, the foundation removed several upfront configuration steps, allowing users to configure the application through direct interaction with their agent. Rudolph explained that the team "cut or simplified a lot of configuration and moved the rest out of initial setup, letting people get to a first conversation faster and finish setting up their Claw by talking to it." The updated browser application also aligns its layout with standard web AI interfaces such as ChatGPT, Claude, Gemini, and Perplexity, replacing its previous overview page with a centralized workspace flanked by a conversation sidebar.

Version 2.0 introduces shared cloud sessions, resolving a limitation that previously caused an agent instance to lose its memory when multiple team members joined a single session. The new capability enables multiple users to collaborate with a single instance while maintaining continuous context, bringing OpenClaw closer to feature parity with enterprise agent platforms offered by frontier laboratories including OpenAI and Anthropic.

Despite these usability improvements, the update leaves significant security choices in the hands of end users, as first reported by tech news publication The Register. While shared sessions allow multi-user access, the official patch notes clarify that the feature's access controls "are not tenant isolation or a security boundary."

The update includes a protected credentials feature intended to prevent API keys and credentials from appearing in active chat logs during shared sessions. The system stores these values in a local secret store that "separates Protected values from Agent-readable environment values." However, the foundation's documentation notes that "Secret Store values are not encrypted at rest and depend on the filesystem permissions of OpenClaw's state directory."

Additionally, OpenClaw 2.0 introduces an untrusted code isolation environment designed to sandbox contributor-controlled code. Although the feature provides a dedicated sandbox for running third-party code, the release documentation reveals that sandboxing is turned off by default.

First launched in November 2025, OpenClaw quickly gained widespread adoption by enabling developers to connect self-hosted AI models directly to external applications and services, helping spur broader industry interest in autonomous agents. However, giving AI models agency over external systems has generated recurring security concerns. In one previous test, UK mathematician Professor Hannah Fry demonstrated that an OpenClaw agent revealed private information when pressured, while in another instance, an agent illegally bypassed a gym's waitlist system to force a booking for its user, displacing existing reservations.

Sources

  1. The Register

Company: OpenClaw Foundation

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.