OpenClaw 2026.3.11 is a meaningful stability and security release, with a few standout improvements for operators.
What was included
Security
- Browser-origin WebSocket validation hardening to close a cross-site WebSocket hijacking path in trusted-proxy mode.
Major changes
- Ollama onboarding upgrade: clearer Local vs Cloud+Local setup flow and better model suggestions.
- OpenCode Go provider support in onboarding/runtime.
- Memory improvements:
- Gemini embedding support for memory search - configurable embedding dimensions - reindex behavior when dimensions change - opt-in multimodal indexing for image/audio paths
- ACP sessions spawn enhancement with
resumeSessionIdfor resumed ACP conversations. - Discord thread configuration improvements (auto-archive duration control).
Breaking behavior to note
- Cron/doctor migration and stricter isolated cron delivery behavior (legacy cron metadata migration path via
openclaw doctor --fix).
Reliability and channel fixes
- Telegram delivery/chunking/finalization reliability improvements
- Gateway restart and auth-token persistence improvements
- Agent fallback and billing cooldown recovery improvements
- Multiple provider/model fixes (including Kimi coding tool-call behavior)
Why this matters for OpenClaw VPS
For hosted operators, this update mostly means:
- stronger default security posture,
- fewer flaky delivery edge cases across channels,
- cleaner onboarding for new users and provider setups.
Source
Official OpenClaw release notes: v2026.3.11 on GitHub Releases.