OpenClaw telemetry

This service answers the daily update check that OpenClaw installs make. Everything it does is in this repository.

What an install sends

With automatic update checks enabled, a successful version check is reused for 24 hours. The request carries a User-Agent:

openclaw/2026.8.2 (darwin; node/v26.0.1; arm64; gateway)

Anonymous feature statistics are off by default. Operators can enable them during interactive setup, with openclaw telemetry on, or with telemetry.enabled: true. When enabled, the same request carries a small body of feature facts:

{
  "schema": 1,
  "version": "2026.8.2",
  "platform": "darwin-arm64",
  "node": "26.0.1",
  "surface": "gateway",
  "features": {
    "channels": ["telegram", "discord"],
    "providerFamilies": ["anthropic", "openai"],
    "plugins": ["codex", "diagnostics-otel"],
    "pluginsEnabled": 7,
    "sessionsLast24h": 14
  }
}

Interactive setup defaults to No thanks; guided Quick Start skips the question. Scripted installs do not opt in automatically. The enabled setting controls inclusion, not whether a prompt was answered.

Channels and providers describe configuration; plugins describe enabled inventory, not invocations. sessionsLast24h counts retained session-creation events timestamped in the preceding 24 hours, not active sessions or messages. Missing or unreadable local state produces zero.

Update outcomes

The receiver also supports identifier-free terminal update outcomes from a companion client implementation. These use a separate dataset, strict public version labels and bounded outcome categories, with no geography, install IDs, raw errors or logs. Uploads are limited to 4096 bytes. Reports are retained for three months; no public individual-report route is provided. The companion client reports outcomes on by default, like the existing update ping, under update-request policy rather than optional feature-statistics consent. update.checkOnStart: false, OPENCLAW_NO_AUTO_UPDATE=1, and Nix mode suppress outcomes; a truthy CI always suppresses outcomes, even when a replacement OPENCLAW_TELEMETRY_ENDPOINT is configured. DO_NOT_TRACK controls feature statistics, not update outcomes. Receiver support does not itself enable client reporting: deploy and verify the receiver and separate dataset before releasing the default-on client, under separately authorized rollout. See the outcome contract and collection boundaries.

Approximate location

Cloudflare provides approximate location: country, region code, city, and timezone. We store no raw IP addresses or precise coordinates in analytics.

Recorded update checks include these fields even when anonymous feature statistics are off or DO_NOT_TRACK is set. Missing or invalid fields stay empty. Records are retained for three months.

What we exclude from Analytics Engine

Reports contain no user, account, install, or device identifier. Cloudflare processes connection IP addresses, and the Worker uses them transiently for rate limiting without storing them in Analytics Engine. Worker logs are disabled; Cloudflare's separate infrastructure processing is outside those settings.

How to turn it off

Command or settingEffect
openclaw telemetry offStops anonymous feature statistics. Update checks and default-on outcomes continue.
DO_NOT_TRACK=1Same, enforced from the environment.
update.checkOnStart: falseStops automatic update requests and outcome reporting. Explicit updates and other configured services are separate.

OPENCLAW_NO_AUTO_UPDATE=1 also prevents automatic update requests. A truthy CI suppresses daily update checks and optional feature statistics unless a replacement OPENCLAW_TELEMETRY_ENDPOINT is explicitly configured. The replacement-endpoint exception applies only to daily update checks and optional feature statistics, not update outcomes.

openclaw telemetry show displays policy and a CLI-built payload preview, not the exact next Gateway payload or server-derived location information. Registry state and collection time can differ. If policy disables requests, it shows Request: none. Disabling requests does not erase previously recorded rows.