Guide

OpenClaw v2026.5.28: Channel delivery and session identity got safer, operator field notes

May 30, 20265 min readUpdated September 11, 2026By OpenClawBlog Team

The source record for v2026.5.28 names a provider, model, voice, or context change. This is an operator's reading of that record, with the exact source facts kept next to a bounded experiment rather than a generic feature list.

Treat this as a stable maintenance checkpoint and keep the release record beside the backup and rollback evidence. A release tag describes the project change. Your Gateway's provider, channel, platform, and account support should be recorded separately.

Channel
Stable

Primary signals
Agent and Codex runtime recovery is steadier; Channel delivery and session identity got; Mobile and chat surfaces got a broader

Publication date
2026-05-30

A small field test

Agent and Codex runtime recovery is steadier

Evidence from the release. subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort while live OpenClaw locks survive cleanup, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime state.

Operator reading. A catalog label for Agent and Codex runtime recovery is steadier is only the first signal. Confirm the account, endpoint, context limit, and tool policy that the running Gateway actually selected.

Channel delivery and session identity got safer

Evidence from the release. Channel delivery and session identity got safer across outbound plugin hooks, Matrix room ids, iMessage reactions/approvals, Slack final replies, Discord recovered tool warnings, runtime-config message actions, WhatsApp profile auth roots, Telegram polling, and Microsoft Teams service URL trust checks.

Operator reading. Treat Channel delivery and session identity got safer as a boundary change. Exercise one permitted request and one refused request with a test identity, then keep both decisions in the log.

Mobile and chat surfaces got a broader refresh

Evidence from the release. the iOS Pro UI, hosted push relay default, realtime Talk tab playback, Gateway chat transport, onboarding, Talk permissions, WebChat reconnect delivery, and session picker behavior now preserve more state across reconnects and empty searches.

Operator reading. Treat Mobile and chat surfaces got a broader refresh as a boundary change. Exercise one permitted request and one refused request with a test identity, then keep both decisions in the log.

Browser, channel, and automation inputs are stricter

Evidence from the release. Browser tool timeouts, viewport/tab indices, Gateway ports, cron retry handling, Discord component ids, schema array refs, Telegram callback pages, and channel progress callbacks now reject malformed values earlier and preserve the intended delivery context.

Operator reading. Use Browser, channel, and automation inputs are stricter as a routing test: capture the destination before the send, interrupt the transport, and verify that retry logic did not duplicate or redirect the response.

The details that affect a runbook

Provider, media, and document coverage expands

Provider, media, and document coverage expands with Claude Opus 4.8, Fal Krea image schemas, NVIDIA featured models, MiniMax streaming music responses, encrypted PDF extraction, voice model catalogs, GitHub Copilot agent runtime support, and a Codex Supervisor plugin path for delegated Codex workflows.

Provider, media, and document coverage expands changes a capability choice, not automatically a billing or privacy agreement. Record provider, model id, context setting, and fallback behavior before changing a default.

Status

show active subagent details in status output.

Keep Status measurable: name the input, expected output, failure signal, and operator who approved the test before calling the change ready.

Diffs

split the default language pack and expand default Diffs language coverage while keeping the host floor aligned.

Use Diffs for a small reproducible task: save the input, visible result, useful failure, and version context another operator would need.

Operator checklist before rollout

  1. Before touching persistent state, capture the version, host, provider, and workspace for Agent and Codex runtime recovery is steadier.
  2. Read the linked release record and verify a backup whenever the change can alter configuration or session data.
  3. Interrupt one delivery after admission, reconnect the transport, and compare the final reply with the original conversation.
  4. Force a short transport interruption and verify that retry or recovery preserves the original thread and sender.
  5. Close the test with the evidence attached, and do not widen the rollout while a behavior remains unexplained.
openclaw --version
openclaw gateway status
openclaw security audit

Keep the source trail attached

Close the loop with an explicit next action: keep the candidate isolated, proceed with the staged upgrade, or stop and investigate. Do not treat a green install as proof that the runtime path is correct.

Regression cases from the source

Agents. fall back to local config pruning when the optional agents delete Gateway probe cannot authenticate, so offline installs can still delete agents without removing shared workspaces. Treat the fix as a boundary condition and retain the source wording beside your local result.

Tighten phone-control mutation authorization [AI]. The release records a focused fix in tighten phone-control mutation authorization [ai]. Keep the reproduction and the post-fix result together in the acceptance record.

This page is a practical reading of the v2026.5.28 source record; the release index and model provider reference remain the references to use for migrations and support boundaries.

Reference Trail

Sources and further reading

  1. v2026.5.28 source recordgithub.com
  2. release indexgithub.com
  3. model provider referencedocs.openclaw.ai
Back to ArchiveMore: GuidesNext: Before an OpenClaw Answer Becomes an Article, Build the Evidence Handoff