@GitTrend0x: Microsoft Announces OpenClaw Official App. Allows Agents to Control Your Windows: ✓ Built-in Permissions ✓ Full Control from System Tray ✓ Secure by Default, Runs in a Container Open Source: https://github.com/openclaw/openclaw-w…

X AI KOLs Timeline Products

Summary

Microsoft has announced the official OpenClaw Windows app, enabling AI assistants to control Windows with built-in permissions, complete system tray control, and secure container-based execution.

Microsoft announces the official OpenClaw app. Allows agents to control your Windows: ✓ Built-in permissions ✓ Full control from the system tray ✓ Secure by default, runs in a container Open source code: https://github.com/openclaw/openclaw-windows-node…
Original Article
View Cached Full Text

Cached at: 06/05/26, 05:17 PM

Microsoft announces the official OpenClaw app. Allows agents to control your Windows: ✓ Built-in permissions ✓ Full control from system tray ✓ Secure by default, runs in a container. Open source: https://github.com/openclaw/openclaw-windows-node…


openclaw/openclaw-windows-node

Source: https://github.com/openclaw/openclaw-windows-node

🦞 OpenClaw Windows Hub

OpenClaw Windows Node banner

A native Windows companion suite for OpenClaw (https://openclaw.ai) - the AI-powered personal assistant.
Made with 🦞 love by Scott Hanselman and Molty

OpenClaw Windows Hub tray menu

OpenClaw Windows Hub command center

OpenClaw Windows Hub pairing and connection settings

OpenClaw Windows Hub activity and diagnostics

Projects

This monorepo contains the Windows hub, shared client libraries, and CLI utilities:

ProjectDescription
OpenClaw.Tray.WinUISystem tray application (WinUI 3) for quick access to OpenClaw
OpenClaw.SharedShared gateway client library
OpenClaw.CliCLI validator for WebSocket connect/send/probe using tray settings

🚀 Quick Start

End-user installer? Download the latest stable x64 or ARM64 installer from the OpenClaw Windows docs (https://docs.openclaw.ai/platforms/windows), or see docs/SETUP.md for step-by-step installation (no build required).

Managed WSL gateway? Local setup creates a locked-down app-owned OpenClawGateway distro. See docs/WSL_GATEWAY_ADMIN.md for editing openclaw.json as the openclaw user and using root for protected-file administration.

Direct downloads from the latest OpenClaw release:

  • OpenClawCompanion-Setup-x64.exe (https://github.com/openclaw/openclaw/releases/latest/download/OpenClawCompanion-Setup-x64.exe)
  • OpenClawCompanion-Setup-arm64.exe (https://github.com/openclaw/openclaw/releases/latest/download/OpenClawCompanion-Setup-arm64.exe)
  • OpenClawCompanion-SHA256SUMS.txt (https://github.com/openclaw/openclaw/releases/latest/download/OpenClawCompanion-SHA256SUMS.txt)

Prerequisites

  • Windows 10 (20H2+) or Windows 11
  • .NET 10.0 SDK - https://dotnet.microsoft.com/download/dotnet/10.0
  • Windows 10 SDK (for WinUI build) - install via Visual Studio or standalone
  • WebView2 Runtime - pre-installed on modern Windows, or get from https://developer.microsoft.com/microsoft-edge/webview2

Build

Use the build script to check prerequisites and build:

``powershell

Check prerequisites

.\build.ps1 -CheckOnly

Build all projects

.\build.ps1

Build specific project

.\build.ps1 -Project WinUI ``

Or build directly with dotnet:

``powershell

Build all (use build.ps1 for best results)

dotnet build

Build WinUI (requires runtime identifier for WebView2 support)

dotnet build src/OpenClaw.Tray.WinUI/OpenClaw.Tray.WinUI.csproj -r win-arm64 # ARM64 dotnet build src/OpenClaw.Tray.WinUI/OpenClaw.Tray.WinUI.csproj -r win-x64 # x64

Build MSIX package (for camera/mic consent prompts)

dotnet build src/OpenClaw.Tray.WinUI -r win-arm64 -p:PackageMsix=true # ARM64 MSIX dotnet build src/OpenClaw.Tray.WinUI -r win-x64 -p:PackageMsix=true # x64 MSIX ``

Run Tray App

``powershell

Build and launch the unpackaged WinUI tray app

.\run-app-local.ps1

If you already built, skip rebuild and launch the existing Debug output

.\run-app-local.ps1 -NoBuild

Run isolated from your normal tray settings so multiple worktrees can run together

.\run-app-local.ps1 -Isolated

Alpha update testing from a Release build

.\run-app-local.ps1 -Configuration Release -Isolated -UpdateChannel alpha

Optional: launch through WinAppCLI with Package.appxmanifest

.\run-app-local.ps1 -UseWinApp -NoBuild ``

The default path starts the unpackaged executable directly. -UseWinApp requires Microsoft WinAppCLI (winget install Microsoft.WinAppCLI) and is only needed when you want manifest/MSIX-adjacent launch validation.

