AI Agents

OpenClaw 2.0: Multiplayer Sessions Inside One Trust Boundary

OpenClaw 2.0 shipped as version 2026.8.1 on 2026-08-31, after roughly two months of work from 933 contributors and more than 16,000 pull requests — from a project that had previously shipped 106 releases in 230 days. The marquee feature is shared cloud sessions: a second person can join an agent's live work, or take it over, with context intact. The sentence to read twice is OpenClaw's own: those controls are not tenant isolation and not a security boundary. Multiplayer arrived; the wall between players did not. We also read the repository directly rather than quoting launch-day figures — 388,206 stars as of 2026-08-31T13:28:06Z — and found a licence GitHub declines to classify, for a reason worth knowing.

Diagram showing an OpenClaw gateway as a single trust boundary with shared sessions inside it

We covered OpenClaw in July for the model-agnostic seam — the single place where you decide what it costs and who you depend on. Version 2.0 does not touch that seam. It changes who else can be in the room.

What shipped in 2026.8.1

Third-party, from the release and its coverage, read 2026-08-31:

The release notes lead with an unusual warning of their own: if the automatic update fails, use a local coding harness to help complete it and diagnose migration errors, and back up your configuration and state first. A project telling you to back up before upgrading is being honest, and you should take it literally.

One trust boundary per gateway

This is the part to get right before you enable sharing.

Sharing a session puts a person inside the boundary, not beside itOpenClaw documents the sharing controls as convenience features, not tenant isolation.ONE GATEWAY = ONE TRUST BOUNDARYthe agentcredentialspluginsmemory · browseryouthe person who set it upanyone you invite to a shared sessionsame boundary, same credentials, same reacheveryoneelseThere is no inner wall. Invite someone to collaborate and they are inside the same boundary as the credentials.Source: OpenClaw’s own documentation and 2.0 release coverage, read 2026-08-31. We have not audited the implementation.
Multiplayer, but the boundary is still drawn around the whole gateway.

OpenClaw is a self-hosted, single-user assistant that holds your credentials, reads your messages and can drive a browser. That was always the trade — we called it the honest security trade-off in the original write-up. Version 2.0 does not change the shape of the trade; it adds a way to bring someone else inside it.

So treat a shared session the way you would treat handing someone your unlocked laptop, not the way you would treat adding a teammate to a workspace. If you need real separation between people, run separate gateways. That is what “one trust boundary per gateway” means in practice, and it is the correct architecture — it is just not what “multiplayer” usually implies. Our agent security page covers the wider category of this mistake.

The setup change, and what it does to your bill

Reusing your existing ChatGPT, Claude or Codex login to get started is a real onboarding win and a quiet cost decision. It means the default path now routes your agent through whichever subscription you already had open, rather than making you choose a model deliberately.

That matters because the model choice is where the money is. On our executed benchmark, Claude Sonnet 5 and DeepSeek V3.2 both scored 9 out of 9, at $1.67 and $0.08 per 1,000 tasks respectively — a 21x gap for the same result on the same nine tasks. An agent that quietly defaults to whatever you were already signed into is an agent whose bill you have not chosen.

OpenClaw remains genuinely model-agnostic, so the fix is a config change rather than a migration. It is worth making deliberately once, especially now that Claude Code weekly limits drop 17% on 2026-09-14 and more people will be looking at where their agent tokens actually go.

The repository, read directly

Most coverage quotes a star count from launch day. We queried the GitHub API at 2026-08-31T13:28:06Z:

Fieldopenclaw/openclawFor scale: deepseek-ai/deepseek-harness
Stars388,206205,981
Forks81,49923,879
Watchers1,754888
LanguageTypeScriptTypeScript
Repository created2025-11-242026-08-13
Issue trackerenableddisabled
Latest releasev2026.8.1, 2026-08-31—

Our July write-up recorded 340,000 stars. That is 48,206 added in seven weeks. For context on how fast this category moves, DeepSeek Harness reached 205,981 stars in eighteen days from a standing start — we measured it at 183,972 nine days ago, so it added 22,009 in that window alone. Any star count you read without a timestamp is decoration.

The licence GitHub will not classify

GitHub reports OpenClaw's licence as NOASSERTION, displayed as “Other”. That looks alarming on a project holding your credentials, so we read the file.

It is the MIT Licence, copyright OpenClaw Foundation, with every canonical clause present — the grant, the notice requirement, the warranty disclaimer and the liability limitation. The file is 1,170 characters against roughly 1,070 for canonical MIT, and the difference is one appended sentence stating that third-party notices for incorporated or adapted code are recorded in THIRD_PARTY_NOTICES.md.

That single added line is why GitHub's detector, which needs a near-exact match, falls back to “Other”. So: the badge is misleading, the licence is MIT, and the appended pointer is a reason to read THIRD_PARTY_NOTICES.md rather than a reason to worry. If licence provenance matters to your review, open weights versus open source covers why the badge is never the answer.

Who should upgrade

What we did not test

FAQ

What is new in OpenClaw 2.0? Shared cloud sessions, guided model setup that reuses existing logins and local runtimes, a faster Control UI, and work across installation, plugins, credentials, browser control, messaging, automation and memory — 16,000+ pull requests from 933 contributors, shipped as version 2026.8.1 on 2026-08-31.

Are OpenClaw shared sessions secure? OpenClaw's own documentation says the sharing controls are not tenant isolation and not a security boundary. Anyone in a shared session is inside the same trust boundary as the gateway's credentials.

How many GitHub stars does OpenClaw have? 388,206 as of 2026-08-31T13:28:06Z, with 81,499 forks.

What licence is OpenClaw under? MIT. GitHub shows “Other” because the LICENSE file appends one sentence pointing at THIRD_PARTY_NOTICES.md, which defeats its exact-match detector.

Should I back up before upgrading? Yes — the release notes ask you to back up configuration and state before updating.

Written by

Founder of DataLLM Lab, the unified LLM gateway. Kevin tests models the boring way — same prompts, real costs, unedited outputs — and writes up what the runs actually show. Articles are drafted with AI assistance and published under his name; every first-party number comes from an executed run.

One API for every model

One API, every model.

Get a single API key for Claude Opus 4.7, GPT-5.4, and 300+ more — with automatic price comparison and routing to the best model for every request.