Verified OpenClaw embedding
CLAWSEMBLY
Embed upstream OpenClaw.
Grant only what it needs.
Exact artifacts and public compatibility evidence meet a default-deny capability broker. BrowserPod executes; your application keeps authority.
Latest compatibility probe
Evidence before emulation.
The report separates facts we can prove from runtime behavior still under test. “It starts” is not compatibility.
openclaw@2026.6.11
- Node engine
- —
- Tarball
- —
- Unpacked
- —
- Direct deps
- —
Release tracking
Stable, rollback, preview.
Three npm channels, one fail-closed promotion gate. Observe it in CI without installing the SDK; runtime evidence is never inherited.
Preview manifest diff Resolving exact dependency specs… Inspect exact specs ↓
Preview Gateway contract Inspecting protocol surface… Inspect exact changes ↓
Loading fail-closed policy…
Use policy JSON ↗Browser host / local authority
Prove the host without booting a legacy runtime.
Credential, identity, budget, and consent controls execute in this page. BrowserPod starts only through the verified SDK with an owner-supplied key; this public page and report contract are BrowserPod-only.
creating…
CHECKING…
- 01Production runtimeBrowserPod 2.x · selected
- 02Exact installermanifest + lock integrity readback
- 03Gateway controllertoken-private · origin-pinned · stop
- 04Protocol + pairingexact review · token vault · chat RPC
- 05Guest transportSHA-256 source + readback
- 06Permission lifecyclepending · approve · expire/revoke
- 07Provider evidenceowner key required
- 08Legacy runtime fallbacknone in app bundle
The product boundary
Runtime is commodity.
Authority is not.
OpenClaw, plugins, dependencies, and generated code remain untrusted. Every host action crosses one exact, revocable, evidence-bound grant.
openclaw@2026.6.11
plugins · packages · generated code
DENY
- pending exact request
- user approve + expiry
- cancel + deny + revoke
- payload-free audit
credential vault · identity
provider policy · storage · permissions
Exact artifact → origin-pinned Gateway → signed protocol 4 handshake → one-shot pairing review → encrypted device token → bounded chat/history/abort → expiring exact grant → typed mailbox → payload-free audit. Drift, replay, and cross-runtime evidence fail closed.
Read the embedding contract ↗Adopted embedded runtime
BrowserPod executes.
Clawsembly decides.
BrowserPod is selected for commercial browser-local execution. It remains below the support line until the real upstream Gateway reproduces every checked-in lifecycle, security, persistence, and performance proof.
A byte-reproducible SDK tarball passes isolated ESM and TypeScript consumers. It pins report bytes, npm identity, and browser origin, rechecks exact pairing access, encrypts issued device tokens, then admits only bounded chat/history/abort RPC. Real provider evidence is unrun; hard dispose remains unavailable.
Commercial SDK artifact ✓ 02 / archived probeNode 22.19 converted in 1,625.84 s to 316.7 MB, then failed before its guest command. Browser packaging is blocked until host execution passes.
Apache-2.0 + guest Archived ↗OpenClaw requires Node 22.19+. Current 32-bit-only execution cannot run the official Linux x64 Node artifact.
Technically blocked RejectedNode 22.19+ → Gateway handshake → broker turn → tool → history → cancel → persistent restore → documented terminate/dispose → license review.
Run evidence capture ↗The compatibility loop
A release arrives.
The evidence updates.
-
01
Pin the artifact
Resolve an exact npm version and integrity. Never install an unverified
latest. -
02
Classify the edges
Inventory native packages, lifecycle scripts, Node APIs, schemas, and protocol changes.
-
03
Boot on BrowserPod
Run the pinned upstream artifact in BrowserPod. Historical evidence from another provider cannot turn this gate green.
-
04
Grant, test, publish
Exercise only declared host authority, then publish supported, constrained, denied, and unavailable capabilities in machine-readable form.
Design principles
The official runtime.
OpenClaw remains the source of agent behavior, sessions, providers, and protocol.
Unknown capabilities.
Browser limitations fail closed with actionable diagnostics instead of dummy success.
Every compatibility finding.
Reports, manifests, fixtures, and narrow upstream fixes are public OSS artifacts.
Build in public
Help make OpenClaw
safe to embed.
Inspect the blocked launch, install the evidence-bound source alpha, or contribute a reproducible BrowserPod finding. Runtime support remains probing.
npm bootstrap pending · verified GitHub and Pages tarballs are available now