Run CLI WebSocket Validator

Use the CLI to validate gateway connectivity and chat.send outside the tray UI.

``powershell

Show help

dotnet run –project src/OpenClaw.Cli – –help

Use tray settings from %APPDATA%\OpenClawTray\settings.json and send one message

dotnet run –project src/OpenClaw.Cli – –message “quick send validation”

Loop sends and also probe sessions/usage/nodes APIs

dotnet run –project src/OpenClaw.Cli – –repeat 5 –delay-ms 1000 –probe-read –verbose

Override gateway URL/token for isolated testing

dotnet run –project src/OpenClaw.Cli – –url ws://127.0.0.1:18789 –token “” –message “override test” ``

📦 OpenClaw.Tray (Molty)

Modern Windows 11-style system tray companion that connects to your local OpenClaw gateway.

Features

  • 🦞 Lobster branding - Pixel-art lobster tray icon with status colors
  • 🎨 Modern UI - Windows 11 flyout menu with dark/light mode support
  • 💬 Quick Send - Send messages via global hotkey (Ctrl+Alt+Shift+C)
  • 🔄 Auto-updates - Automatic updates from GitHub Releases
  • 🌐 Web Chat - Embedded chat window with WebView2
  • 📊 Live Status - Real-time sessions, channels, and usage display
  • 🧭 Command Center - Dense gateway, channel, usage, node, pairing, and allowlist diagnostics from one window
  • ⚡ Activity Stream - Command Center page for live session, usage, node, and notification events
  • 🔔 Toast Notifications - Clickable Windows notifications with smart categorization
  • 📡 Channel Control - Start/stop Telegram & WhatsApp from the menu
  • 🖥️ Node Observability - Node inventory with online/offline state and copyable summary
  • ⏱ Cron Jobs - Quick access to scheduled tasks
  • 🚀 Auto-start - Launch with Windows
  • ⚙️ Settings - Full configuration page
  • 🎯 First-run onboarding — 6-screen setup wizard (connection, permissions, chat, configuration)

Quick Send scope requirement

Quick Send uses the gateway chat.send method and requires the operator device to have operator.write scope. If Quick Send fails with missing scope: operator.write, Molty now copies identity + remediation guidance to your clipboard, including:

  • operator role and client.id used by the tray app
  • gateway-reported operator device id (if provided)
  • currently granted scopes (if provided)

For this specific error (missing scope: operator.write), the cause is an operator token scope issue. Update the token used by the tray app so it includes operator.write, then retry Quick Send. If Quick Send fails with pairing required / NOT_PAIRED, that is a device approval issue. Approve the tray device in gateway pairing approvals, reconnect, and retry.

Menu Sections

  • Status - Gateway connection status with click-to-view details
  • Command Center - Hub with diagnostics, channel health, usage, sessions, nodes, and copyable repair commands
  • Sessions - Active agent sessions with preview and per-session controls
  • Usage - Provider/cost summary with quick jump to activity details
  • Channels - Telegram/WhatsApp status with toggle control
  • Nodes - Online/offline node inventory and copyable summary
  • Recent Activity - Timestamped event stream for sessions, usage, nodes, and notifications
  • Actions - Dashboard, Web Chat, Quick Send, Activity Stream, History
  • Support & Debug - Logs, config, diagnostics folder, redacted support context, browser setup, port/capability/node/channel/activity summaries, and managed SSH tunnel restart
  • Settings - Configuration and auto-start

Mac Parity Status

Comparing against openclaw-menubar (https://github.com/magimetal/openclaw-menubar) (macOS Swift menu bar app):

