OpenClaw 2.0: Multiplayer Sessions Inside One Trust Boundary
OpenClaw 2.0 shipped as version 2026.8.1 on 2026-08-31, after roughly two months of work from 933 contributors and more than 16,000 pull requests — from a project that had previously shipped 106 releases in 230 days. The marquee feature is shared cloud sessions: a second person can join an agent's live work, or take it over, with context intact. The sentence to read twice is OpenClaw's own: those controls are not tenant isolation and not a security boundary. Multiplayer arrived; the wall between players did not. We also read the repository directly rather than quoting launch-day figures — 388,206 stars as of 2026-08-31T13:28:06Z — and found a licence GitHub declines to classify, for a reason worth knowing.
We covered OpenClaw in July for the model-agnostic seam — the single place where you decide what it costs and who you depend on. Version 2.0 does not touch that seam. It changes who else can be in the room.
What shipped in 2026.8.1
Third-party, from the release and its coverage, read 2026-08-31:
- Shared cloud sessions — a second person can join an agent's live work or take it over, with context intact. This is the headline.
- Guided model setup that reuses what is already on your machine: existing ChatGPT, Claude or Codex logins, API keys, and local runtimes like Ollama or LM Studio.
- A 575 ms Control UI startup, and configuration moved out of first-run so the first conversation begins sooner.
- 16,000+ pull requests from 933 contributors, 569 of them first-time.
- Work spanning installation, agents, plugins, credentials, browser controls, messaging, automation, memory and the native apps.
- A deliberate slowdown: roughly two months for this release, against 106 releases in the previous 230 days. The project says it paused its cadence because it needed a stronger foundation and a safer upgrade path.
The release notes lead with an unusual warning of their own: if the automatic update fails, use a local coding harness to help complete it and diagnose migration errors, and back up your configuration and state first. A project telling you to back up before upgrading is being honest, and you should take it literally.
One trust boundary per gateway
This is the part to get right before you enable sharing.
OpenClaw is a self-hosted, single-user assistant that holds your credentials, reads your messages and can drive a browser. That was always the trade — we called it the honest security trade-off in the original write-up. Version 2.0 does not change the shape of the trade; it adds a way to bring someone else inside it.
So treat a shared session the way you would treat handing someone your unlocked laptop, not the way you would treat adding a teammate to a workspace. If you need real separation between people, run separate gateways. That is what “one trust boundary per gateway” means in practice, and it is the correct architecture — it is just not what “multiplayer” usually implies. Our agent security page covers the wider category of this mistake.
The setup change, and what it does to your bill
Reusing your existing ChatGPT, Claude or Codex login to get started is a real onboarding win and a quiet cost decision. It means the default path now routes your agent through whichever subscription you already had open, rather than making you choose a model deliberately.
That matters because the model choice is where the money is. On our executed benchmark, Claude Sonnet 5 and DeepSeek V3.2 both scored 9 out of 9, at $1.67 and $0.08 per 1,000 tasks respectively — a 21x gap for the same result on the same nine tasks. An agent that quietly defaults to whatever you were already signed into is an agent whose bill you have not chosen.
OpenClaw remains genuinely model-agnostic, so the fix is a config change rather than a migration. It is worth making deliberately once, especially now that Claude Code weekly limits drop 17% on 2026-09-14 and more people will be looking at where their agent tokens actually go.
The repository, read directly
Most coverage quotes a star count from launch day. We queried the GitHub API at 2026-08-31T13:28:06Z:
| Field | openclaw/openclaw | For scale: deepseek-ai/deepseek-harness |
|---|---|---|
| Stars | 388,206 | 205,981 |
| Forks | 81,499 | 23,879 |
| Watchers | 1,754 | 888 |
| Language | TypeScript | TypeScript |
| Repository created | 2025-11-24 | 2026-08-13 |
| Issue tracker | enabled | disabled |
| Latest release | v2026.8.1, 2026-08-31 | — |
Our July write-up recorded 340,000 stars. That is 48,206 added in seven weeks. For context on how fast this category moves, DeepSeek Harness reached 205,981 stars in eighteen days from a standing start — we measured it at 183,972 nine days ago, so it added 22,009 in that window alone. Any star count you read without a timestamp is decoration.
The licence GitHub will not classify
GitHub reports OpenClaw's licence as NOASSERTION, displayed as “Other”. That looks alarming on a project holding your credentials, so we read the file.
It is the MIT Licence, copyright OpenClaw Foundation, with every canonical clause present — the grant, the notice requirement, the warranty disclaimer and the liability limitation. The file is 1,170 characters against roughly 1,070 for canonical MIT, and the difference is one appended sentence stating that third-party notices for incorporated or adapted code are recorded in THIRD_PARTY_NOTICES.md.
That single added line is why GitHub's detector, which needs a near-exact match, falls back to “Other”. So: the badge is misleading, the licence is MIT, and the appended pointer is a reason to read THIRD_PARTY_NOTICES.md rather than a reason to worry. If licence provenance matters to your review, open weights versus open source covers why the badge is never the answer.
Who should upgrade
- New installs: straightforwardly yes. Guided setup is the point of this release.
- Existing single-user installs: yes, but back up configuration and state first, as the release notes ask. A 16,000-PR release is a large surface.
- Anyone planning to share sessions: only after deciding that everyone you invite may hold everything the gateway holds. If that is not acceptable, run a second gateway instead.
- Anyone who set it up by reusing an existing login: go back and choose the model deliberately.
What we did not test
- We have not run OpenClaw 2.0. Everything above is read from the repository, the release notes and launch coverage. We did not install it, audit the sharing implementation, or verify the 575 ms figure.
- The security claim is theirs, not ours. We are reporting that OpenClaw documents the sharing controls as not being a security boundary. We have not tested whether they can be escaped.
- Contributor and pull-request counts come from launch coverage, not from our own query.
- Star counts are a snapshot taken 2026-08-31T13:28:06Z and were already wrong when you read them. That is why they carry a timestamp.
FAQ
What is new in OpenClaw 2.0? Shared cloud sessions, guided model setup that reuses existing logins and local runtimes, a faster Control UI, and work across installation, plugins, credentials, browser control, messaging, automation and memory — 16,000+ pull requests from 933 contributors, shipped as version 2026.8.1 on 2026-08-31.
Are OpenClaw shared sessions secure? OpenClaw's own documentation says the sharing controls are not tenant isolation and not a security boundary. Anyone in a shared session is inside the same trust boundary as the gateway's credentials.
How many GitHub stars does OpenClaw have? 388,206 as of 2026-08-31T13:28:06Z, with 81,499 forks.
What licence is OpenClaw under? MIT. GitHub shows “Other” because the LICENSE file appends one sentence pointing at THIRD_PARTY_NOTICES.md, which defeats its exact-match detector.
Should I back up before upgrading? Yes — the release notes ask you to back up configuration and state before updating.
DataLLM Lab