Build1 distinct publisher3 min readPublished
OpenClaw's shared sessions let a colleague take over an agent's work with its context intact while model credentials stay on the Gateway host, which is the same design that gives each install exactly one trust boundary.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Start with what a shared session actually hands over. The Gateway runs on the operator's machine and owns sessions, credentials and tool access [9]. When a second person joins active work, the session's accumulated context comes with them [14], and the execution may not be on that machine at all: a session can run on the Gateway host, a paired device or a temporary cloud worker [15]. The canonical transcript, the model credentials and the workspace state stay with the Gateway, so provider credentials do not need to be copied to the remote execution machine [16]. That separation is good engineering, and it is the specific reason a team with a rule against pasting API keys into a hosted service can evaluate this at all.
The limit is documented rather than buried. OpenClaw's security documentation defines one trust boundary per Gateway, and for participants who do not trust each other it recommends separate Gateways, separate credentials and preferably separate operating-system users or hosts [17]. Shared access is scoped to an individual, a family or a team whose members already trust one another, and multiplayer does not make one install a multi-tenant service [18]. So the unit of isolation is the install. There is no narrower role described inside a session, which means an invitee inherits an agent that can hold credentials, read messages and execute commands [13].
The cadence figures are worth converting. Averaged out, 106 releases across 230 days is one roughly every 2.2 days [20]. The pause before 2.0 was near seven weeks [7], which is about 22 of those intervals [21]. If more than 16,000 pull requests in this cycle are roughly half of everything ever merged [4][7], the project's lifetime merged total sits near 32,000 [22]. All self-reported, though the repository's public activity is consistent with that scale [5].
Treat the five-minute onboarding path the way you would treat any vendor benchmark: it measures the run the documentation chose, installation to a working browser conversation [12]. For it to transfer, model access has to be sitting on the box already, whether that is a ChatGPT or Claude subscription, an API key or a local model [2], and you have to leave out model authentication, channel pairing and optional plugins, which the docs concede can extend the process [12]. On a team, pairing is the step that repeats per person and per channel across WhatsApp, Telegram, Slack, Discord, Signal and iMessage [10]. Optional configuration now gets finished in conversation instead of in the setup flow [3], which is sensible product design and also means the record of what you configured is a transcript.
One more adoption cost, from the release's own scope. Installation, messaging, memory, skills, model support, automations, native apps, plugins and security all changed in a single cycle that began as an onboarding and browser project [8]. My read: if you have a running 1.x install with paired channels, plan this as a rebuild rather than an upgrade, and expect the security surface to be the part you re-check.
What would have to be true for the team story to hold is that your trust graph is one blob per credential set. If a contractor needs a narrow session, the documented answer is another Gateway under another OS user, and that provisioning is yours [17]. The flagship example in the announcement, meanwhile, is still monitoring a parent's inbox for school notices and forwarding selected ones through Telegram [19], which tells you where the polish went.
Ranked by verification strength, evidence, and original report placement.
OpenClaw released version 2.0 on August 30th, rebuilding its browser interface, cutting setup work and adding shared sessions that let multiple people collaborate with an AI agent without discarding its existing context.
New OpenClaw installations can start with model access already present on a computer, including ChatGPT or Claude subscriptions, API keys and local models.
OpenClaw moved optional configuration out of the initial setup flow, allowing users to finish configuring an agent through conversation.
OpenClaw says 933 contributors worked on the update, including 569 first-time contributors, across more than 16,000 pull requests. Those figures are self-reported.
The self-reported contribution figures are consistent in scale with the activity visible in OpenClaw's public repository, which had roughly 388,000 stars and 81,000 forks when the release landed.
OpenClaw said it had previously shipped 106 releases in 230 days, typically separated by one or two days.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
product
ChatGPT Work's real ask is your Slack, and somebody has to say yes on everyone's behalf1 distinct publisher
invest
Scalable Capital puts ChatGPT, Claude and Grok inside the European order ticket2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet reading one announcement
Every number in this story travels the same route: OpenClaw's post on X and its own documentation, relayed by RuntimeWire. The reporting is honest about that — it tags the contributor figures as self-reported and offers 388,000 stars only as evidence that numbers of that magnitude are plausible, not that these ones are right. The architectural claims are stronger, because they describe published security documentation anyone can go read, while the release statistics have not been recounted by anyone.
Enormous attention, unaudited headcount
The public repository numbers are the real signal: 388,000 stars and 81,000 forks are not something a release post can invent. What they measure is attention, not installs. For the release itself the only usage evidence is contributors merging their own work and, for shared sessions specifically, the project saying its own team used the feature while building it. No third-party deployment, no team rollout, nobody outside the project describing what running this looks like.
Restrained telling of a promotional source
The framing here works against inflation rather than for it: the piece leads with a constraint, that one install has exactly one trust boundary, and closes on the harder maintenance problem an agent wired into personal accounts creates. What overstatement survives is inherited, not added — 'roughly half of all pull requests ever merged' and 933 contributors are announcement rhetoric passed through with a warning label, and a five-minute setup path is a documentation promise no reader has yet timed.
The subject wrote the source
The primary source is the party being covered, announcing its own biggest release. Underneath that sits a denser tangle the reporting does disclose: the OpenClaw Foundation counts OpenAI among its major donors, engineers from OpenAI, Microsoft, Nvidia, Atlassian and Tencent serve as core maintainers, and the creator joined OpenAI in February 2026 while continuing to steward the project. Nobody in that arrangement benefits from a modest contributor count or a difficult upgrade story.
Solid on design, soft on numbers
Split the story in two and confidence splits with it. How OpenClaw is built — Gateway owns credentials and transcript, execution can move, one trust boundary per install, separate hosts for people who do not trust each other — is described precisely enough to act on and is checkable against published docs. How big and how fast is a set of project-supplied statistics with a single outlet standing behind them. Treat the architecture as reliable and the counts as directional.