FeatureMacWindowsNotes
Menu bar/tray icon✅✅Color-coded status
Gateway status display✅✅Connected/Disconnected
PID display✅✅Command Center shows gateway listener process/PID
Channel status✅✅Mac: Discord / Win: Telegram+WhatsApp
Sessions count✅✅
Last check timestamp✅✅Shown in tray tooltip
Gateway start/stop/restart✅⚠️Windows can restart the managed SSH tunnel from tray Support & Debug and Command Center; external gateway process control is not implemented
View Logs✅✅
Open Web UI✅✅
Refresh✅✅Auto-refresh on menu open
Launch at Login✅✅
Notifications toggle✅✅

Windows-Only Features

These features are available in Windows but not in the Mac app:

FeatureDescription
Quick Send hotkeyCtrl+Alt+Shift+C global hotkey
Embedded Web ChatWebView2-based chat window
Toast notificationsClickable Windows notifications
Channel controlStart/stop Telegram & WhatsApp
Modern flyout menuWindows 11-style with dark/light mode
Deep linksopenclaw:// URL scheme with IPC
First-run onboarding6-screen guided setup wizard (Welcome → Connection → Wizard → Permissions → Chat → Ready)

🔌 Node Mode (Agent Control)

When Node Mode is enabled in Settings, your Windows PC becomes a node that the OpenClaw agent can control - just like the Mac app! The agent can:

CapabilityCommandsDescription
Systemsystem.notify, system.run, system.run.prepare, system.which, system.execApprovals.get, system.execApprovals.setShow Windows toast notifications, execute commands with policy controls
Canvascanvas.present, canvas.hide, canvas.navigate, canvas.eval, canvas.snapshot, canvas.a2ui.push, canvas.a2ui.pushJSONL, canvas.a2ui.resetDisplay and control a WebView2 window
Screenscreen.snapshot, screen.recordCapture screenshots and fixed-duration MP4 screen recordings
Cameracamera.list, camera.snap, camera.clipEnumerate cameras and capture still photos or short video clips
Speech-to-textstt.transcribeCapture audio from the default microphone for a bounded duration and return transcribed text. Default-off; opt-in via Settings. When enabled, advertised to both gateway callers (subject to gateway allowlist) and local MCP clients (subject to bearer token).
Locationlocation.getReturn Windows geolocation when permission is available
Devicedevice.info, device.statusReturn Windows host/app metadata and lightweight status
Text-to-speechtts.speakSpeak text aloud through Windows speech synthesis, or ElevenLabs when configured

Packaged installs declare camera, microphone, and location capabilities. Windows may ask for consent the first time a node capability uses one of those protected resources.

Node Setup

  1. Enable Node Mode in Settings (enabled by default)

  2. First connection creates a pairing request on the gateway

  3. Approve the device on your gateway:

    bash openclaw devices list # Find your Windows device openclaw devices approve # Approve it

  4. Configure gateway allowCommands - Add the commands you want to allow under gateway.nodes in ~/.openclaw/openclaw.json:

    json { "gateway": { "nodes": { "allowCommands": [ "system.notify", "system.run", "system.run.prepare", "system.which", "system.execApprovals.get", "system.execApprovals.set", "canvas.present", "canvas.hide", "canvas.navigate", "canvas.eval", "canvas.snapshot", "canvas.a2ui.push", "canvas.a2ui.pushJSONL", "canvas.a2ui.reset", "screen.snapshot", "camera.list", "camera.snap", "camera.clip", "location.get", "device.info", "device.status", "tts.speak" ] } } }

    ⚠️ Important: The gateway has a server-side allowlist. Commands must be listed explicitly - wildcards like canvas.* don’t work! Privacy-sensitive commands such as screen.record and agent-driven audio playback via tts.speak should only be added to allowCommands when you explicitly want to allow them.

  5. Test it from your Mac/gateway:

    ``bash

    Show a notification

    openclaw nodes notify –node –title “Hello” –body “From Mac!”

    Open a canvas window

    openclaw nodes canvas present –node –url “https://example.com”

    Execute JavaScript (note: CLI sends “javaScript” param)

    openclaw nodes canvas eval –node –javaScript “document.title”

    Render A2UI JSONL in the canvas (pass the file contents as a string)

    openclaw nodes canvas a2ui push –node –jsonl “$(cat ./ui.jsonl)”

    Take a screenshot

    openclaw nodes invoke –node –command screen.snapshot –params ‘{“screenIndex”:0,“format”:“png”}’

    Record a short screen clip (requires explicitly allowing screen.record on the gateway)

    openclaw nodes screen record –node –duration 3000 –fps 10 –screen 0 –no-audio –out /tmp/openclaw-windows-screen-record-test.mp4 –json

