Verified OpenClaw embedding

CLAWSEMBLY

Embed upstream OpenClaw.
Grant only what it needs.

Exact artifacts and public compatibility evidence meet a default-deny capability broker. BrowserPod executes; your application keeps authority.

Latest stable PROBING
Scroll to evidence

Latest compatibility probe

Evidence before emulation.

The report separates facts we can prove from runtime behavior still under test. “It starts” is not compatibility.

reports / openclaw / 2026.6.11

openclaw@2026.6.11

Node engine
Tarball
Unpacked
Direct deps
Loading checked-in report…
Generated Desktop Chromium baseline

Release tracking

Stable, rollback, preview.

Three npm channels, one fail-closed promotion gate. Observe it in CI without installing the SDK; runtime evidence is never inherited.

Resolving channels…
Tracked Open release JSON ↗

Browser host / local authority

Prove the host without booting a legacy runtime.

Credential, identity, budget, and consent controls execute in this page. BrowserPod starts only through the verified SDK with an owner-supplied key; this public page and report contract are BrowserPod-only.

Browser host credential vault Checking…
Browser-host session budget
Protected live smoke test gpt-5.6-luna · store:false

Sends only a fixed probe prompt to OpenAI. It never includes workspace, chat, tool-result, device-token, or backup data. Output is hidden until the response completes and is rendered as plain text.

Loading official-price bound…

Live test locked · save an OpenAI credential first

Checking browser cryptography…

Mock broker probe only; no provider request is made. The browser host rejects traffic beyond this budget. Never mounted into the OpenClaw workspace.
Browser device identity creating… CHECKING…
browserpod-contract.log
  1. 01Production runtimeBrowserPod 2.x · selected
  2. 02Exact installermanifest + lock integrity readback
  3. 03Gateway controllertoken-private · origin-pinned · stop
  4. 04Protocol + pairingexact review · token vault · chat RPC
  5. 05Guest transportSHA-256 source + readback
  6. 06Permission lifecyclepending · approve · expire/revoke
  7. 07Provider evidenceowner key required
  8. 08Legacy runtime fallbacknone in app bundle

The product boundary

Runtime is commodity.
Authority is not.

OpenClaw, plugins, dependencies, and generated code remain untrusted. Every host action crosses one exact, revocable, evidence-bound grant.

01 / untrusted BrowserPod guest

openclaw@2026.6.11
plugins · packages · generated code

02 / Clawsembly DEFAULT
DENY
  • pending exact request
  • user approve + expiry
  • cancel + deny + revoke
  • payload-free audit
03 / trusted host Browser authority

credential vault · identity
provider policy · storage · permissions

Implemented slice

Exact artifact → origin-pinned Gateway → signed protocol 4 handshake → one-shot pairing review → encrypted device token → bounded chat/history/abort → expiring exact grant → typed mailbox → payload-free audit. Drift, replay, and cross-runtime evidence fail closed.

Read the embedding contract ↗

Adopted embedded runtime

BrowserPod executes.
Clawsembly decides.

BrowserPod is selected for commercial browser-local execution. It remains below the support line until the real upstream Gateway reproduces every checked-in lifecycle, security, persistence, and performance proof.

Default gate

Node 22.19+ → Gateway handshake → broker turn → tool → history → cancel → persistent restore → documented terminate/dispose → license review.

Run evidence capture ↗

The compatibility loop

A release arrives.
The evidence updates.

  1. 01

    Pin the artifact

    Resolve an exact npm version and integrity. Never install an unverified latest.

  2. 02

    Classify the edges

    Inventory native packages, lifecycle scripts, Node APIs, schemas, and protocol changes.

  3. 03

    Boot on BrowserPod

    Run the pinned upstream artifact in BrowserPod. Historical evidence from another provider cannot turn this gate green.

  4. 04

    Grant, test, publish

    Exercise only declared host authority, then publish supported, constrained, denied, and unavailable capabilities in machine-readable form.

Design principles

01 / USE

The official runtime.

OpenClaw remains the source of agent behavior, sessions, providers, and protocol.

02 / DENY

Unknown capabilities.

Browser limitations fail closed with actionable diagnostics instead of dummy success.

03 / SHARE

Every compatibility finding.

Reports, manifests, fixtures, and narrow upstream fixes are public OSS artifacts.

Build in public

Help make OpenClaw
safe to embed.

Inspect the blocked launch, install the evidence-bound source alpha, or contribute a reproducible BrowserPod finding. Runtime support remains probing.

npm bootstrap pending · verified GitHub and Pages tarballs are available now