    List cameras

    openclaw nodes invoke –node –command camera.list

    Take a photo (NV12/MediaCapture fallback)

    openclaw nodes invoke –node –command camera.snap –params ‘{“deviceId”:“”,“format”:“jpeg”,“quality”:80}’

    Speak text aloud on the Windows node (requires TTS enabled in Settings and tts.speak allowed on the gateway)

    openclaw nodes invoke –node –command tts.speak –params ‘{“text”:“Hello from OpenClaw”,“provider”:“windows”}’

    Execute a command on the Windows node

    openclaw nodes invoke –node –command system.run –params ‘{“command”:“Get-Process | Select -First 5”,“shell”:“powershell”,“timeoutMs”:10000}’

    View exec approval policy

    openclaw nodes invoke –node –command system.execApprovals.get

    Update exec approval policy (add custom rules)

    openclaw nodes invoke –node –command system.execApprovals.set –params ‘{“rules”:[{“pattern”:“echo ”,“action”:“allow”},{“pattern”:“”,“action”:“deny”}],“defaultAction”:“deny”}’ ``

    📷 Camera permission: Desktop builds rely on Windows Privacy settings. Packaged MSIX builds will show the system consent prompt. 🔒 Exec Policy: system.run is gated by an approval policy on the Windows node at %LOCALAPPDATA%\OpenClawTray\exec-policy.json (schema: { "defaultAction": "...", "rules": [...] }). This is separate from gateway-side ~/.openclaw/exec-approvals.json.

    Rules are matched against the full command line. Known wrapper payloads such as cmd /c ..., powershell -Command ..., pwsh -EncodedCommand ..., and bash -c ... are also evaluated before execution. Dangerous environment overrides like PATH, PATHEXT, NODE_OPTIONS, GIT_SSH_COMMAND, LD_*, and DYLD_* are rejected.

Command Center diagnostics

Open the status detail/Command Center from the tray menu or with openclaw://commandcenter. It shows:

  • channel health from gateway health events, including node-mode health received without a separate operator connection
  • active sessions, usage/cost data, node inventory, declared commands, and Mac parity notes
  • allowlist diagnostics that separate safe companion commands from privacy-sensitive opt-ins like screen.record, camera.snap, and camera.clip
  • copyable repair commands for safe allowlist fixes and pending pairing approval
  • recent activity and node invoke results through the Activity Stream, storing command names/status/duration only (not payloads, screenshots, recordings, or secrets)

bash openclaw nodes invoke --node --command system.execApprovals.set --params '{"rules":[{"pattern":"powershell.exe","action":"allow"},{"pattern":"pwsh.exe","action":"allow"},{"pattern":"echo *","action":"allow"},{"pattern":"*","action":"deny"}],"defaultAction":"deny"}' 🔐 Web Chat secure context: Remote web chat requires https:// (or localhost). If using a self-signed cert, trust it in Windows (Trusted Root Certification Authorities) or use an SSH tunnel to localhost.

Node Status in Tray Menu

The tray menu shows node connection status:

  • 🔌 Node Mode section appears when enabled
  • ⏳ Waiting for approval… - Device needs approval on gateway
  • ✅ Paired & Connected - Ready to receive commands
  • Click the device ID to copy it for the approval command

Deep Links

OpenClaw registers the openclaw:// URL scheme for automation and integration:

LinkDescription
`openclaw://

Similar Articles

@GitHub_Daily: Microsoft recently open-sourced an AI terminal: Intelligent Terminal, based on Windows Terminal, with an AI assistant built into the terminal. It can automatically detect command-line output, and when errors occur, send the context to AI for analysis with one click, without manual copy-paste, and can even directly help execute...

X AI KOLs Timeline

Microsoft open-sourced Intelligent Terminal, an AI-powered terminal based on Windows Terminal that integrates AI assistants to help with command-line errors and tasks.

@github: OpenClaw. Is it the Linux of AI?

X AI KOLs Timeline

The tweet questions if OpenClaw, a project on GitHub, could become the Linux equivalent for the AI field, suggesting its potential significance as an open-source initiative.

openclaw/openclaw

GitHub Trending (daily)

OpenClaw is a personal AI assistant that runs locally on user devices and integrates with various messaging channels through a central gateway, supporting connection to AI models and tools.

@interjc: openclaw 都有手机 app 了

X AI KOLs Following

OpenClaw has launched native mobile apps for iOS and Android, allowing users to run AI agents on the go with features like channels, tasks, and replies.